Communication method and apparatus, and system
By introducing a model that detects adversarial samples in the wireless communication system, the problem of performance degradation of AI models caused by adversarial samples during the inference stage is solved, and the attacks of adversarial samples are identified and prevented, and network performance is guaranteed.
Patent Information
- Application Number
- PCT/CN2024/134250
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-27
- Filing Date
- 2024-11-25
- Publication Date
- 2025-06-05
AI Technical Summary
In wireless communication systems, the AI model may be input to adversarial samples during the inference stage, resulting in a degradation of model performance and inability to output the correct results, thereby deteriorating network performance.
A communication method is provided to acquire adversarial samples through the first network element and train a detection model, and send the detection model to the second network element for identifying adversarial samples at the inference stage of the AI model, thereby avoiding performance degradation.
Effectively identify and prevent adversarial samples from attacking AI models, protect network performance, and prevent performance degradation.
Smart Images

Figure CN2024134250_05062025_PF_FP_ABST
Abstract
Description
Communication method, device and system
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 27, 2023, with application number 202311604240.8 and application name “Communication Methods, Devices and Systems”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technologies, and in particular to communication methods, devices, and systems. Background Art
[0003] With the development of communication technology, the introduction of artificial intelligence (AI) into wireless communication systems is being considered to improve network performance. Among them, AI models are the core of AI application scenarios.
[0004] Currently, after the AI model training is completed, it can be sent to the corresponding node for inference. During the inference stage, the corresponding results output by the AI model based on the input data (also called input samples) can be used to adjust the network strategy. However, during the inference stage, the AI model may be input with adversarial samples. Adversarial samples refer to samples that change features to circumvent model detection. If the AI model is input with adversarial samples, it may not output the correct results, resulting in a decrease in the inference performance of the AI model. Summary of the Invention
[0005] Embodiments of the present application provide communication methods, devices, and systems that can identify adversarial samples input into an AI model during the inference phase to avoid degradation of AI model performance.
[0006] In the first aspect, a communication method is provided, which can be executed by a first network element, or by a component of the first network element (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can realize all or part of the functions of the first network element. The following is an example of the execution subject of the method, which includes: the first network element obtains an adversarial sample and trains a first model based on the adversarial sample. Then, the first network element sends the first model to the second network element. The first model is used to detect whether the inference data of the AI model is an adversarial sample.
[0007] Based on the communication method provided in the embodiments of the present application, a model for detecting adversarial samples can be introduced into the AI application scenarios of the communication network, which can identify whether the inference data is an adversarial sample during the inference stage of the AI model, thereby avoiding the performance degradation of the AI model and ensuring network performance.
[0008] In one possible design, the method further includes: the first network element obtaining training data and generating adversarial samples based on the training data.
[0009] Based on this solution, the first network element can train the first model based on the adversarial samples generated by itself, thereby ensuring the security of the network.
[0010] In one possible design, a first network element trains a first model based on an adversarial sample, including: the first network element generates an explainable artificial intelligence (XAI) feature sample based on the adversarial sample, and trains the first model based on the XAI feature sample. The XAI feature sample includes a value representing feature importance of the adversarial sample; or the XAI feature sample includes a value representing unit importance of the AI model.
[0011] In one possible design, the method further includes: the first network element sending a second model to the second network element, wherein the XAI feature sample is generated by the second model, and the second model is used to interpret the AI model.
[0012] Based on this solution, the second model can be used to generate XAI feature samples and explain the AI model, which can help personnel understand the output of the AI model and whether the output of the AI model is reliable.
[0013] In one possible design, the method further includes: the first network element sending the AI model to the second network element, wherein the AI model is associated with the first model.
[0014] Based on this solution, after receiving the AI model, the second network element can learn, based on its association with the first model, that the first model is used to detect the inference data of the AI model.
[0015] In one possible design, the method further includes: the first network element receiving the adversarial sample detected by the second network element.
[0016] In one possible design, the method further includes: the first network element receiving identification information of an AI model from the second network element, wherein the AI model is associated with the first model.
[0017] Based on this solution, the first network element can determine, based on the identification information of the AI model, that the received adversarial sample is detected by the first model associated with the AI model.
[0018] In one possible design, the method further includes: the first network element retraining the first model based on the adversarial samples detected by the second network element.
[0019] Based on this solution, the first network element can retrain the first model according to the detected adversarial samples to improve the performance of the first model.
[0020] In one possible design, the method also includes: the first network element sends a first parameter to the second network element, the first parameter is used to indicate a threshold of a first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
[0021] Based on this solution, the number of adversarial samples detected can be counted by the first counter, which facilitates the statistics of adversarial samples.
[0022] In one possible design, the method further includes: the first network element receiving information about the terminal device from the second network element. The first network element deregisters the terminal device based on the information about the terminal device.
[0023] Based on this solution, the first network element can deregister the terminal device that sends adversarial samples to the second network element, preventing the terminal device from continuing to send adversarial samples to the second network element.
[0024] In the second aspect, a communication method is provided, which can be executed by a second network element, or by a component of the second network element (such as a processor, chip, or chip system, etc.), or by a logic module or software that can implement all or part of the functions of the second network element. The following is an example of the execution subject of the method, which includes: the second network element obtains a first model and inference data. Then, the second network element detects whether the inference data input to the AI model is an adversarial sample based on the first model.
[0025] Based on the communication method provided in the embodiments of the present application, a model for detecting adversarial samples can be introduced into the AI application scenarios of the communication network, which can identify whether the inference data is an adversarial sample during the inference stage of the AI model, thereby avoiding the performance degradation of the AI model and ensuring network performance.
[0026] In one possible design, the second network element detects whether the inference data input into the AI model is an adversarial sample based on the first model, including: the second network element inputs the output result of the AI model into the first model, and detects whether the inference data is an adversarial sample based on the output result of the first model.
[0027] In one possible design, the second network element detects whether inference data input into the AI model is an adversarial example based on the first model, including: the second network element obtains an XAI feature sample based on the output of the AI model. The second network element then inputs the XAI feature sample into the first model and detects whether the inference data is an adversarial example based on the output of the first model. The XAI feature sample includes a value representing the feature importance of the inference data; or the XAI feature sample includes a value representing the unit importance of the AI model.
[0028] Based on this solution, multiple methods are provided for detecting whether the inference data of the AI model is an adversarial sample based on the first model. You can choose the appropriate method according to actual needs.
[0029] In one possible design, the method further includes: the second network element obtaining a second model, wherein the second model is used to generate an XAI feature sample.
[0030] Based on this solution, the second model can be used to generate XAI feature samples and explain the AI model, which can help personnel understand the output of the AI model and whether the output of the AI model is reliable.
[0031] In one possible design, the method also includes: if the first condition is met, the second network element performs at least one of the following: releasing the connection with the terminal device, sending the detected adversarial sample to the first network element, or sending information of the terminal device to the third network element.
[0032] Based on this solution, the second network element can perform subsequent actions to protect network security when certain conditions are met.
[0033] In one possible design, the first condition is: the inference data from the terminal device is detected to be an adversarial sample; or, the first condition is: the first counter corresponding to the terminal device reaches a threshold; wherein, each time the inference data from the terminal device is detected to be an adversarial sample, the current value of the first counter is increased by one.
[0034] Based on this solution, the second network element can release the connection with the terminal device when it detects that the inference data from the terminal device is an adversarial sample, or detects that the inference data from the terminal device reaches a certain number of times, and send the detected adversarial sample to the first network element, or send at least one item of the terminal device's information to the third network element, thereby preventing the terminal device from continuing to send adversarial samples and protecting network security.
[0035] In one possible design, the threshold is preset. Alternatively, the threshold is configured by the first network element.
