A model task processing method, device, equipment and medium
By dividing the cloud service provider's model tasks into multiple stages and processing the task stage to be reinforced in a trusted hardware environment, the problem of cloud service providers obtaining user data without authorization is solved, and model task processing with high security and data isolation is achieved.
Patent Information
- Application Number
- CN202411959462.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-12-27
AI Technical Summary
In cloud computing scenarios, cloud service providers of Model as a Service may obtain the runtime data of user container groups without authorization, resulting in low security of model task processing. Existing technologies such as device-level trusted execution environment and password obfuscation technology are not effective.
The target model task is divided into multiple task stages, and according to the reinforcement configuration information, the task stage to be reinforced is scheduled to the virtual machine in the trusted execution environment based on trusted hardware for processing, and the non-reinforced task stage is scheduled to the ordinary virtual machine for processing, using the trusted execution environment to provide hardware-level data isolation.
It improves the security of model task processing, prevents internal attacks on cloud service providers, improves data isolation and security at runtime, and ensures performance.
Smart Images

Figure CN119883512B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a model task processing method, apparatus, device, and medium. Background Art
[0002] In cloud computing scenarios, Model as a Service (MaaS) cloud service providers can provide models as services to users. Users expect their pods for model-related tasks to be isolated in terms of network, compute, and storage to ensure security. Cloud service provider personnel may, without authorization, access runtime data from the Elastic Compute Service Virtual Machine (ECSVM) where the user's pod resides, thereby obtaining data for user inference or fine-tuning, resulting in lower security for the user's model task processing. Related technologies attempt to address this issue through device-level or process-level trusted execution environments or password obfuscation techniques, but the results are ineffective and need improvement. Summary of the Invention
[0003] In order to solve the above technical problems, the present disclosure provides a model task processing method, device, equipment and medium.
[0004] The present disclosure provides a model task processing method, the method comprising:
[0005] Acquire a target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model;
[0006] Determining, according to the reinforcement configuration information, a task stage to be reinforced and a non-reinforced task stage among the multiple task stages;
[0007] Scheduling the task phase to be reinforced to the corresponding first virtual machine for processing, and scheduling the task phase not to be reinforced to the corresponding second virtual machine for processing;
[0008] The first virtual machine is deployed in a trusted execution environment based on trusted hardware.
[0009] The present disclosure also provides a model task processing device, the device comprising:
[0010] An acquisition module, configured to acquire a target model task and reinforcement configuration information, wherein the target model task includes a plurality of task stages for the target model;
[0011] A determination module, configured to determine a task stage to be reinforced and a task stage not to be reinforced among the multiple task stages according to the reinforcement configuration information;
[0012] a processing module, configured to dispatch the task phase to be reinforced to the corresponding first virtual machine for processing, and dispatch the task phase not to be reinforced to the corresponding second virtual machine for processing;
[0013] The first virtual machine is deployed in a trusted execution environment based on trusted hardware.
[0014] An embodiment of the present disclosure also provides an electronic device, which includes: a processor; a memory for storing executable instructions of the processor; the processor is used to read the executable instructions from the memory and execute the instructions to implement the model task processing method provided by the embodiment of the present disclosure.
[0015] An embodiment of the present disclosure further provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to execute the model task processing method provided by the embodiment of the present disclosure.
[0016] Compared with the prior art, the technical solution provided by the embodiment of the present disclosure has the following advantages: the model task processing solution provided by the embodiment of the present disclosure obtains the target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model, determines the task stage to be reinforced and the non-reinforced task stage in the multiple task stages according to the reinforcement configuration information, schedules the task stage to be reinforced to the corresponding first virtual machine for processing, and schedules the non-reinforced task stage to the corresponding second virtual machine for processing, wherein the first virtual machine is deployed in a trusted execution environment based on trusted hardware. With the above technical solution, the cloud service provider can divide the target model task into multiple task stages, and schedule different task stages to different virtual machines for reinforcement according to the reinforcement configuration information. Since the first virtual machine is deployed in a trusted execution environment based on trusted hardware, the model task processed by the first virtual machine can obtain higher security, effectively improve the security of model task processing, prevent internal attacks by relevant personnel of the cloud service provider, and improve the security level of data isolation at runtime while ensuring the impact on performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.
[0018] Figure 1 A flowchart of a model task processing method provided in some embodiments of the present disclosure;
[0019] Figure 2 A flowchart of another model task processing method provided in some embodiments of the present disclosure;
[0020] Figure 3 A schematic diagram of the architecture of a virtual machine deployed based on an executable environment provided in some embodiments of the present disclosure;
[0021] Figure 4 A flowchart of another model task processing method provided in some embodiments of the present disclosure;
[0022] Figure 5 A schematic diagram of the control plane architecture provided for some embodiments of the present disclosure;
[0023] Figure 6 A schematic diagram of the structure of a model task processing device provided in some embodiments of the present disclosure;
[0024] Figure 7 A schematic structural diagram of an electronic device provided in some embodiments of the present disclosure. DETAILED DESCRIPTION
[0025] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0026] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0027] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.
