Method, apparatus, device, medium and program product for model security reasoning
By encrypting machine learning models and user requests using vocabulary transformation rules, the problems of data leakage and high computational costs in existing technologies are solved, achieving efficient and secure model inference and making it suitable for data protection in generation tasks.
Patent Information
- Application Number
- CN202511212184.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-11-18
AI Technical Summary
Existing technologies pose a risk of data leakage during machine learning model inference. Furthermore, existing encryption schemes are computationally expensive, have high hardware costs, limited security, or require modifications to existing processes, and cannot effectively protect the output text of the generation task.
The first machine learning model is converted into an encrypted second machine learning model using vocabulary conversion rules. User requests and feedback are also encrypted using vocabulary conversion rules to ensure data security and model accuracy.
It offers enhanced security and usability, is suitable for generation tasks, reduces model inference loss, requires no additional modifications, has the same efficiency as plaintext inference, and is compatible with mainstream models.
Smart Images

Figure CN120975244A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Example embodiments of the present disclosure generally relate to the field of computers, and in particular, to a method, apparatus, device, computer-readable storage medium and computer program product for secure inference of a model. BACKGROUND
[0002] With the development of information technology, various terminal devices can provide various services to people in work and life, etc. The implementation of services can utilize machine learning models deployed on a service side, that is, the implementation of services at a terminal device needs model inference services provided by the service side. For example, a terminal device can provide services for users through a digital assistant. In the interaction process, the digital assistant can obtain request data provided by the user and send the request data to the service side, so that the machine learning model deployed on the service side performs inference according to the request data. However, in the above process, there can be a data security risk, for example, the request data from the user and the machine learning model at the service side can be leaked. At this time, it is expected to implement model inference in a more secure manner. SUMMARY
[0003] In a first aspect of the present disclosure, a method for secure inference of a model is provided. The method comprises: converting a first machine learning model into an encrypted second machine learning model based on a vocabulary conversion rule; in response to receiving a first user request, converting the first user request into an encrypted second user request based on the vocabulary conversion rule; obtaining feedback for the second user request, the feedback being generated by the second machine learning model processing the second user request; and converting the feedback into a response for the first user request based on the vocabulary conversion rule.
[0004] In a second aspect of the present disclosure, a method for secure inference of a model is provided. The method comprises: obtaining a second machine learning model, the second machine learning model being obtained by encrypting a first machine learning model based on a vocabulary conversion rule; receiving a second user request, the second user request being obtained by encrypting a first user request based on the vocabulary conversion rule; and processing the second user request based on the second machine learning model to generate feedback for the second user request.
[0005] In a third aspect of the disclosure, an apparatus for model secure inference is provided. The apparatus includes a first conversion module configured to convert a first machine learning model to an encrypted second machine learning model based on a vocabulary conversion rule; a second conversion module configured to convert, in response to receiving a first user request, the first user request to an encrypted second user request based on the vocabulary conversion rule; an obtaining module configured to obtain feedback for the second user request, the feedback generated by the second machine learning model processing the second user request; and a third conversion module configured to convert the feedback to an answer for the first user request based on the vocabulary conversion rule.
[0006] In a fourth aspect of the disclosure, an apparatus for model secure inference is provided. The apparatus includes an obtaining module configured to obtain a second machine learning model, the second machine learning model obtained by encrypting a first machine learning model based on a vocabulary conversion rule; a receiving module configured to receive a second user request, the second user request obtained by encrypting a first user request based on the vocabulary conversion rule; and a generating module configured to process the second user request based on the second machine learning model to generate feedback for the second user request.
[0007] In a fifth aspect of the disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. The instructions, when executed by the at least one processor, cause the device to perform the method of the first aspect or the second aspect.
[0008] In a sixth aspect of the disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has stored thereon a computer program, the computer program being executable by a processor to implement the method of the first aspect or the second aspect.
[0009] In a seventh aspect of the disclosure, a computer program product is provided, the program product including a computer program executable by a processor to implement the method of the first aspect or the second aspect.
[0010] It should be understood that the contents described in this part of the content are not intended to limit the key features or important features of the embodiments of the disclosure, nor are they used to limit the scope of the disclosure. Other features of the disclosure will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS
[0011] The above and other features, advantages, and aspects of embodiments of the disclosure will become more apparent by describing in detail exemplary embodiments thereof with reference to the attached drawings in which:
[0012] Figure 1 a schematic diagram showing an example environment in which embodiments in accordance with the present disclosure can be implemented;
[0013] Figure 2 a schematic diagram showing an example architecture of a system for model secure inference in accordance with some embodiments of the present disclosure;
[0014] Figure 3 a schematic diagram showing an example architecture of a machine learning model in accordance with some embodiments of the present disclosure;
[0015] Figure 4A and Figure 4B flowcharts showing example processes for model secure inference in accordance with some embodiments of the present disclosure, respectively;
[0016] Figure 5A and Figure 5B schematic structural block diagrams of example apparatuses for model secure inference in accordance with some embodiments of the present disclosure, respectively; and
[0017] Figure 6 a block diagram of an electronic device capable of implementing a number of embodiments of the present disclosure. DETAILED DESCRIPTION
[0018] Embodiments of the present disclosure will be described below in greater detail with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be interpreted as being limited to the embodiments set forth herein; rather, these embodiments are provided so as to more completely and thoroughly understand the present disclosure. It is to be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of the present disclosure.
[0019] It is noted that the headings provided herein are not limitations of the disclosure. Various embodiments are described throughout this document and any type of embodiment can be included under any heading. Moreover, embodiments described in any heading can be combined with any other embodiment described in the same heading and / or in a different heading in any manner.
[0020] In the description of embodiments of the present disclosure, the term "includes" and its derivatives are to be interpreted as incorporating by reference the phrases "without limitation" or "to the extent applicable". The term "based on" is to be interpreted as "based, at least in part, on". The term "one embodiment" or "an embodiment" are to be interpreted as "at least one embodiment". The term "some embodiments" are to be interpreted as "at least some embodiments". Other explicit or implicit definitions can also be included below. The terms "first", "second", etc. can refer to different or same objects. Other explicit or implicit definitions can also be included below.
[0021] The data of the user, the acquisition and / or use of the data, etc. can be involved in the embodiments of the present disclosure. These aspects comply with the corresponding laws and regulations and relevant provisions. In the embodiments of the present disclosure, the collection, acquisition, processing, processing, forwarding, use, etc. of all data are performed on the premise that the user is aware of and confirms. Accordingly, when implementing the embodiments of the present disclosure, the type of data or information that can be involved, the use range, the use scenario, etc. should be notified to the user and the authorization of the user should be obtained through appropriate means according to the relevant laws and regulations. The specific notification and / or authorization manner can vary according to the actual situation and application scenario, and the scope of the present disclosure is not limited in this respect.
[0022] In the present specification and embodiments, if the scheme involves personal information processing, it will be processed on the premise of legality basis (for example, obtaining the consent of the subject of personal information, or being necessary for the performance of a contract, etc.), and will be processed only within the prescribed or agreed range. The user refuses to process personal information other than the necessary information required for the basic function, which does not affect the user's use of the basic function.
[0023] Example Environment
[0024] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. As shown, the example environment 100 can include an electronic device 110. Figure 1
[0025] In this example environment 100, the electronic device 110 can operate an application 120 that provides an information query service for a user 140. The application 120 can be any appropriate type of application for information query, examples of which can include but are not limited to a digital assistant or other appropriate application. The user 140 can interact with the application 120 via the electronic device 110 and / or its attached devices. In some embodiments, the application 120 can access a model 130 at a server to provide services for the user 140. In some embodiments, the model 130 can be a machine learning model, a deep learning model, a learning model, a neural network, etc. In some embodiments, the model 130 can include a language model, such as a large language model (LLM). The large language model can have the ability to ask and answer by learning from a large amount of corpus. The model 130 can also be based on other appropriate models. The model 130 refers to a model provided by other applications or platforms independent of the application 120. In some embodiments, the application 120 can be used to determine whether the feedback of the model 130 meets the user's expectations. The electronic device 110 communicates with the model 130 to implement the provision of services for the application 120.
[0026] In Figure 1 In environment 100, if application 120 is active, electronic device 110 can use application 120 to present interface 150 for supporting the acquisition of user input and the presentation of interaction results to user 140. Interface 150 may include, for example, a conversational interface between user 140 and application 120. User 140 can send user input indicating a target task to application 120 through the conversational interface. During the interaction, application 120 provides the acquired user input to model 130 to obtain a response from model 130 to the user input. Subsequently, application 120 provides services to user 140 based on the response from model 130. Interface 150 can be used to present responses to user input. In some embodiments, depending on the configuration of application 120, interaction messages with application 120 may include multimodal messages, such as text messages (e.g., natural language text), voice messages, image messages, video messages, etc.
