IP Library › Granted Patent US 12,580,823
Granted Patent B2
US 12,580,823 · App. 15/995,376 · Granted Mar 17, 2026

On-premise machine learning model selection in a network assurance service

Inventors: Andrea Di Pietro (Lausanne, CH); Jean-Philippe Vasseur (Saint Martin d'uriage, FR); Erwan Barry Tarik Zerhouni (Zürich, CH); Grégory Mermoud (Veyras, CH)
Assignee: Cisco Technology, Inc.
H04L41/16G06F18/2178G06F18/40G06N20/00H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,823
App. No.
15/995,376
Granted
Mar 17, 2026
Kind
B2
Abstract

In one embodiment, a network assurance service uses a first machine-learning based model that is locally deployed to a network to assess a set of input features comprising measurements from the network. The service monitors, locally in the network, performance of the first machine learning-based model. The service determines that the monitored performance of the first machine learning-based model does not meet one or more performance requirements associated with the network. The service selects a second machine learning-based model for deployment to the network, based on the one or more performance requirements associated with the network and on the set of input features of the first machine learning-based model. The service deploys the selected second machine learning-based model to the network as a replacement for the first machine learning-based model.

Claims (53)

1 . A method comprising:

using, by a network assurance service, a first machine learning-based model that is locally deployed to a network to assess a set of input features comprising measurements indicative of behavior of the network;

monitoring, by the service and locally in the network, performance of the first machine learning-based model according to its resource consumption;

determining, by the service, that the monitored performance of the first machine learning-based model does not meet one or more performance requirements associated with the network based on an assessment that the resource consumption of the first machine learning-based model exceeds a maximum allowed resource consumption;

disabling, by the service, one or more optional input features of the first machine learning-based model, based on the determination that the monitored performance of the first machine learning-based model does not meet the one or more performance requirements associated with the network, wherein the one or more optional input features are selected based on a feature classification stored for the first machine learning-based model that associates each input feature with an estimated resource consumption value;

selecting, by the service and only after determining that the monitored performance of the first machine learning-based model still does not meet set-meet the one or more performance requirements associated with the network after disabling the one or more optional input features according to the feature classification until either the one or more performance requirements are satisfied or no additional optional input features remain, a second machine learning-based model from among a set of machine learning-based models for deployment to the network; and

deploying, by the service, the selected second machine learning-based model to the network as a replacement for the first machine learning-based model.

2 . The method as in claim 1 , wherein the second machine learning-based model is trained based on measurements from one or more other networks different than the network where the first machine learning-based model is locally deployed.

3 . The method as in claim 1 , wherein monitoring the performance of the first machine learning-based model comprises:

receiving relevancy feedback from a user interface regarding alerts raised by the first machine learning-based model and sent to the user interface; and

using the feedback to compute a precision or recall for the first machine learning-based model.

4 . The method as in claim 1 , wherein the second machine learning-based model is selected based on a determination by the service that the second machine learning-based model consumes fewer resources than the first machine learning-based model.

5 . The method as in claim 1 , further comprising:

deploying, by the service, the first machine learning-based model to the network, to test whether the performance of the first machine learning-based model satisfies the performance requirements associated with the network.

6 . The method as in claim 5 , further comprising:

selecting, by the service, the first machine learning-based model for deployment to the network from among the set of machine learning-based models, based on the first machine learning-based model requiring the most resources for execution from among the set of machine learning-based models.

7 . The method as in claim 1 , wherein monitoring the performance of the first machine learning-based model comprises:

receiving feedback regarding outputs of the first machine learning-based model from a network security system; and

using the feedback to determine the performance of the first machine learning-based model.

8 . The method as in claim 1 , wherein the second machine learning-based model is selected by a cloud-based selection engine, the method further comprising:

sending an indication of the monitored performance of the first machine learning-based model to the cloud-based selection engine.

9 . An apparatus, comprising:

one or more network interfaces;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

use a first machine learning-based model that is locally deployed to a network to assess a set of input features comprising measurements indicative of behavior of the network;

monitor, locally in the network, performance of the first machine learning-based model according to its resource consumption;

determine that the monitored performance of the first machine learning-based model does not meet one or more performance requirements associated with the network based on an assessment that the resource consumption of the first machine learning-based model exceeds a maximum allowed resource consumption;

disable one or more optional input features of the first machine learning-based model, based on the determination that the monitored performance of the first machine learning-based model does not meet the one or more performance requirements associated with the network, wherein the one or more optional input features are selected based on a feature classification stored for the first machine learning-based model that associates each input feature with an estimated resource consumption value;

select, only after determining that the monitored performance of the first machine learning-based model still does not meet set-meet the one or more performance requirements associated with the network after disabling the one or more optional input features according to the feature classification until either the one or more performance requirements are satisfied or no additional optional input features remain, a second machine learning-based model from among a set of machine learning-based models for deployment to the network; and

deploy the selected second machine learning-based model to the network as a replacement for the first machine learning-based model.

