Hardware-level multi-source AI decision consensus reaching method and device, chip, equipment, server and platform
Patent Information
- Application Number
- CN202610404656.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-30
- Publication Date
- 2026-09-11
AI Technical Summary
[0004]然而,这种传统的软件共识方案存在明显的技术缺陷
本申请提供的一种基于硬件级多源AI决策共识达成方法,针对传统软件共识方案存在的时延高、易篡改及容错兜底能力弱等技术缺陷,通过控制硬件仲裁装置通过并行输入缓存单元采集多路推理决策流并确立历史信誉分数,解决了传统方案中多源数据同步困难且缺乏长期信誉考量的问题。相较于传统依赖中间件汇总的方案,本申请通过硬件缓存执行时钟域对齐与数据缓冲,使得异构AI源的决策数据能够以较低的时延差进行并行处理,为硬件级的高速仲裁提供了稳定的数据基准。
Smart Images

Figure CN122735752A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence security and multi-agent system technology, and more specifically, to a method, device, chip, equipment, server, and platform for achieving consensus on hardware-level multi-source AI decision-making. Background Technology
[0002] With the development of safety-critical fields such as autonomous driving, industrial automation, and intelligent financial risk control, AI systems are evolving from independent decision-making by a single model to collaborative decision-making by multiple models and multiple agents. To avoid the risks of algorithmic defects, data poisoning, or model failure that may exist in a single model, it is usually necessary to introduce multiple heterogeneous AI models to cross-validate and reach a consensus on the same task, thereby improving the overall redundancy and decision robustness of the system.
[0003] In existing multi-source AI decision-making schemes, a software-based voting consensus logic is typically employed. This scheme first aggregates the discrete inference decision data output by various AI models through a software middleware layer; then, it calls upon the main processor's computing resources to execute a software voting process based on algorithms such as Byzantine fault tolerance, comparing the consistency of each model's output; finally, it generates a final decision instruction based on the voting results and sends it to the execution mechanism.
[0004] However, this traditional software consensus scheme has significant technical flaws. Since the consensus logic runs entirely at the software level, its execution speed is limited by the main processor's scheduling and bus bandwidth, making it difficult to meet the low-latency requirements of high-frequency real-time decision-making scenarios. Furthermore, the software layer is highly susceptible to malicious bypass or tampering, leading to a loss of credibility in the consensus results. Simultaneously, traditional schemes lack a dynamic hardware evaluation mechanism for AI model credibility. When faced with some models consistently outputting abnormal decisions, it is difficult to implement efficient weighted arbitration and tiered fault-tolerant rollback at the hardware level, resulting in low security and stability of the system under extreme conditions. Summary of the Invention
[0005] This application provides a method, apparatus, chip, device, server, and platform for achieving hardware-level multi-source AI decision consensus, in order to at least alleviate the aforementioned technical problems.
[0006] A hardware-level multi-source AI decision consensus method includes: Step 1: Control the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through the parallel input buffer unit, so as to generate a multi-source inference decision set and establish the historical reputation score of each AI model. Step 2: Call the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body; Step 3: Control the consensus algorithm engine and threshold decision unit to perform parallel consensus calculation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results; Step 4: Utilize the failure rollback controller and evidence solidification unit to perform fault tolerance protection, evidence solidification, and reputation update processing for the hardware consensus decision results.
[0007] Optionally, step 1, controlling the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through a parallel input buffer unit, to generate a multi-source inference decision set and establish the historical reputation score of each AI model, includes: After establishing a sideband communication link between the hardware arbitration device and the inference processors corresponding to each AI model, the parallel input buffer unit in the hardware arbitration device is used to synchronously receive the inference decision streams output by each AI model. The identity identifier, initial decision value, and hardware signature certificate of each AI model are extracted from the inference decision flow corresponding to each AI model to generate a multi-source inference decision set.
[0008] Optionally, step 1, controlling the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through a parallel input buffer unit to generate a multi-source inference decision set and establish the historical reputation score of each AI model, also includes: The parallel input buffer unit performs hardware data buffering and clock domain alignment processing based on a preset bit width on the identity identifiers, initial decision values, and hardware signature credentials of each AI model carried in the inference decision stream to generate a multi-source inference decision set. Access the dynamic reputation assessment unit inside the hardware arbitration device to read the pre-stored historical reputation scores of each AI model.
[0009] Optionally, step 2, invoking the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set, to generate a weighted decision feature body, includes: The multi-source inference decision set is fed to the parallel verification unit, which extracts the initial decision value and hardware signature certificate corresponding to each AI model from the multi-source inference decision set and performs hardware-level signature verification and format legality detection on them to determine the valid decision subset composed of the verified initial decision value and hardware signature certificate for hardware-level aggregation processing to generate a weighted decision feature body.
[0010] Optionally, step 2, which involves invoking the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body, further includes: The dynamic reputation assessment unit is invoked in a coordinated manner. Based on the identity identifiers of each AI model contained in the multi-source inference decision set, the corresponding historical reputation scores and the current business scenario security level are retrieved. Hardware-level aggregation is performed on the initial decision values of each AI in the effective decision subset and the hardware signature credentials to generate a weighted decision feature body that reflects the distribution of the credibility of each AI decision within the current decision cycle.
[0011] Optionally, step 3 involves controlling the consensus algorithm engine and the threshold decision unit to perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate a hardware consensus decision result. The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the trend of multi-source consensus. The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
[0012] Optionally, step 3, controlling the consensus algorithm engine and the threshold decision unit to perform consensus operations and validity determination processing on the weighted decision feature body, to generate a hardware consensus decision result, includes: The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the multi-source consensus trend, and then perform validity determination processing to generate a hardware consensus decision result.
[0013] Optionally, step 3, controlling the consensus algorithm engine and the threshold decision unit to perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results, further includes: The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
[0014] Optionally, step 4, utilizing the failure rollback controller and the evidence solidification unit, performs hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision result, including: The hardware consensus decision result is fed to the failure rollback controller. In response to the consensus failure state carried in the hardware consensus decision result, the built-in four-level hardware state machine automatically triggers a graded rollback action including retry, backup switch, manual intervention and emergency termination to block decision risks without software intervention. Optionally, step 4, utilizing the failure rollback controller and the evidence solidification unit, performs hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision result, including: The driving evidence solidification unit extracts the hardware consensus decision results and the historical reputation scores corresponding to each AI model, and performs hardware signature encapsulation on them according to the physically unreadable private key built into the chip to generate a hardware signature consensus receipt anchored to the current hardware epoch timestamp. The hardware signature consensus receipt is physically stored in a non-volatile storage unit, and the hardware consensus decision results are used to dynamically update the historical reputation scores of each AI model in the dynamic reputation evaluation unit.
[0015] A hardware-based multi-source AI decision consensus-building device includes: The parallel input buffer unit is used to perform inference decision stream acquisition and processing for multiple independently running and heterogeneous artificial intelligence models to generate the multi-source inference decision set, and simultaneously establish the historical reputation score stored in the dynamic reputation evaluation unit and corresponding one-to-one with each of the artificial intelligence models. The parallel verification unit and the dynamic reputation evaluation unit are used to perform feature extraction and legality verification processing on the multi-source reasoning decision set to determine the effective decision subset, and to perform a credible weighted operation in combination with the historical reputation score to generate the weighted decision feature body; The consensus algorithm engine and threshold decision unit are used to perform parallel consensus computation on the weighted decision feature body to obtain a preliminary consensus value, and to generate the hardware consensus decision result by comparing the preliminary consensus value with the consensus threshold; and The failure rollback controller and evidence solidification unit are used to perform hierarchical rollback control in response to the consensus failure state in the hardware consensus decision result, extract consensus calculation process data, perform hardware signature encapsulation to generate the hardware signature consensus receipt, and perform dynamic updates on the historical reputation score.
[0016] An AI chip, comprising: AI inference processor, used to perform inference operations on multiple artificial intelligence models; and Hardware-based multi-source AI decision consensus device.
[0017] An electronic device, comprising: The AI chip described in any of the above items; The electronic device is used to perform security actions based on the hardware consensus decision results generated in the AI chip, and to perform decision tracing based on the hardware signature consensus receipt embedded in the AI chip.
[0018] A cloud-based AI accountability server includes: The motherboard, and the AI accelerator card and network interface unit integrated on the motherboard; The AI accelerator card includes the AI chip described in any of the above claims, and the AI chip integrates the device described in any of the above claims. The cloud-based AI accountability server performs hardware-level arbitration on cloud-based multi-model inference services through the hardware-based multi-source AI decision consensus reaching device, and sends the hardware signature consensus receipt to the external audit terminal through the network interface unit.
[0019] A cloud-based AI trusted computing platform, comprising: A cluster management server, and a plurality of cloud AI accountability servers described above that are communicatively connected to the cluster management server; The cluster management server is used to collect hardware signature consensus receipts generated by multiple cloud AI accountability servers across nodes, and to perform global consensus integrity verification based on the model identifier and consensus weight contained in each hardware signature consensus receipt, so as to construct a cloud hardware-level multi-source AI decision consensus evidence chain that covers multi-node distributed AI decision-making tasks and is physically anchored to the chip-level hardware trust root.
[0020] Technical advantages of the technical solution provided in this application This application provides a hardware-based multi-source AI decision consensus method. Addressing the technical shortcomings of traditional software consensus schemes, such as high latency, susceptibility to tampering, and weak fault tolerance, this method controls a hardware arbitration device to collect multiple inference decision streams through a parallel input buffer unit and establish historical reputation scores. This solves the problems of difficult multi-source data synchronization and lack of long-term reputation considerations in traditional schemes. Compared to traditional schemes that rely on middleware aggregation, this application performs clock domain alignment and data buffering through hardware caching, enabling parallel processing of decision data from heterogeneous AI sources with lower latency differences, providing a stable data benchmark for high-speed hardware-based arbitration.
[0021] By invoking parallel verification units and dynamic reputation evaluation units to perform legality verification and hardware-level aggregation to generate weighted decision feature bodies, this approach solves the problems of one-sided evaluation of AI source credibility and vulnerability to malicious node attacks in traditional solutions. Compared to the traditional single majority voting logic, this application intercepts illegal requests through hardware-level signature verification and performs weighted aggregation of each decision based on dynamically maintained historical reputation scores. This hardware-based weighting mechanism ensures that the high-credibility model has greater say, enabling the aggregated decision feature body to more accurately reflect the multi-source consensus trend and improving the system's resistance to interference from abnormal or poisoned models.
[0022] By employing a consensus algorithm engine and a threshold decision unit to perform parallel consensus computation and validity determination, hardware consensus decision results are generated, overcoming the slow response speed of traditional software consensus under complex arithmetic logic. Compared to traditional CPU instruction execution logic, this application utilizes a hardware-built-in multiplier array and adder tree structure to complete large-scale parallel computation within extremely low clock cycles. By dynamically switching consensus logic and combining it with hardware threshold decision-making, the determinism and execution speed of the consensus process are significantly improved, enabling the determination of the final valid decision within nanoseconds, providing downstream execution mechanisms with more real-time instruction support.
