Electronic device, method, and non-transitory computer-readable recording medium for protecting artificial intelligence model

By employing compression and encryption techniques for AI model weights within electronic devices, the solution safeguards AI models from theft and unauthorized access, maintaining data integrity and functionality.

WO2025178288A1PCT designated stage Publication Date: 2025-08-28SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/001788
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-03
Filing Date
2025-02-06
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

Existing technologies face challenges in protecting artificial intelligence models from data theft and unauthorized access, particularly in scenarios where sensitive AI model weights are stored in volatile and non-volatile memories, which can be exploited by malicious users.

Method used

Implementing a compressor and decompressor within an electronic device to compress and decompress AI model weights using algorithms like lossless compression (RLE, ZVC, UBWC) and selectively apply encryption, ensuring secure transfer and storage of AI model data between memory and processor units.

Benefits of technology

Enhances security by maintaining the integrity and confidentiality of AI model data, preventing unauthorized reconstruction and theft, while ensuring efficient operation of AI model functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025001788_28082025_PF_FP_ABST
    Figure KR2025001788_28082025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is an electronic device. The electronic device may store weights related to an artificial intelligence (AI) model in a non-volatile memory. The electronic device may compress, by means of a compressor, some weights related to a designated operation among the weights stored in the non-volatile memory on the basis of a load request for the designated operation, and load the compressed weights to a first volatile memory. The electronic device may decompress the some weights compressed and loaded to the first volatile memory by means of a decompressor and load the decompressed weights to a second volatile memory. The electronic device may perform the designated operation on the basis of the some weights decompressed and loaded to the second volatile memory.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device, method, and non-transitory computer-readable recording medium for protecting artificial intelligence models

[0001] The following descriptions relate to electronic devices, methods, and non-transitory computer-readable recording media for protecting artificial intelligence models.

[0002] Artificial intelligence is a field of computer engineering and information technology that studies ways to enable computers to perform human-like tasks such as thinking, learning, and self-improvement. It means enabling computers to imitate human intelligent behavior.

[0003] Artificial intelligence is a technology for simulating the neural activity of humans (or living things), such as perception and / or inference, and can be implemented by hardware, software, or a combination of these designed to perform computations for simulating neural activity.

[0004] An electronic device is disclosed. The electronic device may include a compressor for compressing data based on a compression algorithm, a decompressor for decompressing data based on a decompression algorithm corresponding to the compression algorithm, at least one processor, a non-volatile memory for storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to store weights associated with an artificial intelligence (AI) model in the non-volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to compress, through the compressor, some weights associated with a designated operation among the weights stored in the non-volatile memory based on a load request for a designated operation and load the compressed weights into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to decompress the portion of the weights loaded in the compressed state into the first volatile memory through the decompressor and load the decompressed portion of the weights into the second volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to perform the specified operation based on the portion of the weights loaded in the decompressed state into the second volatile memory.

[0005] An electronic device is disclosed. The electronic device may include a communication circuit, a compressor for compressing data based on a compression algorithm, a decompressor for decompressing data based on a decompression algorithm corresponding to the compression algorithm, at least one processor, a non-volatile memory for storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to obtain an artificial intelligence (AI) model including weights from a server via the communication circuit. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to compress the weights included in the AI ​​model through the compressor and store the compressed weights in the non-volatile memory based on a storage request for the weights. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to load some of the weights associated with the designated operation among the compressed weights stored in the non-volatile memory in a compressed state into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to decompress the some of the weights loaded in the compressed state into the first volatile memory through the decompressor and load them into the second volatile memory.The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to perform the specified operation based on the weights loaded in the decompressed state into the second volatile memory.

[0006] An electronic device is disclosed. The electronic device may include a communication circuit, a decompressor for decompressing data based on a decompression algorithm, at least one processor, a non-volatile memory for storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to obtain an artificial intelligence (AI) model including weights in a compressed state from a server via the communication circuit. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to store the weights in a compressed state in the non-volatile memory based on a storage request for the weights. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to load some of the weights associated with the designated operation among the weights in the compressed state into the first volatile memory in the compressed state. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to decompress the some of the weights loaded into the first volatile memory in the compressed state through the decompressor and load the decompressed some of the weights into the second volatile memory. The instructions, when individually or collectively executed by the at least one processor, may cause the electronic device to perform the designated operation based on the some of the weights loaded into the second volatile memory in the decompressed state.

[0007] A method is disclosed. The method can be performed in an electronic device. The method can include storing weights related to an artificial intelligence (AI) model in a non-volatile memory. The method can include compressing some of the weights related to the specified operation among the weights stored in the non-volatile memory through a compressor and loading them into a first volatile memory based on a load request for a specified operation. The method can include decompressing some of the weights loaded in the compressed state into the first volatile memory through a decompressor and loading them into a second volatile memory. The method can include performing the specified operation based on some of the weights loaded in the decompressed state into the second volatile memory.

[0008] A non-transitory computer-readable storage medium is disclosed. The non-transitory computer-readable storage medium may store a program including instructions. The instructions, when individually or collectively executed by at least one processor of an electronic device, may cause the electronic device to store weights associated with an artificial intelligence (AI) model in a non-volatile memory. The instructions, when individually or collectively executed by at least one processor of the electronic device, may cause the electronic device to, based on a load request for a designated operation, compress some of the weights stored in the non-volatile memory associated with the designated operation through a compressor and load them into a first volatile memory. The instructions, when individually or collectively executed by at least one processor of the electronic device, may cause the electronic device to decompress some of the weights loaded in the compressed state into the first volatile memory through a decompressor and load them into a second volatile memory. The instructions, when individually or collectively executed by at least one processor of the electronic device, may cause the electronic device to perform the specified operation based on the portion of the weights loaded in the decompressed state into the second volatile memory.

[0009] FIG. 1 is a block diagram of an electronic device within a network environment according to various embodiments.

[0010] FIG. 2A is a block diagram of an electronic device according to one embodiment.

[0011] FIG. 2b is a block diagram of an electronic device according to one embodiment.

[0012] FIG. 2c is a block diagram of an electronic device according to one embodiment.

[0013] FIG. 3 is a block diagram of an electronic device according to one embodiment.

[0014] FIG. 4A is a block diagram of an electronic device according to one embodiment.

[0015] FIG. 4b is a block diagram of an electronic device according to one embodiment.

[0016] FIG. 4c is a block diagram of an electronic device according to one embodiment.

[0017] FIG. 4d is a block diagram of an electronic device according to one embodiment.

[0018] FIG. 5 is a block diagram of a server and an electronic device according to one embodiment.

[0019] Figure 6 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0020] Figure 7 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0021] Figure 8 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0022] FIG. 9 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0023] FIG. 10 is a diagram illustrating an example of an artificial intelligence (AI) model driven by an electronic device according to one embodiment.

[0024] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments.

[0025] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0026] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or operations. According to one embodiment, as at least a part of the data processing or operations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together with the main processor (121). For example, when the electronic device (101) includes the main processor (121) and the auxiliary processor (123), the auxiliary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a given function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0027] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0028] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).

[0029] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0030] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0031] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0032] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0033] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0034] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0035] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0036] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0037] The haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. According to one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0038] The camera module (180) can capture still images and moving images. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0039] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented as, for example, at least a part of a power management integrated circuit (PMIC).

[0040] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0041] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0042] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 664 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 6 ms or less for round trip) for URLLC realization.

[0043] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas, for example, by the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device via the at least one selected antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0044] According to various embodiments, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.

[0045] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0046] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0047] FIG. 2A is a block diagram of an electronic device according to one embodiment. FIG. 2A may be described with reference to FIG. 1.

[0048] Referring to FIG. 2A, the electronic device (101) may include a processor (120), a direct memory access (DMA) controller (230), memory (240), storage (260), and a compressor module (280).

[0049] In one embodiment, the processor (120) may correspond to the processor (120) of FIG. 1. In one embodiment, the processor (120) may include at least one core (221, 225). In one embodiment, the at least one core (221, 225) may be understood as one of the main processor (121) or the auxiliary processor (123) of FIG. 1. For example, the at least one core (221, 225) may be one of a central processing unit (CPU) (or an application processor (AP)), a graphic processing unit (GPU), a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor. In one embodiment, the processor (120) may include a CPU (or an AP), a GPU, or an NPU as one of the at least one core (221, 225).

