Method for allocating processing power in a system having at least one machine learning model

The method optimizes computing resource allocation for machine learning models in software development by using metrics and weightings, addressing inefficiencies in current AI methods to enhance security and efficiency.

WO2025153397A1PCT designated stage expired Publication Date: 2025-07-24ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/050495
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-19
Filing Date
2025-01-10
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Current AI methods in software development do not optimally allocate computing resources based on the specific requirements and computational intensity of different machine learning models, leading to inefficient use of resources.

Method used

A method for allocating computing power based on metrics and weightings specific to each machine learning model, considering their relevance and context within the system, using a planner module to optimize resource distribution across multiple software projects.

Benefits of technology

Optimizes computing resource allocation to achieve maximum security gains and efficiency by prioritizing business-critical projects and models, reducing unnecessary computing power usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025050495_24072025_PF_FP_ABST
    Figure EP2025050495_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method (100) for allocating processing power in a system (1) having at least one machine learning model, the system (1) being designed to develop and / or manage software, comprising the following steps: - initiating (101) an application of the at least one machine learning model, wherein at least one metric for the at least one machine learning model is determined, the at least one metric providing a measure of a required processing power relative to a quality of an output from the at least one machine learning model, - providing (102) a weighting for the at least one machine learning model, the weighting representing a relevance of the at least one machine learning model based on a context in the system (1), - allocating (103) the processing power for a use of the at least one machine learning model on the basis of the at least one determined metric and the provided weighting. The invention also relates to a computer program, to a device and to a storage medium for this purpose.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Procedure for allocating in a with a machine learning model

[0003] The invention relates to a method for allocating computing power in a system with at least one machine learning model, wherein the system is designed for software development and / or management. Furthermore, the invention relates to a computer program, a device, and a storage medium for this purpose.

[0004] State of the art

[0005] Some artificial intelligence (AI) methods are more general in nature, while others are highly specialized. For every step in a typical software development process cycle, there is at least one type of machine learning model that can be best used to improve overall code quality. These machine learning models include large language models (LLMs), which are particularly well-suited for code generation and deployment, e.g., Helm charts. LLMs typically start with a very general base model that can solve common tasks and are then further trained to solve specific requirements, such as generating specific code. Graph neural networks (GNNs) can identify problems that would normally require extensive analysis if they can be represented as a graph. Such problems can, for example,the detection of variable misuse and type inference during build time.

[0006] Genetic machine learning models, for example, are suitable for highly specific use cases. These usually start with an empty or problem-specific predefined set and iterate over this set. Fuzzing is an example of genetic machine learning models that generate more and more or better test cases to cover more code blocks and branches in the software under test. Neural networks (NNs), for example, are very well suited for pattern recognition. Pattern recognition involves detecting specific vulnerabilities that could be exploited, e.g., user input passed to a memcopy function. Each AI method, or each type of machine learning model, has its own metrics that the respective AI method attempts to maximize. In fuzzing, this would be, for example, the test coverage of a code.

[0007] In the current state of the art, the use of different KL methods, or different types of machine learning models, is handled very optimistically based on their respective advantages and does not take the required computational power into account. In practice, however, machine learning models can be very computationally intensive. This can be due to factors such as training, as with LLMs and NNs, or frequent use, as with genetic machine learning models.

[0008] Disclosure of the invention

[0009] The subject matter of the invention is a method having the features of claim 1, a computer program having the features of claim 8, a device having the features of claim 9 and a computer-readable storage medium having the features of claim 10. Further features and details of the invention emerge from the respective subclaims, the description and the drawings. Features and details described in connection with the method according to the invention naturally also apply in connection with the computer program according to the invention, the device according to the invention and the computer-readable storage medium according to the invention, and vice versa, so that with regard to the disclosure of the individual aspects of the invention, reference is or can always be made to each other.

