Method and device for protecting model security, equipment and storage medium
By using direction transformation parameters to transform the weight tensor of the machine learning model in a trusted execution environment, and combining the processing unit and the trusted execution environment for collaborative reasoning, the problem of data security protection of the machine learning model is solved, and privacy security and inference performance are achieved.
Patent Information
- Application Number
- CN202510561372.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-04-29
AI Technical Summary
The differentiation of training and application links of existing machine learning models leads to data security protection issues, and traditional obfuscation strategies cannot take into account privacy security and inference performance.
Direction transformation parameters are used to transform the weight tensor of the machine learning model in a trusted execution environment, generate direction correction tensors, and collaborative reasoning is carried out in combination with processing units and trusted execution environment to protect the model security.
Effectively protect the privacy and security of the model, improve inference performance, and improve the model's attack resistance.
Smart Images

Figure CN120493239A_ABST
Abstract
Description
Technical Field
[0001] Example embodiments of the present disclosure generally relate to the field of computers, and more particularly, to methods, devices, apparatuses, computer-readable storage media, and computer program products for protecting model security. Background Art
[0002] With the continuous development of machine learning models, the training and application stages of machine learning models are becoming increasingly differentiated. Model trainers are typically able to integrate powerful computing power and massive amounts of data to train machine learning models. Model users often belong to specific business areas and apply the machine learning models provided by trainers to specific business scenarios to reduce costs or improve business capabilities. This differentiation and coordination allows trainers and users to leverage their respective strengths, improving model training efficiency and application capabilities. However, it also raises the issue of data security protection within the machine learning models themselves. Summary of the Invention
[0003] In the first aspect of the present disclosure, a method for protecting model security is provided. The method includes: obtaining an input feature representation for a first model layer in a machine learning model, the first model layer including a direction transformation parameter deployed in a trusted execution environment of a computing device and a first weight tensor deployed in a processing unit outside the trusted execution environment, the first weight tensor being obtained by transforming a trained weight tensor of the first model layer using the direction transformation parameter; generating a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit; transmitting the input feature representation and the first feature tensor to the trusted execution environment; processing the input feature representation using the direction transformation parameter in the trusted execution environment to generate a direction correction tensor; and correcting the first feature tensor based on the direction correction tensor in the trusted execution environment to determine an output feature representation corresponding to the first model layer.
[0004] In the second aspect of the present disclosure, a device for protecting model security is provided. The device includes: an acquisition module configured to acquire an input feature representation for a first model layer in a machine learning model, the first model layer including a direction transformation parameter deployed in a trusted execution environment of a computing device and a first weight tensor deployed in a processing unit outside the trusted execution environment, the first weight tensor being obtained by transforming the trained weight tensor of the first model layer using the direction transformation parameter; a generation module configured to generate a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit; a transmission module configured to transmit the input feature representation and the first feature tensor to the trusted execution environment; a processing module configured to process the input feature representation using the direction transformation parameter in the trusted execution environment to generate a direction correction tensor; and a correction module configured to correct the first feature tensor based on the direction correction tensor in the trusted execution environment to determine an output feature representation corresponding to the first model layer.
[0005] In a third aspect of the present disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. When executed by the at least one processor, the instructions cause the device to perform the method of the first aspect.
[0006] In a fourth aspect of the present disclosure, a computer-readable storage medium is provided, wherein computer-executable instructions are stored on the computer-readable storage medium, and the computer-executable instructions can be executed by a processor to implement the method of the first aspect.
[0007] In a fifth aspect of the present disclosure, a computer program product is provided, comprising computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the method according to the first aspect of the present disclosure is implemented.
[0008] It should be understood that the content described in this summary section is not intended to limit the key features or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. In the accompanying drawings, the same or similar reference numerals represent the same or similar elements, wherein:
[0010] Figure 1 A schematic diagram illustrating an example environment in which embodiments according to the present disclosure may be implemented;
[0011] Figure 2A flowchart illustrating a process for securing a model according to some embodiments of the present disclosure is shown;
[0012] Figure 3 A schematic diagram illustrating an example scenario for protecting model security according to some embodiments of the present disclosure;
[0013] Figure 4 A schematic structural block diagram of an example apparatus for protecting model security according to some embodiments of the present disclosure is shown; and
[0014] Figure 5 A block diagram of an electronic device capable of implementing various embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0015] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0016] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may be included below.
[0017] Herein, unless explicitly stated otherwise, executing a step “in response to A” does not mean executing the step immediately after “A” but may include one or more intermediate steps.
[0018] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) must comply with the requirements of relevant laws, regulations and relevant provisions.
[0019] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0020] For example, in response to receiving a user's active request, a prompt message is sent to the user to clearly remind the user that the operation requested to be performed will require obtaining and using the user's personal information, so that the user can independently choose whether to provide personal information to the electronic device, application, server or storage medium and other software or hardware that performs the operation of the technical solution of the present disclosure based on the prompt message.
[0021] As an optional but non-limiting implementation, in response to receiving a user's active request, a prompt message may be sent to the user, for example, in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0022] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0023] As used herein, the term "model" can learn the association between corresponding inputs and outputs from training data, so that after training is completed, corresponding outputs can be generated for given inputs. The generation of the model can be based on machine learning technology. Deep learning is a machine learning algorithm that processes inputs and provides corresponding outputs by using multiple layers of processing units. A neural network model is an example of a model based on deep learning. In this article, "model" may also be referred to as "machine learning model", "learning model", "machine learning network" or "learning network", and these terms are used interchangeably in this article.
[0024] A "neural network" is a machine learning network based on deep learning. A neural network is capable of processing inputs and providing corresponding outputs. It typically includes an input layer, an output layer, and one or more hidden layers between the input and output layers. Neural networks used in deep learning applications typically include many hidden layers, thereby increasing the depth of the network. The layers of a neural network are connected in sequence so that the output of the previous layer is provided as input to the next layer, where the input layer receives the input of the neural network and the output of the output layer serves as the final output of the neural network. Each layer of a neural network includes one or more nodes (also called processing nodes or neurons), each of which processes the input from the previous layer.