[0050] For example, the processor (120) (or at least one core (221, 225)) may include volatile memory (e.g., registers, cache, SRAM, PSRAM, or DRAM).

[0051] In one embodiment, the DMA controller (230) may include a DMA write (231) and / or a DMA read (235).

[0052] In one embodiment, the DMA controller (230) may be included in a circuit for a communication bus (or an internal bus). For example, if the DMA controller (230) is to provide data to a graphic processing unit (GPU) and / or a neural processing unit (NPU), it may be included in a circuit for the communication bus (or an internal bus). For example, if the DMA controller (230) is to provide data to a graphic processing unit (GPU) and / or a neural processing unit (NPU), the DMA controller (230) may communicate with the graphic processing unit (GPU) and / or the neural processing unit (NPU) via the communication bus (or the internal bus). In this case, the DMA controller (230), the graphic processing unit (GPU), and the neural processing unit (NPU) may be included in different direct circuits (or different SoCs (systems on a chip)). However, the present invention is not limited thereto. For example, if the DMA controller (230) is to provide data to the CPU (or AP), it may be included inside the CPU (or AP) (e.g., the structure of FIG. 4a).

[0053] In one embodiment, the processor (120) and the DMA controller (230) may be included in a single SoC (system on a chip) (or a single integrated circuit), but are not limited thereto.

[0054] In one embodiment, the memory (240) may correspond to the memory (130) of FIG. 1. For example, the memory (240) may correspond to the volatile memory (132) of FIG. 1. For example, the memory (240) may be located outside the processor (120) and the DMA controller (230). In one embodiment, the memory (240) may be a memory that is physically separate from memories (e.g., registers and at least one cache) within the processor (120) and the DMA controller (230).

[0055] In one embodiment, the memory (240) may temporarily load data (270) stored in storage (260) into the memory (240) based on a command (e.g., a read command) of the processor (120). In one embodiment, the memory (240) may store data (250) loaded into the memory (240) into the storage (260) based on a command (e.g., a write command) of the processor (120).

[0056] In one embodiment, the storage (260) may correspond to the non-volatile memory (134) of FIG. 1. In one embodiment, the storage (260) may transfer data (270) stored in the storage (260) to the memory (240) in response to a read command of the processor (120). In one embodiment, the storage (260) may store data (250) loaded in the memory (240) in the storage (260) in response to a write command of the processor (120). In one embodiment, the data (250) loaded in the memory (240) may be (substantially) identical to the data (270) stored in the storage (260).

[0057] In one embodiment, the compressor module (280) may include a compressor (281) and / or a decompressor (285).

[0058] In one embodiment, the compressor module (280) may be included in a circuit for a communication bus (or internal bus). For example, if the compressor module (280) is to provide data to a graphics processing unit (GPU) and / or a neural network processing unit (NPU), it may be included in a circuit for a communication bus (or internal bus). For example, if the compressor module (280) is to provide data to a graphics processing unit (GPU) and / or a neural network processing unit (NPU), the compressor module (280) may communicate with the graphics processing unit (GPU) and / or the neural network processing unit (NPU) via a communication bus (or internal bus). In this case, the compressor module (280), the graphics processing unit (GPU), and the neural network processing unit (NPU) may be included in different direct circuits (or different SoCs). However, the present invention is not limited thereto. For example, if the compressor module (280) is to provide data to the CPU (or AP), it may be included inside the CPU (or AP) (e.g., the structure of FIG. 4a).

[0059] In one embodiment, the processor (120) and the compressor module (280) may be included in a single SoC (system on a chip) (or a single integrated circuit). In one embodiment, the compressor module (280) may be included as an integral part of a single integrated circuit together with a CPU, a GPU, and / or an NPU. In one embodiment, the compressor module (280) may be included in a processing circuit that is physically separate from the CPU, GPU, and / or NPU within a single SoC, but is not limited thereto. In one embodiment, the processor (120) and the compressor module (280) may be included in separate integrated circuits.

[0060] In one embodiment, the memory (240) and / or the storage (260) may be included within a single SoC (or, a single integrated circuit). In one embodiment, the memory (240) and the storage (260) may be included as a single integrated circuit. In one embodiment, the memory (240) may be included in a processing circuit that is physically separate from the storage (260), but is not limited thereto. In one embodiment, the memory (240) and / or the storage (260) may be included in separate integrated circuits.

[0061] In one embodiment, data (250, 270) stored in memory (240) and / or storage (260) may be accessed by an application. Accordingly, data (250, 270) stored in memory (240) and / or storage (260) may be stolen by an application executed by a malicious user.

[0062] Therefore, if the data (250, 270) is an AI (artificial intelligence) model acquired by investing a lot of resources, and is stolen by a malicious user, the same AI model can be reconstructed through the stolen data (250, 270).

[0063] Therefore, a method may be required to protect data (250, 270) related to the AI ​​model stored in memory (240) and storage (260).

[0064] Hereinafter, with reference to FIG. 2a, an operation of an electronic device (101) to protect data (250, 270) related to an AI model can be described.

[0065] Below, the path through which data (270) stored in storage (260) is transferred to the processor (120) can be described.

[0066] In one embodiment, the processor (120) (or CPU) may generate a command (or request) to load data (270) stored in storage (260) including weights (271, 273, 275) into memory (240) to execute one or more functions related to an AI model. The one or more functions related to the AI ​​model may include a function of training the AI ​​model and / or a function of inferring input data based on the AI ​​model. However, the embodiment is not limited thereto. In one embodiment, the data (270) stored in storage (260) may be compressed based on a specified compression algorithm. For example, the specified compression algorithm may be lossless compression (e.g., run length encoding (RLE), zero value compression (ZVC), universal bandwidth compression (UBWC)). However, the embodiment is not limited thereto. According to an embodiment, the compression algorithm may be referred to as an encryption algorithm. In some embodiments, the compression algorithm may twist (or scramble) (or interleave) (or rearrange a sequence of data) the data. Twisting (or scrambling) (or interleaving) (or rearranging a sequence of data) the data may include changing the order of or encrypting at least a portion of the data without substantially changing the size of the data.

[0067] In one embodiment, data (270) may represent data related to an artificial intelligence (AI) model, such as layers, weights, and operations of the AI ​​model. In one embodiment, data (270) may include a plurality of nodes indicated by the AI ​​model, and / or weights (271, 273, 275) assigned to connections between the plurality of nodes. For example, data (210) may include weights (271, 273, 275) for one or more convolution operations associated with the AI ​​model. For example, data (210) may include weights (271, 273, 275) for one or more convolution operations based on a convolution filter associated with the AI ​​model. For example, data (210) may include weights (271, 273, 275) for one or more depthwise convolution operations associated with the AI ​​model. For example, data (210) may include weights (271, 273, 275) for mean pooling operations associated with the AI ​​model. For example, data (210) may include weights (271, 273, 275) for obtaining parameters (e.g., argmax) for maximizing the operation results of layers associated with the AI ​​model. For example, data (210) may include weights (271, 273, 275) for linearizing the operation results of layers associated with the AI ​​model (e.g., linear operation). However, the present invention is not limited thereto. Data (210) may include hyperparameters associated with the AI ​​model.For example, hyperparameters may include at least one of a learning rate, a cost function, a regularization parameter, a mini-batch size, the number of training iterations, the number of hidden layers, a meta parameter, or a free parameter.

[0068] In one embodiment, the weights (271, 273, 275) may have quantized values. However, this is not limited to the above. The weights (271, 273, 275) may have non-quantized (or unquantized) values.

[0069] In one embodiment, the processor (120) (or CPU) may load data (270) stored in storage (260) into memory (240) based on a command (or request) for loading weights.