[0010] The invention particularly relates to a method for allocating computing power in a system with at least one machine learning model, wherein the system is configured for software development and / or management, comprising the following steps, wherein the steps can be performed repeatedly and / or sequentially. The steps of the method are preferably performed continuously and / or cyclically. Software security is preferably an integral component of the development and / or management of the software. Preferably, the development and / or management of the software is based on the "DevSecOps" approach. DevSecOps is, in particular, a term composed of the words "Development," "Security," and "Operations." DevSecOps can refer to an approach in software development in which security is considered an integral component of the entire development process.In contrast to traditional models, where security considerations are often only taken into account at the end of the development cycle, DevSecOps prefers to integrate security aspects into the software development lifecycle from the beginning.

[0011] In a first step, an application of the at least one machine learning model is preferably initiated, wherein at least one metric for the at least one machine learning model is determined. The at least one metric provides, in particular, a measure of the required computing power in relation to the quality of an output of the at least one machine learning model. If at least two different machine learning models are used, a different metric can also be determined for each of the machine learning models.

[0012] Possible metrics for the at least one machine learning model can, for example, relate to code generation by the at least one machine learning model. This can be measured using the following code complexity metrics, for example: cyclomatic complexity, number of lines of code, number of lines of code with executable code, coupling and / or depth of inheritance, maintainability index, cognitive complexity, Halstead volume, and rework ratio.

[0013] Furthermore, test cases generated by the at least one machine learning model can be evaluated within the context of other possible metrics. Examples are fuzz tests or LLM-generated unit tests. Created test cases can be measured using the following test metrics: A test metric could be a number of crashes or hangs, ideally a number of (potentially exploitable) bugs identified by crashing inputs. Furthermore, a test metric could be a total runtime or a timeout. Another test metric could be a coverage, e.g.

[0014] These could be row coverage, block coverage, edge coverage, or branch coverage. Furthermore, the frequency of newly discovered coverage or the number of generated test cases could be possible test metrics. For embedded systems, additional test metrics could include power consumption, returned error codes, and timeouts.

[0015] In a further step, a weighting is preferably provided for the at least one machine learning model. The weighting can represent a relevance of the at least one machine learning model related to a context in the system. In an alternative possibility, the weighting can also be defined or determined dynamically and / or automatically by the system. The relevance related to the context in the system expresses in particular that, for example, some software projects are more important or business-critical than others. The weighting can further indicate that some machine learning models are more important than others, e.g. if a generative machine learning model generates secure code, optionally with a validation and verification network. As a result, testing can become less relevant and correspondingly less computing power can be allocated to a machine learning model used for testing.

[0016] In a further step, the computing power is preferably allocated with regard to the use of the at least one machine learning model based on the at least one determined metric and the provided weighting. For this purpose, at least one fitness value can first be determined based on the at least one determined metric and the provided weighting, for example by multiplying a respective value of the metric by a respective weighting of the respective machine learning model. A specialized planner module in the form of a software module can be used to allocate the computing power. In simple terms, this determines in particular when, where, and with which computing power the at least one machine learning model is used. This advantageously allows optimal utilization of the computing power available to the system.

[0017] Furthermore, within the scope of the invention, it can be provided that the at least one machine learning model is a generative machine learning model, a graph-based machine learning model, a self-learning machine learning model, and / or a pattern recognition machine learning model. In particular, at least one of the aforementioned machine learning models can be provided. A generative machine learning model is preferably a large language model. The self-learning machine learning model is preferably a genetic machine learning model and is, in particular, a neural network that applies a genetic algorithm, for example, fuzzing. The pattern recognition machine learning model is, in particular, a neural network trained for pattern recognition.

[0018] Furthermore, it is conceivable for the system to comprise at least two generative machine learning models, in particular large language models, wherein the at least two generative machine learning models are combined in a generative machine learning model cluster. This advantageously makes it possible to provide a combined application of the at least two generative machine learning models. For this purpose, problems that can be solved by the at least two generative machine learning models can also be combined accordingly. This advantageously increases efficiency and reduces the required computing power. The at least two generative machine learning models can at least provide code generation. Furthermore, deployment of software by the generative machine learning models is possible.

