Methods for ai / ML model detectability and watermarking
The WTRU's configuration and watermarking capabilities address the security and authenticity issues of AI/ML models by embedding and detecting watermarks, ensuring secure and reliable use.
Patent Information
- Application Number
- PCT/US2024/061768
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-12-23
- Publication Date
- 2025-07-03
AI Technical Summary
The security and authenticity of artificial intelligence (AI) and machine learning (ML) models are compromised by unauthorized access, theft, tampering, and unauthorized redistribution, leading to intellectual property theft and performance deterioration.
A wireless transmit/receive unit (WTRU) is equipped with a transceiver and processor to receive configuration information for AI/ML model inference and watermark extraction, detect trigger events, and transmit watermark information, embedding watermarks in model weights or activation functions using filtering and extraction functions.
Ensures the integrity and authenticity of AI/ML models by enabling secure detection and verification of their use, preventing unauthorized access and tampering, and maintaining model reliability.
Smart Images

Figure US2024061768_03072025_PF_FP_ABST
Abstract
Description
METHODS FOR AI / ML MODEL DETECTABILITY AND WATERMARKINGCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 615,011 , filed December 27, 2023, the contents of which are incorporated herein by reference.BACKGROUND
[0002] Use of artificial intelligence (Al) and machine learning (ML) enables a wide range of applications on various smart devices. However, concerns related to security and authenticity of various AI / ML models used in the applications have risen. In that, the use of the AI / ML models risks unauthorized access, theft, tampering of the AI / ML models, or tampering of data used by the AI / ML models. This may lead to incorrect or unreliable output of the AI / ML models or deterioration in performance of the AI / ML models. Additionally, unauthorized copying or redistribution of proprietary AI / ML models may lead to intellectual property (IP) theft Hence, integrity and authenticity of the AI / ML models is essential to maintain reliability and security of the smart devices and wireless networks.SUMMARY
[0003] In various embodiments, a wireless transmit / receive unit (WTRU) is provided. The WTRU includes a memory, a transceiver, and a processor. The transceiver is configured to receive, from a network, an artificial intelligence (Al) / machine learning (ML) model, first configuration information associated with performing an inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model. The transceiver is further configured to transmit watermark information to the network. The processor is configured to detect occurrence of at least one trigger event associated with the watermark. The processor is further configured to extract the watermark from the AI / ML model based on the at least one trigger event using at least the second configuration information. The processor is further configured to generate the watermark information indicative of the extracted watermark.
[0004] In various embodiments, a method used in a WTRU is provided. The method comprises receiving, from a network, an AI / ML model, first configuration information associated with performing an inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model. The method further comprises detecting occurrence of at least one trigger event related to the watermark. The method further comprises extracting the watermark from the AI / ML model based on the at least one trigger event using at least the second configuration information. The method further comprises transmitting, to the network, watermark information indicative of the extracted watermark
[0005] In an embodiment, the watermark is embedded in one or more of: one or more weights of the AI / ML model, or one or more activation functions of the AI / ML model.
[0006] In an embodiment, the WTRU applies a first input to the AI / ML model to generate an inference output based at least on the first configuration information. The WTRU applies a second input to the AI / ML model to generate the watermark information based at least on the second configuration information
[0007] In an embodiment, the inference output and the watermark information are generated and transmitted jointly.
[0008] In an embodiment, the inference output and the watermark information are generated and transmitted separately.
[0009] In an embodiment, the second configuration information is indicative of one or more of: a watermark type, a filtering configuration, a preprocessing configuration, or an extraction function configuration.
[0010] In an embodiment, the preprocessing configuration is indicative of one or more processes comprising: a float precision or a fixed-point precision, one or more floor functions or one or more ceiling functions, or one or more permutation patterns or one or more interleaving patterns.
[0011] In an embodiment, the filtering configuration is indicative of one or more of: one or more coordinates of the watermark, one or more coordinates of the one or more activation functions, or one or more threshold weights for selecting the one or more weights of the AI / ML model
[0012] In an embodiment, the extraction function configuration is indicative of one or more extraction functions comprising: a hash function, a statistical analysis of the inference output, a sign extraction function or a magnitude extraction function, a sign flipping function, or a value-based selection function or a thresholdbased selection function.
[0013] In an embodiment, the WTRU selects the one or more weights or the one or more activation functions of the AI / ML model based on the filtering configuration. The WTRU performs the one or more processes on the one or more weights or the one or more activation functions based on the preprocessing configuration. The WTRU extracts the watermark by applying the one or more extraction functions based on the extraction function configuration.
[0014] In an embodiment, detecting occurrence of the at least one trigger event comprises receiving, from the network, an indication of the at least one trigger event associated with one or more of: monitoring performance of the AI / ML model, updating the AI / ML model, or one or more network conditions.
[0015] In an embodiment, the watermark information is transmitted to the network using one or more of: a medium access control (MAC) control element (CE), a radio resource control (RRC) message, or a physical uplink control channel (PUCCH) etc.BRIEF DESCRIPTION OF THE DRAWINGS
[0016] A more detailed understanding may be had from the following description, given by way of example in conjunction with the accompanying drawings, wherein like reference numerals in the figures indicate like elements, and wherein:
[0017] FIG. 1A is a system diagram illustrating an example communications system in which one or more disclosed embodiments may be implemented;
[0018] FIG. 1 B is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that may be used within the communications system illustrated in FIG. 1A according to an embodiment;
[0019] FIG. 1C is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that may be used within the communications system illustrated in FIG. 1A according to an embodiment;
[0020] FIG. 1D is a system diagram illustrating a further example RAN and a further example CN that may be used within the communications system illustrated in FIG. 1A according to an embodiment;
[0021] FIG. 2 is a flow diagram of a method for extracting and reporting a watermark according to an embodiment;
[0022] FIG. 3 is a flow diagram of a method for input-based functional watermarking including joint inference and watermarking according to an embodiment;
[0023] FIG. 4 is a flow diagram of a method for input-based functional watermarking including separate inference and watermarking according to an embodiment;
[0024] FIG. 5 is a diagram of a system architecture according to an embodiment;
[0025] FIG. 6 is a diagram of joint inference and watermarking with implicit watermarking according to an embodiment; and
[0026] FIG. 7 is a diagram of separate inference and watermarking according to an embodiment.DETAILED DESCRIPTION
[0027] As discussed herein, one or more abbreviations in the following (non-exhaustive) list, shown in T able 1, may be used herein.Table 1
[0028] FIG. 1A is a diagram illustrating an example communications system 100 in which one or more disclosed embodiments may be implemented. The communications system 100 may be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 may enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 may employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), singlecarrier FDMA (SC-FDMA), zero-tail unique-word discrete Fourier transform Spread OFDM (ZT-UW-DFT-S- OFDM), unique word OFDM (UW-OFDM), resource block-filtered OFDM, filter bank multicarrier (FBMC), and the like.
[0029] As shown in FIG. 1A, the communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104, a core network (ON) 106, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though itwill be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a station (STA), may be configured to transmit and / or receive wireless signals and may include a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. Any of the WTRUs 102a, 102b, 102c and 102d may be interchangeably referred to as a UE.
[0030] The communications systems 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d to facilitate access to one or more communication networks, such as the CN 106, the Internet 110, and / or the other networks 112. By way of example, the base stations 114a, 114b may be a base transceiver station (BTS), a NodeB, an eNode B (eNB), a Home Node B, a Home eNode B, a next generation NodeB, such as a gNode B (gNB), a new radio (NR) NodeB, a site controller, an access point (AP), a wireless router, and the like. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.
[0031] The base station 114a may be part of the RAN 104, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC),relay nodes, and the like. The base station 114a and / or the base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be in licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum A cell may provide coverage for a wireless service to a specific geographical area that may be relatively fixed or that may change over time. The cell may further be divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in one embodiment, the base station 114a may include three transceivers, i.e., one for each sector of the cell. In an embodiment, the base station 114a may employ multiple-input multiple output (MIMO) technology and may utilize multiple transceivers for each sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.
[0032] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).
[0033] More specifically, as noted above, the communications system 100 may be a multiple access system and may employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 and the WTRUs 102a, 102b, 102c may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 116 using wideband CDMA (WCDMA). WCDMA may include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High-Speed Downlink (DL) Packet Access (HSDPA) and / or High-Speed Uplink (UL) Packet Access (HSUPA).
[0034] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).
[0035] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR Radio Access , which may establish the air interface 116 using NR.
[0036] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may implement LTE radio access and NR radio access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g , an eNB and a gNB).
[0037] In other embodiments, the base station 114a and the WTRUs 102a, 102b, 102c may implement radio technologies such as IEEE 802.11 (i.e , Wireless Fidelity (WiFi), IEEE 802.16 (i.e., WorldwideInteroperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.
[0038] The base station 114b in FIG 1A may be a wireless router, Home Node B, Home eNode B, or access point, for example, and may utilize any suitable RAT for facilitating wireless connectivity in a localized area, such as a place of business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a roadway, and the like. In one embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In an embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR etc.) to establish a picocell or femtocell. As shown in FIG. 1A, the base station 114b may have a direct connection to the Internet 110. Thus, the base station 114b may not be required to access the Internet 110 via the CN 106.
[0039] The RAN 104 may be in communication with the CN 106, which may be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 may provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in FIG. 1 A, it will be appreciated that the RAN 104 and / or the CN 106 may be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 or a different RAT. For example, in addition to being connected to the RAN 104, which may be utilizing a NR radio technology, the CN 106 may also be in communication with another RAN (not shown) employing a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or WiFi radio technology.
[0040] The CN 106 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or the other networks 112. The PSTN 108 may include circuit-switched telephone networks that provide plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices that use common communication protocols, such as the transmission control protocol (TCP), user datagram protocol (UDP) and / or the internet protocol (IP) in the TCP / IP internet protocol suite. The networks 112 may include wired and / or wireless communications networks owned and / or operated by other service providers. For example, the networks 112 may include another CN connected to one or more RANs, which may employ the same RAT as the RAN 104 or a different RAT.
[0041] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers forcommunicating with different wireless networks over different wireless links). For example, the WTRU 102c shown in FIG. 1 A may be configured to communicate with the base station 114a, which may employ a cellularbased radio technology, and with the base station 114b, which may employ an IEEE 802 radio technology.
[0042] FIG. 1 B is a system diagram illustrating an example WTRU 102. As shown in FIG. 1 B, the WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other peripherals 138, among others. It will be appreciated that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.
[0043] The processor 118 may be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), any other type of integrated circuit (IC), a state machine, and the like. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. 1 B depicts the processor 118 and the transceiver 120 as separate components, it will be appreciated that the processor 118 and the transceiver 120 may be integrated together in an electronic package or chip.
[0044] The transmit / receive element 122 may be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in one embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.
[0045] Although the transmit / receive element 122 is depicted in FIG. 1 B as a single element, the WTRU 102 may include any number of transmit / receive elements 122. More specifically, the WTRU 102 may employ MIMO technology. Thus, in one embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.
[0046] The transceiver 120 may be configured to modulate the signals that are to be transmitted by the transmit / receive element 122 and to demodulate the signals that are received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11 , for example.
