Security management against vulnerabilities in machine learning models in a communication network environment
Patent Information
- Application Number
- PCT/EP2026/055462
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-24
- Filing Date
- 2026-02-27
- Publication Date
- 2026-10-01
Smart Images

Figure EP2026055462_01102026_PF_FP_ABST
Abstract
Description
[0001] SECURITY MANAGEMENT AGAINST VULNERABILITIES IN MACHINE LEARNING MODELS IN A COMMUNICATION NETWORK ENVIRONMENT
[0002] Field
[0003] The field relates generally to communication networks, and more particularly, but not exclusively, to security management in such communication networks.
[0004] Background
[0005] This section introduces aspects that may be helpful in facilitating a better understanding of the inventions. Accordingly, the statements of this section are to be read in this light and are not to be understood as admissions about what is in the prior art or what is not in the prior art.
[0006] Advancements in communication network technologies have rapidly progressed over recent years.
[0007] Fourth generation (4G) wireless mobile telecommunications technology, also known as Long Term Evolution (LTE) technology, provided high-capacity mobile multimedia with high data rates particularly for human interaction, as compared with previous generations of communication networks.
[0008] Fifth generation (5G) technology currently provides not only for human interaction use cases, but also for machine type communications in so-called Internet of Things (loT) networks. While 5G networks enable massive loT services (e.g., very large numbers of limited capacity devices) and mission-critical loT services (e.g., requiring high reliability), improvements over 4G communication services are supported in the form of enhanced mobile broadband (eMBB) services providing improved wireless Internet access for mobile devices.
[0009] Sixth generation (6G) technology is now being developed for communication networks that differs from 5G technology by offering, inter alia, significant improvements in speed and latency (e.g., the Ultra-Reliable Low-Latency Communication (URLLC) service that began with 5G is being refined and improved in 6G to address more stringent connectivity requirements), as well as the capability to sense a physical environment through expanded spectrum band usage. Such sensing capability enables creation of a digital twin of the physical environment which leads to new applications such as, but not limited to, highly accurate localization and immersive experiences. Furthermore, in 6G technology, artificial intelligence(Al) applications, which may include machine learning (ML) applications, e.g., AI / ML applications, are intended to be more readily utilized to facilitate various communication network functionalities.
[0010] However, security management is an important consideration in any communication network environment - and now especially ones that provide for applications such as localization, immersion, AI / ML, and the like. Moreover, security management is an ongoing consideration due to continuing attempts to improve the architectures and protocols associated with communication networks in order to increase network efficiency and / or subscriber convenience. Accordingly, security management can present significant technical challenges.
[0011] Summary
[0012] Illustrative embodiments provide security techniques for managing vulnerabilities in artificial intelligence / machine learning (AI / ML) models used in a communication network environment.
[0013] In one illustrative embodiment, a method includes obtaining a security instruction message from a control entity of a communications network, the security instruction message indicating one or more security measures to be implemented in the communications network for one or more types of artificial intelligence / machine learning operations. The method further includes generating a security policy indicating the one or more security measures to be implemented in the communications network for the one or more types of artificial intelligence / machine learning operations.
[0014] For example, the one or more artificial intelligence / machine learning operations may include a centralized machine learning model sharing procedure and / or a distributed machine learning model sharing procedure (e.g., federated learning). In some examples, the one or more security measures may include at least one of: one or more security measures to be implemented in one or more model sharing scenarios; one or more security measures to be implemented for one or more trust levels between model sharing entities; and one or more security measures to be implemented for one or more analytics sensitivity levels.
[0015] Further illustrative embodiments are provided in the form of a non-transitory computer readable medium having embodied therein executable program code that when executed by a processor causes the processor to perform the above and / or other steps, operations, and the like. Still further illustrative embodiments comprise an apparatus with a processor and a memoryconfigured to perform the above and / or other steps, operations, and the like. Some illustrative embodiments comprise a system configured to perform the above and / or other steps, operations, and the like. Further, some illustrative embodiments comprise an apparatus or a system comprising means for performing the above and / or other steps, operations, and the like.
[0016] Advantageously, illustrative embodiments provide security techniques for managing vulnerabilities (e.g., evading trapdoors) in AI / ML models used among user equipment and / or core network functions in a communication network environment.
[0017] These and other features and advantages of embodiments described herein will become more apparent from the accompanying drawings and the following detailed description.
[0018] Brief Description of the Drawings
[0019] FIG. 1 illustrates a communication network environment with which one or more illustrative embodiments may be implemented.
[0020] FIG. 2 illustrates user equipment and entities with which one or more illustrative embodiments may be implemented.
[0021] FIG. 3 illustrates a procedure for security policy generation and implementation for machine learning models in a communication network environment according to an illustrative embodiment.
[0022] FIG. 4 illustrates a procedure for security policy generation and implementation for machine learning models in a communication network environment according to another illustrative embodiment.
[0023] FIG. 5 illustrates a procedure for security policy generation and implementation for machine learning models in a communication network environment according to yet another illustrative embodiment.
[0024] FIG. 6 illustrates a procedure for security policy generation and implementation for machine learning models in a communication network environment according to a further illustrative embodiment.
[0025] FIG. 7 illustrates a backdoor attack test procedure for security policy implementation for machine learning models in a communication network environment according to an illustrative embodiment.FIG. 8 illustrates a data trap countermeasure procedure for security policy implementation for machine learning models in a communication network environment according to an illustrative embodiment.
[0026] Detailed Description
[0027] Embodiments will be illustrated herein in conjunction with example communication systems and associated techniques for security management in communication systems. It should be understood, however, that the scope of the claims is not limited to particular types of communication systems and / or processes disclosed. Embodiments can be implemented in a wide variety of other types of communication systems, using alternative processes and operations. For example, although illustrated in the context of wireless cellular systems utilizing the 3rd Generation Partnership Project (3GPP) system elements such as a 3GPP next generation system (5G), the disclosed embodiments can be adapted in a straightforward manner to a variety of other types of communication systems such as 6G communication systems.
