Method and apparatus for determining task execution policy

By receiving request information in the trusted module and sending execution strategy change samples to non-adversarial samples, the problem of high inference error rate when receiving adversarial samples is solved, and the effect of reducing the model error rate is achieved.

WO2025130470A1PCT designated stage expired Publication Date: 2025-06-26HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/132767
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-20
Filing Date
2024-11-18
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

The prior art is difficult to effectively reduce the inference error rate of artificial intelligence models when receiving adversarial samples.

Method used

By receiving request information in the trusted module, determining the model and sample corresponding to the task, and when the sample is determined as an adversarial sample, the execution strategy is sent to change the sample to a non-adversarial sample, such as changing the model, changing the sample, or performing feature compression, denoising or data smoothing on the sample.

Benefits of technology

It effectively reduces the error rate of model inference and avoids error results caused by adversarial samples.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132767_26062025_PF_FP_ABST
    Figure CN2024132767_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of artificial intelligence. Provided are a method and apparatus for determining a task execution policy. In the method, a trusted module can receive first request information for indicating a first model corresponding to a first task and a first example corresponding to the first task, and when the first example is an adversarial example of the first model, the trusted module can send an execution policy for the first task. The execution policy for the first task is used for indicating a mode of converting the first example into a non-adversarial example. Since the execution policy for the first task can indicate the mode of converting the first example into the non-adversarial example, the problem of a model inference error caused by the adversarial example can be ameliorated, so that the error rate in model inference is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for determining task execution strategy

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 20, 2023, with application number 202311769643.8 and invention name “Method and Device for Determining Task Execution Strategy”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of artificial intelligence (AI) technology, and in particular to a method and apparatus for determining a task execution strategy. Background Art

[0003] With the advancement of artificial intelligence (AI) technology, more and more businesses are using models, such as AI models or machine learning (ML) models, for reasoning. Models are highly sensitive to input data, so even subtle, imperceptible perturbations to the input data (i.e., samples) can lead to incorrect inference results. Therefore, reducing the error rate of model reasoning is a pressing issue. Summary of the Invention

[0004] This application provides a method and device for determining a task execution strategy, which can reduce the error rate of model reasoning.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a method for determining a task execution strategy is provided. The method can be executed by a trusted module. The trusted module here can refer to the trusted module itself or a processor, module, logical node, chip, or chip system that implements the method within the trusted module.

[0007] The method includes: receiving first request information; the first request information is used to indicate a first model corresponding to a first task and a first sample corresponding to the first task; when the first sample is an adversarial sample of the first model, sending an execution strategy for the first task, the execution strategy of the first task is used to indicate a method for changing the first sample into a non-adversarial sample.

[0008] Based on the method provided in the first aspect above, since the execution strategy of the first task can indicate a way to change the first sample to a non-adversarial sample, this method can improve the problem of model inference errors caused by adversarial samples, thereby reducing the model inference error rate.

[0009] In a possible implementation, changing the first sample to a non-adversarial sample includes: replacing the first model; or replacing the first sample; or performing a first operation on the first sample.

[0010] Based on the above possible implementation methods, the method of changing the first sample into a non-adversarial sample includes replacing the first model, and the first sample can be changed into a non-adversarial sample by replacing the first model; the method of changing the first sample into a non-adversarial sample includes replacing the first sample, and the first sample can be changed into a non-adversarial sample by replacing the first sample; the method of changing the first sample into a non-adversarial sample includes performing a first operation on the first sample, and the first sample can be changed into a non-adversarial sample by performing the first operation on the first sample.

[0011] In one possible implementation, the above method also includes: obtaining first indication information, the first indication information is used to indicate whether the first task has a backup sample, and / or, the first indication information is used to indicate whether the first task has a backup model; determining the execution strategy of the first task based on the first indication information.

[0012] Based on the above possible implementation manner, the execution strategy of the first task may be determined according to the first indication information, that is, the execution strategy of the first task may be determined according to whether there is a backup sample and / or whether the first task has a backup model.

[0013] In one possible implementation, the execution strategy of the first task is determined based on the first indication information, including: the first indication information indicates that the first task has a backup sample, and the execution strategy of the first task indicates to replace the first sample; or, the first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates to replace the first model; the first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates to perform a first operation on the first sample.

[0014] Based on the above possible implementation methods, when the first indication information indicates that the first task has a backup sample and the execution strategy of the first task indicates to replace the first sample, the first model can obtain the output result based on the backup sample to avoid the first model outputting an incorrect result based on the first sample; when the first indication information indicates that the first task has a backup model and the execution strategy of the first task indicates to replace the first model, the backup model of the first task can obtain the output result based on the first sample to avoid the first model outputting an incorrect result based on the first sample; when the first indication information indicates that the first task has no backup sample and no backup model and the execution strategy of the first task indicates to perform a first operation on the first sample, the first model can obtain the output result based on the sample obtained after performing the first operation to avoid the first model outputting an incorrect result based on the first sample.

[0015] In a possible implementation manner, the first operation includes at least one of the following: feature compression, sample denoising, or data smoothing.

[0016] Based on the above possible implementation methods, the sample data that causes the first model to have inference errors can be eliminated by performing feature compression, sample denoising or data smoothing on the first sample, so that the sample obtained after executing the first operation is changed to a non-adversarial sample of the first model.

[0017] In one possible implementation, the execution strategy of the first task indicates replacing the first sample, and the method further includes: obtaining a second sample corresponding to the first task; and determining whether the second sample is an adversarial sample based on the first model.

[0018] Based on the above possible implementation methods, a second sample corresponding to the first task can also be obtained, and whether the second sample is an adversarial sample can be determined according to the first model, so as to reduce the error rate of the first model reasoning.

[0019] In one possible implementation, the execution strategy of the first task indicates replacing the first model, and the method further includes: obtaining a second model corresponding to the first task; and determining whether the first sample is an adversarial sample based on the second model.

[0020] Based on the above possible implementation methods, it is also possible to obtain a second model corresponding to the first task, and determine whether the first sample is an adversarial sample based on the second model, so as to reduce the error rate of the inference result of the first task.

[0021] In a possible implementation, the method further includes: receiving first policy information, where the first policy information indicates an execution policy of the first task.

[0022] Based on the above possible implementations, the trusted module may determine a method for changing the first sample into a non-adversarial sample according to the first policy information.

[0023] In one possible implementation, the method further includes: obtaining a robustness requirement for the first task, where the robustness requirement for the first task indicates a need to detect whether a first sample corresponding to the first task is an adversarial sample; and determining whether the first sample is an adversarial sample based on the first model.

[0024] Based on the above possible implementation methods, the trusted module can determine whether it is necessary to detect whether the first sample is an adversarial sample of the first model according to the robustness requirement of the first task. When the robustness requirement of the first task indicates that it is necessary to detect whether the first sample corresponding to the first task is an adversarial sample, the trusted module can determine that it is necessary to detect whether the first sample is an adversarial sample of the first model. When the robustness requirement of the first task indicates that it is not necessary to detect whether the first sample corresponding to the first task is an adversarial sample, the trusted module can determine that it is not necessary to detect whether the first sample is an adversarial sample of the first model.

[0025] In one possible implementation, the robustness requirement of the first task also indicates the robustness requirement of the output result of the first model corresponding to the first task; determining whether the first sample is an adversarial sample based on the first model includes: determining whether the first sample is an adversarial sample based on the first model and the robustness requirement.

[0026] Based on the above possible implementation methods, it is possible to combine robustness requirements, such as a specific unstable change threshold, to more flexibly determine whether the first sample is an adversarial sample based on the first model.

[0027] Second, a method for determining a task execution strategy is provided, which can be executed by an inference module. The inference module here can refer to the inference module itself, or to a processor, module, logical node, chip, or chip system within the inference module that implements the method.

[0028] The method includes: obtaining a first sample of a first task; sending a first request message; the first request message indicates the first sample of the first task and a first model of the first task; receiving an execution strategy of the first task, the execution strategy of the first task indicating a method for changing the first sample into a non-adversarial sample.

[0029] Based on the method provided in the second aspect above, since the execution strategy of the first task can indicate a way to change the first sample to a non-adversarial sample, this method can improve the problem of model inference errors caused by adversarial samples, thereby reducing the model inference error rate.

[0030] In a possible implementation, changing the first sample to a non-adversarial sample includes: replacing the first model; or replacing the first sample; or performing a first operation on the first sample.

[0031] Based on the above possible implementation methods, the method of changing the first sample into a non-adversarial sample includes replacing the first model, and the reasoning module can change the first sample into a non-adversarial sample by replacing the first model; the method of changing the first sample into a non-adversarial sample includes replacing the first sample, and the reasoning module can change the first sample into a non-adversarial sample by replacing the first sample; the method of changing the first sample into a non-adversarial sample includes performing a first operation on the first sample, and the reasoning module can perform reasoning based on the sample after performing the first operation on the first sample.

[0032] In one possible implementation, the above method also includes: sending first indication information, the first indication information is used to indicate whether the first task has a backup sample, and / or, the first indication information is used to indicate whether the first task has a backup model, and the first indication information is used to determine the execution strategy of the first task.

[0033] Based on the above possible implementation manner, a device that receives the first indication information, such as a trusted module, can determine an execution strategy for the first task according to the first indication information.

[0034] In one possible implementation, the first indication information indicates that the first task has a backup sample, and the execution strategy of the first task indicates replacing the first sample; or, the first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates replacing the first model; the first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates performing a first operation on the first sample.