[0047] The processor 118 of the WTRU 102 may be coupled to, and may receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit) The processor 118 may also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 may access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 may include random-access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 may access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).
[0048] The processor 118 may receive power from the power source 134, and may be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 may be any suitable device for powering the WTRU 102. For example, the power source 134 may include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li- ion), etc.), solar cells, fuel cells, and the like.
[0049] The processor 118 may also be coupled to the GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 may receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 may acquire location information by way of any suitable location-determination method while remaining consistent with an embodiment
[0050] The processor 118 may further be coupled to other peripherals 138, which may include one or more software and / or hardware modules that provide additional features, functionality and / or wired or wireless connectivity. For example, the peripherals 138 may include an accelerometer, an e-compass, a satellite transceiver, a digital camera (for photographs and / or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a Virtual Reality and / or Augmented Reality (VR / AR) device, an activity tracker, and the like. The peripherals 138 may include one or more sensors. The sensors may be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor; a geolocation sensor, an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, a humidity sensor and the like.
[0051] The WTRU 102 may include a full duplex radio for which transmission and reception of some or all of the signals (e g., associated with particular subframes for both the UL (e.g., for transmission) and DL (e.g.,for reception) may be concurrent and / or simultaneous. The full duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference via either hardware (e.g., a choke) or signal processing via a processor (e.g., a separate processor (not shown) or via processor 118). In an embodiment, the WTRU 102 may include a half-duplex radio for which transmission and reception of some or all of the signals (e.g., associated with particular subframes for either the UL (e g., for transmission) or the DL (e g., for reception)).
[0052] FIG. 1C is a system diagram illustrating the RAN 104 and the ON 106 according to an embodiment. As noted above, the RAN 104 may employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.
[0053] The RAN 104 may include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 may include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the eNode-Bs 160a, 160b, 160c may implement MIMO technology. Thus, the eNode-B 160a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a.
[0054] Each of the eNode-Bs 160a, 160b, 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, and the like. As shown in FIG. 1 C, the eNode-Bs 160a, 160b, 160c may communicate with one another over an X2 interface.
[0055] The CN 106 shown in FIG. 1C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166. While the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0056] The MME 162 may be connected to each of the eNode-Bs 162a, 162b, 162c in the RAN 104 via an S1 interface and may serve as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA
[0057] The SGW 164 may be connected to each of the eNode Bs 160a, 160b, 160c in the RAN 104 via the S1 interface. The SGW 164 may generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring user planes during inter-eNode B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.
[0058] The SGW 164 may be connected to the PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.
[0059] The CN 106 may facilitate communications with other networks For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional land-line communications devices. For example, the CN 106 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers.
[0060] Although the WTRU is described in FIGS. 1A-1 D as a wireless terminal, it is contemplated that in certain representative embodiments that such a terminal may use (e.g., temporarily or permanently) wired communication interfaces with the communication network.
[0061] In representative embodiments, the other network 112 may be a WLAN.
[0062] A WLAN in Infrastructure Basic Service Set (BSS) mode may have an Access Point (AP) for the BSS and one or more stations (STAs) associated with the AP. The AP may have access or an interface to a Distribution System (DS) or another type of wired / wireless network that carries traffic in to and / or out of the BSS. Traffic to STAs that originates from outside the BSS may arrive through the AP and may be delivered to the STAs. Traffic originating from STAs to destinations outside the BSS may be sent to the AP to be delivered to respective destinations. Traffic between STAs within the BSS may be sent through the AP, for example, where the source STA may send traffic to the AP and the AP may deliver the traffic to the destination STA The traffic between STAs within a BSS may be considered and / or referred to as peer-to-peer traffic. The peer-to- peer traffic may be sent between (e.g., directly between) the source and destination STAs with a direct link setup (DLS). In certain representative embodiments, the DLS may use an 802.11e DLS or an 802.11z tunneled DLS (TDLS). A WLAN using an Independent BSS (IBSS) mode may not have an AP, and the STAs (e.g., all of the STAs) within or using the IBSS may communicate directly with each other. The IBSS mode of communication may sometimes be referred to herein as an “ad-hoc” mode of communication.
[0063] When using the 802.11 ac infrastructure mode of operation or a similar mode of operations, the AP may transmit a beacon on a fixed channel, such as a primary channel. The primary channel may be a fixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width. The primary channel may be the operating channel of the BSS and may be used by the STAs to establish a connection with the AP. In certain representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) may be implemented, for example in 802.11 systems. For CSMA / CA, the STAs (e.g., every STA), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by aparticular STA, the particular STA may back off. One STA (e.g., only one station) may transmit at any given time in a given BSS.
[0064] High Throughput (HT) STAs may use a 40 MHz wide channel for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadjacent 20 MHz channel to form a 40 MHz wide channel.
[0065] Very High Throughput (VHT) STAs may support 20MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels The 40 MHz, and / or 80 MHz, channels may be formed by combining contiguous 20 MHz channels. A 160 MHz channel may be formed by combining 8 contiguous 20 MHz channels, or by combining two noncontiguous 80 MHz channels, which may be referred to as an 80+80 configuration. For the 80+80 configuration, the data, after channel encoding, may be passed through a segment parser that may divide the data into two streams. Inverse Fast Fourier Transform (IFFT) processing, and time domain processing, may be done on each stream separately The streams may be mapped on to the two 80 MHz channels, and the data may be transmitted by a transmitting STA. At the receiver of the receiving STA, the above described operation for the 80+80 configuration may be reversed, and the combined data may be sent to the Medium Access Control (MAC).
[0066] Sub 1 GHz modes of operation are supported by 802.11 af and 802.11 ah. The channel operating bandwidths, and carriers, are reduced in 802.11af and 802.11ah relative to those used in 802.11n, and 802.11ac. 802.11 af supports 5 MHz, 10 MHz, and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, and 802.11 ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to a representative embodiment, 802.11 ah may support Meter Type Control / Machine- Type Communications (MTC), such as MTC devices in a macro coverage area. MTC devices may have certain capabilities, for example, limited capabilities including support for (e.g , only support for) certain and / or limited bandwidths The MTC devices may include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).
[0067] WLAN systems, which may support multiple channels, and channel bandwidths, such as 802 11 n, 802.11ac, 802.11af, and 802.11 ah, include a channel which may be designated as the primary channel. The primary channel may have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel may be set and / or limited by a STA, from among all STAs in operating in a BSS, which supports the smallest bandwidth operating mode. In the example of 802.11ah, the primary channel may be 1 MHz wide for STAs (e.g., MTC type devices) that support (e.g., only support) a 1 MHz mode, even if the AP, and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or Network Allocation Vector (NAV) settings may depend on the status of the primary channel. If the primary channel is busy, for example, due to a STA (which supports only a 1 MHz operating mode) transmitting to the AP, all available frequency bands may be considered busy even though a majority of the available frequency bands remains idle.
[0068] In the United States, the available frequency bands, which may be used by 802.11 ah, are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. The total bandwidth available for 802.11 ah is 6 MHz to 26 MHz depending on the country code.
[0069] FIG. 1 D is a system diagram illustrating the RAN 104 and the GN 106 according to an embodiment. As noted above, the RAN 104 may employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also be in communication with the CN 106.
[0070] The RAN 104 may include gNBs 180a, 180b, 180c, though it will be appreciated that the RAN 104 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the gNBs 180a, 180b, 180c may implement MIMO technology. For example, gNBs 180a, 108b may utilize beamforming to transmit signals to and / or receive signals from the gNBs 180a, 180b, 180c. Thus, the gNB 180a, for example, may use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum while the remaining component carriers may be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c may implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a may receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).
[0071] The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using transmissions associated with a scalable numerology. For example, the OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using subframe or transmission time intervals (TTIs) of various or scalable lengths (e.g., containing a varying number of OFDM symbols and / or lasting varying lengths of absolute time).
[0072] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standalone configuration, WTRUs 102a, 102b, 102c may utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, WTRUs 102a, 102b, 102c may communicate with gNBs 180a, 180b, 180c using signals in an unlicensed band. In a non-standalone configuration WTRUs 102a, 102b, 102c may communicate with / connect to gNBs 180a, 180b, 180c while also communicating with / connecting to another RAN such as eNode-Bs 160a, 160b, 160c. For example, WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNode-Bs 160a, 160b, 160c substantially simultaneously. In the non- standalone configuration, eNode-Bs 160a, 160b, 160c may serve as a mobility anchor for WTRUs 102a, 102b,102c and gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for servicing WTRUs 102a, 102b, 102c.
[0073] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, DC, interworking between NR and E-UTRA, routing of user plane data towards User Plane Function (UPF) 184a, 184b, routing of control plane information towards Access and Mobility Management Function (AMF) 182a, 182b and the like. As shown in FIG. 1D, the gNBs 180a, 180b, 180c may communicate with one another over an Xn interface.
[0074] The CN 106 shown in FIG. 1 D may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. While the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements may be owned and / or operated by an entity other than the CN operator.
[0075] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N2 interface and may serve as a control node. For example, the AMF 182a, 182b may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling of different protocol data unit (PDU) sessions with different requirements), selecting a particular SMF 183a, 183b, management of the registration area, termination of non-access stratum (NAS) signaling, mobility management, and the like. Network slicing may be used by the AMF 182a, 182b in order to customize CN support for WTRUs 102a, 102b, 102c based on the types of services being utilized WTRUs 102a, 102b, 102c. For example, different network slices may be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for MTC access, and the like The AMF 182a, 182b may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.
[0076] The SMF 183a, 183b may be connected to an AMF 182a, 182b in the CN 106 via an N11 interface. The SMF 183a, 183b may also be connected to a UPF 184a, 184b in the CN 106 via an N4 interface. The SMF 183a, 183b may select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 184b. The SMF 183a, 183b may perform other functions, such as managing and allocating UE IP address, managing PDU sessions, controlling policy enforcement and QoS, providing DL data notifications, and the like. A PDU session type may be IP-based, non-IP based, Ethernet-based, and the like.
[0077] The UPF 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184, 184b may perform other functions, such as routing and forwarding packets,enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering DL packets, providing mobility anchoring, and the like.
[0078] The ON 106 may facilitate communications with other networks For example, the CN 106 may include, or may communicate with, an IP gateway (e.g., an IP multimedia subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which may include other wired and / or wireless networks that are owned and / or operated by other service providers In one embodiment, the WTRUs 102a, 102b, 102c may be connected to a local DN 185a, 185b through the UPF 184a, 184b via the N3 interface to the UPF 184a, 184b and an N6 interface between the UPF 184a, 184b and the DN 185a, 185b.
[0079] In view of FIGs. 1A-1 D, and the corresponding description of FIGs. 1A-1 D, one or more, or all, of the functions described herein with regard to one or more of: WTRU 102a-d, Base Station 114a-b, eNode-B 160a-c, MME 162, SGW 164, PGW 166, gNB 180a-c, AMF 182a-b, UPF 184a-b, SMF 183a-b, DN 185a-b, and / or any other device(s) described herein, may be performed by one or more emulation devices (not shown). The emulation devices may be one or more devices configured to emulate one or more, or all, of the functions described herein. For example, the emulation devices may be used to test other devices and / or to simulate network and / or WTRU functions.
