Systems and methods for enhancing telecom forecasting robustness against adversarial attacks with machine learning

The white-box adversarial training framework for telecom forecasting models addresses vulnerabilities by generating adversarial samples to train models, enhancing resilience and operational efficiency in real-time telecom environments.

WO2025221178A1PCT designated stage Publication Date: 2025-10-23TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050383
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-18
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Telecom forecasting models are vulnerable to adversarial attacks that exploit temporal dependencies and the open nature of wireless channels, leading to security risks, model vulnerabilities, anomaly detection limitations, lack of adaptation to evolving adversarial strategies, data sensitivity, and scalability issues in real-time processing.

Method used

A white-box adversarial training framework dynamically adapts to evolving adversarial strategies, ensuring data integrity and scalability within real-time, cloud-based telecommunications environments by generating adversarial sample data based on KPIs and deployment scenarios to train forecasting models.

Benefits of technology

The framework enhances resilience to evolving threats, provides generalized defense, preserves data integrity, and ensures operational efficiency by adapting to new adversarial strategies, reducing attack transferability, and maintaining service continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050383_23102025_PF_FP_ABST
    Figure SE2024050383_23102025_PF_FP_ABST
Patent Text Reader

Abstract

A computer-implemented method (200, 600) is performed for securing a forecasting model against white-box adversarial attacks. Based on at least one Key Performance Indicator, KPI, and at least one deployment scenario, adversarial sample data is generated (208, 602) for at least one network node (710) in a communications network (702). The at least one KPI and the at least one adversarial sample data are used (210, 604) to train at least one forecasting model. The at least one forecasting model is used (606) to initiate at least one scheduling task.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEMS AND METHODS FOR ENHANCING TELECOM FORECASTING

[0002] ROBUSTNESS AGAINST ADVERSARIAL ATTACKS WITH MACHINE LEARNING

[0003] TECHNICAL FIELD

[0004] The present disclosure relates, in general, to wireless communications and, more particularly, systems and methods for systems and methods for enhancing telecom forecasting robustness against adversarial attacks with Machine Learning (ML).

[0005] BACKGROUND

[0006] As ML experiences a surge, software service providers and telecom vendors are moving towards Artificial Intelligence-centric Radio Access Network (RAN) implementation and integration. As the industry shifts towards a 6thGeneration (6G) future that emphasizes Artificial Intelligence (Al), the imperative for robust and secure ML systems has never been greater.

[0007] Forecasting models have become indispensable in the telecommunications industry, playing a crucial role in predicting key performance indicators (KPIs) like traffic patterns, service quality, energy consumption, and resource allocation. For example, forecasting models have been used when scheduling software upgrades for network sites. Specifically, such software upgrades may be scheduled based on forecasted network traffic, finding the times with least traffic to schedule the upgrades. Minimizing service impact during the software upgrade is a critical part of ensuring a seamless network connection for users. During the software upgrade of a site, all users connected to that site get disconnected. Thus, time series forecasting models have been used to predict time periods with the least traffic for scheduling the upgrade. However, these models currently are trained only on normal data, Performance Management (PM) data, and Configuration Management (CM) data. See, https: / / www.3gpp. org / dynareport?code=SpecVsWi— 32425.htm, last visited April 14, 2024. PM data includes live data that is received from network nodes as defined in 3GPP. CM data is used to estimate coverage areas. This approach does not consider the possibility of adversarial attacks, which could be critical, especially if attackers aim to disrupt the upgrade process to exploit network vulnerabilities. Such attacks can leverage the temporal dependencies inherent to time series data and the inherent openness of wireless channels, introducing substantial security risks to network operations.

[0008] An example adversarial attack scenario includes traffic pattern manipulation during which attackers may introduce adversarial inputs that simulate network congestion or failure, causing inefficient rerouting and scaling actions that disrupt the network's operational efficiency. Another example adversarial attack scenario is Quality of Service (QoS) spoofing during which false signal quality data manipulated by adversarial attacks erroneously indicates poor service areas, affecting customer satisfaction and leading to misdirected network resource distribution. Still another adversarial attack scenario is the creation of resource utilization anomalies. Specifically, by generating adversarial inputs that inaccurately reflect resource utilization, adversaries could trigger over-provisioning — leading to increased operational costs — or under-provisioning — resulting in degraded service quality.

[0009] Historical precedents of instances of these and other cyber-attacks on telecom networks have occurred with alarming regularity. Studies have shown that adversarial attacks can exploit the temporal dependencies and open nature of wireless channels in telecommunication networks, leading to significant vulnerabilities. See, Ahmed et al., Sparse self-attention guided generative adversarial networks for time-series generation, International Journal of Data Science and Analytics, 2023; Li et al., Adversarial Training in Continuous-Time Models and Irregularly Sampled Time-Series," The Second Workshop on New Frontiers in Adversarial Machine Learning, 2023; Galib, Asadullah Hill, and Bidhan Bashyal. On the Susceptibility and Robustness of Time Series Models through Adversarial Attack and Defense, arXiv preprint arXiv:2301.03703 (2023). The susceptibility of deep learning-based time series prediction models to adversarial attacks is such that even minimal perturbations can have a significant impact on the models' performance. See, Wu, Tao, et al., Small perturbations are enough: Adversarial attacks on time series prediction, Information Sciences 587 (2022).