[0023] Finally, by implementing fault tolerance protection, evidence consolidation, and reputation update processing through a failure rollback controller and evidence consolidation unit, a complete closed-loop accountability and dynamic reward / punishment mechanism is formed, solving the problem of lacking hardware-level fault tolerance and audit evidence in the background technology. Compared with the uncontrollable software crashes or infinite loops in traditional solutions, this application achieves decision risk blocking without software intervention through a four-level hardware state machine, and uses physically unreadable private keys to perform hardware signature consolidation of the consensus process. This "arbitration-protection-evidence-evolution" fully hardware closed-loop logic makes the AI decision-making process not only highly robust, but also physically immutable and traceable, effectively solving the security and trust issues in multi-agent collaborative environments. Attached Figure Description
[0024] Figure 1-1 This is a schematic diagram of the overall architecture of the hardware-level multi-source AI decision consensus device of this application.
[0025] Figure 1-2 This is a block diagram showing the data flow and connection of the core sub-module within the hardware arbitration device of this application.
[0026] Figure 1-3 This is a diagram of the parallel hardware implementation scheme of the majority voting circuit in the consensus algorithm engine of this application.
[0027] Figure 1-4 This is a circuit diagram of the parallel multiplier and adder tree for the weighted voting logic in the consensus algorithm engine of this application.
[0028] Figure 1-5 This is a flowchart illustrating the reward and punishment update logic and secure storage process of the dynamic reputation assessment unit in this application.
[0029] Figure 1-6 This is a hardware state machine diagram of the four-level safety rollback mechanism for the failure rollback controller in this application.
[0030] Figure 1-7 This is a schematic diagram of the receipt field structure and chain-like solidification of the multi-source consensus hardware evidence chain in this application.
[0031] Figure 2 This application provides an embodiment of a hardware-level multi-source AI decision consensus achievement method. Detailed Implementation
[0032] like Figure 1-1 As shown, the AI decision input layer features letter combinations from AI Source 1 to AI Source N. Here, the letter "N" represents the total number of AI models connected to the hardware arbitration device, essentially a preset hardware parallel bit width parameter. The corresponding letters "D" in Decisions D1, D2 to DN represent Decisions, i.e., the initial values of the inference results output by each AI source; while the letters "C" in Confidence C1, C2 to CN represent Confidence, used to characterize the model's degree of trust in its output results. These letter combinations with numerical indices establish the parallel spatial arrangement of the multi-source decision streams.
[0033] like Figure 1-3As shown, the letters D, C, and R, and their combinations, appear in the weight calculation unit of the consensus algorithm engine. The letter "D" refers to the initial decision value generated by each AI source; the letter "C" refers to the confidence level output by the model in real time, defined as a fixed-point number between 0 and 255; and the letter "R" refers to reputation, representing the historical reputation score stored in the dynamic reputation evaluation unit. In this circuit logic, the letter "W" in the letter combinations W1, W2 to WN represents weight, which is determined by the formula... Calculate the weighted score of the output. In addition, the letter combination in SUM represents the summation operation, which is used to establish the overall cumulative weight Score(D) for a specific decision option (such as decision A or decision B).
[0034] like Figure 1-3 The weighted voting formula shown includes the mathematical function identifier "argmax". The letter combination "argmax" here represents "the point of maximum value for the function," which technically refers to the hardware maximum weight selector filtering out the decision item corresponding to the highest Score(D) by performing numerical comparison. The letter combination in Threshold represents the threshold value, a pre-set hard boundary parameter used for validity determination. These letter parameters collectively establish the arithmetic logic for the convergence of consensus results from multi-dimensional features to a single valid instruction.
[0035] like Figure 1-4 As shown, in the self-learning logic of the dynamic reputation evaluation unit, the letters "delta" and the subscripted parameters R_i and D_i represent the reputation change step size, which is the fixed increment value used to fine-tune the model reputation based on the consistency detection results within each decision cycle. The parameter "R_i" represents the real-time reputation score of the i-th AI source, while "D_i" represents the original decision value output by the i-th AI source. The letter "i" serves as an index variable, with values ranging from 1 to N. Furthermore, the letter combination in "clamp" represents a clamping function, used to ensure that the reputation value is within the legally defined range of 0 to 255, where boundary checks are performed.
[0036] like Figure 1-6As shown in the four-level hardware state machine diagram of the failure rollback controller, the state identifiers begin with the letter "L". "L1" represents Level 1 (first-level rollback), and its associated letter combination L1_FALLBACK indicates that the system has entered Level 1 rollback mode; "L2" represents Level 2 (second-level rollback), and the corresponding L2_FALLBACK indicates entering Level 2 rollback mode. These letter parameters define the hierarchical transition path of the hardware state machine after receiving a consensus failure signal, establishing risk prevention logic that requires no software intervention.
[0037] like Figure 1-7 As shown in the receipt chain structure and evidence chain diagram, the letters R(n-1), R(n), and the associated hash function identifiers are used. The letter "R" represents the receipt, "n" in parentheses represents the time index of the current hardware epoch, and "n-1" represents the previous time. Therefore, R(n) represents the current receipt, and R(n-1) represents the previous receipt. The letter combination `prevHash` represents forward hashing, which is achieved by executing the formula... The resulting summary, where the letter "H" stands for hash algorithm, establishes the chain-like, fixed logic between receipts at the physical level.
[0038] like Figure 1-7 In the detailed definitions of the receipt fields shown, the letter combination in ModelIDs represents a list of model identifiers; Decisions represents the set of raw decision results from each AI source; ReputationScores represents the real-time reputation score at the time of voting; AlgorithmID represents the consensus algorithm identifier, used to indicate whether majority voting or weighted voting logic is currently being used. Finally, Epoch represents the hardware epoch timestamp, which is essentially an 8-byte monotonically increasing counter. These letter parameters together constitute the complete digital feature payload of the 80-byte signed receipt.
[0039] The following combination Figures 1-1 to 2 The core ideas of this application are illustrated by way of example; however, the following description is not intended to be unique.
[0040] like Figure 2 As shown in the figure, this application provides a hardware-level multi-source AI decision consensus achievement method, which includes: Step 1: Control the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through the parallel input buffer unit, so as to generate a multi-source inference decision set and establish the historical reputation score of each AI model. Step 2: Call the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body; Step 3: Control the consensus algorithm engine and threshold decision unit to perform parallel consensus calculation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results; Step 4: Utilize the failure rollback controller and evidence solidification unit to perform fault tolerance protection, evidence solidification, and reputation update processing for the hardware consensus decision results.
[0041] Optionally, step 1, controlling the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through a parallel input buffer unit, to generate a multi-source inference decision set and establish the historical reputation score of each AI model, includes: After establishing a sideband communication link between the hardware arbitration device and the inference processors corresponding to each AI model, the parallel input buffer unit in the hardware arbitration device is used to synchronously receive the inference decision streams output by each AI model. The identity identifier, initial decision value, and hardware signature certificate of each AI model are extracted from the inference decision flow corresponding to each AI model to generate a multi-source inference decision set.
[0042] Preferably, such as Figure 1-1 As shown, in the hardware-based multi-source AI decision consensus method provided in this application, in the specific technical implementation of step 1, the hardware arbitration device first establishes physical-level sideband communication links with the inference processors corresponding to each of the multiple independently operating and heterogeneous artificial intelligence models (AI source 1, AI source 2 to AI source N). On this communication link, the parallel input buffer unit in the hardware arbitration device synchronously executes the acquisition and processing of the inference decision streams output by each artificial intelligence model. This process ensures through hardware logic that the decision data of different inference cycles can be physically aligned within a nanosecond-level time window. Each inference decision stream carries specific initial decision values (decision D1, decision D2 to decision DN) and associated confidence information (confidence C1, confidence C2 to confidence CN). The parallel input buffer unit parses these streaming data to extract AI model identity identifiers representing the identities of different artificial intelligence models, thereby providing a multi-dimensional multi-source inference decision set for subsequent consensus arbitration.
[0043] Preferably, during the generation of the multi-source inference decision set, the parallel input buffer unit performs hardware data buffering processing based on a preset bit width for the received inference decision stream. Specifically, for the hardware signature credential output by each AI model, the parallel input buffer unit temporarily stores it in a high-speed register array and performs clock domain alignment processing through an internal global clock signal to eliminate phase jitter caused by the difference in crystal oscillator frequencies between different inference processors. Through this purely hardware synchronization mechanism, discrete decision data is converted into a spatially parallel multi-source inference decision set. Simultaneously, the hardware arbitration device synchronously initiates addressing access to the internal dynamic reputation evaluator, retrieving historical reputation scores corresponding to each AI model from the secure storage area based on the parsed AI model identity. These historical reputation scores reflect the performance level of each model in previous decision cycles and are the core basis for establishing the current decision weight.
[0044] Preferably, such as Figure 1-1 As shown, after constructing the multi-source inference decision set and retrieving historical reputation scores, the method enters the signature verification layer for legality verification. Hardware-level signature verification is performed on the hardware signature credentials contained in the multi-source inference decision set by calling parallel verification units. In this stage, Ed25519 verification units (Ed25519 Verification 1, Ed25519 Verification 2 to Ed25519 Verification N) are used to physically verify the identity of each AI model. Specifically, each Ed25519 verification unit uses built-in public key logic to perform integrity and format legality checks on the received initial decision value (e.g., decision D1) and its corresponding confidence level (e.g., confidence level C1). Only decision data that passes verification is marked as a valid decision subset and allowed to be fed into the subsequent consensus arbitration core. This signature verification mechanism, executed at the hardware level, effectively blocks unauthorized fake model decisions from accessing the consensus process, ensuring the physical-level authenticity of the data sources participating in the consensus operation.
[0045] Preferably, within the consensus arbitration core, a dynamic reputation assessment unit, in collaboration with the consensus algorithm engine, performs hardware-level aggregation processing on various decision data within the effective decision subset, combining extracted historical reputation scores and the security level of the current business scenario. This aggregation process is not a simple numerical summation; rather, it utilizes the weight coefficients output by the dynamic reputation assessment unit to perform a weighted mapping of the initial decision value and confidence level, thereby generating a weighted decision feature body reflecting the distribution of the credibility of each AI model's decisions within the current decision-making cycle. This weighted decision feature body, serving as the input to the consensus arbitration core, contains a composite mapping relationship between model identity, weight information, and decision recommendations. Through this hardware-level weight fusion, AI models with higher historical reputation scores dominate the final decision, enhancing the system's defense capabilities against model failure or data poisoning attacks.
[0046] Preferably, after obtaining the weighted decision characteristics, the consensus arbitration core uses its internal arbitration strategy selector to dynamically switch from multiple hardware circuits to the matching hardware consensus logic according to a preset consensus strategy. For example... Figure 1-1 As shown, the consensus arbitration core integrates functional modules such as the Majority Voting Unit, the Weighted Voting Unit, and the Reputation Assessment Unit. Through the arbitration strategy selector, the system can select the computation path that best meets the current business security requirements within a single clock cycle. For example, in scenarios requiring maximum redundancy, switching to the Weighted Voting Unit utilizes its internal parallel multiplier array to perform large-scale parallel operations on the weighted decision feature body, thereby obtaining a preliminary consensus value that uniquely represents the multi-source consensus trend. This purely hardware-based arithmetic logic processing avoids the serial overhead of software instruction execution, ensuring extremely low latency in the consensus-reaching process.
[0047] Preferably, the consensus arbitration core uses a threshold decision unit to compare the preliminary consensus value with a dynamically configured hardware consensus threshold. If the decision shows that the preliminary consensus value reaches the acceptable range, it is determined to be a valid consensus result (Consensus Decision); if the decision does not meet the threshold, the output layer marks the consensus failure state. When the consensus failure state is triggered, the method automatically activates the security rollback module. This security rollback module executes a preset security policy when no consensus is detected, automatically triggering corresponding risk blocking actions through an internal four-level hardware state machine. Finally, the output layer not only outputs the consensus result, but also uses an evidence solidification unit to extract key data from the consensus calculation process and generate a consensus evidence receipt containing an 80-byte signature receipt. This receipt is physically solidified in non-volatile storage, providing tamper-proof evidence support for subsequent audit traceability and liability determination, thus completing the entire hardware closed-loop processing logic from data collection to secure implementation.