[0080] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or in an operator network environment. For example, the one or more emulation devices may perform the one or more, or all, functions while being fully or partially implemented and / or deployed as part of a wired and / or wireless communication network in order to test other devices within the communication network. The one or more emulation devices may perform the one or more, or all, functions while being temporarily implemented / deployed as part of a wired and / or wireless communication network The emulation device may be directly coupled to another device for purposes of testing and / or performing testing using over-the-air wireless communications.
[0081] The one or more emulation devices may perform the one or more, including all, functions while not being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulation devices may be utilized in a testing scenario in a testing laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement testing of one or more components. The one or more emulation devices may be test equipment. Direct RF coupling and / or wireless communications via RF circuitry (e.g., which may include one or more antennas) may be used by the emulation devices to transmit and / or receive data.
[0082] In various embodiments of the present disclosure, one or more methods, systems and / or techniques are provided for detecting one or more artificial intelligence (Al) and / or machine learning (ML) models (simply referred to as “AI / ML”), for AI / ML watermarking, and / or for multi-vendor AI / ML interoperability.
[0083] In an embodiment, a WTRU may receive a trigger for reporting watermark information associated with an AI / ML model, determine the watermark information in response to the trigger, and transmit the determined watermark information.
[0084] In an embodiment, a WTRU may receive one or more of: a proprietary AI / ML model, first configuration information, and / or second configuration information. The first configuration information may be associated with an inference. The second configuration information may be associated with a watermark extraction. The WTRU may also receive the trigger indicative of transmitting and / or reporting the watermark information. The WTRU may extract a watermark from the AI / ML model based on at least one of the first configuration information or the second configuration information. The WTRU may report (e g., transmit) the watermark information.
[0085] In an embodiment, a WTRU may receive a first-part configuration (and / or the first configuration information) and a second-part configuration (and / or the second configuration information). The first-part configuration may be associated with the inference and the second-part configuration may be associated with the watermark. The WTRU may also receive and / or determine a first-part input (e.g , a first input) and / or a second-part input (e.g., a second input). The WTRU may apply the first-part input (e.g., the first input) and / or the second-part input (e.g., the second input) to the AI / ML model to determine a first output and a second output. The second output may be a function of the first-part input (e.g., the first input), the second-part input (e g., the second input), and the AI / ML model. The WTRU may report and / or transmit the watermark information based on the second output.
[0086] For one or more WTRUs supporting one or more proprietary AI / ML models (e.g., intra-vendor and / or inter-vendor AI / ML models etc.), the present disclosure describes various embodiments of one or more methods, systems, and / or techniques for watermarking the one or more proprietary AI / ML models. In an embodiment, a method for the detection of the use of the one or more proprietary AI / ML models is provided. In an embodiment, a method for enabling watermark filtering, extraction, pre-processing, and / or reporting is provided. In an embodiment, a method for input-based functional watermarking and / or verification is provided.
[0087] Al may be broadly defined as a behavior exhibited by a machine. The behavior may, e.g , mimic one or more cognitive functions such as but not limited to sensing, reasoning, adapting, and / or acting.
[0088] ML may refer to multiple classes of algorithms and / or techniques that solve a problem based on learning through an experience (i.e. data), without explicitly being programmed (i.e. configuring a set of rules). ML may be considered as a subset of Al. Different ML paradigms may be envisioned based on nature of the data and / or a feedback available to a learning algorithm. In an example, a supervised learning approach may involve learning a function that maps an input to an output based on a set of labelled training examples, wherein each training example may be a pair of an input and a corresponding output. In an example, an unsupervised learning approach may involve detecting one or more patterns in the data with no pre-existing labels. In an example, a reinforcement learning approach may involve performing a sequence of actions in an environmentto maximize a cumulative reward. In some examples, it may be possible to apply one or more ML algorithms using a combination and / or interpolation of above-mentioned approaches. In an example, a semi-supervised learning approach may utilize a combination of a small amount of labelled data with a large amount of unlabeled data during the training. In this, the semi-supervised learning may fall between the unsupervised learning (i.e. with no labelled training data) and the supervised learning (i.e. with only labelled training data).
[0089] Deep learning (DL) may refer to a class of ML algorithms that employ artificial neural networks (specifically deep neural networks (DNNs)), which may be loosely inspired from various biological systems. The DNNs are a special class of ML models inspired by a human brain wherein an input is linearly transformed and passed through one or more non-linear activation functions multiple times. The DNNs include multiple layers where each layer includes a linear transformation and multiple non-linear activation functions. The DNNs may be trained using training data via a back-propagation algorithm. The DNNs may be utilized in a variety of domains, e.g., speech, vision, and / or natural language, etc. and for various ML settings including supervised, un-supervised, and / or semi-supervised settings. The AI / ML-based methods and / or processes may refer to a realization of one or more behaviors and / or conformance to one or more requirements by learning based on the data, without explicit configuration of a sequence of steps of actions. The AI / ML based methods may enable learning one or more complex behaviors that may be difficult to specify and / or implement using legacy methods.
[0090] In an AI / ML model transfer, an entity and / or a node that trains the AI / ML model (e.g., a training entity and / or a training node) may be different from an entity and / or a node that may use the AI / ML model for the inference (e.g., an inference entity and / or an inference node). For a purpose of deployment, the AI / ML model may be stored in an entity and / or a node (e.g., a storage entity and / or a storage node) before the AI / ML model is delivered to the inference entity and / or the inference node. The AI / ML model transfer may refer to a delivery of the AI / ML model from the training entity, the training node, the storage entity, and / or the storage node to the inference entity and / or the inference node. The AI / ML model transfer may also refer to the delivery of the AI / ML model from the training entity and / or the training node to the storage entity and / or the storage node. In an example, one or more of the training entity and / or the training node, the storage entity and / or the storage node, and / or the inference entity and / or the inference node may belong to different vendors and / or manufacturers. In an example, the entity and / or the node may refer to a WTRU, a gNB, a location management function (LMF), a network data analytics function (NWDAF), a core network function, and / or a logical function described for one or more AI / ML operations. Different options for the AI / ML model transfer may be considered based on a signaling format, a model format, a model storage location, and / or a model training location. In an example, the signaling format may be over-the-top, implementation based, and / or standardized signaling. In an example, the model transfer may use one or more of RRC signaling, non-access stratum (NAS) signaling, LTE positioning protocol (LPP) signaling, and / or user plane (UP) data, etc. In an example, the model storage location may be outside of the 3GPP network or inside of the 3GPP network. In an example, the training location may be a WTRU-side, a NW-side, and / or a neutral (and / or 3rd party) site etc. In an example, the AI / ML models may be transferred in a proprietary format, an open format, and / or a 3GPP defined format. The AI / ML model transfermay be beneficial to handle a site, a scenario, and / or a configuration specific model when a single AI / ML model cannot generalize well to multiple scenarios, configurations, and / or sites etc.
[0091] For the proprietary AI / ML models, there exist many practical issues and / or aspects of deploying the AI / ML models that are related to the proprietary AI / ML models. A proprietary AI / ML model is a AI / ML model of which implementation may be protected by an intellectual property (IP) of an owner and / or a vendor. The method may be applied to the AI / ML models at the WTRU side, where the owner of the proprietary AI / ML model is a different vendor, and the method may also be applied to one or more one-sided AI / ML models as well one or more two-sided AI / ML models, e.g., an autoencoder (AE) [RSJ1]in which the encoder is shared with the WTRU
[0092] Furthermore, there may be various considerations related to the proprietary AI / ML models, including a security aspect of sharing the proprietary AI / ML models, the detectability of the inference by the owner, preventing model stealing, and / or model forging etc.
[0093] In an example, the method may be implemented in 5G NR to manage complex use-cases intelligently, address one or more system-optimization problems, and / or improve user experience in 5G system and beyond. In an example, in the RAN domain, a functional framework for Al-enabled RAN intelligence may be provided. The framework for the Al-enabled intelligence may be used for several use cases and / or embodiments such as but not limited to network energy saving, load balancing, and / or mobility optimization etc.
[0094] Various use cases may be implemented in 3GPP, such as but not limited to CSI feedback enhancement, beam management (BM), and / or positioning etc. However, there are many practical open issues and challenges in conventional 3GPP systems to make an AI / ML framework fully functional, for different (existing and future) use cases. In that, a challenge faced by the conventional 3GPP systems is related to proprietary and multi-vendor AI / ML models. For example, the AI / ML models may not generalize across different WTRU and / or network (NW) vendors, scenarios, sites, configurations, and other implementation considerations. As a result, there is a need to train the AI / ML models at the NW or by a third party before transferring to the WTRU for the inference. To help ensure the security and proprietorship of the AI / ML models from different vendors (e.g., the NW vendors, operators and / or the third party etc.), the AI / ML model typically would be acquired by legitimate means, thus enabling the WTRU to prove and verify the access to the AI / ML models. Additionally, an attacker may be able to tamper with the AI / ML models, thus leading to undesirable behavior by the WTRU and affecting not only this specific WTRU, but degrading the NW performance in general. Therefore, there is a need for secure sharing and detection of the use of the proprietary AI / ML models. Various embodiments of the present disclosure provide one or more of: the secure sharing and detection of the proprietary AI / ML models; the verification for the transfer of and / or access to a proprietary model identifier (ID); the detectability of the proprietary AI / ML model use; prevention of the risks of model sharing between nonlegitimate and / or unverified devices and / or vendors etc.; security for the proprietary AI / ML models, e.g., againstmodel stealing and model forging; and / or protection the proprietary AI / ML models from attacks and model tampering etc
[0095] FIG. 2 is a flow diagram of a method for extracting and reporting a watermark according to one or more embodiments. The method may be performed by the WTRU The WTRU may receive a proprietary AI / ML model and first configuration information for an inference and second configuration information for a watermark extraction.
[0096] At 210, the WTRU receives a trigger to transmit the watermark information. The WTRU receives the proprietary AI / ML model from the NW. In that, one or more items of watermark information may be embedded in the (subset) model weights and / or activation functions.
[0097] In an example, the watermark information may indicate that after training, the model weights are pruned and / or modified (e.g., with a sign flip, by multiplying them by a factor, and / or by adding biases etc ).
[0098] In an example, the watermark information may indicate that during training, the loss function may have a regularizer such that the watermark is enforced and captured on a set of weights, and / or the regularizer that enforces one or more pre-defined statistical distributions on the set of weights.
[0099] In an example, the watermark information may be embedded in one or more activation functions that output one or more pre-defined values when triggered by a preconfigured bit-string and / or a sequence header etc.
[0100] In an example, a position (i.e., a depth) of one or more indexed activation functions may represent the watermark.
[0101] In an example, the watermark may be based on a WTRU request and / or may be NW initiated.
