An end-side large model weight protection method and system based on decryption inference card private memory

By decrypting the private memory system of the inference card, the problems of high leakage risk, low efficiency, or poor versatility in edge-side large model weight protection are solved, achieving efficient and secure edge-side large model weight protection, applicable to various hardware architectures, and improving user experience.

CN122153981APending Publication Date: 2026-06-05SHANGHAI QUSU CHAOWEI TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610016010.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-07
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing mid-side large model weight protection schemes suffer from high leakage risk, low inference efficiency, or poor versatility, failing to simultaneously meet the requirements of secure and reliable operation, efficient inference, and broad applicability.

Method used

An edge-side large model weight protection system based on the private memory of the decryption inference card is adopted. Through the hardware isolation mechanism between the decryption inference card and the host, it is ensured that the model weight is decrypted and inferred only in the private memory of the decryption inference card, avoiding plaintext data leakage. Data interaction is carried out through the PCIe interface to reduce computational overhead.

Benefits of technology

It achieves efficient and secure protection of large model weights on the edge, reduces the risk of model weight leakage, improves inference efficiency, is applicable to various hardware architectures, requires no environment switching, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The application discloses an end-side large model weight protection method based on decryption reasoning card private memory, and aims to solve the problems of high leakage risk, low reasoning efficiency or poor universality of existing protection schemes. The system comprises a large model reasoning application program on the host side, a decryption reasoning card driver program and a decryption reasoning card hardware; ciphertext weights are transmitted into the decryption reasoning card shared memory through the driver, are stored into the private memory accessible only by itself and the reasoning unit after being decrypted by the decryption unit, the reasoning unit reads the weights from the private memory, the shared memory reads the user input during reasoning, and the calculation result is written into the shared memory for the host to read. The plaintext weights only exist in the private memory, the security effect is good, the reasoning has no additional overhead and does not need to be adapted to specific hardware, and the universality is strong.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • End-side large model parameter protection method and system based on trusted execution environment

    CN120744908A