Model loading method and device and electronic equipment

By encrypting and decrypting local data of neural network models, the problem of model theft and data leakage on mobile terminals is solved, and an efficient model loading process is achieved.

CN120929151APending Publication Date: 2025-11-11LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511053204.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-29
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Neural network models on mobile user terminals are at risk of being stolen and leaked because they are not encrypted, while global encryption can affect system performance.

Method used

A partial encryption method is used to encrypt a portion of the data in the neural network model and then decrypt it in a secure execution environment, loading the model in stages.

Benefits of technology

It effectively prevents model theft and data leakage, while maintaining system performance and improving model loading speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120929151A_ABST
    Figure CN120929151A_ABST
Patent Text Reader

Abstract

The invention discloses a model loading method and apparatus, and an electronic device. The method comprises the steps of obtaining first data corresponding to a target model; loading the target model based on first data; in the process of loading the target model based on the first data, obtaining second data corresponding to the target model and sending the second data to the secure execution environment for decryption to obtain third data; loading the target model based on the third data; wherein the target model loading stage at least comprises a first loading stage and a second loading stage, the first data corresponds to the first loading stage, and the third data corresponds to the second loading stage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and in particular to a model loading method, apparatus, and electronic device. Background Technology

[0002] On mobile user terminals, neural network models and data are often not protected for privacy. Furthermore, due to the large memory size of neural network models, encryption is often omitted to ensure timely loading and avoid impacting system performance. This creates opportunities for theft of neural network models and data leakage. Summary of the Invention

[0003] The purpose of this application is to provide a model loading method, including:

[0004] Obtain the first data corresponding to the target model;

[0005] The target model is loaded based on the first data;

[0006] During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and sent to the secure execution environment for decryption to obtain the third data;

[0007] The target model is loaded based on the third data;

[0008] The target model loading stage includes at least a first loading stage and a second loading stage, wherein the first data corresponds to the first loading stage and the third data corresponds to the second loading stage.

[0009] In some embodiments, it also includes:

[0010] During the process of loading the target model based on the third data, the fourth data corresponding to the target model is obtained and sent to the secure execution environment for decryption to obtain the fifth data;

[0011] The target model is loaded based on the fifth data;

[0012] The target model loading stage further includes a third loading stage, and the fifth data corresponds to the third loading stage.

[0013] In some embodiments, the second data is encrypted in a first encryption stage, and the fourth data is encrypted in a second encryption stage, wherein the first encryption stage is different from the second encryption stage.

[0014] In some embodiments, the second data corresponds to the first key, the fourth data corresponds to the second key, and the first key is different from the second key.

[0015] In some embodiments, it also includes:

[0016] Obtain the sixth data;

[0017] The sixth data is sent to a secure execution environment for decryption to obtain the seventh data, which is used for loading in the first loading stage and / or the second loading stage.

[0018] In some embodiments, the second data includes a first part and a second part, wherein the first part is not encrypted and the second part is encrypted;

[0019] During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and sent to a secure execution environment for decryption to obtain the third data, including:

[0020] During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and the second part of the second data is sent to the secure execution environment for decryption to obtain the decrypted second part.

[0021] The first part is combined with the decrypted second part to obtain the third data.

[0022] In some embodiments, obtaining the first data corresponding to the target model includes:

[0023] Get the eighth data;

[0024] The eighth data is sent to a secure execution environment for decryption to obtain the first data.

[0025] In some embodiments, when the target model is a first model, the second data corresponding to the first model includes a first object;

[0026] When the target model is the second model, the second data corresponding to the second model includes the second object;

[0027] The first model is different from the second model, and the first object is different from the second object.

[0028] This application embodiment also provides a model loading device, the device comprising:

[0029] The first acquisition unit is configured to acquire the first data corresponding to the target model;

[0030] The first loading unit is configured to load the target model based on the first data;

[0031] The second acquisition unit is configured to acquire second data corresponding to the target model during the process of loading the target model based on the first data and send the second data to a secure execution environment for decryption to obtain the third data;

[0032] The second loading unit is configured to load the target model based on the third data;

[0033] The target model loading stage includes at least a first loading stage and a second loading stage, wherein the first data corresponds to the first loading stage and the third data corresponds to the second loading stage.