[0027] In some embodiments, application 120 may be associated with a corresponding database storing data or information required by application 120 to respond to user interaction information. For example, application 120 may, in response to user input, retrieve information indicating user input from a database connected to application 120 (e.g., a database storing data of user 140, or a knowledge base storing historical interaction information between user 140 and application 120). Application 120 may then provide the retrieved operational data to model 130, enabling the machine learning model to provide corresponding services to the user based on the user's output.
[0028] In some embodiments, electronic device 110 may be any type of mobile terminal, fixed terminal, or portable terminal, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, handheld computers, portable gaming terminals, VR / AR devices, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio / video players, digital cameras / camcorders, positioning devices, television receivers, radio receivers, e-book devices, gaming devices, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, electronic device 110 may also support any type of user-facing interface (such as "wearable" circuitry).
[0029] In some embodiments, model 130 can be deployed on a server. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms. The server may include, for example, computing systems / servers, such as mainframes, edge computing nodes, computing devices in a cloud environment, etc. The server can provide backend services for the application 120 in electronic device 110 that supports information retrieval.
[0030] A communication connection can be established between the server with model 130 and the electronic device 110. This communication connection can be established via wired or wireless means. The communication connection may include, but is not limited to, Bluetooth, mobile network, Universal Serial Bus (USB), and Wireless Fidelity (WiFi) connections; the embodiments of this disclosure are not limited in this respect. In the embodiments of this disclosure, the server and the electronic device 110 can perform signaling interaction through the communication connection between them.
[0031] It should be understood that the structure and function of the various elements in environment 100 are described for illustrative purposes only and do not imply any limitation on the scope of this disclosure.
[0032] As mentioned above, electronic devices or applications can provide services (such as information retrieval and text processing) to users (e.g., enterprise users) through machine learning models. In the process of invoking a machine learning model, the electronic device or application provides the machine learning model with information corresponding to the user's input and provides the user with the output information generated by the machine learning model based on the user's input, thereby utilizing the machine learning model to provide services to the user.
[0033] However, in some scenarios where machine learning models are invoked (e.g., in enterprise-facing scenarios), user information (e.g., internal company information) may be intercepted or accessed by unauthorized third parties, leading to information leakage. Furthermore, the model training process involves significant time and resource overhead, and the parameters in the trained model involve secure data that requires protection. Deploying the model directly on a server could expose these parameters and result in further information leakage.
[0034] Currently, schemes based on cryptography, trusted hardware, and data obfuscation have been proposed for data encryption; however, existing schemes still have many drawbacks. For example, cryptographic schemes have very high computational and communication costs; trusted hardware schemes rely on additional hardware and system modification costs; data obfuscation schemes have limited security, affecting model performance, and also require intrusive modifications to existing inference service processes.
[0035] For example, in one data obfuscation technique, users randomly replace sensitive markers in the input text with markers that are close to their embeddings (also called features), thus protecting sensitive information in the input text. Because this approach only protects the input data, it is only suitable for classification tasks and not for text generation tasks. In another technique, after converting the markers in the input text into embeddings, differential privacy noise is added to the embeddings, making it impossible for the cloud service to identify the original data corresponding to the noisy embedding. However, this approach performs poorly in model inference and also fails to protect the output text of generation tasks. In yet another technique, the model is split into two parts, with the client bearing the computational burden of the smaller part of the model. This approach protects privacy data by adding noise to the output of the smaller part of the model. However, this approach is also unsuitable for generation tasks.
[0036] Current methods for reversing obfuscation schemes have been proposed to restore obfuscated data back to the user's private information. For example, by comparing the difference between the original embedding and the obfuscated embedding, the obfuscated embedding can be restored to the original token, and so on. This makes the security of existing data obfuscation techniques unsatisfactory. There is a need for more reliable and effective data encryption methods.
[0037] In view of this, embodiments of the present disclosure provide a scheme for data processing. In this scheme, a first machine learning model is converted into an encrypted second machine learning model based on a lexical conversion rule. In response to receiving a first user request, the first user request is converted into an encrypted second user request based on the lexical conversion rule. Feedback for the second user request is obtained, the feedback being generated by the second machine learning model processing the second user request. Based on the lexical conversion rule, the feedback is converted into a response to the first user request.
[0038] In this way, on the one hand, by encrypting both the machine learning model and the user request, data related to the process of the machine learning model processing the user request can be prevented from being leaked, thus improving data security. On the other hand, encrypting both the machine learning model and the user request based on the same vocabulary transformation rule allows the encrypted machine learning model to be matched with the encrypted user request. This ensures that the encrypted user request can be processed normally.
[0039] Specifically, the proposed technical solution offers enhanced security, supporting the protection of input data and inference results for generation tasks, and fully safeguarding the security of user and model data. It provides higher availability and supports lower model inference loss. It offers greater ease of use, achieving secure inference through lightweight, one-time offline processing without additional fine-tuning or training steps. The inference process is compatible with existing inference services, requiring no additional modifications and adapting to mainstream models. In this way, it provides efficient data encryption and processing, achieving online inference efficiency comparable to plaintext-based methods. The following sections, with accompanying figures, further describe various example implementations of this solution in detail.
[0040] Example Architecture
[0041] Figure 2 A schematic diagram of an example architecture 200 for a system for model-safe reasoning according to some embodiments of the present disclosure is shown. Figure 2 As shown, architecture 200 involves Figure 1 The illustrated electronic device 110 and server (e.g., data processing platform 270) are implemented. Architecture 200 includes a model deployment phase and a data processing phase.
[0042] During the model deployment phase, electronic device 110 can deploy machine learning models to data processing platform 270 to provide services to users using data processing platform 270. Model repository 210 may include multiple machine learning models. In some embodiments, electronic device 110 can determine a first machine learning model 220 from model repository 210. Electronic device 110 can determine the first machine learning model 220 based on user access permissions. For example, electronic device 110 can determine one or more machine learning models in model repository 210 that the user has access to as the first machine learning model 220. Electronic device 110 can determine the first machine learning model 220 based on the type of user request. For example, if the type of user request is text processing, electronic device 110 can use a model (e.g., a language model) in model repository 210 used for processing text processing requests as the first machine learning model 220. In some embodiments, the machine learning models in model repository 210 can be pre-trained models to facilitate subsequent use of machine learning models to provide services to users.
[0043] In some embodiments, the electronic device 110 may convert the first machine learning model 220 into an encrypted second machine learning model 230 based on a vocabulary conversion rule 240. The vocabulary conversion rule 240 may be a rule corresponding to the electronic device 110 or a user 140 using the electronic device 110. The user 140 may be an individual user or an enterprise user. Exemplarily, the vocabulary conversion rule 240 corresponding to the electronic device 110 may be determined from a plurality of predetermined conversion rules based on the identification information of the electronic device (e.g., device IP or device ID, etc.) or the identification information of the user 140 (e.g., user ID, etc.). In some embodiments, the vocabulary conversion rule 240 may be encrypted using a key. In this case, the electronic device 110 may determine the key based on user input or based on the user's identification information.
[0044] Furthermore, the obfuscation model parameters (i.e., the parameters in the second machine learning model 230) can be determined based on the vocabulary conversion rule 240, and then the second machine learning model 230 can be deployed to the data processing platform 270 to provide inference service 271. The inference service 271 can then be invoked to process user requests. For example, tokens can be extracted from the initial prompt word information 250 through word segmentation. The encrypted prompt word information 251 can be determined and sent to the data processing platform 270 as a second user request 252. The second machine learning model 230 can process the second user request 252 and provide an encrypted response 261, and then determine a decrypted response 260. It should be understood that, although... Figure 2 Only a single electronic device 110 is shown. Electronic device 110 may include multiple electronic devices, and the multiple electronic devices may coordinate to complete the above process.
[0045] In some embodiments, the method disclosed herein can be performed by a user-side device. The method further includes: sending a second machine learning model to a server, sending a second user request to the server, and receiving feedback from the server. Specifically, the above method can be performed at an electronic device 110. For example, the electronic device 110 can send the second machine learning model 230 to a data processing platform 270 and receive feedback from the data processing platform 270 (e.g., an encrypted response 261). In this way, the user request and the machine learning model exist only in plaintext at the electronic device 110, and the security of the model usage process can be improved.
[0046] In the context of this disclosure, user 140 (also referred to as the user party) may include a single user or multiple users, each of whom may be identified by a globally unique user account or user device identifier. Alternatively and / or additionally, user 140 may also include enterprise users, and may be identified by preset rules that allow the enterprise to authorize users or devices.
