Security capability registration and negotiation amongst vertical federated learning participants

The method addresses the lack of security in VFL by coordinating security mechanisms among participants, ensuring secure training by selecting participants with compatible capabilities, enhancing data and model parameter protection.

WO2025214854A1PCT designated stage Publication Date: 2025-10-16NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/059042
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-08
Filing Date
2025-04-03
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing 3GPP standards lack mechanisms to prevent VFL participants from deciphering training data and model parameters, and there is no defined method to detect and coordinate security capabilities among participants.

Method used

A method for obtaining and coordinating security mechanisms among VFL participants by determining supported security capabilities, selecting participants that support a preferred or common security mechanism, and preparing a VFL process using these mechanisms for secure machine learning model training.

Benefits of technology

Enhances security in VFL processes by ensuring only participants with compatible security mechanisms participate, thereby protecting training data and model parameters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025059042_16102025_PF_FP_ABST
    Figure EP2025059042_16102025_PF_FP_ABST
Patent Text Reader

Abstract

The disclosure inter alia relates to a method comprising: - obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; - determining that a preferred security mechanism has been specified; and - if a preferred security mechanism has been specified: - obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and - preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SECURITY CAPABILITY REGISTRATION AND NEGOTIATION AMONGST VERTICAL FEDERATED LEARNING PARTICIPANTS

[0002] TECHNOLOGICAL FIELD

[0003] The present disclosure is related to, but not limited to, vertical federated learning (VFL) in the context of communication systems as defined by the 3rd Generation Partnership Project (3GPP) standards, such as the 5G standards which are also referred to as New Radio (NR) standards. In particular, the disclosure pertains to security aspects m connection with the training of an artificial intelligence (Al) I machine learning (ML) model using VFL

[0004] BACKGROUND

[0005] Artificial intelligence (Al) is a field of technology currently focused on creating systems mimicking intelligent human decision making and / or behavior in specific domains. Machine learning (ML) is a subset of Al that emphasizes statistical learning from training data Artificial neural network (ANN) algorithms are an example of a class of algorithms used in ML, inspired by a simplification of neurons in a brain

[0006] Vertical Federated Learning (VFL) is a federated learning setting where multiple entities, so-called VFL participants, may jointly tram ML models without exposing their raw training data, local ML models or all of their local ML model parameters With respect to communication systems as defined by 3GPP standard, VFL has been introduced in 3GPP Release 19. Respective use cases comprise VFL among network functions (NF) of a mobile core network, for example, VFL among Network Data Analytics Functions (NWDAF), VFL between Application Functions (AF) and NWDAFs, or NWDAF assisting VFL among AFs In this context, security aspects related to VLF may be relevant, in particular in the case of cross-domain VFL, such as VFL involving the 5G core (5GC) network and an AF

[0007] Furthermore, different VFL roles of the respective entities are possible, which may comprise a VFL initiator, a VFL coordinator, an active VFL participant and a passive VFL participant, and which may be represented by various NFs. In this regard, a VFL initiator may determine that a VFL process should be performed, and the VFL initiator may be involved in the discovery of (i e the search for) VFL participants and in a VFL model training preparation. A VFL coordinator may be required to be involved in the VFL process. When involved, the VFL coordinator may be responsible for maintaining the VFL process, i.e by collecting required inputs from a set of VFL participants in every iteration and providing the VFL participants with the information needed to run the next iteration, and for authorizing or removing VFL participants. An active VFL participant may be an NF performing VFL model training with the required data labels. A passive VFL participant may be an NF performing VFL model training without the data labels, to name but a few non-limiting examples.

[0008] SUMMARY OF SOME EXEMPLARY EMBODIMENTS

[0009] In VFL, there is an active participant comprising or containing the label(s) or ground truths of certain data and / or a passive participant containing or comprising other important features which may be needed for ML model training. These may be unavailable at the active participant. This may lead to a security challenge in that securing of the data and the model parameters shared amongst the VFL members may become paramount. In this context, the term “ground truth”, in accordance with its conventional meaning in the field of machine learning and as used herewith, refers to the correct or “true” answer to a specific problem or question For example, in an image classification system, an algorithm may learn to classify each image into a set of classes, and the algorithm may be trained using training data with ground truth labels indicating the true class of each image, e g. as verified manually by a human operator

[0010] Currently, there exists no mechanism in 3GPP standards which can prevent a VFL participant to decipher the training data from the model parameters and / or embeddings shared by other VFL participants Here, the term “training data” refers to the local data used for training by VFL participants consisting of both labels (in the case of an active participant) and other features (in the case of a passive participant) and their corresponding values Further, a mechanism to detect what kind of security capabilities are supported by a particular VFL participant and how a VFL coordinator can use this information when preparing or controlling a VFL process is not yet defined.

[0011] In view of the above, example embodiments of the present disclosure may inter alia allow improving security in the context of VFL processes performed by NFs in communication systems More specifically example embodiments of the present disclosure may inter alia allow coordinating a security mechanism between VFL participants.

[0012] According to an exemplary aspect of the present disclosure, a method is disclosed. The method may at least comprise: obtaining Vertical Federated Learning (VFL) participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model. In example embodiments of the method, the method may be performed by at least one network function (NF). For example, the at least one network function may be comprised by an apparatus. For example, the at least one network function may be at least one network function of a communication system, such as a communication system according to 3GPP standard. Further, the at least one network function may be at least one network function of 5GC network For example, the at least one network function may be or comprise a network data analytics function (NWDAF). For example, the NWDAF may be or comprise one or more VFL participants For example, the NWDAF may comprise a model training logical function (MTLF) which performs or is involved in the method. For example, the MTLF may be or comprise a VFL initiator NF. For example, the MTLF may be or comprise a VFL coordinator NF. For example, the at least one network function may be or comprise a network repository function (NRF). For example, the at least one network function may be or comprise a network exposure function (NEF). For example, the at least one network function may be or comprise an application function (AF) For example, the AF may be or comprise one or more (e g a single or multiple, at least two) VFL participants. For example, the at least one network function may comprise a VFL initiator NF, a VFL coordinator NF, an NRF, an NEF, and one or more VFL participants. For example, the at least one network function may comprise a VFL initiator NF represented or comprised by an MTLF of an NWDAF, a VFL coordinator NF represented or comprised by an MTLF of an NWDAF, an NRF, an NEF, one or more VFL participants represented or comprised by an NWDAF, and one or more VFL participants represented or comprised by an AF In an embodiment, the VFL coordinator NF and the NEF may be the same entity.

[0013] As used herein, a VFL participant may be understood as an entity which is capable of or intended to participate in a VFL process for training a machine learning (ML) model. In this context, artificial intelligence (Al) is a field of technology focused on creating intelligent systems Machine learning (ML) is a subset of Al that emphasizes statistical learning from data. Artificial neural network (ANN) algorithms are an example of a class of algorithms used in ML, inspired by a simplification of neurons in a brain. ML is An ML lifecycle can be broken up into two parts, namely a training phase in which an ML model is created or “trained” by running a specified subset of data into the model and an ML inference phase in which the ML model is applied to data to produce actionable output. As such, a VFL participant may be understood as an entity capable of training its local ML model using a set of training data, sharing only certain model parameters / embeddings such as locally predicted labels with other VFL participants after each round of training, without ever sharing their raw training data or local ML models with other VFL participants, for example using a VLF training framework such as MMVFL (S. Feng et al. 2024, “MMVFL: A Simple Vertical Federated Learning Framework for Multi-Class Multi-Participant Scenarios”, Sensors, 24(2), 619 <URL: https: / / www.mdpi.eom / 1424-8220 / 24 / 2 / 619>) .

[0014] As used herein, VFL participant information may be understood as any information or data based on which it is possible to identify a group of at least one VFL participant and to determine whether the respective VFL participants of the group support at least one security mechanism. For example, VFL participant information may constitute or comprise a group or list of VFL participants in association with respective security capability information indicating whether the at least one VFL participant supports at least one security mechanism. For example, VFL participant information may constitute or comprise a table with a first column or row listing at least one VFL participant and a second column or row containing information, such as True / False flags, Yes / No flags, binary information, etc., indicative of whether or that the respective VFL participant of the first column or row supports at least one specific security mechanism. For example, the table may comprise one or more further columns or rows containing information, such as True / False flags, Yes / No flags, binary information, etc., indicative of whether the respective VFL participant of the first column or row supports, respectively, one or more further specific security mechanisms.