10 . The apparatus as in claim 9 , wherein the second machine learning-based model is trained based on measurements from one or more other networks different than the network where the first machine learning-based model is locally deployed.

11 . The apparatus as in claim 9 , wherein the apparatus monitors the performance of the first machine learning-based model by:

receiving relevancy feedback from a user interface regarding alerts raised by the first machine learning-based model and sent to the user interface; and

using the feedback to compute a precision or recall for the first machine learning-based model.

12 . The apparatus as in claim 9 , wherein the second machine learning-based model is selected based on a determination by the apparatus that the second machine learning-based model consumes fewer resources than the first machine learning-based model.

13 . The apparatus as in claim 9 , wherein the process when executed is further configured to:

deploy the first machine learning-based model to the network, to test whether the performance of the first machine learning-based model satisfies the performance requirements associated with the network.

14 . The apparatus as in claim 13 , wherein the process when executed is further configured to:

select the first machine learning-based model for deployment to the network from among the set of machine learning-based models, based on the first machine learning-based model requiring the most resources for execution from among the set of machine learning-based models.

15 . The apparatus as in claim 9 , wherein the apparatus monitors the performance of the first machine learning-based model by:

receiving feedback regarding outputs of the first machine learning-based model from a network security system; and

using the feedback to determine the performance of the first machine learning-based model.

16 . The apparatus as in claim 9 , wherein the second machine learning-based model is selected by a cloud-based selection engine, and wherein the process when executed is further configured to:

send an indication of the monitored performance of the first machine learning-based model to the cloud-based selection engine.

17 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a network assurance service to execute a process comprising:

using, by the network assurance service, a first machine learning-based model that is locally deployed to a network to assess a set of input features comprising measurements indicative of behavior of the network;

monitoring, by the service and locally in the network, performance of the first machine learning-based model according to its resource consumption;

determining, by the service, that the monitored performance of the first machine learning-based model does not meet one or more performance requirements associated with the network based on an assessment that the resource consumption of the first machine learning-based model exceeds a maximum allowed resource consumption;

disabling, by the service, one or more optional input features of the first machine learning-based model, based on the determination that the monitored performance of the first machine learning-based model does not meet the one or more performance requirements associated with the network, wherein the one or more optional input features are selected based on a feature classification stored for the first machine learning-based model that associates each input feature with an estimated resource consumption value;

selecting, by the service and only after determining that the monitored performance of the first machine learning-based model still does not meet the one or more performance requirements associated with the network after disabling the one or more optional input features according to the feature classification until either the one or more performance requirements are satisfied or no additional optional input features remain, a second machine learning-based model from among a set of machine learning-based models for deployment to the network; and

deploying, by the service, the selected second machine learning-based model to the network as a replacement for the first machine learning-based model.

18 . The tangible, non-transitory, computer-readable medium as in claim 17 , wherein the second machine learning-based model is trained based on measurements from one or more other networks different than the network where the first machine learning-based model is locally deployed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2018
From: DI PIETRO, ANDREA; VASSEUR, JEAN-PHILIPPE; ZERHOUNI, ERWAN BARRY TARIK; MERMOUD, GRÉGORY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 046287/0107 →
Continuity (1)
Related Publication 20190370218A1 · Dec 5, 2019
References Cited (14)
US 10949535B2 · Luo · 2021 [cited by examiner]
US 11055628B2 · Kaniwa · 2021 [cited by examiner]
US 11108575B2 · Kasaragod · 2021 [cited by examiner]
US 11182691B1 · Zhang · 2021 [cited by examiner]
US 20140278807A1 · Bohacek · 2014 [cited by applicant]
US 20160078361A1 · Brueckner · 2016 [cited by examiner]
US 20160110657A1 · Gibiansky · 2016 [cited by examiner]
US 20160218933A1 · Porras · 2016 [cited by examiner]
US 20170286839A1 · Parker · 2017 [cited by examiner]
US 20180060759A1 · Chu · 2018 [cited by examiner]
US 20180189484A1 · Danahy · 2018 [cited by examiner]
US 20190156247A1 · Faulhaber, Jr. · 2019 [cited by examiner]
US 20190220697A1 · Kiemele · 2019 [cited by examiner]
CN 101782976A · 2010 [cited by applicant]