[0035] Based on the above possible implementation methods, when the first indication information indicates that the first task has a backup sample and the execution strategy of the first task indicates to replace the first sample, the first model can obtain the output result based on the backup sample, thereby avoiding the first model outputting an incorrect result based on the first sample; when the first indication information indicates that the first task has a backup model and the execution strategy of the first task indicates to replace the first model, the backup model of the first task can obtain the output result based on the first sample, thereby avoiding the first model outputting an incorrect result based on the first sample; when the first indication information indicates that the first task has no backup sample and no backup model, the execution strategy of the first task indicates to perform the first operation on the first sample, thereby avoiding the first model outputting an incorrect result based on the first sample.

[0036] In a possible implementation manner, the first operation includes at least one of the following: feature compression, sample denoising, or data smoothing.

[0037] Based on the above possible implementation methods, by performing feature compression, sample denoising or data smoothing on the first sample, sample data that causes inference errors of the first model can be eliminated, so that the sample obtained after executing the first operation is changed to a non-adversarial sample of the first model.

[0038] In a possible implementation, the execution strategy of the first task indicates replacing the first model, and the method further includes: receiving second indication information from the communication node, where the second indication information is used to indicate a backup model for the first task.

[0039] Based on the above possible implementation manner, when the execution strategy of the first task indicates to replace the first model, the backup model of the first task can be obtained according to the second instruction information.

[0040] In one possible implementation, when the execution strategy of the first task indicates replacing the first model, the above method also includes: sending a first sample to a communication node; receiving an inference result from the communication node, wherein the inference result is used to indicate a result obtained by reasoning based on the first sample and the backup model of the first task.

[0041] Based on the above possible implementation manner, the first sample may be sent to the communication node to obtain a result obtained by reasoning based on the first sample and the backup model.

[0042] In a possible implementation, the method further includes: receiving a robustness requirement of the first task, where the robustness requirement of the first task indicates that it is necessary to detect whether a sample corresponding to the first task is an adversarial sample.

[0043] Based on the above possible implementation manner, the reasoning module may determine whether to send the first request information according to the robustness requirement of the first task.

[0044] In a possible implementation, the robustness requirement of the first task also indicates a robustness requirement of an output result of the model of the first task.

[0045] Based on the above possible implementations, the robustness requirements of the output results of the model of the first task can be determined.

[0046] In a possible implementation, the execution strategy of the first task is further used to indicate that the first sample is an adversarial sample.

[0047] Based on the above possible implementation methods, a method for changing the first sample into a non-adversarial sample can be determined according to the execution strategy of the first task.

[0048] In a third aspect, a communication device is provided for implementing the above-mentioned method. The communication device may be the trusted module described in the first aspect; alternatively, the communication device may be the reasoning module described in the second aspect. The communication device includes modules, units, or means corresponding to the above-mentioned method. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above-mentioned functions.

[0049] In conjunction with the third aspect above, in one possible implementation, the communication device may include a processing module and an interface module. The processing module may be configured to implement the processing functions described in any of the above aspects and any possible implementations thereof. The processing module may, for example, be a processor. The interface module, also referred to as an interface unit, may be configured to implement the sending and / or receiving functions described in any of the above aspects and any possible implementations thereof. The interface module may be comprised of an interface circuit, a transceiver, a transceiver, or a communication interface.

[0050] In combination with the third aspect above, in a possible implementation, the interface module includes a sending module and a receiving module, which are respectively used to implement the sending and receiving functions in any of the above aspects and any possible implementations thereof.

[0051] In a fourth aspect, a communication device is provided, comprising: a processor; the processor is coupled to a memory, and after reading instructions from the memory, executes the method described in any of the above aspects according to the instructions. The communication device may be the trusted module described in the first aspect; alternatively, the communication device may be the inference module described in the second aspect.

[0052] In conjunction with the fourth aspect above, in one possible implementation, the communication device further includes a memory for storing program instructions and data. Optionally, the memory is integrated with the processor; or the memory is independent of the processor.

[0053] In conjunction with the fourth aspect above, in one possible implementation, the communication device is a chip or a chip system. Optionally, when the communication device is a chip system, it can be composed of a chip or include a chip and other discrete devices.

[0054] In a fifth aspect, a communication device is provided, comprising: a processor and an interface circuit; the interface circuit being configured to receive a computer program or instruction and transmit it to the processor; and the processor being configured to execute the computer program or instruction, thereby causing the communication device to perform the method described in any of the above aspects. The communication device may be the trusted module described in the first aspect, or the inference module described in the second aspect.

[0055] In conjunction with the fifth aspect above, in one possible implementation, the communication device is a chip or a chip system. Optionally, when the communication device is a chip system, it can be composed of a chip or include a chip and other discrete devices.

[0056] In a sixth aspect, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium. When the computer-readable storage medium is run on a computer, the computer can execute the method described in any one of the above aspects.

[0057] In a seventh aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the method described in any one of the above aspects.

[0058] In an eighth aspect, a communication system is provided, which includes a trusted module for executing the method described in the first aspect, and a reasoning module for executing the method described in the second aspect.

[0059] Among them, the technical effects brought about by any possible implementation method in the third to eighth aspects can be referred to the technical effects brought about by any aspect in the first to second aspects or different possible implementation methods in any aspect, and will not be repeated here.

[0060] It is understandable that, provided that the solutions are not contradictory, the solutions in each aspect can be combined. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] FIG1A is a schematic diagram of a stable region and an unstable region of a classification model provided in the present application;

[0062] FIG1B is a schematic diagram of an image classification model provided by this application being attacked by an adversarial sample;

[0063] FIG1C is a schematic diagram of a regression model provided in this application being attacked by an adversarial sample;

[0064] FIG1D is a schematic diagram of the AI ​​process of the beam management use case provided in this application;

[0065] FIG1E is a schematic diagram of a beam management model provided by this application being attacked by an adversarial example;

[0066] FIG2A is a schematic diagram of a communication system architecture provided by this application;

[0067] FIG2B is a second schematic diagram of the communication system architecture provided by this application;

[0068] FIG2C is a third schematic diagram of the communication system architecture provided by this application;

[0069] FIG2D is a schematic diagram of an AI workflow in a radio access network (RAN) domain provided by this application;

[0070] FIG2E is a schematic diagram of the AI ​​workflow for the operations, administration, and maintenance (OAM) domain provided by this application;

[0071] FIG2F is a fourth schematic diagram of the communication system architecture provided by this application;

[0072] FIG2G is a fifth schematic diagram of the communication system architecture provided by this application;

[0073] FIG3 is a schematic diagram of the hardware structure of the communication device provided in this application;

[0074] FIG4 is a flow chart of the communication method provided by this application;

[0075] FIG5 is a second flow chart of the communication method provided by this application;

[0076] FIG6 is a schematic diagram of the structure of the communication device provided in this application. DETAILED DESCRIPTION

[0077] During the model's inference phase (i.e., the stage where the model generates output results based on inference samples input), if the model is not robust enough, the inference samples may become adversarial examples due to factors such as noise, measurement error, and malicious modification, causing the model's inference to fail. In the field of ML or AI, "robustness" can be understood as the ability of a model to resist certain malicious attacks. The purpose of making a model robust is to ensure that the model's output results are not affected by attacks and changes to the greatest extent possible.

[0078] The adversarial sample mentioned above refers to a sample specially designed for the model during the inference phase of the model. For example, by adding a small but carefully designed perturbation to the original sample, the model is misled, causing the model to obtain incorrect output results.

[0079] The existence of adversarial examples stems from inherent flaws in the model. These flaws refer to naturally existing unstable regions within the model. This is illustrated below using a classification model as an example. Figure 1A shows a schematic diagram of the stable and unstable regions of a classification model. Each circle and square in Figure 1A corresponds to the model's output for different inputs. The circles correspond to points where the model outputs a classification result of "A," and the squares correspond to points where the model outputs a classification result of "B." As can be understood, points closer to the classification boundary are more sensitive to changes in input data. In other words, points closer to the classification boundary are more likely to cause the model to output incorrect results when the input is perturbed. The region near the classification boundary can be called the unstable region (also called the non-robust region), while the region farther from the classification boundary can be called the stable region. The larger the unstable region near the classification boundary of the model, the more likely it is that even small perturbations of inference samples near the classification boundary will result in incorrect outputs, and the greater the probability of adversarial examples existing. Regarding the classification boundaries mentioned above, we can understand it as follows: taking the classification model as an example, we can make decisions on several different possible results based on probability (confidence). Different results correspond to decision thresholds with different probabilities. For example, if more than 50% can be decided as A, then the data near 50% will have a more serious interference on the result.

[0080] Because the model is very sensitive to data, these small perturbations, although usually imperceptible to users, can cause the model to output incorrect results, such as incorrect classification results or incorrect numerical results. The following examples 1 and 2 are used as examples to illustrate this.

[0081] Example 1, as shown in Figure 1B, takes an image classification model attacked by an adversarial sample as an example. The original image is a panda. If the original image is used as the input of the image classification model, the classification result of the image classification model based on the original image output is "panda" (confidence is 57.7%). If some carefully designed noise invisible to the naked eye is superimposed on the original image (for example, the noise can be weighted by 0.007), an adversarial sample image is obtained. The classification result of the image classification model based on the adversarial sample image output is "gibbon" (confidence is 99.3%).

[0082] Example 2, as shown in Figure 1C, uses a regression model attacked by an adversarial sample as an example. The regression model can be a mathematical model that quantitatively describes a statistical relationship. The regression model can be represented by the expression f(x). When the input data is x, the regression model outputs y. If some interference is applied to x, the input data becomes (x+Δx1), and the regression model outputs y'. If some other interference is applied to x, the input data may also become (x+Δx2), and the regression model outputs y". y" and y' are incorrect output data.

