Protected fine-tuning of machine learning models

By fine-tuning the machine learning model by receiving input from visible and invisible channels in a protected environment, the problem that the tuner initiator system cannot directly access the basic model is solved, achieving efficient model fine-tuning and protection of proprietary information.

CN116997912BActive Publication Date: 2026-01-02MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180094869.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-30
Publication Date
2026-01-02
Estimated Expiration
2041-12-30

AI Technical Summary

Technical Problem

During the fine-tuning of a machine learning model, the tuning initiator system may not be the owner of the base model, and the base model provider may be unwilling to share its proprietary information, making it impossible for the tuning initiator system to directly access and use the base model for fine-tuning.

Method used

By fine-tuning in a protected environment, the tuner initiator system receives first inputs such as training data through a visible channel and proprietary inputs through an invisible channel. It uses these inputs to fine-tune the machine learning model, forming a tuned model, which is then stored in the protected environment so that the tuner initiator system can use it but cannot directly access it.

Benefits of technology

This enables the tuner initiator system to efficiently use the basic model for fine-tuning of new tasks, while protecting the proprietary information of the basic model provider from being leaked, thus promoting the rapid dissemination and collaboration of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116997912B_ABST
    Figure CN116997912B_ABST
Patent Text Reader

Abstract

Fine-tuning a machine learning model in a protected environment. Inputs (e.g., training data) received from a tuning initiator system indicating that fine-tuning is occurring are received over a channel visible to the tuning initiator system. Proprietary inputs are received from another party over a secure connection that is not visible to the tuning initiator system. These inputs are then used to fine-tune a machine learning model, resulting in a fine-tuned machine learning model. The resulting fine-tuned machine learning model is then stored in a protected environment such that the fine-tuned machine learning model is available to the tuning initiator system to provide input data thereto and receive output data therefrom, but also such that the tuned model cannot be directly accessed by the tuning initiator system.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] Machine learning is a field of technology that allows for the automatic construction of analytical models. Supervised machine learning is a subcategory of machine learning.

[0002] In supervised machine learning, a labeled dataset is used to train a model so that it can classify data or accurately predict outcomes based on data. A label is the actual correct answer for a given associated input data. For example, assume the input data is a picture of a cat and the model is being trained to classify animal pictures based on the animal depicted. The label specifies "cat" in effect.

[0003] The labels of the dataset are used to determine whether the model made the correct classification or prediction. Depending on whether the model made a classification or prediction that matches the correct answer specified in the label, the training algorithm adjusts the model. The adjustments are made against new training data until the model is fit to make accurate classifications or predictions. There are a variety of training algorithms that can be used to properly train a model. Subsequently, at inference, unlabeled data is input into the model with the goal of providing a classification or prediction based on the new data.

[0004] Once a model is trained, the use of the model can be re-adjusted to perform a new task. Thus, training can start with a previously trained model—allowing training to continue further to fine-tune the model for the new task. This reduces the time and training data required to train a model to perform a new task. "Fine-tuning" a base model is the process of formulating a fine-tuned model based on the base model. Fine-tuning involves taking a base model that has already been trained, applying the base model to new training data, and making further adjustments to the model based on the new training data.

[0005] The subject matter claimed herein is not limited to implementations that solve any disadvantages or that operate only in environments such as those described above. Rather, this background is provided merely to illustrate one example technology area where some embodiments described herein can be practiced. SUMMARY

[0006] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Specific Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter.

[0007] Fine-tuning a previously trained model to perform a new task is much more efficient than training a new model from scratch. This is because, if the new task is comparable to the task for which the model was originally trained, the model will already have most of the parameter values already ready. The parameter values only need to be fine-tuned to perform the new task. Here, the model that exists before it is fine-tuned will be referred to as a “base model.” The model that exists after it is fine-tuned will be referred to as a “tuned model.” The computing system that initiates (i.e., requests) the fine-tuning will be referred to as the “tuning initiator computing system” or “tuning initiator system.”

[0008] In order to be able to form a tuned model by fine-tuning a base model, the tuning initiator system should generally have access to both the base model and a fine-tuning algorithm. The tuning initiator system will then provide the base model with new (adapted to the new task) training data, thereby causing the base model to be tuned according to the tuning algorithm.