[0028] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0029] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0030] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0031] In cloud computing scenarios, users can run tasks related to large language models by renting Infrastructure as a Service (IaaS) or Platform as a Service (PaaS). When users obtain Model as a Service from cloud service providers, they expect their container groups for model-related tasks to be isolated in terms of network, computing, and storage to ensure security. However, cloud service provider personnel can access service users' container groups without online authorization and steal data. For example, cloud service provider personnel can use IaaS technology to manipulate the operating system or hypervisor to perform runtime memory dumps on the virtual machines containing certain user container groups, and then perform offline analysis to obtain information about the user's reasoning or fine-tuning of the container group, resulting in lower security for the user's model task processing.
[0032] In the related art, one implementation method is to directly place the model task into the device of the trusted execution environment, which is completely dependent on the characteristics of the device. If there is no available device, the workload cannot be placed in it. Another implementation method is to use a process-level trusted execution environment to improve the security of model task processing, which requires the use of an application for porting, is costly, and is not suitable for model task processing. Yet another implementation method is to use cryptographic obfuscation technology to improve the security of model task processing. Specifically, cryptographic methods are used to make it impossible for users of the cloud service provider to identify the data running on the Infrastructure as a Service platform. However, this method requires users to perform some data conversion on the client side, and is not very practical. In summary, the above methods are not effective in improving the security of model task processing and need to be improved.
[0033] In order to solve the above problems, the embodiments of the present disclosure provide a model task processing method, which is introduced below in conjunction with specific embodiments.
[0034] Figure 1 This is a flow chart of a model task processing method provided by some embodiments of the present disclosure. The method can be executed by a model task processing device, wherein the device can be implemented using software and / or hardware and can generally be integrated into an electronic device. Figure 1As shown, the method includes:
[0035] Step 101: Obtain target model tasks and reinforcement configuration information, wherein the target model tasks include multiple task phases for the target model.
[0036] The model task processing method provided by the embodiment of the present disclosure can be applied to a cloud service provider (Cloud Service Provider, CSP). A cloud service provider refers to an entity used to provide cloud services (such as infrastructure as a service or platform as a service) to serve different model suppliers (Vendor). For example, a cloud service provider can undertake the large model of the model supplier and provide reasoning, fine-tuning and other services to the outside world based on the large model. The large model is also called the Large Language Model (LLM). The large model is a processing model based on natural language. Through the large model, it can automatically learn the rules and structure of the language, understand the meaning of the language, and generate text with correct grammar and semantic coherence based on the understood meaning. The large model can also realize the generation of images based on text, the generation of videos based on text, and so on. A model supplier refers to an entity that owns a large model and uses a cloud service provider to build its own reasoning-related services.
[0037] A model task refers to a task related to any model issued by a user, such as one or more model reasoning tasks and model fine-tuning tasks for a certain model. In the embodiment of the present disclosure, a target model task refers to a task related to a target model, and the target model can be a model that the user needs to perform task processing. A user (client) refers to an entity that runs applications provided by a cloud service provider and a model supplier, has some requirements for the cloud service provider and the model supplier, and can be considered a common customer of the cloud service provider and the model supplier. A model reasoning task refers to the process of using a trained model to predict or classify data. A model fine-tuning task refers to fine-tuning a model using training data to improve its performance on specific tasks.
[0038] Specifically, a target model task includes multiple task phases for the target model, with no specific limit on the number. Task phases refer to the different stages or tasks that can be split and processed in the lifecycle of a model task, as determined by the cloud service provider through analysis of multiple model tasks.
[0039] Exemplarily, when the target model task is a model training task for the target model, the target model task may include multiple task stages such as a pre-processing stage, an intermediate stage, and a post-processing stage. Among them, the pre-processing stage refers to the preliminary processing and preparation of the input data, such as data cleaning, format conversion, feature extraction, and pre-processing tasks. The intermediate stage mainly performs computing tasks, which are usually the core computing part of the model. The post-processing stage is to further process and integrate the data output by the model, and convert the results into a form that can be finally used or displayed. Specifically, the pre-processing stage is usually performed by a central processing unit (CPU), the intermediate processing stage is usually performed by a graphics processing unit (GPU), and the post-processing stage is usually performed by a central processing unit. Taking the target model task as a model training task as an example, the model training task can be divided into a pre-processing stage of the data set, a training stage of the data set after pre-processing, and an integration stage of the model output data.