[0034] This application also provides an electronic device, including a memory and a processor, wherein the memory stores an executable program, and the processor is used to execute:

[0035] Obtain the first data corresponding to the target model;

[0036] The target model is loaded based on the first data;

[0037] During the process of loading the target model based on the first data, second data corresponding to the target model is obtained and sent to a secure execution environment for decryption to obtain third data; the target model is then loaded based on the third data.

[0038] The target model loading stage includes at least a first loading stage and a second loading stage, wherein the first data corresponds to the first loading stage and the third data corresponds to the second loading stage. Attached Figure Description

[0039] Figure 1 This is a flowchart of the model loading method according to an embodiment of this application;

[0040] Figure 2 This is a structural block diagram of the data decryption method in an embodiment of this application;

[0041] Figure 3 This is a flowchart illustrating the decryption process for one of the encryption methods described in this application.

[0042] Figure 4 This is a structural block diagram of the model loading device of this application;

[0043] Figure 5 This is a structural block diagram of the electronic device of this application. Detailed Implementation

[0044] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0045] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0046] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0047] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0048] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.

[0049] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.

[0050] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.

[0051] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.

[0052] To address the problems in the background technology, one solution is to encrypt only the user data related to the neural network model, without encrypting the neural network model itself, in order to ensure system performance. However, the neural network model using this method is still at risk of being stolen. Another solution is to encrypt both the data and the entire neural network model to prevent its theft. However, this method may result in excessively long loading times for the neural network model, severely impacting system performance.

[0053] Unlike the existing solutions mentioned above, the model loading method provided in this application performs local encryption on the model, that is, it encrypts one or more parts of the model. This not only prevents the neural network model from being stolen, but also avoids the neural network model from taking too long to load, thus ensuring the performance of the system.

[0054] Combination Figure 1 This application provides a model loading method, which includes the following steps:

[0055] S10, Obtain the first data corresponding to the target model.

[0056] For example, the target model can be a neural network model using PyTorch or Transformers, or it can be a neural network model using other learning frameworks. (Combined) Figure 2 The first data corresponding to the target model can be stored in the conventional operating system environment (REE) of the mobile terminal device, such as on the REE's disk or memory. REE can refer to the Android or iOS system of the mobile terminal device. REE can run ordinary applications; here, ordinary applications can be understood as applications with no or low security requirements. Because the applications running in REE are diverse and complex, and have a large attack surface, they are not suitable for processing data with high security requirements or sensitive data (such as encryption keys).

[0057] Mobile terminal devices can be, but are not limited to, mobile phones, iPads, wearable devices, etc.

[0058] The first data can be part of the target model. In some embodiments, the first data may not be encrypted, meaning that the acquired first data can be directly used to load the target model.

[0059] The target model loading phase includes at least a first loading phase and a second loading phase, with the first data corresponding to the first loading phase.

[0060] S20, Load the target model based on the first data.

[0061] For example, after obtaining the first data, the first loading stage of the target model can be performed based on the first data.

[0062] The first loading phase may include a configuration file loading phase, where the first data can be a portion of the target model segmented for the configuration file loading phase. For example, to complete a task using the target model, it can be divided into two or more steps. The target model can be segmented into two or more parts, one for each step. Here, the first loading phase can load the model portion needed for the first step of the task. The configuration file loading phase can load the model structure, hyperparameters (such as the number of layers, hidden dimensions, activation functions, etc.). The first loading phase may also include a model initialization phase. Of course, the first loading phase can include both the configuration file loading phase and the initialization phase simultaneously. That is, the first loading phase is not a single phase, but a combination of multiple phases.

[0063] The first data is a portion of the target model segmented from the target model corresponding to the first loading stage.

[0064] S30, during the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and sent to the secure execution environment for decryption to obtain the third data.