[0036] In one possible design, the method further includes: the second network element obtaining an AI model, wherein the AI model is associated with the first model.
[0037] Based on this solution, after the second network element obtains the AI model, it can learn, based on the association relationship with the first model, that the first model is used to detect the inference data of the AI model.
[0038] In a third aspect, a communication device is provided for implementing the various methods described above. The communication device includes modules, units, or means corresponding to the methods described above. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the functions described above.
[0039] In some possible designs, the communication device may include a transceiver module and a processing module. The transceiver module, which may also be referred to as a transceiver unit, is configured to implement the transmitting and / or receiving functions described in the first or second aspect and any possible implementation thereof. The transceiver module may be comprised of a transceiver circuit, a transceiver, a transceiver, or a communication interface. The processing module may be configured to implement the processing functions described in the first or second aspect and any possible implementation thereof.
[0040] In some possible designs, the transceiver module includes a sending module and a receiving module, which are respectively used to implement the sending and receiving functions in the above-mentioned first aspect or second aspect, and any possible implementation methods thereof.
[0041] In a fourth aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is used to communicate with a module outside the communication device; the processor is used to execute a computer program or instruction so that the communication device performs any of the methods described above.
[0042] In a fifth aspect, a communication device is provided, comprising: at least one processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs any of the methods described in the aforementioned aspects. In one possible implementation, the memory may be coupled to the processor, or may be independent of the processor. In another possible implementation, the communication device further includes the memory. Optionally, the memory and the processor are integrated.
[0043] In aspects 3 to 5, the communication device may be the first network element in the first aspect or any implementation of the first aspect, or a device including the first network element, or a device included in the first network element, such as a chip or a chip system. Alternatively, the communication device may be the second network element in the second aspect or any implementation of the second aspect, or a device including the second network element, or a device included in the second network element, such as a chip or a chip system.
[0044] In a sixth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is run on a communication device, the communication device can execute any of the above aspects or any of its implementation methods.
[0045] In a seventh aspect, a computer program product comprising instructions is provided, which, when executed on a communication device, enables the communication device to execute the method of any of the above aspects or any of its implementations.
[0046] In an eighth aspect, a communication device is provided (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the functions involved in any of the above aspects or any of its implementation methods.
[0047] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.
[0048] In some possible designs, when the device is a chip system, it can be composed of a chip, or it can also include a chip and other discrete devices.
[0049] It can be understood that when the communication device provided in any one of the third to fifth aspects is a chip, the above-mentioned sending action / function can be understood as output, and the above-mentioned receiving action / function can be understood as input.
[0050] Among them, the technical effects brought about by any implementation method of the third to eighth aspects can refer to the technical effects brought about by the corresponding implementation methods of the first to fourth aspects, and will not be repeated here.
[0051] It should be noted that various possible implementations of any of the above aspects can be combined under the premise that the solutions are not contradictory.
[0052] In a ninth aspect, a communication system is provided, which includes a first network element that executes the method of the first aspect, and a second network element that executes the method of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 is a schematic diagram of the framework of AI application in NR system;
[0054] FIG2 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0055] FIG3 is a flow chart of a communication method according to an embodiment of the present application;
[0056] FIG4 is a second flow chart of a communication method provided in an embodiment of the present application;
[0057] FIG5 is a schematic diagram of the composition of a communication device provided in an embodiment of the present application;
[0058] FIG6 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the embodiments of the present application is first given as follows.
[0060] 1. AI in Communication Systems
[0061] AI technology simulates the human brain to perform complex calculations. With the development of both communications and AI technologies, the industry is proposing the use of AI in communications systems to improve network performance and user experience.
[0062] In the application scenario of AI applied to communication systems, after the AI model training is completed, it can be sent to the corresponding node for inference. During the inference stage, the AI model can output network-related prediction results or network policies based on the input data (also called input samples). At present, the 3rd Generation Partnership Project (3GPP) has designed several basic application scenarios for the application of AI on the radio access network (RAN) side, such as network energy saving, load balancing, and mobility optimization. Taking the network energy saving scenario as an example, the AI model can use the data collected in the network to predict the energy efficiency and load status of the network, so as to help the system dynamically configure energy-saving strategies to maintain a balance between system performance and energy efficiency and reduce energy consumption.
[0063] Figure 1 illustrates a possible framework for AI applications in new radio (NR) systems. As shown in Figure 1, the data source module collects and stores data from various network entities (e.g., base stations and terminal devices) as a database for AI model training and data analysis and inference. The model training host module analyzes the training data provided by the data source module and trains an AI model. The trained AI model can then be deployed or updated to the model inference host module. The model inference host module uses the AI model provided by the model training host module and, based on the inference data provided by the data source module, outputs reasonable predictions about network operation or related adjusted policies. Optionally, after using the AI model, the model inference host module can also provide feedback on the AI model's performance to the model training module. The actor module can centrally plan relevant policy adjustments and send the adjusted network policies to multiple network entities for execution. Furthermore, after applying the adjusted network policies, the data source module can collect and store data again within the network. The actor module can also collect the specific performance of the network to which the adjusted network strategy is applied, such as the values of some relevant indicators, and feed back the specific performance of the network together with the adjusted network strategy to the data resource module.
[0064] The different modules shown in FIG1 can be deployed on different entities, or can also be deployed on the same entity.
[0065] It should be understood that the modules and the interaction diagrams between them shown in Figure 1 are provided to facilitate understanding of the application of AI in communication systems. They do not necessarily represent the interaction between the modules shown in Figure 1 in actual applications. For example, if a module in an actual application scenario integrates the functions of the model reasoning management module and the actor module in Figure 1, then the step of transmitting output results between the model reasoning management module and the actor module shown in Figure 1 does not exist.
[0066] 2. Explainable artificial intelligence (XAI):
[0067] XAI is a method and technology for producing accurate and explainable AI models that can explain why and how AI algorithms make specific decisions, so that the results of AI solutions can be understood by humans. There are two options for interpretable AI models: one is to select a model with a simple and easily explainable structure and then train it. This way, the trained model itself is highly interpretable, making its decisions easier for humans to understand. The other is to train a complex, high-performance model and then develop explainability techniques to explain it. Based on these two options, XAI methods can be divided into ex ante explanation and ex post explanation. Ex ante explanation focuses on designing an explainable AI model, while ex post explanation focuses on fitting a simple model to the AI model to be explained, thereby evaluating the importance of the features of the input samples to the AI model to be explained.
[0068] The above introduces the application of AI models in communication systems. However, AI models may be attacked and their performance may be degraded. In the inference stage, attackers can circumvent the detection of the model by changing the characteristics of the input samples. Such samples are called adversarial samples. The AI model may output incorrect results and degrade its performance due to the output of adversarial samples. In the application scenario where the AI model is applied to a communication network, if the adversarial samples cannot be identified, the output results of the AI model after the adversarial samples are input are used to adjust the network strategy, which may deteriorate the network performance. Based on this problem, the present application provides a communication method, device and system that can identify adversarial samples in the inference stage, thereby avoiding attacks on the AI model by adversarial samples.
[0069] The following is an introduction to the specific implementation of the communication method provided in the embodiment of the present application. In the description of the embodiment of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; "and / or" in the embodiment of the present application is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0070] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0071] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.
[0072] In an embodiment of the present application, "pre-definition", "pre-definition", "pre-configuration" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device. For example, it can be burned into the device when the device leaves the factory, or configured when accessing the network for the first time. The embodiment of the present application does not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, which is not limited by the embodiment of the present application.