[0048] Preferably, such as Figure 1-1 As shown, in the hardware-based multi-source AI decision consensus method provided in this application, in the specific technical implementation of step 1, the hardware arbitration device first establishes physical-level sideband communication links with the inference processors corresponding to each of the multiple independently operating and heterogeneous artificial intelligence models (AI source 1, AI source 2 to AI source N). On this communication link, the parallel input buffer unit in the hardware arbitration device synchronously executes the acquisition and processing of the inference decision streams output by each artificial intelligence model. This process ensures through hardware logic that the decision data of different inference cycles can be physically aligned within a nanosecond-level time window. Each inference decision stream carries specific initial decision values (decision D1, decision D2 to decision DN) and associated confidence information (confidence C1, confidence C2 to confidence CN). The parallel input buffer unit parses these streaming data to extract AI model identity identifiers representing the identities of different artificial intelligence models, thereby providing a multi-dimensional multi-source inference decision set for subsequent consensus arbitration.
[0049] Preferably, during the generation of the multi-source inference decision set, the parallel input buffer unit performs hardware data buffering processing based on a preset bit width for the received inference decision stream. Specifically, for the hardware signature credential output by each AI model, the parallel input buffer unit temporarily stores it in a high-speed register array and performs clock domain alignment processing through an internal global clock signal to eliminate phase jitter caused by the difference in crystal oscillator frequencies between different inference processors. Through this purely hardware synchronization mechanism, discrete decision data is converted into a spatially parallel multi-source inference decision set. Simultaneously, the hardware arbitration device synchronously initiates addressing access to the internal dynamic reputation evaluator, retrieving historical reputation scores corresponding to each AI model from the secure storage area based on the parsed AI model identity. These historical reputation scores reflect the performance level of each model in previous decision cycles and are the core basis for establishing the current decision weight.
[0050] Preferably, such as Figure 1-1As shown, after constructing the multi-source inference decision set and retrieving historical reputation scores, the method enters the signature verification layer for legality verification. Hardware-level signature verification is performed on the hardware signature credentials contained in the multi-source inference decision set by calling parallel verification units. In this stage, Ed25519 verification units (Ed25519 Verification 1, Ed25519 Verification 2 to Ed25519 Verification N) are used to physically verify the identity of each AI model. Specifically, each Ed25519 verification unit uses built-in public key logic to perform integrity and format legality checks on the received initial decision value (e.g., decision D1) and its corresponding confidence level (e.g., confidence level C1). Only decision data that passes verification is marked as a valid decision subset and allowed to be fed into the subsequent consensus arbitration core. This signature verification mechanism, executed at the hardware level, effectively blocks unauthorized fake model decisions from accessing the consensus process, ensuring the physical-level authenticity of the data sources participating in the consensus operation.
[0051] Preferably, within the consensus arbitration core, a dynamic reputation assessment unit, in collaboration with the consensus algorithm engine, performs hardware-level aggregation processing on various decision data within the effective decision subset, combining extracted historical reputation scores and the security level of the current business scenario. This aggregation process is not a simple numerical summation; rather, it utilizes the weight coefficients output by the dynamic reputation assessment unit to perform a weighted mapping of the initial decision value and confidence level, thereby generating a weighted decision feature body reflecting the distribution of the credibility of each AI model's decisions within the current decision-making cycle. This weighted decision feature body, serving as the input to the consensus arbitration core, contains a composite mapping relationship between model identity, weight information, and decision recommendations. Through this hardware-level weight fusion, AI models with higher historical reputation scores dominate the final decision, enhancing the system's defense capabilities against model failure or data poisoning attacks.
[0052] Preferably, after obtaining the weighted decision characteristics, the consensus arbitration core uses its internal arbitration strategy selector to dynamically switch from multiple hardware circuits to the matching hardware consensus logic according to a preset consensus strategy. For example... Figure 1-1 As shown, the consensus arbitration core integrates functional modules such as the Majority Voting Unit, the Weighted Voting Unit, and the Reputation Assessment Unit. Through the arbitration strategy selector, the system can select the computation path that best meets the current business security requirements within a single clock cycle. For example, in scenarios requiring maximum redundancy, switching to the Weighted Voting Unit utilizes its internal parallel multiplier array to perform large-scale parallel operations on the weighted decision feature body, thereby obtaining a preliminary consensus value that uniquely represents the multi-source consensus trend. This purely hardware-based arithmetic logic processing avoids the serial overhead of software instruction execution, ensuring extremely low latency in the consensus-reaching process.
[0053] Preferably, the consensus arbitration core uses a threshold decision unit to compare the preliminary consensus value with a dynamically configured hardware consensus threshold. If the decision shows that the preliminary consensus value reaches the acceptable range, it is determined to be a valid consensus result (Consensus Decision); if the decision does not meet the threshold, the output layer marks the consensus failure state. When the consensus failure state is triggered, the method automatically activates the security rollback module. This security rollback module executes a preset security policy when no consensus is detected, automatically triggering corresponding risk blocking actions through an internal four-level hardware state machine. Finally, the output layer not only outputs the consensus result, but also uses an evidence solidification unit to extract key data from the consensus calculation process and generate a consensus evidence receipt containing an 80-byte signature receipt. This receipt is physically solidified in non-volatile storage, providing tamper-proof evidence support for subsequent audit traceability and liability determination, thus completing the entire hardware closed-loop processing logic from data collection to secure implementation.
[0054] Optionally, step 1, controlling the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through a parallel input buffer unit to generate a multi-source inference decision set and establish the historical reputation score of each AI model, also includes: The parallel input buffer unit performs hardware data buffering and clock domain alignment processing based on a preset bit width on the identity identifiers, initial decision values, and hardware signature credentials of each AI model carried in the inference decision stream to generate a multi-source inference decision set. Access the dynamic reputation assessment unit inside the hardware arbitration device to read the pre-stored historical reputation scores of each AI model.
[0055] Preferably, such as Figure 1-2 As shown, in the technical process of controlling the hardware arbitration device to generate a multi-source inference decision set and establish historical reputation scores in this application, the parallel input buffer first serves as the first station of the hardware data stream, receiving the raw bit stream composed of multi-source AI decisions (inference outputs of multiple heterogeneous AI models). Due to the differences in the physical location and crystal oscillators of each AI inference processor, the input raw stream often has slight timing misalignments. The parallel input buffer performs hardware data buffering based on a preset bit width through a built-in high-speed SRAM storage array, using a unified hardware sampling clock to latch multiple asynchronous signals. This processing method can transform the asynchronous decision stream at the physical layer into synchronous data frames aligned to the clock domain at the logical layer, thereby ensuring that subsequent hardware comparisons and weighted operations can be based on the same time reference.
[0056] Preferably, after data alignment, the parallel input buffer concatenates the preprocessed multi-source inference decision set and sends it to the parallel validation unit. In this stage, the parallel validation unit performs hardware parsing of the identity identifier carried by each AI decision to determine the current list of model IDs to be processed. Simultaneously, the hardware arbitration device asynchronously initiates access requests to the read-only storage area in the dynamic reputation evaluation unit based on the parsed model IDs to retrieve the historical reputation scores corresponding to each AI source. This parallel processing logic of "collecting decisions and retrieving reputations simultaneously" minimizes the startup latency of hardware arbitration, allowing reputation-bearing decision data to enter the subsequent consensus engine in a pipeline manner.
[0057] Preferably, such as Figure 1-2 As shown, in the process of establishing historical reputation scores in the Dynamic Reputation Unit, this unit not only acts as a storage repository for reputation scores but also performs real-time weighting based on the verified data output from the Parallel Validation Unit. Specifically, the Dynamic Reputation Unit maps the read historical reputation scores to the corresponding initial decision values to generate a weighted decision feature body. This feature body then enters the Consensus Engine to execute specific voting algorithm logic. This engine utilizes pure hardware logic to achieve parallel comparison of multiple data streams and produces a consensus result representing the collective will. This process, driven by "verified data" to generate "reputable" features, enables a refined measurement of the credibility of AI sources at the hardware level.
[0058] Preferably, the hardware arbitration device in this application uses a threshold decision unit to finalize the legality of the consensus result. The threshold decision unit receives the preliminary consensus value output by the consensus algorithm engine and compares it with a preset dynamic threshold execution value. If the comparison result shows that the current decision has not reached the consensus threshold, it is determined to be in a state of no consensus, thereby triggering the failback controller to execute hardware protection actions. If a consensus is reached, the consensus receipt is transmitted to the evidence storage unit. Through this interlocking functional support relationship between the sub-modules, this application constructs a tight technical closed loop at the hardware level, from input buffering, trusted verification, consensus computation to evidence storage.
[0059] Preferably, such as Figure 1-5As shown, when the Threshold Decision unit determines that consensus has failed, the Failback Controller automatically intervenes through a four-level hardware state machine. In NORMAL mode, the system monitors the consensus status in real time; once consensus failure occurs, the state machine immediately jumps to L1_FALLBACK (Level 1 fallback), where the system uses the decision from the highest historical reputation source as a temporary alternative to maintain business continuity. If the backup solution fails again (i.e., the backup fails), the state machine will further migrate to L2_FALLBACK (Level 2 fallback), executing a preset conservative strategy, such as performing low-risk actions like deceleration and pulling over in an autonomous driving scenario. This hierarchical fault-tolerance mechanism ensures that the system still has hardware-level safety fallback capabilities under extreme uncertainty.
[0060] Preferably, under extremely severe operating conditions, if L2_FALLBACK (secondary fallback) continues to time out or fails, the Failback Controller will force the system into SAFE_MODE (safe mode). At this point, the hardware will stop AI decision-making and issue an alarm, entering a state awaiting manual intervention. Only after manual confirmation or a system reset can the state machine return to NORMAL (normal mode). Meanwhile, if... Figure 1-5 As shown, the system feeds back the final decision state and fallback path to the Evidence Storage unit, which generates an 80-byte signed receipt anchored to the current hardware state and physically stores it in non-volatile memory. This "decision-update-storage" technical path gives the reputation evaluation of AI sources a unidirectional evolution characteristic at the physical level, solving the technical defects of traditional software consensus schemes where reputation data is easily tampered with or rolled back.
[0061] Optionally, step 2, invoking the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set, to generate a weighted decision feature body, includes: The multi-source inference decision set is fed to the parallel verification unit, which extracts the initial decision value and hardware signature certificate corresponding to each AI model from the multi-source inference decision set and performs hardware-level signature verification and format legality detection on them to determine the valid decision subset composed of the verified initial decision value and hardware signature certificate for hardware-level aggregation processing to generate a weighted decision feature body.
[0062] Preferably, such as Figure 1-1 and Figure 1-2As shown, in the hardware-level multi-source AI decision consensus method provided in this application, step 2 involves first performing feature extraction processing on the received multi-source inference decision set through a parallel validation unit. Specifically, the parallel validation unit accurately extracts the initial decision value and hardware signature credential corresponding to each AI model from each AI decision stream fed by the AI decision input layer. In typical industrial automation decision-making scenarios, the initial decision value can be represented as control instruction code, while the hardware signature credential is encrypted authentication data generated by the inference processor corresponding to the AI source. This hardware-level extraction provides a standardized object to be processed for subsequent security verification, ensuring that the granularity of data processing can directly affect the underlying chip protocol.