[0010] Accordingly, the resilience of these models against adversarial attacks remains a pressing concern. Actions need to be taken to secure these models with a stress on security for site software upgrade systems. Due to the vulnerability of time series classification models to adversarial samples, certain previous methods have proposed using an adversarial transformation network to enhance model robustness. See, Karim et al., Adversarial attacks on time series, IEEE transactions on pattern analysis and machine intelligence 43.10, 2020. However, while adversarial attacks on time series classification have been extensively studied, the specific challenges of forecasting regression — where the goal is to predict as close as possible to the desired output amidst potential adversarial disruptions — have not received equivalent attention. This oversight is critical to address given the prevalence of time series data in telecom, where the data (KPIs) is “mostly” represented as temporal time series data (traffic for the software upgrade in this case).

[0011] Furthermore, the existing technologies described above face several problems in the context of adversarial attacks within telecommunication systems. Some of these problems include:

[0012] • Model Vulnerability. Forecasting models, including LSTMs and Transformers, are prone to adversarial attacks that can exploit their inherent weaknesses, such as reliance on temporal correlations.

[0013] • Physical-layer Attacks'. The open nature of wireless communication channels allows noise and adversaries to introduce perturbations that can mislead deep learning models, affecting the semantic interpretation of data crucial for decision-making processes.

[0014] • Anomaly Detection Limitations'. There is a lack of sophisticated methods for accurately classifying anomalies in KPI time series, which is vital for maintaining network performance and reliability.

[0015] • Adversarial Strategy Adaptation'. Models often lack the capability to adapt to continuously evolving adversarial strategies, which can quickly outdate defensive measures.

[0016] • Data Sensitivity and Integrity. The integrity of sensitive telecommunications data is threatened by adversarial attacks, where even minimal perturbations can cause disproportionate impacts.

[0017] • Scalability and Real-time Processing'. The scalability and real-time processing demands of telecommunication systems are not always met by current adversarial defense strategies.

[0018] • Transferability of Attacks'. Adversarial attacks can be transferable between different models, increasing the risk and highlighting the need for robust defense mechanisms that generalize well across various model architectures.

[0019] Accordingly, there is a need for robust defenses as we advance into an increasingly Al-integrated future.

[0020] SUMMARY

[0021] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. For example, methods and systems are provided that relate to a white-box adversarial training framework for software upgrade time series forecasting models. According to certain embodiments, the framework dynamically adapts to evolving adversarial strategies, ensuring data integrity and scalability within real-time, cloud-based telecommunications environments.

[0022] According to certain embodiments, a computer-implemented method performed by a computing device for securing a forecasting model against white-box adversarial attacks is provided. The method includes generating, based on at least one KPI and at least one deployment scenario, adversarial sample data for at least one network node in a communications network. The at least one KPI and the at least one adversarial sample data are used to train at least one forecasting model. The at least one forecasting model is used to initiate at least one scheduling task.

[0023] According to certain embodiments, scheduling node for securing a forecasting model against white-box adversarial attacks is configured to generate, based on at least one KPI and at least one deployment scenario, adversarial sample data for at least one network node in a communications network. The scheduling node uses at least one KPI and the at least one adversarial sample data are used to train at least one forecasting model. The scheduling node uses the at least one forecasting model to initiate at least one scheduling task.

[0024] According to certain embodiments, a computer-readable medium stores instructions for securing a forecasting model against white-box adversarial attacks. The instructions are implemented by a computer to cause the computer to generate, based on at least one KPI and at least one deployment scenario, adversarial sample data for at least one network node in a communications network. The instructions are implemented by a computer to cause the computer to use the at least one KPI and the at least one adversarial sample data to train at least one forecasting model and use the at least one forecasting model to initiate at least one scheduling task.

[0025] Certain embodiments may provide one or more of the following technical advantage(s). For example, certain embodiments may provide a technical advantage of increasing resilience to evolving threats. By adapting to new adversarial strategies, the system remains secure even as attack methods change.

[0026] As another example, certain embodiments may provide a technical advantage of providing generalized defense since reducing attack transferability increases protection across different models and systems.

[0027] As still another example, certain embodiments may provide a technical advantage of preserving data integrity since ensuring minimal impact from attacks preserves the trustworthiness of telecom data.

[0028] As yet another example, certain embodiments may provide a technical advantage of increasing operational efficiency. Real-time processing and scalability ensure that defenses keep pace with the speed of telecom operations, minimizing latency and maintaining service continuity.

[0029] As still another example, certain embodiments may provide a technical advantage of preparing the telecom infrastructure for the increasing use of Al, setting a foundation for secure Al-centric deployments.

[0030] As yet another example, certain embodiments may provide a technical advantage of improving operational reliability. By safeguarding against data perturbation, certain embodiments support the continuous reliability of services crucial for customer satisfaction and trust.

[0031] Other advantages may be readily apparent to one having skill in the art. Certain embodiments may have none, some, or all of the recited advantages.

[0032] BRIEF DESCRIPTION OF THE DRAWINGS

[0033] For a more complete understanding of the disclosed embodiments and their features and advantages, reference is now made to the following description, taken in conjunction with the accompanying drawings, in which:

[0034] FIGURE 1 illustrates an example method for securing a forecasting model against white-box adversarial tasks, according to certain embodiments;

[0035] FIGURE 2 illustrates an example procedure for the development, evaluation, and / or validation of the method of FIGURE 1, according to certain embodiments;

[0036] FIGURE 3 illustrates a graph depicting normalized traffic KPI data for collected for 104 cells randomly selected from a live network during performed experiments, according to certain embodiments;

[0037] FIGURE 4 illustrates a sliding window for time series forecasting used for training the forecasting model, in a particular embodiment;

[0038] FIGURE 5 illustrates a high level flowchart a comparison strategy that may be used for comparing the respective performances of the baseline training forecasting model and the adversarially trained forecasting model, according to certain embodiments;

[0039] FIGURE 6 illustrates an example computer-implemented method by a computing device for securing a forecasting model against white-box adversarial tasks, according to certain embodiments;

[0040] FIGURE 7 illustrates an example communication system, according to certain embodiments;

[0041] FIGURE 8 illustrates an example UE, according to certain embodiments; and

[0042] FIGURE 9 illustrates an example network node, according to certain embodiments.