[0019] A further advantage within the scope of the invention can be achieved if the system comprises at least two self-learning machine learning models, wherein the at least two self-learning machine learning models are bundled in a self-learning machine learning model cluster. This advantageously makes it possible to provide a combined application of the at least two self-learning machine learning models. The at least two self-learning machine learning models can test the system, in particular based on fuzzing. In this case, random test cases are created, for example. The provided cluster can advantageously enable testing for multiple software projects in order to increase testing efficiency and effectiveness.

[0020] Furthermore, it is conceivable that the development and / or management of at least two software projects is carried out automatically by the system, and the allocation of computing power is carried out with regard to the at least two software projects. In other words, according to the present invention, the available computing power can advantageously be allocated to the at least two software projects in a centralized manner. For this purpose, a central data processing device can be provided, which has an overview of the available computing power.

[0021] According to an advantageous development of the invention, the system can be designed as a software system, and the application of the at least one machine learning model comprises generating, modifying, and / or testing at least one software function of the system. In this case, a code of the at least one software function can be at least partially generated, modified, and / or tested.

[0022] Furthermore, within the scope of the invention, it can be provided that the allocation of computing power comprises the following steps:

[0023] Specifying the use of the at least one machine learning model with regard to a period of use, a frequency of use, a location of use and / or a type of use, assigning a respective computing power to the respectively specified use.

[0024] For example, different time periods can be defined for the use of the at least one machine learning model. A location of use can, for example, specify a spatial proximity, so that, for example, use via the internet, such as via a cloud server, or direct use on an existing data processing device can be determined. One type of use can, for example, be a specific processor type such as a CPU or a GPU. The allocation of the respective computing power could, for example, include how much RAM, how many processor cores, and / or how many servers are made available for the use of the respective machine learning model.

[0025] The invention also relates to a computer program, in particular a computer program product, comprising instructions that, when executed by a computer, cause the computer to carry out the method according to the invention. Thus, the computer program according to the invention provides the same advantages as those described in detail with reference to a method according to the invention.

[0026] The invention also relates to a data processing device configured to carry out the method according to the invention. The device can be, for example, a computer that executes the computer program according to the invention. The computer can have at least one processor for executing the computer program. A non-volatile data memory can also be provided, in which the computer program is stored and from which the computer program can be read by the processor for execution.

[0027] The invention may also provide a computer-readable storage medium that contains the computer program according to the invention and / or includes instructions that, when executed by a computer, cause the computer to carry out the method according to the invention. The storage medium is designed, for example, as a data storage device such as a hard disk and / or a non-volatile memory and / or a memory card. The storage medium can, for example, be integrated into the computer.

[0028] Furthermore, the method according to the invention can also be implemented as a computer-implemented method. Further advantages, features, and details of the invention will become apparent from the following description, in which exemplary embodiments of the invention are described in detail with reference to the drawings. The features mentioned in the claims and in the description may be essential to the invention individually or in any combination. They show:

[0029] Fig. 1 shows a schematic visualization of a method, a device, a storage medium and a computer program according to embodiments of the invention,

[0030] Fig. 2 is a schematic representation of a system according to embodiments of the invention.

[0031] In Fig. 1, a method 100, a device 10, a storage medium 15 and a computer program 20 according to embodiments of the invention are shown schematically.