[0063] Preferably, after obtaining the aforementioned hardware signature credential, the Validation Unit initiates high-performance parallel signature verification logic. For example... Figure 1-1 As shown, within the signature verification layer, corresponding verification circuits, namely Ed25519 Verification 1, Ed25519 Verification 2, and Ed25519 Verification N, are synchronously invoked for multiple AI sources (such as AI Source 1, AI Source 2 to AI Source N). Each Ed25519 verification unit uses a public key pre-installed in the hardware security area to perform hardware-level verification processing on the input hardware signature credential, and simultaneously performs message format validity checks. Through this purely hardware-implemented asymmetric encryption algorithm verification, forged or tampered illegal reasoning data can be identified within an extremely short clock cycle. The result of this processing is defined as the verified data, which is essentially a trusted reasoning information stream after excluding illegal interference items.
[0064] Preferably, the parallel validation unit forwards the generated validated data to the consensus arbitration core in real time to establish a valid subset of decisions for subsequent consensus operations. Specifically, only initial decision values that have passed Ed25519 hardware-level signature verification and conform to a preset format protocol will be included in the valid subset of decisions. In words, the validated data generated in the previous stage serves as the input object for this stage, ensuring that every piece of data entering the arbitration core has a clear physical identity anchor. This hardware signature-based admission mechanism, unlike traditional software filtering, can effectively intercept malicious input caused by data poisoning at the chip entry point, providing a clean initial data pool for building a highly robust weighted decision feature body.
[0065] Preferably, such as Figure 1-1 and Figure 1-2As shown, upon receiving a subset of valid decisions, the consensus arbitration core collaboratively invokes the Dynamic Reputation Unit (Reputation Evaluator). The Dynamic Reputation Unit extracts the historical reputation scores corresponding to each AI model from non-volatile storage based on the model identifiers contained in the valid decision subset. To adapt to changing operating environments, this unit also dynamically adjusts the weights of each decision based on the current business scenario's security level. For example, in a high-speed cruise scenario for autonomous driving, the system automatically increases the weight of AI source N, which has a long history of high accuracy. This process achieves deep coupling between historical performance and the real-time environment through a hardware arithmetic logic unit, thereby injecting a time-dimensional credibility metric factor into the subsequently generated weighted decision feature body.
[0066] Preferably, the consensus arbitration core utilizes the acquired historical reputation scores to perform hardware-level aggregation processing on the decision data from each path within the effective decision subset. Specifically, the Reputation Evaluator, through its built-in multiplication circuit, multiplies the initial decision value of each AI model with its corresponding historical reputation score and adds associated confidence weights (e.g., decision D1 + confidence C1). This processing transforms the one-dimensional discrete decision vector into a multi-dimensional weighted feature matrix. This hardware-level aggregation computation generates a weighted decision feature body that fully characterizes the global consensus trend within the current inference cycle. This feature body serves as the direct input to the Consensus Engine, ensuring that subsequent voting logic is not based on "blind equality" but rather on a reputation-based elite governance model.
[0067] Preferably, the generated weighted decision feature body is guided to a specific computational path by an arbitration strategy selector to complete the final leap from feature aggregation to consensus decision. For example... Figure 1-1 As shown, the weight information and decision vector carried in the weighted decision feature body will be allocated to the majority voting unit or the weighted voting unit according to the current preset consensus strategy. Through this modular and functionally supportive structural design, the weighted decision feature body can be transformed into a preliminary consensus value in nanoseconds.
[0068] Optionally, step 2, which involves invoking the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body, further includes: The dynamic reputation assessment unit is invoked in a coordinated manner. Based on the identity identifiers of each AI model contained in the multi-source inference decision set, the corresponding historical reputation scores and the current business scenario security level are retrieved. Hardware-level aggregation is performed on the initial decision values of each AI in the effective decision subset and the hardware signature credentials to generate a weighted decision feature body that reflects the distribution of the credibility of each AI decision within the current decision cycle.
[0069] Preferably, such as Figure 1-2 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, step 2 involves first invoking a dynamic reputation evaluation unit to perform reputation measurement processing on the multi-source inference decision set. This unit obtains the identity identifiers of each AI model parsed by the preceding module through a parallel interface, and uses these identifiers as indexes to retrieve the pre-stored historical reputation scores of each AI model from the on-chip protected read-only storage area. In specific industrial visual quality inspection scenarios, due to the varying robustness of different heterogeneous models to illumination or occlusion, establishing these historical reputation scores, which reflect long-term inference accuracy, provides a physical-level credibility benchmark for subsequent weight allocation.
[0070] Preferably, after extracting historical reputation scores, the Dynamic Reputation Unit simultaneously monitors the current security level of the business scenario to perform real-time weighting on the AI decisions within the effective decision subset. During this process, the Dynamic Reputation Unit uses a built-in multiplication circuit array to perform hardware-level aggregation of the initial decision value of each AI model with its corresponding historical reputation score, thereby generating a weighted decision feature body that reflects the credibility distribution of decisions made by each AI model within the current decision-making cycle. This processing transforms the originally discrete voting data into verified data carrying reputation attributes, enabling subsequent consensus arbitration to automatically identify and suppress interference from low-reputation models.
[0071] Preferably, such as Figure 1-5As shown, the Reputation Unit manages historical reputation scores using a rigorous hardware state machine logic. When the threshold decision unit determines that consensus is successful, the Reputation Unit updates the reputation score by accumulating or deducting a preset step size based on the consistency between the current decision and the consensus result. If the system is in NORMAL mode and consensus fails, the Failback Controller intervenes and guides the state machine to transition to L1_FALLBACK (Level 1 fallback). At this time, the Reputation Unit outputs instructions to make the system prioritize decisions using the highest historical reputation source, leveraging the statistical advantage accumulated historically to offset instantaneous decision fluctuations.
[0072] Preferably, during the verification process of the multi-source inference decision set, the parallel validation unit, in conjunction with the dynamic reputation evaluation unit, associates the verified initial decision values with the hardware signature credentials. Specifically, the dynamic reputation evaluation unit maps the valid subset of verified decisions to the corresponding reputation weight space based on the verification results. This technical processing ensures that the generated weighted decision feature body not only includes the inference logic of each AI model but also incorporates hardware-level identity endorsement. This dual verification mechanism effectively prevents decision drift caused by single-point model failure and enhances the overall redundancy in a multi-agent collaborative environment.
[0073] Preferably, when the Failback Controller triggers L2_FALLBACK (secondary fallback) in response to a consensus failure, the Reputation Unit locks the current reputation record to prevent data rollback based on the feedback from executing a preset conservative strategy. If the backup plan fails again, causing the state machine to jump to SAFE_MODE (safe mode), the system will stop AI decision-making and enter the manual confirmation stage. During this process, the Reputation Unit establishes the fixed logic of historical reputation scores in the read-only area, ensuring that all abnormal behaviors are physically anchored before the system is reset. This reputation evolution process driven by a hardware state machine achieves strong determinism and irreversibility in the consensus system.
[0074] Preferably, such as Figure 1-2As shown, the weighted decision feature body obtained from the above processing actions is defined as a reputation-based feature vector stream and fed into the consensus engine. The consensus engine receives this weighted decision feature body and executes a specific voting algorithm according to the control signals of the arbitration strategy selector. Since the input object already contains weights corrected by the dynamic reputation unit, the consensus engine can achieve hardware consensus decision results with higher computational efficiency when performing parallel computation. This functional support relationship between modules enables the system to achieve rapid decision self-healing through hardware-level reputation weight redistribution when facing model consistency failures caused by data poisoning, thereby improving security in scenarios such as financial intelligent risk control or autonomous driving.
[0075] Optionally, step 3 involves controlling the consensus algorithm engine and the threshold decision unit to perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate a hardware consensus decision result. The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the trend of multi-source consensus. The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
[0076] Preferably, such as Figure 1-1 and Figure 1-3As shown, during hardware-level parallel consensus computation, the consensus arbitration core first selects the hardware consensus logic for the current period from the internally integrated Majority Voting Unit and Weighted Voting Unit through an arbitration strategy selector. When the system selects the weighted voting strategy, the weight calculation unit simultaneously receives the decision D, confidence C, and historical reputation score R from each AI source (e.g., AI source 1, AI source 2 to AI source N). Using the built-in 8-bit fixed-point hardware multiplier, the system calculates the weighted score for each AI source in parallel, i.e., performs the product operation of confidence multiplied by reputation. This processing action realizes the physical coupling between the real-time output credibility of the algorithm and the historical credibility recorded by the hardware, producing a product result representing the decision weight of a single source, providing a weighted data benchmark for subsequent global consensus determination.
[0077] Preferably, such as Figure 1-3 As shown, the consensus algorithm engine utilizes an addition tree structure composed of a parallel multiplier array and a group accumulator to perform categorized accumulation on the weights obtained from the above calculations. Specifically, the group accumulator performs weight aggregation for the same initial decision value; for example, it sums the weights of all AI sources that voted for decision A to obtain the total weight of decision A. Based on the weighted voting formula, the system calculates the sum of the scores of each decision branch and uses the maximum weight selector to perform the maximum value (argmax) operation to select the decision item with the highest weight score as the initial consensus value. This processing action signifies the hardware convergence of multi-source features towards a single trend. Subsequently, the threshold decision unit performs an interval comparison decision with the dynamically configured hardware consensus threshold. If the threshold is met, the final consensus decision is produced; otherwise, a consensus failure state is marked and a backoff signal is triggered.
[0078] Preferably, such as Figure 1-4 As shown, after the hardware consensus decision is established, the dynamic reputation evaluation unit initiates a self-learning process for reputation evolution. This process first acquires pre-configured parameter settings, including incremental values defining the reputation change step size. For each AI source i, the system executes a check action that iterates through each AI source i (Foreach AI source i) through hardware logic. During this process, the hardware first executes the judgment logic for source i's participation in the decision. If it is determined that the AI source did not participate in the voting of the current period, its corresponding historical reputation score remains unchanged, R_i. This approach protects the reputation stability of inactive models, ensuring that reputation evaluation is only based on its actual reasoning behavior, reflecting the objectivity of hardware arbitration.
[0079] Preferably, such as Figure 1-4As shown, for the AI models that actually participated in the decision-making process, the system further executes decision consistency comparison logic. Specifically, the hardware logic performs a discrimination operation between the decision value D_i output by the source and the final consensus result generated in step 3. If the judgment result is yes (correct), meaning that the source's decision is consistent with the consensus result, a reputation increase action is performed, adding a preset reputation change step size to the historical reputation score. Conversely, if the judgment result is no (incorrect), a reputation decrease action is triggered, subtracting the step size from the historical reputation score. This Delta step size update mechanism based on "rewarding the good and punishing the bad" realizes a dynamic profile of the performance of each AI model at the hardware level, enabling high-performing models to have a greater say in subsequent decisions.
[0080] Preferably, after performing reputation addition and subtraction operations, the dynamic reputation evaluation unit performs numerical constraint processing on the updated reputation value through a boundary check circuit. Specifically, the system calls the clamp function logic to strictly limit the reputation score within a preset valid value range (e.g., 0 to 255) to prevent logical anomalies caused by numerical overflow. Through this boundary check, the system ensures that the reputation evaluation of each AI source is always within a controllable fixed-point range. Subsequently, the final reputation score obtained after processing is written back and stored in a secure storage area. This processing action realizes the transformation of reputation data from instantaneous updates to physical solidification, providing the latest historical basis for establishing the historical reputation scores of each AI model in the next cycle.