[0040] Reinforcement configuration information refers to information pre-configured by the model provider for the target model's tasks based on reinforcement requirements. Specifically, the cloud service provider can provide the model provider with a visualization page to enable rapid configuration. Specifically, the reinforcement configuration information is used to specify the target model task's reinforcement phase using target configuration dimensions. Target configuration dimensions are sets of key parameters used to describe and define model tasks. Specifically, target configuration dimensions can include at least one of reinforcement level, task phase, model, and user.
[0041] The "reinforcement level" refers to the protection level pre-configured by the model provider for the target model's tasks based on the reinforcement level dimension. Different levels correspond to different numbers of task stages to be reinforced. For example, if the reinforcement level is level 1, none of the target model's task stages will be reinforced. If the reinforcement level is level 2, one-third of the target model's task stages will be reinforced, while two-thirds will not. The "task stage" refers to the reinforcement configuration information specified by the model provider from the task stage dimension, which specifies which task stages require reinforcement. For example, if the model provider specifies task stage A in the target configuration dimension, task stage A will be determined to require reinforcement. The "model" refers to the reinforcement configuration information specified by the model provider from the model dimension. If the model provider specifies model B in the target configuration dimension, then all model tasks corresponding to model B require reinforcement. The "user" refers to the reinforcement configuration information specified by the model provider from the user dimension. If the model provider specifies user C in the target configuration dimension, then all task stages of the model tasks associated with all models corresponding to user C require reinforcement. The task stage to be reinforced refers to the task stage in the model task that needs to be reinforced.
[0042] In the embodiment of the present disclosure, the cloud service provider can obtain the target model task issued by the user and the reinforcement configuration information pre-set by the model supplier, and the reinforcement configuration information can be set according to actual business needs.
[0043] Step 102: Determine a task phase to be reinforced and a task phase not to be reinforced among multiple task phases according to the reinforcement configuration information.
[0044] The "to-be-hardened" phase refers to the phase of a model task that requires hardening. Hardening here refers to data isolation at the network, computing, and storage levels to prevent potential attacks on virtual machine information by the host operating system or hypervisor. The "non-hardened" phase refers to the phase of a model task that does not require hardening.
[0045] In the embodiment of the present disclosure, the cloud service provider determines the task phase to be reinforced and the task phase not to be reinforced among the multiple task phases of the target model task by parsing the reinforcement configuration information.
[0046] For example, Figure 2 A flow chart of another model task processing method provided in some embodiments of the present disclosure is shown as follows: Figure 2 As shown, the above step 102 may include steps 201, 202, and 203, which specifically include:
[0047] In step 201, when the target configuration dimension is the reinforcement level, the task stages to be reinforced are determined based on the target quantity corresponding to the reinforcement level, and the task stages other than the task stages to be reinforced are determined as non-reinforcement task stages.
[0048] The target number refers to the number of task stages that need to be reinforced in each task stage of the target model task determined based on the reinforcement level.
[0049] In an embodiment of the present disclosure, when the target configuration dimension is the reinforcement level, the cloud service provider can determine the target number based on the reinforcement level, extract the target number of task stages from multiple task stages according to a preset extraction strategy as task stages to be reinforced, and determine the task stages other than the task stages to be reinforced as non-reinforced task stages. The preset extraction strategy here can be, for example, random extraction or extraction in order from large to small according to the amount of data in the task stages, etc., and there is no specific limitation. For example, if the preset extraction strategy is random extraction, when the target number is half, half of the multiple randomly extracted task stages can be determined as task stages to be reinforced, and the task stages other than the task stages to be reinforced can be determined as non-reinforced task stages.
[0050] In step 202 , when the target configuration dimension is a model or a user, when the target model task matches the model or the user, all task stages in the plurality of task stages are determined as task stages to be reinforced.
[0051] Specifically, when the target configuration dimension is model, the cloud service provider matches the target model task with the model. If the match is successful, all task stages of the target model task are determined as task stages to be reinforced. When the target configuration dimension is user, the cloud service provider matches the target model task with the user. If the match is successful, all task stages of the target model task are determined as task stages to be reinforced.
[0052] In step 203, when the target configuration dimension is a task stage, the task stage corresponding to the target configuration dimension among the multiple task stages is determined as the task stage to be reinforced, and the task stages other than the task stage to be reinforced are determined as non-reinforcement task stages.
[0053] In an embodiment of the present disclosure, when the target configuration dimension is the task stage, the cloud service provider can determine, among the multiple task stages of the target model task, the task stage in which the target model pre-configured by the model supplier needs to be reinforced as the task stage to be reinforced, and determine the task stages other than the task stage to be reinforced as the task stage not to be reinforced.