[0028] In accordance with illustrative embodiments implemented in 5G / 6G communication system environments, one or more 3 GPP technical specifications (TS) and technical reports (TR) may provide further explanation of network elements / functions and / or operations that may interact with parts of the inventive solutions. By way of example only, Technical Specification (TS) 33.501, entitled “Technical Specification Group Services and System Aspects; Security Architecture and Procedures for the 5G System,” the disclosure of which is incorporated by reference herein in its entirety, describes security management details applicable to 5G and other networks. Other 3GPP TS / TR documents may provide other details that one of ordinary skill in the art will realize, for example, 3GPP TS 23.288, entitled “Technical Specification Group Services and System Aspects; Architecture Enhancements for 5G System (5GS) to Support Network Data Analytics Services,” the disclosure of which is incorporated by reference herein in its entirety. Note that 3GPP TS / TR documents are nonlimiting examples of communication network standards (e.g., specifications, procedures, reports, requirements, recommendations, and the like). However, while well-suited for 5G-related and other 3 GPP standards, embodiments are not necessarily intended to be limited to any particular standards.
[0029] It is to be understood that the term 5G network, and the like (e.g., 5G system, 5G communication system, 5G environment, 5G communication environment etc.), in someillustrative embodiments, may comprise all or part of an access network and all or part of a core network. However, the term 5G network, and the like, may also occasionally be used interchangeably herein with the term 5GC network, and the like, without any loss of generality, since one of ordinary skill in the art understands any distinctions. Also, it is to be understood that terms and descriptions used for 5G networks can apply to 6G and other networks.
[0030] Prior to describing illustrative embodiments, a general description of certain main components of a communication network environment will be described below in the context of FIGS. 1 and 2.
[0031] FIG. 1 shows a communication system 100 within which illustrative embodiments are implemented. It is to be understood that the elements shown in communication system 100 are intended to represent some main functions provided within the system, e.g., control plane functions, user plane functions, etc. As such, the blocks shown in FIG. 1 reference specific elements in 5G networks that provide some of these main functions. However, other network elements may be used to implement some or all of the main functions represented. Also, it is to be understood that not all functions of a 5G network are depicted in FIG. 1. Rather, at least some functions that facilitate an explanation of illustrative embodiments are represented. Subsequent figures may depict some additional elements / functions (i.e., network entities).
[0032] Accordingly, as shown, communication system 100 comprises user equipment (UE) 102 that communicates via an air interface 103 with an access point 104. It is to be understood that UE 102 may use one or more other types of access points (e.g., access functions, networks, etc.) to communicate with the 5GC network other than a gNB. By way of example only, the access point 104 may be any 5G access network (gNB), an untrusted non-3GPP access network that uses an Non-3GPP Interworking Function (N3IWF), a trusted non-3GPP network that uses a Trusted Non-3GPP Gateway Function (TNGF) or wireline access that uses a Wireline Access Gateway Function (W-AGF) or may correspond to a legacy access point (e.g., eNB). Furthermore, access point 104 may be a wireless local area network (WLAN) access point as may be applicable to illustrative embodiments described herein.
[0033] The UE 102 may be a mobile station, and such a mobile station may comprise, by way of example, a mobile telephone, a computer, an loT device, or any other type of communication device. The term “user equipment” as used herein is therefore intended to be construed broadly, so as to encompass a variety of different types of mobile stations, subscriber stations or, more generally, communication devices, including examples such as a combination of adata card inserted in a laptop or other equipment such as a smart phone. Such communication devices are also intended to encompass devices commonly referred to as access terminals.
[0034] In one illustrative embodiment, UE 102 is comprised of a Universal Integrated Circuit Card (UICC) part and a Mobile Equipment (ME) part. The UICC is the user-dependent part of the UE and contains at least one Universal Subscriber Identity Module (USIM) and appropriate application software. The USIM securely stores a permanent subscription identifier and its related key, which are used to uniquely identify and authenticate subscribers to access networks. The ME is the user-independent part of the UE and contains terminal equipment (TE) functions and various mobile termination (MT) functions. Alternative illustrative embodiments may not use UICC-based authentication, e.g., a Non-Public (Private) Network (NPN).
[0035] Note that, in one example, the permanent subscription identifier is an International Mobile Subscriber Identity (IMSI) unique to the UE. In one embodiment, the IMSI is a fixed 15-digit length and consists of a 3-digit Mobile Country Code (MCC), a 3-digit Mobile Network Code (MNC), and a 9-digit Mobile Station Identification Number (MSIN). In a 5G communication system, an IMSI is referred to as a Subscription Permanent Identifier (SUPI). In the case of an IMSI as a SUPI, the MSIN provides the subscriber identity. Thus, only the MSIN portion of the IMSI typically needs to be encrypted. The MNC and MCC portions of the IMSI provide routing information, used by the serving network to route to the correct home network. When the MSIN of a SUPI is encrypted, it is referred to as Subscription Concealed Identifier (SUCI). Another example of a SUPI uses a Network Access Identifier (NAI). NAI is typically used for loT communication.
[0036] The access point 104 is illustratively part of a radio access network or RAN of the communication system 100. Such a radio access network may comprise, for example, a 5G System having a plurality of base stations. Components of a radio access network may, more generally, be considered “radio access entities.”
[0037] Further, the access point 104 in this illustrative embodiment is operatively coupled to an Access and Mobility Management Function (AMF) 106. In a 5G network, the AMF supports, inter alia, mobility management (MM) and security anchor (SEAF) functions.
[0038] AMF 106 in this illustrative embodiment is operatively coupled to (e.g., uses the services of) other network functions 108. As shown, some of these other network functions 108 include, but are not limited to, a Network Data Analytics Function (NWDAF), a NetworkRepository Function (NRF), and a Policy Control Function (PCF). These listed network function examples are typically implemented in the home network of the UE subscriber, further explained below. The NWDAF is a network function that collects data from various network functions, application functions, as well as operations, administration, and management (0AM) systems, and operational support systems. 0AM refers to processes and tools used to manage and maintain a communication network to ensure that network runs smoothly and efficiently. As used herein, such processes and tools are collectively referred to as an 0AM node (or, more generally, a “control entity”). The NWDAF is configured to facilitate the way data is produced and consumed, as well as to generate analytical insights and take actions based on the analytical insights. The NRF is a centralized repository that enables other NFs to register and discover each other via a standardized application programming interface. The PCF enables policy control and management, facilitating network behavior control, network slicing, UE activities, and communication with other core network functions.