[0015] As used herein, a security mechanism may be understood as any mechanism or method which is capable of preventing a VFL participant to obtain ML model training data from other VFL participants in plain form, i.e deciphered. For example, a security mechanism may be based on encryption, using for example cryptographic defence strategies (CDS) such as multi-party computation (MFC), trusted execution environment (TEE), and / or homomorphic encryption (HE). For example, a security mechanism may be based on privacy preservation, such as privacy preservation by randomly adding noise, gradient discretization, gradient sparsification, or their hybrids. Examples of suitable security mechanisms based on CDS and / or privacy preservation are provided for example in (Y Liu et al 2024, "Vertical Federated Learning: Concepts, Advances, and Challenges" in IEEE Transactions on Knowledge and Data Engineering <URI:https: / / ieeexplore ieee org / document / 10415268>)

[0016] As used herein, security capability information may be understood as any information or data based, at least in part, on which it is possible to determine whether a VFL participant associated with the respective security capability information supports at least one specific security mechanism. For example, the security capability information may constitute or comprise a respective True / False flag or Yes / No flag for the respective VFL participant and for the respective specific security mechanism. For example, the VFL participant and the security capability information can be associated in that they are contained within the same row or column of a table or an array. For example, the VFL participant and the security capability information can be associated by a bijective mathematical function which assigns respective security capability information to at least one VFL participant

[0017] As used herein, a preferred security mechanism may be understood as a security mechanism to be mandatorily used for a VFL process. For example, the preferred security mechanism may be specified by an NF involved in the VFL process, such as a VFL initiator NF or a VFL coordinator NF. For example, one or more exceptions may be defined, wherein the preferred security mechanism is not to be used mandatorily if a respective exception applies

[0018] As used herein, a first selection of VFL participants among the at least one VFL participant may be understood as a first subgroup obtained by selecting VFL participants from the group of VFL participants represented by the VFL participant information. The first selection of VFL participants may comprise none, one, more than one or all VFL participants from the group of VFL participants.

[0019] As used herein, a VFL participant supporting a security mechanism may be understood such that the VFL participant is capable of performing a VFL process using the respective security mechanism.

[0020] As used herein, a VFL process may be understood as a training of a machine learning (ML) model using vertical federated learning (VFL) VFL may be understood as a federated learning setting where multiple parties with different features about the same set of users, or different features about overlapping samples, tram an ML model without exposing their raw data or model parameters After training, the ML model can be used for inference. For example, the VFL process may be performed using an ML model training algorithm such as gradient descent. However, the present disclosure is not limited to using gradient descent and other ML model training algorithm are also conceivable, such as distributed coordinate descent methods

[0021] According to the exemplary aspect of the present disclosure, the method may comprise obtaining VFL participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism In embodiments, the VFL participant information may represent more than one VFL participant, for example at least two VFL participants, or a larger number of VFL participants. In embodiments, a respective security capability information may exist for (e.g. only) one VFL participant, even though the VFL participant information represents more than one (e.g. at least two) VFL participant In example embodiments, respective security capability information may exist for more than one, e.g. for each (or all) VFL participants represented by the VFL participant information In embodiments, the security capability information may be indicative whether the respective VFL participant supports at least one security mechanism. In example embodiments, the security capability information may be indicative whether or not the respective VFL participant supports at least one security mechanism. In example embodiments, the security capability information may be indicative that (or e.g. if or whether, or whether or not) the respective VFL participant supports a first specific security mechanism and that (or e g. if or whether, or whether or not) the respective VFL participant supports a second specific security mechanism. In example embodiments, the security capability information may be indicative that (or e.g. if or whether, or whether or not) the respective VFL participant supports at least one further specific security mechanism. In embodiments, obtaining VFL participant information may be performed by a VFL initiator NF, a VFL coordinator NF, an NRF, or any combination of these. By obtaining VFL participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism, information regarding the supported security mechanisms of the at least one VFL participant is provided to a certain NF of a communication system, based on which a security mechanism can be coordinated between VFL participants to be involved in a VFL process may be achieved. According to the exemplary aspect of the present disclosure, the method may comprise determining that a preferred security mechanism has been specified. In embodiments, determining that a preferred security mechanism has been specified may be or comprise determining whether a preferred security mechanism has been specified In example embodiments, determining that a preferred security mechanism has been specified may be or comprise determining whether or not a preferred security mechanism has been specified. In embodiments, determining that a preferred security mechanism has been specified may be performed by a VFL coordinator NF, an NRF, or both. By determining that a preferred security mechanism has been specified, it may be achieved that a security mechanism can be coordinated between VFL participants to be involved in a VFL process.

[0022] According to the exemplary aspect of the present disclosure, the method may comprise, if a preferred security mechanism has been specified, obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism. In example embodiments, obtaining or performing a first selection of VFL participants may be performed in response to determining that a preferred security mechanism has been specified. In example embodiments, the VFL participants of the first selection each support the preferred security mechanism. In example embodiments, obtaining or performing a first selection of VFL participants among the at least one VFL participant may comprise including in the first selection all VFL participants from the group of VFL participants represented by the VFL participant information, for example if it has been determined beforehand that all these VFL participants support the preferred security mechanism. In embodiments, obtaining or performing a first selection of VFL participants may be performed by a VFL coordinator NF in that the VFL coordinator NF selects a first subgroup from the group of VFL participants represented by the VFL participant information In example embodiments, obtaining or performing a first selection of VFL participants may be performed by a VFL coordinator NF together with an NRF in that the NRF selects a first subgroup from the group of VFL participants represented by the VFL participant information, and in that the NRF transmits the first selection to the VFL coordinator NF which thus obtains the first selection. By obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism, it may be achieved that the preferred security mechanism can be coordinated between VFL participants to be involved in a VFL process.

[0023] According to the exemplary aspect of the present disclosure, the method may comprise, if a preferred security mechanism has been specified, preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model. In embodiments, preparing a VFL process may be performed in response to determmmg that a preferred security mechanism has been specified. In example embodiments, preparing a VFL process may be performed for jointly training a machine learning model, for example if two or more VFL participants support the preferred security mechanism and thus are involved in the VFL process. In embodiments, preparing a VFL process may be performed by a VFL coordinator NF together with one or more VFL participants, such as the VFL participants of the first selection In example embodiments, a VFL initiator NF may be involved in preparing the VFL process In example embodiments, an NRF, an NEF or both may also be involved By preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model, it may be achieved that security of the VFL process to be performed is improved.

[0024] According to the exemplary aspect of the present disclosure, the method may comprise, if a preferred security mechanism has been specified, executing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model. Thereby, it may be achieved that the VFL process is performed and an ML model is trained by the VFL process.

[0025] In example embodiments of the method, the method may further comprise: if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model.

[0026] As used herein, a common security mechanism may be understood as a security mechanism which is supported by the largest number of VFL participants among the group of VFL participants represented by the VFL participant information. In example embodiments, the common security mechanism may be supported by one, some or all (e.g each) VFL participants among the group of VFL participants.

[0027] In example embodiments, identifying a common security mechanism, obtaining or performing a second selection of VFL participants and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model may be performed in response to (e.g. after or subsequent to) determining that no preferred security mechanism has been specified. In example embodiments, identifying a common security mechanism may be performed by a VFL coordinator NF. In example embodiments, the VFL participants of the second selection each support the common security mechanism. In example embodiments, obtaining or performing a second selection of VFL participants among the at least one VFL participant may comprise including in the second selection all VFL participants from the group of VFL participants represented by the VFL participant information, for example if it has been determined beforehand that all these VFL participants support the common security mechanism In example embodiments, obtaining or performing a second selection of VFL participants may be performed by a VFL coordinator NF in that the VFL coordinator NF selects a second subgroup from the group of VFL participants represented by the VFL participant information. In example embodiments, preparing a VFL process may be performed for (e.g jointly) training a machine learning model, for example if two or more VFL participants support the common security mechanism and thus are involved in the VFL process. In embodiments, preparing a VFL process may be performed by a VFL coordinator NF together with one or more VFL participants, such as the VFL participants of the second selection. In example embodiments, a VFL initiator NF may be involved in preparing the VFL process. In embodiments, an NRF, an NEF or both may also be involved. By identifying a common security mechanism, obtaining or performing a second selection of VFL participants and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model, it may be achieved that the common security mechanism may be coordinated between VFL participants to be involved in a VFL process Thus the security of the VFL process to be performed may be improved

[0028] According to the exemplary aspect of the present disclosure, the method may comprise, if a common security mechanism has been specified, executing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model. Thereby, it may be achieved that the VFL process is performed and an ML model is trained by the VFL process.