[0054] Step 103: Schedule the task phase to be reinforced to the corresponding first virtual machine for processing, and schedule the task phase not to be reinforced to the corresponding second virtual machine for processing; wherein the first virtual machine is deployed in a trusted execution environment based on trusted hardware.
[0055] A virtual machine (VM) provides an independent runtime environment for managing user pods and service pods. This allows these pods to share the same virtual hardware resources within the virtual machine while maintaining their own independence and isolation. A first virtual machine is a virtual machine deployed in a trusted execution environment based on trusted hardware, the specific number of which is not limited. A second virtual machine is a virtual machine not deployed in a trusted execution environment based on trusted hardware, the specific number of which is not limited.
[0056] A Trusted Execution Environment (TEE) is a secure area of device hardware or software that is isolated from the main operating system and provides a trusted environment for executing sensitive or critical code and data. The security in the TEE mainly comes from its isolation from the main operating system and hardware protection measures. The first virtual machine is deployed in a trusted execution environment based on trusted hardware. The TEE provides a secure execution environment in which the code and data stored and executed are protected. The TEE itself is composed of special hardware in the processor, and uses some security protection mechanisms to prevent the outside world from tampering with or stealing the code and data in the TEE. In addition, the TEE does not allow ordinary applications to access the code and data therein, thereby improving the security of the system. In an embodiment of the present disclosure, the first virtual machine is completely encapsulated in the executable environment, thereby realizing the integration of the first virtual machine and the executable environment, isolating the relevant data in the executable environment, and ensuring the security of the data.
[0057] A trusted execution environment (TEE) based on trusted hardware provides a secure computing environment through hardware protection mechanisms, preventing potential attacks on virtual machine information by the host operating system or hypervisor. Specifically, hardware protection limits unauthorized access to virtual machine memory and page tables, creating a secure sandbox environment. For cloud service providers, this technology helps enhance the security of user data. Figure 3 The schematic diagram of the architecture of the virtual machine deployed based on the executable environment provided in some embodiments of the present disclosure is as follows: Figure 3 As shown, a hardened virtual machine deployed using a trusted execution environment (TEE) can be an example of the first virtual machine described above, protecting memory security through strict hardware access control. Only authenticated hardware can access memory, and data is stored in plaintext only when accessed by the central processing unit. Otherwise, it is encrypted. This restricts the permissions of the host operating system and hypervisor, making it impossible to read the memory contents even if it is exported.
[0058] In an embodiment of the present disclosure, after the cloud service provider determines the task stage to be reinforced and the non-reinforced task stage among multiple task stages based on the reinforcement configuration information, the task stage to be reinforced is scheduled to the corresponding first virtual machine for processing, and the non-reinforced task stage is scheduled to the corresponding second virtual machine for processing.
[0059] In an optional implementation, the task stage to be reinforced is scheduled to the corresponding first virtual machine for processing, including: scheduling the first task stage corresponding to the central processor in the task stage to be reinforced to the central processing virtual machine in the first virtual machine for processing, and scheduling the second task stage corresponding to the graphics processor to the graphics processing virtual machine in the first virtual machine for processing.
[0060] The first task stage refers to any task stage within the task stage to be reinforced that requires the capabilities of a central processing unit (CPU). A central processing virtual machine (CPU VM) is a virtual machine that simulates the capabilities of a CPU, providing capabilities similar to those of an actual computer CPU. The second task stage refers to any task stage within the task stage to be reinforced that requires the capabilities of a graphics processing unit (GPU). A graphics processing virtual machine (GPU VM) is a virtual machine that simulates the capabilities of a graphics processing unit (GPU), providing capabilities similar to those of an actual computer GPU.
[0061] The central processing virtual machine in the first virtual machine can achieve hardware isolation by directly deploying the central processing virtual machine in a trusted execution environment based on trusted hardware. The graphics processing virtual machine in the first virtual machine can achieve hardware isolation by directly deploying the graphics processing virtual machine in a trusted execution environment based on trusted hardware. Hardware isolation can also be achieved by connecting the central processing virtual machine in the first virtual machine to the graphics processor. Specifically, the central processing virtual machine in the first virtual machine can not only isolate the central processor and memory in hardware, but also isolate peripheral devices such as the graphics processor, ensuring that the content entering the graphics processor peripherals is encrypted, which can prevent attacks from peripheral devices. In addition, only authorized or verified graphics processors can be trusted by the graphics processor-based trusted execution environment virtual machine. At this time, the virtual machine that achieves hardware isolation by connecting the central processing virtual machine in the first virtual machine to the graphics processor is no longer a simple central processor-based trusted execution environment virtual machine, but a graphics processor-based trusted execution environment virtual machine.