[0102] The WTRU may receive first configuration information for the inference and second configuration information for the watermark information extraction. The configuration (e g., the second configuration information) for the watermark extraction may include one or more of: a watermark type, a filtering configuration, a preprocessing configuration and / or an extraction function configuration etc. The watermark type may indicate whether the watermark is embedded in the one or more weights and / or embedded in one or more activation functions etc. The filtering configuration may include one or more of: one or more coordinates of the watermark (e g., one or more depths and / or positions of weights etc.); one or more coordinates of the embedded function; and / or one or more magnitude thresholds (e.g., one or more threshold weights) associated with selection of the subset of weights (e.g., a maximum threshold and / or a minimum threshold). The preprocessing configuration may include one or more of: one or more float and / or fixed point precision For instance, the WTRU may be configured with a specific float precision, e g., half (binary16), single (binary32), double (binary64), and / or binaryl 28, etc. The WTRU may be configured with a specific fixed-point precision, e.g., a float number (e g., a weight) may be represented by an integer multiplied by a fixed scaling factor. The preprocessing configuration may include a floor function and / or a ceiling function. For instance, the WTRU may be configured with a specific floor and / or ceiling function, e.g., one or more maximum and / or minimal thresholds(e g., maximum and / or minimum threshold weights etc.) may be configured, such that the filtered values may be replaced with the one or more maximum and / or minimum thresholds if the one or more weights are above and / or below the threshold values associated with one or more configured ceiling and / or floor functions. The preprocessing configuration may include one or more permutation and / or interleaving patterns. For instance, the WTRU may be configured with a permutation described by a permutation vector and / or matrix.
[0103] In an example, the watermark extraction function configuration may include one or more of: a hash function (e.g., one or more inputs may be model and / or sub-model parameters and an output may be the extracted watermark etc.), one or more statistics (e.g., a probability density function (PDF) etc.) of one or more layers, sign and / or magnitude extraction function, sign-flipping function, and / or a value-based (and / or threshold-based) selection function etc.
[0104] The WTRU may receive the trigger to report the watermark information. The trigger may be based on one or more conditions determined by the WTRU. In an example, the trigger may be based on performance monitoring (e.g., short-term or long-term performance degradation based on a threshold performance). In an example, the trigger may be based on model selection and / or activation, finetuning, model update and / or transfer, and / or fallback to legacy etc The trigger may be based on one or more mobility events, for example, handover (HO), conditional handover (CHO), etc , upon failure event (e.g., beam failure), during initial access (e g., in msg3 or after RRC connection establishment), and / or during RRC state change (e.g., RRC resume) etc. The trigger may be based on reception of an indication, e.g., media access control (MAC) control element (CE) and / or aperiodic request and / or radio resource control (RRC) reconfiguration etc The trigger may be based on a reporting configuration, e.g., periodic reporting and / or aperiodic reporting at one or more predefined times or instances etc.
[0105] At 220, the WTRU determines the watermark according to the configuration (e.g., the second configuration information). The WTRU may select the one or more model weights and / or the one or more activation functions by applying filtering based on the filtering configuration. The WTRU may perform preprocessing by applying one or more preprocessing functions on the one or more selected weights and / or the one or more selected activation functions based on the preprocessing configuration. The WTRU may extract the watermark information by applying one or more extraction functions to one or more preprocessed quantities (e g., one or more preprocessed weights and / or one or more preprocessed activation functions etc.).
[0106] At 230, the WTRU reports i.e. transmits the watermark information. The WTRU may transmit the extracted watermark information to the NW For instance, the WTRU may transmit the extracted watermark using one or more of: the MAC CE, a physical uplink control channel (PUCCH), a RRC msg (e.g., WTRU assistance information (UAI), WTRU uplink (UL) information etc.) etc.
[0107] FIG. 3 is a flow diagram of a method for an input-based functional watermarking including joint inference / watermarking according to one or more embodiments. The method may be performed by the WTRU.
[0108] The WTRU may receive the first-part configuration and the second-part configuration. The first-part configuration may be associated with the inference and the second-part configuration may be associated with the watermark. The WTRU may apply the first part input and / or the second part input to the AI / ML model, determine the first output and the second output, and then report the watermark information and the inference output.
[0109] At 310, the WTRU may receive the AI / ML model (e.g., the proprietary AI / ML model) from the network. The reception of the AI / ML model (e.g , the proprietary AI / ML model) may be based on a request transmitted by the WTRU to the NW and / or may be initiated by the NW.
[0110] The WTRU may also receive the configuration for the inference. The configuration for the inference may include the first input part and the second input part. The first input part may be based on one or more measurements by the WTRU and / or one or more use case specific inputs, e.g., the channel matrix in case of a CSI compression.
[0111] The second input part may be based on a NW configuration and / or an indication. In an example, the second input part may be indicative of a preconfigured signature (and / or the second input may include the preconfigured signature). In an example, the second input may include and / or may be indicative of one or more of: a unique proprietary digital signature, a hash representing a proprietary WTRU vendor, a WTRU specific signature, and / or a vendor-specific signature etc. In an example, the second input part may include and / or may be indicative of a header or a bit-string sequence, for instance, e.g., a model-specific header with a pre-defined output, and / or a model-specific header as side information etc. In an example, the second input part may include and / or may be indicative of a pseudo-random sequence generated based on the NW configuration. In an example, the second input part may include and / or may be indicative of one or more coordinates of one or more specific output units associated with one or more layers, and / or the one or more coordinates of the one or more specific output units associated with one or more activation functions etc.
[0112] In an example, the configuration may include parameters (e.g., length) of the first input part and / or the second input part.
[0113] In an example, the configuration of the second input part may include further information associated with the second input part, e g., a length of the bit-string header, quantization type (e.g., uniform or non- uniform), and / or number of quantization bits etc.
[0114] At 320, the WTRU may determine the second input part based on the configuration and / or the indication. During inference, the WTRU may apply both the first input part and the second input part to the AI / ML model and determine the first output part and the second output part.
[0115] In an example, the second output may be a function of the second input part, the first input part, and / or the AI / ML model etc.
[0116] In an example, the second output part may be the inference output, an output of a SoftMax function (and / or other activation function) layer, an output of one or more pre-configured neurons, and / or an output of one or more preconfigured layers (e.g., add and norm).
[0117] In an example, the second output part may be the watermark information determined by the WTRU. In an example, the second output may include one or more scores and / or distributions associated with one or more specific output units, for instance, one or more SoftMax outputs and / or any other scoring function. In an example, the second output part may be an intermediate inference output of one or more activation functions and / or layers.
[0118] In an example, the WTRU may apply different quantization for the first and second outputs. In an option, the WTRU may apply a default second input part and drop the reporting of the second output part during normal operation.
[0119] At 330, the WTRU may transmit the first and / or second output parts to the gNB. In an example, the WTRU may always transmit the first output part. The WTRU may determine whether to transmit the second output part based on whether a condition (e.g., a trigger condition) is satisfied and / or whether a trigger event occurs
[0120] FIG. 4 is a flow diagram of a method for an input-based functional watermarking including separate inference / watermarking according to one or more embodiments. The method may be performed by the WTRU.
[0121] At 410, the WTRU may receive the AI / ML model (e.g., the proprietary AL / ML model) from the network. The reception of the WTRU may be based on the request transmitted by the WTRU to the NW and / or may be NW initiated. The WTRU may receive two configurations for inference, viz. the first configuration information and the second configuration information. The first inference configuration may apply an input (e.g., the first input and / or the first input part etc.) based on the WTRU measurement and / or a use-case specific input, e.g., the channel matrix in case of the CSI compression. The second inference configuration may apply the input (e.g., the second input and / or the second input part etc.) based on the NW configuration, for example, the preconfigured signature, the header and / or the bit-string sequence, and / or the pseudo-random sequence generated based on the NW configuration. The preconfigured signature may include and / or be indicative of the unique proprietary digital signature, the hash representing the proprietary AI / ML model and / or the WTRU vendor, the WTRU specific signature, and / or the vendor specific signature etc. The second inference may include and / or may be indicative of the header and / or a bit-string sequence, the pseudo-random sequence generated based on the NW configuration etc.
[0122] The WTRU may receive the trigger to transmit the watermark information. In an example, the trigger may be based on one or more WTRU-determined conditions, examples of which include but are not limited to, the performance monitoring (e.g., the short-term and / or long-term performance degradation based on the threshold performance); the model selection and / or activation; the model finetuning; the model update and / or transfer; the fallback to legacy; the mobility event, e.g., the HO, the OHO, etc.; upon failure event (e.g, thebeam failure etc ), during initial access (e.g., in msg3 and / or after RRC connection establishment); during RRC state change (e.g., RRC resume), based on reception of an indication, e.g., the MAC CE; an aperiodic request; RRC reconfiguration; and / or the configuration, e.g., periodic reporting etc.
[0123] At 420, upon determining that the watermark trigger condition is satisfied, the WTRU may apply the second configuration information (i.e., select one input from a plurality of inputs based on a condition e.g., a slot number, a frame number, and / or a counter for a watermark procedure etc ), and at 430, the WTRU may perform the inference, and determine the second output at 440. In an example, the second output part may be an inference output, an output of the Soft ax (and / or other activation functions) layer, an output of one or more pre-configured neurons, an output of one or more preconfigured layers (add and norm), when the second input is applied. The WTRU may apply different quantization for the second output. At 450, the WTRU may transmit the second output to the gNB.
[0124] One or more aspects or features disclosed herein are common to some or all embodiments disclosed herein. For example, in this disclosure, one or more embodiments for detectability of the proprietary AI / ML models and / or watermarking for the proprietary AI / ML models are described. More specifically, one or more embodiments of methods and / or procedures for the watermark extraction and the watermark reporting for verification access are described. Also, one or more embodiments of one or more methods for input-based functional watermarking are described, along with one or more procedures for verification and reporting watermark information.
[0125] In an example, the proprietary AI / ML models may include one or more AI / ML models having a proprietor and / or an owner that may claim an intellectual property right in the AI / ML model. Examples of the proprietor and / or the owner include a single entity, e.g., the NW, the vendor, and / or the operator etc. The proprietary AI / ML model may require additional procedures to be transferred, copied, shared, downloaded, and / or used.
[0126] In an example, the first input part may include the inference input of the AI / ML model. The first input part may include the one or more measurements by the WTRU that may be processed by the AI / ML model, which may be use-case specific (for example, for the CSI enhancements, the first input part may be a full raw channel matrix and / or eigenvectors of the channel matrix etc.).
[0127] In an example, the second input part may include the input to the AI / ML model, which may be associated with the watermark. The second input part may include a watermark extraction input, which may be used to enable the AI / ML model to output the watermark to be reported and / or used for verification access.
[0128] In an example, the first output of the AI / ML model may include and / or may be indicative of the inference output. The first output part may be a function of the first input part.
[0129] In an example, the second output of the AI / ML model may include and / or may be indicative of the output carrying the watermark information, which may be reported and / or transmitted to enable the proprietaryAI / ML model to verify the WTRU access. The second output part may be the function of the first input part, the second input part, and / or the AI / ML model.