[0009] However, the user(s) of the tuning initiator system can not be the owner of the base model, and the base model provider can not be willing to share their base model. For example, the base model provider can consider aspects of the base model to be proprietary. Alternatively or additionally, the tuning initiator system can not own the tuning algorithm. The principles described herein allow the tuning initiator system to formulate and use a tuned model while providing security to any entity that provides a base model and / or a tuning algorithm. In other words, the entities can allow the tuning initiator system to use their proprietary information (such as a base model and / or a tuning algorithm) to formulate a tuned model without disclosing their proprietary information to the tuning initiator system.

[0010] According to the principles described herein, fine-tuning of a machine learning model in a protected environment is described. The fine-tuning includes receiving, from a tuning initiator system, some inputs into the protected environment (the “first inputs”) via a first channel that is visible to the tuning initiator system. Such information includes at least training data for the fine-tuning process. The fine-tuning also includes accessing other inputs (the “second inputs”) through a second channel that is not visible to the tuning initiator system. Such second inputs will include proprietary information of a party that allows the tuning initiator system to use (but not see) the proprietary information when performing the fine-tuning.

[0011] The first and second inputs are then used to fine-tune the machine learning model, thereby forming a fine-tuned machine learning model. The resulting fine-tuned machine learning model is then stored in the protected environment such that the fine-tuned machine learning model is available to the tuning initiator system to provide input data to and receive output data from, but also such that the fine-tuned machine learning model cannot be directly accessed by the tuning initiator system.

[0012] Additional features and advantages will be set forth in the description that follows, and in part will be obvious from the description, or can be learned by the practice of the teachings herein. Features and advantages of the application can be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. Features of the present application will become more fully apparent from the following description and appended claims, or can be learned by the practice of the application as set forth hereinafter. BRIEF DESCRIPTION OF DRAWINGS

[0014] To describe the manner in which the above-recited and other advantages and features can be obtained, a brief description of the subject matter can be rendered by reference to specific embodiments thereof which are illustrated in the appended drawings. Understanding that these drawings depict only typical embodiments and are not therefore to be considered to be limiting of the scope of the application, the embodiments will be described and explained with additional specificity and detail through the use of the accompanying drawings in which:

[0015] Figure 1 A network environment in which the principles described herein can be employed is illustrated, including a tuning initiator system and a provider system, each providing some input for a model tuning process, and further including a protected system in which the tuning actually occurs;

[0016] Figure 2 A flowchart of a method for tuning a machine learning model in a protected environment according to the principles described herein is illustrated;

[0017] Figure 3A An example of a first input received from a tuning initiator system is illustrated;

[0018] Figure 3B An example of a second input received from a provider system is illustrated;

[0019] Figure 4 A flowchart of a method of a tuning initiator system (or any other authorized system) using a tuned model to access inferences generated by the tuned model is illustrated;

[0020] Figure 5 An environment representing an example of Figure 1 An environment representing an example of

[0021] Figure 6 An example lock computation representing an example of Figure 5 An example lock computation representing an example of

[0022] Figure 7 An example computing system in which the principles described herein can be employed is illustrated.

[0023] DETAILED DESCRIPTION

[0024] Fine-tuning a previously trained model to perform a new task is much more efficient than training a new model from scratch. This is because, if the new task is comparable to the task for which the model was originally trained, the model will already have most of the parameter values already ready. The parameter values only need to be fine-tuned to perform the new task. Here, the model that exists before it is fine-tuned will be referred to as a "base model." The model that exists after fine-tuning will be referred to as a "tuned model." The computing system that initiates (i.e., requests) the fine-tuning will be referred to as the "tuning initiator computing system" or "tuning initiator system."

[0025] To be able to form a tuned model by fine-tuning a base model, the tuning initiator system should typically have access to both the base model and a fine-tuning algorithm. The tuning initiator system will then provide the base model with new (adapted to the new task) training data, thereby causing the base model to be tuned according to the tuning algorithm.

[0026] However, the user(s) of the tuning initiator system can not be the owner of the base model, and the base model provider can not be willing to share their base model. For example, the base model provider can consider aspects of the base model to be proprietary. Alternatively or additionally, the tuning initiator system can not own the tuning algorithm. The principles described herein allow the tuning initiator system to formulate and use a tuned model while providing security to any entity that provides a base model and / or a tuning algorithm. In other words, the entities can allow the tuning initiator system to use their proprietary information (such as a base model and / or a tuning algorithm) to formulate a tuned model without disclosing their proprietary information to the tuning initiator system.