[0047] Here, the user performing the encryption process of the machine learning model, the user deploying the encrypted model to the server, and the user using the encrypted model can be the same or different. One or more of these can use the same or different electronic devices and perform their respective processes. For example, a first user (e.g., a model developer) can convert a first machine learning model into an encrypted second machine learning model at a first device, a second user (e.g., a model administrator) can deploy the second machine learning model to the data processing platform 270 at a second device, and a third user (e.g., a regular end-user) can access the remote second machine learning model at a third device. Specifically, in an enterprise user environment, the first, second, and third users, as well as the first, second, and third devices, can be designated users or devices within an authorized enterprise, or any user or device within that enterprise.
[0048] See below. Figure 3 Describe the specific process of data encryption. Figure 3 A schematic diagram of an example architecture 300 of a machine learning model according to some embodiments of the present disclosure is shown. Figure 3 As shown, architecture 300 includes a word segmenter 320 with a vocabulary, an embedding layer 340, an encoder backbone network composed of Transformer structures, and a task-related output layer 360. In some embodiments, the word segmenter 320 is used to determine input tokens 330 based on prompt word information 310 indicating a user request, that is, to divide the prompt word information 310 into multiple tokens. Subsequently, the word segmenter 320 can obtain a series of indices according to the order of these tokens in the vocabulary. The embedding layer 340 can obtain the embedding vectors corresponding to these tokens according to the indices of the tokens, thereby determining the embedding vector matrix corresponding to the input text.
[0049] The encoder backbone network may include multiple structural layers, such as a first decoding layer 350-1 and a second decoding layer 350-2, which may be referred to individually or collectively as decoding layer 350. Figure 3 The number of decoding layers 350 shown is merely exemplary and is not intended to be any limitation.
[0050] In some embodiments, the output layer 360, also referred to as the output head layer, is used to generate the target token 370. The output layer 360 can convert the output vector into probability values for each token in the vocabulary, thereby determining the next generated token based on the magnitude of the probability values. During the prediction phase, the output layer predicts the next token based on the current text. Subsequently, the output token is concatenated to the input text and fed back into the model for prediction until the model outputs a stop identifier or reaches the maximum length limit. In some embodiments, the electronic device 110 can output information 380 based on the target token 370 as a response to the prompt word information 310.
[0051] In some embodiments, the first machine learning model may include multiple model parameters at multiple layers. For ease of description, the model parameters of the first machine learning model may be referred to as first model parameters. Here, model parameters may include model weights, such as the weights at various layers in the model. The electronic device 110 may perform parameter obfuscation on the multiple model parameters included in the first machine learning model 220 based on the determined vocabulary conversion rule 240 to obtain a second machine learning model 230. Parameter obfuscation of the multiple model parameters by the electronic device 110 may include adding noise to at least some of the parameters in the model and / or transforming all the parameters in the model. For example, the first machine learning model 220 may be represented as Φ, and the second machine learning model 230 may be represented as Φ′. The parameters of the first machine learning model are:
[0052]
[0053] In the above formula, W embed The embedding model parameters at the embedding layer and W embed The dimension of W is n×d. head The output head model parameters at the output head layer and W head The dimension is d×n. (AttenEachHead) i These are the attention model parameters for the attention layer of the i-th decoding layer. The attention model parameters can include multiple sub-model parameters, for example, For the query model parameters of the i-th decoding layer, For the key model parameters of the i-th decoding layer, For the value model parameters of the i-th decoding layer, For the output model parameters of the i-th decoding layer, The dimensions are all d×d head FFN i These are the feedforward model parameters for the i-th decoding layer. The feedforward model parameters can include multiple sub-model parameters, for example, For the upsampling model parameters of the i-th decoding layer, For the gate model parameters of the i-th decoding layer, Let these be the downsampling model parameters for the i-th decoding layer. The dimension is d×d ffn , The dimension is d ffn ×d. m is the number of decoding layers, d is the dimension of hidden layers, n represents the total number of tags, and d head d represents the attention head dimension. ffn This represents the output dimension of the upsampling layer in the feedforward network.
[0054] In one embodiment, during the conversion of a first machine learning model into an encrypted second machine learning model, noise can be added to the parameters of the first model to determine noisy model parameters; based on vocabulary conversion rules, the order of multiple dimensions of the noisy model parameters is updated to form updated noisy model parameters; and noise is removed from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the parameters of the first model. It should be understood that the first and second machine learning models can have completely identical structures, and the corresponding parameters in the two models are of the same type; the difference lies in the numerical values of the corresponding parameters. In this way, noise can be added to the model parameters to hide their specific values; on the other hand, the second model parameters can adjust the specific processing procedures in the second machine learning model to compensate for the impact of the added noise on the machine learning model. In this way, the accuracy of the machine learning model can be ensured while maintaining security.
[0055] Specifically, for a given first model parameter among multiple first model parameters, the electronic device 110 can add noise to that first model parameter to determine a noise model parameter. In some embodiments, the electronic device 110 can determine the value range associated with the first model parameter based on its type, and then determine the noise to be added to the first model parameter. Subsequently, the electronic device 110 determines the noise model parameter based on the influence factor and noise corresponding to the first model parameter. For example, if the model parameter is an embedded model parameter W... embed The electronic device 110 can sample the noise added to the model parameters by considering the range of values for the embedded model parameters. For example, the noise can be sampled based on a Gaussian distribution. The noise for the embedded model parameters can be determined by the following formula:
[0056]
[0057] In the above formula, Here are the noise model parameters for the embedding layer, α is the influence factor corresponding to the embedding model parameters, and noise is the noise with a dimension of n×d.
[0058] In some embodiments, if the model parameter is a query model parameter OR key model parameters Electronic device 110 can sample and obtain the noise added to the model parameters in a similar manner. (Regarding the query model parameters) Bond model parameters The noise can be determined by the following formula:
[0059]
[0060] In the above formula, α qk The influencing factors corresponding to the attention model parameters. For the noise model parameters of the query model parameters, These are the noise model parameters for the key model parameters.
[0061] In some embodiments, if the model parameter is a gate model parameter Electronic device 110 can determine noise model parameters based on the mean and standard deviation of the gate model parameters. For example, electronic device 110 can determine noise model parameters from... Sampling is performed in the distribution to obtain the noise added to the model parameters, μ. g ,σ g They are W Gate The mean and standard deviation. The noise model parameters for the gate model parameters can be determined using the following formula:
[0062]
[0063] In the above formula, For the noise model parameters of the gate model parameters, α g This represents the influence factor corresponding to the AND gate model parameters.
[0064] In some embodiments, if the model parameter is the output head model parameter W head The electronic device 110 can determine the noise model parameters based on the mean and standard deviation of the output head model parameters. For example, the electronic device 110 can obtain... Sampling is performed separately to obtain the noise added to the model parameters, μ. head ,σ head The output head model parameters W are respectively head The mean and standard deviation. The noise model parameters for the output head model parameters can be determined using the following formula:
[0065]
[0066] In the above formula, For the noise model parameters of the output head model parameters, α head This refers to the influence factors corresponding to the output head model parameters.
[0067] It should be understood that the order of the various dimensions of the tokens in a user request can be interchanged to encrypt the user request. After converting the model parameters of the machine learning model into updated noise model parameters, the order of the various dimensions of the machine learning model needs to match the order of the various dimensions of the prompt word tokens, requiring the interchange of the order of dimensions in the noise model parameters of the machine learning model. In some embodiments, the electronic device 110 can update the order of multiple dimensions of the noise model parameters based on the lexicon conversion rule 240 to form updated noise model parameters. In this way, the order of the various dimensions within the machine learning model is consistent with the order of the various dimensions of the tokens in the encrypted user request, thereby offsetting the effects caused by encrypting the user request. In some embodiments, updating the noise model parameters based on the lexicon conversion rule 240 may include updating the vocabulary of the word segmenter 320, the noise model parameters of the embedding layer 340, the noise model parameters of the output layer 360, etc.
[0068] In some embodiments, the electronic device 110 may provide prompt word information 310 to the word segmenter 320 to obtain input tokens 330. The electronic device 110 may update the word list of the word segmenter 320 based on the word list transformation rule 240. For example, the electronic device 110 may determine a seed matrix based on the word list transformation rule 240 and perform row permutation operations on the word list. The electronic device 110 may perform row permutation on the word list based on the following formula:
[0069]
[0070] In the above formula, This is the transformed vocabulary. The original vocabulary is represented by 'key', which is a seed matrix determined based on vocabulary transformation rule 240.