[0043] DETAILED DESCRIPTION

[0044] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0045] As used herein, ‘node’ can be a network node or a UE. Examples of network nodes are NodeB, base station (BS), multi-standard radio (MSR) radio node such as MSR BS, eNodeB (eNB), gNodeB (gNB), Master eNB (MeNB), Secondary eNB (SeNB), integrated access backhaul (IAB) node, network controller, radio network controller (RNC), base station controller (BSC), relay, donor node controlling relay, base transceiver station (BTS), Central Unit (e.g. in a gNB), Distributed Unit (e.g. in a gNB), Baseband Unit, Centralized Baseband, C-RAN, access point (AP), transmission points, transmission nodes, Remote Radio Unit (RRU), Remote Radio Head (RRH), nodes in distributed antenna system (DAS), core network node (e.g. Mobile Switching Center (MSC), Mobility Management Entity (MME), etc.), Operations & Maintenance (O&M), Operations Support System (OSS), Self Organizing Network (SON), positioning node (e.g. E-SMLC), etc. The terms network node and radio network node are used interchangeably herein.

[0046] Another example of a node is user equipment (UE), which is a non-limiting term and refers to any type of wireless device communicating with a network node and / or with another UE in a cellular or mobile communication system. Examples of UE are target device, device to device (D2D) UE, vehicular to vehicular (V2V), machine type UE, MTC UE or UE capable of machine to machine (M2M) communication, Personal Digital Assistant (PDA), Tablet, mobile terminals, smart phone, laptop embedded equipment (LEE), laptop mounted equipment (LME), Unified Serial Bus (USB) dongles, etc.

[0047] The term radio access technology (RAT), may refer to any RAT such as, for example, Universal Terrestrial Radio Access Network (UTRA), Evolved Universal Terrestrial Radio Access Network (E-UTRA), narrow band internet of things (NB-IoT), WiFi, Bluetooth, next generation RAT, NR, 4G, 5G, etc. Any of the equipment denoted by the terms node, network node or radio network node may be capable of supporting a single or multiple RATs.

[0048] Al models such as, for example, time series forecasting models that are used for scheduling software upgrades are vulnerable to adversarial attacks. With respect to these attacks, there are several kinds of assumptions that may be made with respect to the attacker’s knowledge. For example, a white-box attack assumes the attacker has full knowledge and access to the model, including architecture, inputs, outputs, and weights. By contrast, a blackbox attack assumes the attacker only has access to the inputs and outputs of the model and knows nothing about the underlying architecture or weights.

[0049] Certain embodiments disclosed herein relate to systems and methods for securing the development of traffic forecasting models for software upgrade against white-box attacks. For example, methods and systems are provided that relate to a white-box adversarial training framework for software upgrade time series forecasting models. Since models are developed internally, network operators have access to the source code and data. Accordingly, embodiments described herein include training models in an adversarial fashion to mitigate security risks.

[0050] According to certain embodiments, the framework dynamically adapts to evolving adversarial strategies, ensuring data integrity and scalability within real-time, cloud-based telecommunications environments. This proactive approach equips the models with the resilience to withstand and counteract such adversarial attacks, ensuring reliability and security for the software upgrade process. Additionally, a dynamic adaptation mechanism introduces a training regime that evolves in response to new adversarial tactics, ensuring the forecasting model remains robust over time.

[0051] Certain embodiments include data integrity safeguards that maintain the integrity of sensitive telecom data against subtle adversarial perturbations.

[0052] In particular embodiments, the systems and methods are implemented to provide robustness in Al-centric Telecom and a systematic defense mechanism for Al models deployed on Cloud RAN or One RAN. In particular embodiments, the systems and methods employ strategic defense integration and preparedness for the future. For example, the systems and methods anticipate future adversarial strategies and prepare defenses in advance by seamlessly incorporating robustness into the existing Al frameworks without compromising performance.

[0053] FIGURE 1 illustrates an example method 100 for securing a forecasting model against white-box adversarial tasks, according to certain embodiments. At step 102, live network data is collected from each RAN node. Such data includes performance management (PM) data such as is defined in 3GPP Specification 32.425vl 8.0.0.

[0054] At step 104, adversarial samples are generated based on the PM data and deployment scenarios. For example, in a particular embodiment, KPIs such as raw traffic KPIs are calculated for the PM data and the adversarial samples are generated based on the KPIs and deployment scenarios. In performance management, KPIs such as raw traffic KPIs are critical metrics calculated to assess network efficiency and capability. For instance, the KPI pmRadioThpVolUl, represents the successfully transferred data volume at the MAC level in the uplink, measured in kilobits. Similarly, pmRadioThpVolDl tracks the downlink data volume, providing insights into the downlink capacity and throughput performance. There are several algorithms that may be used for the purpose of calculating KPIs. In a particular embodiment, for example, the fast gradient sign method attack is implemented. See, Goodfellow et al., Explaining and Harnessing Adversarial Examples, arXiv preprint arXiv: 1412.6572, 2014.