[0032] Fig. 1 shows in particular an embodiment of a method 100 for allocating computing power in a system 1 with at least one machine learning model, wherein the system 1 is designed for developing and / or managing software. In a first step 101, an application of the at least one machine learning model is initiated, wherein at least one metric for the at least one machine learning model is determined. The at least one metric provides a measure of the required computing power in relation to the quality of an output of the at least one machine learning model. In a second step 102, a weighting is provided for the at least one machine learning model, wherein the weighting represents a relevance of the at least one machine learning model related to a context in the system 1.In a third step 103, the computing power is allocated with respect to the use of the at least one machine learning model based on the at least one determined metric and the provided weighting. Fig. 2 shows a system 1 according to embodiments of the invention, wherein the system 1 is designed for developing and managing software. The system 1 comprises various machine learning models such as a generative machine learning model 2, a self-learning machine learning model 3, a graph-based machine learning model 4, and a pattern recognition machine learning model 5. In this embodiment, several generative machine learning models 2 are combined to form a generative machine learning model cluster 6. Analogously, several self-learning machine learning models 3 are combined to form a self-learning machine learning model cluster 7.The machine learning models are used for various tasks in the area of ​​software development and management, which is illustrated by the respective loops 8 in the middle part of Fig. 2. The loops 8 each represent a software project or a DevSecOps cycle. Each loop 8 includes code generation 11, code building 12, testing 13, release 14, deployment 15, operation 16, monitoring 17, and planning 18. Software development and management preferably uses the DevSecOps approach.

[0033] The present invention relates in particular to Artificial Intelligence (AI) methods in DevSecOps, namely generative machine learning models 2 such as Large Language Models (LLM), graph-based machine learning models 4 such as Graph Neural Networks (GNN), self-learning machine learning models 3 such as genetic machine learning models, and pattern recognition machine learning models 5 such as Neural Networks (NN). While some machine learning models are general and can use a "one-size-fits-all" model for multiple software projects, others, for example, require a specialized machine learning model for each individual software project. In particular, frequent retraining of specialized machine learning models, creation of general machine learning models, and continuous application of some machine learning models can be very computationally intensive.In some cases, this may require so much computing power that it would be uneconomical to provide virtually unlimited resources to each machine learning model. One aspect of the invention is, in particular, a holistic approach to multiple software projects and the introduction of a planning module that allocates computing power to where the greatest security gain is expected.

[0034] For example, the present invention addresses the problem of how to plan computing power with multiple machine learning models in such a way that the greatest possible security advantage can be achieved for multiple software projects.

[0035] According to exemplary embodiments, the invention has, in particular, the following advantages over the prior art. A holistic view of the optimal use of computing resources is provided for all software projects and for all machine learning models involved. Computing power is preferably automatically allocated to important or business-critical software projects. A weighting is preferably applied, whereby computing power is controlled in a causal relationship. For example, if the code generated by a machine learning model is provably secure, e.g., through a verification and validation network or another static method, the machine learning-based tests for this code can be reduced.

[0036] A system 1 according to a possible embodiment is shown in Fig. 2. The system extends prior art systems, for example, in the following points. In particular, multiple DevOps cycles are considered, for example, multiple software projects. A company can divide available computing power, e.g., servers, across multiple software projects, so a holistic view can be advantageous.

[0037] Generative machine learning models 2, such as LLMs, can be grouped together in a generative machine learning model cluster 6. Since generative machine learning models 2 are best suited for general problems, coding and implementation problems can also be grouped together in clusters. Furthermore, self-learning machine learning models 3 can also be bundled together in a self-learning cluster 7. For example, if fuzzing is used as a genetic machine learning model 3, each fuzzer preferably starts from scratch or with a minimal test set whose test coverage increases over time, the longer a specific software project is fuzzed. Some parts can be reused, e.g., mutation strategies or the generation of inputs, but genetic machine learning models 3 are particularly characterized by a highly specific application.

[0038] Graph-based machine learning models 4 and pattern recognition machine learning models 5, on the other hand, can be very general and can be reused in many parts for multiple software projects.