[0029] In example embodiments of the method, identifying a common security mechanism, obtaining or performing a second selection of VFL participants, and preparing (and / or executing) a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model may also be performed if (and e.g. in response to determining that) a preferred security mechanism has been specified, and if (and e g. in response to determining that) an additional condition is or is not fulfilled. For example, identifying a common security mechanism, obtaining or performing a second selection of VFL participants, and preparing (and / or executing) a respective VFL process may be performed if a preferred security mechanism has been specified, but one or more (e.g. more than a threshold or more than a threshold percentage) of VFL participants do not support the preferred security mechanism.

[0030] In example embodiments of the method, the method may at least comprise: obtaining Vertical Federated Learning (VFL) participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model.

[0031] In example embodiments of the method, the method may further comprise: registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.

[0032] As used herein, registering a VFL participant may be understood as a process in which VFL participant identification information in association with respective security capability information is provided from a first entity such as a NF to a second entity such as a different NF. For example, registering a VFL participant may comprise providing information which identifies the VFL participant. For example, registering a VFL participant may comprise providing information indicating VFL capabilities of the VFL participant For example, registering a VFL participant may comprise providing information indicating a role of the VFL participant, such as a role as an active VFL participant of a role as a passive VFL participant. For example, registering a VFL participant may comprise providing information indicating at least one security mechanism supported by the VFL participant. For example, registering a VFL participant may comprise providing information indicating at least one parameter related to the at least one security mechanism, such as a parameter indicating an encryption strength (e.g. indicating an encryption key length) in an encryption-based security mechanism, or a minimum threshold of privacy expected in a privacy preservation-based security mechanism, to name non-limiting examples. In example embodiments, a VFL participant may register in an NRF For example, a VFL participant implemented or comprised by an NWDAF or a trusted AF may register in an NRF. In example embodiments, a VFL participant may register in an NEF and the NEF may register the VFL participant in an NRF at a later point For example, a VFL participant implemented or comprised by an untrusted AF may register in an NEF and the NEF may register the VFL participant in an NRF at a later point. As used herein, VFL participant identification information may be understood as any information or data based on which a specific VFL participant can be identified By registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant, VFL participant information for coordinating a security mechanism between VFL participants can be obtained.

[0033] In example embodiments of the method, the method may further comprise: requesting an initiation of a VFL process.

[0034] In example embodiments, requesting an initiation of a VFL process may be performed by a VFL initiator NF. In example embodiments, requesting an initiation of a VFL process may be performed in that a VFL initiator NF transmits a respective request to a VFL coordinator NF By requesting an initiation of a VFL process, it may be achieved that a VFL initiator NF is enabled to initiate a VFL process. In example embodiments, requesting an initiation of a VFL process may comprise an indication that a security mechanism is required for the VFL process. For example the indication may be in the form of a “secured VFL” flag. Thereby it may be achieved that the VFL initiator NF is enabled to ensure the use of a security mechanism for performing a VFL process

[0035] In example embodiments of the method, obtaining the VFL participant information may comprise: requesting and / or performing a discovery of VFL participants.

[0036] As used herein, a discovery may be understood as a search for VFL participants which fulfil at least one requirement. For example, the at least one requirement may be or comprise that a respective VFL participant has registered in an NRF. For example, the at least one requirement may be or comprise that a respective VFL participant has registered in a NRF and supports at least one security mechanism. For example, the at least one requirement may be or comprise a security -related requirement, such as the requirement that VFL participants to be discovered support a specified security mechanism, e.g. a preferred security mechanism, or the requirement that a certain parameter of a security mechanism fulfils a certain condition, e g. is equal or larger than a threshold As a non-limiting example, the condition may be the compliance with a specified encryption strength (e.g. an encryption key length) in an encryption-based security mechanism. As a further non-limiting example, the threshold may be a minimum threshold of privacy expected in a privacy preservation-based security mechanism. In example embodiments, requesting and / or performing a discovery of VFL participants may be performed by a VFL coordinator NF together with an NRF in that the VFL coordinator NF transmits a discovery request to the NRF and subsequently the NRF performs a respective discovery among VFL participants registered in the NRF In example embodiments, requesting and / or performing a discovery of VFL participants may be performed by a VFL initiator NF together with an NRF in that the VFL initiator NF transmits a discovery request to the NRF and subsequently the NRF performs a respective discovery among VFL participants registered in the NRF. By requesting and / or performing a discovery of VFL participants, it may be achieved that VFL participants can be identified so that a security mechanism can be coordinated between them In example embodiments, requesting a discovery of VFL participants may comprise an indication that a security mechanism is required for the VFL process. For example the indication may be in the form of a “securedVFL” flag. For example, the indication may be or correspond to the indication comprised by a previous request for an initiation of a VFL process.

[0037] In example embodiments of the method, obtaining the VFL participant information may comprise: obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.

[0038] In example embodiments, the list is obtained by an NRF as a result of a discovery performed by the NRF, and the list is then transmitted to (and thus also obtained by) a VFL coordinator NF having requested the discovery. In example embodiments, the list is obtained by an NRF as a result of a discovery performed by the NRF, and the list is then transmitted to (and thus also obtained by) a VFL initiator NF having requested the discovery. In example embodiments, the list received by the VFL initiator NF may be transmitted to (and thus also obtained by) a VFL coordinator NF, for example together with a request for initiating a VFL process. By obtaining a list representing the at least one VFL participant, it may be achieved that a security mechanism can be coordinated between the VFL participants in the list which are to be involved in a VFL process

[0039] In example embodiments of the method, obtaining the VFL participant information may comprise: obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list

[0040] Thereby, it may be achieved that respective security capability information for the at least one VFL participant in the list becomes available. In example embodiments, the list comprising the at least one VFL participant may be a column or row of a table or an array, and the VFL participant can be associated with the security capability information in that they are both contained within the same row (if the list comprising the at least one VFL participant is a column) or column (if the list comprising the at least one VFL participant is a row) of the table or array

[0041] In example embodiments of the method, obtaining the VFL participant information may comprise: requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or obtaining the respective security capability information from the respective VFL participant.

[0042] Thereby, it may be achieved that respective security capability information also becomes available for the at least one VFL participant in the list for which no associated security capability information has been obtained together with the list. For example, the at least one VFL participant in the list for which no associated security capability information has been obtained together with the list may be a VFL participant which has been registered without security capability information. For example, the at least one VFL participant in the list for which no associated security capability information has been obtained together with the list may be a VFL participant for which security capability information has been registered, but has not been retrievable. In example embodiments, requesting security capability information from the VFL participant may be performed in that a VFL coordinator NF transmits a respective request to the VFL participant. In example embodiments, obtaining the security capability information from the respective VFL participant may be performed in that a VFL coordinator NF receives the security capability information from the VFL participant, for example in response to a request for security capability information.

[0043] In example embodiments of the method, the method may further comprise: initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.

[0044] As used herein, a security negotiation may be understood as a procedure in which a security mechanism is identified and coordinated between VFL participants In example embodiments of the method, preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model may comprise at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the preferred security mechanism; rejecting a VFL request.

[0045] Finalisation of VFL participant selection may comprise an addition or deletion of individual VFL participants, or a verification that the VFL participant selection is correct. In example embodiments, configuring the use of the preferred security mechanism may comprise the specification of security parameters related to the preferred security mechanism. Rejecting a VFL request may be performed by a VFL coordinator NF, for example if (and e g. in response to determining that) a security negotiation has not been successful.

[0046] In example embodiments of the method, preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model may comprise at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the common security mechanism; rejecting a VFL request.

[0047] Finalisation of VFL participant selection may comprise an addition or deletion of individual VFL participants, or a verification that the VFL participant selection is correct. In embodiments, configuring the use of the common security mechanism may comprise the specification of security parameters related to the common security mechanism. Rejecting a VFL request may be performed by a VFL coordinator NF, for example if (and e.g. in response to determining that) a security negotiation has not been successful.