[0071] In some embodiments, the electronic device 110 can process the input label 330 based on the updated noise model parameters. To ensure the accuracy of the processing results, the electronic device 110 can update the processing procedures associated with the corresponding model parameters based on the updated noise model parameters to compensate for the noise in the updated noise model parameters. Specifically, the processing procedures in the machine learning model are represented by various model parameters. The electronic device 110 can remove the noise in the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters, thereby updating the processing procedures of the second machine learning model.
[0072] For example, electronic device 110 can update the processing related to the word segmenter 320 of the first machine learning model 220 based on the updated vocabulary. Electronic device 110 can update the original vocabulary 240 based on the following formula to obtain a confusion vocabulary 231, thereby using the confusion vocabulary 231 to process prompt word information to update the processing related to the word segmenter 320:
[0073]
[0074] In the above formula, This is an encrypted vocabulary, and tok is the input token.
[0075] In some embodiments, the electronic device 110 can update the embedding model parameters based on the vocabulary transformation rule 240 to form updated noise model parameters. For example, the electronic device 110 can determine a seed matrix based on the vocabulary transformation rule 240 and perform row permutation operations on the embedding model parameters. The updated noise model parameters corresponding to the embedding layer are...
[0076] In some embodiments, the electronic device 110 can update the processing procedures associated with the model parameters based on operations performed on the noise model parameters corresponding to the embedding layer, to adapt to the obfuscation of the embedding model parameters. For example, the electronic device 110 can determine the embedding model parameters of the second machine learning model at the embedding layer to remove noise from the updated noise model parameters. Specifically, a first obfuscation matrix can be determined based on a Gaussian distribution; and a linear transformation can be performed on the updated noise model parameters based on the first obfuscation matrix to obtain the second model parameters. In this way, security can be further improved while ensuring the accuracy of the machine learning model. The electronic device 110 can update the processing procedures related to the embedding layer based on the following formula:
[0077]
[0078] In the above formula, P is the first confusion matrix and P is a d×d dimensional matrix obtained by sampling from a Gaussian distribution. The parameters are the first transformation model parameters at the embedding layer of the second machine learning model.
[0079] According to the above formula (9), the electronic device 110 can perform a linear transformation on the updated noise model parameters based on the first confusion matrix to obtain the first transformed model parameters. Subsequently, the electronic device 110 can determine the embedding layer model parameters of the second machine learning model based on the first transformed model parameters, that is, determine the processing procedure at the embedding layer of the second machine learning model.
[0080] In some embodiments, the output of the embedding layer 340 is provided to the first decoding layer 350-1. The first decoding layer 350-1 includes an attention layer 351 and a feedforward layer 352. To accommodate obfuscation for the first machine learning model, the electronic device 110 can determine the corresponding second model parameters of the attention layer 351 and the feedforward layer 352 of the second machine learning model, and then update the processing of the attention layer and the feedforward layer of the second machine learning model.
[0081] In some embodiments, for attention layer 351, electronic device 110 can determine each model parameter of the attention layer of the second machine learning model 220 based on noise model parameters related to the attention layer (e.g., query model parameters, key model parameters, value model parameters, and output model parameters, etc.), and then update the processing related to the attention layer 351 of the second machine learning model 220.
[0082] Specifically, in the process of removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters, a second confusion matrix and a third confusion matrix can be determined based on the blocks associated with the attention model parameters, the dimensions of the second and third confusion matrices being equal to the dimensions of the blocks; and a linear transformation is performed on the attention model parameters based on the second and third confusion matrices to obtain the portions of the second model parameters corresponding to the attention model parameters. In this way, the process of introducing and removing noise can be transformed into a simple computational process, thereby improving the security of calling the machine learning model.
[0083] The blocks associated with the attention model parameters can be determined. Here, the block size can be 2×2. A second confusion matrix (e.g., a rotation matrix) and a third confusion matrix (e.g., a scaling matrix) corresponding to the blocks can be determined. Here, the rotation and scaling matrices can be determined in various ways, for example, randomly. The rotation and scaling matrices have the same dimension and are smaller than the dimension of the attention model parameters.
[0084] Furthermore, the electronic device 110 can update the noise model parameters related to the attention layer based on the following formula, thereby determining the model parameters at the attention layer in the second machine learning model, and then updating the processing procedures related to the attention layer:
[0085]
[0086] In the above formula, For the parameters of the transformed query model, For the key model parameters of the transformation, For the value model parameters of the transformation, Let S be the output model parameters of the transformation, R be the second confusion matrix and matrix R be of type random rotation, and S be the third confusion matrix and matrix S be of type random scaling. -1 Let S be the inverse of a randomly scaled matrix. The diagonal elements of matrix S are randomly selected. For example, the diagonal elements of matrix S can be uniformly distributed in (-1, 1).
[0087] The electronic device can determine the query model parameters and key model parameters at the attention layer of the second machine learning model based on the rotation matrix and the scaling matrix. As shown in Equation (10), the electronic device 110 can perform a linear transformation on the query model parameters based on the second confusion matrix R and the third confusion matrix S to obtain the transformed query model parameters. As shown in Equation (11), the electronic device 110 can perform a linear transformation on the key model parameters based on the inverse matrix of the second confusion matrix and the inverse matrix of the third confusion matrix to obtain the transformed key model parameters.
[0088] In some embodiments, matrix R can be a matrix with a block size of 2, for example, as shown in formula (12). In this formula, It is a random value.
[0089]
[0090] In some embodiments, during the processing of the output of the embedding layer 340 using the attention layer 351, the query features of the attention layer can be determined by the following formula:
[0091]
[0092] In the above formula, q represents the feature of the query input to attention layer 351. For example, at layer 1, q is a row vector in the input embedding. The RoPE operator can be rotated by a rotation matrix. By substitution, we can obtain the following formula:
[0093]
[0094] In the above formula, x is the position of feature q in the feature sequence, and θ x This is the angle corresponding to that position. The key features of the attention layer can be determined by the following formula:
[0095]
[0096] In the above formula, k represents the key feature input to attention layer 351, y represents the position of feature k in the feature sequence, and θ represents the position of feature k in the feature sequence. y This represents the angle corresponding to that position. Both matrices S and R can be related to... sum matrix By exchanging these terms, we can derive the following formula:
[0097]
[0098] Using the above embodiments, noise can be introduced into a machine learning model in a simpler and more effective way to improve the model's security. Furthermore, the influence of noise can be eliminated during the internal processing of the machine learning model, thereby ensuring that the output of the machine learning model is consistent with the output without introduced noise (e.g., results determined based on plaintext). Thus, security can be improved while ensuring the accuracy of the machine learning model.
[0099] In one embodiment, the attention model parameters further include value model parameters and output model parameters. In the process of removing noise from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters, a fourth confusion matrix, which is an invertible matrix, can be determined based on a Gaussian distribution; and a linear transformation is performed on the attention model parameters based on the fourth confusion matrix and the first confusion matrix to obtain the portions of the second model parameters corresponding to the value model parameters and the output model parameters, respectively. In this way, the confusion matrix can be used to process the value model parameters and output model parameters in the attention model parameters, thereby improving security while ensuring the accuracy of the machine learning model. The value model parameters and output model parameters in the second machine learning model can be determined using the following formula.
[0100]
[0101] In the above formula, U is the fourth confusion matrix and matrix U is the result of... The d×d dimensional matrix obtained by sampling, U -1 Let U be the inverse matrix of matrix U. As shown in equation (17), electronic device 110 can be based on the inverse matrix U of the fourth confusion matrix U. -1 The inverse matrix P of the first confusion matrix -1 The value model parameters are linearly transformed to obtain the transformed value model parameters. As shown in Equation (18), the electronic device 110 can perform a linear transformation on the output model parameters based on the fourth confusion matrix U and the first confusion matrix P to obtain the transformed output model parameters. The electronic device 110 can determine the processing procedure at the attention layer of the second machine learning model based on the transformed query model parameters, the transformed key model parameters, the transformed value model parameters, and the transformed output model parameters.
[0102] For ease of description, the result of Q*K processed by the Softmax function can be denoted as Γ. The calculation process of the value features and output features can be determined by the following formula:
[0103]
[0104] In the above formula, v is the embedding of the value and comes from the embedding layer or the output of the previous transformer block. P on the right is added when transforming the embedding matrix or the feedforward network output. It can be seen that the output of the transformed attention layer, compared to the output of the attention layer before transformation (the result calculated in plaintext), only has the addition of a first confusion matrix P, the influence of which will be eliminated in the feedforward network.