[0073] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0074] In the embodiment of the present application, "sending information to... (taking the second network element as an example)" can be understood as the destination end of the information being the second network element. This can include sending information to the second network element directly or indirectly. "Receiving information from... (taking the first network element as an example)" can be understood as the source end of the information being the first network element, which can include receiving information from the first network element directly or indirectly. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in the embodiments of the present application can be understood similarly and will not be repeated here.
[0075] The technical solutions provided in this application can be used in various communication systems, for example, long term evolution (LTE) systems, fourth generation (4G) mobile communication systems, fifth generation (5G) mobile communication systems and their evolution systems, non-terrestrial networks (NTN) systems, vehicle to everything (V2X) systems, LTE and NR hybrid networking systems, or device-to-device (D2D) systems, machine to machine (M2M) communication systems, Internet of Things (IoT), and future next generation communication systems, such as sixth generation (6G) mobile communication systems. In addition, the term "system" and "network" can be used interchangeably.
[0076] It should be noted that the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0077] It should be noted that the names of the network elements appearing in this document are only possible exemplary names. If the names actually used by the network elements in subsequent communication networks (such as 6G networks) are different from the names appearing in this document, it does not affect the application of the communication method provided in the embodiments of this application.
[0078] Figure 2 is a schematic diagram of the architecture of a possible, non-limiting communication system applicable to an embodiment of the present application. As shown in Figure 2, the communication system 10 includes a RAN 100 and a core network (CN) 200. The RAN 100 includes at least one RAN node (such as 110a and 110b in Figure 2, collectively referred to as 110) and at least one terminal device (such as 120a-120j in Figure 2, collectively referred to as 120). The RAN 100 may also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in Figure 2). The terminal device 120 is connected to the RAN node 110 via a wireless connection. The RAN node 110 is connected to the core network 200 via a wireless or wired connection. The core network devices in the core network 200 and the RAN node 110 in the RAN 100 can be different physical devices, or they can be the same physical device that integrates the core network logical functions and the radio access network logical functions.
[0079] Optionally, as shown in FIG. 2 , the communication system 10 may further include the Internet 300 .
[0080] All or part of the functions of the network elements (such as the RAN node 110, core network elements, etc.) in the embodiments of the present application may also be implemented through software functions running on hardware, or through virtualization functions instantiated on a platform (such as a cloud platform). The network elements in the embodiments of the present application may also be logical nodes, logical modules, or software that can implement all or part of the network element functions.
[0081] The RAN 100 may be a 3GPP-related cellular system, such as a 4G or 5G mobile communication system, or a future-oriented evolutionary system (such as a 6G mobile communication system). The RAN 100 may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The RAN 100 may also be a communication system that integrates two or more of the above systems.
[0082] RAN node 110, sometimes also referred to as access network equipment, RAN entity, or access node, constitutes part of the communication system and facilitates wireless access for terminal devices. Multiple RAN nodes 110 in the communication system 10 can be of the same type or different types. In some scenarios, the roles of RAN node 110 and terminal device 120 are relative. For example, network element 120i in Figure 2 can be a helicopter or drone, which can be configured as a mobile base station. For terminal device 120j accessing the RAN 100 via network element 120i, network element 120i is a base station; however, for base station 110a, network element 120i is a terminal device. RAN node 110 and terminal device 120 are sometimes referred to as communication devices. For example, network elements 110a and 110b in Figure 2 can be understood as communication devices with base station functionality, and network elements 120a-120j can be understood as communication devices with terminal functionality.
[0083] In one possible scenario, a RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation nodeB (gNB), a next-generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. A RAN node may be a macro base station (such as 110a in Figure 2 ), a micro base station or an indoor station (such as 110b in Figure 2 ), a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, a RAN node may also be a server, a wearable device, a vehicle, or an onboard device. For example, the access network device in V2X technology may be a road side unit (RSU).
[0084] All or part of the functions of the RAN node in the embodiments of the present application may also be implemented through software functions running on hardware, or through virtualized functions instantiated on a platform (e.g., a cloud platform). The RAN node in the embodiments of the present application may also be a logical node, logical module, or software that can implement all or part of the functions of the RAN node.
[0085] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0086] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, the embodiments of the present application are described by taking CU, CU-CP, CU-UP, DU and RU as examples. Any of the CU (or CU-CP, CU-UP), DU and RU in the embodiments of the present application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0087] Terminal devices may also be referred to as terminals, user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be widely used in various scenarios, such as D2D, V2X communication, machine-type communication (MTC), Internet of Things, virtual reality (VR), augmented reality (AR), industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation or smart city, etc. Terminal devices can be mobile phones, tablet computers, computers with wireless transceiver functions, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of the present application do not limit the device form of the terminal device.
[0088] Optionally, the core network 200 may include an operation administration and maintenance (OAM) network element, an access and mobility management function (AMF), or other network elements. The OAM network element is primarily responsible for performing routine network and service analysis, forecasting, planning, and configuration, as well as daily operational activities such as network and service testing and fault management. The AMF network element is responsible for terminal device identity verification, authorization, registration, mobility management, and connection management.
[0089] In an embodiment of the present application, the communication system 10 may include an AI module. The AI module is a module with machine learning computing capabilities. In a wireless communication system, the AI module may be located on the core network side, such as in an OAM network element, on the RAN side, such as in a gNB or CU, in a terminal device, or as a separate network element entity. For example, if the AI module is a separate network element entity, the entity may be called an artificial intelligence controller (AIC) (other names are possible and are not limited in this embodiment). Optionally, in the wireless communication system, the AI module may perform a series of AI calculations, such as model building, training approximation, and reinforcement learning, based on input data (optionally, network operation data provided by the RAN or monitored by core network elements, such as network load and channel quality). The trained model provided by the AI module has the ability to predict network changes, such as load prediction and quality of service (QoS) prediction. Furthermore, the AI module can perform policy inference on the network prediction results based on the trained model to obtain a reasonable network policy. For example, the AI module can perform policy reasoning from the perspectives of network energy saving or mobility optimization based on the prediction results output by the model to obtain energy-saving strategies or mobility optimization strategies.
[0090] In one possible scenario, the communication system 10 may include the architecture shown in Figure 1. For example, the AI module may include the model training management module or the model inference management module in Figure 1.
[0091] In one possible scenario, when the AI module is located in a core network element (e.g., an OAM element), it can reuse the current northbound interface for communication with RAN nodes. When the AI module is located in a RAN node (e.g., a gNB or CU), it can reuse the current F1, Xn, and Uu interfaces for communication with RAN nodes, terminal devices, or core network elements. When the AI module is an independent network entity, it can establish communication links with core network elements, RAN nodes, or terminal devices, such as wired or wireless links.
[0092] The communication method provided in the embodiment of the present application is described below in conjunction with the architecture shown in FIG1 and the communication system shown in FIG2 .
[0093] It should be noted that in the following embodiments of the present application, the names of the various network elements, the names of the messages exchanged between the various network elements, the names of the various parameters, or the names of the various information are only examples. In other embodiments, they may also be other names, and the method provided in this application does not make specific limitations on this.
[0094] It is understood that in the embodiments of the present application, each network element or entity may perform some or all of the steps in the embodiments of the present application. These steps or operations are merely examples, and the embodiments of the present application may also perform other operations or variations of various operations. In addition, the steps may be performed in a different order than those presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.
[0095] Referring to FIG3 , the communication method provided in the embodiment of the present application includes steps S301 to S303:
[0096] S301: A first network element obtains an adversarial sample and trains a first model based on the adversarial sample. The first model is used to detect whether the inference data of the AI model is an adversarial sample.
[0097] Regarding obtaining adversarial samples, the embodiments of the present application do not limit the specific implementation method. The following introduces possible implementations provided by the embodiments of the present application.