[0081] Preferably, such as Figure 1-1 As shown, the aforementioned reputation update process and the consensus decision completion action form a close functional support relationship. The evidence solidification unit simultaneously extracts the updated reputation list, consensus results, and voting details, encapsulating them into an 80-byte signed receipt. This fully hardware-based closed loop, from "weighted voting calculation" to "reputation reward and punishment evolution," not only... Figure 1-3 The parallel circuit shown achieves high-speed consensus, and further... Figure 1-4 The self-learning logic shown enables the system to robustly evolve itself. Compared to traditional static weighting schemes, this application, through dynamic adjustment of reputation increase and reputation decrease, can spontaneously eliminate "bad apples" that consistently output abnormal data, thereby constructing a physical-level, tamper-proof security barrier in multi-agent collaboration.
[0082] Optionally, step 3, controlling the consensus algorithm engine and the threshold decision unit to perform consensus operations and validity determination processing on the weighted decision feature body, to generate a hardware consensus decision result, includes: The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the multi-source consensus trend, and then perform validity determination processing to generate a hardware consensus decision result.
[0083] Preferably, such as Figure 1-3 As shown, in the hardware-based multi-source AI decision consensus method provided in this application, in the specific technical implementation of step 3, the hardware arbitration device is first controlled to dynamically switch from the majority voting circuit, weighted voting circuit, and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Specifically, the arbitration strategy selector inside the hardware arbitration device analyzes the feature distribution of the multi-source inference decision set in real time. When it is detected that fine-grained weight evaluation needs to be performed, the instruction selection path is switched to the weighted voting unit. This processing action realizes the on-demand allocation of computing resources through hardware routing, ensuring that the consensus decision-making process can perform targeted arbitration for the confidence differences of heterogeneous AI sources, thereby establishing a highly robust decision path at the hardware level.
[0084] Preferably, after receiving a valid subset of decisions, the consensus algorithm engine calls the weight calculation unit to perform parallel weight mapping. For example... Figure 1-3 As shown, the weight calculation unit simultaneously extracts the corresponding initial decision value D, confidence level C, and historical reputation score R for each input AI source, i.e., AI source 1, AI source 2 to AI source N. In this stage, the hardware utilizes a built-in 8-bit fixed-point hardware multiplier to perform a fixed-point product operation based on Ci∈[0,255] and Ri∈[0,255] for each AI source, i.e., using the formula... The system calculates the current weight for each AI source. Through this process, the system physically couples the algorithm confidence of the AI model with the historical credibility recorded by the hardware, producing the current weight that represents the overall credibility of the single-source decision, providing an accurate fixed-point numerical basis for subsequent global consensus accumulation.
[0085] Preferably, such as Figure 1-3 As shown, the consensus algorithm engine utilizes an addition tree structure composed of a parallel multiplier array and a group accumulator to perform group accumulation processing on the current weights generated by all AI sources within a set single hardware clock cycle. Specifically, the group accumulator performs weight aggregation for the same decision content; for example, it sums the weights of all AI sources that voted for decision A to obtain the total weight of decision A. Similarly, the total weight of decision B is obtained. This parallel hardware implementation scheme based on the addition tree makes the aggregation calculation of large-scale multi-source data no longer limited by the serial execution overhead of software instructions, and can produce statistical results reflecting the multi-source consensus trend at extremely low clock frequencies.
[0086] Preferably, after the group accumulator completes the statistical calculation of the weights of each branch, the consensus algorithm engine calls the maximum weight selector to perform the initial consensus value establishment process. The maximum weight selector uses a hardware comparator array to compare the total weight of decision A with the total weight of decision B, and selects the one with the highest score as the initial consensus value according to the maximum value (argmax) logic in the weighted voting formula. This processing action marks the convergence of multi-source divergence features to hardware with a single trend, ensuring that the initial consensus value selected by the system has the highest support in both statistical and credibility dimensions. Subsequently, the result is fed into the threshold decision unit in real time, ready to perform the validity judgment process for consensus strength.
[0087] Preferably, the threshold decision unit performs a comparison decision based on a preset threshold for the preliminary consensus value. For example... Figure 1-3 As shown, the system determines whether Score(D) has reached the threshold (reached the threshold value?). If the determination is "yes", the preliminary consensus value is determined as a valid final decision and converted into a hardware consensus decision result; if the determination is "no", a "backoff" signal is triggered and the output layer marks the consensus failure state. This determination step filters out low-quality decisions caused by excessive disagreement from the AI source through pure hardware logic. Subsequently, as... Figure 1-4 As shown, the system enters the self-learning phase after the consensus decision is completed. The dynamic reputation evaluation unit obtains the reputation change step size (delta) in the parameter configuration and checks whether each AI source i participated in this decision by traversing the judgment logic of each AI source i (Foreach AI source i).
[0088] Preferably, for the AI source i that participated in the decision-making, the dynamic reputation assessment unit performs a consistent reputation reward and punishment update. For example... Figure 1-4 As shown, the system determines the decision of source i. Does it equal the consensus result? If the result is "yes" (correct), then the reputation increase action will be executed, that is, the initial value or the current historical reputation score will be increased. Add step size If the result is "No" (incorrect), then a reputation reduction action will be performed. Finally, the system uses a boundary check circuit and a clamp function to confine the updated constraints within a fixed-point range [0, 255] and stores them in secure storage. This "computation-determination-update" hardware logic gives the reputation evaluation of AI sources physical-level evolution and tamper resistance, ensuring that the historical reputation scores can more accurately reflect the true performance of each model when step 3 is executed next time.
[0089] Optionally, step 3, controlling the consensus algorithm engine and the threshold decision unit to perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results, further includes: The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
[0090] Preferably, such as Figure 1-4 As shown, the threshold decision unit plays a crucial logical gatekeeping role in controlling the consensus algorithm engine to execute parallel consensus computation. Specifically, the threshold decision unit first receives the preliminary consensus value output by the group accumulator and retrieves the dynamically configured hardware consensus threshold pre-set in the system. In this decision-making stage, the threshold decision unit performs a threshold comparison to determine whether Score(D) has reached the threshold. If the comparison result determines that Score(D) is greater than the threshold, i.e., the threshold is met, it is determined to be a valid final decision, thereby generating a hardware consensus decision result that can directly drive the downstream execution mechanism. This purely hardware-based threshold filtering mechanism can effectively intercept low-quality instructions generated due to excessive divergence from multiple sources, ensuring the robustness of the output results.
[0091] Preferably, such as Figure 1-4 As shown, if the initial consensus score fails to meet the preset threshold, i.e., the threshold judgment unit determines that the threshold is not met, the system automatically marks the consensus failure state. This processing action will serve as a trigger signal, synchronized in real time to the subsequent failure rollback controller, to initiate a decision-making risk blocking process without software intervention. During this process, the system not only establishes the consensus failure conclusion for the current period, but also instructs the relevant execution mechanisms to enter a safe and controlled state through rollback logic. This judgment result serves as negative feedback for the completion of the consensus decision, ensuring that even under extremely adverse conditions, such as when multiple models are simultaneously subjected to data poisoning attacks leading to severe weight distribution, the system can promptly mitigate losses through parallel arithmetic logic of pure hardware circuits.
[0092] Preferably, after establishing the hardware consensus decision result, the dynamic reputation evaluation unit simultaneously initiates performance audits for each AI model. Specifically, the system first accesses non-volatile memory to obtain parameter configurations including the reputation change step size (delta) and initial values (initial value R_i=128). Based on this, the hardware logic initiates a polling operation that iterates through each AI source i (Foreach Alsource i). This polling process aims to establish a reward and punishment mapping corresponding to the decision performance of each AI model, ensuring that the reputation score can dynamically map the real-time inference quality of the model, keeping its value within the preset range: [0, 255].
[0093] Preferably, such as Figure 1-4 As shown, during the traversal of each AI source i, the dynamic reputation evaluation unit first performs a qualification judgment on whether source i participates in the decision-making process through a built-in comparison circuit. If the judgment result is "no", it indicates that the AI model has not produced a valid output in the current period, and the system immediately instructs the model's reputation score to remain unchanged (R_i) to avoid inactivity interfering with the historical evaluation system. If the judgment result is "yes", the system further performs a consistency check to determine whether D_i = consensus exists. This action identifies the authenticity of each model's contribution by comparing the initial output value of each AI source with the final hardware consensus decision result bit by bit.
[0094] Preferably, based on the aforementioned decision consistency determination result, the dynamic reputation assessment unit implements differentiated weight evolution for the models participating in the decision-making process. If D_i is consistent with the consensus result, i.e., determined to be yes (correct), the system automatically performs reputation increase processing, increasing the value of R_i by adding up to delta through an addition circuit. Conversely, if determined to be no (incorrect), a reputation decrease action is triggered, decreasing the value of R_i by subtracting delta through a subtraction circuit. This dynamic reward and punishment logic based on the Delta step size ensures that the weight of high-performing models gradually increases in subsequent decisions, while models with poor performance are quickly de-weighted. The processed reputation value is then clamped through a boundary check circuit. This ensures that data does not overflow during fixed-point arithmetic.
[0095] Preferably, the latest reputation score, after boundary check and correction, is finally physically stored in a secure storage area via the bus interface. This solidification process marks the completion of the evolution of the AI model evaluation system within this cycle. Figure 1-4As shown, the entire "arbitration-determination-update" logical flow relies on the parallel arithmetic logic of pure hardware circuits, enabling large-scale data throughput within a single hardware clock cycle. In this way, the system not only produces real-time hardware consensus decision results but also constructs an immutable model trust root at the physical level, effectively solving the technical bottlenecks of software consensus schemes in the background, which are easily maliciously tampered with and have slow response times.
[0096] Optionally, step 4, utilizing the failure rollback controller and the evidence solidification unit, performs hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision result, including: The hardware consensus decision result is fed to the failure rollback controller. In response to the consensus failure state carried in the hardware consensus decision result, the built-in four-level hardware state machine automatically triggers a graded rollback action including retry, backup switch, manual intervention and emergency termination to block decision risks without software intervention. Preferably, such as Figure 1-6 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, in the specific technical implementation of step 4, the hardware consensus decision result is first fed to the Failback Controller in real time. In response to the consensus failure state (consensus failure) carried in the hardware consensus decision result, the Failback Controller immediately initiates an automated intervention process based on the hardware state machine. In the initial normal operating mode of the system, if a consensus failure signal is received from the threshold decision unit, the state machine will execute a decision risk blocking mechanism without software intervention. This achieves a physical migration from the business logic layer to the protection logic layer through rapid conduction of logic circuits, establishing the underlying response benchmark of the system under extreme uncertainty conditions.
[0097] Preferably, the Failback Controller automatically triggers tiered rollback actions through a built-in four-level hardware state machine, initially entering the L1 level rollback (L1_FALLBACK) state. In this state, the tiered rollback action executed by the system is defined as L1: using the historically highest reputation source for decision-making. Specifically, the controller reads the model performance records stored in the dynamic reputation assessment unit, and when consensus support is lost, forces the selection of the single AI source with the most stable historical performance as a temporary instruction through a hardware multiplexer. This processing action, while ensuring business continuity, uses long-term statistical trust roots to offset instantaneous decision fluctuations, producing highly reliable rollback decisions and providing a nanosecond-level time window for system self-healing.