[0027] According to the principles described herein, fine-tuning of a machine learning model in a protected environment is described. The fine-tuning includes receiving, from a tuning initiator system, some inputs into the protected environment (the "first inputs") via a first channel that is visible to the tuning initiator system. Such information includes at least training data for the fine-tuning process. The fine-tuning also includes accessing other inputs (the "second inputs") through a second channel that is not visible to the tuning initiator system. Such second inputs will include proprietary information of a party that allows the tuning initiator system to use (but not see) the proprietary information when performing the fine-tuning.

[0028] The first and second inputs are then used to fine-tune the machine learning model, thereby forming a fine-tuned machine learning model. The resulting fine-tuned machine learning model is then stored in the protected environment such that the fine-tuned machine learning model is available to the tuning initiator system to provide input data to and receive output data from, but also such that the fine-tuned machine learning model cannot be directly accessed by the tuning initiator system.

[0029] Figure 1A network environment 100 in which the principles described herein can be employed is illustrated. The network environment 100 includes a protected system 101, a tuning initiator computing system 110, and a provider computing system 120, each of which can be constructed as described below for Figure 7 The protected system can also be referred to herein as a “protected environment.”

[0030] The protected system 101 is the computing system in which fine-tuning actually occurs. The tuning initiator system 110 initiates the fine-tuning process and provides (as shown by arrow 112) training data and potentially other data (“first data”) to facilitate the fine-tuning process. This first input is provided over a first channel 111 that is visible to the tuning initiator computing system 110. The provider computing system 120 provides (as shown by arrow 122) proprietary input (“second input”) that facilitates the fine-tuning process. This second input is provided over a second channel that is not visible to the tuning initiator computing system 110. The dashed boundary 130 symbolically represents the environment in which fine-tuning occurs that is not observable by the tuning initiator computing system 110.

[0031] Figure 2 A flowchart of a method 200 for fine-tuning a machine learning model in a protected environment according to the principles described herein is illustrated. Fine-tuning occurs such that the tuning initiator system indicating that fine-tuning is occurring does not have visibility to proprietary input provided by another party and does not have visibility to the resulting tuned model. Since the method 200 can be performed by the protected system 101 of Figure 1 The environment 100 of Figure 1 The method 200 of Figure 2 will now be described frequently with reference to the environment 100 of

[0032] The method 200 includes receiving a first input including training data into the protected environment from a tuning initiator system via a first channel visible to the tuning initiator system, the first input including the training data (act 201). Referring to Figure 1 The protected system 101 receives (as shown by arrow 112) the first input from the tuning initiator system 110 over the first channel 111 visible to the tuning initiator system 110. In this specification and claims, a channel is “visible” to a tuning initiator system if the tuning initiator system can see the data being communicated over the channel.

[0033] The method 200 also includes accessing a second input over a second channel that is not visible to the tuning initiator system (act 202). Referring to Figure 1The protected system 101 receives (as shown by arrow 122) second input from the provider system 110 through a second channel 121 that is not visible to the tuning initiator system 110. In this specification and claims, a channel is "not visible" to a tuning initiator system if the tuning initiator system is unable to see the data being transmitted through the channel.

[0034] Figure 3A An example of first input 300A received from the tuning initiator system is illustrated. The first input 300A includes training data 301 and potentially other data 302. Figure 3B An example of second input 300B received from the provider system is illustrated. The second input 300B includes proprietary data 311.

[0035] In one example, the proprietary data 311 received from the provider system is a base model. The base model provider can indeed consider many aspects of the base model to be proprietary, including the architecture, biases, weights, and so on. The base model can be the result of a great deal of work, time, and investment. Thus, the base model provider can hesitate to allow use of its base model to generate a fine-tuned model if the tuning initiator system can have direct access to that base model. The principles described herein can allow for more open use of the base model for fine-tuning purposes while protecting the proprietary data of the provider system 120.

[0036] In another example, the proprietary data received from the provider system is fine-tuning computer executable instructions (e.g., a fine-tuning program). The provider system can also provide such a fine-tuning program, which can also be considered proprietary. Alternatively, the protected system 101 has its own fine-tuning program for performing fine-tuning. In addition, alternatively, the tuning initiator system 110 can have already provided a base model and only wishes to use a fine-tuning model or other proprietary information provided by the provider system 120.

[0037] Thus, the proprietary information 311 of the second input 300B received from the provider system can include, for example, a base model and / or a fine-tuning program. In addition, other data 302 provided by the tuning initiator system, if any, can include a base model and / or a fine-tuning program.