[0065] For example, during the process of loading the target model based on the first data, second data corresponding to the target model can be obtained. The second data can be encrypted data, and the encrypted second data can also be stored in the REE, such as on the REE's disk or memory. (Re-combined...) Figure 2 The second data stored on the disk can be loaded into memory and then sent to the TEE for decryption. Here, the second data refers to the other parts segmented from the target model. The encryption of the second data can be performed before, during, or after the acquisition of the first data, or during the loading of the target model based on the first data. In short, the encryption process of the second data and the loading process of the target model can be performed simultaneously without affecting each other, which can speed up the encryption and decryption process of the target model and improve the loading process.

[0066] After obtaining the second data, it can be sent to a Secure Execution Environment (TEE) for decryption. Since the TEE has a high level of security, it can decrypt the encrypted second data and ensure the security of the decrypted second data. This avoids the theft of the target model due to the data being loaded not being encrypted, and may also cause leakage of user data.

[0067] For example, there is at least one trusted application (TA) in the TEE. The TA can hold a platform key injected during the factory production process. Based on the platform key and the set decryption algorithm (such as AES ECB symmetric encryption algorithm), the second data sent to the TEE can be decrypted, and the plaintext obtained after decryption is the third data.

[0068] In other words, this application only encrypts a part of the target model, rather than encrypting the entire target model. Therefore, the data encryption and decryption processes can complement each other. Data can be decrypted while encrypting a portion of the data, which speeds up the encryption and decryption process of the target model and also improves the deployment and loading speed of the target model.

[0069] In addition, this application can acquire the second data while loading the target model based on the first data, and realize the sending and decryption of the second data, thus preparing for the second loading stage of the target model and improving the overall loading speed of the target model.

[0070] In some embodiments, if a target model is loaded in the REE, the obtained third data can be sent back to the REE, and the second data in the REE can be replaced with the third data.

[0071] S40, Load the target model based on the third data.

[0072] For example, the third data is the data corresponding to the second loading stage of the target model, based on which the second loading stage of the target model can be performed.

[0073] For example, continuing with the above embodiments, the second loading stage can be the pre-trained weight loading stage following the first loading stage (including the configuration file loading stage and the initialization stage). The pre-trained weight loading stage requires third data, and the target model can be loaded with pre-trained weights based on this third data.

[0074] When encrypting a segment of the target model, you can select the key parts of the target model for encryption. Since the target model is loaded and run as a whole, if you select the key parts for encryption, you can prevent the target model from being directly stolen.

[0075] This application embodiment encrypts a portion of the target model, preventing the unencrypted target model from being directly stolen, and ensuring that loading the target model does not affect system performance.

[0076] In some embodiments, the model loading method further includes:

[0077] S50, during the process of loading the target model based on the third data, the fourth data corresponding to the target model is obtained and the fourth data is sent to the secure execution environment for decryption to obtain the fifth data.

[0078] For example, the target model loading stage may also include a third loading stage. After the second loading stage of the target model is completed, the third loading stage can be performed. For instance, if the target model has inference capabilities and can be used for result inference, then the third loading stage could be an inference stage.

[0079] During the second loading stage of loading the target model based on the third data, fourth data corresponding to the target model can be obtained. This fourth data can be a portion of the target model stored on the REE disk or in memory, used for executing the push streaming process. For target models with inference capabilities, the inference portion is a critical part; therefore, the fourth data can be encrypted. The encryption of the fourth data can occur during the first and / or second loading stages of loading the target model, or it can occur before the first loading stage. That is, the encryption of the fourth data and the loading of the target model can be performed synchronously. Obtaining the fourth data during the loading of the target model based on the third data and sending it to the TEE for decryption allows the decryption process to also be synchronized with the loading of the target model. In other words, both the encryption and decryption of the fourth data can be performed simultaneously with the loading of the target model, accelerating the encryption and decryption process and improving the deployment and loading speed of the target model.

[0080] After decrypting the fourth data in the TEE, the fifth data is obtained. That is, the fifth data is the decrypted data of the fourth data. The fifth data corresponds to the third loading stage of the target model, that is, the fifth data can be used for loading the third stage of the target model.