[0025] Generally speaking, machine learning can be roughly divided into three stages, namely the training stage, the testing stage, and the application stage (also known as the inference stage). In the training stage, a given model can be trained using a large amount of training data, and the parameter values are continuously updated iteratively until the model can obtain consistent inferences that meet the expected goals from the training data. Through training, the model can be considered to be able to learn the association between input and output (also known as input-to-output mapping) from the training data. The parameter values of the trained model are determined. In the testing stage, the test input is applied to the trained model to test whether the model can provide the correct output, thereby determining the performance of the model. In the application stage, the model can be used to process the actual input based on the parameter values obtained through training to determine the corresponding output.
[0026] As used herein, the term "weight tensor" may be a tensor having any suitable number of dimensions. For example, a weight tensor may be a weight matrix. Hereinafter, the weight matrix will be primarily used as an example of a weight tensor for description.
[0027] As mentioned above, with the continuous development of machine learning models, the training and application stages of machine learning models are becoming increasingly differentiated. Model trainers (also known as model providers) are typically able to integrate powerful computing power and massive amounts of data to train machine learning models. Model users often belong to specific business areas and apply the machine learning models provided by trainers to specific business scenarios to reduce costs or improve business capabilities. This differentiation and coordination helps trainers and users leverage their respective strengths, improving model training efficiency and application capabilities. However, it also raises the issue of data security protection for machine learning models.
[0028] To address data security concerns surrounding machine learning models, some providers choose to utilize trusted execution environments (TEEs) to protect these models. Specifically, the model is divided into two parts based on computational intensity. The more computationally intensive part is obfuscated and deployed in a standard execution environment, while the less computationally intensive part is deployed in a trusted execution environment (TEE). During inference, both the standard and TEEs perform collaborative reasoning. In the standard execution environment, input data is processed using obfuscated weight vectors. In the TEE, the processed results are restored to yield the true output.
[0029] Traditional obfuscation techniques can be categorized into lightweight and complex obfuscation strategies. Lightweight obfuscation strategies focus on the model's reasoning performance, employing relatively simple and lightweight obfuscation strategies. These strategies fail to protect the directional information of the privacy weight vector. When attackers use public information to steal the model, the privacy protection of these strategies is poor, and security still needs to be improved. Complex obfuscation strategies focus on the model's security, utilizing relatively complex matrix multiplication to obfuscate the model's weights. However, the computational complexity of restoring the processing results in a trusted execution environment is high, approaching the computational complexity of performing reasoning operations at the corresponding model layer in the trusted execution environment, impacting the model's reasoning performance. Therefore, traditional obfuscation strategies cannot balance the model's privacy, security, and reasoning performance.
[0030] In view of this, an embodiment of the present disclosure proposes an improved solution for protecting model security. In this solution, for the first model layer in the machine learning model, the direction transformation parameters are used in advance to transform (also referred to as obfuscation) the trained weight tensor of the first model layer to obtain a first weight tensor. During the process of the computing device running the machine learning model, the direction transformation parameters are deployed in the trusted execution environment of the computing device, and the first weight tensor is deployed in a processing unit outside the trusted execution environment of the computing device. If the input feature representation for the first model layer is obtained, the first feature tensor for the first model layer is generated by at least processing the input feature representation using the first weight tensor in the processing unit. Afterwards, the input feature representation and the first feature tensor are transmitted from the processing unit to the trusted execution environment. In the trusted execution environment, the input feature representation is processed using the direction transformation parameters to generate a direction correction tensor. In addition, the first feature tensor is corrected based on the direction correction tensor to determine the output feature representation corresponding to the first model layer.
[0031] In an embodiment of the present disclosure, the first weight tensor deployed in the processing unit is obtained by obfuscating the direction transformation parameters, which can effectively protect the direction information of the trained weight tensor. In a trusted execution environment, it is only necessary to use the direction transformation parameters to process the input feature representation to generate a direction correction tensor. The direction correction tensor is then used to correct the direction of the first feature tensor. In this way, the amount of computation in the trusted execution environment is relatively small, and the inference speed is relatively fast, which can achieve the goal of balancing the privacy security and inference performance of the model.
[0032] Various example implementations of this solution are described in detail below in conjunction with the accompanying drawings.
[0033] Sample Environment
[0034] Figure 1A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. In this example environment 100, a processing unit 120 and a trusted execution environment (TEE) 130 are deployed in a computing device 110. Compared to the processing unit 120, the trusted execution environment 130 has a higher degree of trust. In other words, the security factor of the trusted execution environment 130 is higher than the security factor of the processing unit 120.
[0035] In some embodiments, the trusted execution environment 130 can be referred to as a secure execution environment. A trusted execution environment is a hardware-based security technology that creates a secure computing environment isolated from the outside world by dividing it into secure and non-secure parts. The secure computing environment can ensure the confidentiality and integrity of data and code loaded within the trusted execution environment. The trusted execution environment is isolated from the normal execution environment, has a higher level of security, and is suitable for processing sensitive data. In some embodiments, a normal execution environment can be deployed in the processing unit 120, and the normal execution environment can be formed by the default operating environment or the traditional operating environment of the computing device 110.
[0036] In some embodiments, processing unit 120 may include a first type of processing unit, and trusted execution environment 130 may be deployed in a second type of processing unit. The first type of processing unit and the second type of processing unit here may be formed by any appropriate different types of processing units. In some examples, processing unit 120 may include a graphics processing unit (GPU), and trusted execution environment 130 may be deployed in a central processing unit (CPU). In this way, processing unit 120 is suitable for performing relatively computationally intensive operations, and trusted execution environment 130 has a relatively high degree of trustworthiness and security.
[0037] In some embodiments of the present disclosure, a machine learning model 140 is deployed in the computing device 110 and can be executed in the computing device 110. In some embodiments, the machine learning model 140 may include multiple model layers. The multiple model layers are divided into two groups of model layers based on their computational intensity or privacy. Each group of model layers may include one or more model layers. In some embodiments, one group of model layers may include model layers 142-1, 142-2, ..., and 142-M, which have relatively high computational density, and another group of model layers may include model layers 144-1, 144-2, ..., and 144-N, which have relatively low computational density, where M and N are both positive integers. The first group of model layers may be deployed in the processing unit 120, and the other group of model layers may be deployed in the trusted execution environment 130. In some examples, the first group of model layers may include, but are not limited to, linear layers, and the other group of model layers may include, but are not limited to, activation layers, regularization layers, and the like. Of course, the above-mentioned model layer division method is merely exemplary, and any appropriate method can be selected to divide the multiple model layers of the machine learning model 140 according to actual needs. The embodiments of the present disclosure are not limited to this.