[0048] In example embodiments of the method, requesting the initiation of the VFL process may comprise specifying the preferred security mechanism. Thereby, it may be achieved that the preferred security mechanism is used for performing the VFL process. In example embodiments, specifying the preferred security mechanism may comprise specifying at least one parameter related to the preferred security mechanism. For example, the at least one parameter may define an enciyption strength (e g. an enciyption key length) in an enciyption-based security mechanism. For example, the at least one parameter may define a minimum threshold of privacy expected in a privacy preservation-based security mechanism. In example embodiments, requesting a discovery of VFL participants may comprise specifying the preferred security mechanism specified in advance when requesting the initiation of the VFL process. In example embodiments, performing a discovery of VFL participants may take into account the preferred security mechanism specified in advance when requesting the discovery of VFL participants. For example, the discovery may take into account the preferred security mechanism in that the discovery selects (e.g only) VFL participants supporting the preferred security mechanism. Thereby, it may be achieved that the discovery yields VFL participants supporting the preferred security mechanism, so that performing or obtaining the first selection of VFL participants can be simplified. In example embodiments, performing a discovery of VFL participants may also take into account the at least one parameter related to the preferred security mechanism. For example, the discovery may take into account the at least one parameter related to the preferred security mechanism in that the discovery selects (e.g. only) VFL participants complying with the at least one parameter. Thereby, it may be achieved that the discoveiy yields VFL participants supporting the preferred security mechanism and complying with the at least one parameter, so that performing or obtaining the first selection of VFL participants can be further simplified

[0049] In example embodiments of the method, the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.

[0050] For example, an encryption-based security mechanism may be based on homographic encryption or on additive homographic encryption. For example, an encryption-based security mechanism may involve encryption and / or decryption of data using an encryption key. For example, a privacy preservation-based security mechanism may be based on differential privacy. For example, a privacy preservation-based security mechanism may involve the modification of at least one gradient used in stochastic gradient descent of an ML model. For example, the modification of the at least one gradient may involve the addition of noise For example, a privacy preservationbased security mechanism may be based on an epsilon parameter and / or a delta parameter

[0051] In example embodiments of the method, at least one parameter of the at least one security mechanism may vary as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process.

[0052] For examples the at least one security mechanism may vary as a function of a granularity of an analytics identifier or of a model identifier of an ML model to be trained. For example, an analytics ID for advertisement can have a different privacy noise addition than an analytics ID for network optimization. For example, the at least one security mechanism may be different in a case where (e.g. all) VFL participants are from a same vendor, compared to a case where VFL incorporates participants from different vendors or different domains (e.g. 5G Core and AF).

[0053] According to the exemplary aspect, a respective apparatus for a network function is disclosed The apparatus may comprise at least one processor and at least one memory The at least one memory may store instructions that, when executed by the at least one processor, cause the apparatus at least to perform: obtain Vertical Federated Learning (VFL) participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determine that a preferred security mechanism has been specified; if a preferred security mechanism has been specified: obtain or perform a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and prepare a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model.

[0054] Within the exemplary aspect, the disclosure of any action of the method shall also be considered as a disclosure of an instruction that, when executed by the at least one processor of the apparatus, causes the apparatus to perform the respective action.

[0055] In an example embodiment, the network function may comprise or may be comprised in the apparatus. In an example embodiment, the network function may be a VLF coordinator In an example embodiment, the network function may be a network data analytics function (NWDAF) In an example embodiment, the NWDAF may comprise a model training logical function (MTLF)

[0056] According to the exemplary aspect, a respective apparatus is disclosed, too. The apparatus according to the exemplary aspect may comprise means for performing a method according to the exemplary aspect. Within the exemplary aspect, the disclosure of any method action shall also be considered as a disclosure of means for performing the respective method action. The apparatus according to the exemplary aspect may be an apparatus for a network function.

[0057] In an example embodiment, the network function may comprise or may be comprised in the apparatus. In an example embodiment, the network function may be a VLF coordinator In an example embodiment, the network function may be a network data analytics function (NWDAF). In an example embodiment, the NWDAF may comprise a model training logical function (MTLF)

[0058] The means or functionality of the apparatus according to the exemplary aspect can be implemented in hardware and / or software They may comprise one or multiple modules or units providing the respective functionality. They may for instance comprise at least one processor for executing computer program code for performing the required functions, at least one memory storing the program code, or both. Alternatively, they could comprise for instance circuitry that is designed to implement the required functions, for instance implemented in a chipset or a chip, like an integrated circuit In general, the means may comprise for instance one or more processing means or processors.

[0059] According to the exemplary aspect, a respective computer-readable medium is disclosed. The computer-readable medium may be non-transitory. The computer-readable medium according to the exemplary aspect may comprise program instructions that, when executed by an apparatus for a network function, cause the apparatus to perform a method according to the exemplary aspect. The computer-readable medium according to the exemplary aspect could for example be a disk or a memory or the hke. The program mstructions could be stored in the computer-readable medium in the form of instructions encoding the computer-readable medium. The computer-readable medium may be intended for taking part in the operation of a device, like an internal or external memory, for instance a Read-Only Memory (ROM) or hard disk of a computer, or be intended for distribution of the program, like an optical disc.

[0060] Accordmg to the exemplary aspect, a respectrve computer program rs drsclosed. The computer program according to the exemplary aspect may comprise instructions which, when executed by an apparatus, cause the apparatus to perform a method according to the exemplary aspect. The apparatus may be an apparatus for a network function.

[0061] The computer program according to the exemplary aspect may be stored on a computer-readable storage medium, in particular a tangible and / or non-transitory computer-readable storage medium In particular, the computer program according to the exemplary aspect may be stored on a non-transitory computer-readable medium according to the exemplary aspect.

[0062] It is to be understood that the presentation of the embodiments disclosed herein is merely by way of examples and non-limiting

[0063] Other features of the present disclosure will become apparent from the following detailed description considered in conjunction with the accompanying drawings. It is to be understood, however, that the drawings are designed solely for purposes of illustration and not as a definition of the limits of the present disclosure, for which reference should be made to the appended claims It should be further understood that the drawings are not drawn to scale and that they are merely intended to conceptually illustrate the structures and procedures described herein.

[0064] BRIEF DESCRIPTION OF THE FIGURES

[0065] Some example embodiments will now be described with reference to the accompanying drawings in which

[0066] FIG. 1 exemplarily illustrates, in a schematic diagram, a system architecture of a communication system in which example embodiments of the present disclosure may be performed;

[0067] FIG. 2 shows, in a data flow chart, an example embodiment of a method according to the present disclosure;

[0068] FIG. 3 shows, in a data flow chart, another example embodiment of a method according to the present disclosure; FIG. 4 shows, in a flow chart, another example embodiment of a method according to the present disclosure;

[0069] FIG. 5 shows, in a schematic block diagram, an example embodiment of an apparatus for a network function according to the present disclosure; and

[0070] FIG. 6 shows, in a schematic illustration, examples of tangible and non-transitory computer-readable storage media;

[0071] DETAILED DESCRIPTION OF THE FIGURES

[0072] The following description serves to deepen the understanding of the present disclosure and shall be understood to complement and be read together with the description of example embodiments of the present disclosure as provided in the above SUMMARY section of this specification

[0073] In the following and with reference to FIG. 1, a system architecture of a communication system, in which the present disclosure may be applied, is described. While the specific system in the examples below is for a 5G system, this is to be considered (e.g. only) as a non-limiting example, and any next generation systems or standards above and beyond 5G are also considered

[0074] A 5G system (5GS) 100 is a communication system (e.g , a 3GPP system) comprising a (Radio) Access Network ((R)AN) 102 (referred to generally herein as a RAN) and a 5G core network (5GC) that communicate with 5G User Equipment (UE) 101 The RAN 102 and 5GC together may be referred to as a 5G network, a 5G mobile network, a 5G communication network, etc

[0075] RAN 102 provides radio or wireless connectivity to a UE 101 and connects the UE 101 to the 5GC. RAN 102 may comprise a Next Generation Radio Access Network (NG-RAN), an Evolved Universal Terrestrial Radio Access Network (E-UTRAN), a non-3GPP access network (N3AN), a non-terrestrial access network (NTN), and / or another type of RAN connecting to 5GC. RAN 102 may support access through at least one RAN node, e g. a gNodeB (gNB), an ng-eNodeB (ng-eNB), an eNodeB (eNB), and / or a Wireless Local Area Network (WLAN) access point. RAN 102 may support satellite radio access, new Radio Access Technologies (RATs), etc.

[0076] 5G core network (5GC) comprises a Network Functions (NF), which may be implemented as a network element on dedicated hardware, as a chip or a chipset comprised in a network element, as a software instance running on appropriate dedicated or general hardware, as a virtualized network function (VNF) instantiated on a dedicated or general virtualization platform, etc. Some or all of these NFs can be stateless, virtualized, hosted on virtual machines or servers, operating-system-level virtualized, containerized, hosted in multi-user spaces, can be application virtualized, network virtualized, storage virtualized, server virtualized, or desktop virtualized, can be hosted / stored on / at a cloud computing environment, and / or the like

[0077] The NFs comprised by the 5GC as shown in FIG. 1 are: Access and Mobility Management function (AMF) 109, Session Management function (SMF) 110, User plane function (UPF) 112 which may be connected to (external) Data Network (DN) 113, Policy Control Function (PCF) 105, Authentication Server Function (AUSF) 108, Unified Data Management (UDM) 106, Application Function (AF) 107, Network Exposure function (NEF) 104, Network Repository function (NRF) 103, and Network Data Analytics Function (NWDAF) 111 comprising Model Training Logical Function (MTLF) I l la and Analytics Logical Function (AnLF) 111b. In general, the 5GC may comprise other NFs not mentioned here and not shown in FIG. 1, such as for example Network Slice Selection Function (NSSF) or not comprise one or more NFs mentioned above.

