ML Model Behavior Monitoring for Adversarial Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in securely sharing and detecting abnormal behavior of machine learning models between different vendors, as reverse engineering and adversarial attacks can expose proprietary information and compromise model integrity.

Innovation Solution

A system is implemented to monitor machine learning model behavior by comparing it against expected behavior information, detecting anomalies and adversarial attacks, and involving a trusted apparatus for confirmation, ensuring secure model execution and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If machine learning models are shared between different vendors to improve network data analytics capability, then network performance and efficiency are improved, but model integrity and security are compromised due to reverse engineering and adversarial attacks

Engineering Contradiction:
Improvenetwork performanceVSAvoidmodel integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing expected behavior information for ML models before deployment. This includes defining normal resource usage patterns, output ranges, and operational parameters that serve as a baseline for detecting adversarial attacks and model corruption, enabling early intervention before integrity is compromised

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A trusted apparatus acts as an intermediary between ML model producers and consumers. This mediator validates model behavior by comparing actual performance against expected behavior information, detecting adversarial attacks, and ensuring model integrity is maintained during sharing and deployment across different vendor environments

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If machine learning models are shared between different vendors to improve network data analytics capability, then network performance and efficiency are improved, but proprietary information is exposed through reverse engineering

Engineering Contradiction:
Improvenetwork performanceVSAvoidproprietary information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by establishing expected behavior information for ML models before deployment. This includes defining normal resource usage patterns, output ranges, and operational parameters that serve as a baseline for detecting adversarial attacks and model corruption, enabling early intervention before integrity is compromised

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A trusted apparatus acts as an intermediary between ML model producers and consumers. This mediator validates model behavior by comparing actual performance against expected behavior information, detecting adversarial attacks, and ensuring model integrity is maintained during sharing and deployment across different vendor environments

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If machine learning models are monitored for abnormal behavior to detect adversarial attacks, then model security is improved, but system complexity increases due to behavior monitoring and comparison mechanisms

Engineering Contradiction:
Improvemodel securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing expected behavior information for ML models before deployment. This includes defining normal resource usage patterns, output ranges, and operational parameters that serve as a baseline for detecting adversarial attacks and model corruption, enabling early intervention before integrity is compromised

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A trusted apparatus acts as an intermediary between ML model producers and consumers. This mediator validates model behavior by comparing actual performance against expected behavior information, detecting adversarial attacks, and ensuring model integrity is maintained during sharing and deployment across different vendor environments

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4319048B1Abnormal model behavior detection
Publication Date: 2026.03.18 NOKIA TECHNOLOGIES OY
  • EP4319048B1 patent drawingFigure 1
  • EP4319048B1 patent drawingFigure 2
  • EP4319048B1 patent drawingFigure 3

AI summary

Example embodiments of the present disclosure relate to abnormal model behavior detection. A first apparatus obtains a machine learning model and expected behavior information of the machine learning model. The first apparatus monitors behavior information of the machine learning model during execution of the machine learning model; and determines occurrence of an abnormal behavior of the machine learning model during the execution by comparing the monitored behavior information with the expected behavior information.