[0038] Referring back to Figure 2After accessing the first input and the second input, the protected system uses the first input and the second input to fine-tune the machine learning model, thereby forming a tuned machine learning model (act 303). This can include applying a fine-tuning procedure (whether provided by the tuning initiator system 110, the provider system 120, or the protected system 101 itself) to the base model and the training data. For example, the fine-tuning procedure can be fine-tuning computer-executable instructions that are executable by one or more processors of the protected system to cause the protected system to perform the fine-tuning.

[0039] The protected system then stores the resulting tuned model in the protected system (act 304). Because of the protection represented by the box 130, this storage inside the protected system means that while the tuning initiator system can provide input to the tuned machine learning model (e.g., over the channel 111) and can receive output from the tuned machine learning model (e.g., also over the channel 111), the tuning initiator system does not have visibility into the tuned model itself. Thus, the tuning initiator system cannot infer what the original base model was based on the appearance of the tuned model. Figure 1

[0040] Thus, the tuned model remains within the protected scope of the protected system 101. Figure 4 A flowchart of a method 400 is illustrated that uses a fine-tuned model to access inferences generated by the fine-tuned model by a tuning initiator system (or any other authorized system). The protected system receives an instruction from the tuning initiator system (or other authorized system) to perform an inference by applying the tuned machine learning model to new data (act 401). In response to receiving this instruction, the protected system applies the tuned model to the new data (act 402). The inference generated by the tuned model is then provided to the tuning initiator system (or other authorized system) (act 403).

[0041] Figure 5 An environment 500 is illustrated that represents an example of the environment 100 of Figure 1 The environment 500 includes a customer subscription 510, a service subscription 520, and a fine-tuning subscription 501, which represent respective examples of the tuning initiator system 110, the provider system 120, and the protected system 101 of Figure 1

[0042] ​​The service subscription 520 includes a service component registry 521, centralized storage 522, and image storage 523. The service component registry 521 is a catalog in which component metadata for published components is registered. Each workspace also has its own registry that the service component registry 521 uses. The centralized storage 522 stores published components. Component folders containing data files will be saved in the service-level storage account. Reference images will be saved in the image storage 523.

[0043] The fine-tuning subscription 501 includes service-managed lock storage 502 that holds proprietary data that should not be visible to the customer subscription 510. The customer subscription 510 cannot directly access the service-managed lock storage 502. For example, the storage can be a storage node in a cloud computing environment. The service-managed lock storage 502 is only accessed by service-managed lock computation 503 in normal operation. The computer 503 can be a compute node in a cloud computing environment. The service-managed lock computation actually performs the fine-tuning operation to generate the tuned model.

[0044] The data structures can be imported from the service component registry 521 to the workspace component registry 511. As an example, a base model fine-tuning can be published as a service component (like a reusable job) that contains: 1) components such as scripts and configuration files (stored in component storage 522); 2) model artifacts for the base model (also stored in component storage 522); and 3) a linked environment artifact for the container image (stored in image storage 523). All of these artifacts are protected. During import, the component metadata is copied from the service component registry 521 to the workspace component registry 511. In addition, the component folders are copied from the centralized storage 522 to the managed lock storage 502.

[0045] To run the fine-tuning job. The components (including the base model and scripts and binaries for the fine-tuning program) are loaded from the component storage 522 into the service-managed lock computation 503 (either directly or first via the service-managed lock storage 502). The customer subscription 510 provides the training data into the customer storage and then also to the managed lock computation 503. The customer uses the managed computation handler 514 along with the component metadata 511 to submit the fine-tuning job. The managed inference handler 515 can be a REST API that takes input data in the request and returns inference results in the response. The managed storage handler 513 is used as a reference to the tuned model.

[0046] Figure 6 An example lock computation 600 is illustrated that represents Figure 5FIG. 6 illustrates an example of a lockdown computation 503. The lockdown computation 600 is used to protect data structures that the customer should not see. When the customer components are executed, the protected data structures will not leak outside of the lockdown computation 600. In addition, when the imported components are executed, no user data is leaked onto the internet.