[0083] It is understandable that the event in which the above-mentioned model inference process is affected by adversarial samples is also called an adversarial attack. Specifically, an adversarial attack can be understood as the process of applying slight perturbations to the original input inference samples of the target machine learning model to generate adversarial samples and deceive the target model.

[0084] Because adversarial attacks on models can have unimaginable consequences, AI robustness requires careful consideration. Many international organizations are paying close attention to this issue. For example, the draft EU AI Act explicitly proposes that AI systems undergo certain robustness enhancements to protect against attacks such as poisoning and adversarial attacks. The EU AI Act (ACT ARTICLE 15) outlines AI robustness requirements: AI-specific vulnerabilities should be addressed, including, where appropriate, measures to prevent, detect, respond to, address, and control attacks that attempt to manipulate training datasets ("data poisoning") or pre-trained components used for training ("model poisoning"), attacks designed to cause model errors ("adversarial examples" or "model evasion"), confidentiality attacks, or other model flaws, all of which could lead to harmful decisions.

[0085] The following describes the AI ​​process using the beam management use case as an example. As shown in Figure 1D, the specific steps are described below, using the beam management use case model as an example. S101 to S106 correspond to the model's training phase, and S107 to S111 correspond to the model's inference phase.

[0086] S101: The RAN node in the NR sends a full-beam scanning instruction to the terminal. Correspondingly, the terminal receives the full-beam scanning instruction.

[0087] The term "full beam" refers to an omnidirectional beam. The specific angle value indicated by the omnidirectional beam can be set by the RAN node. For example, the omnidirectional beam can be 180° or 360°. The full beam scan can be a 32-beam, 64-beam, or 256-beam beam scan. The specific number of beams is configured by the RAN node. This example uses 64 beams as the full beam scan.

[0088] S102: The terminal obtains data of a training model for beam scanning.

[0089] For beam scanning use cases, the terminal can measure all beams to obtain inference samples for the beam scanning training model and obtain the reference signal receiving power (RSRP) of each beam. The identity (ID) of all beams and the corresponding RSRP can be used as data for the training model.

[0090] S103: The terminal sends the training model data to the RAN node. Correspondingly, the RAN node receives the training model data from the terminal.

[0091] S104: The RAN node generates or trains a model.

[0092] It can be understood that the RAN node uses the data of the training model from the terminal to generate or train the model, and the output data is the probability of occurrence of 5 optimal beams among 64 beams.

[0093] S105: The RAN node sends a sparse beam scanning instruction to the terminal. Correspondingly, the terminal receives the sparse beam scanning instruction from the RAN node.

[0094] In this example, 16 beams are used as the number of beams in the sparse beam system.

[0095] S106: The terminal sends the RSRP corresponding to the sparse beam to the RAN node. Correspondingly, the RAN node receives the RSRP corresponding to the sparse beam from the terminal.

[0096] It should be understood that the combination of steps S105 to S106 can be performed multiple times to enable the RAN node to obtain samples corresponding to multiple sparse beams. These samples can be used as training samples to train the model.

[0097] S107: The RAN node uses the model to infer five optimal beams.

[0098] It can be understood that the RAN node uses the model generated in S104 to infer the five optimal beams among the 64 beams and obtains the beam IDs of the five optimal beams.

[0099] In addition, the number of optimal beams can be set by presetting or other means. This example uses five optimal beams as an example, but the number of optimal beams can also be any other number without limitation. A schematic diagram of the five optimal beams inferred by the RAN node from the 64 beams can be seen in the grid diagram next to S107. The five black squares in the grid diagram indicate the five optimal beams.

[0100] S108: The RAN node sends an instruction to the terminal to perform a two-stage scan based on the five optimal beams. Correspondingly, the terminal receives the instruction from the RAN node to perform a two-stage scan based on the five optimal beams.

[0101] S109: The terminal measures beam RSRP.

[0102] The terminal measures RSRP and selects the optimal beam from the five optimal beams.

[0103] S110: The terminal sends an indication of the optimal beam to the RAN node. Correspondingly, the RAN node receives the indication of the optimal beam from the terminal.

[0104] It can be understood that the indication of the optimal beam may include the ID of the optimal beam.

[0105] S111: The RAN node sends a signal based on the optimal beam. Correspondingly, the terminal receives the signal sent from the RAN node based on the optimal beam.

[0106] As can be understood, during the model inference phase of the beam management use case described above, in conjunction with Figure 1E , the RAN node can obtain sparse beam scanning results from multiple terminals, thereby obtaining multiple samples (see the first left figure in Figure 1E ). A model is trained using these samples. The model's inference process can be expressed as f(x), and the model output is the five best beams out of 64. During the model inference process, if the terminal does not make errors when measuring the RSRP of the beams, that is, the data of the inference sample input to the model is correct, the model outputs the correct result (see the first right figure in Figure 1E ). If the terminal makes errors when measuring the RSRP of the beams, and the errors are so large that the sample falls into the model's unstable region, the model output is likely to be incorrect, and the inference sample becomes an adversarial example for the model, outputting an incorrect result (see the second left figure in Figure 1E ).

[0107] This shows that during the inference stage of the model, the model may make inference errors due to slight perturbations in the input data.

[0108] In order to solve the above problems, the present application provides a method for determining a task execution strategy. In this method, a trusted module can receive a first request message, wherein the first request message is used to indicate a first model corresponding to a first task and a first sample corresponding to the first task, and determine whether the first sample is an adversarial sample based on the first model. In the case where the first sample is an adversarial sample, the trusted module can determine the execution strategy of the first task, and the execution strategy of the first task is used to indicate a method for changing the first sample to a non-adversarial sample. Through the above scheme, the trusted module can determine whether the first sample is an adversarial sample. If the first sample is an adversarial sample, the trusted module can determine a method for changing the first sample to a non-adversarial sample, thereby avoiding model inference errors caused by adversarial samples, and the model inference error rate will be improved.

[0109] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0110] It is understood that the method provided in this application can be used in various AI systems. The method provided in this application is described below using the AI ​​system 20 shown in FIG2A as an example. FIG2A is merely a schematic diagram and does not limit the applicable scenarios of the technical solutions provided in this application.

[0111] FIG2A is a schematic diagram of the architecture of the AI ​​system 20 provided in this application. In FIG2A , the AI ​​system 20 may include a trusted module 201 and a reasoning module 202 connected to the trusted module 201. Optionally, the AI ​​system 20 may also include a management module 203.

[0112] The trusted module 201 can be configured to obtain a first model corresponding to a first task and a first sample corresponding to the first task, determine whether the first sample is an adversarial sample based on the first model, and, if the first sample is an adversarial sample, determine an execution strategy for the first task. The execution strategy for the first task indicates at least one method for changing the first sample to a non-adversarial sample. The trusted module 201 is further configured to transmit the execution strategy for the first task to the reasoning module 202, so that the reasoning module 202 executes the first task according to the execution strategy.

[0113] The management module 203 may be configured to send the robustness requirement of the first task to the trusted module 201 , so that the trusted module 201 determines whether it is necessary to detect whether the sample corresponding to the first task is an adversarial sample based on the robustness requirement of the first task.

[0114] In one possible implementation, the AI ​​system 20 shown in FIG2A can be applied to a 3GPP network or an open radio access network (ORAN) architecture, etc., which is not specifically limited in the present embodiment. Detailed description is given below.

[0115] Exemplarily, the AI ​​system 20 shown in FIG2A can be applied to the communication network architecture shown in FIG2B . The communication network shown in FIG2B can be divided into a RAN domain and a RAN domain / cross-domain management service (MnS) consumer according to function. The RAN domain includes a domain management function (for example, the domain management function can be OAM) and a RAN node. The RAN node has an AI / ML reasoning function and a trusted AI / ML management function. The AI / ML reasoning function can have the function of a reasoning module 202, the trusted AI / ML management function can have the function of a trusted module 201, and the domain management function can have the function of a management module 203. The RAN domain is also called an access network domain.

[0116] In FIG2B , the RAN domain sends data to the RAN domain / inter-domain MnS consumers through the northbound interface, and the RAN domain / inter-domain management service consumers send data to the RAN domain through the southbound interface.

[0117] For example, the AI ​​system 20 shown in Figure 2A can also be applied to the communication network architecture shown in Figure 2C. Figure 2C differs from Figure 2B in that, in Figure 2C, the domain management function has AI / ML reasoning function and trusted AI / ML management function. Among them, the AI / ML reasoning function can have the function of the reasoning module 202, the trusted AI / ML management function has the function of the trusted module 201, and the domain management function can have the function of the management module 203. It can be understood that in addition to the two communication system architectures described in Figure 2B or Figure 2C, there can also be other communication system architectures. For example, the RAN node can have AI / ML reasoning function, and the domain management function can have trusted AI / ML management function. Alternatively, the RAN node can have trusted AI / ML management function, and the domain management function can have AI / ML reasoning function. This application does not limit the location where the AI / ML reasoning function and the trusted AI / ML management function are deployed in the 3GPP network.

[0118] This implementation allows for flexible deployment of AI / ML reasoning and trusted AI / ML management functions. Both functions provide diverse services for different interfaces, meeting the requirements of service-oriented interface definition. The following describes the AI ​​workflows related to RAN nodes and domain management functions.

[0119] Taking Figure 2B as an example, the AI ​​workflow of the RAN node is mainly divided into the stages of data collection, training, inference, and use (actor), as shown in Figure 2D. First, the RAN node can collect data. The collected data can be used as training data for model training or as input data for the trained model to perform model inference. The output data of the model can be applied to the corresponding scenario. Other data obtained during the use of the model that is different from the input data can also be fed back to the data collection module. The above process can be repeated and will not be repeated here.

