Federated Learning Authorization for Secure AI/ML Model Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization capabilities in the 3GPP SBA framework are insufficiently granular to provide the necessary level of security for federated learning of AI/ML models in 5G networks, particularly for Network Data Analytics Functions (NWDAFs) operating as clients and servers, exposing confidential models to unauthorized parties.
Innovation Solution
Implement methods for registering and authorizing Network Functions (NFs) in a network repository function (NRF) with detailed authorization information, including identifiers and scopes, to ensure only authorized NFs can join federated learning groups, preventing unauthorized access and fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current authorization capabilities in 3GPP SBA framework are used, then network function authorization is provided, but the authorization granularity is insufficient to secure federated learning of AI/ML models
Solution Approach 1:
The patent segments the authorization capability into finer-grained components by introducing FL group-specific authorization information that includes FL group identifier, model identifier, and scope parameters. This allows differentiated authorization control for different federated learning groups and models, resolving the contradiction between providing secure authorization and maintaining system simplicity.
Solution Approach 2:
The patent adds new dimensions to the authorization framework by introducing FL group identifier and model identifier as additional authorization parameters. This dimensional expansion enables granular control over which network functions can access which models in which federated learning groups, thereby enhancing security without overwhelming complexity.
2Object-affected harmful factors
If detailed authorization information is registered in NRF, then unauthorized access to models is prevented, but the complexity of authorization management increases
Solution Approach 1:
The patent uses the Network Repository Function (NRF) as an intermediary to centralize and manage authorization information. By registering FL group authorization information in the NRF, the system simplifies authorization management while preventing unauthorized access, as the NRF acts as a single point of truth for authorization decisions.
Solution Approach 2:
The patent implements preliminary authorization registration where authorization information is registered before federated learning operations commence. This preliminary action ensures that unauthorized access is prevented from the outset, while the structured registration process in NRF manages complexity by establishing clear authorization boundaries in advance.
3Reliability
If NFs are authorized to join FL groups, then secure model sharing is enabled, but the complexity of joining and managing FL groups increases
Solution Approach 1:
The patent makes the authorization mechanism universal by using the same NRF registration process for all FL group authorization scenarios. This multi-functional approach handles different FL group configurations and network function roles through a unified authorization framework, simplifying operations while maintaining security.
Solution Approach 2:
The patent implements feedback mechanisms where the NRF provides authorization status information to network functions, enabling them to make informed decisions about joining FL groups. This feedback loop simplifies the joining process by providing clear authorization guidance, while maintaining secure model sharing through verified authorization.
Data Source
AI summary
Methods for a first network function (NF) configured to operate as a server of a federated learning (FL) group in a communication network. Such methods include registering, in a network repository function (NRF) of the communication network, information associated with the FL group. The FL group includes the first NF and one or more further NFs configured to operations as clients in the FL group. The registered information includes authorization information for additional NFs to join the FL group as clients. Such methods include receiving an indication of a second NF, of the communication network, that is a candidate client for the FL group and obtaining an indication that the second NF is authorized to join the FL group as a client. The indication is based on the registered authorization information. Such methods include, based on the indication, updating the FL group to include the second NF as a client.