[0039] Other network functions 108 may include network functions that can act as service producers (NFp) and / or service consumers (NFc). Note that any network function can be a service producer for one service and a service consumer for another service. Further, when the service being provided includes data, the data-providing NFp is referred to as a data producer, while the data-requesting NFc is referred to as a data consumer. A data producer may also be an NF that generates data by modifying or otherwise processing data produced by another NF. Note that NFs may, more generally, be considered “network entities.”
[0040] Note that a UE, such as UE 102, is typically subscribed to what is referred to as a Home Public Land Mobile Network (HPLMN) in which some or all of the functions 106 and 108 reside. Alternatively the UE, such as UE 102, may receive services from aNon-Public Network (NPN) where these functions may reside. The HPLMN is also referred to as the Home Environment (HE). If the UE is roaming (not in the HPLMN), it is typically connected with a Visited Public Land Mobile Network (VPLMN) also referred to as a visited network, while the network that is currently serving the UE is also referred to as a serving network. In the roaming case, some of the functions 106 and 108 can reside in the VPLMN, in which case, functions in the VPLMN communicate with functions in the HPLMN as needed. However, in a nonroaming scenario, access and mobility management functions 106 and the other network functions 108 reside in the same communication network, i.e., HPLMN. Embodimentsdescribed herein, unless otherwise specified, are not necessarily limited by which functions reside in which PLMN (i.e., HPLMN or VPLMN).
[0041] The access point 104 is also operatively coupled (via one or more of functions 106 and / or 108) to a Session Management Function (SMF) 110, which is operatively coupled to a User Plane Function (UPF) 112. UPF 112 is operatively coupled to a Packet Data Network, e.g., Internet 114. Note that the thicker solid lines in this figure denote a user plane (UP) of the communication network, as compared to the thinner solid lines that denote a control plane (CP) of the communication network. It is to be appreciated that network (e.g., Internet) 114 in FIG.
[0042] 1 may additionally or alternatively represent other network infrastructures including, but not limited to, cloud computing infrastructure and / or edge computing infrastructure. Further typical operations and functions of such network elements are not described here since they are not the focus of the illustrative embodiments and may be found in appropriate 3GPP 5G documentation. Note that functions shown in 106, 108, 110 and 112 are examples of network functions (NFs).
[0043] It is to be appreciated that this particular arrangement of system elements is an example only, and other types and arrangements of additional or alternative elements can be used to implement a communication system in other embodiments. For example, in other embodiments, the communication system 100 may comprise other elements / functions not expressly shown herein.
[0044] Accordingly, the FIG. 1 arrangement is just one example configuration of a wireless cellular system, and numerous alternative configurations of system elements may be used. For example, although only single elements / functions are shown in the FIG. 1 embodiment, this is for simplicity and clarity of description only. A given alternative embodiment may of course include larger numbers of such system elements, as well as additional or alternative elements of a type commonly associated with conventional system implementations.
[0045] It is also to be noted that while FIG. 1 illustrates system elements as singular functional blocks, the various subnetworks that make up the network may be partitioned into so-called network slices. Network slices (network partitions) are logical networks that provide specific network capabilities and network characteristics that can support a corresponding service type, optionally using network function virtualization (NFV) on a common physical infrastructure. With NFV, network slices are instantiated as needed for a given service, e.g., eMBB service, massive loT service, and mission-critical loT service. A network slice or function is thusinstantiated when an instance of that network slice or function is created. In some embodiments, this involves installing or otherwise running the network slice or function on one or more host devices of the underlying physical infrastructure. UE 102 is configured to access one or more of these services via access point 104.
[0046] FIG. 2 is a block diagram illustrating computing architectures for various participants in methodologies according to illustrative embodiments. More particularly, system 200 is shown comprising user equipment (UE) 202 and a plurality of entities 204-1, . . . . , 204-N. For example, in illustrative embodiments and with reference back to FIG. 1, UE 202 can represent UE 102, while entities 204-1, . . . , 204-N can represent functions 106 and 108 (i.e., network entities such as, but not limited to, NWDAF, NRF, PCF, etc.), and as will be described in illustrative embodiments herein, a Mobile Security Management Function (MSMF), as well as access point 104 (i.e., radio access entity such as, but not limited to, a RAN node or gNB). It is to be appreciated that the UE 202 and entities 204-1, . . . . , 204-N are configured to interact to provide security management and other techniques described herein.
[0047] The user equipment 202 comprises a processor 212 coupled to a memory 216 and interface circuitry 210. The processor 212 of the user equipment 202 includes a security management processing module 214 that may be implemented at least in part in the form of software executed by the processor. The security management processing module 214 performs security management described in conjunction with subsequent figures and otherwise herein. The memory 216 of the user equipment 202 includes a security management storage module 218 that stores data generated or otherwise used during security management operations.
[0048] Each of the entities (individually or collectively referred to herein as 204) comprises a processor 222 (222-1, . . . , 222-N) coupled to a memory 226 (226-1, . . . , 226-N) and interface circuitry 220 (220-1, . . . , 220-N). Each processor 222 of each entity 204 includes a security management processing module 224 (224-1, . . . , 224-N) that may be implemented at least in part in the form of software executed by the processor 222. The security management processing module 224 performs security management operations described in conjunction with subsequent figures and otherwise herein. Each memory 226 of each entity 204 includes a security management storage module 228 (228-1, . . . , 228-N) that stores data generated or otherwise used during security management operations.The processors 212 and 222 may comprise, for example, microprocessors such as central processing units (CPUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs) or other types of processing devices, as well as portions or combinations of such elements.
[0049] The memories 216 and 226 may be used to store one or more software programs that are executed by the respective processors 212 and 222 to implement at least a portion of the functionality described herein. For example, security management operations and other functionality as described in conjunction with subsequent figures and otherwise herein may be implemented in a straightforward manner using software code executed by processors 212 and 222.