[0039] Within the scope of the present invention, according to embodiments, a holistic consideration of all different metrics of the machine learning models is provided, whether for the same machine learning model or machine learning model clusters from different DevOps cycles or for the same DevOps cycle from different machine learning models. For the generative machine learning model cluster, a sum of all fitness values (i.e., all metrics of the individual generative class) from each of the F generative machine learning model blocks are used. In particular, each block has its own weight wj to represent that some generative machine learning model blocks may be more important than others. The weights may change over time. The weights are labeled F in the formula below to distinguish them from other weights.

[0040] The same applies to the self-learning machine learning model cluster, where all fitness functions g of G self-learning machine learning model blocks are summed together with a corresponding weight w.

[0041] For the other two machine learning models, their metrics and / or fitness values ​​can be adopted unchanged. This means, in particular, that for graph-based machine learning models, f Graphbastert and for pattern recognition machine learning models f Mu ster detection should be considered.

[0042] According to the exemplary embodiments, the planner module takes the current total fitness value f Ge and then attempts to optimize a future overall fitness value f' overall for multiple software projects and multiple machine learning models. where HI {f Generative' f self-learning' f Graph-based < flauster recognitionf

[0043] The generative machine learning model 2, or the generative machine learning model cluster 6, should generate "good" code. Examples include ChatGPT or Github's Code Pilot, which can be used for code generation. Code generation can be measured using the following code complexity metrics: cyclomatic complexity, number of lines of code, number of lines of executable code, coupling and / or depth of inheritance, maintainability index, cognitive complexity, Halstead volume, and rework ratio.

[0044] The self-learning machine learning model 3, or the self-learning machine learning model cluster 7, should generate "good" test cases. Examples are fuzz tests or LLM-generated unit tests. Generated test cases can be measured using the following test metrics. One test metric could be the number of crashes or hangs, or in the best case, the number of (potentially exploitable) bugs identified by crashing inputs. Furthermore, a test metric could be a total runtime or a timeout. Another test metric could be coverage, such as line coverage, block coverage, edge coverage, or branch coverage. Furthermore, the frequency of newly discovered coverage or the number of generated test cases can be possible test metrics. For embedded systems, additional test metrics could be power consumption, returned error codes, and timeouts.

[0045] The method according to an embodiment is described below:

[0046] First, the system 1 shown in Fig. 2 can be provided and, in a first step, each machine learning model can be executed to obtain some fitness values ​​f. In a further step, weightings w can be provided or, alternatively, calculated in each cycle by a planner module according to the invention. In this case, each weighting can represent that, for example, some software projects are more important (or more business-critical) than others. The weighting w can further indicate that some machine learning models are more important than others, e.g. when a generative machine learning model generates secure code, optionally with a validation and verification network. This can make testing less relevant. In a further step, in particular by the planner module, it can be estimated how much computing power should be allocated to each machine learning model and / or software project.Preferably, a maximum value for the function f should be found. Ge This can be represented, for example, as a search-based problem that can be solved using a machine learning model itself, such as

[0047] Gradient descent with a neural network. The planner module covers, for example, the following relationships. It can be considered which software project is more business-critical, e.g., based on an observation in a monitoring phase, where a number of users or a number of attacks can be analyzed. Furthermore, it can be evaluated which software project takes longer or is more complicated to create. This can be identified where a graph-based machine learning model 4 can be used most advantageously. Furthermore, it can be determined where new code was generated with a generative machine learning model, e.g., a new feature or a patch, and where this new code needs more testing with a self-learning machine learning model compared to older code. In a further step, each machine learning model is executed with a given computing budget.Subsequently, a continuous update of all metrics and fitness values ​​f can be provided. The process of estimating how much computing power should be allocated to each machine learning model and / or software project is preferably performed repeatedly, especially cyclically. Furthermore, the weights w can be updated repeatedly. Typically, a DevOps cycle preferably has no end, but the overall computing power may decrease when the metric and fitness values ​​reach or approach a saturation point.