[0098] Preferably, if the execution result in the L1 level rollback state still fails to meet the preset safety expectations, resulting in a backup failure, the Failback Controller will drive the state machine to further transition to the L2 level rollback (L2_FALLBACK) state. For example... Figure 1-6 As shown, in L2 state, the tiered fallback action executed by the system is defined as L2: executing a preset conservative strategy. In autonomous driving or industrial collaboration scenarios, this strategy can be manifested as hardware-level degradation operations, such as executing emergency deceleration or mechanical locking. This step-by-step transition from "high-performance decision-making" to "extremely high-safety conservative instructions" ensures that even in extreme situations where multiple AI models fail collectively, the execution risk at the physical level remains within a controllable preset range.
[0099] Preferably, in extremely severe continuous failure scenarios, if the secondary rollback logic continues to run without receiving a recovery signal, triggering a timeout state, the Failback Controller will force the system into a safe mode (SAFE_MODE). In this mode, the hierarchical rollback action performed by the system is defined as SAFE: stop AI decision-making and wait for human intervention. At this time, the hardware arbitration device physically disconnects all electrical connections between the AI inference stream and the execution mechanism and issues the highest-level alarm signal. This action signifies that the system has entered a passive protection state, preventing any irreversible destructive instructions from being generated under logical confusion.
[0100] Preferably, such as Figure 1-6 As shown, the regression from the safe mode (SAFE_MODE) to the normal state follows a strictly controlled process. The state machine is only allowed to transition from the locked state back to the normal operating mode after detecting manual confirmation or executing a system reset command. Throughout the tiered rollback control process, the FailbackController synchronously sends the transition conditions and execution results of each state transition to the Evidence Storage unit. This unit then extracts the specific path of the tiered rollback and transforms it into a digital record containing complete voting information and risk blocking details, providing physical-level state mirror data for subsequent auditing and tracing.
[0101] Preferably, such as Figure 1-6As shown, the evidence solidification unit uses a physically unreadable private key built into the chip to perform hardware accountability kernel signing on all process data, including rollback decisions, generating a consensus receipt structure totaling 80 bytes (fixed length). This receipt possesses the characteristics of fixed length, linkability, hardware signature, and containing complete voting information. Physically solidified into non-volatile memory, it constitutes original electronic evidence that can be used for audit traceability, liability determination, cross-platform verification, and legal admissibility. This "state machine decision-making - real-time response - evidence closed loop" technical logic differs from traditional software anomaly handling mechanisms. It not only eliminates secondary risks caused by software crashes but also ensures the transparency and immutability of the decision-making risk blocking process.
[0102] Preferably, such as Figure 1-7 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, step 4 involves the Evidence Storage unit performing the construction of the hardware-level multi-source AI decision consensus evidence chain. Specifically, the Evidence Storage unit extracts in real time the hardware consensus decision results output by the previous module, the historical reputation scores corresponding to each AI source, and the key EpochCounter value. Based on this, the hardware logic calculates the SHA-256 digest of the previous record to establish the PreviousHash field in the current receipt. This processing action realizes the logical anchoring of discrete decision receipts at the physical level, ensuring that each newly generated receipt contains the trust endorsement of the previous historical node, thereby constructing an evidence chain with physical-level correlation at the hardware level.
[0103] Preferably, the evidence solidification unit performs parallel encapsulation processing on the consensus decision digest, the source bitmap, and the vote result summary through its internal hash calculation circuit. For example... Figure 1-7 As shown, the Source Bitmap uses 4 bytes to mark which AI sources participated in the voting, while the Vote Summary records the number of votes / weights received for each decision. These micro-features describing the decision-making process are integrated into a total of 80 bytes (fixed length). Through this fixed-length design, the hardware arbitration device can pipeline the chained storage of large-scale decision data within a preset non-volatile storage cycle, greatly improving the throughput efficiency of the evidence chain in extremely short clock cycles.
[0104] Preferably, during the physical solidification stage of the evidence chain, the evidence solidification unit drives the hardware accountability kernel signature logic, calling the chip's built-in physically unreadable private key to encrypt the encapsulated receipt. For example... Figure 1-7 As shown, this action generates a 64-byte hardware signature by performing Ed25519 signature processing. Because the private key is physically isolated within a protected hardware root of trust, any malicious software-level attack cannot extract or tamper with this signature. This processing establishes the physical authenticity of the evidence receipt, giving the generated 80-byte signature receipt the technical attributes of immutability, traceability, and legal evidentiary value, providing original credentials with chip-level trust endorsement for subsequent cross-platform verification.
[0105] Preferably, the hardware-level multi-source AI decision-making consensus evidence chain in this application adopts a chain-like solidification mechanism, physically linking the current 80-byte signed receipt with the historical records in memory through a forward hash field. Specifically, after the system detects a "consensus decision complete" signal, it automatically reads the hash value of the previous receipt as the initial parameter for the current record. This recursive processing logic of "current anchoring to history" ensures the integrity of the evidence chain. If the data in any link of the chain is maliciously modified externally, due to the extremely low probability of hash collisions, the forward hash verification of all subsequent nodes will fail. This chain structure generated based on hardware logic, unlike traditional log recording, can prove its integrity at the physical level, effectively addressing the judicial traceability needs in a multi-agent collaborative environment.
[0106] Preferably, such as Figure 1-7 As shown, the generated consensus receipt is physically stored in non-volatile memory, forming a core database that can be used for audit traceability and liability determination. Because this receipt contains complete voting information (including model ID, weight distribution, epoch timestamp, etc.), external audit terminals can accurately reconstruct the "decision-making scene" of any historical decision by reading the evidence chain. For example, in the event of a dispute over autonomous driving, the audit terminal can use the hash verification logic in the chain-based solidification diagram to confirm the initial decision value of each AI source at the moment of the accident. This technical step represents a technological leap from "black-box reasoning" to "transparent auditing" in the AI decision-making process, providing objective and rigorous hardware evidence support for determining liability in safety-critical areas.
[0107] Preferably, this evidence chain achieves cross-platform verification compliance through the anchoring effect of a chip-level hardware root of trust. Specifically, during the generation of an 80-byte signed receipt, the evidence solidification unit simultaneously physically couples the device identifier with the hardware epoch timestamp. This ensures that the exported evidence chain not only possesses tamper-proof characteristics locally, but also, after being uploaded to a cloud-based AI trusted computing platform, can still construct an evidence network covering multiple nodes through global consensus integrity verification. This hardware evidence transfer mechanism from "end" to "cloud," through kernel-level encryption with physically unreadable private keys, effectively solves the technical deficiencies of multi-source AI decision-making systems, such as the ease of data tampering and the difficulty of liability determination, greatly enhancing the system's technical credibility in legal evidence scenarios.
[0108] Preferably, such as Figure 1-1 and Figure 1-2 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, the signature verification layer integrates multiple parallel Ed25519 verification units (Ed25519 Verification 1 to Ed25519 Verification N) to perform nanosecond-level physical verification processing for valid decision subsets. Specifically, each Ed25519 verification unit employs a fully hardened combinational logic gate design, mapping the dot product and modular exponentiation operations in the asymmetric signature verification algorithm to a pipelined arithmetic logic architecture. Through this hardware-level signature verification processing, the system can, upon receiving a multi-source inference decision set, use a pre-set hardware public key to perform instantaneous verification of the hardware signature credentials carried by each inference decision stream, producing unique verified data representing the legitimacy of the identity. This establishes the first hardware barrier against malicious instruction access at the chip's physical entry point.
[0109] Preferably, the core circuitry within the Ed25519 verification unit employs massively parallel bit-width processing technology. For each AI source (e.g., AI source 1), the verification unit synchronously extracts its initial decision value and the corresponding 64-byte hardware signature credential. During processing, the hardware logic utilizes the physical public key pre-embedded in a secure storage area, employing a parallel shift register array and a multi-stage accumulator structure to perform high-speed hash comparison and scalar multiplication operations on the input object. This purely hardware-implemented algorithm logic avoids the context switching overhead of general-purpose processors when executing complex cryptographic instructions, improving the determinism and execution speed of the verification process.
[0110] Preferably, during the hardware-level signature verification process, the Ed25519 verification unit collaborates with the parallel verification unit to perform format validity checks. For example... Figure 1-1As shown, the system not only verifies the mathematical correctness of the signature, but also checks in real time whether data fields such as decision D1 and confidence C1 conform to the preset protocol frame width through a gate circuit array. If the signature verification of a certain AI source fails or the message format is abnormal, the hardware will immediately generate a physical-level interception signal to prevent that data from entering the consensus arbitration core. The effective decision subset produced by this processing stage ensures that every feature value participating in subsequent consensus operations has physical authenticity, greatly reducing the probability of the system being attacked by fake models.
[0111] Preferably, such as Figure 1-2 As shown, the verified data produced by the Ed25519 verification unit is pushed to the dynamic reputation assessment unit in real time as a key processing object. To achieve functional support between units, the verification unit, while outputting the verification result, also adds a hardware-generated clock stamp signal to establish the time position of the decision in the hardware epoch. This hardware-based data flow enables reputation-based feature aggregation to be performed based on the latest physically verified identity. Compared to traditional software signature verification, this application, through fully hardened combinational logic, compresses the signature verification action, which originally required millisecond-level processing, to a nanosecond-level clock cycle, providing the necessary low-latency implementation for high-frequency real-time decision-making scenarios.
[0112] Preferably, the parallel design of the Ed25519 verification unit can support the simultaneous input of multiple AI sources into the database. For example... Figure 1-1 As shown, the signature verification layer performs non-interventional parallel processing on AI sources 1 to N through multiple completely independent Ed25519 verification circuits. This hardware redundancy design ensures that even if one verification circuit experiences a delay due to a fault, it will not affect the decision synchronization of other AI sources. The processed multi-channel verified data is then aligned within the hardware arbitration device, thereby driving subsequent majority voting units or weighted voting units. This "multi-channel parallelism - hardware filtering - synchronous convergence" technical logic maintains an extremely high parallel data throughput rate while ensuring decision security.
[0113] Preferably, all process data, after physical verification by the Ed25519 verification unit, is ultimately encapsulated and solidified by the evidence solidification unit for the consensus receipt structure. Specifically, the evidence solidification unit extracts the signature status bit generated by each Ed25519 verification unit and maps it to a specific field of the 80-byte signature receipt. This processing action establishes a complete technical closed loop from identity verification to decision-making and then to the generation of audit evidence. Through this processing method, which is physically anchored to the chip-level hardware root of trust, the system not only achieves real-time blocking of illegal AI sources, but also retains verification records with legal evidentiary effect in non-volatile memory, improving the security and trustworthiness level in a multi-agent collaborative environment.
[0114] Preferably, such as Figure 1-2 and Figure 1-7 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, the Evidence Storage unit performs the generation process for the 80-byte signature receipt. Specifically, the Evidence Storage unit first generates a temporary random scalar with a physical entropy source using an internal hardware random number generator. This process aims to provide an unpredictable initial perturbation to the asymmetric encryption process, ensuring the uniqueness of the generated hardware signature even with identical decision data inputs. Through this hardware-level randomization, the system avoids the risk of signature replay attacks at the underlying logic level, establishing the absolute uniqueness of each consensus receipt on the hardware epoch axis.
[0115] Preferably, the evidence solidification unit, in conjunction with the secure and controlled logic within the chip, initiates a request to access the physically unreadable private key. For example... Figure 1-2 As shown, the private key is stored in a physically clonable unit inside the chip. A hardware-level access control matrix ensures that it cannot be retrieved by the external bus or software layer under any operating condition. During this process, the hardware logic concatenates key fields such as the consensus result output by the consensus algorithm engine, the updated reputation score output by the dynamic reputation evaluation unit, and the participating source bitmap determined by the parallel verification unit to form a data packet to be signed. This processed object constitutes the core payload of the 80-byte signed receipt, reflecting the complete physical mirror of the consensus reached in this decision-making process.