[0038] The machine learning model 140 can be different types of models. In some embodiments, the machine learning model 140 can be built based on a deep neural network or a language model (LM). In some embodiments, the machine learning model based on the large language model (LLM) can accept model inputs in textual modalities (e.g., natural language and / or machine language) and / or model inputs in non-textual modalities (e.g., images, voice, video, etc.), and can generate desired outputs based on the model inputs and prompt words. The prompt words here are used to guide the machine learning model to generate user needs that can solve the model inputs. In an application scenario for supporting user dialogue, the user's input can be provided to the machine learning model 140 as at least a part of the model input (the other part may include prompt words). Based on the model output, content corresponding to the user's input can be generated and provided to the user.
[0039] In some embodiments, the computing device 110 communicates with the server 150 to support the operation of the machine learning model 140. In some examples, the server 150 may be a server of the provider of the machine learning model 140, and the computing device 110 may be an electronic device of the user of the machine learning model 140. The computing device 110 may obtain the machine learning model 140 or the parameters necessary for the operation of the machine learning model 140 from the server 150. In some examples, the computing device 110 may be a terminal device or an edge device. In this case, the machine learning model 140 may be referred to as an end-side machine learning model. The terminal device may be any type of mobile terminal, fixed terminal, or portable terminal, including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an e-book device, a gaming device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some examples, the computing device 110 may also be a server, or a computing device in a cloud environment, and so on. It should be understood that the specific device type of computing device 110 may vary depending on the deployment method of machine learning model 140, and the embodiments of the present disclosure do not limit the device type of computing device 110. In some embodiments, server 150 can be various types of computing systems / servers capable of providing computing capabilities, including but not limited to mainframes, edge computing nodes, computing devices in cloud environments, etc. Server 150 can be implemented in a cloud environment, for example.
[0040] It should be understood that the structure and function of each element in environment 100 are described for exemplary purposes only and do not imply any limitation on the scope of the present disclosure. Although the processing unit and the trusted execution environment are shown as being in a computing device, it should be understood that this is merely exemplary. The processing unit and the trusted execution environment in the embodiments of the present disclosure can be deployed in any appropriate type of electronic device.
[0041] Example Process
[0042] Some example embodiments of the present disclosure will be described below with continued reference to the accompanying drawings. Figure 2 A flowchart of process 200 for securing a model according to some embodiments of the present disclosure is shown. Part or all of process 200 may be implemented by computing device 110, or by computing device 110 in conjunction with other devices, such as computing device 110 in conjunction with server 150. Below, for ease of discussion, the execution of process 200 is described from the perspective of computing device 110, but this is for exemplary purposes only.
[0043] In box 210, the computing device 110 obtains an input feature representation for a first model layer in the machine learning model 140. In some embodiments, the first model layer can be any one of the one or more model layers of the machine learning model 140 deployed in the processing unit 120. As an example, the first model layer can be any one of the model layers 142-1, 142-2, ..., and 142-M. For example, the first model layer can be a linear layer that is not deployed in a normal execution environment. Of course, the above-mentioned first model layer is only exemplary, and the first model layer can be any other appropriate model layer in the machine learning model 140. The embodiments of the present disclosure are not limited to this.
[0044] The first model layer may include a first weight tensor deployed in the processing unit 120 and a direction transformation parameter deployed in the trusted execution environment 130. The first weight tensor may be obtained by transforming the trained weight tensor of the first model layer using the direction transformation parameter. Specifically, after the machine learning model 140 is trained, each model layer of the machine learning model 140 has a corresponding trained weight tensor. Accordingly, the first model layer also has a corresponding trained weight tensor, which is a weight tensor that has not been obfuscated or transformed. The first weight tensor is obtained by transforming the direction of the trained weight tensor of the first model layer using the direction transformation parameter.
[0045] In some embodiments, the trained weight tensor may include a trained weight matrix, which may include a plurality of weight vectors. The first weight tensor may include a first weight matrix, which may include a plurality of weight vectors. As an example, Figure 3 FIG. 3 is a schematic diagram illustrating an example scenario 300 for protecting model security according to some embodiments of the present disclosure. Figure 3 As shown in 320, the trained weight tensor of the first model layer may include the trained weight matrix W vic , the trained weight matrix W vic Including weight vector Weight vector Weight vector and weight vector like Figure 3 As shown in 330, the first weight tensor may include a first weight matrix W obf , the first weight matrix W obf Can include weight vectors Weight vector Weight vector and weight vector It is understood that the first weight tensor is merely exemplary, and the dimension of the first weight tensor may be different when the type of the machine learning model 140 is different or the model layer is different. The embodiments of the present disclosure are not limited to this.
[0046] In some embodiments, the computing device 110 may receive the machine learning model 140 from the server 150. The computing device 110 may transform the trained weight tensor of the first model layer in the machine learning model 140 based on the direction transformation parameter to obtain a first weight tensor. Before performing an inference process using the machine learning model 140, the computing device 110 may deploy the first weight tensor of the first model layer to the processing unit 120. The computing device 110 may also deploy the direction transformation parameter of the first model layer to the trusted execution environment 130.
[0047] In other embodiments, the server 150 may transform the trained weight tensor of the first model layer in the machine learning model 140 based on the direction transformation parameter to obtain a first weight tensor. The server 150 may use the first weight tensor to replace the trained weight tensor of the first model layer in the machine learning model 140. Thereafter, the server 150 may provide the modified machine learning model 140 to the computing device 110.
[0048] The following uses the example of computing device 110 performing the transformation of the trained weight tensor into the first weight tensor to illustrate the transformation process from the trained weight tensor to the first weight tensor. However, it is understandable that the transformation process performed by computing device 110 below can also be performed by server 150.