[0081] In some embodiments, the decrypted fifth data can be sent back to the REE, and the fifth data can replace the fourth data in the REE.

[0082] S60, Load the target model based on the fifth data.

[0083] For example, the third stage of the target model can be loaded using the fifth data obtained in step S50.

[0084] For example, continuing with the above embodiments, the inference stage of the target model can be loaded using the fifth data.

[0085] In some embodiments, the target model with an inference phase may be quite large. Directly loading the first, second, and third loading phases of the target model all at once could be slow, taking up a long time and potentially degrading system performance. Therefore, the inference phase can be loaded selectively; that is, the inference phase of the target model can be loaded only when it is needed, otherwise, it can be left unloaded.

[0086] For example, if an inference phase is required when performing data processing using the target model loaded in the first and second loading phases, steps S50 and S60 described above can be executed. The target model can provide a prompt button indicating whether to load the inference phase. The user can select whether to load the inference portion of the target model or not by touching the corresponding prompt button.

[0087] When the target model is large, it can be split into segments. To perform an inference task, a portion of the target model can be loaded first. During the execution of this portion of the target model, or after the execution of this portion of the target model is completed, another portion of the model (the inference phase of the target model) can be loaded.

[0088] This embodiment can further improve the loading efficiency of the target model and avoid loading the entire target model at once, which would affect system performance.

[0089] In some embodiments, the second data is encrypted in a first encryption stage, and the fourth data is encrypted in a second encryption stage, wherein the first encryption stage is different from the second encryption stage.

[0090] For example, the second and fourth data can be encrypted separately without affecting each other, thus improving the efficiency of data encryption. This is especially important when the amount of the second and / or fourth data is large, as encrypting them simultaneously might slow down the encryption process. Furthermore, encrypting the second and fourth data separately also improves the efficiency of retrieving them.

[0091] The second data can be encrypted before it is acquired. This "before" can refer to either the initial loading phase of loading the target model based on the first data, or it can be before the initial loading phase of loading the target model based on the first data has even begun.

[0092] Before acquiring the fourth data, the fourth data is encrypted. Here, "before acquiring the fourth data" can be during the second loading stage of loading the target model based on the third data, or before the second loading stage of loading the target model based on the third data has started; it can also be during the first loading stage of loading the target model based on the first data, or before the first loading stage of loading the target model based on the first data has started.

[0093] It should be noted that the first encryption stage of the second data can be performed before or after the second encryption stage of the fourth data, as long as it does not affect the acquisition of the second and fourth data.

[0094] Especially when both the second and fourth data are large, encrypting the second and fourth data separately can improve the efficiency of encryption processing for the second and fourth data.

[0095] In some embodiments, the second data corresponds to the first key, the fourth data corresponds to the second key, and the first key is different from the second key.

[0096] For example, the encryption key for the second data and the encryption key for the fourth data can be different. The encryption methods for the second data and the fourth data can be the same, but the encryption keys for the second data and the fourth data can be different. Alternatively, the second data and the fourth data can be encrypted using different encryption methods, and the encryption keys for the second data and the fourth data can be different.

[0097] The first key corresponding to the first data and the second key corresponding to the fourth data can be stored in the TEE. The TEE can use the decryption algorithms agreed upon with the second data and the fourth data respectively to decrypt the second data and the fourth data, and send the decrypted plaintext (the third data corresponding to the second data and the fifth data corresponding to the fourth data) back to the REE. The REE uses the third data to load the second loading stage of the target model and uses the fifth data to load the third loading stage of the target model.

[0098] After obtaining the second data, it can be decrypted using the first key to obtain the third data. The first key can be stored in the TEE (Trusted Execution Environment). If the first key is leaked, it will not affect the security of the fourth data during subsequent decryption. Similarly, the leakage of the second key will not affect the security of the second data. Therefore, the second and fourth data correspond to different keys, further ensuring their security.

[0099] In some embodiments, the model loading method further includes:

[0100] Obtain the sixth data;

[0101] The sixth data is sent to a secure execution environment for decryption to obtain the seventh data, which is used for loading in the first loading stage and / or the second loading stage.

