A running mode protection method, system and electronic device suitable for model inference

By generating a public sample set and employing a dual verification mechanism, combined with homomorphic encryption algorithms, the hardware dependency and computational complexity issues of existing model inference security schemes are resolved. This achieves efficient and sensitive protection of model operation modes, ensuring model integrity and privacy security.

CN122137585APending Publication Date: 2026-06-02NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2026-02-04
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing model inference security solutions rely on trusted execution environments or dedicated hardware security chips, which are characterized by high cost, poor compatibility, and high performance overhead. Cryptographic methods cannot effectively detect subtle tampering of the model during runtime. Homomorphic encryption and zero-knowledge proofs have high computational complexity and cannot detect tampering attacks with fine precision.

Method used

By generating a public sample set and its standard output labels, sensitive samples are randomly selected and duplicated. After mixing and randomly shuffling, the dataset is encrypted using a homomorphic encryption algorithm. Ciphertext inference is performed and double verification is conducted, including verification of the consistency of results for sensitive samples and the consistency of results for duplicates, to ensure the integrity of the model's operating mode.

Benefits of technology

It achieves highly sensitive integrity protection for model inference at the software level, eliminates dependence on hardware, ensures data privacy and security for model users, and improves the reliability and efficiency of verification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137585A_ABST
    Figure CN122137585A_ABST
Patent Text Reader

Abstract

This invention provides a method, system, and electronic device for protecting the operational mode of model inference, relating to the field of artificial intelligence security technology. The method includes: generating a public sample set based on the original model; randomly selecting sensitive samples and copying the query sample to be inferred multiple times, mixing them, and then randomly shuffling them; encrypting the mixed dataset using a homomorphic encryption algorithm and sending it to a remote system for encrypted inference; finally, decrypting and reconstructing the returned encrypted inference result locally, and using double verification to determine whether the operational mode of the remote system is complete. This invention, by generating highly sensitive samples and combining sample copying, random shuffling, and homomorphic encryption algorithms, achieves efficient and reliable detection of tampering with the operational mode of the remote model's inference process, while simultaneously ensuring data privacy.
Need to check novelty before this filing date? Find Prior Art