[0130] In an example, the detectability and verification of the AI / ML models may be based on one or more watermarking techniques. The watermarking may include the process of embedding identification information into some original data (and / or the AI / ML models) to claim and / or verify ownership and / or copyright without affecting the data and / or the AI / ML model usage. The watermark may also be used for enabling the detectability of the proprietary AI / ML model use and might leverage different aspects related to how the watermark is embedded into the AI / ML model, verification access, capacity, authentication, and / or uniqueness etc.
[0131] In one example, a realization of one or more embodiments described herein, the NW vendor may train the proprietary AI / ML model (may be one-sided or two-sided). The NW may decide that the usage of the AI / ML model at the WTRU needs to be verified and detected The NW may determine and / or design a content of the watermark by including vendor-specific information and / or training-data related information. The content of the watermark may be linked to an assistance input, i e., a set of applicable conditions.
[0132] The AI / ML model may be shared online and / or offline, and the WTRU may be preconfigured with an inference input and a watermark input and / or may receive, explicitly, the configuration, e.g., after model finetuning, after model download, and / or after model activation, etc.
[0133] The WTRU may need to verify the watermark and the access to the AI / ML model, which may be from another vendor, wherein the WTRU may perform one or more procedures and / or exchange signaling with the NW for enabling the AI / ML model verification and initialization, via watermark pre-processing and / or postprocessing, watermark filtering and / or extraction, and / or reporting the watermark information.
[0134] The WTRU may or may not receive an activation command for performing the inference. The activation command may be received when the WTRU has verified the access to the proprietary AI / ML model. The WTRU may receive the activation command, for example, when the verification procedure is successful, or when the WTRU is already authenticated and authorized to use the AI / ML model. The WTRU may receive a deactivation command in case of failure of the verification access procedure, for example if the WTRU reported an invalid watermark, if the WTRU no longer has access to the updated and / or fine-tuned model, or when the WTRU vendor is no longer among the legitimate vendors for using the proprietary AI / ML model
[0135] Common benefits of one or more of the embodiments disclosed herein include the proprietary AI / ML model detectability, i.e., the owner is enabled to detect that the AI / ML model is used by another device and / or vendor, access verification to use the proprietary AI / ML model via watermark verification (extraction and / or filtering) and reporting, preventing stealing and unverified sharing of model instances, securing the proprietary AI / ML models against model stealing and forging, protecting the AI / ML model IP while ensuring accountability, and enabling proprietary models access and use to be unique by instance and specific to one or more predefined conditions, e.g., WTRU-specific, vendor-specific, or verified instances of the AI / ML model linked to specific applicable conditions.
[0136] Regarding the trigger for watermark determination and / or reporting, in one or more solution, the one or more trigger conditions may refer to the one or more events and / or conditions, upon which the WTRU may determine, extract, and / or report the watermark information.
[0137] In an example, the events and / or the conditions may be preconfigured for the WTRU In more examples, the events and / or the conditions may include, but are not limited to, one or more of: measurementbased conditions, model performance-based conditions, model operation-based conditions, WTRU statebased conditions, and / or WTRU mobility-based conditions, etc.
[0138] In an example, the WTRU may be configured to determine, extract, and / or report the watermark information based on the performance of the AI / ML model. For instance, the WTRU may trigger reporting the watermark information when the performance of the AI / ML model is below the preconfigured threshold. In an example, the WTRU may trigger reporting the watermark information when the variation in the performance of the AI / ML model exceeds the threshold performance. The threshold performance may be preconfigured for the WTRU and / or the AI / ML model. In an example, the threshold performance may be configured specifically for the WTRU. In an example, the threshold performance may be configured specifically for a use case. In an example, the WTRU may derive the performance of the AI / ML model over a preconfigured time period. The WTRU may be configured with one or more conditions related to a short-term performance monitoring and / or a long-term performance monitoring. In an example, the WTRU may be configured with different behaviors associated with watermark reporting based on the type of the performance monitoring. For instance, the WTRU may be configured to trigger a one-shot watermark reporting when the AI / ML model performance based on the short-term monitoring is below a first threshold performance. In another example, the WTRU may be configured to trigger periodic and / or semi-persistent watermark reporting when the AI / ML model performance based on long-term monitoring is below a threshold.
[0139] In an example, the WTRU may be configured to determine, extract, and / or report the watermark information based on an operation status of the AI / ML model. In an example, the WTRU may trigger the watermark reporting when the AI / ML model is selected for the inference. In an example, the WTRU may trigger the watermark reporting when the AI / ML model is activated. In an example, the WTRU may trigger watermark reporting when the AI / ML model is updated. In an example, the WTRU may trigger watermark reporting when the AI / ML model is finetuned. In an example, the WTRU may trigger the watermark reporting when a new AI / ML model is downloaded. In an example, the WTRU may trigger the watermark reporting when a fallback from an AI / ML model operation to a legacy operation is triggered.
[0140] In an embodiment, the WTRU may be configured to determine, extract, and / or report the watermark information based on the mobility event. In an example, the WTRU may trigger the watermark reporting upon the mobility event including a legacy handover, a conditional handover, and / or a lower layer triggered mobility (LTM) event. In an example, the WTRU may be explicitly configured to report the watermark information in signaling associated with a mobility procedure (e.g., in the RRC configuration, the MAC CE, and / or L1 signaling etc.) In a solution, the WTRU may be configured to trigger the watermark reporting during an initial access. Inan example, the WTRU may report the watermark information in msg3. In an embodiment, the WTRU may be configured with the one or more AI / ML models for potential activation in a RRC reconfiguration message. The WTRU may determine the watermark information upon receiving the RRC reconfiguration message for the one or more indicated AI / ML models. The WTRU may report the watermark information associated with the one or more AI / ML models in a RRC reconfiguration complete message. In an example, the WTRU may trigger the watermark reporting upon detecting a radio link failure. In an example, the WTRU may trigger the watermark reporting upon detecting a beam failure In an example, the WTRU may trigger the watermark reporting based on radio link monitoring status and / or beam failure instance counter etc. In an example, the WTRU may trigger the watermark reporting during an RRC state change. For instance, the WTRU may trigger the watermark reporting during an RRC resume procedure. In an example, the WTRU may transmit the watermark information in an RRC resume request and / or an RRC resume complete message.
[0141] In an example, the WTRU may be configured to determine, extract, and / or report the watermark information based on a network command. For instance, the WTRU may receive the network command in the MAC CE and / or L1 signaling or RRC signaling. In an example, the WTRU may receive the indication and / or command from the gNB and / or the network to determine and / or transmit watermark information associated with the one or more AI / ML models. In an example, the WTRU may report the watermark information in the MAC CE, L1 and / or the RRC signaling. If more than one item of the watermark information is reported, then the WTRU may include one or more identifiers associated with the one or more AI / ML models for which the watermark is transmitted.
[0142] In an example, the WTRU may be configured to determine, extract, and / or report the watermark information periodically. For instance, the WTRU may be configured to determine, extract, and / or report the watermark information upon expiry of a timer Tr. In an example, a value of the timer Tr may be configured by one or more higher layers (e.g. , the RRC) signaling In an embodiment, the WTRU may derive the value of the timer Tr based on one or more other configuration and / or conditions. In an example, the value of the timer Tr may be derived based on a WTRU activity state (e.g., a DRX cycle, and / or a parameterization thereof).
[0143] In an example, the WTRU may be configured to report the watermark information during a security mode command procedure. For instance, upon receiving a security mode command from the network, the WTRU may derive one or more access stratum (AS) keys. In an example, the WTRU may derive the watermark information upon verifying that the security mode command message passes the integrity protection check. The WTRU may be configured to report the watermark information along with a security model complete message. In an embodiment, the WTRU may report the watermark information after the AS security is activated
[0144] Regarding a WTRU procedure for extracting and / or reporting the watermark, in an example, the watermark may be embedded in the AI / ML model, for example, during the model training process. In an example, the AI / ML model may be trained by the proprietor by adding a vendor-specific input and / or a digital signature as side information, wherein the inference output may produce a fingerprint that may be capturedand associated to the proprietary AI / ML model In another example, the watermark may be determined and / or designed after training the AI / ML model, for example by truncating the AI / ML model based on the configuration (e g., removing a set of layers, activations, and / or neurons etc.) and / or modifying one or more AI / ML model parameters (e.g., by flipping a sign of one or more configured weights of the AI / ML model). In an example, the watermark may be captured within a structure of the AI / ML model, by adding a specific regularizer into the loss function, that penalizes a set of weights if the set of weights exceed one or more pre-defined thresholds. The one or more involved weights of the trained Al / M L model may have one or more vendor-specific measurements, which may include signs, magnitudes, values, and / or statistical distributions etc.
[0145] The WTRU may apply one or more pre-processing processes and / or one or more pre-processing functions to one or more inputs before applying the one or more inputs to the AI / ML model and processing by filtering and / or applying the extraction function. The WTRU may apply one or more post-processing processes and / or one or more post-processing functions to one or more outputs of the AI / ML model before reporting the inference output and the watermark information.
[0146] FIG. 5 is a diagram of a system architecture according to one or more embodiments.
[0147] At 510, the WTRU may receive the proprietary AI / ML model, wherein the reception of the proprietary AI / ML model may be NW initiated and / or based on the WTRU request In an example, only a subset (e.g., one or more parts and / or functions etc.) of the AI / L model may be received, and in another option, the entire AI / ML model may be received, e.g , with one or more modified weights.
[0148] In an embodiment, a proprietary watermark may be embedded and / or captured in the one or more weights of a subset of the AI / ML model weights and / or the one or more activation functions. In an example, after training, the one or more model weights may be pruned and / or modified (e.g., with the sign flip and / or by multiplying the model weights by a factor and / or adding biases etc.) to generate one or more modified weights. In an example, during training, the loss function may have the regularizer such that the watermark may be enforced and / or captured based on the set of weights, and / or the regularizer that enforces one or more predefined statistical distributions based on the set of weights For instance, L1 , L2 and / or L1 / L2 regularizers may be used in the loss function to adjust the set of weights, or to maintain the set of weights within a specific range and / or interval.
[0149] In an example, the loss function may be any differentiable function, depending on the use-case. In an example, the activation function may generate one or more pre-defined values when triggered by a preconfigured bit-string or sequence header. A position e.g., an exact position or an approximate position (e.g., depth) of one or more indexed activation functions may represent the watermark. For example, the position of a layer in a DNN model may be given by an integer that indicates an exact coordinate of a layer, e.g., in the AI / ML model with two hidden layers followed by an activation function layer, the position of the activation function may be given by three (input layer counted as 0). More generally, the WTRU may be configured with one or more rules and / or parameters to determine the subset of weights from the AI / ML model. In an example,the one or more rules may include indicating implicitly and / or explicitly an index, position, and / or location of the set of model weights relevant for the watermark extraction
[0150] After receiving the proprietary AI / ML model (and / or the subset of the proprietary AI / ML model), the WTRU may be preconfigured and / or may receive the first configuration information for the inference, and the second configuration information for the watermark extraction. The first inference configuration may be usecase specific, whereas the second configuration information associated with the watermarking extraction may include one or more of: the watermark type, the filtering configuration, the preprocessing configuration, and / or one or more extraction function configuration.