[0105] In one embodiment, the model parameters of the feedforward layer can be processed in a similar manner. The first model parameters include the feedforward model parameters at the feedforward layer in the first machine learning model, which include upsampled model parameters, downsampled model parameters, and gate model parameters. In the process of removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters: multiple fifth confusion matrices (which may include permutation matrices and scaling matrices) are generated randomly; and the feedforward model parameters are linearly transformed based on the first confusion matrix and the multiple fifth confusion matrices to obtain the second model parameters. In this way, confusion matrices can be used to process the upsampled model parameters, downsampled model parameters, and gate model parameters in the feedforward layer model parameters, thereby improving security while ensuring the accuracy of the machine learning model.
[0106] For attention layer 351, electronic device 110 can update the noise model parameters (e.g., upsampling model parameters, downsampling model parameters, and gate model parameters) related to the feedforward layer based on the confusion matrix, thereby determining the feedforward model parameters of the second machine learning model and updating the processing procedures related to feedforward layer 352 of the second machine learning model 220. Electronic device 110 can determine the noise model parameters related to the feedforward layer based on the following formula, thereby updating the processing procedures related to the feedforward layer:
[0107]
[0108] In the above formula, The parameters of the upsampling model are for the transformation. The parameters of the downsampling model are for the transformation. These are the gate model parameters for the transformation. Multiple fifth confusion matrices can include: H, S Up S Down Matrix H is a random permutation matrix, where each row and column of matrix H contains only one element that is 1, and all other elements are 0. -1 Let S be the inverse of matrix H. Up Sum of matrix S Down For a randomly scaled matrix and SUp S Down =I. For the noise model parameters of the upsampled model parameters, These are the noise model parameters for the downsampling model parameters.
[0109] As shown in equations (20) to (22), the electronic device 110 can be based on the inverse matrix P of the first confusion matrix. -1 Matrix H and S Up A linear transformation is performed on the upsampling model parameters to obtain the transformed upsampling model parameters. Electronic device 110 can be based on the inverse matrix P of the first confusion matrix. -1 The gate model parameters are linearly transformed using the first confusion matrix P and matrix H to obtain the transformed gate model parameters. Electronic device 110 can be based on the first confusion matrix P and matrix H. -1 and S Down The downsampling model parameters are linearly transformed to obtain the transformed downsampling model parameters. Subsequently, the electronic device 110 determines the feedforward layer processing procedure based on the transformed upsampling model parameters, the transformed downsampling model parameters, and the transformed gate model parameters.
[0110] During the information processing process of the electronic device 110 using the feedforward layer 352, the features corresponding to the embedding and attention layer 342 outputs of the cue word information 310 can be residually linked. Here, the output of the feedforward layer 352 can be denoted as FP, and the output of the upsampling layer can be determined by the following formula, where g up For the output of the upsampling layer, g gate For the output of the gating layer:
[0111]
[0112] The input to the downsampling layer can be determined by the following formula:
[0113] g = g up ⊙g gate =(FW2⊙SiLU(FW1))S Up H (25)
[0114] The output of the downsampling layer (i.e., the output of the feedforward layer) can be determined by the following formula:
[0115] o = gH -1 S Down W3P=(FW2⊙SiLU(FW1))W3P (26)
[0116] It can be seen that the output of the transformed feedforward layer is only slightly different from the output of the original feedforward layer (the result determined in plaintext) except for the addition of the first confusion matrix P, the influence of which will be eliminated in the output layer.
[0117] In some embodiments, the model parameters at the output head layer can be processed in a similar manner. Here, the first model parameters include the output head model parameters at the output head layer of the first machine learning model, and removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters includes: performing a linear transformation on the updated noisy model parameters based on the inverse matrix of the first confusion matrix to obtain the second model parameters. In this way, the influence of the confusion of the first confusion matrix introduced in the previous processing can be eliminated, thereby improving security while ensuring the accuracy of the machine learning model.
[0118] Specifically, the electronic device 110 can update the noise model parameters of the output layer based on the vocabulary transformation rule 240 to form updated noise model parameters. For example, the electronic device 110 can use the vocabulary transformation rule 240 as a seed matrix to perform a permutation operation on the output head model parameters. The updated output head model parameters are:
[0119]
[0120] To accommodate the obfuscation of the first machine learning model, the electronic device 110 can update the processing procedures related to the output layer based on the updated output head model parameters. The electronic device 110 can update the output head model parameters based on the following formula, thereby updating the processing procedures related to the output layer, where P... -1 This is the inverse of the first confusion matrix. For the parameters of the second transformation model:
[0121]
[0122] According to equation (28) above, electronic device 110 can perform a linear transformation on the updated noise model parameters based on the inverse matrix of the first confusion matrix to obtain the output head model parameters at the output head layer of the second machine learning model. Subsequently, electronic device 110 can determine the processing procedure at the output head layer of the second machine learning model based on these output head model parameters.
[0123] As can be seen from equations (8), (9), and (28) above, the electronic device 110 updates the processing related to the embedding layer, output layer, and word segmentation table of the machine learning model based on the first confusion matrix and the inverse matrix of the first confusion matrix. During the process of the electronic device processing prompt word information using the encrypted word segmenter and embedding layer, since the original word list and noise model parameters are processed based on the same confusion matrix, the tokens corresponding to the user request are still converted into the correct encrypted token sequence.
[0124] In the process described above, involving adding noise to the model parameters of a machine learning model and performing a linear transformation on the noisy model parameters, if the first confusion matrix P is leaked to a third party, it could lead to information leakage during the machine learning model's processing. For example, a third party could determine the parameter combination of a second machine learning model based on the first confusion matrix P. For instance, if a third party knows the individual model parameters in the second machine learning model, they could potentially calculate and determine the first confusion matrix P, thereby posing a security threat. For example, when the dimension d of the machine learning model is 2... 12 At that time, the computational complexity is 2. 72 The above, and the space complexity is 2. 42 That concludes the above process. Despite the significant computational overhead, the possibility of data leakage still exists.
[0125] Therefore, to further improve model security, the electronic device 110 can allow the second machine learning model to increase the hidden layer dimension. In one embodiment, the first model parameters are the model parameters at layers among multiple layers of the first machine learning model. For each layer among multiple layers, the first dimension of the first model parameters at that layer can be expanded to a second dimension based on a predetermined expansion dimension; a confusion matrix is determined based on the expanded dimension and the first dimension; and the second model parameters are determined based on the confusion matrix. In this case, the second machine learning model can use the additional dimension to increase the randomness of the first confusion matrix P, thereby ensuring that each layer in the second machine learning model uses a different first confusion matrix. For example, the increased hidden layer dimension d... ′ It can be determined by the following formula, where h is the extended dimension:
[0126] d′=d+2*h (29)
[0127] Electronic device 110 can be based on a predetermined extended dimension h and a predetermined pair of inverse matrices B. d×d , d′×d′ dimensional permutation matrix Z, non-full rank matrix E d×h and F d×h Generate the first confusion matrix P at each layer. i In some embodiments, the electronic device 110 can construct a matrix associated with a first machine learning model (i.e., B) by concatenating the matrix. d×d or ), for the random matrix of the model structure layer associated with the model parameters (i.e., C i Or D i ) and the matrix associated with the first machine learning model (i.e., E) d×h or F d×hThis forms a sampling matrix for the model structure layer. Subsequently, the electronic device 110 performs a linear transformation on the sampling matrix using the permutation matrix Z to obtain the first confusion matrix P corresponding to the model structure layer. i .
[0128] For example, electronic device 110 first obtains a d×h-dimensional random matrix C through sampling. i And matrix C i Satisfy C i When F = 0, the confusion matrix can be determined by the following formula, where P i The confusion matrix corresponding to the i-th model structure layer is:
[0129] P i =[BC i E d×h Z (30)
[0130] In some embodiments, the electronic device 110 can obtain a d×h-dimensional random matrix C through sampling. i And matrix D i Satisfy F·D i =0, the inverse of the confusion matrix can be determined by the following formula, where The inverse matrix of the confusion matrix corresponding to the i-th model structure layer is:
[0131]
[0132] For any model structure layer, the confusion matrix and its inverse matrix corresponding to that model structure layer both satisfy the following formula (i and j are different integers):
[0133]
[0134] It can be seen that the confusion matrix P determined by the above formula i The performance of the machine learning model is consistent with that of the fixed first confusion matrix P, both effectively removing the introduced noise. Regarding the aforementioned confusion matrix P... i For a given model structure layer, the following relationship exists:
[0135]
[0136] In the above formula, It is the parameter combination of the second machine learning model, W i It is the d×d dimension parameter matrix of the first machine learning model. It is the Kronecker product, vec(P) i ) is the matrix P i The parameters are a column vector stacked column by column, vec([BCi E d×h ]Z) is the matrix [BC i E d×h The Z parameter is a column vector stacked column by column.