[0102] For example, during the loading phase of the target model, the sixth data corresponding to the target model is required. Because the sixth data itself has a certain degree of dispersion and independence, segmented encryption may not be effective in preventing leakage and theft. Therefore, in this embodiment, the sixth data is fully encrypted. Furthermore, compared to the target model, the sixth data corresponding to the target model is relatively small, and encrypting the sixth data as a whole will not significantly affect the system's performance.

[0103] The sixth data can be stored on the REE's disk or in memory. The sixth data can be sent to the TEE for decryption to obtain the seventh data, which is the data decrypted from the sixth data.

[0104] If the seventh data is needed in the first loading stage, the sixth data can be obtained when the first data is obtained, and the seventh data obtained by decrypting the sixth data can be used for loading in the first loading stage.

[0105] If the seventh data is not needed in the first loading stage but is needed in the second loading stage, then the sixth data can be obtained when obtaining the second data, and the seventh data obtained by decrypting the sixth data can be used for loading in the second loading stage. Alternatively, the sixth data can be obtained when obtaining the first data, and the decrypted seventh data can be kept for later use.

[0106] The sixth data is obtained by encrypting the data required for the target model, and the seventh data is obtained by decrypting the sixth data in the TEE, which improves the security of the data.

[0107] The encryption of the sixth data can be performed simultaneously with the encryption of the second and fourth data, or it can be performed in different time periods.

[0108] For example, if the seventh data obtained by decrypting the sixth data is not needed in the first loading stage, the sixth data can be obtained by encrypting the data in the first loading stage based on the first data to load the target model.

[0109] The process of encrypting the sixth data can be carried out simultaneously with the loading of the target model, which can further accelerate the encryption and decryption process of the target model and the deployment process of the target model.

[0110] For some general-purpose pre-trained models, anti-theft protection is not necessary. In this case, the target model does not need any encryption. However, the fine-tuned data corresponding to the target model needs to be encrypted. Generally, independently managed fine-tuned data is not very large and can be processed using the same fully encrypted method as the model data.

[0111] In some embodiments, the second data includes a first portion and a second portion, wherein the first portion is unencrypted and the second portion is encrypted.

[0112] Step S30: During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and sent to the secure execution environment for decryption to obtain the third data, including:

[0113] S301, during the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and the second part of the second data is sent to the secure execution environment for decryption to obtain the decrypted second part.

[0114] S302, combine the first part with the decrypted second part to obtain the third data.

[0115] For example, in combination Figure 3 The second data includes the unencrypted first part (corresponding to...) Figure 3 The plaintext in the left part and the encrypted second part (corresponding to) Figure 3 The ciphertext in the left-hand section). The first part of the second data does not need to be sent to the TEE environment for decryption (it can be decrypted using the platform key in the TEE). Only the second part of the second data needs to be sent to the TEE for decryption, which can improve the processing efficiency of the second data.

[0116] For example, combining again Figure 3 The second part of the second data can be determined using interleaved encryption, meaning the first and second data can be distributed in a scatter pattern. One or more local portions of the original unencrypted data are encrypted; the encrypted portions constitute the second data, and the unencrypted portions constitute the first part. It's important to note that all unencrypted local portions of the second data combined together constitute the first part, and all encrypted local portions of the second data combined together constitute the second part. If the second part includes multiple local portions, it can be sent to the TEE together, or each encrypted local portion can be sent to the TEE separately.

[0117] The method for selecting the encrypted portion of interleaved encryption can be to extract a fixed-size data block (e.g., 16 bytes) from the entire data space in a uniformly distributed manner (e.g., per memory page), then encrypt the extracted data block, and replace the original data block with the obtained ciphertext result.

[0118] A uniformly distributed extraction method can be used in units of a basic memory page (typically 512 bytes) or a large memory page (e.g., 4KB). However, units should not be too large, otherwise the risk of successful data theft (e.g., neural network models) increases; but units should also not be too small, as this would multiply the amount of data to be decrypted, significantly straining system performance.