[0098] In one possible implementation, the first network element can generate adversarial samples based on the acquired training data. In one possible way of this implementation, the first network element can apply an attack algorithm (such as the fast gradient sign method, distributed adversarial attack, deep fool, Jacobi-based saliency map attack, etc.) to add perturbations to normal training data, that is, modify the numerical values corresponding to one or more features of the training data, and input the perturbed training data into the AI model. If the output result of the AI model does not meet expectations, the perturbed training data can be considered to be an adversarial sample. Furthermore, the first network element can collect adversarial samples to form an adversarial sample set.
[0099] The AI model's output may not match expectations, which could mean that the sample labels of the output do not match those of the normal training data. Alternatively, the output value may be outside the expected range. Based on the different types of AI model outputs, there are many different ways to determine whether the AI model's output matches expectations, which are not limited in the present embodiments.
[0100] For example, if the output of an AI model is a prediction of base station load, the normal output should be less than a threshold. If the output of the AI model exceeds the threshold after inputting data, it can be considered an adversarial example.
[0101] If the sample label of normal training data is QoS, and after the perturbed training data is input into the AI model, the sample label of the output result of the AI model is load, which is different from QoS, then the perturbed training data can be considered an adversarial sample.
[0102] Optionally, in this implementation, the first network element may obtain training data from other network elements or terminal devices. This embodiment of the present application does not limit the specific network element or elements from which the first network element obtains training data. In one possible scenario, the first network element may obtain training data from a second network element. The second network element is described in detail below and is not further elaborated here.
[0103] Optionally, in this implementation, the training data acquired by the first network element may be network-related data or information. For example, a RAN node (such as a base station within the management scope of the first network element) may send RAN-side data or information for training to the first network element. These RAN-side data or information used for training may be reported by the terminal device to the RAN node (for example, the terminal device reports the measurement results obtained based on the measurement configuration to the RAN node), local to the RAN node, or derived by the RAN node based on data or information from the terminal device or other RAN nodes. For example, the RAN-side data or information used for training may include the resource status of the RAN node, the energy consumption status of the RAN node, the traffic information of the terminal device, the reference signal received power (RSRP), reference signal received quality (RSRQ), or signal interference noise ratio (SINR) of the serving cell and / or neighboring cells measured by the terminal device, etc. For another example, the core network element may send network-related data or information acquired by the core network element to the first network element, such as QoS information of the terminal device.
[0104] In another possible implementation, the first network element may obtain adversarial samples from other network elements or terminal devices. For example, the first network element may receive adversarial samples from a core network element. For another example, the first network element may receive adversarial samples from a third party.
[0105] In an embodiment of the present application, adversarial examples can be used to train a first model. The trained first model can detect whether the inference data input to the AI model is an adversarial example. That is, the output of the first model can indicate whether the inference data input to the AI model is an adversarial example.
[0106] For example, the output result of the first model can be 0 or 1. 0 represents that the inference data of the AI model is not an adversarial sample (it can also represent normal inference data), and 1 represents that the inference data of the AI model is an adversarial sample.
[0107] Regarding training the first model based on adversarial samples, the embodiments of the present application do not limit the specific implementation method. The following describes possible implementations provided by the embodiments of the present application.
[0108] In one possible implementation, the first network element may input an adversarial example into an AI model and train the first model based on the output of the AI model. For example, if an adversarial example is input into the AI model, the first network element may input the output of the AI model into the first model to obtain the output of the first model. If the output of the first model indicates an adversarial example, then the first model has correctly detected the adversarial example.
[0109] Optionally, the first network element may combine normal training data and adversarial samples to perform supervised training on the first model.
[0110] Exemplarily, the first network element may set sample labels for normal training data and adversarial samples respectively. The sample label may indicate whether the data is normal training data or an adversarial sample. For example, a sample label value of 0 indicates normal training data, and a sample label value of 1 indicates an adversarial sample. The first network element inputs normal training data or adversarial samples into the AI model, obtains the output result of the AI model, and then inputs the output result of the AI model into the first model. After obtaining the output result of the first model, the output result of the first model may be compared with the sample label of the data input into the AI model to determine whether the first model has detected correctly. For example, if the output result of the first model indicates an adversarial sample, and the sample label of the data input into the AI model also indicates an adversarial sample, then the first model has detected correctly. If the output result of the first model indicates normal training data, and the sample label of the data input into the AI model also indicates normal training data, then the first model has detected correctly.
[0111] In another possible implementation, the first network element can generate an XAI signature sample based on the adversarial sample and train the first model based on the XAI signature sample. For example, if the adversarial sample is input into the AI model, the first network element can generate an XAI signature sample based on the output of the AI model and input the XAI signature sample into the first model to obtain the output of the first model. If the output of the first model indicates an adversarial sample, then the first model has correctly detected the adversarial sample.
[0112] The XAI feature sample may include a value representing the feature importance of the adversarial sample. For example, the XAI feature sample may include a Shapley additive explanation (SHAP) value. Alternatively, the XAI feature sample may include a value representing the unit importance of the AI model. For example, assuming that the AI model is a neural network model, the XAI feature sample may include the SHAP value of the neuron of the hidden layer of the neural network, where the hidden layer is, for example, the penultimate layer of the neural network, i.e., the hidden layer adjacent to the output layer.
[0113] Optionally, the first network element may further generate XAI feature samples based on normal training data, and may combine these with XAI feature samples generated based on adversarial samples to perform supervised training on the first model. The XAI feature samples generated based on normal training data may include values representing feature importance of the normal training data, or values representing unit importance of the AI model. For details, please refer to the above introduction to XAI feature samples, which will not be elaborated here.
[0114] Exemplarily, the first network element may set sample labels for normal training data and adversarial samples respectively. The first network element inputs the normal training data or adversarial samples into an AI model, obtains the output of the AI model, and then generates an XAI feature sample based on the output of the AI model. After inputting the XAI feature sample into the first model and obtaining the output of the first model, the first network element may compare the output of the first model with the sample labels of the data input to the AI model to determine whether the first model has correctly detected the data.
[0115] Optionally, the XAI feature sample may be generated by the second model. The first network element may input the adversarial sample or normal training data into the AI model, and input the output result of the AI model into the second model to obtain the XAI feature sample output by the second model.
[0116] Among them, the second model can be used to explain the AI model, and can also be called the XAI model.
[0117] The embodiments of the present application do not limit the specific manner in which the first network element obtains the second model. For example, the first network element may train the second model. Alternatively, the first network element may obtain the second model from another network element. Alternatively, the second model may be pre-set in the first network element (for example, the operator or a third party deploys the second model in the first network element).
[0118] Optionally, the first network element may send the second model to the second network element.
[0119] In addition, the AI model used by the first network element when training the first model may be trained by the first network element. The first network element may train the AI model based on the acquired training data. Alternatively, the AI model may be acquired by the first network element from other network elements, such as core network elements, third-party network elements, or other network elements.
[0120] Exemplarily, the third-party network element may be a server of a manufacturer that provides over-the-top (OTT) services provided by an operator.
[0121] S302: The first network element sends a first model to the second network element. Correspondingly, the second network element receives the first model.
[0122] In one possible implementation, the first network element may send the first model to the second network element when the first model meets certain conditions. For example, the first network element may send the first model to the second network element when the detection precision or detection accuracy of the first model reaches a threshold (e.g., 99%).
[0123] S303. If the second network element needs to input the inference data into the AI model for inference, the second network element can detect whether the inference data is an adversarial sample based on the first model.
[0124] Based on the communication method provided in the embodiments of the present application, a model for detecting adversarial samples can be introduced into the AI application scenarios of the communication network, so that adversarial samples input into the AI model can be identified during the inference phase, thereby avoiding performance degradation of the AI model and ensuring network performance.