[0055] As used herein, deployment scenarios are based on how the network nodes and network are interconnected with each other. In a particular embodiment, deployment scenarios include a combination of coverage and capacity. Because it is desirable for users to be connected at all times, coverage is measure of how obstructed or not obstructed the network is. Capacity is indicate of how good the network and / or signal is and thus be measured in terms of signal quality such as, for example, RSRP, RSRQ, and SNR, in particular embodiments.

[0056] At step 106, a forecasting model is adversarially trained on both raw KPI samples and adversarial samples.

[0057] At step 108, the forecasting model is deployed and monitored over time.

[0058] FIGURE 2 illustrates an example procedure 200 for the development, evaluation, and / or validation of the method described above, according to certain embodiments. As illustrated, the procedure 200 includes training both a baseline model and an adversarial trained model such that the outputs of both models may be compared for the purpose of validating the adversarially trained model.

[0059] The procedure 200 begins when data is collected at step 202. Specifically, PM data is obtained from each RAN node in a communication network. In a particular embodiment, for example, the PM data includes time-series data used to gauge RAN node observability. Data is recorded in Rolling Operation Period (ROP) files that are sent to the system at ROP intervals. For example, a ROP may be 15 minutes, in a particular embodiment.

[0060] At step 203, at least one KPI is calculated based on the PM data. For example, in a particular embodiment, the KPIs are calculated based on the PM data using standard statistical methods and algorithms that are commonly accepted in the telecommunications industry. For example, a KPI like pmRadioThpVolDl (downlink throughput volume) might typically be calculated by aggregating the total data transmitted over a specified time period and then normalizing this by the number of active sessions to derive the average throughput per session. This approach provides a measure of network efficiency and service quality from the user's perspective.

[0061] FIGURE 3 illustrates a graph 300 depicting normalized traffic KPI data for collected for 104 cells randomly selected from a live network during performed experiments. In the illustrated example, the traffic KPI data was calculated for a period of 6 days.

[0062] Returning to FIGURE 2, a baseline traffic forecasting model is trained based on the collected PM data at step 204. The objective is to establish the baseline performance on the untouched dataset obtained at step 202.

[0063] For example, in a particular embodiment, Long Short-Term Memory (LSTM) was chosen as a selected baseline model to train and evaluate the forecasting without adversarial samples. FIGURE 4 illustrates a sliding window 400 for time series forecasting used for training the forecasting model, in a particular embodiment. In the illustrated experiment, 24 hours of history was used to predict the future 8 hours horizon. The forecasting model was trained based on a month of data for the 104 cells. Each cell was associated with its own LSTM model, so a total of 104 models. Since data is collected over each ROP, 1 ROP was moved each time to generate a training sample. This is commonly called the sliding window method.

[0064] Returning to FIGURE 2, the performance and robustness of the baseline traffic forecasting model is then evaluated at step 206. For example, in a particular embodiment, mean squared error (MSE), root mean squared error (RMSE), mean absolute error (MAE), and / or R squared (R2) metrics are used to evaluate the trained baseline model on RAN data.

[0065] At step 208, the PM data obtained at step 202 is also used to generate adversarial samples. This step may be similar to step 104 described above with respect to method 100.

[0066] In a particular embodiment, for example, a Fast Gradient Sign Method attack (FGSM) algorithm is used to generate adversarial samples for the obtained PM data for the RAN nodes. FGSM is one of the first and most popular adversarial attacks to date. It is designed to attack neural networks by leveraging the way they learn with gradients. A step-by-step description of how this method works includes:

[0067] 1. Model Training'. First, a neural network model is trained on a dataset to achieve high performance, as described above in step 204.

[0068] 2. Gradient Calculation'. Once the model is trained, for a given input, the gradient of the loss with respect to the input sample is calculated. The loss measures how incorrect the model's predictions are, and the gradient is a multi-dimensional vector that points in the direction of increasing loss.

[0069] 3. Sign of Gradient'. The sign of this gradient is then computed. The sign function simply takes the gradient vector and replaces each component with +1 if it's positive, -1 if it's negative, and 0 if it's zero. This sign vector indicates the direction in each dimension of the input space that would increase the regression loss.

[0070] 4. Perturbation Creation'. This sign vector is then multiplied by a small scalar value called epsilon (a), which controls the magnitude of the perturbation. The idea is to apply a tiny change to the input sample that will result in the highest possible increase in loss, thus leading the model to misclassify the image.

[0071] 5. Adversarial Sample Generation'. The original input is then modified by this scaled sign vector, creating a new sample that is only slightly different from the original but is likely to be misinterpreted by the model. This new sample is known as an "adversarial example."

[0072] The formula for creating an adversarial example using FGSM is given by:

[0073] Advx= x + e . sign( VxJ (9, x , y)) where:

[0074] Advxis the adversarial sample, x is the input normal PM sample, • e is a small constant (the perturbation magnitude),

[0075] • signQ denotes the sign function,

[0076] • 0, x , y) is the gradient of the loss function J with respect to the input image x, given the model parameters 0 and the correct label y.

[0077] In the experiments described herein, e = 0.1 was used.

[0078] Once adversarial samples are ready, the baseline models are evaluated to check if the performance is dropping when the models are attacked by these adversarial samples. Thus, at step 210, the forecasting model is adversarially trained using the adversarial samples generated at step 208. The step includes re-training the forecasting models with a mix of genuine data and the adversarial sample data to improve its robustness and to mitigate the hazardous effects of the adversarial attacks. The training setup and data sliding window may be the same as described above.