[0078] Turning now to FIG 2, a data flow chart of an example embodiment of a method according to the present disclosure is shown. More specifically, the succession of actions and / or steps between a VFL initiator NF 201, a VFL coordinator NF 202, NRF 203, NEF 204, a first VFL participant 205 and a second VFL participant 206 is shown. In this non-limiting example, the VFL initiator NF 201 and the VFL coordinator NF 202 are implemented or comprised by Model Training Logical Function (MTLF) of NWDAF, but they may in general be implemented or comprised by other NFs Further, whereas two VFL participants are involved in this example embodiment, the present disclosure generally covers any reasonable number of VFL participants, in particular one VFL participant or more than two VFL participants. In the example of FIG 2, the first VFL participant 205 is an active VFL participant and is implemented by NWDAF, whereas the second VFL participant 206 is also an active VFL participant, but is implemented by AF. In general however, any VFL participant involved may be active or passive and may be implemented by NWDAF, by AF, or by other NFs

[0079] Within action 211, the first VFL participant 205 registers in the NRF 203 with respect to its VFL capabilities, its role as an active VFL participant, and its supported security mechanisms. A supported security mechanism of the supported security mechanisms may be, for example, an encryption-based security mechanism, a privacy preservation-based security mechanism, or both Further, the first VFL participant 205 indicates security -related parameters, for example a minimum threshold of privacy expected in a privacy preservation-based security mechanism, to name but one non-limiting example.

[0080] Within action 212, the second VFL participant 206 registers in the NEF 204 with respect to its VFL capabilities, its role as an active VFL participant, and its supported security mechanisms. Again, the supported security mechanisms may be, for example, an encryption-based security mechanism, a privacy preservation-based security mechanism, or both.

[0081] Within action 213, NEF 204 registers in NRF 203 the VFL profile of the second VFL participant 206 implemented by AF. More specifically, NEF 204 registers in NRF 203 the information registered previously, i e. within action 212, in NEF 204 by the second VFL participant 206. This information includes in particular the supported security mechanisms of the second VFL participant 206.

[0082] Actions 211, 212 and 213 thus may be considered as a registering of VFL participants. As a result of actions 211, 212 and 213, NRF 203 in particular possesses information which identifies the first VFL participant 205 and the second VFL participant 206, and which indicates the supported security mechanisms of the first VFL participant 205 and the second VFL participant 206 Accordingly, NRF 203 also possesses information whether the first VFL participant 205 and the second VFL participant 206, respectively, support at least one security mechanism.

[0083] Within action 220, VFL initiator NF 201 sends a request for initiating a VFL process to VFL coordinator NF 202. The request comprises a “securedVFL” flag as an indication that a security mechanism is required for the VFL process Furthermore, the request specifies a preferred security mechanism

[0084] Within action 230, VFL coordinator NF 202, based, at least in part, on the request received within action 220 from VFL initiator NF 201, sends a request to NRF 203 for a discovery of suitable VFL participants for the VFL process. In this context, suitable VFL participants may be understood as VFL participants which inter alia adhere the “securedVFL” flag, i e which support at least one security mechanism

[0085] Within action 240, e g. after performing a respective discovery of VFL participants which support at least one security mechanism, NRF 203 sends a list of VFL participants to VFL coordinator NF 202. The list includes VFL participants which support at least one security mechanism. In this non-limiting example, it is assumed that the first VFL participant 205 supports both an encryption-based security mechanism and a privacy preservationbased security mechanism. The second VFL participant 206 supports (e.g. only) an encryption-based security mechanism. Since both the first VFL participant 205 and the second VFL participant 206 thus support at least one security mechanism, and since they have both been registered at NRF 203, they have both been found in the discovery. Thus, the list of selected VFL participants here comprises the first VFL participant 205 and the second VFL participant 206. Together with the list of selected VFL participants, NRF 203 sends information associated with the first and second VFL participant which indicates the security mechanisms supported by the first and second VFL participant, respectively. In this specific example, NRF 203 sends a table to VFL coordinator NF 202. The table includes a first column which lists the VFL participants, a second column which indicates whether the respective VFL participant supports an encryption-based security mechanism, and a third column which indicates whether the respective VFL participant supports a privacy preservation-based security mechanism. With the supported security mechanisms of the first and second VFL participant specified above for this non-limiting example, the table may have the following exemplary structure and content:

[0086] As a result, the VFL coordinator NF 202 likewise possesses information which identifies the first VFL participant 205 and the second VFL participant 206, and which indicates the supported security mechanisms of the first VFL participant 205 and the second VFL participant 206. Accordingly, the VFL coordinator NF 202 also possesses information whether the first VFL participant 205 and the second VFL participant 206, respectively, support at least one security mechanism.

[0087] Within action 250, VFL coordinator NF 202 initiates security negotiation for the first VFL participant 205 and the second VFL participant 206.

[0088] Actions 211, 212, 213, 220, 230 and 240 in combination may be considered as a registration and discovery phase, which is followed by a selection and security negotiation phase comprising actions 260 and 270, as described in the following.

[0089] Within action 260, VFL coordinator NF 202 determines that a preferred security mechanism has been specified by the VFL initiator NF 201 within action 220. Accordingly, VFL coordinator NF 202 filters the list (or in this specific example: the table) of VFL participants for VFL participants which support the preferred security mechanism. In doing so, VFL coordinator NF 202 performs a (first) selection of VFL participants which support the preferred security mechanism. In this non-limiting example, the preferred security mechanism specified within action 220 by the VFL initiator NF 201 has been an encryption-based security mechanism, which is supported by both the first VFL participant 205 and the second VFL participant 206 Thus, the (first) selection here includes the first VFL participant 205 and the second VFL participant 206

[0090] In an embodiment, VFL coordinator NF 202 may specify, together with the request for discovery of action 230, the preferred security mechanism. In this case, filtering the list (or table) of VFL participants for VFL participants which support the preferred security mechanism may already be performed by NRF 203. The resulting (e g first) selection may then be sent to the VFL coordinator NF 202, which thereby obtains the (e g first) selection of VFL participants which support the preferred security mechanism.

[0091] Within action 270, VFL coordinator NF 202 or VFL initiator NF 201 assigns a VFL session identifier, coordinates with the first VFL participant 205 and the second VFL participant 206 to prepare the VFL process for training a machine learning model, and configures the use of the preferred security mechanism, i e in this example the encryption-based security mechanism.

[0092] In an embodiment, the VFL coordinator NF 202 and the NEF 204 may be the same entity, for example in the case of cross-domain VFL comprising 5GC and AF. Within an action not shown in Fig. 2, the VFL process for training a machine learning model may be executed with the first VFL participant 205 and the second VFL participant 206.

[0093] Turning now to FIG. 3, a data flow chart of another example embodiment of a method according to the present disclosure is shown. Similarly to FIG. 2, FIG. 3 shows the succession of actions between a VFL initiator NF 301, a VFL coordinator NF 302, NRF 303, NEF 304, a first VFL participant 305 and a second VFL participant 306 In this non-limiting example of FIG 3, the VFL initiator NF 301 and the VFL coordinator NF 302 are implemented or comprised by Model Training Logical Function (MTLF) of NWDAF, but they may in general be implemented or comprised by other NFs. Further, whereas two VFL participants are involved in this example embodiment, the present disclosure generally covers any reasonable number of VFL participants, in particular one VFL participant or more than two VFL participants. In the example of FIG 3, the first VFL participant 305 is again an active VFL participant and is implemented by NWDAF, whereas the second VFL participant 306 is also an active VFL participant, but is implemented by AF. In general however, any VFL participant involved may be active or passive and may be implemented by NWDAF, by AF, or by other NFs.

[0094] Within action 311, the first VFL participant 305 registers in the NRF 303 with respect to its VFL capabilities and its role as an active VFL participant, e g but not with respect to its supported security mechanisms

[0095] Within action 312, the second VFL participant 306 registers in the NEF 304 with respect to its VFL capabilities and its role as an active VFL participant, e.g but not with respect to its supported security mechanisms.