[0151] For inference, at 520, the preprocessing may be applied to the first input. The preprocessed first input may be used, at 530, by the AI / ML model to generate the first output. At 540, the postprocessing may be applied to the output to generate the inference output. In an example, the inference output may be transmitted to the NW for authentication and / or verification performed at 570.
[0152] In an example, examples of the watermark type may include but are not limited to the one or more watermarks embedded in the set of weights, embedded in the one or more activation functions, embedded in a sub-model, and / or functionality-based embedded, etc.
[0153] At 550, the filtering configuration may include one or more coordinates of the watermark, e.g., depth and position of weights and / or a set of coordinates etc. In an example, the filtering configuration may include the one or more coordinates of the one or more activation functions etc. In an example, the filtering configuration may include a maximum magnitude threshold and / or a minimum magnitude threshold for the selection of the one or more subsets of the weights. In an example, the filtering configuration may be granular, e g., different thresholds associated with different sets of positions. In an example, the filtering configuration may include an indication of a sub-graph of the AI / ML model. For instance, the subset of the AI / ML model may be indicated in the filtering configuration. In another example, the filtering configuration may include indication of one or more parts of the AI / ML model to prune, i.e., modify the weights by one or more zeros and maintain a remaining subset
[0154] In an example, the preprocessing configuration may include the float and / or fixed point precisions, the floor and / or ceiling functions, the permutations and / or the interleaving patterns etc. The WTRU may be configured with a specific float precision, e.g , half (binary16), single (binary32), double (binary64), and / or bi nary 128, etc. The WTRU may be configured with a specific fixed-point precision, e.g., a float number (e g., a weight) may be represented by an integer multiplied by a fixed scaling factor. The WTRU may be configured with a specific floor and / or ceiling function, e.g., a maximum and / or minimal threshold may be configured, such that one or more filtered values may be replaced with the maximum and / or minimum thresholds if the one or more weights are above and / or below the one or more threshold values associated with the configured ceiling and / or floor functions. The WTRU may be configured with the permutation described by a permutation vector and / or a matrix etc.
[0155] At 560, the extraction function configuration may include one or more of: the hash function (e.g , the hash function having the model and / or sub-model parameters as the input and the watermark as the input); the one or more statistics (e.g., the PDF etc.) e.g., of one or multiple layers; the sign and / or magnitude extraction functions; the sign flipping function; and / or the value-based and / or the threshold-based selection functions etc.
[0156] In an example, WTRU may determine the watermark from the proprietary AI / ML model by performing selection based on the filtering configuration and may extract the watermark after performing pre-processing.
[0157] The selection of the watermark may be based on the selection of the one or more model weights, layers, and / or activation functions. The selection may be based on the one or more coordinates indicated in the filtering configuration, e.g , indication of one or more layer depths, positions, indexes and / or activation function depths, and / or exact (or almost exact) position of the one or more neurons within the one or more layers, etc. In an embodiment, the selection may be additionally based on the one or more minimum and / or maximum thresholds for filtering and / or selecting the subset of neurons with the one or more weights less and / or greater than the one or more corresponding thresholds indicated in the configuration.
[0158] The WTRU may perform the pre-processing of the filtered watermark information. The WTRU may pre-process the watermark information by applying one or a set of pre-defined operators and / or functions, e.g., the WTRU may use the floor and / or ceiling function or a specific filter, and / or based on the float-precision limit included in the pre-processing configuration. In an embodiment, the WTRU may perform the pre-processing to the filtered watermark information by applying the permutation and / or interleaving function, wherein the one or more function parameters may be included in the pre-processing configuration.
[0159] The WTRU may apply the configured extraction function to the pre-processed filtered watermark information. In an embodiment, the WTRU may apply the configured (received in the extraction function configuration) hash function with the input as the pre-processed watermark information, and the output as a hash value and / or a hash code calculated by the hash function that may map the input information to a unique hash code (may be fixed-length and / or variable-length etc.). In an example, the proprietary AI / ML model may be assumed to be trained on a training dataset with one or more additional inputs from the configuration, wherein the input may be a vendor-specific ID and / or a hash, for example, and the AI / ML model output depends on the input and / or the model etc.
[0160] In an example, the WTRU may apply one or more preconfigured statistics measurements on the pre-processed filtered watermark information, e g., cumulative distribution function (CDF) and / or PDF etc., measurements (after the pre-processing) of the one or more layers, one or more sets or neurons, etc. In an example, the WTRU may use the extraction function based on the sign and / or magnitude of the filtered information, e.g., sign-flipping function, sign-based selection function, and / or magnitude-based selection function. In an example, the WTRU may use the extraction function based on the one or more thresholds. The WTRU may select the values from the filtered watermark information that meet the one or more preconfiguredthresholds. In another example, the WTRU may select the values within a specific preconfigured interval, wherein the interval configuration may be included in the extraction function configuration.
[0161] The WTRU may be configured to determine the watermark to be used for verifying the legitimate usage of the proprietary AI / ML model. The WTRU may be configured to indicate and / or report the extracted watermark associated with the proprietary AI / ML model. In an example, the watermark reporting may be referred to an AI / ML watermark reporting and / or an AI / ML watermark feedback, etc The watermark reporting may be periodic, semi-persistent and / or event triggered etc. For instance, the WTRU may be configured to transmit the watermark based on or more preconfigured trigger events and / or trigger conditions. In an example, the trigger conditions may include one or more parameters such as but not limited to when the AI / ML model is switched and / or changed; when one or more parts, e.g., the one or more weights and / or activation functions of the AI / ML model are updated; when the AI / ML model is disabled and reactivated after a number of time slots; when the performance of AI / ML model changes (e g., increases or decreases) by the one or more preconfigured threshold performances; and / or upon a successful RRC configuration. In an embodiment, the WTRU may be configured to report the watermark information based on one or more triggers described herein.
[0162] In an example, the extracted watermark may be transmitted and / or indicated in different formats. For instance, a format of the reporting and / or transmission of the watermark information may be dependent on the watermark extraction configuration. In an example, if the filtering-based configuration is used for watermark extraction, then the watermark may be reported in a first watermark reporting format, e.g., an index from one of more predefined indices associated with the filtering configuration. In another example, if the preprocessingbased configuration is used, then the watermark may be reported in a second watermark reporting format, e.g., an identification number of an extracted interleaving pattern.
[0163] In an example, the WTRU may be configured to report the extracted watermark in a feedback message. The WTRU may report the extracted watermark in the MAC CE. In another example, the WTRU may report the watermark in a L1 feedback, e.g., on the PUCCH resource. In an example, the WTRU may report the extracted watermark in one or more PUSCH resources. In another example, the WTRU may transmit the watermark feedback via a uplink control information (UCI). In another example, the watermark information may be reported in the RRC message. In an example, the watermark feedback may be associated with multiple watermarks, wherein each watermark may be associated with a different proprietary AI / ML model.
[0164] The WTRU may be configured to receive a verification as a response to the indicated watermark. For instance, the WTRU may receive the activation command. The activation command may be received on a condition that the reported watermark is valid, i e., the watermark verification procedure is successful. The WTRU may use the AI / ML model for performing the inference upon receiving the activation command. In another embodiment, the WTRU may receive a deactivation command in case of a verification failure, e.g., when the reported watermark is no longer valid and / or the reported watermark is incorrect. This may imply that the WTRU cannot use the AI / ML model for inference. The WTRU may be configured for a second attempt to re-extract and transmit the watermark information. In another option, the WTRU may be configured with amaximum number of watermark feedback instances and / or reports. If the WTRU fails in extracting the watermark within the allowed maximum number of times, then the WTRU may not be allowed to use the AI / ML model and / or attempt to extract the watermark for a given amount of time.
[0165] In operation, the WTRU may receive the proprietary AI / ML model and the first configuration information for the inference and the second configuration information for the watermark extraction. The WTRU may also receive the trigger to transmit the watermark information. The WTRU may determine the watermark according to the configuration. Upon receiving the trigger, the WTRU may report the watermark information
[0166] The WTRU may receive the AI / ML model and / or the proprietary AI / ML model from the NW. The one or more items of the watermark information may be embedded in the one or more model weights (and / or a subset of model weights) and / or the one or more activation functions. In an example, after training, the one or more model weights may be pruned and / or modified (e.g , with the sign flip and / or by multiplying the one or more weights by a factor and / or adding biases to the one or more weights) In an example, during training, the loss function may have the regularizer such that the watermark may be enforced and / or captured on the set of weights, and / or the regularizer that enforces one or more pre-defined statistical distribution on the set of weights. In an example, the embedded activation function may output the one or more pre-defined values when triggered by the pre-configured bit-string and / or the sequence header. In an example, the position (i.e., the depth) of the one or more indexed activation functions may represent the watermark. The reception of the one or more AI / ML models and / or the one or more proprietary AI / ML models may be based on the WTRU request and / or may be NW initiated.
[0167] The WTRU may receive the first configuration information for the inference and the second configuration information for the watermark extraction. The configuration for the watermark extraction may include one or more of: the watermark type, the filtering configuration, the pre-processing configuration, and / or the extraction configuration.
[0168] The watermark type may be embedded in the one or more weights and / or embedded in the one or more activation functions. The filtering configuration may include the one or more coordinates of the watermark (e g., depth and / or position of the one or more weights), the one or more coordinates of the one or more embedded functions, and / or a magnitude threshold (e.g., the maximum magnitude threshold and / or a minimum magnitude threshold etc.) for the selection of the subset of weights.
[0169] The preprocessing configuration may include the float and / or fixed point precision. In an example, the WTRU may be configured with one or more specific float precisions, e.g., half (binary 16), single (binary32), double (binary64), binary 128, etc. The WTRU may be configured with one or more specific fixed-point precisions, e.g., the float number (e.g., the weight), may be represented by an integer multiplied by a fixed scaling factor. The WTRU may be configured with the specific floor and / or ceiling functions, e.g., the maximum and / or minimal threshold may be configured, such that the one or more filtered values are replaced with the maximum and / or minimum thresholds if the one or more weights are above and / or beyond the maximum and / orminimum threshold values associated with the configured floor and / or ceiling functions The WTRU may be configured with the permutation described by the permutation vector and / or matrix.
[0170] The extraction function configuration may include the hash function (the input may be model and / or sub-model parameters and output may be the watermark), the statistics (e.g, PDF, ...) of the one or more layer, the sign and / or magnitude extraction function , the sign flipping function, the value-based and / or threshold-based selection function etc.
[0171] The WTRU may receive the trigger to transmit the watermark information The watermark reporting may be initiated by the WTRU based on the one or more conditions, such as but not limited to performance monitoring (e.g., short-term and / or long-term performance degradation based on the threshold performance), model selection and / or activation, finetuning, model update and / or transfer, fallback to legacy, e.g., one or more mobility events such as but not limited to the HO, the CHO, etc., failure event (e.g., the beam failure etc.), the initial access (e.g., in msg3 and / or after RRC connection establishment etc.), RRC state change (e.g., RRC resume etc.), the NW trigger e.g., the MAC CE, aperiodic request, RRC reconfiguration, and / or periodically.