[0137] If matrix Z cannot be determined, the third party needs to determine the confusion matrix P. i The solution is then performed by converting the model into a matrix containing unknown parameters (d and d'). Since the matrix Z is undetermined, if the expanded dimension h is sufficiently large, it will prevent a third party from determining the parameters of the confusion matrix. This improves the security of the second machine learning model.
[0138] In some embodiments, electronic device 110 may deploy a second machine learning model on a server device to implement data processing platform 270 within the server device. Data processing platform 270 provides inference services to users based on the second machine learning model 230.
[0139] The above embodiments disclose aspects related to model transformation and model deployment. In some embodiments, the electronic device 110 can perform data processing tasks on received user requests. For example, the electronic device 110 can acquire user requests and send them to a data processing platform to provide services to the user based on feedback from the data processing platform 270.
[0140] During the data processing phase, if electronic device 110 receives a first user request from user 140, it converts the first user request into an encrypted second user request based on the lexical transformation rule 240. The first user request instructs the user on a task related to the inference service. (Return to reference) Figure 2 Based on a first user request, electronic device 110 determines initial prompt word information 250 indicating the user's intent. Subsequently, electronic device 110 performs word segmentation on the initial prompt word information 250 using an original vocabulary 241 to obtain corresponding tags. Electronic device 110 can determine the mapping relationship between the original words and obfuscated words specified by the vocabulary conversion rules using an obfuscation vocabulary 231 corresponding to the second machine learning model 230. Then, based on this mapping relationship, electronic device 110 performs inverse word segmentation on the tags, converting the first word in the first user request into a second word in the second user request corresponding to the first word. Thus, the tags can be encrypted to obtain encrypted prompt word information 251 (i.e., the second user request 252).
[0141] Electronic device 110 can provide a second user request to data processing platform 270. Data processing platform 270 processes the second user request using a second machine learning model and provides a response to the second user request. In some embodiments, data processing platform 270 may include multiple second machine learning models. Data processing platform 270 can determine the second machine learning model corresponding to a user based on a user identifier, and then process the second user request based on the determined second machine learning model. Data processing platform 270 can determine the second machine learning model corresponding to a user request based on the selection of a particular machine learning model in the second user request. Therefore, by processing the first user request using a confused vocabulary 231 encrypted with unified vocabulary conversion rules and the second machine learning model 230, the accuracy of data processing can be guaranteed in a unified manner while ensuring information security. In this way, the complexity of managing multiple machine learning models can be reduced.
[0142] In some embodiments, during the process of converting feedback into a response to a first user request based on lexical transformation rules, feedback from a server for a second user request can be received, and this feedback is encrypted; and the encrypted feedback is converted into a decrypted response based on lexical transformation rules. In this way, it can be ensured that the user-side device can obtain a response represented in plaintext format.
[0143] Specifically, electronic device 110 receives the response from data processing platform 270 to the second user's request, which is an encrypted response 261. Subsequently, electronic device 110 can convert the encrypted response into a decrypted response based on a word-switching rule. Electronic device 110 performs word segmentation on the encrypted response 261 using a confusion word list 231 to obtain corresponding tags. Then, electronic device 110 uses the original word list 240 to perform inverse word segmentation on the tags to obtain the decrypted response 260. For example, electronic device 110 can convert the third word in the encrypted response into the corresponding fourth word in the decrypted response based on the mapping relationship between the original words and confusion words specified by the word-switching rule, thereby determining the decrypted response. Electronic device 110 can then provide the decrypted response to user 140 as a response to the first user's request.
[0144] The process of the method executed at electronic device 110 has been described in detail above. Alternatively and / or additionally, this disclosure further provides an inference method for model security. The method includes: acquiring a second machine learning model, the second machine learning model being obtained by encrypting a first machine learning model based on a lexical transformation rule; receiving a second user request, the second user request being obtained by encrypting the first user request based on a lexical transformation rule; and processing the second user request based on the second machine learning model to generate a response to the second user request. In some embodiments, the method may be executed at a server. In this manner, it can be ensured that both the user request and the machine learning model at the server are encrypted, thereby improving the security of the inference process.
[0145] In some embodiments, obtaining the second machine learning model includes obtaining the second machine learning model from the first user. Here, the second machine learning model may be an encrypted machine learning model determined based on the manner described above.
[0146] In some embodiments, receiving a second user request includes receiving the second user request from a first user. Here, the second user request may be an encrypted user request determined based on the manner described above.
[0147] In some embodiments, the method further includes sending feedback to a first user. Here, the feedback may be encrypted feedback determined based on the manner described above.
[0148] In some embodiments, the first machine learning model includes first model parameters, and the second machine learning model is obtained by: adding noise to the first model parameters to determine noisy model parameters; updating the order of multiple dimensions of the noisy model parameters based on vocabulary transformation rules to form updated noisy model parameters; and removing noise from the updated noisy model parameters to determine second model parameters of the second machine learning model corresponding to the first model parameters. The second model parameters of the second machine learning model can be determined based on the various formulas described above.
[0149] In some embodiments, the first model parameters are model parameters at a layer among multiple layers of a first machine learning model, and removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters includes: for a layer among multiple layers, expanding a first dimension of the first model parameters at the layer to a second dimension based on a predetermined expansion dimension; determining a confusion matrix based on the expansion dimension and the first dimension; and determining the second model parameters based on the confusion matrix.
[0150] This disclosure utilizes obfuscation-based encryption of machine learning model processing to improve the security of machine learning models. Specifically, the technical solution described above is compatible with mainstream models, providing encrypted machine learning models without requiring adjustments to model training and fine-tuning. The proposed method offers higher security and provides accuracy consistent with plaintext processing. Furthermore, the proposed method incurs only a low computational load. For example, offline model obfuscation processing can be performed on conventional electronic devices, and the processing time is controlled to approximately half an hour based on the processing power of conventional computing devices. In subsequent online inference processes, the inference efficiency is consistent with that of plaintext processing.
[0151] Example Process
[0152] Figure 4A A flowchart of an example process 400A for model-secure reasoning according to some embodiments of the present disclosure is shown. Process 400A may be implemented in electronic device 110. Process 400A is described below as an example only with respect to a server.
[0153] like Figure 4A As shown, in box 410A, the first machine learning model is converted into an encrypted second machine learning model based on the lexical transformation rules. In box 420A, in response to receiving a first user request, the first user request is converted into an encrypted second user request based on the lexical transformation rules. In box 430A, feedback for the second user request is obtained; the feedback is generated by the second machine learning model processing the second user request. In box 440A, the feedback is converted into a response to the first user request based on the lexical transformation rules.
[0154] In some embodiments, the process 400 is performed by a user-side device, and the method further includes: sending a second machine learning model to a server; sending a second user request to the server; and receiving feedback from the server.
[0155] In some embodiments, the first machine learning model includes first weights, and converting the first machine learning model into an encrypted second machine learning model includes: adding noise to the first weights to determine noise weights; updating the order of multiple dimensions of the noise weights based on a vocabulary conversion rule to form updated noise weights; and removing noise from the updated noise weights to determine second weights of the second machine learning model corresponding to the first weights.
[0156] In some embodiments, adding noise to a first weight to determine a noise weight includes: determining the noise to be added to the first weight based on a range of values associated with the first weight; and determining the noise weight based on an influence factor and noise associated with the first weight.
[0157] In some embodiments, the first weights include the embedding weights at the embedding layer of the first machine learning model, and removing noise from the updated noise weights to determine the second weights of the second machine learning model corresponding to the first weights includes: determining a first confusion matrix based on a Gaussian distribution; and performing a linear transformation on the updated noise weights based on the first confusion matrix to obtain the second weights.
[0158] In some embodiments, the first weight includes the output head weight at the output head layer of the first machine learning model, and removing noise from the updated noise weight to determine the second weight corresponding to the first weight of the second machine learning model includes: performing a linear transformation on the updated noise weight based on the inverse matrix of the first confusion matrix to obtain the second weight.
[0159] In some embodiments, the first weight includes attention weights at the attention layer of the first machine learning model, the attention weights including query weights and key weights, and removing noise from the updated noise weights to determine the second weights of the second machine learning model corresponding to the first weights includes: determining a second confusion matrix and a third confusion matrix based on blocks associated with the attention weights, the dimensions of the second confusion matrix and the third confusion matrix being equal to the dimensions of the blocks; and performing a linear transformation on the attention weights based on the second confusion matrix and the third confusion matrix to obtain portions of the second weights corresponding to the query weights and key weights, respectively.