[0125] Optionally, the inference data acquired by the second network element may be network-related data or information. For example, the terminal device may send measurement results of certain parameters, such as the terminal device's traffic information, QoS parameters, energy consumption status, etc., to the second network element as inference data. For another example, a RAN node (such as a base station adjacent to the second network element) may send RAN-side data or information to the second network element as inference data. This RAN-side data or information used for inference may be local to the RAN node, or may be derived by the RAN node based on data or information from the terminal device or other RAN nodes. For example, the RAN-side data or information used for inference may include historical information about the terminal device (such as the location, QoS parameters, or performance information of a historically switched terminal device), the resource status of the RAN node, or the energy consumption status of the RAN node. For another example, the core network element may send network-related data or information acquired by the core network element, such as the terminal device's QoS information, to the second network element.
[0126] For detecting whether the inference data of the AI model is an adversarial sample, the second network element can determine whether the inference data is an adversarial sample based on the output result of the AI model obtained after inputting the inference data into the AI model and the first model. The following describes possible implementations provided by this application.
[0127] In one possible implementation, the second network element can input the output of the AI model into the first model and, based on the output of the first model, determine whether the inference data is an adversarial sample. For details on this implementation, please refer to the above description of training the first model in S301 and will not be elaborated here.
[0128] In another possible implementation, the second network element may obtain an XAI feature sample based on the output of the AI model. The second network element then inputs the XAI feature sample into the first model and, based on the output of the first model, determines whether the inference data is an adversarial sample. The XAI feature sample may include a value representing the feature importance of the inference data or a value representing the unit importance of the AI model. Optionally, in this implementation, the second network element may receive a second model from the first network element and generate an XAI feature sample based on the second model. For details of this implementation, please refer to the above description of training the first model in S301 and will not be elaborated here.
[0129] Optionally, the AI model used by the second network element may be the one sent by the first network element to the second network element. In this case, the AI model sent by the first network element to the second network element is the AI model used by the first network element when training the first model. Alternatively, the second network element may obtain the AI model from another network element. Alternatively, the AI model may be pre-configured in the second network element.
[0130] The embodiments of the present application do not restrict the timing of the first network element sending the first model to the second network element and the second network element obtaining the AI model. For example, assuming that the AI model is sent from the first network element to the second network element, the first network element may first send the AI model to the second network element via one or more messages, and then send the first model and the AI model to the second network element.
[0131] In one possible scenario, in order to enable the second network element to know that the first model can be used to detect the inference data of the AI model, the AI model can be associated with the first model.
[0132] Exemplarily, the first network element may send the first model and the AI model together to the second network element, so that the first model and the AI model may be naturally associated.
[0133] For example, assuming that the AI model acquired by the second network element can be identified by identification information, such as a model identification number (model ID). When the first network element sends the first model to the second network element, the identification information of the AI model can be sent to the second network element together with the first model. The second network element can then associate the first model with the AI model based on the identification information of the AI model.
[0134] Optionally, if the first network element also sends the second model to the second network element, the embodiments of the present application do not restrict the timing between the first network element sending the second model to the second network element, the first network element sending the first model to the second network element, and the second network element obtaining the AI model. For example, the first network element may send the first model, the second model, and the AI model to the second network element simultaneously. For another example, the first network element may first send the AI model to the second network element, and then send the first model and the second model.
[0135] Optionally, if the first network element also sends a second model to the second network element, the second model can be associated with the AI model. For example, the AI model obtained by the second network element can be identified by identification information. When the first network element sends the second model to the second network element, it can send the identification information of the AI model along with the second model to the second network element. The second network element can then associate the second model with the AI model based on the identification information of the AI model. For another example, the first network element can simultaneously send the AI model and the second model to the second network element, so that the second model and the AI model can be naturally associated.
[0136] The above describes how the second network element determines whether the AI model's inference data is an adversarial example based on the first model. The following describes possible scenarios after the second network element determines whether the AI model's inference data is an adversarial example based on the first model.
[0137] In one possible scenario, if the second network element determines that the inference data of the AI model is an adversarial sample, the second network element may ignore the output result of the AI model, that is, the second network element will not perform subsequent actions based on the output result. If the second network element determines that the inference data of the AI model is not an adversarial sample, but normal inference data, the second network element may further perform subsequent actions based on the output result of the AI model. Optionally, the subsequent action may be at least one of: sending the output result of the AI model to the network element responsible for unified planning of network policies, adjusting relevant network policies, or sending relevant network policies to corresponding network elements.
[0138] For example, assuming the output of the AI model is a prediction of the load of the second network element, the second network element can decide whether to perform resource management actions based on the AI output, based on whether the inference data input into the AI model is an adversarial sample. For example, if the second network element determines that the load prediction value output by the AI model is higher than the threshold used to determine whether load balancing is appropriate, and the inference data input into the AI model is not an adversarial sample, the second network element may switch some terminal devices to adjacent RAN nodes.
[0139] For another example, assuming that the output result of the AI model is a prediction of the QoS of the terminal device, the second network element can decide whether to perform actions such as mobility management of the terminal device based on the output result of the AI, based on whether the inference data of the AI model is an adversarial sample.
[0140] Based on this solution, if the inference data of the AI model is identified as an adversarial sample, the network element using the AI model can refuse to adopt or execute the corresponding inference results, avoiding deterioration of network system performance.
[0141] In one possible scenario, the second network element may send the detected adversarial sample to the first network element if the first condition is met.
[0142] Optionally, the first condition may be: detecting an adversarial sample. That is, as long as the second network element detects the adversarial sample, it sends the detected adversarial sample to the first network element.
[0143] Alternatively, the second network element may maintain a corresponding counter for a device that provides inference data (such as a RAN node, a core network element, or a terminal device). When the second network element detects for the first time that the inference data from a certain device is an adversarial sample, the initial value of the counter corresponding to the device is added or subtracted by a preset value (for example, it may be added by 1), and each time the inference data from the device is detected to be an adversarial sample, the current value of the counter corresponding to the device is added or subtracted by a preset value (for example, it may be added by 1). In this case, the first condition may be that the counter corresponding to the device reaches a threshold. That is, if the counter corresponding to a certain device reaches a threshold, the second network element sends the adversarial sample from the device to the first network element.
[0144] For example, assume that a counter maintained by a second network element for a terminal device is called a first counter. The initial value of the first counter is 0, and the threshold value is 5. Each time the second network element detects that the inference data from the terminal device is an adversarial example, the first counter is incremented by 1. When the second network element detects that the inference data from the terminal device is an adversarial example five times, the value of the first counter reaches the threshold value of 5, and the second network element sends these five detected adversarial examples to the first network element.
[0145] Optionally, the threshold of the counter may be preset, or may be configured by the first network element or another network element. For example, the first network element may send a first parameter to the second network element, where the first parameter is used to indicate the threshold of the counter.
[0146] Alternatively, the first condition may be: the value of one or more network-related indicators is higher or lower than a corresponding threshold. In the first condition, the value of the network-related indicator may be measured, such as measured by the second network element, or the value of the measured indicator sent by a terminal device or other network element to the second network element. Alternatively, in the first condition, the value of the network-related indicator may be a prediction result output by an AI model.
[0147] Exemplarily, the first condition may be: the load of the network is higher than a corresponding threshold, the throughput of the network is lower than a corresponding threshold, or the energy consumption of the network is higher than a corresponding threshold, etc.
[0148] Optionally, when the second network element sends the adversarial sample to the first network element, it may also send identification information of the AI model. After receiving the identification information of the AI model and the adversarial sample, the first network element may determine the first model associated with the AI model based on the identification information of the AI model, thereby determining that the adversarial sample was detected by the first model.