[0049] In some embodiments, the computing device 110 can use a direction transformation parameter to transform the direction of the weight components of the trained weight tensor in each dimension to obtain a weight tensor after direction transformation. Afterwards, the computing device 110 can use a sequence transformation parameter to adjust the order of at least part of the weight components in the direction-transformed weight tensor in the direction-transformed weight tensor to obtain a first weight tensor. In this way, not only the direction of the weight components in each dimension of the trained weight tensor is adjusted, but also the order of the weight components is disrupted, so that the attacker cannot compare the direction similarity between the weight tensor of the model layer in the pre-trained model and the weight components in the first weight tensor, and cannot restore the order of the weight components based on the direction similarity, which can significantly improve the anti-attack capability of the machine learning model 140.
[0050] As an example, the trained weight tensor may include a trained weight matrix, which may be represented as The direction transformation parameter may include a direction transformation vector v. The computing device 110 may use the direction transformation vector v and the trained weight matrix W to calculate the direction transformation parameter.vic The weight vector for each dimension in Added to adjust the weight vector Afterwards, the computing device 110 may randomly shuffle the trained weight matrix W using the sequential transformation parameters. vic The order of the weight vectors on at least some dimensions in is used to obtain a first weight matrix (i.e., a first weight tensor). The first weight matrix can be expressed as, for example
[0051] In some embodiments, the computing device 110 may obtain tensor scaling information, which may include a first scaling factor and a second scaling factor corresponding to each dimension in the trained weight tensor. For a dimension in the trained weight tensor, the computing device 110 may adjust the size of the directional transformation parameter for the dimension using the first scaling factor corresponding to the dimension to obtain an adjusted directional transformation parameter. The computing device 110 may adjust the size of the weight component using the second scaling factor corresponding to the dimension to obtain an adjusted weight component. Thereafter, the computing device 110 may transform the direction of the adjusted weight component using the adjusted directional transformation parameter to obtain the weight component of the directional transformed weight tensor for the dimension. For each dimension in the trained weight tensor, the computing device 110 may repeat the above process to obtain the weight component of the directional transformed weight tensor for the corresponding dimension. In this way, not only the direction of each weight component can be adjusted, but also the size of each weight component can be adjusted, which can further increase the difficulty of restoring the first weight tensor and further improve the anti-attack capability of the machine learning model 140.
[0052] As an example, the trained weight tensor still includes the trained weight matrix For example, the computing device 110 may transform the trained weight matrix using the following formula to obtain a first weight matrix
[0053]
[0054] Wherein, v represents the direction transformation vector (i.e., the direction transformation parameter); represents the weight vector of the i-th dimension in the trained weight matrix; q i Represents The corresponding first scaling factor; p i Represents The corresponding second scaling factor; Π represents the order transformation parameter, which is used to randomly disrupt the order.
[0055] In some embodiments, the first model layer may be the first model layer of the machine learning model 140. In this case, the computing device 110 may determine an input feature representation for the first model layer based on the model input of the machine learning model 140 as the input feature representation of the first model layer.
[0056] In some embodiments, the first model layer may not be the first model layer of the machine learning model 140. In this case, the input feature representation of the first model layer can be the output feature representation corresponding to the second model layer before the first model layer in the machine learning model 140. If the processing of the second model layer is all executed in the processing unit 120, the computing device 110 can obtain the output feature representation of the second model layer from the processing unit 120 as the input feature representation for the first model layer. If part of the processing of the second model layer is executed in the trusted execution environment 130, and the output feature representation of the second model layer is generated in the trusted execution environment 130, the computing device 110 can transmit the output feature representation corresponding to the second model layer from the trusted execution environment 130 to the processing unit 120 as the input feature representation for the first model layer.
[0057] Return to Combine Figure 2 As shown, in block 220, the computing device 110 generates a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit 120. In some embodiments, the order transformation parameters of the first model layer may also be deployed in the trusted execution environment 130. The computing device 110 may process the input feature representation using the first weight tensor in the processing unit 120 to generate a second feature tensor. Thereafter, the computing device 110 may update the order of at least a portion of the components in the second feature tensor in the second feature tensor using the order transformation parameters in the trusted execution environment 130 to obtain the first feature tensor.
[0058] As an example, the first weight tensor may include a first weight matrix W obf In this example, the computing device 110 may generate the first feature tensor based on the following formula:
[0059] Y'=X·W obf (2)
[0060] Y"=Y'·Π -1 (3)
[0061] Among them, Y′ represents the second feature matrix (that is, the second feature tensor), X represents the input feature representation of the first model layer; Y″ represents the first feature matrix (that is, the first feature tensor), and Π represents the order transformation parameter. Specifically, the computing device 110 can generate the second feature matrix Y′ using the above formula (2) in a common execution environment, such as a GPU. Afterwards, the computing device 110 can restore the order of the feature vectors in each dimension of the second feature matrix Y′ using the above formula (3) based on the order transformation parameter in a TEE, such as a CPU, to obtain the first feature matrix Y". In this way, the intensive calculation process for the input feature representation is executed in a common execution environment, which can ensure the inference performance. The order restoration process of the feature vectors in the second feature matrix Y′ is executed in the TEE, which can avoid the leakage of the order transformation parameter.
[0062] Continue to combine Figure 2 As shown, in box 230, the computing device 110 may transmit the input feature representation and the first feature tensor from the processing unit 120 to the trusted execution environment 130. Here, the data transmission between the processing unit 120 and the trusted execution environment 130 may be implemented through any appropriate communication mechanism. In some examples, the computing device 110 may utilize a communication channel such as a bus to transmit the input feature representation and the first feature tensor from the processing unit 120 to the trusted execution environment 130. In other examples, the computing device 110 may also utilize, for example, a shared storage space between the processing unit 120 and the trusted execution environment 130 to implement the transmission of the input feature representation and the first feature tensor. It is understandable that when the device type and system architecture of the computing device 110 are different, the data transmission method between the processing unit 120 and the trusted execution environment 130 may be different. The embodiments of the present disclosure are not limited to this.