[0096] Within action 313, NEF 304 registers in NRF 303 the VFL profile of the second VFL participant 306 implemented by AF. More specifically, NEF 304 registers in NRF 303 the information registered previously, i e. within action 312, in NEF 304 by the second VFL participant 306. This information however does not include the supported security mechanisms of the second VFL participant 306.

[0097] Actions 311, 312 and 313 thus may be considered as a registering of VFL participants. As a result of actions 311, 312 and 313, NRF 303 possesses information which identifies the first VFL participant 305 and the second VFL participant 306 In contrast to the example embodiment of FIG. 2 however, NRF 303 at this state does not possess information which indicates the supported security mechanisms of the first VFL participant 305 and the second VFL participant 306, or which indicates whether the first VFL participant 305 or the second VFL participant 306 support at least one security mechanism.

[0098] Within action 320, VFL initiator NF 301 sends a request for initiating a VFL process to VFL coordmator NF 302. The request comprises a “securedVFL” flag as an indication that a security mechanism is required for the VFL process. In the example embodiment of FIG. 3, contrary to the example embodiment of FIG. 2, the request however does not specify a preferred security mechanism Within action 330, VFL coordinator NF 302, based on the request received within action 320 from VFL initiator NF 301, sends a request to NRF 303 for a discovery of suitable VFL participants for the VFL process. Suitable VFL participants, in particular in this context, may be understood as VFL participants. These inter alia may adhere the “securedVFL” flag, i.e. which support at least one security mechanism.

[0099] Within action 340, after performing a respective discovery, NRF 303 sends a list of VFL participants to VFL coordinator NF 302. In this example embodiment, where NRF 303 at this state does not possess information indicating the supported security mechanisms of the registered VFL participants (see above), the discovery cannot be directed towards VFL participants which support at least one security mechanism. This would also be the case if the supported security mechanisms had been registered, but had not been retrievable from NRF 303 Thus, the discovery may be directed towards other criteria, for example the VFL capabilities registered beforehand within actions 311, 312 and 313 In this example, the discovery yields the first VFL participant 305 and the second VFL participant 306 resulting from an analysis of their VFL capabilities. Accordingly, the list of VFL participants sent from NRF 303 to VFL coordinator NF 302 includes the first VFL participant 305 and the second VFL participant 306, but the list does not contain information associated with the first and second VFL participant which indicates the security mechanisms supported by the first and second VFL participant, respectively Therefore, VFL coordinator NF 302 in this example retrieves this information individually from the first and second VFL participant within actions 345, 346, 347 and 348, as described in the following.

[0100] Besides this, actions 311, 312, 313, 320, 330 and / or 340 in combination may be considered as a registration and discovery phase, which is followed by a selection and security negotiation phase comprising actions 345, 346, 347, 348, 360 and / or 370, as described in the following

[0101] Within action 345, VFL coordinator NF 302 requests, from the first VFL participant 305, information which indicates the security mechanisms supported by the first VFL participant 305.

[0102] Within action 346, the first VFL participant 305 transmits to VFL coordinator NF 302 respective information which indicates the security mechanisms supported by the first VFL participant 305.

[0103] Within action 347, VFL coordinator NF 302 requests, from the second VFL participant 306, information which indicates the security mechanisms supported by the second VFL participant 306. In an embodiment, the request may be sent via NEF 304.

[0104] Within action 348, the second VFL participant 306 transmits to VFL coordinator NF 302 respective information which indicates the security mechanisms supported by the second VFL participant 306. In an example embodiment, the information may be transmitted via NEF 304 As a result, the VFL coordinator NF 302 now possesses information which identifies the first VFL participant 305 and the second VFL participant 306, and which indicates the supported security mechanisms of the first VFL participant 305 and the second VFL participant 306. Accordingly, the VFL coordinator NF 302 also possesses information whether the first VFL participant 305 and the second VFL participant 306, respectively, support at least one security mechanism. In this non-limiting example, it is again assumed that the first VFL participant 305 supports both an encryption-based security mechanism and a privacy preservation-based security mechanism, and that the second VFL participant 306 supports (e.g. only) an encryption-based security mechanism.

[0105] Within action 360, VFL coordinator NF 302 determines that no preferred security mechanism has been specified, in particular not by the VFL initiator NF 301 within action 320. Accordingly, VFL coordinator NF 302 identifies an encryption-based security mechanism as a common security mechanism, i.e. as the kind of security mechanism which is supported by the largest number of VFL participants This is because, as explained above, an encryption-based security mechanism in this non-limiting example is assumed to be supported by both the first VFL participant 305 and the second VFL participant 306, whereas a privacy preservation-based security mechanism is assumed to be supported (e.g. only) be the first VFL participant 305. Subsequently, VFL coordinator NF 302 filters the list of VFL participants for VFL participants which support the common security mechanism In doing so, VFL coordinator NF 302 performs a (second) selection of VFL participants which support the common security mechanism (note that a respective first selection does not exist in this example embodiment, since no preferred security mechanism has been specified). In this non-limiting example, the (second) selection includes the first VFL participant 305 and the second VFL participant 306, which both support the common security mechanism.

[0106] Within action 370, VFL coordinator NF 302 or VFL initiator NF 301 assigns a VFL session identifier, coordinates with the first VFL participant 305 and the second VFL participant 306 to prepare the VFL process for training a machine learning model, and configures the use of the common security mechanism, i.e. in this example the encryption-based security mechanism.

[0107] In an embodiment, the VFL coordinator NF 302 and the NEF 304 may be the same entity, for example in the case of cross-domain VFL comprising 5GC and AF.

[0108] Within an action not shown in Fig. 3, the VFL process for training a machine learning model may be executed with the first VFL participant 305 and the second VFL participant 306.

[0109] Turning now to FIG. 4, a flow chart of another example embodiment of a method according to the present disclosure is shown. Within action 410, VFL participant information representing at least one VFL participant in association with respective security capability information is obtained, wherein the security capability information is indicative that a the respective VFL participant supports at least one security mechanism.

[0110] Within action 420, determination that a preferred security mechanism has been specified is performed

[0111] Within action 430, if a preferred security mechanism has been specified, a first selection of VFL participants among the at least one VFL participant is obtained or performed, wherein the VFL participants of the first selection support the preferred security mechanism. Furthermore, a VFL process is prepared using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model.

[0112] FIG. 5 is a block diagram of an example embodiment of an apparatus 500 for a network function. For instance, apparatus 500 may be configured for performing actions of one or more of the embodiments of a method according to the present disclosure, such as the embodiments of a method explained in the context of FIG 2, FIG. 3 and FIG. 4

[0113] Apparatus 500 comprises a processor 501. Processor 501 may represent a single processor or two or more processors, which are for instance at least partially coupled, for instance via a bus Processor 501 executes a program code stored in program memory 502 (for instance program code causing apparatus 500 to perform alone and / or together with one or more further apparatuses 500, one or more of the embodiments of a method according to the present disclosure or parts thereof, when executed on processor 501), and interfaces with a main memory 503.

[0114] Program memory 502 may also comprise an operating system for processor 501. Some or all of memories 502 and 503 may also be included into processor 501. Program memory 502 and main memory 503 may be formed by a single memory.

[0115] Moreover, processor 501 may control a communication interface 504 which is for example configured to communicate according to a communication system like a 3GPP communication system. Communication interface 504 of apparatus 500 may be realized by one or more network interfaces for instance.

[0116] The components 502, 503 and 504 of apparatus 500 may for instance be connected with processor 501 by means of one or more serial and / or parallel busses

[0117] It is to be understood that apparatus 500 may comprise various other components.

[0118] FIG. 6 is a schematic illustration of examples of tangible and non-transitory computer-readable storage media according to the present disclosure that may for instance be used to implement memory 502 of FIG. 5. To this end, FIG. 6 displays a flash memory 600, which may for instance be soldered or bonded to a printed circuit board, a sohd-state drive 601 compnsrng a plurality of memory chrps (e g. Flash memory chips), a magnetic hard drive 602, a Secure Digital (SD) card 603, a Universal Serial Bus (USB) memory stick 604, an optical storage medium 605 (such as for instance a CD-ROM or DVD) and a magnetic storage medium 606

[0119] The following embodiments are also disclosed:

[0120] Embodiment 1 : A method comprising: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model

[0121] Embodiment 2: The method according to embodiment 1, further comprising: if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model

[0122] Embodiment 3: The method according to embodiment 1 or 2, further comprising: registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.