[0050] A given one of the memories 216 and 226 may therefore be viewed as an example of what is more generally referred to herein as a computer program product or still more generally as a computer or processor readable (non-transitory or storage) medium that has executable program code embodied therein. Other examples of computer or processor readable media may include disks or other types of magnetic or optical media, in any combination. Illustrative embodiments can include articles of manufacture comprising such computer program products or other computer or processor readable media.
[0051] Further, the memories 216 and 226 may more particularly comprise, for example, electronic random-access memory (RAM) such as static RAM (SRAM), dynamic RAM (DRAM) or other types of volatile or non-volatile electronic memory. The latter may include, for example, non-volatile memories such as flash memory, magnetic RAM (MRAM), phasechange RAM (PC-RAM) or ferroelectric RAM (FRAM). The term “memory” as used herein is intended to be broadly construed, and may additionally or alternatively encompass, for example, a read-only memory (ROM), a disk-based memory, or other type of storage device, as well as portions or combinations of such devices.
[0052] The interface circuitries 210 and 220 illustratively comprise transceivers or other communication hardware or firmware that allows the associated system elements to communicate with one another in the manner described herein.
[0053] It is apparent from FIG. 2 that user equipment 202 and plurality of entities 204 are configured for communication with each other as security management participants via their respective interface circuitries 210 and 220. This communication involves each participant sending data to and / or receiving data from one or more of the other participants. The term“data” as used herein is intended to be construed broadly, so as to encompass any type of information that may be sent between participants including, but not limited to, identity data, key pairs, key indicators, access tokens, secrets, security management messages, registration request / response messages and data, request / response messages, authentication request / response messages and data, metadata, control data, audio, video, multimedia, consent data, other messages, etc.
[0054] It is to be appreciated that the particular arrangement of components shown in FIG. 2 is an example only, and numerous alternative configurations may be used in other embodiments. For example, any given network element / function and / or access point can be configured to incorporate additional or alternative components and to support other communication protocols.
[0055] Other system elements such as access point 104, SMF 110, and UPF 112 may each be configured to include components such as a processor, memory and network interface. Also, entities such as third-party applications and network operators can participate in methodologies described herein via computing devices configured to include components such as a processor, memory and network interface. These elements and devices need not be implemented on separate stand-alone processing platforms, but could instead, for example, represent different functional portions of a single common processing platform.
[0056] More generally, FIG. 2 can be considered to represent processing devices configured to provide respective security management functionalities and operatively coupled to one another in a communication system. By way of example only, all or parts of each of UE 202 and the plurality of entities 204 (e.g., processor and memory) can be considered examples of means for performing one or more operations, one or more steps, one or more functions, one or more processes, etc. as described herein.
[0057] Given the above general description of some features of a communication network environment, problems with existing security approaches in managing vulnerabilities associated with AI / ML models, and solutions proposed in accordance with illustrative embodiments, will now be described herein below.
[0058] UEs and / or other devices can be configured to participate with a NWDAF and / or a third-party artificial intelligence / machine learning (AI / ML) engine or neural network model trainer. More particularly, model training (i.e., part of analytics services) via an NWDAF model training logical function (MTLF) has been described in the above-referenced TS 23.288with corresponding security mechanisms defined in TS 33.501. In 6G networks, it has been proposed to implement native Al wherein network elements (UE, radio access nodes, core network functions, etc.) have AI / ML capabilities and generative Al (GenAI) functionalities. Note that the terms AI / ML, Al, and ML may illustratively be used interchangeably herein.
[0059] Trained AI / ML model sharing has been defined in which a pretrained model is acquired from an entity to be used directly or after fine tuning with specialized data. Such trained AI / ML model sharing can be performed via a completely open model, for instance, in federated learning (FL) or in centralized learning where the consumer can then further fine tune the model using its own training data. Alternatively, trained AI / ML model sharing can be performed in the form of a “blackbox” accessible only through an application programming interface (API).
[0060] However, in a scenario where the AI / ML model producer is malicious, the AI / ML producer can inject “backdoor traps” and corrupt the AI / ML model during training. Such backdoor traps act as security vulnerabilities in the AI / ML models that contain them. For example, when used by AI / ML model consumers, such vulnerable AI / ML models can be used to steal an AI / ML model consumer’s local training data (e.g., privacy backdoors) or can be programmed to be triggered when receiving certain inputs (data poisoning backdoors) to provide biased or tampered inference outputs.
[0061] Since these backdoors are injected in the AI / ML models during the training phase itself, it is extremely difficult to detect them. Therefore, it would be advantageous to generate and implement security policies, based upon the use case and deployment needs to be implemented, to evade such backdoors. Currently, there exist no mechanisms to enable the AI / ML model consumers to generate and / or receive such security policies and perform these measures before using the AI / ML models. Such vulnerabilities and security threats will become more severe with the advent of 6G networks which intend to utilize AI / ML applications ubiquitously.
[0062] Illustratively embodiments overcome the above-mentioned and other technical drawbacks associated with existing AI / ML model approaches by providing security management techniques to evade backdoor attacks by defining security policies that can be applied at the end model consumer, e.g., an entity and / or device that will be further retraining the AI / ML model and / or using the AI / ML model for inference.
[0063] In various illustrative embodiments to be further described, the security policies can be dynamically generated by a variety of different entities and / or devices. For example, such security policies can be generated either by an NRF, a new model security managementfunction (MSMF), an 0AM, or by a PCF, based upon the deployment scenarios and use cases. In some illustrative embodiments, the security policies generated are based upon the trust between the vendors (e.g., as indicated by an interoperability indicator), sensitivity of the analytics being performed (e.g., high - highly sensitive, medium - moderately sensitive, or low - minimally or not sensitive), the way in which the trained model is accessed, and if further fine tuning is needed or not (e.g., in the case where the AI / ML models are open source AI / ML models or pre-shared AI / ML models wherein the model consumer has to further train the obtained AI / ML model using its own local training data). These and other factors can eventually alter the sensitivity of the training data which is used to fine tune / train the AI / ML model, and in the case there is not enough trust between the vendors (e.g., not present as part of an interoperability list) then stringent security mechanisms may be applied.