[0062] In an embodiment of the present disclosure, after the cloud service provider determines the task stages to be reinforced and the non-reinforced task stages among multiple task stages based on the reinforcement configuration information, it determines whether the task stages to be reinforced need to be processed using the capabilities of the central processing unit or the graphics processing unit, and schedules the first task stage in the task stages to be reinforced that needs to be processed using the capabilities of the central processing unit to be processed to the central processing virtual machine in the first virtual machine for processing, and schedules the second task stage in the task stages to be reinforced that needs to be processed using the capabilities of the graphics processor to be processed to the graphics processing virtual machine in the first virtual machine for processing.
[0063] Exemplarily, a cloud service provider utilizes a trusted execution environment based on trusted hardware to schedule multiple task stages of a target model task on demand to different virtual machines deployed in a trusted execution environment based on trusted hardware. For example, taking the target model task as a training task, the training task includes a data preprocessing task stage and a data fine-tuning task stage of the training task. Specifically, the cloud service provider can place the data preprocessing task stage of the training task into a central processing virtual machine in the first virtual machine for processing, and place the data fine-tuning task stage into a graphics processing virtual machine in the first virtual machine for processing. In this way, the cloud service provider can fully utilize the strengths of different virtual machines deployed in a trusted execution environment based on trusted hardware, thereby protecting the load of different stages of the target model. It can be seen that the embodiments of the present disclosure can effectively manage the resources of different virtual machines deployed in a trusted execution environment based on trusted hardware. According to the needs of the target model task, the target model task can be divided into different task stages, and then different task stages can be placed in different types of virtual machines deployed in a trusted execution environment based on trusted hardware, thereby improving the runtime data isolation of a task stage in the model task, thereby resisting attacks from the infrastructure as a service level.
[0064] In an optional implementation, the non-reinforced task stage is scheduled to the corresponding second virtual machine for processing, including: scheduling the third task stage corresponding to the central processor in the non-reinforced task stage to the central processing virtual machine in the second virtual machine for processing, and scheduling the fourth task stage corresponding to the graphics processor to the graphics processing virtual machine in the second virtual machine for processing.
[0065] The third task stage refers to any task stage in the non-reinforced task stage that needs to utilize the capabilities of the central processing unit for processing, and the fourth task stage refers to any task stage in the non-reinforced task stage that needs to utilize the capabilities of the graphics processing unit for processing.
[0066] In an embodiment of the present disclosure, after the cloud service provider determines the task stages to be reinforced and the non-reinforced task stages among multiple task stages based on the reinforcement configuration information, it determines whether the non-reinforced task stages need to be processed using the capabilities of the central processing unit or the graphics processing unit, and schedules the third task stage in the non-reinforced task stage that needs to be processed using the capabilities of the central processing unit to the central processing virtual machine in the second virtual machine for processing, and schedules the fourth task stage in the non-reinforced task stage that needs to be processed using the capabilities of the graphics processor to the graphics processing virtual machine in the second virtual machine for processing.
[0067] In addition, the task phase to be reinforced and the task phase not to be reinforced are also scheduled according to the virtual machine parameters or virtual machine tags set in the reinforcement configuration information.
[0068] The virtual machine parameters can include configuration parameters of the virtual machine, such as 8-core or 16-core, where core refers to the number of CPU cores. They can also include the virtual machine's memory size, such as 8GB or 16GB, and different hypervisors. The virtual machine tags can include the source of the virtual machine, the model of the virtual machine, and so on.
[0069] In the embodiment of the present disclosure, the task stage to be reinforced and the non-reinforced task stage are also scheduled according to the virtual machine parameters set in the reinforcement configuration information. Specifically, if the virtual machine parameters set in the reinforcement configuration information are 8GB, the virtual machine corresponding to 8GB is used to process at least one of the multiple task stages of the target model task.
[0070] In another embodiment of the present disclosure, the task stage to be reinforced and the non-reinforced task stage are also scheduled according to the virtual machine label set in the reinforcement configuration information. Specifically, if the virtual machine label set in the reinforcement configuration information is virtual machine D, the virtual machine corresponding to virtual machine D is used to process at least one of the multiple task stages of the target model task.
[0071] In order to prove to the user that the corresponding load is indeed running in a hardware-protected environment, in an optional implementation, the cloud service provider can output the corresponding data processing report through the container component added in the first virtual machine and the second virtual machine, wherein the data processing report carries the corresponding authentication certificate for the content of the first virtual machine.