[0119] TEE can decrypt the entire second part simultaneously, or it can decrypt each part of the second part separately. Each encrypted part can correspond to the same key or different keys.

[0120] The second part of the encrypted second data is sent to the TEE for decryption. The plaintext obtained after decryption can be sent back to the REE to replace the ciphertext in the second data. Finally, the first part and the decrypted second part are combined to obtain a complete plaintext data (the third data).

[0121] In some embodiments, obtaining the first data corresponding to the target model may include:

[0122] S101, Obtain the eighth data;

[0123] S102, the eighth data is sent to a secure execution environment for decryption to obtain the first data.

[0124] For example, the first data is also obtained after decryption. In this case, the eighth data can be obtained first and sent to the TEE for decryption. The eighth data can be a part of the encrypted target model. The eighth data can be stored on disk or in memory. After the eighth data is loaded from disk into memory, it can be sent from the REE to the TEE for decryption to obtain the first data.

[0125] The encryption method for the eighth data can be the same as or different from the encryption methods for the second and fourth data. The key corresponding to the eighth data can be a third key, which can be different from both the first and second keys.

[0126] The encryption of the eighth data can be completed before the eighth data is obtained, so as not to affect the determination of the first data, and thus not to affect the first loading stage of the target model.

[0127] In some embodiments, when the target model is a first model, the second data corresponding to the first model includes a first object.

[0128] When the target model is the second model, the second data corresponding to the second model includes the second object.

[0129] The first model is different from the second model, and the first object is different from the second object.

[0130] For example, the first model and the second model are different types of neural network models, and the encrypted parts in the target model can be different for different types of target models.

[0131] For example, the first model can be divided into three modules. The third module is the most critical part of the first model. The third module can be encrypted, and the encrypted third module is the second data of the first model. The second data of the first model includes the first object.

[0132] For the second model, it can be divided into a first module and a second module. The second module is the most crucial part of the second model, and therefore, it can be encrypted. The encrypted second module constitutes the second data of the second model. The second data of the second model includes the second object.

[0133] Here, the first and second modules of the second model may all be different from the first, second, and third modules of the first model; or the first module of the second model may be the same as the first module in the first model, but the second module of the second model may be different from both the second and third modules of the first model; or the second module of the second model may contain some content that is the same (but not completely the same) as the third module of the first model, mainly reflecting the difference between the first object and the second object.

[0134] This application embodiment also provides a model loading device, combined with Figure 4 The model loading device includes:

[0135] The first acquisition unit is configured to acquire the first data corresponding to the target model.

[0136] For example, the target model can be a neural network model using PyTorch or Transformers, or a neural network model using other learning frameworks. The first data corresponding to the target model can be stored in the conventional operating system environment (REE) of the mobile terminal device, such as on the REE's disk or memory. The REE can refer to the Android or iOS system of the mobile terminal device. The REE can run ordinary applications; here, ordinary applications can be understood as applications with no or low security requirements. Because the applications running in the REE are diverse and complex, with a large attack surface, it is not suitable for processing data with high security requirements or sensitive data (such as encryption keys). The first acquisition unit can obtain the aforementioned first data from the REE.

[0137] Mobile terminal devices can be, but are not limited to, mobile phones, iPads, wearable devices, etc.

[0138] The first data can be part of the target model. In some embodiments, the first data may not be encrypted, meaning that the acquired first data can be directly used to load the target model.

[0139] The target model loading phase includes at least a first loading phase and a second loading phase, with the first data corresponding to the first loading phase.

[0140] The first loading unit is configured to load the target model based on the first data.

[0141] For example, after obtaining the first data, the first loading unit can load the target model in the first loading stage based on the first data.

[0142] The first loading phase may include a configuration file loading phase, where the first data can be a portion of the target model segmented for the configuration file loading phase. For example, to complete a task using the target model, it can be divided into two or more steps. The target model can be segmented into two or more parts, one for each step. Here, the first loading phase can load the model portion needed for the first step of the task. The configuration file loading phase can load the model structure, hyperparameters (such as the number of layers, hidden dimensions, activation functions, etc.). The first loading phase may also include a model initialization phase. Of course, the first loading phase can include both the configuration file loading phase and the initialization phase simultaneously. That is, the first loading phase is not a single phase, but a combination of multiple phases.