[0070] In one embodiment, the processor (120) (or CPU) may generate a command (or request) for loading weights related to an operation among weights (251, 253, 255) included in data (250) loaded into memory (240). In one embodiment, the processor (120) (or CPU), when requesting data (250) loaded into memory (240), may determine whether to perform bus compression on the data (250) (or weights (251, 253, 255) included in the data (250). In one embodiment, the operation may be an operation for executing one or more functions related to an AI model. For example, bus compression may refer to a function of compressing or decompressing data (250) on a data transmission path (or bus) between the memory (240) and the processor (120). The electronic device (101) can internally decompress or compress compressed data that can maximize the bus compression rate in the memory (240) through the compressor module (280) on the data transmission path (or bus) between the memory (240) and the processor (120). The electronic device (101) can transmit the compressed data to the processor (120) through the compressor module (280). The electronic device (101) can transmit the decompressed data to the memory (240) through the compressor module (280). In one embodiment, the size of the data after being compressed through the compressor module (280) can be the same as the size of the data before being compressed. In one embodiment, the size of the data after being decompressed through the compressor module (280) can be the same as the size of the data before being decompressed.For example, the compression algorithm through the compressor module (280) may be lossless compression (e.g., run length encoding (RLE), zero value compression (ZVC), universal bandwidth compression (UBWC)). In one embodiment, the compression algorithm through the compressor module (280) may be a compression algorithm that can have the highest compression ratio when compressing in the data transmission path (or bus) between the memory (240) and the processor (120). According to an embodiment, the compression algorithm may be a distortion-based compression algorithm. For example, the compression ratio may represent the ratio between the size of data before compression and the size of data after compression. For example, the smaller the size of data after compression, the higher the compression ratio may be evaluated. According to an embodiment, the compression algorithm may be referred to as an encryption algorithm.

[0071] In one embodiment, the DMA controller (230) can load data (250) from the memory (240) through a communication bus with the memory (240) based on a command (or request) for loading weights related to an operation. In one embodiment, the DMA lead (235) of the DMA controller (230) can load data (250) from the memory (240) through a communication bus with the memory (240) based on a command (or request) for loading weights related to an operation.

[0072] In one embodiment, the compressor module (280) may decompress data (250) loaded from memory (240) via DMA read (235) based on a command (or request) from the processor (120) (or CPU). In one embodiment, the compressor module (280) may decompress data (250) via a decompressor (285). In one embodiment, decompression via the decompressor (285) may be based on a designated decompression algorithm. For example, the designated decompression algorithm may be a counterpart algorithm to a designated compression algorithm applied to data (270) (or data (250)) stored in storage (260) (or memory (240)). For example, the specified compression algorithm may be lossless compression (e.g., run length encoding (RLE), zero value compression (ZVC), universal bandwidth compression (UBWC)). Depending on the embodiment, the decompression algorithm may be referred to as a decryption algorithm.

[0073] In one embodiment, the compressor module (280) can selectively decompress the data (250) based on a determination by the processor (120) (or CPU) as to whether to decompress the data (250). In one embodiment, decompression of the data (250) through the compressor module (280) (or decompressor (285)) can be selectively bypassed based on a determination by the processor (120) (or CPU) as to whether to decompress the data (250). For example, bypassing decompression of the data (250) through the decompressor (285) can include transferring the data (250) loaded from the memory (240) to the processor (120) without decompression. For example, bypassing decompression of data (250) through a decompressor (285) may include the DMA controller (230) delivering data (250) loaded from memory (240) via a DMA lead (235) to the processor (120) without providing it to the compressor module (280).

[0074] For example, the processor (120) (or CPU) may determine whether to decompress data (250) through the decompressor (285). For example, the processor (120) (or CPU) may instruct the compressor module (280) and / or the DMA controller (230) to decompress data (250). For example, the processor (120) (or CPU) may instruct the compressor module (280) to decompress data (250) based on determining whether to decompress data (250). For example, the compressor module (280) may decompress data (250) through the decompressor (285) based on the processor (120) (or CPU) instructing decompression. For example, the processor (120) (or CPU) may instruct the DMA controller (230) to transfer the data (250) based on a determination not to decompress the data (250). For example, decompression of the data (250) through the decompressor (285) may be bypassed based on the processor (120) (or CPU) not instructing the compressor module (280) to decompress.

[0075] For example, the compressor module (280) can determine whether to decompress data (250) through the decompressor (285) based on predefined conditions. For example, the compressor module (280) can decompress data (250) that satisfies the predefined conditions through the decompressor (285). For example, the compressor module (280) can bypass decompression through the decompressor (285) of data (250) that does not satisfy the predefined conditions. For example, the compressor module (280) can decompress data (250) through the decompressor (285) when the data (250) is related to an AI model. For example, the compressor module (280) can decompress the data (250) through the decompressor (285) if the data (250) is related to parameters (251, 253, 255) for calculation through an AI model. For example, the compressor module (280) can decompress the data (250) through the decompressor (285) if the data (250) is related to weights for calculation through an AI model.

[0076] In one embodiment, the compressor module (280) may provide the decompressed data (215) to the processor (120) (or GPU, or NPU) through the decompressor (285). For example, the data (215) may be referred to as raw data, but is not limited thereto. For example, if the data (250) is not related to an AI model, the DMA controller (230) may provide the uncompressed data (210) to the processor (120). In one embodiment, the processor (120) may be one of a CPU (or AP), a GPU, or an NPU. In one embodiment, the compressor module (280) may provide the decompressed data (215) to a volatile memory (e.g., a register, a cache, an SRAM, a PSRAM, or a DRAM) of the processor (120) through the decompressor (285).

[0077] In one embodiment, the processor (120) (or GPU, or NPU) may perform operations to execute one or more functions related to an AI model based on the decompressed data (215). In one embodiment, the processor (120) (or GPU, or NPU) may perform operations to execute one or more functions related to an AI model based on the decompressed data (215) loaded into a volatile memory (e.g., a register, a cache, an SRAM, a PSRAM, or a DRAM) of the processor (120). In one embodiment, the processor (120) may perform operations to execute one or more functions related to an AI model based on the decompressed data (215) loaded into a volatile memory (e.g., a register, a cache, an SRAM, a PSRAM, or a DRAM) through the NPU or the GPU.

[0078] Below, the path through which data (211) is transferred from the processor (120) to the storage (260) can be described.

[0079] In one embodiment, the processor (120) may generate a command (or request) for storing data (211) related to an AI model in a memory (240). The data (211) related to the AI ​​model may be weights updated as the AI ​​model is trained, but is not limited thereto.

[0080] In one embodiment, the compressor module (280) may compress data (211) output from the processor (120) based on a command (or request) from the processor (120). In one embodiment, the compressor module (280) may compress data (211) through the compressor (281). In one embodiment, the compression through the compressor (281) may be based on a specified compression algorithm. For example, the specified compression algorithm may correspond to a specified compression algorithm applied to data (270) (or data (250)) stored in the storage (260) (or memory (240)). In one embodiment, the size of data after compression through the compressor (281) may be the same as the size of data before compression. For example, the specified compression algorithm may be lossless compression (e.g., run length encoding (RLE), zero value compression (ZVC), universal bandwidth compression (UBWC)). In one embodiment, the weights indicated by the data after compression through the compressor (281) may be at least partially different from the weights indicated by the data before compression. However, the present invention is not limited thereto. In one embodiment, the specified compression algorithm may be a compression algorithm that can have the highest compression ratio when compressed on a communication bus. According to an embodiment, the compression algorithm may be a distortion-based compression algorithm. For example, the compression ratio may represent a ratio between the size of data before compression and the size of data after compression. For example, the smaller the size of data after compression, the higher the compression ratio may be evaluated. According to an embodiment, the compression algorithm may be referred to as an encryption algorithm.

[0081] In one embodiment, the compressor module (280) may selectively compress data (211) based on a determination by the processor (120) as to whether to compress data (211). In one embodiment, compression of data (211) through the compressor module (280) (or compressor (281)) may be selectively bypassed based on a determination by the processor (120) as to whether to compress data (211). For example, bypassing compression of data (211) through the compressor (281) may include storing data (211) output from the processor (120) in the memory (240) without compression. For example, bypassing compression of data (211) through a compressor (281) may include the processor (120) passing the data (211) to the DMA controller (230) (or the DMA write (231) of the DMA controller (230)) instead of providing it to the compressor module (280).