[0116] Preferably, such as Figure 1-7 As shown, the evidence solidification unit performs hardware-level kernel signature processing on the aforementioned data packet to be signed using its built-in Ed25519 core circuitry. In this stage, the hardware utilizes a physically unreadable private key and a random scalar generated by a hardware random number generator to perform complex elliptic curve multiplication and modular addition operations on the data packet to be signed, thereby producing a 64-byte Ed25519 signature. Through this purely hardware-implemented arithmetic logic, the system deeply binds decision logic, weight information, and the chip's physical identity. The result of this processing is defined as a signature payload with hardware accountability characteristics, providing physical-level immutability for subsequent legal evidence.
[0117] Preferably, the evidence solidification unit further invokes the hash calculation circuit to perform digest extraction on the historical receipts of the previous period to establish the PreviousHash field in the current receipt. Specifically, the hardware logic calculates the SHA-256 digest (taking the first 20 bytes) of the 80 bytes of data stored in the non-volatile storage unit at the previous moment, and spatially aligns and concatenates it with the current EpochCounter and Ed25519 signature. This action realizes the logical linkability of evidence records at the physical level, ensuring that the hardware-level multi-source AI decision consensus evidence chain composed of the receipt sequence has a unidirectional evolution characteristic. Any illegal rollback of historical records will cause the hash verification of subsequent chains to break.
[0118] Preferably, such as Figure 1-2 and Figure 1-7 As shown, the generated consensus receipt, totaling 80 bytes (fixed length), is ultimately sent to the storage layer for physical hardening via the DMA (Direct Memory Access) controller. During this process, the evidence hardening unit monitors write pulses through a hardware state machine to ensure the receipt is accurately stored in non-volatile memory and cannot be deleted by instructions. This fully hardware-based closed-loop flow logic, from "physical private key invocation" to "chained hash calculation" and then to "non-volatile storage," endows every piece of data generated during the AI decision-making process with audit evidence attributes physically anchored to a hardware root of trust, greatly enhancing the system's technical credibility in cross-platform verification and accountability.
[0119] Preferably, the evidence solidification unit in this application also supports real-time retrieval by external audit terminals through an interface that outputs a consensus receipt. Since the receipt contains complete voting information (including model ID, algorithm identifier, epoch timestamp, etc.), the audit terminal can perform offline signature verification by reading the evidence chain in non-volatile memory and using the publicly available physical key, without relying on a compromised software environment. This functional support relationship between "hardware signature verification of identity" and "hash chain verification of integrity" establishes the traceability cornerstone of multi-source AI decision-making systems in safety-critical fields such as industrial automation and autonomous driving, and solves the serious technical defect in the background technology where software evidence storage is easily bypassed or tampered with maliciously.
[0120] Optionally, step 4, utilizing the failure rollback controller and the evidence solidification unit, performs hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision result, including: The driving evidence solidification unit extracts the hardware consensus decision results and the historical reputation scores corresponding to each AI model, and performs hardware signature encapsulation on them according to the physically unreadable private key built into the chip to generate a hardware signature consensus receipt anchored to the current hardware epoch timestamp. The hardware signature consensus receipt is physically stored in a non-volatile storage unit, and the hardware consensus decision results are used to dynamically update the historical reputation scores of each AI model in the dynamic reputation evaluation unit.
[0121] Preferably, such as Figure 1-2 As shown, in the hardware-level multi-source AI decision consensus method provided in this application, in the specific technical implementation of step 4, the control hardware arbitration device calls the EvidenceStorage unit to perform the generation process of the hardware-level multi-source AI decision consensus evidence chain. Specifically, the EvidenceStorage unit extracts in real time the hardware consensus decision result determined by the previous module, the historical reputation score of each AI model, and the epoch counter anchored to the current hardware clock through a parallel bus. Based on this, the EvidenceStorage unit initiates a call instruction to the physically unreadable private key built into the chip and drives the built-in Ed25519 core circuit to perform hardware-level kernel signature processing on the original payload, including the initial decision value, weight distribution, and threshold parameters. This processing action produces a hardware signature that uniquely represents the physical attributes of this decision, ensuring that the consensus data has physical immutability at the moment of generation.
[0122] Preferably, such as Figure 1-7 As shown, the evidence solidification unit constructs a receipt chain structure and performs field encapsulation processing on 80-byte signed receipts. In the detailed definition of specific receipt fields, the hardware logic first establishes an 8-byte EpochCounter, which serves as a monotonically increasing counter to prevent replay attacks. This is followed by a 20-byte PreviousHash field, which extracts the SHA-256 digest of the previous receipt, achieving a chained coupling of "current receipt anchoring to historical records." This processing ensures that each receipt R(n) contains the hash fingerprint of the previous receipt R(n-1), thereby constructing a logically coherent hardware evidence chain at the physical level.
[0123] Preferably, during the encapsulation process, the evidence solidification unit simultaneously establishes key descriptive fields for audit traceability, liability determination, and cross-platform verification. Specifically, the hardware logic fills the identifiers of all AI models participating in the voting into the ModelIDs field and writes the original decision value of each model into the Decisions field. Furthermore, the system maps the reputation value of each model at the time of voting to the ReputationScores field, along with the consensus algorithm ID and the minimum threshold parameter (Threshold) required to reach consensus. These high-dimensional feature payloads, together with the 64-byte Ed25519 signature, constitute a total of 80 bytes (fixed length) of consensus receipt. This fixed-length design, containing complete voting information, provides a standardized data benchmark for subsequent legal evidence.
[0124] Preferably, such as Figure 1-5 As shown, the dynamic reputation assessment unit, in conjunction with the evidence solidification unit, performs reputation update processing based on decision performance. After consensus decision-making is completed, the system enters the self-learning phase of reward and punishment logic. Specifically, the hardware logic first executes the judgment action for each AI source i, and performs differentiated processing according to the state of source i's participation in the decision. If it is determined that source i did not participate in the voting of the current period, its reputation score is instructed to remain unchanged (R_i). If it is determined that source i participated in the decision, a consistency check is further performed. If the source decision D_i equals the consensus result (i.e., it is judged as yes (correct)), a reputation increase processing is performed, that is, R_i+=delta is executed using an adder. Conversely, if it is judged as no (incorrect), a reputation decrease processing is triggered, and reputation is deducted through the action R_i-=delta.
[0125] Preferably, after performing the reputation addition and subtraction operations, the dynamic reputation evaluation unit performs a clamping operation through the boundary check circuit. Establish the corrected historical reputation score. For example... Figure 1-5 As shown, this update action is directly controlled by the state transition logic of the failure rollback controller. Reputation changes generated in normal operation mode are physically persisted to non-volatile storage units after passing boundary checks. If the system triggers L1 level rollback, L2 level rollback, or enters SAFE_MODE (safe mode) due to consensus failure, the evidence persistence unit will simultaneously capture the cause of failure and physically persist it, ensuring that all abnormal decision paths have been truthfully recorded before system reset or manual confirmation.
[0126] Preferably, such as Figure 1-7As shown, the hardware-signed consensus receipts generated through the aforementioned chain structure provide physical-level security for complex multi-agent systems. Since each receipt is strongly associated with the preceding record via prevHash = H(R(n-1)), this immutable, non-insertable, and non-deletable technical characteristic establishes the system's sole source of fact in the event of disputes. The derived receipt chain supports offline verifiable cross-platform verification, enabling judicial terminals or audit servers to reconstruct the complete decision-making process record using the hardware public key. This series of fully hardware-based closed-loop processing logics, from "kernel signing" to "chain storage" and then to "dynamic rewards and punishments," solves the serious technical problem in the background technology where software solutions lack hardware-level fault tolerance and audit evidence.
[0127] Preferably, such as Figure 1-5 and Figure 1-6 As shown, in the hardware-based multi-source AI decision consensus method provided in this application, when the system faces extreme attack scenarios such as multiple AI models being simultaneously subjected to collaborative data poisoning, the hardware arbitration device performs defense through the coupling of a dynamic reputation unit and a failure backoff controller. Specifically, the dynamic reputation unit monitors the decision consistency of each AI source in real time. If the attack causes most models to output abnormal values, although the consensus result may temporarily shift, the hardware logic will establish the current credibility weight of each source by comparing historical reputation scores. This processing action ensures that even when the models are collectively damaged, "honest nodes" with a long history of high reputation still retain a high weighted discourse power, thereby building the first numerical defense barrier against data poisoning at the underlying level.
[0128] Preferably, when a coordinated poisoning attack reduces the consensus strength, causing the initial consensus value to fail to reach the dynamically configured hardware consensus threshold set by the Threshold Decision unit, the system immediately establishes a consensus failure state. For example... Figure 1-6 As shown, at this point, the Failback Controller automatically intervenes, driving the hardware state machine to transition from the normal operating mode to L1 fallback (L1_FALLBACK). In this state, the tiered fallback action performed by the system is defined as L1: using the highest historical reputation source for decision-making. By forcibly selecting the highest reputation source, which is unaffected by this poisoning or exhibits more robust performance, as the instruction source, the hardware logic achieves immediate blocking of decision-making risks without software intervention, ensuring the safe operation of the execution mechanism during the attack window.
[0129] Preferably, such as Figure 1-5As shown, for models that have made erroneous decisions due to poisoning, the dynamic reputation assessment unit collaboratively executes reputation reward and punishment update processing based on a delta step size. In the specific implementation, the hardware logic identifies the erroneous outputs of all poisoned models by performing a comparison to determine if D_i equals consensus, and triggers a reputation reduction action (R_i -= delta). As the decision cycle evolves, the historical reputation scores of these poisoned models decay rapidly. Through this hardware self-learning mechanism, the system establishes a "blacklist effect" against malicious sources at the physical level, ensuring that even if an attacker controls most models, their overall weight will fall below a threshold in a short period, thus inducing continuous fallback protection logic.
[0130] Preferably, if the extreme poisoning scenario persists and causes the backup to fail, the failure rollback controller will drive the state machine to migrate to L2 level two rollback (L2_FALLBACK) and even safe mode (SAFE_MODE). Figure 1-5 and Figure 1-6 As shown, in the second-level rollback, the hardware executes a preset conservative strategy to hedge against unknown algorithmic risks; while after entering safe mode, the system executes a tiered rollback action defined as SAFE: stopping AI decision-making and waiting for human intervention. This step-by-step fault-tolerance mechanism based on a hardware state machine establishes a safety fallback boundary for the system when encountering "AI de-intelligence attacks" or "mass poisoning," preventing abnormal decisions from causing destructive consequences at the physical level.
[0131] Preferably, as the poisoning attack weakens or the malicious source is eliminated, the system performs recovery processing through a dynamic reputation assessment unit. When the "honest node" regains dominance and decision consistency is restored in subsequent cycles, the system controls the state machine to return to normal operation mode based on manual confirmation or a system reset signal. During this process, all abnormal decision records, reputation deduction trajectories, and state transition paths caused by the poisoning are encapsulated into 80-byte signed receipts by the Evidence Storage unit and stored in non-volatile memory. This "real-time blocking - dynamic demotion - physical solidification" processing logic enables the system not only to defend against coordinated attacks but also to produce an accountability evidence chain with a chip-level root of trust.