[0149] Optionally, if the first network element receives an adversarial sample detected by the second network element, the first network element may retrain the first model based on the received adversarial sample.
[0150] In one possible scenario, if the first condition is met and the detected adversarial sample originates from a terminal device, the second network element may release the connection with the terminal device. For example, assuming the second network element is a RAN node, if the second network element detects that the inference data from a terminal device is an adversarial sample, the second network element may release the radio resource control (RRC) connection with the terminal device.
[0151] In one possible scenario, if the first condition is met and the adversarial sample detected is from a terminal device, the second network element may send the terminal device information to the third network element. In this scenario, when the second network element sends the terminal device information to the third network element, it may indicate that the terminal device is the terminal device that sent the adversarial sample.
[0152] The third network element and the first network element may be different network elements or the same network element. For example, the first network element may be an OAM network element, and the third network element may be an AMF network element. Alternatively, the first network element and the third network element may be the same AMF network element.
[0153] Exemplarily, the information of the terminal device may be identification information of the terminal device, such as a globally unique temporary identifier (GUTI), a subscription permanent identifier (SUPI), or a unique identifier of the terminal device on the Xn interface within the next generation RAN node (NG-RAN node) (NG-RAN node UE XnAP ID).
[0154] Optionally, if the third network element receives information about the terminal device from the second network element, the third network element may deregister the terminal device. For example, assuming that the third network element is an AMF network element, the third network element may delete the registration information of the terminal device (e.g., delete the authorization information of the terminal device) to deregister the terminal device.
[0155] Optionally, if the third network element receives information about the terminal device from the second network element, the third network element may reject the connection request of the terminal device. For example, assuming that the third network element is a RAN node, the third network element may reject the request of the terminal device when the terminal device requests to access the serving cell.
[0156] It is understandable that in the above embodiment, if the first condition is met, there is no dependency between the different steps that the second network element can execute, and the second network element can execute one or more of the above steps. That is, if the first condition is met, the second network element can execute at least one of the following: sending the detected adversarial sample to the first network element, releasing the connection with the terminal device, or sending information about the terminal device to the third network element. Moreover, if the second network element executes multiple steps above, the embodiment of the present application does not limit the timing between different steps. The second network element can execute different steps sequentially or simultaneously.
[0157] In a possible scenario, the first network element may also update the first model and / or the second model through the corresponding solution in the above embodiment, and send the updated first model and / or the second model to the second network element.
[0158] Optionally, the network element in the above embodiments, such as the first network element, the second network element or the third network element, may be a core network element or a RAN node, and the embodiments of the present application do not limit this.
[0159] In one possible scenario, the first network element, the second network element, or the third network element may include the AI module introduced above.
[0160] In one possible scenario, the first network element may include the model training management module described above. The second network element may include the model reasoning management module described above. Optionally, the second network element may also include the actor module described above.
[0161] The following describes a possible exemplary process of an embodiment of the present application, taking the first network element as an OAM network element and the second network element as a RAN node as an example. As shown in Figure 4, the exemplary process includes the following steps:
[0162] S401: The RAN node sends a measurement configuration to the UE, instructing the UE to perform a measurement process and report a measurement result. Correspondingly, the UE receives the measurement configuration.
[0163] S402: The UE obtains measurement results according to the measurement configuration and reports the measurement results to the RAN node. Correspondingly, the RAN node receives the measurement results.
[0164] Exemplarily, the UE may measure the frequency points and beams indicated in the measurement configuration, and the obtained measurement results may include RSRP, RSRQ, SINR, etc. of the serving cell and / or neighboring cells.
[0165] S403: The RAN node sends the measurement result reported by the UE together with other data used for training as training data to the OAM network element. Correspondingly, the OAM network element receives the training data.
[0166] Among them, other data used for training can be local information of the RAN node, or information derived by the RAN node based on information from the UE or adjacent RAN nodes, such as the resource status of the RAN node, the energy consumption status of the gNB, or the traffic information of the UE.
[0167] S404: The OAM network element trains an AI model based on the training data reported by the RAN node. The AI model can be used for one or more tasks, or it can be understood that the AI model can be used to implement one or more functions. For example, the AI model can be used to predict RAN node load information, predict UE QoS information, etc.
[0168] S405. The OAM network element obtains an adversarial sample.
[0169] Optionally, the OAM network element may generate adversarial samples based on normal training data reported by the RAN node. Alternatively, the OAM network element may obtain adversarial samples from other network element nodes, which is not limited in this application.
[0170] S406. The OAM network element trains a first model based on the training data and the adversarial sample.
[0171] Among them, in one possible implementation method, OAM can label normal training data and adversarial samples respectively, generate XAI feature samples through the second model, and perform supervised training on the first model based on the XAI feature samples and sample labels.
[0172] For details of S405-S406, please refer to the above introduction to S301, which will not be elaborated here.
[0173] S407: The OAM network element sends the AI model and the first model to the RAN node. Correspondingly, the RAN node receives the AI model and the first model. The AI model and the first model sent by the OAM network element may be those obtained through initial training or updated AI models and the first model.
[0174] In one possible implementation, the OAM network element may first send the AI model via one or more messages, and then send the first model, with the first model and the AI model's model ID being sent together. After receiving the AI model and the first model, the RAN node may associate the first model with the AI model based on the model ID.
[0175] Optionally, corresponding to the possible implementation of generating an XAI feature sample using the second model in S406, the OAM network element may further send the second model to the RAN node in S407. The OAM network element may send the second model together with the AI model, or may send the AI model first and then send the second model and model ID.
[0176] S408: The UE reports data used for inference, such as measurement results, to the RAN node. For details, refer to S402.
[0177] Optionally, the RAN node may also receive data for inference from an adjacent RAN node. For example, the adjacent RAN node may send information such as UE history information, resource status of the adjacent RAN node, and energy efficiency of the adjacent RAN node to the RAN node. Accordingly, the RAN node receives the inference data.
[0178] S409: The RAN node inputs the inference data into the AI model, performs model inference, and outputs a result or decision. Furthermore, the RAN node determines whether the inference data is an adversarial example based on the inference data, the output of the AI model, and the first model. If the inference data is determined to be an adversarial example, the RAN node ignores the output.
[0179] Among them, optionally, corresponding to the possible implementation method of training based on XAI feature samples in the above S406, the RAN node can generate XAI feature samples through the second model, and input the XAI feature samples into the first model, and judge whether the inference data input to the AI model is an adversarial sample based on the output result of the first model.
[0180] Optionally, the exemplary process may further include S410: the RAN node maintains a counter with an initial value of 0 for each UE. If the inference data from the UE is detected as an adversarial sample, the value of the counter corresponding to the UE is incremented by 1. The maximum value of the counter can also be understood as the maximum number of times the RAN node has detected an adversarial sample.
[0181] The maximum value of the counter may be preset or configured by the OAM network element / AMF network element.
[0182] Optionally, the exemplary process may further include S411: if the RAN node detects that the inference data from the UE is an adversarial sample, releasing the connection with the UE.
[0183] Optionally, S411 may be triggered when the value of the counter corresponding to the UE reaches a maximum value.
[0184] Optionally, the exemplary process may further include S412: if the RAN node detects that the inference data from the UE is an adversarial sample, sending the adversarial sample to the OAM network element. Correspondingly, the OAM network element receives the adversarial sample.
[0185] Optionally, the OAM network element may retrain the first model based on the received adversarial samples.
[0186] Optionally, S412 may be triggered when the value of the counter corresponding to the UE reaches a maximum value.