[0048] Alternatively, the idea is not limited to AI-based methods, but is also applicable to DevSecOps methods. Typical DevSecOps methods include the following: requirements analysis, secure coding, SÄST, white box DAST, black box DAST, digital sign, security analysis, security monitoring, security audit, security patch, security scan, security configuration, and secure transfer.

[0049] The method for holistic load or computing power distribution according to embodiments can also be used for already known algorithms such as code generators, build chains, tests, etc. However, with the advent of machine learning models, which can be very expensive in terms of power consumption, the method according to embodiments is particularly advantageous. DevSecOps can have several metrics, such as the following: a defect density, a defect burn rate, a profiling of critical risks, most important vulnerability types, a number of attackers per application, an attacker response rate, risk points per device, a number of continuous delivery cycles per month, and a number of problems during red teaming exercises. The present invention particularly describes load or computing power balancing for a system 1.System 1 preferably interacts by itself, with all metrics and the actual load or computing power balancing, ie the allocation 103 of computing power, being handled by the.

[0050] System 1 should preferably be carried out automatically.

[0051] The above explanation of the embodiments describes the present invention exclusively by way of examples. Of course, individual features of the embodiments can be freely combined with one another, provided they are technically feasible, without departing from the scope of the present invention.

Claims

Claims 1. A method (100) for allocating computing power in a system (1) having at least one machine learning model, wherein the system (1) is designed for developing and / or managing software, comprising the following steps: Initiating (101) an application of the at least one machine learning model, wherein at least one metric is determined for the at least one machine learning model, wherein the at least one metric provides a measure of a required computing power in relation to a quality of an output of the at least one machine learning model, Providing (102) a weighting for the at least one machine learning model, wherein the weighting represents a relevance of the at least one machine learning model related to a context in the system (1), Allocating (103) the computing power with respect to a use of the at least one machine learning model based on the at least one determined metric and the provided weighting.

2. The method (100) according to claim 1, characterized in that the at least one machine learning model is a generative machine learning model (2), a graph-based machine learning model (4), a self-learning machine learning model (3) and / or a pattern recognition machine learning model (5).

3. Method (100) according to one of the preceding claims, characterized in that the system (1) comprises at least two generative machine learning models (2), in particular large language models, wherein the at least two generative machine learning models (2) are combined in a generative machine learning model cluster (6) in order to provide a combined application of the at least two generative machine learning models (2), wherein the at least two generative machine learning models (2) provide at least one generation of code.

4. Method (100) according to one of the preceding claims, characterized in that the system (1) comprises at least two self-learning machine learning models (3), wherein the at least two self-learning machine learning models (3) are bundled in a self-learning machine learning model cluster (7) in order to provide a combined application of the at least two self-learning machine learning models (3), wherein the at least two self-learning machine learning models (3) test the system (1), in particular on the basis of fuzzing.

5. Method (100) according to one of the preceding claims, characterized in that the development and / or the management of at least two software projects is carried out automatically by the system (1) and the allocation (103) of the computing power is carried out with regard to the at least two software projects.

6. Method (100) according to one of the preceding claims, characterized in that the system (1) is designed as a software system and the application of the at least one machine learning model comprises generating, modifying and / or testing at least one software function of the system (1).

7. Method (100) according to one of the preceding claims, characterized in that the allocation (103) of the computing power comprises the following steps: Specifying the use of the at least one machine learning model with regard to a period of use, a frequency of use, a location of use and / or a type of use, Assigning a respective computing power to the respective specified use.

8. A computer program (20) comprising instructions which, when the computer program (20) is executed by a computer (10), cause the computer (10) to carry out the method (100) according to any one of the preceding claims.

9. Device (10) for data processing which is arranged to carry out the method (100) according to one of claims 1 to 7.

10. A computer-readable storage medium (15) comprising instructions which, when executed by a computer (10), cause the computer (10) to perform the steps of the method (100) according to any one of claims 1 to 7.