[0063] At block 240, computing device 110, in trusted execution environment 130, processes the input feature representation using the directional transformation parameters to generate a directional correction tensor. The directional correction tensor is used to correct the direction of the first feature tensor. It will be appreciated that the specific process of processing the input feature representation using the directional transformation parameters here depends primarily on the process of transforming the trained weight tensor using the directional transformation parameters. Depending on the process of processing the trained weight tensor using the directional transformation parameters, the process of processing the input feature representation using the directional transformation parameters here may also be different.
[0064] In some embodiments, the direction transformation parameter may include a direction transformation vector v, and the computing device 110 may generate a direction correction tensor in the TEE based on the following formula:
[0065] R v =X·v (4)
[0066] Among them, Rv represents the direction correction vector (ie, the direction correction tensor); X represents the input feature representation. Of course, the above processing process is only exemplary, and the embodiments of the present disclosure are not specifically limited in this regard.
[0067] At block 250, the computing device 110, in the trusted execution environment 130, corrects the first feature tensor based on the direction correction tensor to determine an output feature representation corresponding to the first model layer. It is understood that the process of correcting the first feature tensor based on the direction correction tensor mainly depends on the process of processing the trained weight tensor using the direction transformation parameters. In the case where the process of processing the trained weight tensor using the direction transformation parameters is different, the process of correcting the first feature tensor using the direction correction tensor may be different. The embodiments of the present disclosure are not limited to this.
[0068] In some embodiments, as described in the above analysis, the direction of the weight component of each dimension of the trained weight tensor can be adjusted using the direction transformation parameter to obtain a first weight tensor. On this basis, the computing device 110 can use the direction correction tensor in the trusted execution environment 130 to correct the direction of the feature component on each dimension of the first feature tensor to determine the output feature representation corresponding to the first model layer. As an example, the computing device 110 can use the direction correction vector R in the TEE v , correct the eigenvector on each dimension in the first feature matrix Y″ to obtain the eigenvector on the corresponding dimension in the output feature matrix.
[0069] In some embodiments, the trained weight tensor of the first model layer can be adjusted using the direction transformation parameter and the tensor scaling information to obtain the first weight tensor of the first model layer. Based on this, the computing device 110 can, in the trusted execution environment 130, correct the direction and magnitude of the feature components of the first feature tensor in each dimension based on the direction correction tensor and the tensor scaling information to obtain the output feature representation of the first model layer.
[0070] In some embodiments, the tensor scaling information includes a first scaling factor and a second scaling factor corresponding to the feature component in each dimension of the first feature tensor. Computing device 110 may use the first scaling factor corresponding to the feature component in that dimension to adjust the size of the direction-corrected tensor for that dimension. Computing device 110 may use the adjusted direction-corrected tensor to correct the direction of the feature component to obtain a corrected feature component. Computing device 110 may then use the second scaling factor to adjust the size of the corrected feature component.
[0071] As an example, the first feature tensor may include a first feature matrix Y″=[y″1, y″2, ..., y″ n ],y″ iRepresents the eigenvector of the i-th dimension in the first feature matrix Y″. The tensor scaling information can include i The corresponding first scaling factor q i and the second scaling factor p i In this case, the computing device 110 may determine the feature vector of the i-th dimension in the output feature representation using the following formula in the TEE:
[0072] y i =(y″ i -q i ·R v ) / p i (5)
[0073] It is understandable that the computing device 110 can use formula (5) to process the feature vectors on each dimension in the first feature matrix to obtain the output feature representation of the first model layer.
[0074] In some embodiments, the first model layer may be the last model layer in the machine learning model 140. In this case, the output feature representation of the first model layer is the model output of the machine learning model 140. The computing device 110 may use the output feature representation of the first model layer as the model output of the machine learning model 140.
[0075] In some embodiments, the first model layer may not be the last processing layer of the machine learning model 140. In this case, the computing device 110 may provide the output feature representation corresponding to the first model layer from the trusted execution environment 130 to the processing unit 120 as the input feature representation for the next processing layer after the first model layer in the machine learning model 140. It should be noted that the machine learning model 140 may have multiple processing layers deployed in the trusted execution environment 120. During each inference process of the machine learning model 140, the computing device 110 may need to repeatedly perform the above process 200 multiple times.
[0076] With the development of machine learning model-related technologies, many open source databases provide pretrained machine learning models. Developers can obtain pretrained machine learning models from these open source databases. By constructing a training dataset based on specific task requirements and using it to fine-tune the parameters of the pretrained machine learning model, a machine learning model can be obtained that meets specific task requirements. This not only shortens the training cycle but also saves computing resources, helping to reduce training costs. By observing machine learning models fine-tuned using pretrained machine learning models, it is found that the directions of the weight tensors in the trained machine learning model are highly similar to those in the pretrained model. This similarity can be easily exploited by attackers to attack on-device machine learning models.
[0077] In view of this, some embodiments of the present disclosure further provide a model testing solution for testing the anti-attack capabilities of the machine learning model 140. Part or all of the model testing process can be implemented by the computing device 110, implemented by the computing device 110 and other devices, or implemented by other devices, such as the server 150. Below, for ease of discussion, the execution of the process is described from the perspective of the computing device 110, but this is merely exemplary.
[0078] In some embodiments of the present disclosure, the computing device 110 may determine a pre-trained weight tensor and a confused weight tensor of a first model layer of a machine learning model 140. In some embodiments, the computing device 110 may determine the type of the machine learning model 140 being tested. Based on the type of the machine learning model 140, a pre-trained machine learning model 140 is obtained from a public database. Thereafter, the computing device 110 may obtain the pre-trained weight tensor of the first model layer in the pre-trained machine learning model 140 and the confused weight tensor of the first model layer in the trained machine learning model 140. The confused weight tensor here refers to a weight tensor obtained after performing obfuscation processing on the trained weight tensor of the first model layer. For example, the confused weight tensor may include the first weight tensor of the first model layer.
[0079] As an example, Figure 3 As shown in 310, it is assumed that the pre-trained weight tensor corresponding to the first model layer in the pre-trained machine learning model 140 includes the pre-trained weight matrix Pre-trained weight matrix W pre Including weight vector Weight vector Weight vector and weight vector like Figure 3 As shown in 320, the trained weight tensor of the first model layer may include the trained weight matrix W vic , the trained weight matrix W vic Including weight vector Weight vector Weight vector and weight vector Obviously, the direction and magnitude of the weight vectors in the trained weight matrix have changed compared to the pre-trained weight matrix. However, the direction and magnitude of the weight vectors in the trained weight matrix are still highly similar to those in the pre-trained weight matrix.