[0187] Optionally, the exemplary process may further include S413 (not shown in FIG4 ): if the RAN node detects that the inference data from the UE is an adversarial sample, it sends information about the UE to the AMF network element. Correspondingly, after receiving the information about the UE, the AMF network element deregisters the UE.
[0188] Optionally, S413 may be triggered when the value of the counter corresponding to the UE reaches a maximum value.
[0189] Optionally, the exemplary process may further include S414 (not shown in FIG. 4 ): if the RAN node detects that the inference data from the UE is an adversarial example, it may transmit information about the UE to a neighboring RAN node. Correspondingly, after receiving the information about the UE, if the neighboring RAN node subsequently requests to establish a connection with the UE, the neighboring RAN node may reject the request.
[0190] Optionally, S414 may be triggered when the value of the counter corresponding to the UE reaches a maximum value.
[0191] For details of S407-S414, please refer to the above introduction to S302-S303, which will not be elaborated here.
[0192] In addition, the above embodiment uses the interaction between a first network element and a second network element as an example to introduce the communication method provided by the embodiment of the present application. In one possible scenario, the communication method provided by the embodiment of the present application can be applied not only to network elements, but also to terminal devices. For example, the second network element in the above embodiment can also be replaced by a terminal device, and the communication method executed by the second network element can also be adaptively executed by the terminal device.
[0193] The above mainly introduces the solutions provided by the embodiments of the present application from the perspective of interaction between various network elements. Accordingly, the embodiments of the present application also provide a communication device, which is used to implement the various methods described above. The communication device can be each network element in the above method embodiments, or a device that includes each of the above network elements, or a component that can be used for each of the above network elements. It is understood that in order to implement the above functions, the communication device includes hardware structures and / or software modules corresponding to performing each function. Those skilled in the art should readily appreciate that, in combination with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or in a hardware-driven manner by computer software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0194] In the embodiment of the present application, the communication device can be divided into functional modules according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be understood that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.
[0195] Figure 5 shows a schematic diagram of the structure of a communication device 500. The communication device 500 includes a processing module 501 and a transceiver module 502. Optionally, the communication device 500 may also include a storage module 503. The transceiver module 502, also known as a transceiver unit, is used to implement transceiver functions and may be, for example, a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0196] Taking the communication device 500 as the first network element in the above embodiment as an example, in a possible implementation manner:
[0197] The processing module 501 is configured to obtain adversarial samples and train a first model based on the adversarial samples. The transceiver module 502 is configured to send the first model to the second network element. The first model is configured to detect whether the inference data of the AI model is an adversarial sample.
[0198] Optionally, the processing module 501 is further configured to obtain training data and generate adversarial samples based on the training data.
[0199] Optionally, the processing module 501 trains the first model based on the adversarial sample, including: generating an XAI feature sample based on the adversarial sample, and training the first model based on the XAI feature sample. The XAI feature sample includes a value representing the feature importance of the adversarial sample; or the XAI feature sample includes a value representing the unit importance of the AI model.
[0200] Optionally, the transceiver module 502 is further configured to send a second model to the second network element, wherein the XAI feature sample is generated by the second model, and the second model is used to interpret the AI model.
[0201] Optionally, the transceiver module 502 is further configured to send an AI model to the second network element, where the AI model is associated with the first model.
[0202] Optionally, the transceiver module 502 is further configured to receive an adversarial sample detected by the second network element.
[0203] Optionally, the transceiver module 502 is further configured to receive identification information of an AI model from a second network element, wherein the AI model is associated with the first model.
[0204] Optionally, the processing module 501 is further configured to retrain the first model according to the adversarial samples detected by the second network element.
[0205] Optionally, the transceiver module 502 is further used to send a first parameter to the second network element, where the first parameter is used to indicate a threshold of a first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
[0206] Optionally, the transceiver module 502 is further configured to receive information of the terminal device from the second network element. The processing module 501 is further configured to deregister the terminal device according to the information of the terminal device.
[0207] Taking the communication device 500 as the second network element in the above embodiment as an example, in a possible implementation manner:
[0208] The transceiver module 502 is configured to obtain the first model and inference data. The processing module 501 is configured to detect whether the inference data input into the AI model is an adversarial sample based on the first model.
[0209] Optionally, the processing module 501 detects whether the inference data input into the AI model is an adversarial sample based on the first model, including: inputting the output result of the AI model into the first model, and detecting whether the inference data is an adversarial sample based on the output result of the first model.
[0210] Optionally, processing module 501 detects whether inference data input to the AI model is an adversarial example based on the first model, including: obtaining an XAI feature sample based on the output of the AI model. Inputting the XAI feature sample into the first model, and detecting whether the inference data is an adversarial example based on the output of the first model. The XAI feature sample includes a value representing feature importance of the inference data; alternatively, the XAI feature sample includes a value representing unit importance of the AI model.
[0211] Optionally, the transceiver module 502 is further configured to obtain a second model, wherein the second model is used to generate an XAI feature sample.
[0212] Optionally, if the first condition is met, the processing module 501 or the transceiver module 502 is also used to perform at least one of the following: releasing the connection with the terminal device, sending the detected adversarial sample to the first network element, or sending information of the terminal device to the third network element.
[0213] Optionally, the first condition is: the inference data from the terminal device is detected to be an adversarial sample; or, the first condition is: the first counter corresponding to the terminal device reaches a threshold; wherein, each time the inference data from the terminal device is detected to be an adversarial sample, the current value of the first counter is increased by one.
[0214] Optionally, the threshold is preset. Alternatively, the threshold is configured by the first network element.
[0215] Optionally, the transceiver module 502 is further configured to obtain an AI model, wherein the AI model is associated with the first model.
[0216] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0217] Alternatively, the modules in FIG5 may also be referred to as units. For example, the processing module may be referred to as a processing unit, and the transceiver module may be referred to as a transceiver unit. In addition, in the embodiment shown in FIG5 , the names of the units may not be those shown in the figure. For example, the transceiver module may also be referred to as a communication module or a communication unit.
[0218] If the various units in Figure 5 are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The storage medium for storing computer software products includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0219] In the embodiment of the present application, the communication device 500 is presented in the form of various functional modules divided in an integrated manner. The "module" here can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0220] In a simple embodiment, those skilled in the art may appreciate that the communication device 500 may take the form of the communication device shown in FIG. 6 .
[0221] As shown in Figure 6, the communication device 600 includes one or more processors 601, a communication line 602, and at least one communication interface (Figure 6 is only an example of including a communication interface 604 and a processor 601 for illustration), and may optionally also include a memory 603.
[0222] The processor 601 may be a general-purpose central processing unit (CPU), a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application.
[0223] The communication line 602 may include a path for connecting different components.
[0224] The communication interface 604 may be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, terminals, and wireless local area networks (WLANs). For example, the transceiver module may be a device such as a transceiver or a transceiver. Alternatively, the communication interface 604 may be a transceiver circuit or input / output interface within the processor 601, for implementing signal input and output to the processor.
[0225] The memory 603 may be a device having a storage function. For example, it may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may be independent and connected to the processor via a communication line 602. The memory may also be integrated with the processor.
[0226] The memory 603 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 601. The processor 601 is used to execute the computer-executable instructions stored in the memory 603, thereby implementing the communication method provided in the embodiment of the present application.
[0227] Alternatively, optionally, in an embodiment of the present application, the processor 601 may also perform processing-related functions in the communication method provided in the following embodiments of the present application, and the communication interface 604 is responsible for communicating with other devices or communication networks, which is not specifically limited in the embodiments of the present application.
[0228] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.
[0229] In a specific implementation, as an embodiment, the processor 601 may include one or more CPUs, such as CPU0 and CPU1 in FIG6 .