[0123] Embodiment 4: The method according to one of embodiments 1 to 3, further comprising: requesting an initiation of a VFL process Embodiment 5: The method according to one of embodiments 1 to 4, wherein obtaining the VFL participant information comprises: requesting and / or performing a discovery of VFL participants.

[0124] Embodiment 6: The method according to embodiments 5, wherein obtaining the VFL participant information comprises: obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.

[0125] Embodiment 7 : The method according to embodiment 6, wherein obtaining the VFL participant information comprises: obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list.

[0126] Embodiment 8: The method according to embodiment 6 or 7, wherein obtaining the VFL participant information comprises: requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or obtaining the respective security capability information from the respective VFL participant.

[0127] Embodiment 9: The method according to one of embodiments 1 to 8, further comprising: initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.

[0128] Embodiment 10: The method according to one of embodiments 1 to 9, wherein preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the preferred security mechanism.

[0129] Embodiment 11 : The method according to embodiment 2, wherein preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the common security mechanism.

[0130] Embodiment 12: The method according to embodiment 4, wherein requesting the initiation of the VFL process comprises specifying the preferred security mechanism

[0131] Embodiment 13: The method according to one of embodiments 1 to 12, wherein the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.

[0132] Embodiment 14: The method according to one of embodiments 1 to 13, wherein at least one parameter of the at least one security mechanism varies as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process.

[0133] Embodiment 15: The method according to one of embodiments 1 to 14, wherein the method is performed by at least one network function

[0134] Embodiment 16: An apparatus for a network function, the apparatus comprising at least one processor and at least one memory, the at least one memoiy storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model

[0135] Embodiment 17: The apparatus according to embodiment 16, wherein the at least one memory is further storing instructions that, when executed by the at least one processor, cause the apparatus to perform: if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model

[0136] Embodiment 18: The apparatus according to embodiment 16 or 17, wherein the at least one memory is further storing instructions that, when executed by the at least one processor, cause the apparatus to perform: registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.

[0137] Embodiment 19: The apparatus according to one of embodiments 16 to 18, wherein the at least one memory is further storing instructions that, when executed by the at least one processor, cause the apparatus to perform: requesting an initiation of a VFL process

[0138] Embodiment 20: The apparatus according to one of embodiments 16 to 19, wherein obtaining the VFL participant information comprises: requesting and / or performing a discovery of VFL participants.

[0139] Embodiment 21 : The apparatus according to embodiment 20, wherein obtaining the VFL participant information comprises: obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.

[0140] Embodiment 22: The apparatus according to embodiment 21, wherein obtaining the VFL participant information comprises: obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list.

[0141] Embodiment 23: The apparatus according to embodiment 21 or 22, wherem obtaining the VFL participant information comprises: requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or obtaining the respective security capability information from the respective VFL participant.

[0142] Embodiment 24: The apparatus according to one of embodiments 16 to 23, wherein the at least one memory is further storing instructions that, when executed by the at least one processor, cause the apparatus to perform: initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.

[0143] Embodiment 25: The apparatus according to one of embodiments 16 to 24, wherein preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the preferred security mechanism.

[0144] Embodiment 26: The apparatus according to embodiment 17, wherein preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the common security mechanism

[0145] Embodiment 27 : The apparatus according to embodiment 19, wherein requesting the initiation of the VFL process comprises specifying the preferred security mechanism.

[0146] Embodiment 28: The apparatus according to one of embodiments 16 to 27, wherein the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.

[0147] Embodiment 29: The apparatus according to one of embodiments 16 to 28, wherein at least one parameter of the at least one security mechanism varies as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process. Embodiment 30: The apparatus according to one of embodiments 16 to 29, wherein the apparatus is an apparatus for at least one network function.

[0148] Embodiment 31 : The apparatus according to one of embodiments 16 to 30, wherein the network function comprises or is comprised in the apparatus.

[0149] Embodiment 32: The apparatus according to one of embodiments 16 to 31, wherein the network function is a VLF coordinator.

[0150] Embodiment 33: The apparatus according to one of embodiments 16 to 32, wherein the network function is a network data analytics function (NWDAF) comprising a model training logical function (MTLF).

[0151] Embodiment 34: An apparatus for a network function, the apparatus comprising: means for obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; means for determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: means for obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and means for preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model.

[0152] Embodiment 35: The apparatus according to embodiment 34, further comprising: if no preferred security mechanism has been specified: means for identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; means for obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and means for preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model.

[0153] Embodiment 36: The apparatus according to embodiment 34 or 35, further comprising: means for registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.

[0154] Embodiment 37: The apparatus according to one of embodiments 34 to 36, further comprising: means for requesting an initiation of a VFL process.

[0155] Embodiment 38: The apparatus according to one of embodiments 34 to 37, wherein the means for obtaining the VFL participant information comprise: means for requesting and / or performing a discovery of VFL participants

[0156] Embodiment 39: The apparatus according to embodiment 38, wherein the means for obtaining the VFL participant information comprise: means for obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.

[0157] Embodiment 40: The apparatus according to embodiment 39, wherein the means for obtaining the VFL participant information comprise: means for obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list

[0158] Embodiment 41 : The apparatus according to embodiment 39 or 40, wherein the means for obtaining the VFL participant information comprise: means for requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or means for obtaining the respective security capability information from the respective VFL participant.

[0159] Embodiment 42: The apparatus according to one of embodiments 34 to 41, further comprising: means for initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.

[0160] Embodiment 43: The apparatus according to one of embodiments 34 to 42, wherein the means for preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model comprise at least one of the following: means for finalising of VFL participant selection; means for instantiating a VFL session identifier; means for configuring the use of the preferred security mechanism.

[0161] Embodiment 44: The apparatus according to embodiment 35, wherein the means for preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model comprise at least one of the following: means for finalising of VFL participant selection; means for instantiating a VFL session identifier; means for configuring the use of the common security mechanism

[0162] Embodiment 45: The apparatus according to embodiment 37, wherein the means for requesting the initiation of the VFL process comprise means for specifying the preferred security mechanism.

[0163] Embodiment 46: The apparatus according to one of embodiments 34 to 45, wherein the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.

[0164] Embodiment 47 : The apparatus according to one of embodiments 34 to 46, wherein at least one parameter of the at least one security mechanism varies as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process.

[0165] Embodiment 48: The apparatus according to one of embodiments 34 to 47, wherein the apparatus is an apparatus for at least one network function.

[0166] Embodiment 49: The apparatus according to one of embodiments 34 to 48, wherein the network function comprises or is comprised in the apparatus.

[0167] Embodiment 50: The apparatus according to one of embodiments 34 to 49, wherein the network function is a VLF coordinator.

[0168] Embodiment 51 : The apparatus according to one of embodiments 34 to 50, wherein the network function is a network data analytics function (NWDAF) comprising a model training logical function (MTLF).

[0169] Embodiment 52: A computer-readable medium comprising program instructions which, when executed by an apparatus for a network function, cause the apparatus at least to perform: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one secun ty mechanism; and determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model

[0170] Embodiment 53: The computer-readable medium according to embodiment 52, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform: if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model

[0171] Embodiment 54: The computer-readable medium according to embodiment 52 or 53, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform: registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.

[0172] Embodiment 55: The computer-readable medium according to one of embodiments 52 to 54, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform: requesting an initiation of a VFL process

[0173] Embodiment 56: The computer-readable medium according to one of embodiments 52 to 55, wherein obtaining the VFL participant information comprises: requesting and / or performing a discovery of VFL participants.

[0174] Embodiment 57 : The computer-readable medium according to embodiment 56, wherein obtaining the VFL participant information comprises: obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.

[0175] Embodiment 58: The computer-readable medium according to embodiment 57, wherein obtaining the VFL participant information comprises: obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list.

[0176] Embodiment 59: The computer-readable medium according to embodiment 57 or 58, wherein obtaining the VFL participant information comprises: requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or obtaining the respective security capability information from the respective VFL participant.

[0177] Embodiment 60: The computer-readable medium according to one of embodiments 52 to 59, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform: initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.

[0178] Embodiment 61 : The computer-readable medium according to one of embodiments 52 to 60, wherein preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the preferred security mechanism.

[0179] Embodiment 62: The computer-readable medium according to embodiment 53, wherein preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the common security mechanism.

[0180] Embodiment 63: The computer-readable medium according to embodiment 55, wherein requesting the initiation of the VFL process comprises specifying the preferred security mechanism Embodiment 64: The computer-readable medium according to one of embodiments 52 to 63, wherein the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.