[0120] Taking Figure 2C as an example, the AI ​​workflow of OAM (i.e., the domain management function in Figure 2C) can be divided into three stages: training, deployment, and reasoning, as shown in Figure 2E. During the training stage, OAM can train the model and test the model after training. During the model testing process, if there is a problem, OAM can re-train the model. After the model is tested, OAM can deploy the model to the RAN node. After the model is deployed, OAM can use these models for reasoning. If an abnormality occurs during the reasoning process, OAM can also train the model for further correction of the model. It can be understood that after the above-mentioned corrected model (or the model of other situations) completes the model testing, it can also be used for model reasoning without deployment (or other models that have already been deployed).

[0121] In addition to the above-mentioned methods, the AI ​​system 20 shown in FIG2A can also be applied to an ORAN network. For example, the AI ​​system 20 can also be applied to the communication system architecture shown in FIG2F or FIG2G.

[0122] It can be understood that the ORAN network is an open RAN architecture with open standardized interfaces. Each module can be built independently so that cellular network equipment developed according to different standards can interoperate with each other. In this way, wireless network equipment providers can focus on providing specific components instead of building the entire RAN, thereby making the mobile communication network software-based, virtualized, flexible, intelligent and energy-saving.

[0123] As shown in FIG2F or FIG2G , the communication system architecture of the ORAN network may include: a non-real-time radio intelligent controller (Non-RT RIC), a near-real-time radio intelligent controller (Near-RT RIC), an ORAN central unit (ORAN-central unit, O-CU) and an ORAN distributed unit (ORAN-distributed unit, O-DU).

[0124] Both the O-CU and O-DU are ORAN nodes. The O-CU is the centralized unit (CU) within the ORAN system, primarily responsible for non-real-time Layer 2 (L2) and radio resource control (RRC) functions. The O-DU is the distributed unit (DU) within the ORAN system, primarily responsible for real-time Layer 2 functions and baseband signal processing.

[0125] Near-real-time RIC enhances radio resource management (RRM) by integrating RRM, slice management, service level agreements, AI / ML, and mobile edge cloud computing technologies to provide near-real-time intelligent control of the RAN (the access network portion of ORAN). Near-real-time RIC connects to the O-CU, O-DU, and non-real-time RIC through standardized ORAN interfaces.

[0126] The non-real-time RIC resides in the ORAN network management platform and performs policy management, RAN analysis, and AI / ML-based function management. The non-real-time RIC connects to the near-real-time RIC via an ORAN standardized interface.

[0127] Both near-real-time RIC and non-real-time RIC belong to the real-time radio intelligent controller (RT RIC). In one possible implementation, near-real-time RIC implements near-real-time control and optimization of ORAN nodes (O-CU / O-DU), while non-real-time RIC implements non-real-time control of ORAN nodes (O-CU / O-DU). For example, model training can be completed on the non-real-time RIC platform and deployed to the near-real-time RIC platform for inference. The non-real-time RIC can also issue execution policies to the near-real-time RIC.

[0128] For ORAN networks, the O-CU or O-DU may have AI / ML reasoning capabilities, and the non-real-time RIC or near-real-time RIC may have trusted AI / ML management capabilities. Figure 2F shows a schematic diagram of a non-real-time RIC with trusted AI / ML management capabilities. Figure 2G shows a schematic diagram of a near-real-time RIC with trusted AI / ML management capabilities. In the communication network architecture shown in Figure 2F or Figure 2G, the O-CU or O-DU may have AI / ML reasoning capabilities. The trusted AI / ML management function may have the functions of the above-mentioned trusted module 201, and the AI / ML reasoning function may have the functions of the above-mentioned reasoning module 202.

[0129] In this application, a RAN node may be a device with wireless transceiver functions that can help terminals achieve wireless access. The RAN node in this application may also be referred to as a node in the RAN, a RAN node, or an access network device. RAN nodes include, but are not limited to, evolved NodeBs (eNBs or e-NodeBs) in LTE, next generation eNBs (ng-eNBs) in next generation LTE, gNodeBs or gNBs in NR, next generation radio access network (NG-RAN) nodes, transmitting points (TPs) or transmission receiving points (TRPs), base stations developed in subsequent 3GPP evolutions, next generation NodeBs (gNBs), next generation base stations in 6G mobile communication systems, base stations in future mobile communication systems, satellites, access nodes in Wi-Fi systems, wireless relay nodes, wireless backhaul nodes, integrated access and backhaul (IAB) nodes, mobile switching centers, and RAN nodes in non-terrestrial network (NTN) communication systems, i.e., RAN nodes that can be deployed on high-altitude platforms or satellites. Base stations can be macro base stations, micro base stations, pico base stations, small cells, relay stations, or balloon base stations. Multiple base stations can support networks with the same technology mentioned above, or they can support networks with different technologies mentioned above. A base station can include one or more co-sited or non-co-sited TRPs. A RAN node can also be a device that acts as a base station in D2D communication, Internet of Vehicles communication, drone communication, and machine communication. A RAN node can also be a wireless controller in a cloud radio access network (CRAN) scenario. A RAN node can also be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), a radio unit (RU), a roadside unit (RSU) with base station function, a wired access gateway, or a core network element. A RAN node can also be a server, a wearable device, a machine communication device, or an on-board device. For example, a RAN node in V2X technology can be an RSU.The following description uses a base station as an example of a RAN node. The multiple RAN nodes may be base stations of the same type or different types. A base station may communicate with a terminal or communicate with the terminal through a relay station. A terminal may communicate with multiple base stations using different technologies. For example, a terminal may communicate with a base station supporting an LTE network or a base station supporting a 5G network, and may also support dual connectivity with base stations on an LTE network and a base station on a 5G network.

[0130] In this application, the CU and DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It is understandable that the CU can be divided into a RAN node in the access network, or the CU can be divided into a RAN node in the core network, without limitation here.

[0131] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (ORAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application takes CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0132] In this application, the form of a RAN node is not limited. The device used to implement the functions of a RAN node can be a RAN node; it can also be a device that supports the RAN node to implement the functions, such as a chip system. The device can be installed in a RAN node or used in conjunction with a RAN node.

[0133] Optionally, each module in FIG. 2A of the present application (such as the trusted module 201, the reasoning module 202 or the management module 203, etc.) can also be referred to as a communication device, which can be a general device or a dedicated device, and the present application does not make specific limitations on this.

[0134] Optionally, the relevant functions of each module in FIG. 2A of the present application (e.g., trusted module 201, reasoning module 202, or management module 203, etc.) can be implemented by a single device, or by multiple devices, or by one or more functional modules within a single device. This application does not impose any specific limitations on this. It is understood that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (e.g., a cloud platform).

[0135] In a specific implementation, each module in FIG. 2A of the present application (e.g., trusted module 201, reasoning module 202, or management module 203) may adopt the structure shown in FIG. 3 or include the components shown in FIG. FIG. 3 is a schematic diagram of the hardware structure of a communication device applicable to the present application. The communication device 30 includes at least one processor 301 and at least one communication interface 304 for implementing the method provided in the present application. The communication device 30 may also include a communication circuit 302 and a memory 303.

[0136] The processor 301 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.

[0137] The communication link 302 may include a path for transmitting information between the above components, such as a bus.

[0138] Communication interface 304 is used to communicate with other devices or communication networks. Communication interface 304 can be any transceiver-like device, such as an Ethernet interface, a radio access network (RAN) interface, a wireless local area network (WLAN) interface, a transceiver, a pin, a bus, an interface circuit, or a transceiver circuit.

[0139] The memory 303 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory can be independent and coupled to the processor 301 via a communication line 302. The memory 303 can also be integrated with the processor 301. The memory provided in this application can generally be non-volatile.

[0140] Among them, the memory 303 is used to store computer-executable instructions involved in executing the solution provided by this application, and is controlled by the processor 301. The processor 301 is used to execute the computer-executable instructions stored in the memory 303, thereby implementing the method provided by this application. Alternatively, optionally, in this application, the processor 301 can also perform the processing-related functions of the method provided below in this application, and the communication interface 304 is responsible for communicating with other devices or communication networks, which is not specifically limited in this application.

[0141] Optionally, the computer-executable instructions in this application may also be referred to as application code, which is not specifically limited in this application.

[0142] The coupling in this application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules.

[0143] As an embodiment, the processor 301 may include one or more CPUs, such as CPU0 and CPU1 in FIG. 3 .

[0144] As an embodiment, the communication device 30 may include multiple processors, such as processor 301 and processor 307 in FIG3 . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0145] As an embodiment, the communication device 30 may further include an output device 305 and / or an input device 306. The output device 305 is coupled to the processor 301 and can display information in a variety of ways. For example, the output device 305 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 306 is coupled to the processor 301 and can receive user input in a variety of ways. For example, the input device 306 can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0146] It is understandable that the composition structure shown in Figure 3 does not constitute a limitation on the communication device. In addition to the components shown in Figure 3, the communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0147] The method provided by the present application will be described below with reference to the accompanying drawings. Each module in the following embodiment may include the components shown in FIG3 , which will not be described in detail.

[0148] It is understandable that the message names between modules or the names of parameters in the messages in the following embodiments of the present application are merely examples, and other names may be used in specific implementations, and the present application does not impose any specific limitations on this.

[0149] It can be understood that in this application, "sending a first request message to... (such as a trusted module)" can be understood as the destination end of the information being the trusted module, which can include directly or indirectly sending information to the trusted module. "Receiving a first request message from... (such as an inference module)" can be understood as the source end of the information being the inference module, which can include directly or indirectly receiving information from the inference module. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.

