A running mode protection method, system and electronic device suitable for model inference
By generating a public sample set and employing a dual verification mechanism, combined with homomorphic encryption algorithms, the hardware dependency and computational complexity issues of existing model inference security schemes are resolved. This achieves efficient and sensitive protection of model operation modes, ensuring model integrity and privacy security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
- Filing Date
- 2026-02-04
- Publication Date
- 2026-06-02
AI Technical Summary
Existing model inference security solutions rely on trusted execution environments or dedicated hardware security chips, which are characterized by high cost, poor compatibility, and high performance overhead. Cryptographic methods cannot effectively detect subtle tampering of the model during runtime. Homomorphic encryption and zero-knowledge proofs have high computational complexity and cannot detect tampering attacks with fine precision.
By generating a public sample set and its standard output labels, sensitive samples are randomly selected and duplicated. After mixing and randomly shuffling, the dataset is encrypted using a homomorphic encryption algorithm. Ciphertext inference is performed and double verification is conducted, including verification of the consistency of results for sensitive samples and the consistency of results for duplicates, to ensure the integrity of the model's operating mode.
It achieves highly sensitive integrity protection for model inference at the software level, eliminates dependence on hardware, ensures data privacy and security for model users, and improves the reliability and efficiency of verification results.
Smart Images

Figure CN122137585A_ABST