[0079] At step 212, the performance and robustness of the adversarially trained forecasting model is evaluated to determine the increase in resilience. In a particular embodiment, at least one model evaluation metric is determined for the at least on adversarially trained forecasting model. The evaluation metrics may be the similar as those discussed above with respect to step 206.

[0080] At step 214, the output of two models is compared. This step includes comparing the performance metrics of the baseline forecasting model with the evaluation metrics determined for the adversarially trained model.

[0081] FIGURE 5 illustrates a high level flowchart 500 of a comparison strategy that may be used for comparing the respective performances of the baseline training forecasting model and the adversarially trained forecasting model, according to certain embodiments. In the illustrated embodiment, for each training scenario (baseline or adversarial), during an inference stage for testing the robustness of the models, the forecasting model is inputted with genuine samples and adversarial samples. For example, baseline forecasting model 502 and adversarially trained forecasting model 504 are trained based on RAN PM data 506 and adversarial samples 508, respectively. Then, performance metrics 510 from baseline forecasting model 502 and performance metrics 512 from adversarially trained forecasting model 504 are compared. In a particular embodiment, for example, performance metrics such as MSE, MAE, RMSE, and / or R2 are calculated for the respective models and compared.

[0082] Once the adversarially trained forecasting model has been evaluated against adversarial attacks, the method may further include identifying deployment scenarios, deploying the adversarially trained forecasting model and monitoring the adversarially trained forecasting model.

[0083] In a particular embodiment, the adversarially trained forecasting model is used to generate the scheduling matrix for the network operator. The scheduling matrix represents an approach to managing software upgrade rollouts based on network traffic for telecom networks. This scheduling matrix is designed as a predictive framework that lays out the forecasted network traffic across various sites within a network. Its primary function is to aid operators in strategically planning software upgrades, targeting periods of minimal network usage. By doing so, the scheduling matrix significantly mitigates the impact on end-users, primarily by reducing the number of users who experience service disruptions.

[0084] Experiments & Validation

[0085] The methods described herein were developed and tested. The results of the experiments are discussed below.

[0086] The LSTM model provides highly accurate predictions when trained per cell.

[0087] Table 1 shows the performance of the baseline forecasting model before and after including the Adversarial Samples during inference. Specifically, Table 1 shows the average MSE, MAE, RMSE, and R2 scores for all the 104 cells for the performed experiment. For MSE, MAE, and RMSE, a smaller value is favourable (closer to zero). For the R2 score, a high number is favourable (closer to 1). The metrics clearly degrade as the adversarial samples are inputted to the model during inference.

[0088] Table 1 During the experiments, the predicted forecasts for the models were plotted with and without adversarial training samples for 4 different days. It was noted that, when trained adversarially, the results of the forecasting model tended to be closer to the real data as opposed to the predictions from the baseline forecasting models for all four days.

[0089] The new models were then compared with the baseline models. It was noted that, for all three metrics, it was clear that the adversarially trained forecasting models outperformed the baseline forecasting models. Additionally, the adversarially trained forecasting model outperformed the baseline model on the R2 score.

[0090] The mean value was quantitatively measured for each metric over all the cells together and indicated the improvement from baseline to adversarial training as a percentage increase. Table 1 shows the performance of the model before and after training adversarially. The method clearly improves after training with adversarial samples.

[0091] Table 2

[0092] The accuracy obtained with and without adversarial training follows:

[0093] • Baseline accuracy: 0.2437837837837838

[0094] • Adversarial accuracy: 0.2708108108108108

[0095] In conclusion, the study and experiments demonstrated the efficacy of adversarial training in enhancing the robustness and performance of the forecasting model. By incorporating adversarial examples into the training regime, a marked quantitative improvement was observed across several key metrics. Specifically, MSE saw a significant reduction of 17.15%, indicating a substantial increase in the forecasating model's predictive accuracy. Similarly, MAE decreased by 8.45%, reflecting a finer convergence to the true data points. RMSE also improved by 7.75%, suggesting a more consistent model performance across the spectrum of testing scenarios. Most notably, the improvement in the R2 metric, which measures the proportion of variance in the dependent variable that is predictable from the independent variables, was increased by 9.50%.

[0096] This improvement signifies not just an enhancement in prediction accuracy, but also an increase in the forecasting model's ability to generalize from its training data to unseen data, a critical aspect of robust predictive modeling. The transition from baseline to adversarially trained models represents a strategic pivot towards robustness in ML. The results underscore the potential of adversarial training as a powerful tool to combat the vulnerabilities inherent in traditional ML models.

[0097] Finally, applying the forecasting model to the software scheduling task showed that adversarial training increased the prediction accuracies by around 3%, a significant increase that enhances user experience, influences energy savings and resource allocation, and reduces service impact.

[0098] In industries where precision and resilience are important, these advances signify more than just incremental progress. They reflect a paradigm shift towards the adoption of ML models that are robust by design and are capable of withstanding adversarial conditions without compromising on performance. This is particularly critical in telecom, where the accuracy and dependability of predictive models have direct implications on network reliability, customer satisfaction, QoS, and operational efficiency. Embracing adversarial training may enhance network infrastructure, ensuring that it is not only resilient against a wide array of potential disruptions but also more adept at handling the complex, dynamic demands of modem telecommunications. The integration of adversarial training methodologies will be instrumental in developing the next generation of telecom solutions — solutions that are secure, scalable, and sophisticated enough to handle potential challenges.