[0143] The first data is a portion of the target model segmented from the target model corresponding to the first loading stage.

[0144] The second acquisition unit is configured to acquire second data corresponding to the target model during the process of loading the target model based on the first data and send the second data to a secure execution environment for decryption to obtain the third data.

[0145] For example, during the loading of the target model based on the first data, the second acquisition unit can acquire the second data corresponding to the target model. The second data can be encrypted data, and the encrypted second data can also be stored in the REE, such as on the REE's disk or memory. After the second data stored on the disk is loaded into memory, the second acquisition unit can send the second data to the TEE for decryption. Here, the second data refers to the other parts segmented from the target model. The encryption of the second data can be performed before acquiring the first data, during acquiring the first data, or during the loading of the target model based on the first data. In short, the encryption process of the second data and the loading process of the target model can be performed simultaneously without affecting each other, which can speed up the encryption and decryption process of the target model and improve the loading process of the target model.

[0146] After obtaining the second data, the second acquisition unit can send the second data to the Secure Execution Environment (TEE) for decryption. Since the TEE has a high security level, it can decrypt the encrypted second data and ensure the security of the second data obtained after decryption. This avoids the target model being stolen because the data loaded into the target model is not encrypted, and may also cause leakage of user data.

[0147] For example, there is at least one trusted application (TA) in the TEE. The TA can hold a platform key injected during the factory production process. Based on the platform key and the set decryption algorithm (such as AES ECB symmetric encryption algorithm), the second data sent to the TEE can be decrypted, and the plaintext obtained after decryption is the third data.

[0148] In other words, this application only encrypts a part of the target model, rather than encrypting the entire target model. Therefore, the data encryption and decryption processes can complement each other. Data can be decrypted while encrypting a portion of the data, which speeds up the encryption and decryption process of the target model and also improves the deployment and loading speed of the target model.

[0149] In addition, this application can acquire the second data while loading the target model based on the first data, and realize the sending and decryption of the second data, thus preparing for the second loading stage of the target model and improving the overall loading speed of the target model.

[0150] In some embodiments, if a target model is loaded in the REE, the obtained third data can be sent back to the REE, and the second data in the REE can be replaced with the third data.

[0151] The second loading unit is configured to load the target model based on the third data.

[0152] For example, the third data is the data corresponding to the second loading stage of the target model, and the second loading unit can perform the second loading stage of the target model based on the third data.

[0153] For example, continuing with the above embodiments, the second loading stage can be the pre-trained weight loading stage following the first loading stage (including the configuration file loading stage and the initialization stage). The pre-trained weight loading stage requires third data, and the target model can be loaded with pre-trained weights based on this third data.

[0154] When encrypting a segment of the target model, you can select the key parts of the target model for encryption. Since the target model is loaded and run as a whole, if you select the key parts for encryption, you can prevent the target model from being directly stolen.

[0155] This application embodiment encrypts a portion of the target model, preventing the unencrypted target model from being directly stolen, and ensuring that loading the target model does not affect system performance.

[0156] This application also provides an electronic device, combined with Figure 5 The electronic device may include a memory and a processor, wherein the memory stores an executable program, and the processor is used for:

[0157] The process involves: acquiring first data corresponding to the target model; loading the target model based on the first data; during the loading of the target model based on the first data, acquiring second data corresponding to the target model and sending the second data to a secure execution environment for decryption to obtain third data; and loading the target model based on the third data. The target model loading stage includes at least a first loading stage and a second loading stage, with the first data corresponding to the first loading stage and the third data corresponding to the second loading stage.

[0158] The processor is also used to perform steps of the other methods described in the above embodiments.

[0159] Furthermore, one embodiment of this application also provides a storage medium storing a computer program that, when executed by a processor, implements the region determination method described above. It should be understood that the various solutions in this embodiment have the corresponding technical effects in the above method embodiments, and will not be repeated here.