[0082] For example, the processor (120) may determine whether to compress data (211) through the compressor (281). For example, the processor (120) may instruct the compressor module (280) and / or the DMA controller (230) as to whether to compress data (211). For example, the processor (120) may instruct the compressor module (280) to compress data (211) based on determining whether to compress data (211). For example, the compressor module (280) may compress data (211) through the compressor (281) based on the processor (120) instructing compression. For example, the processor (120) may instruct the DMA controller (230) to store data (211) in the memory (240) based on determining not to decompress data (211). For example, compression of data (211) through the compressor (281) may be bypassed based on the processor (120) not instructing the compressor module (280) to compress.

[0083] For example, the compressor module (280) can determine whether to compress data (211) through the compressor (281) based on predefined conditions. For example, the compressor module (280) can compress data (211) that satisfies the predefined conditions through the compressor (281). For example, the compressor module (280) can bypass compression through the compressor (281) of data (211) that does not satisfy the predefined conditions. For example, the compressor module (280) can compress data (211) through the compressor (281) when the data is related to an AI (artificial intelligence) model. For example, the compressor module (280) can compress data (211) through the compressor (281) if the data (211) is related to parameters (251, 253, 255) for calculation through an AI model. For example, the compressor module (280) can compress data (211) through the compressor (281) if the data is related to weights for calculation through an AI model.

[0084] In one embodiment, the compressor module (280) may provide compressed data (211) to the DMA controller (230) via the compressor (281). However, this is not limited thereto. For example, if the data (211) is not related to an AI model, the processor (120) may provide uncompressed data (211) to the DMA controller (230).

[0085] In one embodiment, the DMA controller (230) may store compressed data (211) through the compressor (281) in the memory (240). However, this is not limited thereto. For example, if the data (211) is not related to an AI model, the DMA controller (230) may store uncompressed data (211) in the memory (240).

[0086] In one embodiment, the DMA write (231) of the DMA controller (230) may store compressed data (211) in the memory (240) through a communication bus with the memory (240) based on a command (or request) for storing weights related to an operation.

[0087] In one embodiment, the processor (120) may generate a command (or request) for storing data (250) stored in memory (240) into storage (260). In one embodiment, the processor (120) may store compressed data (250) stored in memory (240) into storage (260) based on the command (or request) for storing data (250).

[0088] As described above, the electronic device (101) can store AI model data in a compressed state in the storage (260) and memory (240). In addition, the electronic device improves data transmission and reception performance by compressing or decompressing the data through the compressor module. In addition, the electronic device (101) can transmit or receive the data in a twisted state by compressing or decompressing the data through the compressor module. Accordingly, even if the AI ​​model data is stolen from the storage (260) and memory (240), it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0089] As described above, the electronic device (101) can optionally store data of an AI model that does not wish to be made public in a compressed state in storage (260) and memory (240).

[0090] FIG. 2B is a block diagram of an electronic device according to an embodiment. FIG. 2C is a block diagram of an electronic device according to an embodiment. FIGS. 2B and 2C may be described with reference to FIGS. 1 and 2A.

[0091] The electronic device (101) of FIGS. 2b and 2c may exhibit a state in which the arrangement of the hardware configuration has been changed compared to the electronic device (101) of FIG. 2a.

[0092] For example, the compressor module (280) of the electronic device (101) of FIG. 2b can perform the functions performed by the compressor (281) of FIG. 2a and the functions performed by the decompressor (285) of FIG. 2a through a single, non-separated hardware component (e.g., a single processing circuit), compared to the compressor module (280) of the electronic device (101) of FIG. 2a.

[0093] For example, the compressor module (280) of FIG. 2B can decompress data (250) loaded from memory (240) via DMA read (235) based on a command (or request) from the processor (120). For example, the compressor module (280) of FIG. 2B can decompress data (211) transmitted through the processor (120) based on a command (or request) from the processor (120).

[0094] For example, the compressor module (280) of the electronic device (101) of FIG. 2c may be included as a component within the DMA controller (230), compared to the compressor module (280) of the electronic device (101) of FIG. 2b. According to an embodiment, the compressor module (280) of the electronic device (101) of FIG. 2c may include the compressor (281) of FIG. 2a and the decompressor (285) of FIG. 2a, and may be included as a component within the DMA controller (230).

[0095] For example, the compressor module (280) of FIG. 2c can decompress data (250) loaded from memory (240) via DMA read (235) based on a command (or request) from the processor (120). For example, the compressor module (280) of FIG. 2c can decompress data (211) transmitted via the processor (120) based on a command (or request) from the processor (120). In addition, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) can transmit or receive data in a twisted state by compressing or decompressing data through the compressor module, and accordingly, even if the data of the AI ​​model is stolen from the storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model through the stolen data.

[0096] FIG. 3 is a block diagram of an electronic device according to one embodiment. FIG. 3 may be described with reference to FIGS. 1 and 2A to 2C.

[0097] Comparing the electronic device (101) of FIG. 3 with the electronic device (101) of FIGS. 2A to 2C, the storage (260) can be divided into at least two areas (361, 365).

[0098] Among the two areas (361, 365), the first area (361) may be a protected area (or, SE (secure element)) accessible to applications running in a trusted execution environment (TEE). Among the two areas (361, 365), the second area (365) may be a general area accessible to applications running in a rich execution environment (REE). In one embodiment, the trusted execution environment may be an environment requiring higher security than the general execution environment.

[0099] In one embodiment, the data (370) stored in the first region (361) may include weights (371, 373, 375) for executing one or more functions related to the AI ​​model. In one embodiment, the data (370) stored in the first region (361) may correspond to the data (210). In one embodiment, the data (370) stored in the first region (361) may be uncompressed data.

[0100] In one embodiment, the data (270) stored in the second area (365) may include weights (271, 273, 275) for executing one or more functions related to the AI ​​model. In one embodiment, the data (270) stored in the second area (365) may be compressed data based on a specified compression algorithm.

[0101] Comparing the electronic device (101) of FIG. 3 with the electronic device (101) of FIGS. 2A to 2C, the electronic device (101) of FIG. 3 may further include a compressor module (330). In one embodiment, the compressor module (330) may include a compressor (331) and a decompressor (335). However, the present invention is not limited thereto. For example, the compressor module (330) of the electronic device (101) of FIG. 3, like the compressor module (280) of FIG. 2B, may perform the functions performed by the compressor (281) of FIG. 2A and the functions performed by the decompressor (285) of FIG. 2A through a single, non-separated hardware component (e.g., a single processing circuit).

[0102] In one embodiment, the compressor (331) can compress data based on the same designated compression algorithm as the compressor (281). In one embodiment, the decompressor (335) can decompress data based on the same designated decompression algorithm as the decompressor (285).

[0103] The structure of the compressor module (280) and the DMA controller (230) of FIG. 3 is illustrated as being the same as the structure of the compressor module (280) and the DMA controller (230) of FIG. 2a, but this is merely an example. Depending on the embodiment, the structure of the compressor module (280) and the DMA controller (230) of FIG. 3 may have one of the structures of the compressor module (280) and the DMA controller (230) of FIGS. 2a to 2c.

[0104] Hereinafter, with reference to FIG. 3, an operation of an electronic device (101) to protect data (250, 270, 370) related to an AI model can be described.

[0105] Hereinafter, a path through which data (270, 370) stored in storage (260) is transferred to the processor (120) may be described. In one embodiment, the processor (120) may include at least one core (221, 225). In one embodiment, at least one core (221, 225) may be understood as one of the main processor (121) or auxiliary processor (123) of FIG. 1. For example, at least one core (221, 225) may be one of a CPU (or AP), a GPU, or an NPU.

[0106] In one embodiment, the processor (120) may generate a command (or request) to load data associated with an AI model to execute one or more functions associated with the AI ​​model.

[0107] In one embodiment, the processor (120) may identify an area of ​​the storage (260) where data related to the AI ​​model is stored, based on a command (or request) for loading weights. However, the present invention is not limited thereto. In one embodiment, the processor (120) may identify whether data related to the AI ​​model stored in the storage (260) is compressed, based on a command (or request) for loading weights.