[0047] The lockdown computation has a service management virtual network 601 that blocks any inbound or outbound connections except for the lockdown storage 502, the customer storage 512, and the services managed within the service subscription 520. The component containers (e.g., 611A and 611B) run within an overlay network 610. The components 611A and 611B can communicate with each other, but cannot make any inbound or outbound connections. Each component container has a service management sidecar container 612 that shares a volume (e.g., volume 613) with the sidecar container for input / output datasets. The sidecar container 612 will use appropriate credentials to connect to the lockdown storage 502 and the customer storage 512. The input datasets can come from the lockdown storage 502 or the customer storage 512. The output datasets (including models) can only be put into the lockdown storage 502. Logs and metrics from the imported components will be sent to the customer workspace 510. Logs / metrics from the customer components will be blocked.

[0048] Accordingly, the principles described herein provide an efficient way for a tuning initiator system to fine-tune a base model, while providing appropriate protection for parties that assist by providing proprietary data (e.g., base models and fine-tuning procedures). Thus, the principles described herein encourage cooperation in forming new models, and allow for rapid dissemination of new models designed for new tasks.

[0049] Since the principles described herein are performed in the context of a computing system, reference will be made to Figure 7 Some introductory discussion of computing systems is provided. Computing systems are now increasingly taking a wide variety of forms. Computing systems may, for example, be handheld devices, appliances, laptop computers, desktop computers, mainframes, distributed computing environments, data centers, or even devices that have not conventionally been considered a computing system. In this description and in the claims, the term "computing system" is defined broadly to include any device or system (or combination thereof) that includes at least one physical and tangible processor, and a physical and tangible memory capable of having

[0050] As Figure 7In the illustrated embodiment, and in its most basic configuration, computing system 700 includes at least one hardware processing unit 702 and memory 704. The processing unit 702 includes a general purpose processor. Although not required, the processing unit 702 also can comprise a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or any other specialized circuit. In one embodiment, the memory 704 includes physical system memory. This physical system memory can be volatile, non-volatile, or some combination of the two. In a second embodiment, the memory is non-volatile mass storage such as a physical storage medium. If the computing system is distributed, the processing, memory, and / or storage capability can be distributed as well.

[0051] The computing system 700 also has associated storage and / or storage capacity. In one embodiment, the storage is a physical storage medium. In a second embodiment, the storage is a non-volatile mass storage such as a physical storage medium. In a third embodiment, the storage is a combination of volatile and non-volatile mass storage. If the computing system is distributed, the storage capability can be distributed as well.

[0052] One of ordinary skill in the art will recognize that the structure of the executable component exists on a computer-readable medium, such that, when interpreted by one or more processors of a computing system (e.g., by a processor thread), causes the computing system to perform some function. Such structure can be directly computer-readable by the processor (as is the case when the executable component is binary). Alternatively, the structure can be structured to be interpretable and / or compiled (whether in a single stage or in multiple stages) in order to generate such binary files that are directly interpretable by the processor. This understanding of example structures of an executable component is well within the understanding of one of ordinary skill in the computing arts when using the term "executable component."

[0053] The term "executable component" is also well understood by those of ordinary skill in the computing arts to include structures implemented in hardware, such as hardwired logic gates, for example, in a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), or any other special-purpose circuit, that are dedicated to the function(s) of the structure. Thus, the term "executable component" is a term of art to those of ordinary skill in the computing arts that is well understood to include structures of a nature that are well understood by those of ordinary skill in the computing arts, whether implemented in software, hardware, or a combination. In this specification, the terms "component," "agent," "manager," "service," "engine," "module," "virtual machine," and the like can also be used. As used in this specification and in this case, these terms, whether expressed to be modified by an adjective, are also intended to be synonymous to the term "executable component," and thus also of a nature that is well understood by those of ordinary skill in the computing arts.

[0054] In the description that follows, embodiments are described with reference to acts that are performed by one or more computing systems. If such acts are implemented in software, one or more processors of an associated computing system that performs the act direct the operation of the computing system in response to having executed computer- executable instructions that constitute an executable component. For example, such computer- executable instructions can be implemented on one or more computer-readable media that form part of the computer program product. Examples of such an operation involve the manipulation of data. When the acts of are implemented at least partially in hardware, for example, as with an FPGA, or an ASIC, computer-executable instructions stored on one or more computer-readable media can direct the operation of the computer system to generate the hardware logic structures that implement the acts that are hard-coded or hard-wired into the logic structures.