[0160] In some embodiments, the attention weights further include value weights and output weights, and removing noise from the updated noise weights to determine the second weights of the second machine learning model corresponding to the first weights includes: determining a fourth confusion matrix based on a Gaussian distribution, the fourth confusion matrix being an invertible matrix; and performing a linear transformation on the attention weights based on the fourth confusion matrix and the first confusion matrix to obtain the portions of the second weights corresponding to the value weights and output weights, respectively.
[0161] In some embodiments, the first weight includes feedforward weights at the feedforward layer in the first machine learning model, the feedforward weights including upsampling weights, downsampling weights and gate weights, and removing noise from the updated noise weights to determine the second weights of the second machine learning model corresponding to the first weights includes: generating a plurality of fifth confusion matrices in a random manner; and performing a linear transformation on the feedforward weights based on the first confusion matrix and the plurality of fifth confusion matrices to obtain the portions of the second weights corresponding to the upsampling weights, downsampling weights and gate weights, respectively.
[0162] In some embodiments, the first model parameters are model parameters at a layer among multiple layers of a first machine learning model. Removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters includes: for a layer among multiple layers, expanding a first dimension of the first model parameters at the layer to a second dimension based on a predetermined expansion dimension; determining a confusion matrix based on the expansion dimension and the first dimension; and determining the second model parameters based on the confusion matrix.
[0163] In some embodiments, converting a first user request into an encrypted second user request based on a lexicon conversion rule includes: converting a first word in the first user request into a second word in the second user request corresponding to the first word, based on the mapping relationship between the original word and the obfuscated word specified by the lexicon conversion rule.
[0164] In some embodiments, converting feedback into a response to a first user request based on a lexicon conversion rule includes: receiving feedback from a server for a second user request, wherein the feedback is an encrypted response; and converting the encrypted feedback into a decrypted response based on the lexicon conversion rule.
[0165] In some embodiments, converting an encrypted response into a decrypted response based on a lexicon conversion rule includes: converting a third word in the encrypted response into a fourth word in the decrypted response corresponding to the third word, based on the mapping relationship between the original words and obfuscated words specified by the lexicon conversion rule.
[0166] Figure 4B A flowchart of an example process 400B for model-secure reasoning according to some embodiments of the present disclosure is shown. Process 400B may be implemented in electronic device 110. Process 400B is described below as an example only with respect to a server.
[0167] like Figure 4B As shown, in box 410B, a second machine learning model is obtained, which is obtained by encrypting the first machine learning model based on a lexical transformation rule. In box 420B, a second user request is received, which is obtained by encrypting the first user request based on a lexical transformation rule. In box 430B, the second user request is processed based on the second machine learning model to generate feedback for the second user request.
[0168] In some embodiments, obtaining the second machine learning model includes obtaining the second machine learning model from the first user.
[0169] In some embodiments, receiving a second user request includes receiving a second user request from a first user.
[0170] In some embodiments, process 400B further includes sending feedback to the first user.
[0171] In some embodiments, the first machine learning model includes first model parameters, and the second machine learning model is obtained by: adding noise to the first model parameters to determine noisy model parameters; updating the order of multiple dimensions of the noisy model parameters to form updated noisy model parameters based on vocabulary transformation rules; and removing noise from the updated noisy model parameters to determine second model parameters of the second machine learning model corresponding to the first model parameters.
[0172] In some embodiments, the first model parameters are model parameters at a layer among multiple layers of a first machine learning model, and the second model parameters are determined based on the following: for a layer among multiple layers, expanding a first dimension of the first model parameters at the layer to a second dimension based on a predetermined expansion dimension; determining a confusion matrix based on the expansion dimension and the first dimension; and determining the second model parameters based on the confusion matrix.
[0173] Example Devices and Apparatus
[0174] Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes. Figure 5A A schematic structural block diagram of an example device 500A for model-safe reasoning according to certain embodiments of the present disclosure is shown. Device 500A may be implemented as or included in electronic device 110. Various modules / components in device 500A may be implemented by hardware, software, firmware, or any combination thereof.
[0175] like Figure 5A As shown, the apparatus 500A includes: a first conversion module 510A configured to convert a first machine learning model into an encrypted second machine learning model based on a lexicon conversion rule; a second conversion module 520A configured to, in response to receiving a first user request, convert the first user request into an encrypted second user request based on the lexicon conversion rule; an acquisition module 530A configured to acquire feedback for the second user request, the feedback being generated by the second machine learning model processing the second user request; and a third conversion module 540A configured to convert the feedback into a response for the first user request based on the lexicon conversion rule.
[0176] In some embodiments, the apparatus is implemented by a user-side device, and the apparatus further includes a processing module configured to: send a second machine learning model to a server; send a second user request to the server; and receive feedback from the server.
[0177] In some embodiments, the first conversion module 510 is further configured to: determine noise to be added to the first weight based on the value range associated with the first weight; and determine a noise weight based on the influence factor and noise associated with the first weight.
[0178] In some embodiments, the first weights include the embedding weights at the embedding layer of the first machine learning model, and the first transformation module 510 is further configured to: determine a first confusion matrix based on a Gaussian distribution; and perform a linear transformation on the updated noise weights based on the first confusion matrix to obtain a second weight.
[0179] In some embodiments, the first weights include the output head weights at the output head layer of the first machine learning model, and the first transformation module 510 is further configured to: perform a linear transformation on the updated noise weights based on the inverse of the first confusion matrix to obtain the second weights.
[0180] In some embodiments, the first weight includes attention weights at the attention layer of the first machine learning model, the attention weights including query weights and key weights, and the first transformation module 510 is further configured to: determine a second confusion matrix and a third confusion matrix based on blocks associated with the attention weights, the dimensions of the second confusion matrix and the third confusion matrix being equal to the dimensions of the blocks; and perform a linear transformation on the attention weights based on the second confusion matrix and the third confusion matrix to obtain portions of the second weights corresponding to the query weights and key weights, respectively.
[0181] In some embodiments, the attention weights further include value weights and output weights, and the first transformation module 510 is further configured to: determine a fourth confusion matrix based on a Gaussian distribution, the fourth confusion matrix being an invertible matrix; and perform a linear transformation on the attention weights based on the fourth confusion matrix and the first confusion matrix to obtain portions of the second weights corresponding to the value weights and output weights, respectively.
[0182] In some embodiments, the first weight includes feedforward weights at the feedforward layer in the first machine learning model, the feedforward weights including upsampling weights, downsampling weights and gate weights, and the first transformation module 510 is further configured to: generate a plurality of fifth confusion matrices in a random manner; and perform a linear transformation on the feedforward weights based on the first confusion matrix and the plurality of fifth confusion matrices to obtain the portions of the second weights that correspond to the upsampling weights, downsampling weights and gate weights respectively.
[0183] In some embodiments, the first weight is the weight at a layer among multiple layers of the first machine learning model, and the first transformation module 510 is further configured to: for a layer among multiple layers, extend the first dimension of the first weight at the layer to a second dimension based on a predetermined extension dimension; determine a confusion matrix based on the extension dimension and the first dimension; and determine second model parameters based on the confusion matrix.
[0184] In some embodiments, the second conversion module 530 is further configured to: convert the first word in the first user request into the second word in the second user request corresponding to the first word, based on the mapping relationship between the original word and the confused word specified by the word list conversion rules.
[0185] In some embodiments, the apparatus further includes a processing module configured to: receive feedback from a server in response to a second user request, wherein the response is encrypted; and convert the encrypted feedback into a decrypted response based on a lexicographical conversion rule.
[0186] In some embodiments, the processing module is further configured to: convert the third word in the encrypted response into the fourth word in the decrypted response corresponding to the third word, based on the mapping relationship between the original word and the obfuscated word specified by the vocabulary conversion rules.
[0187] Figure 5B A schematic structural block diagram of an example device 500B for model-secure reasoning according to certain embodiments of the present disclosure is shown. Device 500B may be implemented as or included in a server. The various modules / components in device 500B may be implemented by hardware, software, firmware, or any combination thereof.
[0188] like Figure 5B As shown, the device 500B includes: an acquisition module 510B configured to acquire a second machine learning model, the second machine learning model being obtained by encrypting a first machine learning model based on a word conversion rule; a receiving module 520B configured to receive a second user request, the second user request being obtained by encrypting a first user request based on a word conversion rule; and a generation module 530B configured to process the second user request based on the second machine learning model to generate feedback for the second user request.
[0189] In some embodiments, the acquisition module 510B is further configured to: acquire a second machine learning model from a first user.