[0108] In one embodiment, the processor (120) may compress data (370) stored in the first area (361) of the storage (260) through the compressor (331) based on the fact that data related to the AI ​​model is stored in the first area (361) of the storage (260). However, the present invention is not limited thereto. In one embodiment, the processor (120) may compress data stored in the storage (260) through the compressor (331) based on the fact that data related to the AI ​​model is stored in the storage (260) in an uncompressed state.

[0109] In one embodiment, the processor (120) may bypass compression of data (270) stored in the second area (365) through the compressor (331) based on the fact that data related to the AI ​​model is stored in the second area (365) of the storage (260). For example, bypassing compression of data (270) stored in the second area (365) through the compressor (331) may include storing data (270) stored in the storage (260) in the memory (240) without compression.

[0110] In one embodiment, the processor (120) may generate a command (or request) for loading a weight related to an operation among the weights (251, 253, 255) included in the data (250) stored in the memory (240). In one embodiment, the DMA controller (230) may decompress the data (250) loaded from the memory (240) through the decompressor (285) based on the command (or request) for loading the weight related to the operation. In one embodiment, the DMA controller (230) may provide the decompressed data (210) through the decompressor (285) to the processor (120). In one embodiment, the processor (120) may perform an operation for executing one or more functions related to an AI model based on the decompressed data (210).

[0111] Below, the path through which data (210) obtained from the processor (120) is transferred to storage (260) can be described.

[0112] In one embodiment, the processor (120) may generate a command (or request) for storing data (210) related to an AI model into a memory (240). In one embodiment, the DMA controller (230) may obtain data (210) from the processor (120) through a communication bus with the processor (120) based on the command (or request) for storing data (210). In one embodiment, the DMA controller (230) may compress data (210) output from the processor (120) through a compressor (281). In one embodiment, the processor (120) may generate a command (or request) for storing compressed data (250) stored in the memory (240) into a storage (260).

[0113] In one embodiment, the processor (120) may identify an area of ​​the storage (260) in which the compressed data (250) is to be stored, based on a command (or request) for storing the compressed data (250). In one embodiment, the processor (120) may determine one area in which the compressed data (250) is stored, among the first area (361) or the second area (365), based on a command (or request) for storing the compressed data (250). However, the present invention is not limited thereto. In one embodiment, the processor (120) may identify whether decompression of data related to an AI model to be stored in the storage (260) is required, based on a command (or request) for storing the compressed data (250).

[0114] In one embodiment, the processor (120) may decompress the compressed data (250) through the decompressor (335) based on identifying that the compressed data (250) is stored in the first area (361) of the storage (260). However, the present invention is not limited thereto. For example, the processor (120) may determine whether to decompress the data (250) through the decompressor (335) regardless of whether the compressed data (250) is stored in the first area (361) of the storage (260). In one embodiment, the processor (120) may decompress the compressed data (250) through the decompressor (335) based on identifying that decompression of data related to an AI model to be stored in the storage (260) is required.

[0115] In one embodiment, the processor (120) may store the decompressed data (370) in a first area (361) of the storage (260).

[0116] In one embodiment, the processor (120) may bypass decompression of compressed data (250) via the decompressor (335) based on identifying that data associated with the AI ​​model is stored in the second area (365) of the storage (260). For example, bypassing decompression of compressed data (250) via the decompressor (335) may include storing data (250) stored in the memory (240) in the storage (260) (or the second area (365) of the storage (260)) without decompression.

[0117] As described above, the electronic device (101) can store the data of the AI ​​model in different areas (361, 365) of the storage (260). For example, when the data of the AI ​​model is stored in an area where the possibility of the data of the AI ​​model being stolen is low (e.g., the protected area (361) of the storage (260), the electronic device (101) can store the data of the AI ​​model in an uncompressed state, and when the data of the AI ​​model is stored in an area where the possibility of the data of the AI ​​model being stolen is relatively high (e.g., the general area (365) of the storage (260), the electronic device can store the data of the AI ​​model in a compressed state. In addition, the electronic device improves the data transmission and reception performance by compressing or decompressing the data through the compressor module. In addition, the electronic device (101) can transmit or receive the data in a twisted state by compressing or decompressing the data through the compressor module, and accordingly, even if the data of the AI ​​model is stolen from the storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0118] FIG. 4A is a block diagram of an electronic device according to an embodiment. FIG. 4B is a block diagram of an electronic device according to an embodiment. FIG. 4C is a block diagram of an electronic device according to an embodiment. FIG. 4D is a block diagram of an electronic device according to an embodiment.

[0119] FIGS. 4A to 4D can be described with reference to the electronic device (101) of FIGS. 1 to 3.

[0120] Referring to FIGS. 4A to 4D , compressor modules (411, 415) may be arranged within the electronic device (101) to correspond to each of the cores (221, 225) of the processor (120). Each of the compressor modules (411, 415) may correspond to the compressor module (280) of FIGS. 2A to 2C or FIG. 3 . For example, each of the compressor modules (411, 415) may include a compressor (281) and a decompressor (285).

[0121] In one embodiment, the compression algorithm and decompression algorithm applied to each of the compressor modules (411, 415) may be the same. However, this is not limited thereto. The compression algorithm (or decompression algorithm) applied to each of the compressor modules (411, 415) may be different.

[0122] The cores (221, 225) of the processor (120) of FIGS. 4A to 4D may be distinguished from a graphics processing unit (GPU), a neural network processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor. For example, the cores (221, 225) may be a CPU (or AP).

[0123] In one embodiment, referring to FIGS. 4A to 4C, the processor (120) may place compressor modules (411, 415) after a designated memory step to prevent (or prevent) data theft.

[0124] For example, referring to FIG. 4a, compressor modules (411, 415) may be placed in a path between the L1 caches (421, 425) and the cores (221, 225) to prevent (or prevent) theft of data stored in designated caches (e.g., L3 cache (440), L2 caches (431, 435), and L1 caches (421, 425). For example, referring to FIG. 4a, the compressor modules (411, 415) may be placed between the L1 caches (421, 425) and registers of each of the cores (221, 225). However, the present invention is not limited thereto. For example, referring to FIG. 4b, compressor modules (411, 415) may be placed in a path between L2 caches (431, 435) and L1 caches (421, 425) to prevent (or, prevent) theft of data stored in designated caches (e.g., L3 cache (440), L2 caches (431, 435), and L1 caches (421, 425)). For example, referring to FIGS. 4c and 4d, compressor modules (411, 415) may be placed in a path between L3 cache (440) and L2 caches (431, 435) to prevent (or, prevent) theft of data stored in designated caches (e.g., L3 cache (440), L2 caches (431, 435), and L1 caches (421, 425)). For example, referring to FIG. 4c, when the compressor modules (411, 415) are arranged in the path between the L3 cache (440) and the L2 caches (431, 435), the compressor modules (411, 415) may be integrally included in the processor (120). For example, referring to FIG. 4d, when the compressor modules (411, 415) are arranged in the path between the L3 cache (440) and the L2 caches (431, 435), the compressor modules (411, 415) may be included on a separate circuit that is distinct from the processor (120).

[0125] For example, the compressor module (411) may, in response to a read request from the core (221), decompress data related to an AI model stored in a compressed state. In one embodiment, the compressor module (411) may provide the decompressed data to the core (221).

[0126] For example, the compressor module (411) may compress data related to an AI model in a decompressed state in response to a write request from the core (221). In one embodiment, the compressor module (411) may provide the compressed data to the L1 cache (421).

[0127] According to an embodiment, the compressor modules (411, 415) may be implemented as software modules. When the compressor modules (411, 415) are implemented as software modules, the compressor modules (411, 415) may decompress compressed data related to the AI ​​model stored in the L1 caches (421, 425). For example, the compressor modules (411, 415) may input the decompressed data into registers of each of the cores (221, 225). However, the present invention is not limited thereto.