[0181] Embodiment 65: The computer-readable medium according to one of embodiments 52 to 64, wherein at least one parameter of the at least one security mechanism varies as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process.

[0182] Embodiment 66: The computer-readable medium according to one of embodiments 52 to 65, wherein the computer-readable medium is a non-transitory computer-readable medium

[0183] Any presented connection in the described embodiments is to be understood in a way that the involved components are operationally coupled. Thus, the connections can be direct or indirect with any number or combination of intervening elements, and there may be merely a functional relationship between the components

[0184] Further, as used in this text, the term ‘circuitry’ refers to any of the following:

[0185] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry);

[0186] (b) combinations of circuits and software (and / or firmware), such as:

[0187] (i) a combination of processor(s), or

[0188] (ii) sections of processor(s) / software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone, to perform various functions); and

[0189] (c) circuits, such as a microprocessor(s) or a section of a microprocessor(s), that require software or firmware for operation, even if the software or firmware is not physically present.

[0190] This definition of ‘circuitry’ applies to all uses of this term in this text, including in any claims. As a further example, as used in this text, the term ‘circuitiy ’ also covers an implementation of merely a processor (or multiple processors) or section of a processor and its (or their) accompanying software and / or firmware. The term ‘circuitry’ also covers, for example, a baseband integrated circuit or applications processor integrated circuit for a mobile phone.

[0191] Any of the processors mentioned in this text, in particular but not limited to processor 501 of FIG. 5, could be a processor of any suitable type Any processor may comprise but is not limited to one or more microprocessors, one or more processor(s) with accompanying digital signal processor(s), one or more processor(s) without accompanying digital signal processor(s), one or more special-purpose computer chips, one or more field- programmable gate arrays (FPGAS), one or more controllers, one or more application-specific integrated circuits (ASICS), or one or more computer(s). The relevant structure / hardware has been programmed in such a way to carry out the described function.

[0192] Moreover, any of the actions or steps described or illustrated herein may be implemented using executable instructions in a general-purpose or special-purpose processor and stored on a computer-readable storage medium (e g. disk, memory, or the like) to be executed by such a processor. References to ‘computer-readable storage medium’ should be understood to encompass specialized circuits such as FPGAs, ASICs, signal processing devices, and other devices.

[0193] As used herein, “at least one of the following: <a list of two or more elements*” and “at least one of <a list of two or more elements*” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0194] The wording “A, or B, or C, or a combination thereof’ or “at least one of A, B and C” may be understood to be not exhaustive and to include at least the following: (i) A, or (ii) B, or (iii) C, or (iv) A and B, or (v) A and C, or (vi) B and C, or (vii) A and B and C

[0195] It will be understood that the embodiments disclosed herein are only exemplary, and that any feature presented for a particular exemplaiy embodiment may be used with any aspect of the present disclosure on its own or in combination with any feature presented for the same or another particular exemplary embodiment and / or in combination with any other feature not mentioned It will further be understood that any feature presented for an example embodiment in a particular category may also be used in a corresponding manner in an example embodiment of any other category.

[0196] ABBREVIATIONS

[0197] 3GPP 3rd Generation Partnership Project

[0198] 5GC 5G Core

[0199] 5GS 5G System

[0200] AF Application Function

[0201] Al Artificial Intelligence

[0202] AMF Access and Mobility Management function

[0203] AnLF Analytics Logical Function

[0204] AUSF Authentication Server Function

[0205] DN Data Network gNB gNodeB

[0206] ML Machine Learning MTLF Model Training Logical Function

[0207] NEF Network Exposure Function

[0208] NF Network Function

[0209] NR New Radio NRF Network Repository Function

[0210] NWDAF Network Data Analytics Function

[0211] PCF Policy Control Function

[0212] RAN Radio Access Network

[0213] SMF Session Management function UDM Unified Data Management

[0214] UE User Equipment

[0215] UPF User Plane Function

[0216] VFL Vertical Federated Learning

Claims

C l a i m s1 ) A method comprising : obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model2) The method according to claim 1 , further comprising: if no preferred security mechanism has been specified: identifying a common security mechanism supported by the largest number of VFL participants among the at least one VFL participant; obtaining or performing a second selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the second selection support the common security mechanism; and preparing a VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model3) The method according to claim 1 or 2, further comprising: registering the at least one VFL participant, wherein registering a respective VFL participant comprises providing VFL participant identification information in association with respective security capability information, wherein the VFL participant identification information is indicative of a respective VFL participant.4) The method according to one of claims 1 to 3, further comprising: requesting an initiation of a VFL process5) The method according to one of claims 1 to 4, wherein obtaining the VFL participant information comprises: requesting and / or performing a discovery of VFL participants.6) The method according to claim 5, wherein obtaining the VFL participant information comprises: obtaining, as a result of the discovery of VFL participants, a list representing the at least one VFL participant.7) The method according to claim 6, wherein obtaining the VFL participant information comprises: obtaining, for at least one VFL participant in the list, security capability information in association with the respective VFL participant, wherein the respective security capability information is obtained together with the list.8) The method according to claim 6 or 7, wherein obtaining the VFL participant information comprises: requesting, for at least one VFL participant in the list for which no associated security capability information has been obtained together with the list, respective security capability information from the respective VFL participant; and / or obtaining the respective security capability information from the respective VFL participant.9) The method according to one of claims 1 to 8, further comprising: initiating a security negotiation for the at least one VFL participant represented by the VFL participant information.10) The method according to one of claims 1 to 9, wherein preparing the VFL process using the VFL participants of the first selection and the preferred security mechanism for training the machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the preferred security mechanism.11) The method according to claim 2, wherein preparing the VFL process using the VFL participants of the second selection and the common security mechanism for training a machine learning model comprises at least one of the following: finalisation of VFL participant selection; instantiating a VFL session identifier; configuring the use of the common security mechanism.12) The method according to claim 4, wherein requesting the initiation of the VFL process comprises specifying the preferred security mechanism.13) The method according to one of claims 1 to 12, wherein the at least one security mechanism is at least one of the following: an encryption-based security mechanism; a privacy preservation-based security mechanism.14) The method according to one of claims 1 to 13, wherein at least one parameter of the at least one security mechanism vanes as a function of at least one of the following: an identifier of a machine learning model to be trained using the VFL process; the VFL participants participating in the VFL process.15) The method according to one of claims 1 to 14, wherein the method is performed by at least one network function.16) An apparatus for a network function, the apparatus comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model17) The apparatus according to claim 16, wherein the at least one memory is further storing instructions that, when executed by the at least one processor, cause the apparatus to perform the method according to one of claims 2 to 15.18) The apparatus according to claim 16 or 17, wherein the network function comprises or is comprised in the apparatus.19) The apparatus according to one of claims 16 to 18, wherein the network function is a VLF coordinator.20) The apparatus according to one of claims 16 to 19, wherein the network function is a network data analytics function (NWDAF) comprising a model training logical function (MTLF).21) An apparatus for a network function, the apparatus comprising: means for obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; means for determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: means for obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and means for preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model.22) The apparatus according to claim 21 , further comprising means for performing the method according to one of claims 2 to 1523) The apparatus according to claim 21 or 22, wherein the network function comprises or is comprised in the apparatus.24) The apparatus according to one of claims 21 to 23, wherein the network function is a VLF coordinator25) The apparatus according to one of claims 21 to 24, wherein the network function is a network data analytics function (NWDAF) comprising a model training logical function (MTLF)26) A non-transitory computer-readable medium comprising program instructions which, when executed by an apparatus for a network function, cause the apparatus at least to perform: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; andpreparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model27) The non-transitory computer-readable medium according to claim 26, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform the method according to one of claims 2 to 15.28) A computer-readable medium comprising program instructions which, when executed by an apparatus for a network function, cause the apparatus at least to perform: obtaining Vertical Federated Learning, VFL, participant information representing at least one VFL participant in association with respective security capability information, wherein the security capability information is indicative that the respective VFL participant supports at least one security mechanism; determining that a preferred security mechanism has been specified; and if a preferred security mechanism has been specified: obtaining or performing a first selection of VFL participants among the at least one VFL participant, wherein the VFL participants of the first selection support the preferred security mechanism; and preparing a VFL process using the VFL participants of the first selection and the preferred security mechanism for training a machine learning model29) The computer-readable medium according to claim 28, further comprising program instructions which, when executed by the apparatus, cause the apparatus to perform the method according to one of claims 2 to 15.

Citation Information

Patent Citations

  • Distributed machine learning in an information centric network

    US20200027022A1

  • Systems and methods for trustworthiness determination

    WO2023154444A1