[0150] It is understood that in this application, " / " can indicate that the objects associated with each other are in an "or" relationship, for example, A / B can mean A or B; "and / or" can be used to describe that there are three relationships between the associated objects, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, expressions similar to "at least one of A, B and C" or "at least one of A, B or C" are usually used to indicate any of the following: A exists alone; B exists alone; C exists alone; A and B exist at the same time; A and C exist at the same time; B and C exist at the same time; A, B and C exist at the same time. The above uses A, B and C as an example to illustrate the optional items of the item. When there are more elements in the expression, the meaning of the expression can be obtained according to the above rules.

[0151] In order to facilitate the description of the technical solutions of the present application, in the present application, words such as "first" and "second" may be used to distinguish between technical features with the same or similar functions. The words such as "first" and "second" do not limit the quantity and execution order, and the words such as "first" and "second" do not necessarily limit them to be different. In the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" should not be interpreted as being more preferred or more advantageous than other embodiments or design. The use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0152] It is understood that the "embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the various embodiments in the entire specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It is understood that in the various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the present application.

[0153] It can be understood that in the present application, "used to indicate" can include direct indications and indirect indications, and can also include explicit indications and implicit indications. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and it does not mean that the indication information must carry A. The information indicated by a certain information (such as the first indication information described below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, directly indicating the information to be indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent.

[0154] It can be understood that in this application, "when...", "in the case of...", "if" and "if" all mean that corresponding processing will be taken under certain objective circumstances, and do not limit the time, nor do they require judgment actions when implementing them, nor do they mean that there are other limitations.

[0155] It is understood that some optional features in this application may, in certain scenarios, be implemented independently of other features, such as the solution on which they are currently based, to solve corresponding technical problems and achieve corresponding effects. They may also be combined with other features in certain scenarios as needed. Accordingly, the devices provided in this application may also implement these features or functions accordingly, which will not be described in detail here.

[0156] It is understandable that the same step or steps or technical features with the same function in different embodiments of the present application can be referenced to each other.

[0157] It is understood that in this application, the trusted module and / or the reasoning module and / or the management module may perform some or all of the steps in this application. These steps are merely examples, and this application may also perform other steps or variations of various steps. In addition, the steps may be performed in a different order than presented in this application, and it is possible that not all of the steps in this application need to be performed.

[0158] It is understandable that the method provided below in this application is illustrated by taking the trusted module, reasoning module and management module as the execution subject of the interactive diagram as an example, but this application does not limit the execution subject of the interactive diagram. For example, the trusted module in the method provided in the following embodiment of this application can also be a chip, chip system, or processor that supports the trusted module to implement the method, or a logical node, logical module or software that can implement all or part of the trusted module; the reasoning module in the method provided below in this application can also be a chip, chip system, or processor that supports the reasoning module to implement the method, or a logical node, logical module or software that can implement all or part of the reasoning module; the management module in the method provided below in this application can also be a chip, chip system, or processor that supports the management module to implement the method, or a logical node, logical module or software that can implement all or part of the management module.

[0159] As shown in FIG4 , a method for determining a task execution strategy provided by the present application may include the following steps:

[0160] S401: The reasoning module obtains a first sample of a first task.

[0161] In this application, the reasoning module may be the reasoning module 202 shown in FIG2A . The first task is a task to be performed by the reasoning module. The first task may correspond to at least one sample, and the at least one sample includes the first sample.

[0162] In one possible implementation, the reasoning module obtains the first sample of the first task from the corresponding RAN node. It will be appreciated that if the reasoning module is deployed on the RAN node, the reasoning module obtains the first sample of the first task using an interface within the RAN node. If the reasoning module is located within a domain management function (such as OAM), the reasoning module can obtain the first sample of the first task through an interface between the OAM and the RAN node. The following describes the process of the reasoning module obtaining the first sample of the first task, using the example of the reasoning module being deployed on the RAN node.

[0163] For example, the first task is a beam management use case. When the full beam is configured as 64 beams and the sparse beam is configured as 16 beams, the RAN node initiates the collection of the first sample by instructing the terminal to perform a sparse beam scan. The terminal obtains the beam measurement results of 16 beams out of the 64 beams (such as the RSRP of the 16 beams) as the result of the sparse beam scan and sends the result of the sparse beam scan to the RAN node. After receiving the result of the sparse beam scan from the terminal, the RAN node indicates the result of the sparse beam scan to the inference module, and the inference module can use the result of the sparse beam scan as the first sample of the first task.

[0164] For example, the first task is described using a cell load balancing use case. It will be appreciated that cell load balancing targets multiple cells managed by a RAN node. If the number of terminals accessing some of these cells is about to reach or has already exceeded the cell's load capacity, the service quality of the terminals accessing these cells will degrade, while the number of terminals accessing other cells in the multiple cells may be very small. In this case, to ensure the service quality of the terminals, the number of terminals accessing the cells can be adjusted. The inference module can instruct the RAN node to obtain information about terminals accessing the multiple cells managed by the RAN node. The terminal information may include information about the terminal's location, mobility, and certain measurement indicators. The measurement indicator information may include, for example, RSRP, and / or reference signal receiving quality (RSRQ), and / or signal to interference plus noise ratio. The inference module obtains information about the terminals accessing the multiple cells managed by the RAN node from the RAN node, and may use this terminal information as the first sample for the first task.

[0165] Optionally, the management module sends a third indication message to the reasoning module. Accordingly, the reasoning module receives the third indication message from the management module. The third indication message may indicate the first task. For example, the third indication message may include the name or identifier of the first task. Optionally, the third indication message may also include the name or identifier of the model corresponding to the first task (such as the first model in S402). After receiving the third indication message, the reasoning module may obtain the first sample of the first task based on the third indication message. The management module may be the management module 203 shown in Figure 2A.

[0166] It is understandable that the first task may also be pre-set in the reasoning module. In this way, the management module may not need to send the third instruction information to the reasoning module.

[0167] S402: The reasoning module sends a first request message to the trusted module. Correspondingly, the trusted module receives the first request message from the reasoning module.

[0168] The first request information is used to indicate the first model corresponding to the first task and the first sample corresponding to the first task. For example, the first request information includes the name of the first model or the identifier of the first model, and the first sample.

[0169] In the present application, the trusted module may be the trusted module 201 shown in FIG. 2A .

[0170] In one possible implementation, after receiving the first request information, the trusted module determines whether the first sample is an adversarial sample based on the first model. Specifically, the trusted module may perturb the input within a certain range and determine whether the first sample is an adversarial sample based on the degree of change in the output of the first model. Specifically, if the change in the output of the first model exceeds a preset threshold, the trusted module determines that the first sample is in an unstable region of the model and identifies the first sample as an adversarial sample; if the sample is in a stable region of the first model, the trusted module determines that the first sample is a non-adversarial sample.

[0171] Optionally, the trusted module obtains the robustness requirement of the first task, and the robustness requirement of the first task indicates the need to detect whether the sample corresponding to the first task is an adversarial sample. In this way, the trusted module can determine whether it is necessary to detect whether the sample corresponding to the first task is an adversarial sample based on the acquired robustness requirement of the first task. For example, the management module sends the robustness requirement of the first task to the trusted module. Correspondingly, the trusted module can receive the robustness requirement of the first task from the management module. It should be understood that different models can have different unstable areas, so the robustness requirements corresponding to different models of the same task can be the same or different. The robustness requirements corresponding to different tasks can be the same or different.

[0172] It is understandable that the robustness requirement of the first task may also indicate that there is no need to detect whether the first sample corresponding to the first task is an adversarial sample, and the trusted module does not detect whether the first sample is an adversarial sample.

[0173] Optionally, the robustness requirement of the first task also indicates the robustness requirement of the output result of the first model corresponding to the first task. For example, the robustness requirement of the first task may include a first threshold. The first threshold is a threshold for determining whether the first sample is in an unstable region of the first model. In this way, the trusted module can determine whether the first sample is an adversarial sample based on the first model and the robustness requirement.

[0174] In one possible implementation, the robustness requirement of the output result of the first model corresponding to the first task can be quantified by the above-mentioned first threshold. Specifically, the above-mentioned trusted module perturbs the input of the first sample, and determines whether the first sample is an adversarial sample based on whether the change in the output of the first model is greater than or equal to the first threshold. It can be understood that the lower the robustness requirement, the larger the first threshold, that is, the lower the standard for the trusted module to judge the first sample as an adversarial sample; the higher the robustness requirement, the smaller the first threshold, that is, the higher the standard for the trusted module to judge the first sample as an adversarial sample, the easier it is for the first sample to fall into the unstable area of ​​the first model, and the easier it is for the first sample to be judged as an adversarial sample compared to the scenario with low robustness requirements.

[0175] S403: When the first sample is an adversarial sample of the first model, the trusted module sends the execution strategy of the first task to the reasoning module. Correspondingly, the reasoning module receives the execution strategy of the first task from the trusted module.

[0176] In this application, the execution strategy of the first task indicates the method for changing the first sample to a non-adversarial sample. For example, the method includes: replacing the first model; or replacing the first sample; or performing a first operation on the first sample. The first operation includes at least one of the following: feature compression, sample denoising, or data smoothing.

[0177] In one possible implementation, the trusted module obtains first indication information. The first indication information is used to indicate whether the first task has a backup sample, and / or the first indication information is used to indicate whether the first task has a backup model. For example, the reasoning module sends the first indication information to the trusted module. Correspondingly, the trusted module receives the first indication information from the reasoning module. In this way, the trusted module can determine the execution strategy of the first task based on the first indication information. Optionally, before the reasoning module sends the first indication information to the trusted module, the management module can send fourth indication information to the reasoning module. The fourth indication information can indicate whether the first task has a backup model. In this way, the reasoning module can send the first indication information to the trusted module after receiving the fourth indication information.