[0080] like Figure 3 As shown in 330, the confusion weight tensor may include a confusion weight matrix W obf , confusion weight matrix Wobf Can include weight vectors Weight vector Weight vector and weight vector Obviously, if we only adjust the order and size of the weight vectors, the directional similarity between the obfuscated weight vectors and the pre-trained weight vectors is preserved.
[0081] In some embodiments of the present disclosure, the computing device 110 determines the correspondence between the weight components on each dimension in the pre-trained weight tensor and the weight components on each dimension in the first weight tensor. In some embodiments, the computing device 110 may determine the correspondence between the weight components on each dimension in the pre-trained weight tensor and the weight components on each dimension in the first weight tensor based on the directional similarity between the weight components on each dimension in the pre-trained weight tensor and the weight components on each dimension in the first weight tensor. Thereafter, based on the directional similarity, determine the correspondence between the weight components on each dimension in the pre-trained weight tensor and the weight components on each dimension in the first weight tensor.
[0082] As an example, Figure 3 As shown, the computing device 110 can determine the vector direction of each weight vector in the pre-trained matrix. The computing device 110 can also determine the vector direction of each weight vector in the confusion weight matrix. Thereafter, the computing device 110 can use the mapping function σ(·) as shown below to determine the mapping relationship between the weight vector in the pre-trained matrix and the weight vector in the confusion weight matrix:
[0083]
[0084] Among them, σ(i) represents the direction similarity; Represents the vector direction of the weight vector of the i-th dimension in the pre-training matrix; Represents the vector direction of the weight vector of the i-th dimension in the confusion weight matrix; express and Direction Distance, indicating and Specifically, the computing device 110 can use formula (6) to determine a pair of weight vectors with the smallest directional distance from the pre-trained weight matrix and the confusion weight matrix, and then determine that there is a mapping relationship between the pair of weight vectors. For example, according to Figure 3 The mapping relationship shown in 340 determines the result, the weight vector Mapping to weight vector Weight vector Mapping to weight vector Weight vector Mapping to weight vector Weight vector Mapping to weight vector
[0085] In some embodiments of the present disclosure, the computing device 110 adjusts the order of the weight components on at least some dimensions in the obfuscated weight tensor based on the corresponding relationship to obtain a restored weight tensor. Specifically, the computing device 110 may adjust the order of the weight components on at least some dimensions in the obfuscated weight tensor based on the order of the weight components of each dimension in the pre-trained weight tensor and the corresponding relationship to obtain a restored weight tensor. As an example, Figure 3 As shown, the computing device 110 can adjust the confusion weight matrix based on the corresponding relationship The order of the weight vectors in the , to obtain the restored weight matrix The weight vector With the weight vector Correspondingly, the weight vector With the weight vector Correspondingly, the weight vector With the weight vector Correspondingly, the weight vector With the weight vector Corresponding.
[0086] In some embodiments of the present disclosure, the computing device 110 determines an evaluation result of the anti-attack capability of the machine learning model 140 based on the restored weight tensor and the trained weight tensor of the first model layer. In some embodiments, the computing device 110 may compare the directional similarity and size similarity between the weight component of each dimension in the restored weight tensor and the weight component of each dimension in the trained weight tensor. Thereafter, the computing device 110 may determine an evaluation result of the anti-attack capability of the machine learning model 140 based on the directional similarity and size similarity. Specifically, if the directional similarity and size similarity are higher, it indicates that the anti-attack capability of the machine learning model 140 is lower. If the directional similarity and size similarity are lower, it indicates that the anti-attack capability of the machine learning model 140 is higher.
[0087] In some embodiments, computing device 110 may determine a restoration coefficient based on a ratio between a pair of weight components having a mapping relationship in the pre-trained weight tensor and the obfuscated weight tensor, and determine a weight component of a corresponding dimension in the restored weight tensor based on the restoration coefficient and the weight component of the corresponding dimension in the obfuscated weight tensor.
[0088] As an example, computing device 110 may determine the restitution coefficient based on the following formula:
[0089]
[0090] in, represents the coefficient of restitution; Represents the weight vector length; Represents the weight vector length.
[0091] The computing device 110 may also determine the weight components of each dimension in the restored weight tensor based on the following formula:
[0092]
[0093] Specifically, the computing device 110 can obtain the restored weight matrix based on the above formula (7) and formula (8):
[0094] In some embodiments, computing device 110 may also train machine learning model 140 using the sample set to adjust the restored weight tensor of the first model layer. Computing device 110 may then determine an assessment result of the attack resistance of machine learning model 140 based on the adjusted restored weight tensor and the trained weight tensor.
[0095] As an example, the computing device 110 may obtain a plurality of input samples. The computing device 110 may provide the plurality of input samples to the machine learning model 140 including the confusion weight tensor, and obtain the output result of the machine learning model 140 as a plurality of output samples corresponding to the plurality of input samples to form a sample set. The computing device 110 may use the sample set to adjust the recovered weight matrix of the first model layer The computing device 110 may recover the weight matrix and the trained weight matrix The direction similarity and size similarity between the corresponding weight vectors in . Furthermore, the evaluation result of the anti-attack capability of the machine learning model 140 can be determined.
[0096] It is understandable that the above example only uses the first model layer as an example to illustrate the evaluation result of the anti-attack capability of the machine learning model 140. In actual application, the restored weight tensors and trained weight tensors of multiple processing layers of the machine learning model 140 can be combined to determine the evaluation result of the anti-attack capability of the machine learning model 140. For example, the restored weight tensors and trained weight tensors of multiple processing layers in the machine learning model 140 that need to be deployed in the processing unit can be combined to determine the evaluation result of the anti-attack capability of the machine learning model 140.