[0064] FIG. 3 illustrates a procedure 300 for security policy generation and implementation for machine learning models in a communication network environment according to an illustrative embodiment. As shown, procedure 300 involves an NF service consumer (AI / ML model consumer) 302, an NRF 304, an 0AM (node) 306, and an NF service producer (AI / ML model producer) 308. In general, in accordance with steps 1 through 11 of procedure 300, security policy generation instructions are pushed by 0AM 306 to the core network, e.g., NRF 304, and then NRF 304 generates the security policies.
[0065] Step 1. 0AM 306 sends a policy provision request to NRF 304 for AI / ML model sharing (e.g., an N_nrf_model_provisioning_security message) indicating measures to be applied in various model sharing scenarios and trust between model sharing entities and the sensitivity of analytics (if available). The policy provisioning request may generally be referred to as a “security instruction message.” For example, in the case of cross vendor AI / ML model sharing of a complete AI / ML model, or in the case of using open source large language models (LLMs) and then further fine tuning, or in the case of a sensitive analytics ID AI / ML model, a privacy preserving technique (e.g., differential privacy (DP)) is applied before fine tuning the model or a poisoning backdoor attack detection mechanism is triggered using sample test data. Further, in the case of inference, especially for the AI / ML models only accessible via API / dedicated service requests with an expectation of receiving an analytics prediction output, a test can be initiated to detect the presence of a poisoning backdoor trap.
[0066] Step 2. NF service producer 308 (e.g., AI / ML model producer or MTLF in a majority of use cases) updates its profile with NRF 304 during an NF registration per analytics ID. Forexample, an Nnrf_Nfmanagement_Register message can include: AI / ML process type: centralized machine learning and / or distributed machine learning (e.g., FL), Vendor ID, Interoperability Indicator, Method of training the AI / ML model: completely trained / developed locally inhouse / operator owned or open source model subject to further fine tuning, Method of sharing trained AI / ML model supported: complete model with end to end encryption | complete model without encryption (for enabling local inference) | API accessible containers (for providing inference service without sharing the complete model) | model training with DP enhanced training data | model training without DP, and AI / ML model secured training capabilities supported: privacy enabled model training (for instance DP based training), encrypted Model sharing, sensitivity of Analytics ID: (low / medium / high) if present.
[0067] Step 3. NF service consumer 302 (e.g., AI / ML model consumer) sends an enhanced discovery request with additional information entities (IES) indicating the support for model security capabilities such as DP based training. For example, an Nnrf NFDiscovery Request message can include: Model Discovery IE(s), Analytics ID / Model ID, and model security supporting capabilities: e.g., DP based training.
[0068] Step 4. NRF 304, based upon the information received from the 0AM 306 (step 1), NF service producer (308) profile updates (step 2), and the AI / ML model consumer (302) enhanced discovery request (step 3), generates policies specific to the consumer and producer details and the AI / ML model being requested as part of enhanced discovery response. For example, an Nnrf_NFDiscovery_Response message can include: Nfprofile AllowedSecurityCapability: If (ModellD =1, Vendor = abc, analytics ID = xyz, AI / ML Process Type = FL, ConsumerNFtype=DCCF, analytics ID sensitivity = low) then Model Sharing Mechanism= CompleteModel without DP, AllowedSecurityCapability: If (Model2, Vendorl, AI / ML Process Type = Centralized training, analytics ID = abc, analytics ID sensitivity = high, ConsumerNFtype=ADRF) then Model Sharing Mechanism= CompleteModel with DP and use test data for poisoning backdoor attack detection | Only API accessible. Note that the AI / ML model consumer NF type here is just examples - Data Collection and Coordination Function (DCCF) and Analytics and Data Repository Function (ADRF), and alternatively can even be any other native Al NF.
[0069] Step 5. NF service consumer 302 (AI / ML model consumer) also sends an enhanced access token request indicating its supporting security capabilities. For example, an Nnrf AccessToken Request message can include: Target: AI / ML model producer NFtype / Instance ID, Source: NFc type / Instance ID, Target Model ID: Model2, Source supporting security capabilities = DP.
[0070] Step 6. NRF 304 then verifies if the NF service consumer 302 (AI / ML model consumer) is authorized to receive the trained AI / ML model or initiate FL training or not. In the case of successful verification, NRF 304 generates an enhanced access token with additional claims including: AI / MLSecurity - Privacy Enhanced (DP), Model SharingMechanism - FL, Complete Model, API accessible container (only inference), and AnalyticsIDSensitvity - Low / Medium / High. Note that enhancement in the access token is needed in the cases such as FL where the NF service producer 308 is the FL client which needs to process the AI / ML model training based upon the security policies.
[0071] Step 7. NRF 304 then sends the enhanced access token as a response to the NF service consumer 302 (AI / ML model consumer) which can include: Target: NFp type / instance ID, Source: NFc type / instance ID, Target Model ID: ABC, Allowed Model Sharing: Complete Model / API accessible container, Allowed security capabilities at producer = DP, and Analytics Sensitivity: Low / Medium / High.
[0072] Step 8. NF service consumer 302 (AI / ML model consumer) then sends a request (either to request a trained AI / ML model for analytics or, in the case of FL, to initiate the FL process via the FL clients) along with the enhanced access token received in step 7.
[0073] Step 9. In the case that the request is for FL and the NF service producer 308 is an FL client, then the FL client verifies the access token and applies the security policies present in the access token claims such that, for example, privacy enhancement is applied to all the gradients while performing AI / ML model training on its local training data, and only then the model updates are sent to an FL server for aggregation.
[0074] Step 10. In the case that the request is for just a trained AI / ML model, then the model is delivered either in the form of a URI from where the AI / ML model can be accessed (e.g., the ADRF details from where the AI / ML model can be downloaded), or in the form of an API access point where the inference input can be sent to receive analytics output (e.g., the NFp instance ID which can be sent the service request for getting the analytics output).