[0178] In one possible design, the first indication information may include the ID of the backup model to indicate to the trusted module that there is a backup model for the first task. Specifically, the backup model may be a different version of the first model, or the input or output of the backup model may be similar to that of the first model, but the internal implementation of the backup model may be different from that of the first model. For example, taking the model of the load balancing use case as an example, the relationship between the backup model and the first model is explained: the input of the backup model and the input of the first model (such as the first sample) may both include RAN node resource usage, terminal performance data, neighboring node resource usage and corresponding terminal performance, but the algorithm for load balancing of the backup model is different from that of the first model. For example, a RAN node may obtain the model of the load balancing use case deployed by other RAN nodes from other RAN nodes other than the RAN node, and use the obtained model as the backup model for the first task.

[0179] It is understandable that the content indicated by the first instruction information is different, and the execution strategy of the first task indicates a different way of changing the first sample to a non-adversarial sample.

[0180] In Design 1, if the first instruction information indicates that the first task has a backup sample, the execution strategy of the first task instructs the first sample to be replaced. In other words, if the first instruction information indicates that the first task has a backup sample, the trusted module can instruct the reasoning module to replace the first sample with a non-adversarial sample.

[0181] In Design 2, if the first instruction information indicates that the first task has a backup model, the execution strategy of the first task instructs the first model to be replaced. In other words, if the first instruction information indicates that the first task has a backup model, the trusted module can instruct the inference module to change the first example to a non-adversarial example by replacing the first model.

[0182] It is understandable that the present application does not limit the number of backup models. When there are multiple backup models for the first task, the execution strategy of the first task may indicate all or part of the multiple backup models to indicate that model reasoning can be performed through these backup models. Optionally, the execution strategy of the first task may also include: a method for merging the reasoning results of multiple backup models, such as voting, weighted averaging, and other methods. For example, taking the first task as a classification task as an example to illustrate the voting method: voting may refer to the confidence of the results output after sample reasoning is performed on the first sample according to multiple backup models, and selecting the result with the highest confidence as the classification result of the first sample. For another example, taking the first task as a regression task as an example to illustrate the weighted averaging method: weighted averaging may refer to the numerical value of the results output after sample reasoning is performed on the first sample according to multiple backup models, and the numerical value after weighted averaging is used as the output result of the first task. Among them, the weight corresponding to the result output by each backup model may be preset, or the same, and this application does not limit it.

[0183] In one possible implementation, when the execution policy of the first task indicates replacing the first model, the inference module receives second indication information from a communication node, where the second indication information indicates a backup model for the first task. The communication node may be, for example, a RAN node adjacent to the RAN node where the first model is deployed, without limitation. For example, the second indication information includes the backup model for the first task. For another example, the second indication information includes the ID of the backup model for the first task. Based on the ID of the backup model, the inference module may obtain the backup model corresponding to the ID of the backup model from the management module.

[0184] Optionally, the reasoning module may request the communication node for a backup model of the first task, and the communication node sends the second indication information to the reasoning module based on the request of the reasoning module. Correspondingly, the reasoning module receives the second indication information from the communication node.

[0185] In another possible implementation, the inference module sends a first sample to a communication node. The communication node stores a backup model for the first task. After receiving the first sample, the communication node can input the first sample into the backup model for the first task to obtain an inference result, and then send the inference result to the inference module. Accordingly, the inference module receives the inference result from the communication node. The inference result indicates the result obtained by inference based on the first sample and the backup model for the first task. Exemplarily, the communication node is a RAN node adjacent to the RAN node deploying the first model.

[0186] It can be understood that the first task can correspond to one or more backup models. When the first task corresponds to one backup model or multiple backup models, and these backup models are deployed on a communication node, the reasoning module sends a first sample to this communication node to request the communication node to obtain the reasoning result of the backup model deployed on the communication node based on the first sample. When the first task corresponds to multiple backup models, and these multiple backup models are deployed on different communication nodes, the reasoning module can also send the first sample to the above-mentioned different communication nodes respectively to request each of the above-mentioned different communication nodes to obtain the reasoning result of the backup model deployed on each communication node based on the first sample.

[0187] In Design 3, if the first indication information indicates that there are no backup samples or backup models for the first task, the method for changing the first sample to a non-adversarial sample includes performing a first operation on the first sample. In other words, if the first indication information indicates that there are no backup samples or backup models for the first task, the trusted module may change the first sample to a non-adversarial sample by performing the first operation on the first sample.

[0188] It should be understood that if the first sample is determined to be an adversarial sample of the first model, using the first model to perform sample inference on the first sample is likely to cause the first model to infer an erroneous result. In order to avoid this situation, other samples can be used for sample inference. In the absence of a backup sample, one possible implementation method is that the trusted module can perform a first operation on the first sample to eliminate sample data that causes the first model to infer errors. For example, the trusted module can eliminate sample data that causes the first model to infer errors by performing feature compression, sample denoising, or data smoothing on the first sample, so that the sample obtained after performing the first operation is changed to a non-adversarial sample of the first model.

[0189] Optionally, the management module may instruct the management module on the specific method of the first operation (i.e., feature compression, sample denoising, or data smoothing). If the trusted module does not receive instructions from the management module on the specific method of the first operation, the trusted module may select an appropriate first operation based on the characteristics of the first sample. Alternatively, if the first task is a regression task, the first operation may be sample denoising or data smoothing, etc., without limitation.

[0190] Sample denoising removes noise from the sample. Noise refers to errors or outliers in the first sample. Removing noise can prevent it from misleading the first model. Feature compression removes redundant information by selecting categorical information or discriminant features from the data. Data smoothing processes first samples with severe data jitter to produce data samples with more stable values.

[0191] It is understood that Designs 1 through 3 above are merely examples of the correspondence between the first instruction information and the execution strategy of the first task. In specific applications, the first instruction information and the execution strategy of the first task may have other correspondences. For example, in Design 1 or Design 2, the method of changing the first sample to a non-adversarial sample can also be replaced by performing the first operation on the first sample.

[0192] Optionally, when the execution strategy of the first task indicates multiple items, the priorities of the execution strategies may be arranged in descending order as follows: replacing the first sample, replacing the first model, and performing the first operation on the first sample.

[0193] In addition to the above methods, the trusted module can determine the execution policy for the first task based on the first policy information. For example, the management module sends the first policy information to the trusted module, and the trusted module receives the first policy information from the management module. The first policy information indicates replacing the first model, replacing the first sample, or performing the first operation on the first sample.

[0194] Exemplarily, when the management module indicates to the trusted module through the first policy information that the execution strategy of the first task indicates replacing the first model, the trusted module receives the first indication information from the reasoning module which also indicates that the first task has a backup model. The trusted module can determine the execution strategy of the first task as replacing the first model.

[0195] Optionally, after determining the execution strategy for the first task, the trusted module may send the strategy to the reasoning module so that the reasoning module performs corresponding operations according to the strategy. Optionally, the execution strategy for the first task further indicates that the first sample is an adversarial sample.

[0196] Optionally, the execution strategy of the first task further indicates a sample obtained by performing the first operation on the first sample. If the trusted module can obtain multiple samples by performing the first operation on the first sample, the execution strategy of the first task may further indicate a method for merging the results obtained by the first model from performing inference on the multiple samples. The merging method may be voting, weighted averaging, etc. The specific method of voting or weighted averaging can be found in the explanation of the voting or weighted averaging process in Design 2 and will not be repeated here.

[0197] It is understood that when the trusted module determines that the first sample is a non-adversarial sample, this can also be indicated through the execution policy of the first task. For example, the execution policy of the first task can be an empty message so that the reasoning module knows that the first sample is a non-adversarial sample. When the trusted module determines that the first sample is a non-adversarial sample, the reasoning module can learn that the first sample is an adversarial sample and the method for changing the adversarial sample to a non-adversarial sample based on the execution policy of the first task.

[0198] It can be understood that if the execution strategy of the first task indicates that the first model should be replaced, the reasoning module can input the first sample into the backup model to perform model reasoning. If the execution strategy of the first task includes a method for merging the reasoning results of multiple backup models, the reasoning module can determine the reasoning results of multiple alternative models based on the method for merging the reasoning results of multiple backup models, and then determine the final output result based on the reasoning results of multiple alternative models. Exemplarily, the first task is taken as an example of a load balancing use case. If the execution strategy of the first task indicates that the first sample is an adversarial sample, the backup model includes backup model 1 and backup model 2, and the method for merging the reasoning results of backup model 1 and backup model 2 is voting, the reasoning module can input the first sample into backup model 1 and backup model 2 respectively for model reasoning, obtain the reasoning result of backup model 1 and the reasoning result of backup model 2, and take the cell load balancing solution with the least terminal scheduling as the final result. Alternatively, if the execution strategy of the first task indicates replacing the first model, the reasoning module can obtain the second model corresponding to the first task and request the trusted module to determine whether the first sample is an adversarial sample of the second model. For details, please refer to the corresponding descriptions in S407 to S408 below and will not be repeated here.

[0199] It can be understood that if the execution strategy of the first task indicates to replace the first sample, the reasoning module can obtain the second sample corresponding to the first task and request the trusted module to determine whether the second sample is an adversarial sample of the first model. For details, please refer to the corresponding descriptions in S405 to S406 below and will not be repeated here.

[0200] It will be understood that if the execution strategy of the first task instructs the execution of the first operation on the first sample and the sample obtained by performing the first operation on the first sample, the inference module may input the received sample into the first model for model inference. If multiple samples are obtained by performing the first operation on the first sample, and the execution strategy of the first task further instructs the method for merging the multi-sample inference results corresponding to the multiple samples, the inference module may input each sample into the first model and merge the results obtained by inference of the multiple samples according to the method.