[0132] Preferably, such as Figure 1-2 and Figure 1-7As shown, this application establishes a hardware-level multi-source AI decision-making consensus evidence chain through the evidence solidification unit, providing crucial support for judicial evidence collection after a poisoning attack. Since each consensus receipt contains a list of ModelIDs, real-time reputation scores, and an Ed25519 signature, auditors can utilize the chain structure of prevHash = H(R(n-1)) to accurately trace back to the physical moment the poisoning attack began and the evolution of each model's weights. This hardware-based defense and recovery system overcomes the fatal flaws of traditional software solutions—such as susceptibility to bypassing low-level attacks, lack of self-healing capabilities, and absence of tamper-proof audit records—achieving reliable control over the entire lifecycle of multi-source AI decision-making.
[0133] The exemplary explanations of the following embodiments can be found in the above embodiments, and will not be repeated here.
[0134] This application also provides a hardware-level multi-source AI decision consensus-building device, including: The parallel input buffer unit is used to perform inference decision stream acquisition and processing for multiple independently running and heterogeneous artificial intelligence models to generate the multi-source inference decision set, and simultaneously establish the historical reputation score stored in the dynamic reputation evaluation unit and corresponding one-to-one with each of the artificial intelligence models. The parallel verification unit and the dynamic reputation evaluation unit are used to perform feature extraction and legality verification processing on the multi-source reasoning decision set to determine the effective decision subset, and to perform a credible weighted operation in combination with the historical reputation score to generate the weighted decision feature body; The consensus algorithm engine and threshold decision unit are used to perform parallel consensus computation on the weighted decision feature body to obtain a preliminary consensus value, and to generate the hardware consensus decision result by comparing the preliminary consensus value with the consensus threshold; and The failure rollback controller and evidence solidification unit are used to perform hierarchical rollback control in response to the consensus failure state in the hardware consensus decision result, extract consensus calculation process data, perform hardware signature encapsulation to generate the hardware signature consensus receipt, and perform dynamic updates on the historical reputation score.
[0135] This application also provides an AI chip, including: AI inference processor, used to perform inference operations on multiple artificial intelligence models; and Hardware-based multi-source AI decision consensus device.
[0136] This application also provides an electronic device, including: The AI chip described in any of the above items; The electronic device is used to perform security actions based on the hardware consensus decision results generated in the AI chip, and to perform decision tracing based on the hardware signature consensus receipt embedded in the AI chip.
[0137] This application also provides a cloud-based AI accountability server, including: The motherboard, and the AI accelerator card and network interface unit integrated on the motherboard; The AI accelerator card includes the AI chip described in any of the above claims, and the AI chip integrates the device described in any of the above claims. The cloud-based AI accountability server performs hardware-level arbitration on cloud-based multi-model inference services through the hardware-based multi-source AI decision consensus reaching device, and sends the hardware signature consensus receipt to the external audit terminal through the network interface unit.
[0138] This application also provides a cloud-based AI trusted computing platform, including: A cluster management server, and a plurality of cloud AI accountability servers described above that are communicatively connected to the cluster management server; The cluster management server is used to collect hardware signature consensus receipts generated by multiple cloud AI accountability servers across nodes, and to perform global consensus integrity verification based on the model identifier and consensus weight contained in each hardware signature consensus receipt, so as to construct a cloud hardware-level multi-source AI decision consensus evidence chain that covers multi-node distributed AI decision-making tasks and is physically anchored to the chip-level hardware trust root.
Claims
1. A method for achieving hardware-level multi-source AI decision consensus, characterized in that, include: Step 1: Control the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through the parallel input buffer unit, so as to generate a multi-source inference decision set and establish the historical reputation score of each AI model. Step 2: Invoke the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body; Step 3: Control the consensus algorithm engine and threshold decision unit to perform parallel consensus calculation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results; Step 4: Utilize the failure rollback controller and evidence solidification unit to perform fault tolerance protection, evidence solidification, and reputation update processing for the hardware consensus decision results.
2. The method for achieving hardware-level multi-source AI decision consensus according to claim 1, characterized in that, Step 1: Control the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through the parallel input buffer unit, so as to generate a multi-source inference decision set and establish the historical reputation score of each AI model, including: After establishing a sideband communication link between the hardware arbitration device and the inference processors corresponding to each AI model, the parallel input buffer unit in the hardware arbitration device is used to synchronously receive the inference decision streams output by each AI model. The identity identifier, initial decision value, and hardware signature certificate of each AI model are extracted from the inference decision flow corresponding to each AI model to generate a multi-source inference decision set.
3. The method for achieving hardware-level multi-source AI decision consensus according to claim 2, characterized in that, Step 1: Control the hardware arbitration device to perform inference decision stream acquisition for multiple AI models through the parallel input buffer unit, so as to generate a multi-source inference decision set and establish the historical reputation score of each AI model, including: The parallel input buffer unit performs hardware data buffering and clock domain alignment processing based on a preset bit width on the identity identifiers, initial decision values, and hardware signature credentials of each AI model carried in the inference decision stream to generate a multi-source inference decision set. Access the dynamic reputation assessment unit inside the hardware arbitration device to read the pre-stored historical reputation scores of each AI model.
4. The method for achieving hardware-level multi-source AI decision consensus according to claim 1, characterized in that, Step 2: Invoke the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body, including: The multi-source inference decision set is fed to the parallel verification unit, which extracts the initial decision value and hardware signature certificate corresponding to each AI model from the multi-source inference decision set and performs hardware-level signature verification and format legality detection on them to determine the valid decision subset composed of the verified initial decision value and hardware signature certificate for hardware-level aggregation processing to generate a weighted decision feature body.
5. The method for achieving hardware-level multi-source AI decision consensus according to claim 4, characterized in that, Step 2, invoking the parallel verification unit and the dynamic reputation evaluation unit to perform legality verification and hardware-level aggregation processing on the multi-source reasoning decision set to generate a weighted decision feature body, also includes: The dynamic reputation assessment unit is invoked in a coordinated manner. Based on the identity identifiers of each AI model contained in the multi-source inference decision set, the corresponding historical reputation scores and the current business scenario security level are retrieved. Hardware-level aggregation is performed on the initial decision values of each AI in the effective decision subset and the hardware signature credentials to generate a weighted decision feature body that reflects the distribution of the credibility of each AI decision within the current decision cycle.
6. The method for achieving hardware-level multi-source AI decision consensus according to claim 1, characterized in that, Step 3: The consensus algorithm engine and threshold decision unit perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results. The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the trend of multi-source consensus. The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
7. The method for achieving hardware-level multi-source AI decision consensus according to claim 1, characterized in that, Step 3: The consensus algorithm engine and threshold decision unit perform consensus operations and validity determination processing on the weighted decision feature body to generate hardware consensus decision results, including: The hardware arbitration device is controlled to dynamically switch from the majority voting circuit, weighted voting circuit and reputation scoring circuit integrated in the consensus algorithm engine to the matching hardware consensus logic according to the preset consensus strategy. Based on the aforementioned hardware consensus logic, a parallel multiplier array and an adder tree structure are used to perform consensus operations on the weighted decision feature body within a set single hardware clock cycle to obtain a preliminary consensus value that uniquely represents the multi-source consensus trend, and then perform validity determination processing to generate a hardware consensus decision result.
8. The method for achieving hardware-level multi-source AI decision consensus according to claim 7, characterized in that, Step 3: The consensus algorithm engine and threshold decision unit perform parallel consensus computation and validity determination processing on the weighted decision feature body to generate hardware consensus decision results, which also includes: The threshold decision unit is invoked to compare the preliminary consensus value with the dynamically configured hardware consensus threshold execution range. If the threshold is met, the final decision is determined to be valid. If the threshold is not met, the consensus failure state is marked. Then, the hardware consensus decision result used to drive the downstream actuator or trigger the protection action is determined by the parallel arithmetic logic of the pure hardware circuit.
9. A method for achieving hardware-level multi-source AI decision consensus according to claim 1, characterized in that, Step 4: Utilize the failure rollback controller and evidence solidification unit to perform hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision results, including: The hardware consensus decision result is fed to the failure rollback controller. In response to the consensus failure state carried in the hardware consensus decision result, the built-in four-level hardware state machine automatically triggers a graded rollback action including retry, backup switch, manual intervention and emergency termination, so as to block decision risk without software intervention.
10. A method for achieving hardware-level multi-source AI decision consensus according to claim 9, characterized in that, Step 4: Utilize the failure rollback controller and evidence solidification unit to perform hardware state machine-based fault tolerance protection, evidence solidification, and reputation update processing on the hardware consensus decision results, including: The driving evidence solidification unit extracts the hardware consensus decision results and the historical reputation scores corresponding to each AI model, and performs hardware signature encapsulation on them according to the physically unreadable private key built into the chip to generate a hardware signature consensus receipt anchored to the current hardware epoch timestamp. The hardware signature consensus receipt is physically stored in a non-volatile storage unit, and the hardware consensus decision results are used to dynamically update the historical reputation scores of each AI model in the dynamic reputation evaluation unit.
11. A hardware-level multi-source AI decision-making consensus-building device, characterized in that, include: The parallel input buffer unit is used to perform inference decision stream acquisition and processing for multiple independently running and heterogeneous artificial intelligence models to generate the multi-source inference decision set, and simultaneously establish the historical reputation score stored in the dynamic reputation evaluation unit and corresponding one-to-one with each of the artificial intelligence models. The parallel verification unit and the dynamic reputation evaluation unit are used to perform feature extraction and legality verification processing on the multi-source reasoning decision set to determine the effective decision subset, and to perform a credible weighted operation in combination with the historical reputation score to generate the weighted decision feature body; The consensus algorithm engine and threshold decision unit are used to perform parallel consensus computation on the weighted decision feature body to obtain a preliminary consensus value, and generate the hardware consensus decision result by comparing the preliminary consensus value with the consensus threshold. as well as The failure rollback controller and evidence solidification unit are used to perform hierarchical rollback control in response to the consensus failure state in the hardware consensus decision result, extract consensus calculation process data, perform hardware signature encapsulation to generate the hardware signature consensus receipt, and perform dynamic updates on the historical reputation score.
12. An AI chip, characterized in that, include: AI inference processor, used to perform inference operations on multiple artificial intelligence models; as well as The hardware-based multi-source AI decision consensus-building device as described in claim 11.
13. An electronic device, characterized in that, include: The AI chip as described in claim 12; The electronic device is used to perform security actions based on the hardware consensus decision results generated in the AI chip, and based on the hardware signature consensus receipt embedded in the AI chip.
14. A cloud-based AI accountability server, characterized in that, include: The motherboard, and the AI accelerator card and network interface unit integrated on the motherboard; The AI accelerator card includes the AI chip as described in claim 12, and the AI chip integrates the device as described in claim 11. The cloud-based AI accountability server performs hardware-level arbitration on cloud-based multi-model inference services through the hardware-based multi-source AI decision consensus reaching device, and sends the hardware signature consensus receipt to the external audit terminal through the network interface unit.
15. A cloud-based AI trusted computing platform, characterized in that, include: A cluster management server, and multiple cloud AI accountability servers as described in claim 14 that are communicatively connected to the cluster management server; The cluster management server is used to collect hardware signature consensus receipts generated by multiple cloud AI accountability servers across nodes, and to perform global consensus integrity verification based on the model identifier and consensus weight contained in each hardware signature consensus receipt, so as to construct a cloud hardware-level multi-source AI decision consensus evidence chain that covers multi-node distributed AI decision-making tasks and is physically anchored to the chip-level hardware trust root.