[0172] In an example, the WTRU may determine the watermark by selecting the one or more model weights and / or one or more activations by applying filtering based on the filtering configuration. In an example, the WTRU may perform preprocessing on the one or more selected weights based on the preprocessing configuration; and / or extracting the watermark information by applying the extraction function to the preprocessed quantities. In an example, the WTRU may transmit the extracted watermark in the MAC CE, PUCCH, and / or the RRC msg (e.g., the UAI and / or the WTRU UL information) etc.
[0173] The watermark may be embedded in the AI / ML model such that the output of the AI / ML model may be indicative of the watermark information when applying the predefined value as the input. In an example, the embedding may be applied during the AI / ML model training process. For instance, the model may be trained by the proprietor by adding the vendor-specific input and / or the digital signature as an item of side information. The inference output may produce a fingerprint that may be captured and / or associated to the proprietary AI / ML model. In an example, the watermark may be determined and / or designed after training the AI / ML model, for example by truncating the AI / ML model according to the configuration (e.g, removing the set of layers, activations, and / or neurons etc.), and / or modifying the AI / ML model parameters (e g, by flipping the sign of the configured weights of the AI / ML model) In an example, the NW may embed the pre-determined input header, the digital signature, and / or the hash representing the watermark, wherein the watermark information may be captured in the model output. Also, in an example, the watermark captured in the output may be compressed using the preconfigured hash function, and only the hash code may be reported.
[0174] The WTRU may be configured with the AI / ML model enabled for watermarking. The AI / ML model for watermarking may be configured to receive a single input vector and / or a plurality of input vectors and / or one or more input vectors with multiple parts.
[0175] In an example, the AI / ML model at the WTRU may be configured to receive two input vectors and / or tensors (i.e receiver input in two parts). The first input part may be application and / or task specific and may represent the input specific to the task for which the AI / ML model is trained. For instance, the AI / ML model may be configured for the CSI compression task and the first input may be the CSI tensor. In another example, the AI / ML model may be trained to perform the CSI prediction task and the first input may be a set of multiple past CSI tensors. The second input part may be associated with enabling the watermarking operation and / or may be configured by the network and / or may be configured and / or defined by the entity with the ownership and / or proprietorship of the AI / ML model.
[0176] In an embodiment, the second input part at the WTRU may be configured as a unique, proprietary digital signature associated with the specific AI / ML model. In an embodiment, the digital signature may be specific to the WTRU and / or may be specific to the WTRU vendor.
[0177] In an example, the network may configure the WTRU with the input sequence which may be pre- processed at the WTRU through a network defined mapping function to receive the second input of the AI / ML model.
[0178] In an example, the second input part at the WTRU may be configured as the bit string sequence. The bit string may be a model specific header with a pre-defined output or may include model specific side information.
[0179] In an embodiment, the second input part may be a part of the AI / ML model (e.g., one or more additional weights, biases, and / or masks etc.) which may activate the AI / ML model and / or enable the regular operation of the AI / ML model.
[0180] In an example, the WTRU may be configured with the second input part where the input may be the pseudo random sequence generated by the network using the network configuration as a seed and / or using the one or more environmental parameters (e.g., channel state, signal to noise ratio (SNR), doppler, and / or delay spread etc.) as the seed.
[0181] In an embodiment, the WTRU may be configured with the second input part where the second input part may serve as the indication of the one or more coordinates and / or positions of one or more specific output units associated with one or more specific layers. Alternatively, the input serves as an indication of the one or more coordinates and / or positions of the one or more specific output units associated with the one or more activation functions.
[0182] Further, the WTRU may be configured with the length of the first input and / or the first input part and the length for the second input and / or the second input part. These lengths may either be fixed once configured and / or may be variable and / or may be reconfigurable. The WTRU may receive the configuration in the RRC signaling (e.g., the RRC setup and / or the RRC reconfiguration etc.).
[0183] Further, the second input part configuration may be quantized and / or maybe protected and / or encoded using one or more additional error correction bits. Thus, the WTRU may be configured with informationto decode and / or undo any quantization and / or error correction. The configuration may include the quantization type (e.g., scalar quantization, vector quantization, uniform quantization and / or non-uniform quantization etc.), length, and / or number of bits etc
[0184] FIG. 6 is a diagram of the joint inference / watermarking with implicit watermarking, according to one or more embodiment FIG. 6 illustrates an AI / ML model 610, a first input 620, a second input 630, and an output 640. In an example, the AI / ML model 610 at the WTRU may be configured to receive only one input vector and / or tensor at a given time. The WTRU may further be configured to perform inference twice with two different model inputs, the first input 620 and / or the second input 630. The first input 620 may relate to the application and / or task associated with the AI / ML model 610. For example, for the AI / ML based CSI compression task, the first input 620 may correspond to the CSI tensor. The second input 630 may relate to evaluating the watermarking information. The network may configure the second input 630 at the WTRU to be the unique proprietary digital signature specified by the network specifically for the WTRU and / or for the AI / ML model 610 and / or for the vendor. Optionally, the network may configure the second input 630 at the WTRU as the header and / or the bit string sequence and / or as the pseudo random sequence.
[0185] For joint inference and / or watermarking, the AI / ML model 610 at the WTRU side may use the second configuration information for the determination of the second input 630. The WTRU may use the second input to perform the inference. During the inference, the WTRU may apply the first input 620 and / or the second input 630, and determine the output 640 including the first output part and the second output part The first output part may be the inference output and the second output part may be the function of the second input part, the first input part, and / or the AI / ML model 610 etc.
[0186] In an example, the second output may be the inference output, wherein the watermark may be captured implicitly in the output. In an embodiment, the proprietary AI / ML model may be trained on a dataset using specific (e.g., NW and / or vendor-specific) side information and / or the one or more additional inputs. The side information may be the watermark configuration included in the second configuration information. In another example, the proprietary AI / ML model may be trained on the dataset with different configurations and / or combinations of one or more configurations or one or more applicable conditions. The watermark verification may be scenario-specific and may provide different watermarks unique by instances defined by one or more applicable conditions at the WTRU. In this case, the WTRU may first report the one or more applicable conditions before triggering the watermark verification procedure and receiving the second part configuration. In another embodiment, the side information may be WTRU-specific and / or WTRU-vendor specific, thereby enabling watermark uniqueness by instance and more robust detectability.
[0187] In another example, the second output part may be the output of the pre-determined activation function, e.g., one or more SoftMax scores. In this example, the index of the activation function and / or the activation units may be indicated in the configuration. In another example, the WTRU may include, in the second output part, outputs of one or more specific layers and / or units during the inference. In an example, the output of one or more pre-configured neurons, e.g., one or more indexes of the one or more neurons may beindicated in the second configuration information. More examples include the output of the one or more preconfigured layers; the WTRU may be configured with more granularity, e.g., to output one or more subsets of different layers of the AI / ML model; signs of one or more sets of processing units (neurons) etc.
[0188] In another embodiment, the watermark information may be captured and reported explicitly For example, the AI / L may be trained in a way that forces the watermark information to be systematically attached with the inference output In an embodiment, the WTRU may be configured to apply post-processing, e.g., duplication and / or interleaving the second part output.
[0189] The WTRU may apply different quantization functions for the first and second output parts. In an embodiment, the WTRU may receive the quantization configuration, e.g., uniform or not uniform, number of quantization bits for each output part, i.e., for the inference output and / or a watermark information report output.
[0190] In an embodiment, the WTRU may be configured with a default second input part for the watermark, e.g., WTRU and / or vendor specific, to use in case the WTRU is not triggered to report the watermark information. In this embodiment, the WTRU may deactivate the reporting procedure of the second output during normal operation. In this case, the WTRU may perform the inference using the first part input and / or the default second part input and may output the inference result. The WTRU may activate such reporting if not triggered to report the watermark, e.g., when verification access is not needed, and / or when the WTRU is already authenticated, etc.
[0191] For separate inference / watermarking, the WTRU may not be required to transmit the watermark implicitly and / or during the inference. In an embodiment, the WTRU may apply the first configuration information to the proprietary AI / ML model for producing the watermark information before applying the AI / ML model for inference. The WTRU may apply the second inference configuration, wherein the WTRU may select one input from a plurality of inputs based on one or more pre-defined conditions, such as but not limited to a slot number, a frame number, and / or a sliding window etc.
[0192] In an example, the WTRU may be configured with a set of slot numbers each with a different input for the watermark. The WTRU may report a slot number and then apply the second inference configuration corresponding to the second inference input
[0193] In an example, the WTRU may be statically or dynamically configured with multiple frames each with equal or different lengths. The WTRU may select the input according to the current frame. The WTRU may be configured with a dynamic frame counter incremented after every watermark verification of the AI / ML model. The WTRU may use the frame counter to shift the frame, and / or to switch the second inference input according to the new frame.
[0194] For the sliding window, e.g., based on a counter that increments when the second inference input is applied to the model. The WTRU may slide the window accordingly to select a new second inference input.
[0195] The WTRU may perform the inference using the selected inference input and may determine the second output where the watermark is captured. For instance, the second output may be one or more of: theinference output, the output of any one or more pre-configured intermediate layers, e.g , activation functions and / or layers, one or more outputs of one or more pre-configured neurons, etc. In an example, the second output may be a statistical distribution of the one or more layers, e g., the CDF and / or the PDF of the one or more of layers. The statistical distribution may be known by the proprietor, given that the inference input for the watermark verification is configured by the proprietor of the model. The one or more layers and the granularity for reporting statistical measurements may be indicated in the second inference configuration.
[0196] In an embodiment, the WTRU may use a different quantization method for the second inference output before reporting the watermark information. The use of the different quantization method may enable a more robust protection of the watermark. In an example, the WTRU may receive the second inference configuration that may include the configuration of the quantization. In an embodiment, the quantization method (and / or a quantization scheme) may be configured dynamically with respect to the channel condition and / or the one or more applicable conditions for the WTRU. In another embodiment, the WTRU may select the appropriate quantization without reporting the one or more conditions.
[0197] FIG. 7 is a diagram of separate inference / watermarking according to one or more embodiments. FIG. 7 illustrates an AI / ML model 710, an input 720 based on the second configuration information, and watermark information 730 as the output of the AI / ML model 710.
[0198] The WTRU may perform joint and / or separate inference / watermarking. The WTRU may report the watermark information 730 and the inference output. In an embodiment, the WTRU may be configured to report the watermark information 730 upon receiving the one or more triggers.
[0199] When the WTRU is triggered to determine and report the watermark, the WTRU may report the first output part (e g., the inference output) and the second output part (e.g., including the extracted watermark). The WTRU may indicate, to the NW, one or more parameters associated with the first and / or second output parts. In an example, the indication may include one or more of: whether the second output part is included in the report, size (length) of the first output part, size (length) of the second output part, quantization type and / or a number of quantization bits for the first output part, quantization type and / or number of quantization bits for the second output part, the type of the reported second output part (e.g., output of the one or more predetermined activation functions and / or output of the one or more specific layers, etc.).