[0099] FIGURE 6 illustrates an example computer-implemented method 600 for securing a forecasting model against white-box adversarial attacks, according to certain embodiments. In the illustrated embodiment, the method 600 begins at step at 602 when, based on at least one KPI and at least one deployment scenario, adversarial sample data is generated for at least one network node 710 in a communications network. At 1304, the at least one KPI and the at least one adversarial sample data are used to train at least one forecasting model. At step 1306, the at least one forecasting model is used to initiate at least one scheduling task.

[0100] In a particular embodiment, using the at least one forecasting model to perform the at least one scheduling operation includes using the at least one forecasting model to schedule a software upgrade for the network node.

[0101] In a particular embodiment, prior to using the at least one KPI and the at least one adversarial sample data to train the at least one forecasting model, the method includes obtaining PM data for the at least one network node in a communications network. The at least one KPI is calculated based on the PM data, and at least one baseline forecasting model is trained based on the at least one KPI.

[0102] In a particular embodiment, the at least one KPI is calculated based on the PM data, and the adversarial sample data is generated based on the at least one KPI.

[0103] In a particular embodiment, the PM data includes live data indicating a performance level of the at least one forecasting model during at least one ROP.

[0104] In a particular embodiment, obtaining the PM data includes receiving the PM data from the at least one network node on a periodic basis.

[0105] In a particular embodiment, at least one performance metric is determined for the at least one baseline forecasting model trained based on the at least one KPI. Based on the at least one performance metric, a performance of the at least one baseline forecasting model is evaluated.

[0106] In a particular embodiment, evaluating the performance of the at least one forecasting model includes determining a gradient of a loss of the at least one forecasting model.

[0107] In a particular embodiment, the PM data comprises at least one PM data sample, and the adversarial sample data comprises at least one adversarial sample. Generating the adversarial sample includes computing a sign vector of the gradient of the loss of the at least one forecasting model, scaling the sign vector by a scalar value associated with a magnitude of perturbation, and applying the scaled sign vector to the at least one KPI to determine the adversarial sample data.

[0108] In a particular embodiment, the adversarial sample data is used as first input to the at least one forecasting model. At least one model evaluation metric is determined for the at least one forecasting model based on the adversarial sample data. Based on the at least one model evaluation metric, a change in the performance of the at least one forecasting model is determined.

[0109] In a particular embodiment, a comparison of the at least one additional performance metric obtained for the at least one forecasting model is made to the at least one performance metric obtained for the at least one baseline forecasting model. Based on comparison, a determination is made as to whether further training of the at least one baseline model and / or the at least one forecasting model is needed.

[0110] In a particular embodiment, the at least one performance metric and / or the at least one additional performance metric includes at least one of: a mean squared error, a mean absolute error, a root mean squared error, and a R-squared score.

[0111] In a particular embodiment, the at least one forecasting model is re-trained based on the PM data and the adversarial sample data. After re-training the at last one forecasting model, the adversarial sample data is used as second input to the at least one forecasting model. A change in the performance of the at least one forecasting model is determined.

[0112] In a particular embodiment, the method is performed by a scheduling node of the communications network.

[0113] FIGURE 7 shows an example of a communication system 700 in accordance with some embodiments. In the example, the communication system 700 includes a telecommunication network 702 that includes an access network 704, such as a radio access network (RAN), and a core network 706, which includes one or more core network nodes 708. The access network 704 includes one or more access network nodes, such as network nodes 710a and 710b (one or more of which may be generally referred to as network nodes 710), or any other similar 3rdGeneration Partnership Project (3 GPP) access node or non-3GPP access point. The network nodes 710 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 712a, 712b, 712c, and 712d (one or more of which may be generally referred to as UEs 712) to the core network 706 over one or more wireless connections.

[0114] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system 700 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system 700 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0115] The UEs 712 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 710 and other communication devices. Similarly, the network nodes 710 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 712 and / or with other network nodes or equipment in the telecommunication network 702 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 702.

[0116] In the depicted example, the core network 706 connects the network nodes 710 to one or more hosts, such as host 716. These connections may be direct or indirect via one or more intermediary networks or devices.

[0117] In some examples, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi -radio dual connectivity (MR-DC), such as E- UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0118] In the example, the hub 714 communicates with the access network 704 to facilitate indirect communication between one or more UEs (e.g., UE 712c and / or 712d) and network nodes (e.g., network node 710b). In some examples, the hub 714 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 714 may be a broadband router enabling access to the core network 706 for the UEs. As another example, the hub 714 may be a controller that sends commands or instructions to one or more actuators in the UEs.

[0119] FIGURE 8 shows a UE 800 in accordance with some embodiments. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0120] The UE 800 includes processing circuitry 802 that is operatively coupled via a bus 804 to an input / output interface 806, a power source 808, a memory 810, a communication interface 812, and / or any other component, or any combination thereof. The processing circuitry 802 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 810. In some embodiments, the power source 808 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used.

[0121] The memory 810 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 810 includes one or more application programs 814, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 816. The memory 810 may store, for use by the UE 800, any of a variety of various operating systems or combinations of operating systems.

[0122] The processing circuitry 802 may be configured to communicate with an access network or other network using the communication interface 812. The communication interface 812 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 822.

[0123] FIGURE 9 shows a network node 900 that may be operate as a scheduling node in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (Aps) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), NR NodeBs (gNBs)), and any other nodes in communication with these or other nodes in the communication network.