[0075] Step 11. Once the model is received, based upon the policies received in the enhanced discovery response, the AI / ML model consumer (NF service consumer 302) applies the requested security principles such as generating sample input to test the backdoor attack forpoisonous AI / ML models or applying DP based mechanisms during local training and fine tuning of models to preserve its private data.
[0076] FIG. 4 illustrates a procedure 400 for security policy generation and implementation for machine learning models in a communication network environment according to another illustrative embodiment. As shown, procedure 400 involves an NF service consumer (AI / ML model consumer) 402, an NRF 404, a Mobile Security Management Function (MSMF) 405, an 0AM (node) 406, and an NF service producer (AI / ML model producer) 408. In general, in accordance with steps 1 through 12 of procedure 400, security policy generation instructions are pushed by 0AM 406 to MSMF 405, and then MSMF 405 generates the policies for the AI / ML model consumer(s), e.g., NF service consumer 402.
[0077] Steps 1-12 of procedure 400 (FIG. 4) are similar overall to steps 1-11 of procedure 300 (FIG. 3) with network entities having reference numerals in the 300s being similar to network entities having reference numerals in the 400s. The exception in procedure 400 is the introduction of the dedicated network functionality of MSMF 405. Thus, only the differences in procedure 400 relative to procedure 300 are described below.
[0078] Step 2 (sub steps a and b). In sub step 2a, 0AM 406 sends the policy generation information to MSMF 405. While MSMF 405 can be a new NF, in alternative embodiments, MSMF 405 functionality can be realized in an existing NF, e.g., an ADRF. The policy generation information indicates measures to be applied in various model sharing scenarios and trust between model sharing entities and the sensitivity of analytics (if available) - similar to the information described above in procedure 300. In sub step 2b, MSMF 405 indicates to NRF 404, during the profile registration updates, which AI / ML models / vendors / analytics requires enhanced security procedures.
[0079] Steps 3, 4, 5 and 6. The AI / ML model consumer (NF service consumer 402) requests the AI / ML model from NRF 404 and NRF 404 provides an enhanced discovery response by NRF 404 indicating the MSMF (405) service to be called for selected AI / ML model / analytics / vendors. MSMF 405 then sends the access token and service request to NRF 404 and NF service producer 408, respectively, and after successful verification, either contains the trained AI / ML model or has started the FL process.
[0080] Step 7. The AI / ML model consumer (NF service consumer 402) then performs the required discovery and authorization procedure for MSMF 405 (as indicated in the discovery response sent by NRF 404 earlier).Step 8. The AI / ML model consumer (NF service consumer 402) then sends a request to MSMF 405 for the security policies specific to the AI / ML model received. For example, an Nnf_ApplySecurityCapability can include: Model ID: ABC, Model file / address, AI / ML model producer info, FL process ID / info, FL server info.
[0081] Step 9. MSMF 405 then coordinates with NRF 404 and sends a request to NRF 404 to retrieve the AI / ML model producer details (including vendor information, if deemed malicious or not), and to retrieve the sensitivity of the analytics ID. MSMF 405 also sends a request to the FL server using the information received to get the details of all the FL participants.
[0082] Steps 10 and 11. Based upon information received in step 2 and information collected in step 9, MSMF 405 generates security policies (similar to step 4 in procedure 300) to be applied and sends them back as a response.
[0083] Step 12. Based upon the policies received, the AI / ML model consumer (NF service consumer 402) applies the requested security principles such as using test data to trigger the detection of backdoor attack for poisonous AI / ML models or applying DP based mechanisms during local training and fine tuning of models or during an FL process.
[0084] FIG. 5 illustrates a procedure 500 for security policy generation and implementation for machine learning models in a communication network environment according to yet another illustrative embodiment. As shown, procedure 500 involves an NF service consumer (AI / ML model consumer) 502, an NRF 504, an 0AM (node) 506, and an NF service producer (AI / ML model producer) 508. In general, in accordance with steps 1 through 5 (sub steps a and b) of procedure 500, security policy generation instructions are directly pushed by 0AM 506 to the AI / ML model consumer (NF service consumer 502) and the AI / ML model producer (NF service producer 508).
[0085] Step 1. NF service producer 508 provides details regarding Analytics ID, AI / ML process support info (centralized or FL), Vendor ID, Interoperability Indicator, Method of sharing AI / ML model (as complete model or in API-accessible containerized form as shown.
[0086] Step 2. 0AM 506 sends the policy indicating security mechanisms deployed for various AI / ML model sharing and consumption scenarios, e.g., in the case of cross vendor AI / ML model sharing of a complete model, or in case of using open source LLMs and then further fine tuning, apply privacy preserving technique (e.g., DP) before fine tuning the model or use test data to trigger the detection of poisoning backdoor traps.Step 3. In case of FL, 0 AM 506 also sends the policy indicating security mechanisms deployed for various AI / ML model sharing and consumption scenarios for FL clients, e.g., in case of cross vendor AI / ML model sharing of a complete model, or in case of using open source LLMs and then further fine tuning, apply privacy preserving technique (e.g., DP) before fine tuning the model.
[0087] Step 4. Discovery response and access token procedures and model delivery as shown. Step 5 (sub steps a and b). In sub step 5a, once the model is received, based upon the policies received in the enhanced discovery response, the AI / ML model consumer (NF service consumer 502) applies the requested security principles, e.g., use test data to trigger the detection of poisoning backdoor traps or apply DP based mechanism during local training and fine tuning of models. In sub step 5b, in the case the request is for FL and the NF service provider 508 is an FL client, then the FL client verifies the access token and applies the security policies present in the access token claims such that, e.g., privacy enhancement is applied to all the gradients while performing AI / ML model training on its local training data, and only then is the model update sent to the FL server for aggregation.
[0088] FIG. 6 illustrates a procedure 600 for security policy generation and implementation for machine learning models in a communication network environment according to a further illustrative embodiment. As shown, procedure 600 involves a UE (AI / ML model consumer) 602, an AMF 604, a PCF 606, an 0AM (node) 608, an NRF 610, and an NF service producer (AI / ML model producer) 612. In general, in accordance with steps 1 through 11 of procedure 600, UE 602 is receiving the trained AI / ML model (or is part of FL) and seeks to apply security policies.