[0128] As described above, the electronic device (101) may not store data related to the AI ​​model in a decompressed state in the cache memory even when a read request is generated from any one of the cores (221, 225). In addition, the electronic device (101) may improve data transmission and reception performance (e.g., data throughput) by compressing or decompressing data through the compressor modules (411, 415). In addition, the electronic device (101) may transmit and receive data in a twisted state by compressing or decompressing data through the compressor modules (411, 415), and thus, even if the twisted data is stolen, it may have the effect of making it difficult for a malicious user to recover the original AI model.

[0129] FIG. 5 is a block diagram of a server and an electronic device according to one embodiment.

[0130] FIG. 5 can be described with reference to the electronic device (101) of FIGS. 1 to 3.

[0131] Referring to FIG. 5, the electronic device (102) may include a processor (520), a memory (530), a communication module (590), and a compressor module (531). In one embodiment, the processor (520) may correspond to the processor (120) of FIG. 1. In one embodiment, the memory (530) may correspond to the memory (240) of FIG. 1. In one embodiment, the communication module (590) may correspond to the communication module (190) of FIG. 1. In one embodiment, the compressor module (531) may correspond to the compressor module (280) of FIGS. 2A to 2C and FIG. 3. In one embodiment, the compressor module (531) may include a hardware structure for compressing data and a hardware structure for decompressing data, but is not limited thereto. The compressor module (531) may be implemented in software. For example, the compressor module (531) may be software that includes instructions for a function to compress data and a function to decompress data.

[0132] In one embodiment, the electronic device (102) may be a portable communication device (e.g., a smartphone) and / or a computer device (e.g., a laptop, a desktop). In one embodiment, the electronic device (102) may be a server (e.g., the server (108) of FIG. 1).

[0133] In one embodiment, the electronic device (102) may compress the weights of an original AI model (e.g., an AI model in which data related to the AI ​​model is not compressed) within the electronic device (102) (or in an offline state) using the compressor module (531), and provide an AI model including the compressed weights (or twisted weights) to the electronic device (101). Here, the compressed weights (or twisted weights) may have the same size as the uncompressed weights (or untwisted weights), but may be compressed so as not to restore the original AI model. For example, the compressor module (531) may compress the weights of the original AI model based on the same compression algorithm as the compressor module (280) of the electronic device (101). Here, the compression algorithm of the compressor module (280) may be different for each electronic device (101) (or for each processor (120)) (or for each SoC). Additionally, the compression algorithm of the compressor module (280) applied to the electronic device (101) may be a very high level of confidential information.

[0134] In one embodiment, the electronic device (102) may directly or indirectly transmit data (540) including weights (541, 543, 545) to the electronic device (101) via the communication module (590) to execute one or more functions related to the AI ​​model. In one embodiment, the electronic device (102) may directly transmit the compressed data from the data (540) to the electronic device (101) via the compressor module (531) via a communication path (e.g., over-the-air (OTA)) between the communication module (590) and the communication module (190). In one embodiment, the electronic device (102) may indirectly transmit the compressed data from the data (540) to the electronic device (101) via the compressor module (531) via another server. In one embodiment, the other server may be a server of an application store (e.g., Play Store™), but is not limited thereto.

[0135] In one embodiment, the electronic device (102) may obtain identification information of the electronic device (101). For example, the identification information of the electronic device (101) may include information about a compression algorithm applied to a compressor module (280) of the electronic device (101).

[0136] In one embodiment, the electronic device (102) may compress data (540) based on a designated compression algorithm identified based on identification information of the electronic device (101). For example, the electronic device (102) may directly or indirectly transmit the compressed data (540) to the electronic device (101) via the communication module (590).

[0137] In one embodiment, the electronic device (101) can store compressed data (540) obtained from the electronic device (102) as data (270) in the storage (260).

[0138] According to an embodiment, the electronic device (102) may transmit data for updating the AI ​​model to the electronic device (101) based on the update of the AI ​​model associated with the compressed data (540) transmitted to the electronic device (101). For example, the electronic device (102) may distribute update data of an application associated with the AI ​​model installed in the electronic device (101) through an application store (e.g., Play Store™). For example, the electronic device (102) may distribute update data for updating the AI ​​model to the electronic device (101) through OTA. In one embodiment, the update data may be data (or weights) compressed by the compressor module (531) of the server (108) based on a specified compression algorithm of the compressor module (280) of the electronic device (101).

[0139] As described above, when the electronic device (101) acquires data (or weights) related to the AI ​​model, it can acquire already compressed (or encrypted) data (or weights). Accordingly, the possibility of a malicious user stealing uncompressed data (or weights) related to the AI ​​model through the electronic device (101) can be reduced. In addition, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) can transmit or receive data in a twisted state by compressing or decompressing data through the compressor module. Accordingly, even if the data of the AI ​​model is stolen from storage and memory, it can be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0140] Figure 6 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0141] FIG. 6 can be described with reference to the electronic device (101) of FIGS. 1 to 3.

[0142] Referring to FIG. 6, at operation 610, the electronic device (101) may identify a load request. In one embodiment, the electronic device (101) may generate a command (or request) for loading (or reading) weights (271, 273, 275) to execute one or more functions associated with the AI ​​model.

[0143] In operation 620, the electronic device (101) may load the compressed weights into the memory (240). In one embodiment, the electronic device (101) may load the weights stored in the storage (260) into the memory (240) in a compressed state. In one embodiment, the electronic device (101) may load the weights stored in the storage (260) in a compressed state into the memory (240). However, the present invention is not limited thereto. In one embodiment, the electronic device (101) may compress the weights stored in the storage (260) through the compressor module (330) based on the fact that the weights stored in the storage (260) are in an uncompressed state.

[0144] In operation 630, the electronic device (101) may decompress the compressed weights loaded into the memory (240). The electronic device (101) may decompress the compressed weights through a compressor module (280) (e.g., compression / decompression IP). In one embodiment, the compression algorithm performed based on the compressor module (330) may be a counterpart algorithm of the decompression algorithm based on the compressor module (280).

[0145] In operation 640, the electronic device (101) may perform a calculation using the decompressed weights. In one embodiment, the electronic device (101) may perform a calculation to execute one or more functions related to the AI ​​model based on the decompressed weights. The one or more functions related to the AI ​​model may include a function for training the AI ​​model and / or a function for inferring input data based on the AI ​​model. However, the embodiment is not limited thereto. In this way, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) may transmit or receive data in a twisted state by compressing or decompressing data through the compressor module, and thus, even if the AI ​​model data is stolen from storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0146] Figure 7 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0147] FIG. 7 may be described with reference to the electronic device (101) of FIGS. 1 to 3. Operations 610 and 620 of FIG. 7 may correspond to operations 610 and 620 of FIG. 6, respectively.

[0148] Referring to FIG. 7, in operation 610, the electronic device (101) can identify a load request.

[0149] In operation 710, the electronic device (101) may determine whether compression of the weights is required. In one embodiment, the electronic device (101) may identify whether compression of the weights is required based on an area of ​​the storage (260) where weights associated with the AI ​​model are stored. In one embodiment, the electronic device (101) may identify whether compression of the weights is required based on whether the weights associated with the AI ​​model stored in the storage (260) are compressed.

[0150] In one embodiment, the electronic device (101) may identify that compression of the weights is required based on the fact that the area of ​​the storage (260) where the weights related to the AI ​​model are stored is the first area (361) (or the protected area) (or the secure element (SE)). In one embodiment, the electronic device (101) may identify that compression of the weights is not required based on the fact that the area of ​​the storage (260) where the weights related to the AI ​​model are stored is the second area (365) (or the general area).

[0151] In one embodiment, the electronic device (101) may identify that compression of the weights is required based on determining that the weights associated with the AI ​​model stored in the storage (260) are not compressed. In one embodiment, the electronic device (101) may identify that compression of the weights is not required based on determining that the weights associated with the AI ​​model stored in the storage (260) are compressed.

[0152] In operation 720, the electronic device (101) can compress the weights stored in the storage (260). The electronic device (101) can compress the weights stored in the storage (260) in an uncompressed state through the compressor module (330). The electronic device (101) can compress the weights stored in the first area (361) of the storage (260) through the compressor module (330).