[0201] Based on the method shown in Figure 4, if the first sample corresponding to the first task is an adversarial sample of the first model corresponding to the first task, the trusted module determines the execution strategy of the first task based on the first indication information, thereby changing the first sample to a non-adversarial sample, so that the model corresponding to the first task can output correct results, thereby reducing the error rate of model reasoning.

[0202] Optionally, in one possible implementation of the method shown in FIG4 , if the execution strategy of the first task instructs to replace the first sample, the trusted module may further obtain a second sample corresponding to the first task and determine whether the second sample is an adversarial sample based on the first model, so as to reduce the error rate of the first model inference. Specifically, as shown in FIG5 , the method shown in FIG4 further includes the following steps:

[0203] S404: The trusted module obtains a second sample corresponding to the first task.

[0204] In one possible implementation, when the trusted module determines that the first sample is an adversarial sample of the first model, the trusted module can obtain a second sample corresponding to the first task through the inference module. The second sample is a backup sample for the first task.

[0205] For example, using the beam management use case as the first task, the inference module learns, based on the execution strategy of the first task, that the first sample is an adversarial sample of the first model. After replacing the first sample, the inference module instructs the RAN node to collect sparse beam scanning results from the terminal. The RAN node then transmits the set of sparse beam scanning results (i.e., the second sample) fed back by the terminal to the inference module. Subsequently, the inference module can send the scanning results to the trusted module.

[0206] S405: The trusted module determines whether the second sample is an adversarial sample based on the first model.

[0207] The trusted module determines whether the second sample is an adversarial sample of the first model. If the second sample is a non-adversarial sample of the first model, the trusted module can indicate the result to the reasoning module, and the reasoning module can reason on the first sample according to the second model to obtain an inference result. If the second sample is an adversarial sample of the first model, the trusted module can re-determine the execution strategy of the first task (for example, the strategy is to replace other backup samples) and send the strategy to the reasoning module to reduce the error rate of the first model. The specific process can be referred to S403 and will not be repeated here.

[0208] Optionally, in one possible implementation of the method shown in FIG4 , if the execution strategy of the first task instructs to replace the first model, the trusted module may further obtain a second model corresponding to the first task and determine whether the first sample is an adversarial sample based on the second model, thereby reducing the error rate of the first model's reasoning. Specifically, as shown in FIG5 , the method shown in FIG4 further includes the following steps:

[0209] S406: The trusted module obtains a second model corresponding to the first task.

[0210] In one possible implementation, the trusted module may obtain the second model corresponding to the first task through the reasoning module, and the reasoning module may use the alternative model indicated by the management module in the fourth indication information as the second model.

[0211] S407: The trusted module determines whether the first sample is an adversarial sample based on the second model.

[0212] The specific process of the trusted module determining whether the first sample is an adversarial sample of the second model can be referred to S403 and will not be repeated here.

[0213] In one possible implementation, if the trusted module confirms that the first sample is a non-adversarial sample of the second model, the result can be indicated to the reasoning module, and the reasoning module can reason on the first sample according to the second model to obtain an inference result.

[0214] It is understood that if the trusted module confirms that the first sample is an adversarial sample of the second model and indicates this result to the reasoning module, if the reasoning module can obtain other backup models for the first task, it can continue to ask the trusted module to confirm whether the first sample is an adversarial sample of the other backup models for the first task. Optionally, the trusted module can also instruct the reasoning module to perform the first operation on the first sample; or if there is a backup sample of the second model, the trusted module can instruct the replacement of the first sample, without limitation.

[0215] The above description primarily describes the solution provided by this application from the perspective of the interaction between the trusted module and the reasoning module. Accordingly, this application also provides a communication device, which may be the trusted module in the above-described method embodiments, or a device containing the trusted module, or a component that can be used with the trusted module; alternatively, the communication device may be the reasoning module in the above-described method embodiments, or a device containing the reasoning module, or a component that can be used with the reasoning module. It will be understood that, in order to implement the aforementioned functions, the above-described trusted module or reasoning module, etc., includes hardware structures and / or software modules corresponding to the respective functions. Those skilled in the art will readily appreciate that, in conjunction with the various exemplary units and algorithmic operations described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0216] This application can divide the trusted module and the reasoning module into functional modules based on the above method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or software functional modules. It is understood that the division of modules in this application is schematic and is only a logical functional division. In actual implementation, other division methods may be used.

[0217] For example, FIG6 shows a schematic diagram of the structure of a communication device 60, where the functional modules are divided in an integrated manner. Communication device 60 includes an interface module 601 and a processing module 602. Interface module 601, also known as an interface unit, is configured to perform transceiver operations and may be, for example, an interface circuit, a transceiver, a transceiver, or a communication interface. Processing module 602, also known as a processing unit, is configured to perform operations other than transceiver operations and may be, for example, a processing circuit or a processor.

[0218] In some embodiments, the communication device 60 may further include a storage module (not shown in FIG. 6 ) for storing program instructions and data.

[0219] Exemplarily, the communication device 60 is used to implement the functions of the trusted module. The communication device 60 is, for example, the trusted module of the embodiment shown in FIG4 or the embodiment shown in FIG5.

[0220] The interface module 601 is configured to receive first request information, wherein the first request information is used to indicate a first model corresponding to a first task and a first sample corresponding to the first task. For example, the interface module 601 may be configured to execute S402.

[0221] Processing module 602 is configured to control interface module 601 to transmit an execution strategy for the first task when the first sample is an adversarial sample of the first model. The execution strategy for the first task indicates a method for changing the first sample to a non-adversarial sample. For example, processing module 602 may be configured to execute S403.

[0222] In a possible implementation, the first sample is changed into a non-adversarial sample by: replacing the first model; or replacing the first sample; or performing a first operation on the first sample.

[0223] In one possible implementation, the processing module 602 is further used to obtain first indication information, where the first indication information is used to indicate whether the first task has a backup sample and / or whether the first task has a backup model; and determine the execution strategy of the first task based on the first indication information.

[0224] In one possible implementation, the first indication information indicates that the first task has a backup sample, and the execution strategy of the first task indicates replacing the first sample; or, the first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates replacing the first model; the first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates performing a first operation on the first sample.

[0225] In a possible implementation manner, the first operation includes at least one of the following: feature compression, sample denoising, or data smoothing.

[0226] In a possible implementation, the execution strategy of the first task indicates replacing the first sample. The processing module 602 is further configured to obtain a second sample corresponding to the first task; and determine whether the second sample is an adversarial sample based on the first model.

[0227] In a possible implementation, the execution strategy of the first task indicates replacing the first model, and the processing module 602 is further configured to obtain a second model corresponding to the first task; and determine whether the first sample is an adversarial sample based on the second model.

[0228] In a possible implementation, the processing module 602 is further configured to receive first policy information, where the first policy information indicates an execution policy of the first task.

[0229] In one possible implementation, the processing module 602 is further used to obtain the robustness requirement of the first task, where the robustness requirement of the first task indicates that it is necessary to detect whether the first sample corresponding to the first task is an adversarial sample; the processing module 602 is further used to determine whether the first sample is an adversarial sample based on the first model.

[0230] In one possible implementation, the robustness requirement of the first task also indicates the robustness requirement of the output result of the first model corresponding to the first task; the processing module 602 is specifically used to determine whether the first sample is an adversarial sample based on the first model and the robustness requirement.

[0231] When used to implement the function of the trusted module, regarding other functions that the communication device 60 can implement, reference can be made to the relevant introduction of the embodiment shown in FIG4 or the embodiment shown in FIG5 , and no further details will be given.

[0232] Alternatively, illustratively, the communication device 60 is used to implement the function of the reasoning module. The communication device 60 is, for example, the reasoning module of the embodiment shown in FIG4 or the embodiment shown in FIG5.

[0233] The processing module 602 is configured to obtain a first sample of the first task. For example, the processing module 602 may be configured to execute S401.

[0234] The interface module 601 is configured to send a first request message, wherein the first request message indicates a first sample of a first task and a first model of the first task. For example, the interface module 601 may be configured to execute S402.

[0235] The interface module 601 is further configured to receive an execution strategy of the first task, where the execution strategy of the first task indicates a method for changing the first sample into a non-adversarial sample. For example, the interface module 601 may be configured to execute S403.

[0236] In a possible implementation, changing the first sample to a non-adversarial sample includes: replacing the first model; or replacing the first sample; or performing a first operation on the first sample.

[0237] In one possible implementation, the interface module 601 is further used to send first indication information, where the first indication information is used to indicate whether the first task has a backup sample, and / or the first indication information is used to indicate whether the first task has a backup model, and the first indication information is used to determine the execution strategy of the first task.

[0238] In one possible implementation, the first indication information indicates that the first task has a backup sample, and the execution strategy of the first task indicates replacing the first sample; or, the first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates replacing the first model; the first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates performing a first operation on the first sample.

[0239] In a possible implementation manner, the first operation includes at least one of the following: feature compression, sample denoising, or data smoothing.

[0240] In a possible implementation, the execution strategy of the first task indicates replacing the first model. The interface module 601 is further configured to receive second indication information from the communication node, where the second indication information is configured to indicate a backup model for the first task.

[0241] In one possible implementation, the execution strategy of the first task indicates replacing the first model, and the interface module 601 is also used to send the first sample to the communication node; the interface module 601 is also used to receive the inference result from the communication node, and the inference result is used to indicate the result obtained by reasoning based on the first sample and the backup model of the first task.

[0242] In a possible implementation, the interface module 601 is further configured to receive a robustness requirement of the first task, where the robustness requirement of the first task indicates that it is necessary to detect whether a sample corresponding to the first task is an adversarial sample.