[0072] Among them, the container component is used to read the task execution records of the task stage in the virtual machine where it is located. The data processing report refers to a comprehensive description and record of the data processing process. Specifically, the data processing report includes the task execution records of each task stage of the target model, which can include the various stages of the target model task division, as well as the operations performed in each stage and the access to the service. The authentication certificate refers to a certificate issued by an authoritative organization, which is used to prove that the content of the first virtual machine has a certain qualification credential. The authentication certificate cannot be tampered with and can be verified later. Specifically, the authentication certificate can be decrypted and verified by standard methods to ensure the authenticity of the content of the first virtual machine. Each log in the data processing report can be traced back to a specific hardware device. For example, when using a virtual machine, the number of a specific device can be traced through the log to verify the source and accuracy of the log. The content of the first virtual machine refers to the execution record of the model task processing process, such as the execution log of the model task processing process.
[0073] In an embodiment of the present disclosure, the cloud service provider can output a corresponding data processing report by adding a container component to the container group in the first virtual machine and the second virtual machine. Specifically, when the container group is started, the container component preferentially reads the data processing results on the virtual machine and inputs the data processing report, the container group identifier, and the virtual machine identifier into the log service. Based on the container group identifier and the virtual machine identifier, the corresponding data processing report can be queried from the log service to determine whether it is in a trusted execution environment based on trusted hardware.
[0074] The model task processing solution provided by the embodiment of the present disclosure obtains the target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model, determines the task stage to be reinforced and the non-reinforced task stage in the multiple task stages according to the reinforcement configuration information, schedules the task stage to be reinforced to the corresponding first virtual machine for processing, and schedules the non-reinforced task stage to the corresponding second virtual machine for processing, wherein the first virtual machine is deployed in a trusted execution environment based on trusted hardware. With the above technical solution, the cloud service provider can divide the target model task into multiple task stages, and schedule different task stages to different virtual machines for reinforcement according to the reinforcement configuration information. Since the first virtual machine is deployed in a trusted execution environment based on trusted hardware, the model task processed by the first virtual machine can obtain higher security, effectively improve the security of model task processing, prevent internal attacks by relevant personnel of the cloud service provider, and improve the security level of data isolation at runtime while ensuring the impact on performance.
[0075] Figure 4 A flow chart of another model task processing method provided in some embodiments of the present disclosure is as follows: Figure 4 As shown, the method includes:
[0076] First, the user submits a target model task. After receiving the target model task, the backend scheduling module can perceive the needs of the model provider and, using different dimensions and specifying different parameters, inform the scheduling module of the virtual machines to schedule for each task phase of the target model task. For example, if the target model task is a training or fine-tuning task, the target configuration dimension can be used to specify which task phase of the target model task requires reinforcement. For example, at least one of the reinforcement level, task phase, model, and user dimensions can be used to specify which task phase of the target model task requires reinforcement, thereby selecting appropriate resources for scheduling.
[0077] Depending on the scheduling period, tasks at different stages can be placed in different virtual machines, such as a hardened central processing virtual machine, a central processing virtual machine (i.e., the central processing virtual machine of the second virtual machine), a graphics processing virtual machine (i.e., the graphics processing virtual machine of the second virtual machine), or other types of virtual machines. This allows for flexible scheduling for each task stage, without requiring that all multiple task stages of the target model task be placed in the same virtual machine. For example, tasks related to the central processing unit (CPU) can be processed using a hardened CPU virtual machine, while tasks related to the graphics processing unit (GPU) can be processed using a graphics processing virtual machine, making scheduling more granular and reducing costs.
[0078] After the scheduling is completed, the corresponding task stage will be scheduled to the corresponding virtual machine. After the task is completed, a data processing report will be generated for the corresponding task stage. Specifically, for the tasks running in each virtual machine, the data analysis report will provide information to the user, such as which task stages of the target model task are placed in the reinforced central processing virtual machine. The data processing report can be used to carry the corresponding authentication certificate for the content of the reinforced central processing virtual machine to inform the user, further making the user believe in the security of the model task processing.
[0079] Figure 5 This is a schematic diagram of the control plane architecture provided in some embodiments of the present disclosure. Figure 5 The hardware includes a central processing unit (CPU), a network interface card (NIC), and an accelerator (Accelerated Devices). The NIC may include a data processing unit (DPU). The accelerator may include a graphics processing unit (GPU), a tensor processing unit (TPU), a field programmable gate array (FPGA), or an application-specific integrated circuit (ASIC). Figure 5 The storage service in the example may be a cloud storage service implemented based on a cloud server. This embodiment does not limit the specific hardware device for implementing the storage service. The storage service may include one or more databases. Figure 5 As shown, in this embodiment, the control plane model can serve as a model-as-a-service to accept large models from various model providers, and then use these large models to provide external services such as inference services and fine-tuning services. In essence, model-as-a-service is platform-as-a-service.