[0160] Furthermore, embodiments of this application also provide a computer program product, which is tangibly stored on a computer-readable medium and includes computer-readable instructions that, when executed, cause at least one processor to perform a region determination method such as those described in the embodiments above.

[0161] It should be noted that the computer storage medium in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. Computer-readable media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access storage media (RAM), read-only storage media (ROM), erasable programmable read-only storage media (EPROM or flash memory), optical fibers, portable compact disk read-only storage media (CD-ROM), optical storage media, magnetic storage media, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program configured for use by or in connection with an instruction execution system, system, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, antenna, optical fiber, RF, etc., or any suitable combination thereof.

[0162] Furthermore, those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0163] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus, and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A system that specifies functions in one or more boxes.

[0164] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction set implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0165] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0166] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. The scope of protection of this application is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to this application within its substance and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.

Claims

1. A model loading method, comprising: Obtain the first data corresponding to the target model; The target model is loaded based on the first data; During the process of loading the target model based on the first data, second data corresponding to the target model is obtained and sent to a secure execution environment for decryption to obtain third data; the target model is then loaded based on the third data. The target model loading stage includes at least a first loading stage and a second loading stage, wherein the first data corresponds to the first loading stage and the third data corresponds to the second loading stage.

2. The model loading method according to claim 1, Also includes: During the process of loading the target model based on the third data, the fourth data corresponding to the target model is obtained and sent to the secure execution environment for decryption to obtain the fifth data; The target model is loaded based on the fifth data; The target model loading stage further includes a third loading stage, and the fifth data corresponds to the third loading stage.

3. The model loading method according to claim 2, The second data is encrypted in the first encryption stage, and the fourth data is encrypted in the second encryption stage, wherein, The first encryption phase is different from the second encryption phase.

4. The model loading method according to claim 2, The second data corresponds to the first key, and the fourth data corresponds to the second key. The first key is different from the second key.

5. The model loading method according to claim 1, Also includes: Obtain the sixth data; The sixth data is sent to a secure execution environment for decryption to obtain the seventh data, which is used for loading in the first loading stage and / or the second loading stage.

6. The model loading method according to claim 1, The second data includes a first part and a second part, wherein, The first part is not encrypted, while the second part is encrypted; During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and sent to a secure execution environment for decryption to obtain the third data, including: During the process of loading the target model based on the first data, the second data corresponding to the target model is obtained and the second part of the second data is sent to the secure execution environment for decryption to obtain the decrypted second part. The first part is combined with the decrypted second part to obtain the third data.

7. The model loading method according to claim 1, The acquisition of the first data corresponding to the target model includes: Get the eighth data; The eighth data is sent to a secure execution environment for decryption to obtain the first data.

8. The model loading method according to claim 1, When the target model is a first model, the second data corresponding to the first model includes a first object; When the target model is the second model, the second data corresponding to the second model includes the second object; in, The first model is different from the second model, and the first object is different from the second object.

9. A model loading device, the device comprising: The first acquisition unit is configured to acquire the first data corresponding to the target model; The first loading unit is configured to load the target model based on the first data; The second acquisition unit is configured to acquire second data corresponding to the target model during the process of loading the target model based on the first data and send the second data to a secure execution environment for decryption to obtain the third data; The second loading unit is configured to load the target model based on the third data; The target model loading stage includes at least a first loading stage and a second loading stage, wherein the first data corresponds to the first loading stage and the third data corresponds to the second loading stage.

10. An electronic device comprising a memory and a processor, wherein the memory stores an executable program, and the processor is configured to execute: Obtain the first data corresponding to the target model; The target model is loaded based on the first data; During the process of loading the target model based on the first data, second data corresponding to the target model is obtained and sent to a secure execution environment for decryption to obtain third data; the target model is then loaded based on the third data. in, The target model loading stage includes at least a first loading stage and a second loading stage, where the first data corresponds to the first loading stage and the third data corresponds to the second loading stage.