[0243] In a possible implementation, the robustness requirement of the first task also indicates a robustness requirement of an output result of the model of the first task.

[0244] In a possible implementation, the execution strategy of the first task is further used to indicate that the first sample is an adversarial sample.

[0245] When used for the function of the inference module, regarding other functions that the communication device 60 can implement, reference can be made to the relevant introduction of the embodiment shown in FIG4 or FIG5 , and no further details will be given.

[0246] In a simple embodiment, those skilled in the art can imagine that the communication device 60 can be in the form shown in Figure 3. For example, the processor 301 in Figure 3 can call the computer-executable instructions stored in the memory 303 to enable the communication device 60 to execute the method described in the above embodiment.

[0247] Exemplarily, the functions / implementation processes of the interface module 601 and the processing module 602 in FIG6 can be implemented by the processor 301 in FIG3 calling computer-executable instructions stored in the memory 303. Alternatively, the functions / implementation processes of the processing module 602 in FIG6 can be implemented by the processor 301 in FIG3 calling computer-executable instructions stored in the memory 303, and the functions / implementation processes of the interface module 601 in FIG6 can be implemented by the communication interface 304 in FIG3.

[0248] It is understandable that one or more of the above modules or units can be implemented by software, hardware or a combination of the two. When any of the above modules or units is implemented by software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built into an SoC (system on chip) or an ASIC, or it can be an independent semiconductor chip. In addition to the core used to execute software instructions to perform calculations or processing within the processor, it can further include necessary hardware accelerators, such as field programmable gate arrays (FPGAs), PLDs (programmable logic devices), or logic circuits that implement dedicated logic operations.

[0249] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a digital signal processing (DSP) chip, a microcontroller unit (MCU), an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.

[0250] Optionally, the present application also provides a chip system, comprising: at least one processor and an interface, wherein the at least one processor is coupled to a memory via the interface, and when the at least one processor executes a computer program or instruction in the memory, the method in any of the above method embodiments is executed. In one possible implementation, the chip system also includes a memory. Optionally, the chip system can be composed of a chip, or can include a chip and other discrete devices, which is not specifically limited in this application.

[0251] Optionally, the present application also provides a computer-readable storage medium. All or part of the processes in the above-mentioned method embodiments can be completed by a computer program to instruct the relevant hardware. The program can be stored in the above-mentioned computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned method embodiments. The computer-readable storage medium can be an internal storage unit of the communication device of any of the above-mentioned embodiments, such as a hard disk or memory of the communication device. The above-mentioned computer-readable storage medium can also be an external storage device of the above-mentioned communication device, such as a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc. equipped on the above-mentioned communication device. Furthermore, the above-mentioned computer-readable storage medium can also include both the internal storage unit of the above-mentioned communication device and an external storage device. The above-mentioned computer-readable storage medium is used to store the above-mentioned computer program and other programs and data required by the above-mentioned communication device. The above-mentioned computer-readable storage medium can also be used to temporarily store data that has been output or is to be output.

[0252] Optionally, the present application also provides a computer program product. All or part of the processes in the above method embodiments may be completed by a computer program instructing related hardware. The program may be stored in the above computer program product, and when executed, the program may include the processes in the above method embodiments.

[0253] Optionally, the present application also provides a computer instruction. All or part of the process in the above method embodiment can be completed by the computer instruction to instruct the relevant hardware (such as a computer, processor, trusted module or reasoning module, etc.). The program can be stored in the above computer-readable storage medium or in the above computer program product.

[0254] Optionally, the present application further provides a communication system, comprising: the trusted module and the reasoning module in the above embodiment. Optionally, the communication system further comprises: a management module.

[0255] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0256] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0257] The units described as separate components may or may not be physically separate, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0258] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0259] The above is only a specific embodiment of the present application, but the scope of protection of this application is not limited to this. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for determining a task execution strategy, characterized in that: The method comprises: Receive first request information; the first request information is used to indicate a first model corresponding to a first task and a first sample corresponding to the first task; In the case where the first sample is an adversarial sample of the first model, an execution strategy of the first task is sent, where the execution strategy of the first task is used to indicate a method of changing the first sample to a non-adversarial sample.

2. The method according to claim 1, characterized in that The method of changing the first sample into a non-adversarial sample includes: Replace the first model; or, Replace the first sample; or, A first operation is performed on the first sample.

3. The method according to claim 1 or 2, characterized in that: The method further comprises: Acquire first indication information, where the first indication information is used to indicate whether the first task has a backup sample, and / or, the first indication information is used to indicate whether the first task has a backup model; An execution strategy for the first task is determined according to the first indication information.

4. The method according to claim 3, characterized in that The determining the execution strategy of the first task according to the first indication information includes: The first indication information indicates that the first task has a spare sample, and the execution strategy of the first task indicates to replace the first sample; or, The first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates replacing the first model; The first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates to perform a first operation on the first sample.

5. The method according to claim 2 or 4, characterized in that: The first operation includes at least one of the following: feature compression, sample denoising or data smoothing.

6. The method according to claim 2, 4 or 5, characterized in that: The execution strategy of the first task indicates to replace the first sample, and the method further includes: Acquire a second sample corresponding to the first task; Determine whether the second sample is an adversarial sample according to the first model.

7. The method according to claim 2, 4 or 5, characterized in that: The execution strategy of the first task indicates replacing the first model, and the method further includes: Obtaining a second model corresponding to the first task; Determine whether the first sample is an adversarial sample according to the second model.

8. The method according to claim 1 or 2, characterized in that: The method further comprises: First policy information is received, where the first policy information indicates an execution policy of the first task.

9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: Acquire a robustness requirement of the first task, where the robustness requirement of the first task indicates that it is necessary to detect whether the first sample corresponding to the first task is an adversarial sample; Determine whether the first sample is an adversarial sample according to the first model.

10. The method according to claim 9, characterized in that The robustness requirement of the first task further indicates the robustness requirement of an output result of the first model corresponding to the first task; The determining, according to the first model, whether the first sample is an adversarial sample includes: Determine whether the first sample is an adversarial sample according to the first model and the robustness requirement.

11. A method for determining a task execution strategy, characterized in that: The method comprises: Obtain a first sample of a first task; Sending first request information; the first request information indicates a first sample of the first task and a first model of the first task; An execution strategy of a first task is received, where the execution strategy of the first task indicates a method for changing the first sample into a non-adversarial sample.

12. The method according to claim 11, characterized in that The method of changing the first sample into a non-adversarial sample includes: Replace the first model; or, Replace the first sample; or, A first operation is performed on the first sample.

13. The method according to claim 11 or 12, characterized in that: The method further comprises: Sending first indication information, wherein the first indication information is used to indicate whether the first task has a backup sample, and / or the first indication information is used to indicate whether the first task has a backup model, and the first indication information is used to determine an execution strategy for the first task.

14. The method according to claim 13, characterized in that The first indication information indicates that the first task has a spare sample, and the execution strategy of the first task indicates to replace the first sample; or, The first indication information indicates that the first task has a backup model, and the execution strategy of the first task indicates replacing the first model; The first indication information indicates that the first task has neither a backup sample nor a backup model, and the execution strategy of the first task indicates to perform a first operation on the first sample.

15. The method according to claim 12 or 14, characterized in that The first operation includes at least one of the following: feature compression, sample denoising or data smoothing.

16. The method according to any one of claims 12 to 15, characterized in that: The execution strategy of the first task indicates replacing the first model, and the method further includes: Second indication information is received from a communication node, where the second indication information is used to indicate a backup model for the first task.

17. The method according to any one of claims 12 to 16, characterized in that: The execution strategy of the first task indicates replacing the first model, and the method further includes: sending the first sample to a communication node; An inference result is received from the communication node, where the inference result is used to indicate a result obtained by inference based on the first sample and the backup model of the first task.

18. The method according to any one of claims 11 to 17, characterized in that The method further comprises: A robustness requirement of the first task is received, where the robustness requirement of the first task indicates that it is necessary to detect whether a sample corresponding to the first task is an adversarial sample.

19. The method according to claim 18, characterized in that The robustness requirement of the first task also indicates the robustness requirement of the output result of the model of the first task.

20. The method according to any one of claims 11 to 19, characterized in that The execution strategy of the first task is also used to indicate that the first sample is an adversarial sample.

21. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 10, or comprises a unit or module for executing the method according to any one of claims 11 to 20.

22. A communication device, characterized in that: include: A processor, the processor is coupled to a memory, the memory is used to store programs or instructions, when the program or instructions are executed by the processor, the device executes the method as claimed in any one of claims 1 to 10, or executes the method as claimed in any one of claims 11 to 20.

23. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instructions are executed, the computer performs the method according to any one of claims 1 to 10 or the method according to any one of claims 11 to 20.

24. A computer program product, comprising computer program code, characterized in that: When the computer program code is executed on a computer, the computer is enabled to implement the method according to any one of claims 1 to 10 or the method according to any one of claims 11 to 20.

25. A communication system, characterized in that: include: An apparatus for performing the method according to any one of claims 1 to 10 and an apparatus for performing the method according to any one of claims 11 to 20.

Citation Information

Patent Citations

  • Adversarial sample detection method and device, computing equipment and computer storage medium

    CN110741388A

  • Automatic driving sensing method and device of vehicle, vehicle and storage medium

    CN115223127A

  • Defense method and device for resisting attack and electronic equipment

    CN115600107A

  • Adversarial sample detection method and device based on divide-and-conquer strategy

    CN116304923A

  • Method and apparatus for identifying adversarial sample to protect model security

    WO2021143478A1