[0055] While not all computing devices require a user interface, in some embodiments, the computing system 700 includes a user interface system 712 for interfacing with a user. The user interface system 712 can include output mechanisms 712A as well as input mechanisms 712B. The principles described herein are not limited to precise output mechanisms 712A or input mechanisms 712B as these will depend on the nature of the device. However, output mechanisms 712A can include, for example, speakers, displays, tactile outputs, virtual or augmented reality, holograms, and the like. Examples of input mechanisms 712B can include, for example, microphones, touchscreens, virtual or augmented reality, holograms, cameras, keyboards, mouse or other pointer input, any type of sensor, and the like.

[0056] Embodiments described herein can include or utilize special or general purpose computing systems including, for example, one or more processors and system memory, as discussed in greater detail below. Embodiments described herein also include physical and other computer-readable media for carrying or storing computer-executable instructions and / or data structures. Such computer-readable media can be any available media that can be accessed by a general purpose or special purpose computing system. Computer-readable media that store computer-executable instructions are physical storage media. Computer-readable media that carry computer-executable instructions are transmission media. Thus, by way of example, and not limitation, embodiments of the application can comprise at least two distinctly different kinds of computer-readable media: storage media and transmission media.

[0057] Computer-readable storage media includes RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other physical and tangible storage medium which can be used to store desired program code means in the form of computer-executable instructions or data structures and which can be accessed by a general purpose or special purpose computing system.

[0058] A "network" is defined as one or more data links that enable the transport of electronic data between computing systems and / or modules and / or other electronic devices. When information is transferred or provided over a network or another communications connection (either hardwired, wireless, or a combination of hardwired or wireless) to a computing system, the computing system properly views the connection as a transmission medium. Transmission media can include a network and / or data links which can be used to carry desired program code means in the form of computer-executable instructions or data structures and which can be accessed by a general purpose or special purpose computing system. Combinations of the above should also be included within the scope of computer-readable media.

[0059] Further, upon reaching various computing system components, program code means in the form of computer-executable instructions or data structures can be transferred automatically from transmission media to storage media (or vice versa). For example, computer-executable instructions or data structures received over a network or data link can be buffered in RAM within a network interface module (e.g., a "NIC"), and then eventually transferred to computing system RAM and / or to less volatile storage media at a computing system. Thus, it should be understood that storage media can be included in computing system components that also (or even primarily) utilize transmission media.

[0060] Computer-executable instructions include, for example, instructions and data which, when executed at a processor, cause a general purpose computing system, special purpose computing system, or special purpose processing device to perform a certain function or group of functions. Alternatively or additionally, computer-executable instructions can configure a computing system to perform a certain function or group of functions. The computer-executable instructions can be, for example, binary or even instructions that are subject to some translation (such as compilation) before being directly executed by a processor, such as intermediate format instructions such as assembly language, or even source code.

[0061] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the described features or acts described above. Rather, the described features and acts are disclosed as example forms of implementing the claims.

[0062] Those skilled in the art will appreciate that the application can be practiced in network computing environments with many types of computing system configurations, including, personal computers, desktop computers, laptop computers, message processors, hand-held devices, multi-processor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframe computers, mobile telephones, PDAs, pagers, routers, switches, datacenters, wearable devices (such as glasses), and the like. The application can also be practiced in distributed system environments where local and remote computing system, which are linked (either by hardwired data links, wireless data links, or by a combination of hardwired and wireless data links) through a network, both perform tasks for the

[0063] Those skilled in the art will further appreciate that the application can be practiced in a cloud computing environment. Cloud computing environments can be distributed, but this is not always the case. When distributed, cloud computing environments can be distributed internationally within an organization and / or have components possessed across multiple organizations. In this description and the following claims, "cloud computing" is defined as a model for enabling on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services). The definition of "cloud computing" is not limited to any other multi-tenant model of service delivery or tailored system vulnerability that has been delivered to consumers in a many customers environment and offered through that cloud model.

[0064] For the processes and methods disclosed herein, the operations performed in the processes and methods can be implemented in differing order. Furthermore, the outlined operations are only provided as examples, and some of the operations can be optional, combined into fewer steps and operations, supplemented with further operations, or expanded into additional operations without detracting from the essence of the disclosed embodiments.

[0065] The application can take other specific forms without departing from its spirit or characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the application is, therefore, indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and range of equivalency of the claims are to be embraced within the scope of the claims.