[0097] In this way, in an embodiment of the present disclosure, the first weight tensor deployed in the processing unit is obtained by obfuscating the direction transformation parameters, which can effectively protect the direction information of the trained weight tensor. In a trusted execution environment, it is only necessary to use the direction transformation parameters to process the input feature representation to generate a direction correction tensor. The direction correction tensor is then used to correct the direction of the first feature tensor. In this way, the amount of computation in the trusted execution environment is relatively small, and the inference speed is relatively fast, which can achieve the goal of balancing the privacy security and inference performance of the model.
[0098] Example devices and equipment
[0099] The embodiments of the present disclosure also provide corresponding devices for implementing the above methods or processes. Figure 4 1 shows a schematic structural block diagram of an example apparatus 400 for protecting model security according to certain embodiments of the present disclosure. Apparatus 400 may be implemented as or included in computing device 110. Each module / component in apparatus 400 may be implemented by hardware, software, firmware, or any combination thereof.
[0100] like Figure 4 As shown, the device 400 includes: an acquisition module 410, configured to obtain an input feature representation for a first model layer in a machine learning model, the first model layer including a direction transformation parameter deployed in a trusted execution environment of a computing device and a first weight tensor deployed in a processing unit outside the trusted execution environment, the first weight tensor being obtained by transforming the trained weight tensor of the first model layer using the direction transformation parameter; a generation module 420, configured to generate a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit; a transmission module 430, configured to transmit the input feature representation and the first feature tensor to the trusted execution environment; a processing module 440, configured to process the input feature representation using the direction transformation parameter in the trusted execution environment to generate a direction correction tensor; and a correction module 450, configured to correct the first feature tensor based on the direction correction tensor in the trusted execution environment to determine an output feature representation corresponding to the first model layer.
[0101] In some embodiments, the processing unit includes a first type of processing unit, and the trusted execution environment is deployed in a second type of processing unit.
[0102] In some embodiments, the acquisition module 410 is further configured to: in the processing unit, receive from the trusted execution environment an output feature representation corresponding to a second model layer before the first model layer in the machine learning model as an input feature representation for the first model layer.
[0103] In some embodiments, the generation module 420 is further configured to: in a processing unit, process the input feature representation using a first weight tensor to generate a second feature tensor; and in a trusted execution environment, update the order of at least a portion of the components in the second feature tensor in the second feature tensor using a sequence transformation parameter to obtain a first feature tensor, and the sequence transformation parameter is deployed in the trusted execution environment.
[0104] In some embodiments, the correction module 450 is further configured to: in a trusted execution environment, based on the direction correction tensor and tensor scaling information, correct the direction and size of the feature components of the first feature tensor in each dimension to obtain the output feature representation of the first model layer.
[0105] In some embodiments, the tensor scaling information includes a first scaling factor and a second scaling factor corresponding to the feature component on each dimension of the first feature tensor, and the correction module 450 is further configured to: adjust the size of the direction correction tensor for the dimension using the first scaling factor corresponding to the feature component on the dimension; correct the direction of the feature component using the adjusted direction correction tensor to obtain a corrected feature component; and adjust the size of the corrected feature component using the second scaling factor.
[0106] In some embodiments, the device 400 also includes: a providing module configured to provide the output feature representation corresponding to the first model layer from the trusted execution environment to the processing unit as an input feature representation for the third model layer after the first model layer in the machine learning model.
[0107] In some embodiments, the device 400 also includes: an acquisition module, configured to obtain a first weight tensor in the following manner: using a direction transformation parameter to transform the direction of the weight component of the trained weight tensor in each dimension to obtain a weight tensor after direction transformation; and using an order transformation parameter to adjust the order of at least part of the weight components in the direction-transformed weight tensor in the direction-transformed weight tensor to obtain a first weight tensor.
[0108] In some embodiments, the acquisition module is further configured to: adjust the size of the directional transformation parameter for the dimension using a first scaling factor corresponding to the dimension in the tensor scaling information to obtain an adjusted directional transformation parameter; adjust the size of the weight component using a second scaling factor corresponding to the dimension in the tensor scaling information to obtain an adjusted weight component; and transform the direction of the adjusted weight component using the adjusted directional transformation parameter to obtain the weight component of the directionally transformed weight tensor on the dimension.
[0109] The units and / or modules included in the device 400 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units and / or modules can be implemented using software and / or firmware, such as machine executable instructions stored on a storage medium. In addition to or as an alternative to machine executable instructions, some or all of the units and / or modules in the device 500 can be implemented at least in part by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0110] Figure 5 1 shows a block diagram of an electronic device 500 in which one or more embodiments of the present disclosure may be implemented. It should be understood that Figure 5 The illustrated electronic device 500 is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 5 The electronic device 500 shown may include or be implemented as Figure 1 computing device 110, or Figure 4 device 400.
[0111] like Figure 5 As shown, electronic device 500 is in the form of a general electronic device. Components of electronic device 500 may include, but are not limited to, one or more processors 510, memory 520, storage device 530, one or more communication units 540, one or more input devices 550, and one or more output devices 560. Processor 510 may be a real or virtual processor and is capable of performing various processes according to executable instructions stored in memory 520. In a multi-processor system, multiple processors execute computer-executable instructions in parallel to improve the parallel processing capabilities of electronic device 500.
[0112] The electronic device 500 typically includes a plurality of computer storage media. Such media can be any accessible media that can be obtained by the electronic device 500, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 520 can be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 530 can be a removable or non-removable medium and can include a machine-readable medium, such as a flash drive, a disk, or any other medium that can be used to store information and / or data and can be accessed within the electronic device 500.
[0113] The electronic device 500 may further include additional removable / non-removable, volatile / non-volatile storage media. Figure 5 As shown in FIG, a disk drive for reading from or writing to a removable, non-volatile disk (e.g., a "floppy disk") and an optical drive for reading from or writing to a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data media interfaces. The memory 520 may include a computer program product 525 having one or more executable instruction modules configured to perform various methods or actions of various embodiments of the present disclosure.
[0114] The communication unit 540 enables communication with other electronic devices via a communication medium. Additionally, the functions of the components of the electronic device 500 can be implemented in a single computing cluster or multiple computing machines that can communicate via a communication connection. Thus, the electronic device 500 can operate in a networked environment using a logical connection with one or more other servers, a network personal computer (PC), or another network node.