[0190] In some embodiments, the receiving module 520B is further configured to: receive a second user request from the first user.
[0191] In some embodiments, the device 500B further includes a processing module configured to send feedback to a first user.
[0192] In some embodiments, the first machine learning model includes first model parameters, and the second machine learning model is obtained by: adding noise to the first model parameters to determine noisy model parameters; updating the order of multiple dimensions of the noisy model parameters to form updated noisy model parameters based on vocabulary transformation rules; and removing noise from the updated noisy model parameters to determine second model parameters of the second machine learning model corresponding to the first model parameters.
[0193] In some embodiments, the first model parameters are model parameters at a layer among multiple layers of a first machine learning model, and the second model parameters are determined based on the following: for a layer among multiple layers, expanding a first dimension of the first model parameters at the layer to a second dimension based on a predetermined expansion dimension; determining a confusion matrix based on the expansion dimension and the first dimension; and determining the second model parameters based on the confusion matrix.
[0194] The methods described above can be performed using electronic devices. For example... Figure 6 As shown, electronic device 600 is in the form of a general-purpose electronic device. Components of electronic device 600 may include, but are not limited to, one or more processors or processor 610, memory 620, storage device 630, one or more communication units 640, one or more input devices 690, and one or more output devices 660. Processor 610 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 620. In a multiprocessor system, multiple processors execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 600.
[0195] Electronic device 600 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 600, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 620 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 630 can be removable or non-removable media and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data and can be accessed within electronic device 600.
[0196] Electronic device 600 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated...Figure 6 As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 620 may include computer program product 625 having one or more program modules configured to perform various methods or actions of various embodiments of this disclosure.
[0197] The communication unit 640 enables communication with other electronic devices via a communication medium. Additionally, the functionality of the components of the electronic device 600 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, the electronic device 600 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.
[0198] Input device 650 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 660 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 600 can also communicate with one or more external devices (not shown) via communication unit 640 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 600, or with any device that enables electronic device 600 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interface (not shown).
[0199] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above. According to an exemplary implementation of this disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.
[0200] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0201] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0202] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0203] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0204] Various implementations of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.
Claims
1. A method for model-safe reasoning, comprising: Based on the vocabulary conversion rules, the first machine learning model is converted into an encrypted second machine learning model; In response to receiving a first user request, the first user request is converted into an encrypted second user request based on the vocabulary conversion rules; Obtain feedback in response to the second user request, the feedback being generated by the second machine learning model processing the second user request; as well as Based on the vocabulary conversion rules, the feedback is converted into a response to the first user's request.
2. The method according to claim 1, wherein, The method is performed by a user-side device, and the method further includes: Send the second machine learning model to the server; and The second user request is sent to the server, and the feedback is received from the server.
3. The method of claim 1, wherein the first machine learning model includes first model parameters, and converting the first machine learning model into an encrypted second machine learning model comprises: Noise is added to the first model parameters to determine the noise model parameters; Based on the vocabulary conversion rules, the order of multiple dimensions of the noise model parameters is updated to form updated noise model parameters; as well as Noise is removed from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters.
4. The method of claim 3, wherein adding noise to the first model parameters to determine the noise model parameters comprises: Based on the value range associated with the first model parameters, the noise to be added to the first model parameters is determined; as well as The noise model parameters are determined based on the influence factors associated with the first model parameters and the noise.
5. The method of claim 3, wherein the first model parameters include embedded model parameters at the embedding layer of the first machine learning model, and removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters comprises: The first confusion matrix is determined based on the Gaussian distribution; as well as The updated noise model parameters are linearly transformed based on the first confusion matrix to obtain the second model parameters.
6. The method of claim 5, wherein the first model parameters include output head model parameters at the output head layer of the first machine learning model, and removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters comprises: The updated noise model parameters are linearly transformed based on the inverse of the first confusion matrix to obtain the second model parameters.
7. The method of claim 5, wherein the first model parameters include attention model parameters at the attention layer of the first machine learning model, the attention model parameters including query model parameters and key model parameters, and removing noise from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters comprises: Based on the blocks associated with the attention model parameters, a second confusion matrix and a third confusion matrix are determined, wherein the dimensions of the second confusion matrix and the third confusion matrix are equal to the dimensions of the blocks; as well as The attention model parameters are linearly transformed based on the second confusion matrix and the third confusion matrix to obtain the portions of the second model parameters that correspond to the query model parameters and the key model parameters, respectively.
8. The method of claim 7, wherein the attention model parameters further include value model parameters and output model parameters, and removing noise from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters comprises: The fourth confusion matrix is determined based on the Gaussian distribution, and the fourth confusion matrix is an invertible matrix; as well as Based on the fourth confusion matrix and the first confusion matrix, the attention model parameters are linearly transformed to obtain the portions of the second model parameters that correspond to the value model parameters and the output model parameters, respectively.
9. The method of claim 5, wherein the first model parameters include feedforward model parameters at the feedforward layer in the first machine learning model, the feedforward model parameters including upsampling model parameters, downsampling model parameters, and gate model parameters, and removing noise from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters includes: Multiple fifth confusion matrices are generated using a random method; as well as Based on the first confusion matrix and the plurality of fifth confusion matrices, the feedforward model parameters are linearly transformed to obtain the portions of the second model parameters that correspond to the upsampling model parameters, the downsampling model parameters, and the gate model parameters, respectively.
10. The method of claim 3, wherein the first model parameters are model parameters at a layer among a plurality of layers of the first machine learning model, and removing noise from the updated noisy model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters comprises: For the layer among the plurality of layers, Based on a predetermined expansion dimension, the first dimension of the first model parameter at the layer is expanded to a second dimension; Based on the extended dimension and the first dimension, a confusion matrix is determined; as well as Based on the confusion matrix, the parameters of the second model are determined.
11. The method of claim 1, wherein converting the first user request into an encrypted second user request based on the vocabulary conversion rule comprises: Based on the mapping relationship between the original words and the confused words specified by the word list conversion rules, the first word in the first user request is converted into the second word in the second user request corresponding to the first word.
12. The method of claim 1, wherein converting the feedback into the response to the first user request based on the vocabulary conversion rule comprises: Receive the feedback from the server in response to the second user's request, wherein the feedback is encrypted; as well as Based on the aforementioned vocabulary conversion rules, the encrypted feedback is converted into a decrypted response.
13. The method of claim 12, wherein converting the encrypted feedback into the decrypted response based on the vocabulary conversion rule comprises: Based on the mapping relationship between the original words and the obfuscated words specified by the word list conversion rules, the third word in the encrypted feedback is converted into the fourth word in the decrypted response corresponding to the third word.
14. A reasoning method for model safety, comprising: Obtain a second machine learning model, which is obtained by encrypting the first machine learning model based on vocabulary transformation rules; Receive a second user request, which is obtained by encrypting the first user request based on the vocabulary conversion rules; as well as The second user request is processed based on the second machine learning model to generate feedback for the second user request.
15. The method according to claim 14, wherein, Obtaining the second machine learning model includes: obtaining the second machine learning model from the first user; Receiving the second user request includes: receiving the second user request from the first user; The method further includes sending the feedback to the first user.
16. The method of claim 14, wherein the first machine learning model includes first model parameters, and the second machine learning model is obtained based on: Noise is added to the first model parameters to determine the noise model parameters; Based on the vocabulary conversion rules, the order of multiple dimensions of the noise model parameters is updated to form updated noise model parameters; as well as Noise is removed from the updated noise model parameters to determine the second model parameters of the second machine learning model corresponding to the first model parameters.
17. The method of claim 16, wherein the first model parameters are model parameters at a layer among a plurality of layers of the first machine learning model, and the second model parameters are determined based on: for the layer among the plurality of layers, Based on a predetermined expansion dimension, the first dimension of the first model parameter at the layer is expanded to a second dimension; Based on the extended dimension and the first dimension, a confusion matrix is determined; as well as Based on the confusion matrix, the parameters of the second model are determined.
18. An electronic device comprising: At least one processor; as well as At least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 13 or 14 to 17 when executed by the at least one processor.
19. A computer-readable storage medium having a computer program stored thereon, the computer program being executable by a processor to implement the method according to any one of claims 1 to 13 or 14 to 17.
20. A computer program product comprising a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 13 or 14 to 17.
Citation Information
Patent Citations
Large model reasoning method, device and equipment and storage medium
CN117792739A
TEE-based end-side deep neural network model protection method and system
CN119513858A
System and Method for Confirm Transaction by using Dual Channel
KR1020180022049A
Keyboard input method and system, computer-readable storage medium, electronic device, and computer program product
US20240248547A1