[0153] In operation 620, the electronic device (101) can load the compressed weights into the memory (240). In this way, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. Furthermore, the electronic device (101) can transmit or receive data in a twisted state by compressing or decompressing data through the compressor module. Accordingly, even if the AI ​​model data is stolen from storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0154] Figure 8 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0155] FIG. 8 can be described with reference to the electronic device (101) of FIGS. 1 to 3.

[0156] Referring to FIG. 8, in operation 810, the electronic device (101) may identify a storage request. In one embodiment, the storage request may include a command (or request) for storing weights held by the processor (120) into the memory (240). In one embodiment, the storage request may include a command (or request) for the processor (120) to store weights stored in the memory (240) into the storage (260). For example, the storage request may include a command (or request) for the processor (120) to store weights included in data acquired from the electronic device (102) of FIG. 5 into the storage (260). For example, data obtained from the electronic device (102) may be compressed data within the electronic device (102) (or in an offline state) by using a compressor module (531) to compress the weights of the original AI model (e.g., an AI model in a state where data related to the AI ​​model is not compressed) in the electronic device (102).

[0157] In operation 820, the electronic device (101) may store the compressed weights stored in the memory (240) in the storage (260).

[0158] In one embodiment, the electronic device (101) may compress the weights held by the processor (120) through the compressor (281). In one embodiment, the electronic device (101) may store the compressed weights in a compressed state in the memory (240). However, the present invention is not limited thereto. The electronic device (101) may store the compressed weights stored in the memory (240) in an uncompressed state in the storage (260).

[0159] Referring to FIG. 8, in operation 830, the electronic device (101) may identify a load request. Operation 830 may correspond to operation 610 of FIG. 6.

[0160] In operation 840, the electronic device (101) may load the compressed weights into the memory (240). Operation 840 may correspond to operation 620 of FIG. 6.

[0161] In operation 850, the electronic device (101) may decompress the compressed weights loaded into the memory (240). Operation 850 may correspond to operation 630 of FIG. 6.

[0162] In operation 860, the electronic device (101) may perform a calculation using the decompressed weights. Operation 860 may correspond to operation 640 of FIG. 6. In addition, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) may transmit or receive data in a twisted state by compressing or decompressing data through the compressor module, and accordingly, even if the data of the AI ​​model is stolen from storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0163] FIG. 9 is a flowchart illustrating the operation of an electronic device according to one embodiment.

[0164] FIG. 9 may be described with reference to the electronic device (101) of FIGS. 1 to 3. Operation 810 of FIG. 9 may correspond to operation 810 of FIG. 8.

[0165] Referring to FIG. 9, in operation 810, the electronic device (101) may identify a storage request. Operation 810 may correspond to operation 810 of FIG. 8. For example, the storage request may include a command (or request) of the processor (120) to store weights stored in the memory (240) into the storage (260). For example, the storage request may include a command (or request) of the processor (120) to store weights included in data acquired from the electronic device (102) of FIG. 5 into the storage (260). For example, the data acquired from the electronic device (102) may be data compressed within the electronic device (102) (or in an offline state) by using the compressor module (531) to store weights of an original AI model (e.g., an AI model in a state where data related to the AI ​​model is not compressed).

[0166] In operation 910, the electronic device (101) may determine whether decompression of the weights is required. In one embodiment, the electronic device (101) may identify whether decompression of the weights is required based on an area of ​​the storage (260) where the weights associated with the AI ​​model are to be stored.

[0167] In one embodiment, the electronic device (101) may identify that decompression of the weights is required based on the fact that the area of ​​the storage (260) where the weights related to the AI ​​model are to be stored is the first area (361) (or protected area) (or secure element (SE)). In one embodiment, the electronic device (101) may identify that decompression of the weights is not required based on the fact that the area of ​​the storage (260) where the weights related to the AI ​​model are to be stored is the second area (365) (or general area).

[0168] In operation 920, the electronic device (101) can decompress the weights stored in the memory (240). The electronic device (101) can decompress the weights stored in a compressed state in the memory (240) through the decompressor (335).

[0169] In operation 930, the electronic device (101) may store the decompressed weights in a predefined area of ​​the storage (260). The electronic device (101) may store the decompressed weights in a first area (361) (or protected area) (or SE) of the storage (260).

[0170] In operation 940, the electronic device (101) may store the compressed weights in the storage (260). The electronic device (101) may store the weights stored in the memory (240) in a compressed state in the storage (260) (or, the second area (365) of the storage (260)) without decompression. In this way, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) may transmit or receive data in a twisted state by compressing or decompressing data through the compressor module, and accordingly, even if the data of the AI ​​model is stolen from the storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model using the stolen data.

[0171] FIG. 10 is a diagram illustrating an example of an artificial intelligence (AI) model driven by an electronic device according to one embodiment.

[0172] FIG. 10 illustrates an example of a model (1040) driven by an electronic device (101), according to one embodiment. The electronic device (101) of FIG. 10 may be an example of the electronic device (101) of FIG. 1. Referring to FIG. 10, the electronic device (101) of one embodiment may include at least one of a central processing unit (CPU) (1010), a neural processing unit (NPU) (1020), a graphic processing unit (GPU) (1030), or a memory (130). The CPU (1010), the NPU (1020), the GPU (1030), and the memory (130) may be electrically and / or operably coupled with each other by an electronic component, such as a communication bus (1005). The type and / or number of hardware components included in the electronic device (101) is not limited to those illustrated in FIG. 10. Hereinafter, the hardware components being operatively coupled may mean that a direct connection or an indirect connection between the hardware components is established, either wired or wireless, so that a second hardware component is controlled by a first hardware component among the hardware components.

[0173] Referring to FIG. 10, according to one embodiment, an electronic device (101) may include hardware components (e.g., a CPU (1010), an NPU (1020), a GPU (1030), and / or a memory (130)) for performing operations on a model (1040) related to an artificial neural network. The model (1040) and / or the artificial neural network may include a recognition model implemented in software or hardware that mimics the computational capabilities of a biological system by using a large number of artificial neurons (or nodes). For example, according to one embodiment, the electronic device (101) may execute functions similar to human cognitive actions or learning processes based on the model (1040). Based on calculations indicated by the model (1040) and performed in a chain by a plurality of parameters, the electronic device (101) may output data including generalized information about input data. The memory (130) of the electronic device (101) can store the plurality of parameters related to the model (1040). The CPU (1010), NPU (1020), and / or GPU (1030) of the electronic device (101) can include a circuit for performing the calculations that are performed serially by the plurality of parameters.

[0174] According to one embodiment, the CPU (1010) of the electronic device (101) may include hardware components for processing data based on one or more instructions. The hardware components for processing data may include, for example, an arithmetic and logic unit (ALU), a floating point unit (FPU), and / or a field programmable gate array (FPGA). In one embodiment, the CPU (1010) may be referred to as an application processor (AP). The number of CPUs (1010) may be one or more. For example, the CPU (1010) may have a multi-core processor structure such as a dual core, a quad core, or a hexa core. The CPU (1010) of FIG. 10 may be an example of the processor (120) and / or the main processor (121) of FIG. 1.

[0175] An NPU (1020) of an electronic device (101) according to one embodiment may include hardware components dedicated to computations related to a model (1040). For example, the NPU (1020) may include a plurality of circuits for performing computations (e.g., multiplication and / or addition) sequentially and / or in parallel based on the model (1040). The plurality of circuits included in the NPU (1020) may be referred to as neural engines. The NPU (1020) may perform the computations based on a designated data type (e.g., floating point number and / or integer) related to the model (1040).

[0176] According to one embodiment, the GPU (1030) of the electronic device (101) may include one or more pipelines that perform multiple operations for executing instructions related to computer graphics and / or parallel computing. For example, the pipeline of the GPU (1030) may include a graphics pipeline or a rendering pipeline for generating a three-dimensional image and generating a two-dimensional raster image from the generated three-dimensional image. By using the graphics pipelines, calculations related to artificial neural networks may be executed substantially simultaneously.