[0115] Input device 550 may be one or more input devices, such as a mouse, keyboard, or trackball. Output device 560 may be one or more output devices, such as a display, a speaker, or a printer. Electronic device 500 may also communicate with one or more external devices (not shown) via communication unit 540 as needed, such as a storage device, a display device, or the like, with one or more devices that allow a user to interact with electronic device 500, or with any device that allows electronic device 500 to communicate with one or more other electronic devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).
[0116] According to an exemplary implementation of the present disclosure, a computer-readable storage medium is provided, on which computer-executable instructions are stored, wherein the computer-executable instructions are executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer-executable instruction product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the method described above.
[0117] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatuses, devices, and computer-executable instruction products implemented according to the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable executable instructions.
[0118] These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-executable instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture, which includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.
[0119] Computer-executable instructions can be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0120] The flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the systems, methods and computer-executable instruction products according to multiple implementations of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, executable instruction or part of an instruction, and the module, executable instruction or part of an instruction contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0121] While various implementations of the present disclosure have been described above, the foregoing description is intended to be illustrative, not exhaustive, and not limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is selected to best explain the principles of the implementations, their practical applications, or improvements to existing technologies, or to enable others skilled in the art to understand the various implementations disclosed herein.
Claims
1. A method for protecting model security, comprising: Obtaining an input feature representation for a first model layer in a machine learning model, the first model layer comprising a direction transformation parameter deployed in a trusted execution environment of a computing device and a first weight tensor deployed in a processing unit outside the trusted execution environment, the first weight tensor being obtained by transforming a trained weight tensor of the first model layer using the direction transformation parameter; generating a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit; transmitting the input feature representation and the first feature tensor to the trusted execution environment; In the trusted execution environment, processing the input feature representation using the orientation transformation parameters to generate an orientation correction tensor; as well as In the trusted execution environment, the first feature tensor is modified based on the direction correction tensor to determine an output feature representation corresponding to the first model layer. 2 . The method of claim 1 , wherein the processing unit comprises a first type of processing unit and the trusted execution environment is deployed in a second type of processing unit.
3. The method according to claim 1, wherein obtaining the input feature representation for the first model layer comprises: In the processing unit, an output feature representation corresponding to a second model layer preceding the first model layer in the machine learning model is received from the trusted execution environment as an input feature representation for the first model layer.
4. The method of claim 1 , wherein generating the first feature tensor for the first model layer comprises: In the processing unit, the input feature representation is processed using the first weight tensor to generate a second feature tensor; as well as In the trusted execution environment, an order transformation parameter is used to update the order of at least a portion of the components in the second feature tensor to obtain the first feature tensor, and the order transformation parameter is deployed in the trusted execution environment.
5. The method of claim 1 , wherein modifying the first feature tensor based on the direction modification tensor comprises: In the trusted execution environment, based on the direction correction tensor and tensor scaling information, the direction and size of the feature components of the first feature tensor in each dimension are corrected to obtain the output feature representation of the first model layer.
6. The method according to claim 5, wherein the tensor scaling information comprises a first scaling factor and a second scaling factor corresponding to a feature component in each dimension of the first feature tensor, and correcting the direction and magnitude of the feature component in each dimension of the first feature tensor comprises: Adjusting the size of the direction correction tensor for the dimension using a first scaling factor corresponding to the feature component in the dimension; Correcting the direction of the characteristic component using the adjusted direction correction tensor to obtain a corrected characteristic component; as well as The second scaling factor is used to adjust the size of the modified characteristic component.
7. The method according to claim 1, further comprising: An output feature representation corresponding to the first model layer is provided from the trusted execution environment to the processing unit as an input feature representation for a third model layer following the first model layer in the machine learning model.
8. The method according to claim 1, wherein the first weight tensor is obtained by: transforming the direction of the weight component of each dimension of the trained weight tensor using the direction transformation parameter to obtain a direction-transformed weight tensor; and The order of at least part of the weight components in the direction-transformed weight tensor is adjusted using an order transformation parameter to obtain the first weight tensor.
9. The method of claim 8, wherein transforming the direction of the weight components of the trained weight tensor in each dimension comprises: adjusting the magnitude of the directional transformation parameter for the dimension using a first scaling factor corresponding to the dimension in the tensor scaling information to obtain an adjusted directional transformation parameter; adjusting the magnitude of the weight component using a second scaling factor corresponding to the dimension in the tensor scaling information to obtain an adjusted weight component; as well as The adjusted direction transformation parameter is used to transform the direction of the adjusted weight component to obtain the weight component of the direction-transformed weight tensor in the dimension.
10. A device for protecting the safety of a model, comprising: an acquisition module configured to acquire an input feature representation for a first model layer in a machine learning model, wherein the first model layer includes a direction transformation parameter deployed in a trusted execution environment of a computing device and a first weight tensor deployed in a processing unit outside the trusted execution environment, wherein the first weight tensor is obtained by transforming a trained weight tensor of the first model layer using the direction transformation parameter; a generation module configured to generate a first feature tensor for the first model layer by at least processing the input feature representation using the first weight tensor in the processing unit; a transmission module, configured to transmit the input feature representation and the first feature tensor to the trusted execution environment; a processing module configured to process the input feature representation using the direction transformation parameters in the trusted execution environment to generate a direction correction tensor; as well as A correction module is configured to correct the first feature tensor based on the direction correction tensor in the trusted execution environment to determine an output feature representation corresponding to the first model layer.
11. An electronic device comprising: at least one processor; as well as At least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 9 when executed by the at least one processor. 12 . A computer-readable storage medium having computer-executable instructions stored thereon, wherein the computer-executable instructions can be executed by a processor to implement the method according to claim 1 .
13. A computer program product comprising computer executable instructions, wherein the computer executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Machine learning task management method and related device
CN111612168A
Model training method and device and business prediction method and device
CN113159316A
Pedestrian image quality evaluation method, apparatus and device, and readable storage medium
CN116092123A
Image splicing method and device based on foreground and background segmentation
CN119444559A
Audio driven facial animation using machine learning
CN119494894A
Cited By
Data encryption processing method and device, server and storage medium
CN121239475A