[0200] The WTRU may use one or more UL grants to report the second output part (e.g., the watermark information) and the parameter indication over the UL data channel (e.g., PUSCH). The first output part may be reported using one or more configured measurement reporting mechanisms
[0201] When the one or more trigger conditions are not met, the WTRU may report, to the NW, the first output part (i.e., the inference output). In an example, when the one or more trigger conditions are met, the WTRU may report, to the NW, the second output part (i.e , the watermark information). In an example, when the one or more trigger conditions are met and a reporting instance for the first output part overlaps, the WTRU may report, to the NW, both the first output part and the second output part (i.e., the watermark information).
[0202] When the WTRU performs the inference and the watermark extraction separately, the WTRU may report the second output part (e.g., the watermark extracted using the second inference configuration). The WTRU may (e.g., additionally) transmit the indication of the one or more parameters associated with the second output part. The indication may include one or more of: the size (length) of the second output part, the condition that met the trigger to transmit the watermark, and / or quantization type and number of quantization bits for the second output part. The WTRU may report the second output part and / or the one or more associated parameters by way of the indication using the uplink data channel, e.g., upon receiving an UL grant.
[0203] When the WTRU receives, from the NW, the indication that the watermark is verified correctly, the WTRU may apply the first inference configuration and may perform inference on the first input part (e.g., the one or more WTRU measurements such as but not limited to raw channel matrix, and / or channel eigenvectors etc.) The WTRU may report the corresponding inference output (i.e., first output part) to the NW.
[0204] In operation, the WTRU may receive the first part configuration for the inference and the second part configuration, wherein the second part configuration may be associated with the watermark. The WTRU may apply the first and second part inputs to the AI / ML model, determine the first and second outputs, and then report the watermark information and the inference output.
[0205] In the method of joint inference / watermarking, the WTRU may receive the AI / ML model (e.g., the proprietary AI / ML model) from the network, based on the WTRU request and / or upon NW initiation. The WTRU may receive the configuration for the inference. The configuration may include that include the first input part and the second input part. The first input part may be based on the one or more WTRU measurements and / or the one or more use-case specific inputs, e.g., the channel matrix in case of the CSI compression. The second input part may be based on the NW configuration, e.g., the preconfigured signature (e.g., the unique proprietary digital signature), the hash representing the proprietor and / or the WTRU vendor, the WTRU specific signature, or the vendor specific signature, the header or the bit-string sequence (e.g., the AI / ML model specific header with the pre-defined output, and / or the model specific header as the item of side information, the pseudo random sequence generated based on the NW configuration, the one or more coordinates of the one or more specific output units associated with the one or more layers, and / or the one or more coordinates of the one or more specific output units associated with the one or more activation functions etc.
[0206] The configuration may include the lengths of the first and second parts The configuration of the second part may include further information related to the second part, e.g., the length of the bit-string header, the quantization type (e.g , uniform or non-uniform), the number of quantization bits, etc.
[0207] The WTRU may determine the second input based on the second configuration information.
[0208] During inference, the WTRU may apply both the first input part and the second input part to the AI / ML model and determine the first output part and the second output part. The second output may be the function of the second input part, the first input part, and / or the AI / ML model.
[0209] The second output part may be the inference output, the output of the SoftMax (and / or other activation function) layer, the output of the one or more pre-configured neurons, and / or the output of one or more preconfigured layers (add and norm).
[0210] The WTRU may report explicitly the watermark, for instance, one or more scores and / or distribution associated with the one or more specific output units (e.g., the SoftMax outputs and / or any other scoring functions), and / or an intermediate inference output of the one or more activation functions and / or the one or more layers.
[0211] The WTRU may apply different quantization for the first and second parts. The WTRU may apply the default second input part and / or drop the reporting of the second output part during normal operation and perform the watermark reporting procedure upon detecting the occurrence of the trigger condition.
[0212] The WTRU may transmit both the first output part and the second output part to the gNB. In an example, the second output part may not necessarily be transmitted, e.g., if the WTRU is not triggered.
[0213] In operation, in separate inference / watermarking, the WTRU may receive the AI / ML model (e.g., the proprietary AI / ML model) from the network based on the WTRU request and / or be NW initiated. The WTRU may receive the two configurations for inference, including the first inference configuration and the second inference configuration.
[0214] The first inference configuration may apply the first input based on the one or more WTRU measurements and / or the one or more use-case specific inputs, e.g., the channel matrix in case of the CSI compression.
[0215] The second inference configuration may apply the second input based on the NW configuration. The second inference configuration may include one or more of: the preconfigured signature (e g., the unique proprietary digital signature), the hash representing the proprietor and the WTRU vendor, the WTRU specific signature, the vendor specific signature, the header or the bit-string sequence, and / or the pseudo random sequence generated based on the NW configuration.
[0216] The WTRU may receive the trigger to transmit the watermark information. The WTRU may initiate the watermark reporting based on the condition (e.g., based on the performance monitoring (e.g., short-term or long-term performance degradation based on the threshold, upon the model selection and / or activation, upon finetuning, upon the model update and / or transfer, upon fallback to legacy, e.g., upon a mobility event (e g., the HO, the CHO, etc.), a failure event (e.g., the beam failure), during initial access (e.g., in msg3 and / or after a RRC connection establishment), and / or during the RRC state change (e.g., RRC resume), based on the NW trigger (e.g., the MAC CE or the aperiodic request or the RRC reconfiguration), and / or periodic etc.).
[0217] Upon receiving and / or detecting the occurrence of the watermark trigger condition, the WTRU may apply the second inference configuration (i.e., select one input from the plurality of inputs based on the watermark trigger condition, e.g., a slot number and / or frame number and / or counter for a watermark procedure), perform the inference, and / or determine the second output.
[0218] The second output part may be an inference output, output of the SoftMax (and / or other activation function) layer, output of the one or more pre-configured neurons, and / or output of one or more preconfigured layers (add and norm), when the second input is applied. The WTRU may apply different quantization for the second output. The WTRU may transmit the second output to the gNB. The WTRU may apply the first inference configuration, perform the inference, determine the first output, and transmit the output to the gNB.
[0219] Although features and elements are described above in particular combinations, one of ordinary skill in the art will appreciate that each feature or element can be used alone or in any combination with the other features and elements. In addition, the methods described herein may be implemented in a computer program, software, or firmware incorporated in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted over wired or wireless connections) and computer-readable storage media. Examples of computer-readable storage media include, but are not limited to, a read only memory (ROM), a random access memory (RAM), a register, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, magnetooptical media, and optical media such as CD-ROM disks, and digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, UE, terminal, base station, RNC, or any host computer.
Claims
CLAIMSWhat is Claimed:
1. A wireless transmit / receive unit (WTRU) comprising: a processor; and a transceiver, wherein the processor and transceiver are configured to: receive, from a network, an artificial intelligence (Al) / machine learning (ML) model, first configuration information associated with performing an inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model, detect an occurrence of at least one trigger event associated with the watermark, extract the watermark from the AI / ML model based on the detected occurrence of at least one trigger event using at least the second configuration information, generate watermark information indicative of the extracted watermark, and transmit the watermark information to the network.
2. The WTRU of claim 1 , wherein the watermark is embedded in one or more of: one or more weights of the AI / ML model, or one or more activation functions of the AI / ML model.
3. The WTRU of claim 2, wherein the processor is further configured to: apply a first input to the AI / ML model to generate an inference output based at least on the first configuration information, and apply a second input to the AI / ML model to generate the watermark information based at least on the second configuration information.
4. The WTRU of claim 3, wherein the inference output and the watermark information are generated and transmitted jointly5. The WTRU of claim 3, wherein the inference output and the watermark information are generated and transmitted separately6. The WTRU of claim 3, wherein the second configuration information is indicative of one or more of: a watermark type, a filtering configuration, a preprocessing configuration, or an extraction function configuration.
7. The WTRU of claim 6, wherein the preprocessing configuration is indicative of one or more processes comprising: a float precision or a fixed-point precision, one or more floor functions or one or more ceiling functions, or one or more permutation patterns or one or more interleaving patterns8. The WTRU of claim 7, wherein the filtering configuration is indicative of one or more of: one or more coordinates of the watermark, one or more coordinates of the one or more activation functions of the AI / ML model, or one or more threshold weights for selecting the one or more weights of the AI / ML model.
9. The WTRU of claim 8, wherein the extraction function configuration is indicative of one or more extraction functions comprising: a hash function, a statistical analysis of the inference output, a sign extraction function or a magnitude extraction function, a sign flipping function, or a value-based selection function or a threshold-based selection function.
10. The WTRU of claim 9, wherein the processor is further configured to: select the one or more weights or the one or more activation functions of the AI / ML model based on the filtering configuration,perform the one or more processes on the one or more weights or the one or more activation functions based on the preprocessing configuration, and extract the watermark by applying the one or more extraction functions based on the extraction function configuration.
11. The WTRU of claim 1, wherein detecting the occurrence of the at least one trigger event comprises receiving, from the network, an indication of the at least one trigger event associated with one or more of: monitoring performance of the AI / ML model, updating the AI / ML model, or one or more network conditions.
12. The WTRU of claim 1 , wherein the watermark information is transmitted to the network using one or more of: a medium access control (MAC) control element (CE), a radio resource control (RRC) message, or a physical uplink control channel (PUCCH) resource.
13. A method used in a wireless transmit / receive unit (WTRU), the method comprising: receiving, from a network, an artificial intelligence (Al) / machine learning (ML) model, first configuration information associated with performing an inference using the AI / ML model, and second configuration information associated with extracting a watermark from the AI / ML model; detecting occurrence of at least one trigger event related to the watermark; extracting the watermark from the AI / ML model based on the at least one trigger event using at least the second configuration information; and transmitting, to the network, watermark information indicative of the extracted watermark.
14. The method of claim 13, wherein the watermark is embedded in one or more of: one or more weights of the AI / ML model, or one or more activation functions of the AI / ML model.
15. The method of claim 14, the method further comprising: applying a first input to the AI / ML model to generate an inference output based at least on the first configuration information; and applying a second input to the AI / ML model to generate the watermark information based at least on the second configuration information.
16. The method of claim 15, wherein the inference output and the watermark information are generated and transmitted jointly17. The method of claim 15, wherein the inference output and the watermark information are generated and transmitted separately18. The method of claim 15, wherein the second configuration information comprises one or more of: a watermark type, a filtering configuration, a preprocessing configuration, or an extraction function configuration.
19. The method of claim 18, the method further comprising: selecting the one or more weights or the one or more activation functions of the AI / ML model based on the filtering configuration; performing one or more processes on the one or more weights or the one or more activation functions based on the preprocessing configuration; and extracting the watermark by applying one or more extraction functions based on the extraction function configuration20. The method of claim 13, wherein detecting occurrence of the at least one trigger event comprises receiving, from the network, an indication of the at least one trigger event associated with one or more of: monitoring performance of the AI / ML model, updating the AI / ML model, or one or more network conditions.
Citation Information
Patent Citations
Model watermark embedding method and device, computer equipment and storage medium
CN116881871A
Digital watermarking of machine learning models
US20210019605A1
Systems and methods for learning new watermark algorithms for a data processing accelerator
US20210150406A1