[0124] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0125] The network node 900 includes a processing circuitry 902, a memory 904, a communication interface 906, and a power source 908. The network node 900 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node 900 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 900 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 904 for different RATs) and some components may be reused (e.g., a same antenna 910 may be shared by different RATs). The network node 900 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 900, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 900.

[0126] The processing circuitry 902 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 900 components, such as the memory 904, to provide network node 900 functionality.

[0127] In some embodiments, the processing circuitry 902 includes a system on a chip (SOC). In some embodiments, the processing circuitry 902 includes one or more of radio frequency (RF) transceiver circuitry 912 and baseband processing circuitry 914. In some embodiments, the radio frequency (RF) transceiver circuitry 912 and the baseband processing circuitry 914 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 912 and baseband processing circuitry 914 may be on the same chip or set of chips, boards, or units.

[0128] The memory 904 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 902. The memory 904 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 902 and utilized by the network node 900. The memory 904 may be used to store any calculations made by the processing circuitry 902 and / or any data received via the communication interface 906. In some embodiments, the processing circuitry 902 and memory 904 is integrated.

[0129] The communication interface 906 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 906 comprises port(s) / terminal(s) 916 to send and receive data, for example to and from a network over a wired connection. The communication interface 906 also includes radio front-end circuitry 918 that may be coupled to, or in certain embodiments a part of, the antenna 910. Radio front-end circuitry 918 comprises filters 920 and amplifiers 922. The radio front-end circuitry 918 may be connected to an antenna 910 and processing circuitry 902. The radio front-end circuitry may be configured to condition signals communicated between antenna 910 and processing circuitry 902. The radio front-end circuitry 918 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 918 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 920 and / or amplifiers 922. The radio signal may then be transmitted via the antenna 910. Similarly, when receiving data, the antenna 910 may collect radio signals which are then converted into digital data by the radio front-end circuitry 918. The digital data may be passed to the processing circuitry 902. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0130] In certain alternative embodiments, the network node 900 does not include separate radio front-end circuitry 918, instead, the processing circuitry 902 includes radio front-end circuitry and is connected to the antenna 910. Similarly, in some embodiments, all or some of the RF transceiver circuitry 912 is part of the communication interface 906. In still other embodiments, the communication interface 906 includes one or more ports or terminals 916, the radio front-end circuitry 918, and the RF transceiver circuitry 912, as part of a radio unit (not shown), and the communication interface 906 communicates with the baseband processing circuitry 914, which is part of a digital unit (not shown).

[0131] The antenna 910 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna 910 may be coupled to the radio front-end circuitry 918 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 910 is separate from the network node 900 and connectable to the network node 900 through an interface or port.

[0132] The antenna 910, communication interface 906, and / or the processing circuitry 902 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 910, the communication interface 906, and / or the processing circuitry 902 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0133] The power source 908 provides power to the various components of network node 900 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 908 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 900 with power for performing the functionality described herein. For example, the network node 900 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 908. As a further example, the power source 908 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0134] Embodiments of the network node 900 may include additional components beyond those shown in FIGURE 9 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 900 may include user interface equipment to allow input of information into the network node 900 and to allow output of information from the network node 900. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 900.

[0135] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0136] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer- readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer- readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

Claims

CLAIMS:

1. A computer-implemented method (200, 600) for securing a forecasting model against white-box adversarial attacks, the method comprising: based on at least one Key Performance Indicator, KPI and at least one deployment scenario, generating (208, 602) adversarial sample data for at least one network node (710) in a communications network (710); using (210, 604) the at least one KPI and the at least one adversarial sample data to train at least one forecasting model; and using (606) the at least one forecasting model to initiate at least one scheduling task.

2. The method of Claim 1, wherein using the at least one forecasting model to perform the at least one scheduling operation comprises using the at least one forecasting model to schedule a software upgrade for the network node.

3. The method of any one of Claims 1 to 2, wherein prior to using the at least one KPI and the at least one adversarial sample data to train the at least one forecasting model, the method comprises: obtaining (200) performance management, PM, data for the at least one network node in a communications network; calculating (203) the at least one KPI based on the PM data; and training (204) at least one baseline forecasting model based on the at least one KPI.

4. The method of Claim 3, comprising: calculating (203) the at least one KPI based on the PM data, and wherein the adversarial sample data is generated based on the at least one KPI.

5. The method of any one of Claims 3 to 4, wherein the PM data comprises live data indicating a performance level of the at least one forecasting model during at least one rolling observational period, ROP.

6. The method of any one of Claims 3 to 5, wherein obtaining the PM data comprises receiving the PM data from the at least one network node on a periodic basis.

7. The method of any one of Claims 3 to 6, comprising:determining at least one performance metric for the at least one baseline forecasting model trained based on the at least one KPI; and based on the at least one performance metric, evaluating a (206) performance of the at least one baseline forecasting model trained based on the at least one KPI.

8. The method of Claim 7, wherein evaluating the performance of the at least one forecasting model comprises determining a gradient of a loss of the at least one forecasting model.

9. The method of Claim 8, wherein: the PM data comprises at least one PM data sample, the adversarial sample data comprises at least one adversarial sample, and generating the adversarial sample comprises: computing a sign vector of the gradient of the loss of the at least one forecasting model; scaling the sign vector by a scalar value associated with a magnitude of perturbation; and applying the scaled sign vector to the at least one KPI to determine the adversarial sample data.