[0089] Step 0. 0AM 608 provisions policy generation information in PCF 606 similar to the above procedures 300 and 400.
[0090] Step 1. UE 602, when registering in a Uniform Data Management (UDM) function (not expressly shown) via AMF 604, indicates its support for security capabilities for AI / ML model training (such as, DP or detection of backdoors). In the case when UE 602 is also participating in the AI / ML model training, UE 602 also indicates the available analytics ID and / or Model ID.
[0091] Step 2. UE 602 performs authentication and authorization with AMF 604.
[0092] Step 3. PCF 606 generates the policies based upon the information provided by 0AM 608. For instance, AllowedSecurityCapability{If (Modell, Vendorl, AI / ML Process Type =FL) then Model Sharing Mechanism = OnlyAPI|CompleteModel without DP}; AllowedSecurityCapability{If(Model2, Vendorl, AI / ML Process Type = FL, ConsumerNFtype=DCCF) then Model Sharing Mechanism = CompleteModel with DP}.
[0093] Step 4. AMF 604 then pushes these generated policies to UE 602.
[0094] Step 5. UE 602 sends a model request to AMF 604, indicating its support for security capabilities and model / analytics ID. In an alternate embodiment, AMF 604 generates the policies as a response to the AI / ML model request of UE 602, such that the policy can be exactly tailored to the model requirement of UE 602.
[0095] Step 6. AMF 604 then sends an access token request to NRF 610 indicating the source as UE 602, and also the source security capabilities.
[0096] Steps 7, 8, 9 and 10 are the same as the like numbered steps of procedure 300.
[0097] Step 11. When UE 602 receives the AI / ML model, UE 602 applies the policies received from PCF 606 to ensure secured AI / ML model usage.
[0098] In additional embodiments in the above procedures of FIGS. 3-6, the security policy may contain a mechanism to, or otherwise specify that, the model training in sensitive cases (e.g., to evade privacy backdoors) be performed in a trusted execution environment (TEE).
[0099] Furthermore, illustrative embodiments provide security algorithms that can be implemented as security measures definable in security policies established in the above procedures of FIGS. 3-6.
[0100] In one security algorithm depicted in FIG. 7, a backdoor attack mechanism implanted in an AI / ML model (e.g., a neural network or NN) can be detected. The backdoor is supposed to perform well on all classes, except on a few critical classes. On those classes, the NN performs deliberately very poorly. This algorithm uses a secret test data set.
[0101] In another security algorithm depicted in FIG. 8, privacy data traps can be combatted. Such privacy data traps are typically deployed such that they lock in over a known datapoint, which allows that later AL AI / ML. The security algorithm uses input-perturbation by Gaussian noise during the finetuning so as to avoid exposing the data directly to the data traps.
[0102] FIG. 7 illustrates a backdoor attack test procedure 700 for security policy implementation for machine learning models in a communication network environment according to an illustrative embodiment. More particularly, for the backdoor data detection, procedure 700 uses a comparison between the expected performance of the model (e.g., NN) and the empirical version on some test data. For example:1) The UE receives the NN from an untrusted party. The NN could be poisoned (b ackdoored).
[0103] 2) It is assumed that the UE already has a test dataset with true labels to test the NN. 3) It is assumed the UE already has an expected outcome of a misclassification matrix:
[0104] a. The misclassification matrix shows the accuracy of the NN per class of the input data.
[0105] b. The misclassification matrix is a diagonally strong matrix. In an ideal case, it is an identity matrix with ones at the diagonal elements and zeros everywhere else.
[0106] c. The values of each matrix entry
[0107]
[0108] is the probability of outputting class-j while the true class was class-I, therefore,
[0109]
[0110] E [0,1].
[0111] A misclassification matrix (also known as a classification error matrix or a confusion matrix) is a table that summarizes the performance of a classification model by comparing its predictions to actual results and showing, by way of example, counts of true positives, true negatives, false positives, and / or false negative.
[0112] Procedure 700 is a generic test algorithm for backdoor attacks that each UE performs before using a pre-trained AI / ML model. In one example, the cosine of the angle between two misclassification matrices is computed as a measure to detect targeted poisoning of model / data in the pre-trained AI / ML model. In FIG. 7 as further described below, tr() is the trace of a matrix, and superscript T is a matrix transposition.
[0113] Step 702: Obtain UE-confidential test data: (features, labels) and a classification error matrix Mo.
[0114] Step 704: Access and test the (potentially) poisoned AI / ML model with the test data obtained in step 702.
[0115] Step 706: Analyze the performance by plotting the classification error matrix Mt(example shown as matrix 707 in FIG. 7).
[0116] Step 708: Compare the matrices Moand Mt. Again, Mois the base misclassification matrix which is given to the UE. The UE then has to compute misclassification matrix of the NN Mt. Comparing the two matrices using a simple Mean Squared Error (MSE) metric may not be adequate given the position of the discrepancies between Moand Mt. Therefore, procedure 700 uses a discrepancy metric defined as:
[0117]
[0118] where |||| is a Frobenius norm of a matrix and tr() is a trace of a matrix.
[0119] The discrepancy metric emphasizes the importance of diagonal elements by computing the trace. One further metric is to vectorize the matrices and compute the cosine of them as:
[0120] vec
[0121] -
[0122]
[0123] where, vec(M0) is the vectorization of the matrix Mo.
[0124] Steps 710 and 712: If the discrepancy metric in step 708 indicates that Modeviates significantly from Mt(e.g., greater than a deviation threshold y), then the algorithm instructs the UE to stop using the AI / ML model (step 710); otherwise (e.g., deviation is not greater than the deviation threshold y), the algorithm instructs the UE to proceed using the AI / ML model (step 712).