[0080] The data plane relies on Infrastructure as a Service. The data plane can have a corresponding software stack, which can be scheduled and deployed as a service container group on the governed cloud server (Elastic Compute Service, ECS) node. In response to the user's scheduling, it will be scheduled accordingly according to the scheduler. Figure 5 There are multiple user container groups and service container groups in the cloud server virtual machine.
[0081] Typically, Model-as-a-Service tasks can be divided into inference tasks and training tasks (e.g., dynamic fine-tuning tasks). These tasks involve three roles: cloud service providers, model providers, and users.
[0082] Specifically, cloud service providers offer cloud services (e.g., Infrastructure as a Service or Platform as a Service) to serve entities belonging to different model providers. Model providers own large models and utilize cloud service providers to build their own inference tasks and other services. Users are entities that run applications provided by cloud service providers and model providers. Users have corresponding isolation requirements for model providers and cloud service providers. Specifically, when users obtain Model as a Service from cloud service providers, they expect the container groups for their model-related tasks to be isolated in terms of network, compute, and storage to ensure security.
[0083] Figure 6 This is a schematic diagram of the structure of a model task processing device provided in some embodiments of the present disclosure. The device can be implemented by software and / or hardware and can generally be integrated into an electronic device. Figure 6 As shown, the device is set in the first base station and includes:
[0084] An acquisition module 601 is configured to acquire a target model task and reinforcement configuration information, wherein the target model task includes multiple task phases for the target model;
[0085] A determination module 602 is configured to determine a task phase to be reinforced and a task phase not to be reinforced among the multiple task phases according to the reinforcement configuration information;
[0086] The processing module 603 is used to schedule the task phase to be reinforced to the corresponding first virtual machine for processing, and schedule the task phase not to be reinforced to the corresponding second virtual machine for processing;
[0087] The first virtual machine is deployed in a trusted execution environment based on trusted hardware.
[0088] In an optional implementation, the reinforcement configuration information is used to specify the task stage to be reinforced of the target model task using a target configuration dimension, and the target configuration dimension includes at least one of a reinforcement level, a task stage, a model, and a user.
[0089] In an optional implementation, the determining module 602 includes:
[0090] A first determining submodule is configured to, when the target configuration dimension is a reinforcement level, determine a task stage to be reinforced based on the target quantity corresponding to the reinforcement level, and determine the task stages other than the task stage to be reinforced as non-reinforcement task stages;
[0091] a second determining submodule, configured to, when the target configuration dimension is a model or a user, determine all of the multiple task stages as task stages to be reinforced when the target model task matches the model or the user;
[0092] The third determination submodule is used to determine, when the target configuration dimension is a task stage, the task stage corresponding to the target configuration dimension among the multiple task stages as the task stage to be reinforced, and to determine the task stages other than the task stage to be reinforced as non-reinforced task stages.
[0093] In an optional implementation, the processing module 603 includes a first scheduling submodule and a second scheduling submodule;
[0094] The first scheduling submodule is used to schedule the task to be reinforced stage to the corresponding first virtual machine for processing;
[0095] The second scheduling submodule is used to schedule the non-reinforcement task phase to the corresponding second virtual machine for processing.
[0096] In an optional implementation manner, the first scheduling submodule is specifically configured to:
[0097] The first task stage corresponding to the central processor in the task stage to be reinforced is scheduled to the central processing virtual machine in the first virtual machine for processing, and the second task stage corresponding to the graphics processor is scheduled to the graphics processing virtual machine in the first virtual machine for processing.
[0098] In an optional implementation manner, the second scheduling submodule is specifically configured to:
[0099] The third task stage corresponding to the central processor in the non-reinforced task stage is scheduled to the central processing virtual machine in the second virtual machine for processing, and the fourth task stage corresponding to the graphics processor is scheduled to the graphics processing virtual machine in the second virtual machine for processing.
[0100] In an optional implementation, the task phase to be reinforced and the task phase not to be reinforced are also scheduled according to virtual machine parameters or virtual machine tags set in the reinforcement configuration information.
[0101] In an optional embodiment, the device further includes:
[0102] The output module is used to output a corresponding data processing report through the container components added in the first virtual machine and the second virtual machine, wherein the data processing report carries a corresponding authentication certificate for the content of the first virtual machine.
[0103] The model task processing device provided by the embodiments of the present disclosure can execute the model task processing method provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method.
[0104] An embodiment of the present disclosure further provides a computer program product, including a computer program / instruction, which implements the model task processing method provided by any embodiment of the present disclosure when executed by a processor.
[0105] Figure 7 A schematic structural diagram of an electronic device provided in some embodiments of the present disclosure.