10. The method of Claim 9, comprising: using the adversarial sample data as first input to the at least one forecasting model; determining at least one model evaluation metric for the at least one forecasting model based on the adversarial sample data; and based on the at least one model evaluation metric, determining a change in the performance of the at least one forecasting model.

11. The method of Claim 10, comprising: performing a comparison of the at least one additional performance metric obtained for the at least one forecasting model to the at least one performance metric obtained for the at least one baseline forecasting model; and based on comparison, determining whether further training of the at least one baseline model and / or the at least one forecasting model is needed.

12. The method of any one of Claims 7 to 11, wherein the at least one performance metric and / or the at least one additional performance metric comprises at least one of:a mean squared error, a mean absolute error, a root mean squared error, and a R-squared score.

13. The method of any one of Claims 9 to 12, comprising: re-training the at least one forecasting model based on the PM data and the adversarial sample data; and after re-training the at last one forecasting model, using the adversarial sample data as second input to the at least one forecasting model; and determining a change in the performance of the at least one forecasting model.

14. The method of any one of Claims 1 to 13, wherein the method is performed by a scheduling node of the communications network.

15. A scheduling node (900) for securing a forecasting model against white-box adversarial attacks, the scheduling node configured to: based on at least one Key Performance Indicator, KPI and at least one deployment scenario, generate (602) adversarial sample data for at least one network node (710) in a communications network (702); use (604) the at least one KPI and the at least one adversarial sample data to train at least one forecasting model; and use (606) the at least one forecasting model to initiate at least one scheduling task.

16. The scheduling node of Claim 15, wherein when using the at least one forecasting model to perform the at least one scheduling operation the scheduling node is configured to use the at least one forecasting model to schedule a software upgrade for the network node.

17. The scheduling node of any one of Claims 15 to 16, wherein prior to using the at least one KPI and the at least one adversarial sample data to train the at least one forecasting model, the scheduling node is configured to: obtain (200) performance management, PM, data for the at least one network node in a communications network; calculating (203) the at least one KPI based on the PM data; and training (204) at least one baseline forecasting model based on the at least one KPI.

18. The scheduling node of Claim 17, wherein the scheduling node is configured to: calculate (203) the at least one KPI based on the PM data, and wherein the adversarial sample data is generated based on the at least one KPI.

19. The scheduling node of any one of Claims 17 to 18, wherein the PM data comprises live data indicating a performance level of the at least one forecasting model during at least one rolling observational period, ROP.

20. The scheduling node of any one of Claims 17 to 19, wherein when obtaining the PM data the scheduling node is configured to receive the PM data from the at least one network node on a periodic basis.

21. The scheduling node of any one of Claims 17 to 20, wherein the scheduling node is configured to: determine at least one performance metric for the at least one baseline forecasting model trained based on the at least one KPI; and based on the at least one performance metric, evaluate a (206) performance of the at least one baseline forecasting model trained based on the at least one KPI.

22. The scheduling node of Claim 21, wherein when evaluating the performance of the at least one forecasting model the scheduling node is configured to determine a gradient of a loss of the at least one forecasting model.

23. The scheduling node of Claim 22, wherein: the PM data comprises at least one PM data sample, the adversarial sample data comprises at least one adversarial sample, and when generating the adversarial sample the scheduling node is configured to: compute a sign vector of the gradient of the loss of the at least one forecasting model; scale the sign vector by a scalar value associated with a magnitude of perturbation; and apply the scaled sign vector to the at least one KPI to determine the adversarial sample data.

24. The scheduling node of Claim 23, wherein the scheduling node is configured to: use the adversarial sample data as first input to the at least one forecasting model; determine at least one model evaluation metric for the at least one forecasting model based on the adversarial sample data; and based on the at least one model evaluation metric, determine a change in the performance of the at least one forecasting model.

25. The scheduling node of Claim 24, wherein the scheduling node is configured to: perform a comparison of the at least one additional performance metric obtained for the at least one forecasting model to the at least one performance metric obtained for the at least one baseline forecasting model; and based on comparison, determine whether further training of the at least one baseline model and / or the at least one forecasting model is needed.

26. The scheduling node of any one of Claims 21 to 25, wherein the at least one performance metric and / or the at least one additional performance metric comprises at least one of: a mean squared error, a mean absolute error, a root mean squared error, and a R-squared score.

27. The scheduling node of any one of Claims 23 to 26, wherein the scheduling node is configured to: re-train the at least one forecasting model based on the PM data and the adversarial sample data; and after re-training the at last one forecasting model, use the adversarial sample data as second input to the at least one forecasting model; and determine a change in the performance of the at least one forecasting model.

28. The scheduling node of any one of Claims 15 to 27, wherein the method is performed by a scheduling node of the communications network.

29. A computer-readable medium (904) storing instructions for securing a forecasting model against white-box adversarial attacks, the instructions being implemented by a computer to cause the computer to:based on at least one Key Performance Indicator, KPI and at least one deployment scenario, generate (602) adversarial sample data for at least one network node in a communications network; use (604) the at least one KPI and the at least one adversarial sample data to train at least one forecasting model; and use (606) the at least one forecasting model to initiate at least one scheduling task.

Citation Information

Patent Citations

  • System and Method for Forecasting Values of a Time Series

    US20180196900A1

  • System and method for max-margin adversarial training

    US20200134468A1

  • Generating trained neural networks with increased robustness against adversarial attacks

    US20200234110A1

  • Systems and methods for network performance forecasting

    US9439081B1