Claims

1. A computing system for fine-tuning machine learning models in a protected environment, comprising: One or more processors; as well as One or more computer-readable media having computer-executable instructions thereon, the computer-executable instructions being configured such that, if executed by the one or more processors, the computing system will be configured to fine-tune a machine learning model in a protected environment, such that, by being configured to do the following, the tuning initiator system instructing the fine-tuning to have no visibility into the resulting fine-tuned model or at least some information used in the fine-tuning: A first input, including training data, is received from the tuner initiator system into the protected environment via a first channel visible to the tuner initiator system. Access the second input via a second channel that is invisible to the tuner initiator system; The machine learning model is fine-tuned using the first input and the second input to form a fine-tuned machine learning model. as well as The fine-tuned machine learning model is stored in the protected environment such that it is available to the tuner initiator system to provide input data and receive output data from it, but also such that it is not directly accessible to the tuner initiator system.

2. The computing system of claim 1, wherein the second input includes a base model that will be fine-tuned in the fine-tuning to generate the fine-tuned model.

3. The computing system of claim 2, wherein the second input includes fine-tuning computer-executable instructions, and the computing system is further configured to perform the following operations: The fine-tuning computer-executable instructions are executed by one or more processors of the computing system to cause the computing system to form the fine-tuned machine learning model using the base model accessed through the second channel and the training data received through the first channel.

4. The computing system of claim 2, wherein the first input includes fine-tuning computer-executable instructions, and the computing system is further configured to perform the following operations: The fine-tuning computer-executable instructions are executed by one or more processors of the computing system to cause the computing system to form the fine-tuned machine learning model using the base model accessed through the second channel and the training data received through the first channel.

5. The computing system of claim 1, wherein the first input includes a base model that will be fine-tuned in the fine-tuning to generate the fine-tuned model.

6. The computing system of claim 1, wherein fine-tuning the machine learning model using the first input and the second input is performed using multiple containers, a first subset of the containers containing code provided by the tuning initiator system, and a second subset of the containers containing code not provided by an external network entity and which prevents the first subset of the containers from accessing the Internet.

7. A computer-implemented method for fine-tuning a machine learning model in a protected environment, such that a tuning initiator system instructing the fine-tuning to occur has no visibility into the resulting fine-tuned model or at least some information used in the fine-tuning, the method comprising: A first input, including training data, is received from the tuner initiator system into the protected environment via a first channel visible to the tuner initiator system. Access the second input via a second channel that is invisible to the tuner initiator system; The machine learning model is fine-tuned using the first input and the second input to form a fine-tuned machine learning model. as well as The fine-tuned machine learning model is stored in the protected environment such that it is available to the tuner initiator system to provide input data and receive output data from it, but also such that it is not directly accessible to the tuner initiator system.

8. The method of claim 7, wherein the second input received via the second channel includes a basic model that will be fine-tuned in the fine-tuning to generate the fine-tuned model.

9. The method of claim 8, wherein the second input received via the second channel includes fine-tuning computer-executable instructions, the method further comprising: The fine-tuning computer-executable instructions are executed by one or more processors of the computing system to cause the computing system to form the fine-tuned machine learning model using the base model accessed through the second channel and the training data received through the first channel.

10. The method of claim 8, wherein the first input received through the first channel includes fine-tuning computer-executable instructions, the method further comprising: The fine-tuning computer-executable instructions are executed by one or more processors of the computing system to cause the computing system to form the fine-tuned machine learning model using the base model accessed through the second channel and the training data received through the first channel.

11. The method of claim 7, wherein the first input received through the first channel includes a basic model that will be fine-tuned in the fine-tuning to generate the fine-tuned model.

12. The method of claim 11, wherein the second input received via the second channel includes fine-tuning computer-executable instructions, the method further comprising: The fine-tuning computer-executable instructions are executed by one or more processors of the computing system to enable the computing system to use the base model accessed through the first channel and the training data received through the first channel.

13. The method of claim 7, wherein fine-tuning the machine learning model using the first input and the second input is performed using multiple containers, a first subset of which contains code provided by an external network entity, and a second subset of which contains code not provided by the external network entity and prevents the first subset of the containers from accessing the Internet.

14. The method of claim 13, wherein a first subset of the containers operates within an overlay network, the overlay network operates within a virtual network, and a plurality of subsets of the containers operate within the virtual network.

15. The method of claim 14, wherein the code in the second subset of the container communicates outside the virtual network using a dedicated endpoint.

Citation Information

Patent Citations

  • Privacy-preserving machine learning

    CN109416721A

  • Packaging and deploying algorithms for flexible machine learning

    US20200311617A1