[0125] FIG. 8 illustrates a data trap countermeasure procedure 800 for security policy implementation for machine learning models in a communication network environment according to an illustrative embodiment. More particularly, for a privacy data trap countermeasure, it is important to make sure that, when using a differential privacy (DP) approach, the data trap can be avoided. Differential privacy is a mathematical technique that enables training of a machine learning model on sensitive data while guaranteeing that individual data points are not revealed, even if the model is exposed to adversarial attacks. A data trap is typically a use of non-linear layers in the network such as a rectified linear unit (ReLU) function. The data trap is designed in a way such that it is only positive (activates) when the specific data is computed over the neurons, while otherwise always negative. This forces the NN to show drastic outputs upon receiving the specific data trap.
[0126] A typically DP approach includes differentially-private stochastic gradient descent (DP-SGD) which is a modification of the standard SGD algorithm designed to train machine learning models while ensuring differential privacy. More particularly, the model training process does not reveal sensitive information about individual data points.
[0127] In procedure 800, as a countermeasure, noise is added directly to the data, as opposed to the common DP practice of adding it to the gradients, such that the trap is not activated.
[0128] Step 802: Gaussian noise is added to the finetuning data (DP perturbation) to avoid the data traps. Gaussian noise is a type of random noise whose values follow a Gaussian distribution and are unpredictable and vary randomly.Steps 804 through 812: Proceed with model training as shown, e.g., loss function computed on Al model, gradient computation (back propagation), generation of the updated Al model, and repeat until convergence.
[0129] Advantageously, procedure 800 provides finetuning of private data with DP over an untrusted potentially data-trapped Al model. For example, input-perturbation is executed in procedure 800 for use cases with black box access to the Al model. In use cases with white box access to the Al model, DP-SGD can be used for higher privacy-accuracy gains.
[0130] As used herein, it is to be understood that the term “communication network” in some embodiments can comprise two or more separate communication networks. Further, the particular processing operations and other system functionality described in conjunction with the diagrams described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the disclosure in any way. Alternative embodiments can use other types of processing operations and messaging protocols. For example, the ordering of the steps may be varied in other embodiments, or certain steps may be performed at least in part concurrently with one another rather than serially. Also, one or more of the steps may be repeated periodically, or multiple instances of the methods can be performed in parallel with one another.
[0131] It should again be emphasized that the various embodiments described herein are presented by way of illustrative example only and should not be construed as limiting the scope of the claims. For example, alternative embodiments can utilize different communication system configurations, user equipment configurations, base station configurations, provisioning and usage processes, messaging protocols and message formats than those described above in the context of the illustrative embodiments. These and numerous other alternative embodiments within the scope of the appended claims will be readily apparent to those skilled in the art.
Claims
23CLAIMS1. An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain a machine learning model; andexecute a security algorithm on the machine learning model to detect a vulnerability with the machine learning model, the security algorithm, during execution, configured to:apply test data to the machine learning model;generate test performance results based on the applying of the test data to the machine learning model;compare the test performance results to expected performance results to determine a deviation value; andcompare the deviation value to a deviation threshold value to detect the presence of a vulnerability with the machine learning model.
2. The apparatus of claim 1, wherein the apparatus is further caused to:decide to one of keep and discard the machine learning model based on the comparison of the deviation value to the deviation threshold value.
3. The apparatus of claim 2, wherein the machine learning model is kept in response to the deviation value not being greater than the deviation threshold value.
4. The apparatus of claim 2, wherein the machine learning model is discarded in response to the deviation value being greater than the deviation threshold value.
5. The apparatus of claim 1, wherein the test performance results include a test classification error matrix and the expected performance results include a base classification error matrix.
6. The apparatus of claim 5, wherein the deviation value is defined as:where Mois the base classification error matrix, Mtis the test classification error matrix, where |||| is a Frobenius norm of a matrix and tr() is a trace of a matrix.
7. The apparatus of claim 1, wherein the apparatus is part of a user equipment participating in a training process for the machine learning model.
8. A method comprising:obtaining a machine learning model; andexecuting a security algorithm on the machine learning model to detect a vulnerability with the machine learning model, the security algorithm, during execution, configured to:apply test data to the machine learning model;generate test performance results based on the applying of the test data to the machine learning model;compare the test performance results to expected performance results to determine a deviation value; andcompare the deviation value to a deviation threshold value to detect the presence of a vulnerability with the machine learning model;wherein the obtaining and executing are performed by at least one processor and at least one memory coupled thereto.
9. The method of claim 8, wherein the security algorithm, during execution, is further configured to:decide to one of keep and discard the machine learning model based on the comparison of the deviation value to the deviation threshold value.
10. The method of claim 9, wherein the machine learning model is kept in response to the deviation value not being greater than the deviation threshold value.
11. The method of claim 9, wherein the machine learning model is discarded in response to the deviation value being greater than the deviation threshold value.
12. The method of claim 8, wherein the test performance results include a test classification error matrix and the expected performance results include a base classification error matrix.
13. The method of claim 12, wherein the deviation value is defined as:where Mois the base classification error matrix, Mtis the test classification error matrix, where |||| is a Frobenius norm of a matrix and tr() is a trace of a matrix.
14. The method of claim 8, wherein the obtaining and executing is performed by a user equipment participating in a training process for the machine learning model.
15. The method of claim 8, wherein the obtaining and executing is performed by a radio access network node participating in a training process for the machine learning model.
16. An apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:obtain a pre-trained machine learning model;add random noise to a training data set; andre-train the pre-trained machine learning model with the random noise-added training data set.
17. The apparatus of claim 16, wherein the added random noise includes Gaussian noise values.
18. The apparatus of claim 16, wherein the added random noise prevents activation of one or more data traps in the pre-trained machine learning model.
19. The apparatus of claim 1, wherein the apparatus is part of a user equipment participating in a machine learning model training process.
20. A method comprising:obtaining a pre-trained machine learning model;adding random noise to a training data set; andre-training the pre-trained machine learning model with the random noise-added training data set;wherein the obtaining, adding, and re-training are performed by at least one processor and at least one memory coupled thereto.
21. The method of claim 20, wherein the added random noise includes Gaussian noise values to prevent activation of one or more data traps in the pre-trained machine learning model.