[0106] The following specific reference Figure 7 , which shows a schematic structural diagram of an electronic device 700 suitable for implementing the embodiments of the present disclosure. The electronic device 700 in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0107] like Figure 7 As shown, the electronic device 700 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 are also stored in the RAM 703. The processing device 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0108] Typically, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 7 The electronic device 700 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0109] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the model task processing method of the embodiment of the present disclosure are performed.
[0110] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0111] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0112] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0113] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device is enabled to: obtain a target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model; determine the task stage to be reinforced and the non-reinforced task stage among the multiple task stages according to the reinforcement configuration information; schedule the task stage to be reinforced to the corresponding first virtual machine for processing, and schedule the non-reinforced task stage to the corresponding second virtual machine for processing; wherein the first virtual machine is deployed in a trusted execution environment based on trusted hardware.
[0114] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0116] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.
[0117] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0118] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0119] It is understandable that before using the technical solutions disclosed in the embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0120] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0121] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0122] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. A model task processing method, characterized in that: include: Obtaining a target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model, wherein the task stages refer to different links or tasks that can be split and processed in the life cycle of the model task determined by the cloud service provider through analysis of multiple model tasks, and the reinforcement configuration information refers to information pre-configured by the model provider for the target model task based on reinforcement requirements, wherein the reinforcement configuration information is used to specify the task stage to be reinforced of the target model task using target configuration dimensions, wherein the target configuration dimensions include at least one of reinforcement level, task stage, model, and user; Determining, according to the reinforcement configuration information, a task stage to be reinforced and a non-reinforced task stage among the multiple task stages; Scheduling the task phase to be reinforced to the corresponding first virtual machine for processing, and scheduling the task phase not to be reinforced to the corresponding second virtual machine for processing; The first virtual machine is deployed in a trusted execution environment based on trusted hardware.
2. The method according to claim 1, characterized in that Determining, according to the reinforcement configuration information, a task phase to be reinforced and a task phase not to be reinforced among the multiple task phases, comprising: When the target configuration dimension is a reinforcement level, determining a task stage to be reinforced based on the target quantity corresponding to the reinforcement level, and determining the task stages other than the task stage to be reinforced as non-reinforcement task stages; When the target configuration dimension is a model or a user, when the target model task matches the model or the user, all task stages in the multiple task stages are determined as task stages to be reinforced; When the target configuration dimension is a task stage, the task stage corresponding to the target configuration dimension among the multiple task stages is determined as the task stage to be reinforced, and the task stages other than the task stage to be reinforced are determined as non-reinforced task stages.
3. The method according to claim 1, characterized in that Scheduling the task to be reinforced to the corresponding first virtual machine for processing includes: The first task stage corresponding to the central processor in the task stage to be reinforced is scheduled to the central processing virtual machine in the first virtual machine for processing, and the second task stage corresponding to the graphics processor is scheduled to the graphics processing virtual machine in the first virtual machine for processing.
4. The method according to claim 1, wherein Scheduling the non-reinforcement task phase to a corresponding second virtual machine for processing includes: The third task stage corresponding to the central processor in the non-reinforced task stage is scheduled to the central processing virtual machine in the second virtual machine for processing, and the fourth task stage corresponding to the graphics processor is scheduled to the graphics processing virtual machine in the second virtual machine for processing.
5. The method according to claim 1, wherein The task phase to be reinforced and the task phase not to be reinforced are also scheduled according to the virtual machine parameters or virtual machine tags set in the reinforcement configuration information.
6. The method according to claim 1, characterized in that The method further comprises: A corresponding data processing report is output through the container components added in the first virtual machine and the second virtual machine, wherein the data processing report carries a corresponding authentication certificate for the content of the first virtual machine.
7. A model task processing device, characterized in that: include: An acquisition module is configured to acquire a target model task and reinforcement configuration information, wherein the target model task includes multiple task stages for the target model, wherein the task stages refer to different links or tasks that can be split and processed in the life cycle of the model task determined by the cloud service provider through analysis of multiple model tasks, and the reinforcement configuration information refers to information pre-configured by the model provider for the target model task based on reinforcement requirements, wherein the reinforcement configuration information is used to specify the task stage to be reinforced of the target model task using a target configuration dimension, wherein the target configuration dimension includes at least one of a reinforcement level, a task stage, a model, and a user; A determination module, configured to determine a task stage to be reinforced and a task stage not to be reinforced among the multiple task stages according to the reinforcement configuration information; a processing module, configured to dispatch the task phase to be reinforced to the corresponding first virtual machine for processing, and dispatch the task phase not to be reinforced to the corresponding second virtual machine for processing; The first virtual machine is deployed in a trusted execution environment based on trusted hardware.
8. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the model task processing method described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and the computer program is used to execute the model task processing method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Data processing method, device and equipment and computer readable storage medium
CN113761513A
Model protection method and related product
CN116305090A