[0230] In a specific implementation, as an embodiment, the communication device 600 may include multiple processors, such as the processor 601 and the processor 607 in FIG6 . Each of these processors may be a single-core processor or a multi-core processor. The processors herein may include, but are not limited to, at least one of the following: a CPU, a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, and other types of computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing.
[0231] In a specific implementation, as an embodiment, the communication device 600 may further include an output device 605 and an input device 606. The output device 605 communicates with the processor 601 and can display information in a variety of ways. For example, the output device 605 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 606 communicates with the processor 601 and can receive user input in a variety of ways. For example, the input device 606 can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0232] The communication device 600 described above may sometimes also be referred to as a communication device, which may be a general-purpose device or a dedicated device. For example, the communication device 600 may be the first network element, the second network element, or a device having a similar structure as shown in FIG6 . The embodiment of the present application does not limit the type of the communication device 600.
[0233] In addition, the composition structure shown in Figure 6 does not constitute a limitation on the communication device. In addition to the components shown in Figure 6, the communication device 600 may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0234] Alternatively, the functions / implementation processes of the transceiver module 502 and the processing module 501 in FIG5 may be implemented by the processor 601 in the communication device 600 shown in FIG6 calling computer-executable instructions stored in the memory 603. Alternatively, the functions / implementation processes of the processing module 501 in FIG5 may be implemented by the processor 601 in the communication device 600 shown in FIG6 calling computer-executable instructions stored in the memory 603, and the functions / implementation processes of the transceiver module 502 in FIG5 may be implemented by the communication interface 604 in the communication device 600 shown in FIG6.
[0235] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of the two. When any of the above modules or units is implemented in software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built into an SoC or ASIC, or it can be an independent semiconductor chip. In addition to the core used to execute software instructions to perform calculations or processing within the processor, it can further include necessary hardware accelerators, such as FPGAs, programmable logic devices (PLDs), or logic circuits that implement dedicated logic operations.
[0236] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a DSP chip, an MCU, an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.
[0237] Optionally, an embodiment of the present application further provides a communication device (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the method in any of the above method embodiments. In one possible design, the communication device also includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the communication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the communication device. When the communication device is a chip system, it may be composed of a chip, or it may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.
[0238] Optionally, an embodiment of the present application also provides a computer-readable storage medium, which stores a computer program or instruction. When the computer program or instruction is run on a communication device, the communication device can execute the method described in any of the above method embodiments or any of its implementation methods.
[0239] Optionally, an embodiment of the present application further provides a communication system, which includes the network device described in the above method embodiment and the terminal device described in the above method embodiment.
[0240] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more media integrated therein. The available media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, DVDs), or semiconductor media (eg, solid state drives (SSDs)).
[0241] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0242] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the scope of the present application. Thus, the present application is intended to encompass such modifications and variations as fall within the scope of the claims of the present application and their equivalents.
Claims
1. A communication method, characterized in that: The method comprises: Obtain an adversarial sample, and train a first model based on the adversarial sample; the first model is used to detect whether the inference data of the artificial intelligence AI model is an adversarial sample; Sending the first model to the second network element.
2. The method according to claim 1, characterized in that: The method further comprises: Get training data; The adversarial sample is generated according to the training data.
3. The method according to claim 1 or 2, characterized in that: The step of training a first model according to the adversarial sample comprises: Generate an explainable artificial intelligence XAI feature sample according to the adversarial sample; the XAI feature sample includes a value representing the feature importance of the adversarial sample; or, the XAI feature sample includes a value representing the unit importance of the AI model; The first model is trained according to the XAI feature samples.
4. The method according to claim 3, characterized in that The method further comprises: A second model is sent to the second network element, the XAI feature sample is generated by the second model, and the second model is used to interpret the AI model.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: Sending the AI model to the second network element; wherein the AI model is associated with the first model.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Receive the adversarial sample detected by the second network element.
7. The method according to claim 6, characterized in that The method further comprises: Receive identification information of the AI model from the second network element; wherein the AI model is associated with the first model.
8. The method according to claim 6 or 7, characterized in that: The method further comprises: Retraining the first model according to the adversarial samples detected by the second network element.
9. The method according to any one of claims 1 to 8, characterized in that: The method further comprises: A first parameter is sent to the second network element, where the first parameter is used to indicate a threshold of a first counter, and the first counter is used to count the number of adversarial samples detected by the second network element.
10. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: receiving information from a terminal device of the second network element; Deregister the terminal device.
11. A communication method, characterized in that: The method comprises: Obtaining a first model and inference data; According to the first model, detect whether the inference data input into the artificial intelligence AI model is an adversarial sample.
12. The method according to claim 11, characterized in that The detecting, according to the first model, whether the inference data input into the artificial intelligence AI model is an adversarial sample comprises: The output result of the AI model is input into the first model, and based on the output result of the first model, it is detected whether the inference data is an adversarial sample.
13. The method according to claim 11, characterized in that The detecting, according to the first model, whether the inference data input into the artificial intelligence AI model is an adversarial sample comprises: According to the output result of the AI model, an explainable artificial intelligence XAI feature sample is obtained; wherein the XAI feature sample includes a value representing the feature importance of the reasoning data; or the XAI feature sample includes a value representing the unit importance of the AI model; The XAI feature sample is input into the first model, and based on the output result of the first model, it is detected whether the inference data is an adversarial sample.
14. The method according to claim 13, characterized in that The method further comprises: A second model is obtained, where the second model is used to generate an XAI feature sample.
15. The method according to any one of claims 11 to 14, characterized in that: The method further comprises: If the first condition is met, perform at least one of the following: Release the connection with the terminal device; Sending the detected adversarial sample to the first network element; or, Send the terminal device information to the third network element.
16. The method according to claim 15, characterized in that The first condition is: detecting that the inference data from the terminal device is an adversarial sample; or The first condition is that a first counter corresponding to the terminal device reaches a threshold; wherein each time the inference data from the terminal device is detected as an adversarial sample, the current value of the first counter is increased by one.
17. The method according to claim 16, characterized in that The threshold is preset; or, the threshold is configured by the first network element.
18. The method according to any one of claims 11 to 17, characterized in that: The method further comprises: Obtain the AI model; wherein the AI model is associated with the first model.
19. A communication device, characterized in that: The communication device comprises: a module for executing the method according to any one of claims 1-10; or the communication device comprises a module for executing the method according to any one of claims 11-18.
20. A communication device, characterized in that: The communication device comprises: a processor; the processor is used to execute a computer program or instruction stored in a memory, so that the communication device executes the method according to any one of claims 1-10 or 11-18.
21. A chip system, characterized in that: include: processor and interface circuits; The interface circuit is used to receive computer execution instructions and transmit them to the processor; The processor is configured to execute the computer-executable instructions so as to enable the communication device to perform the method according to any one of claims 1-10 or 11-18.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a computer program or an instruction. When the computer program or the instruction is executed on a computer, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 18 is executed.
23. A computer program product, characterized in that The computer program product comprises instructions, and when the instructions are executed on a computer, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 18 is executed.
24. A communication system, characterized in that: The communication system comprises a first network element and a second network element; wherein the first network element is used to execute the method according to any one of claims 1-10, and the second network element is used to execute the method according to any one of claims 11-18.
Citation Information
Patent Citations
Attack sample management method and equipment
CN115225295A
XAI model consistency training method and device, equipment and storage medium
CN116011570A
Performance based switching of a model training process
US20210241169A1
Method for an explainable autoencoder and an explainable generative adversarial network
US20220172050A1
Automated cyberattack detection using time-sequential data, explainable machine learning, and / or ensemble boosting frameworks
US20230208858A1