[0177] The CPU (1010), NPU (1020), and GPU (1030) of FIG. 10 may be included as different integrated circuits in the electronic device (101), or may be included in a single integrated circuit (IC) based on a system on chip (SoC). For example, the CPU (1010), the NPU (1020), the GPU (1030), or a combination thereof, may be included in a single integrated circuit included in the electronic device (101). The type of processing unit included based on the SoC is not limited to the above example, and for example, other hardware components (e.g., a communication processor) not shown in FIG. 10 may be included in a single integrated circuit together with the CPU (1010), the NPU (1020), and the GPU (1030). Hereinafter, in terms of the subject of the calculations of the artificial neural network directed by the model (1040), the CPU (1010), the NPU (1020), the GPU (1030), or a combination thereof may be referred to as an AI (artificial intelligence) accelerator (or accelerator). The AI ​​accelerator may be referred to as an accelerator.

[0178] A memory (130) of an electronic device (101) according to one embodiment may include a hardware component for storing data and / or instructions input and / or output to a CPU (1010), an NPU (1020), and / or a GPU (1030). The memory (130) may include, for example, a volatile memory (132) such as a random-access memory (RAM) and / or a non-volatile memory (134) such as a read-only memory (ROM). The volatile memory (132) may include, for example, at least one of a dynamic RAM (DRAM), a static RAM (SRAM), a cache RAM, and a pseudo SRAM (PSRAM). The non-volatile memory (134) may include, for example, at least one of a programmable ROM (PROM), an erasable ROM (EPROM), an electrically erasable ROM (EEPROM), a flash memory, a hard disk, a compact disk, and an embedded multi media card (eMMC). The memory (130), the volatile memory (132), and the non-volatile memory (134) of FIG. 10 may correspond to the memory (130), the volatile memory (132), and the non-volatile memory (134) of FIG. 1, respectively.

[0179] Within the memory (130), one or more instructions (or commands) indicating operations to be performed by the CPU (1010), the NPU (1020), and / or the GPU (1030) based on data may be stored. A set of one or more instructions may be referred to as firmware, an operating system, a process, a routine, a sub-routine, and / or an application. For example, the CPU (1010), the NPU (1020), and / or the GPU (1030) of the electronic device (101) may perform at least one of the operations of FIGS. 1 to 10 when a set of a plurality of instructions distributed in the form of an operating system, firmware, a driver, and / or an application is executed. Hereinafter, the fact that an application is installed in an electronic device (101) may mean that one or more instructions provided in the form of an application are stored in the memory (130) of the electronic device (101), and that the one or more applications are stored in a format (e.g., a file having an extension specified by an operating system of the electronic device (101)) that is executable by the CPU (1010), NPU (1020), and / or GPU (1030) of the electronic device (101). Pipeline init of FIG. 10 may be configured to be executed by the CPU (1010) of the electronic device (101) and to control the CPU (1010), NPU (1020), and / or GPU (1030).

[0180] In one embodiment, the electronic device (101) can identify a model (1040) based on one or more files stored in the non-volatile memory (134). The one or more files can be related to an application (e.g., an application (146) of FIG. 1), a middleware (e.g., a middleware (144) of FIG. 1), and / or an operating system (e.g., an operating system (142) of FIG. 1) installed in the electronic device (101). In one embodiment where a model (1040) related to an application is stored in the non-volatile memory (134), the CPU (1010) can identify the model (1040) stored in the non-volatile memory (134) based on execution of the application. Identifying a model (1040) stored in the non-volatile memory (134) may include copying (or loading) a plurality of parameters associated with the model (1040), stored in the non-volatile memory (134), into the volatile memory (132). Identifying a model (1040) stored in the non-volatile memory (134) may include obtaining a plurality of instructions for performing calculations indicated by the model (1040), based on the plurality of parameters stored in the volatile memory (132). Accelerators, such as the CPU (1010), the NPU (1020), and / or the GPU (1030), may execute one or more functions associated with the model (1040) indicated by the plurality of parameters stored in the volatile memory (132), based on the plurality of instructions. The one or more functions may include at least one of a function for performing training of a model (1040), a function for performing inference on input data based on the model (1040), a function for performing image-based object recognition, voice recognition, and / or handwriting recognition using the trained model (1040), and a function personalized to a user of the electronic device (101) based on a neural network.However, the examples are not limited thereto.

[0181] According to one embodiment, the electronic device (101) may perform calculations directed by the model (1040) based on a plurality of parameters associated with the model (1040). The plurality of parameters may include weights assigned to a plurality of nodes and / or connections between the plurality of nodes indicated by the model (1040). The plurality of parameters may include hyperparameters related to the model (1040). The hyperparameters may include, for example, at least one of a learning rate, a cost function, a regularization parameter, a mini-batch size, a number of training iterations, a number of hidden layers, a metaparameter, or a free parameter.

[0182] According to one embodiment, the electronic device (101) may perform calculations related to input data based on an artificial intelligence model (1040) using an accelerator. The electronic device (101) may obtain output data from input data input to the artificial intelligence model (1040) based on performing chained (or serial or consecutive) calculations based on a plurality of parameters of the artificial intelligence model (1040). The input data may include a plurality of numeric values ​​that are preprocessed to be input to the artificial intelligence model (1040). The plurality of numeric values ​​may indicate a vector to be input to the artificial intelligence model (1040). The electronic device (101) may obtain at least one numeric value indicating output data by changing the plurality of numeric values ​​included in the input data based on a plurality of parameters and calculations indicated by the artificial intelligence model (1040). The above calculations and / or the plurality of parameters related to the artificial intelligence model (1040) may be distinguished by operation, graph, and / or layer.

[0183] Referring to FIG. 10, an exemplary order of operations (1045-1, 1045-2, 1045-3, 1045-4) included in an artificial intelligence model (1040) is illustrated. The operations (1045-1, 1045-2, 1045-3, 1045-4) may be referred to as sub-models included in the artificial intelligence model (1040). The CPU (1010) of the electronic device (101) may, depending on the size of input data, select the artificial intelligence model (1040) and / or the sub-model from among models corresponding to different sizes and load them to the NPU (1020) and / or the GPU (1030).

[0184] Each of the operations (1045-1, 1045-2, 1045-3, 1045-4) may include a group of calculations that the electronic device (101) sequentially performs based on the operation of the artificial intelligence model (1040). The operations (1045-1, 1045-2, 1045-3, 1045-4) may be distinguished by the type of calculation performed by the electronic device (101). Referring to FIG. 10, the electronic device (101) may sequentially perform calculations on input data based on the order of the operations (1045-1, 1045-2, 1045-3, 1045-4) within the artificial intelligence model (1040). For example, operation (1045-1) may instruct one or more convolution calculations based on a convolution filter associated with the artificial intelligence model (1040). Operation (1045-2) performed after operation (1045-1) may instruct one or more depthwise convolution calculations associated with the artificial intelligence model (1040) on the input data modified by operation (1045-1). Operation (1045-3) performed after operation (1045-2) may instruct mean pooling calculations associated with the artificial intelligence model (1040) on the input data modified by operations (1045-1, 1045-2). Operation (1045-4) performed after operation (1045-3) may instruct convolution calculations related to the artificial intelligence model (1040) on input data changed by operations (1045-1, 1045-2, 1045-3).

[0185] In one embodiment, numerical values ​​included in input data input to the artificial intelligence model (1040) may be changed based on connections between a plurality of nodes included in the artificial intelligence model (1040). The plurality of nodes may be divided into units of layers. In one embodiment, where the plurality of parameters include weights connecting two nodes of different layers of the artificial intelligence model (1040), the electronic device (101) may apply weights to values ​​corresponding to nodes of a specific layer to obtain values ​​corresponding to nodes of another layer connected to the specific layer. Within the artificial intelligence model (1040), a layer including nodes into which values ​​included in the input data are input may be referred to as an input layer. The last layer among the sequentially connected layers within the artificial intelligence model (1040) may be referred to as an output layer. Each of the operations (1045-1, 1045-2, 1045-3, and 1045-4) of FIG. 10 may include at least one of the layers included in the artificial intelligence model (1040). For example, operation (1045-1) may indicate a group of interconnected layers based on a convolution filter among the layers within the artificial intelligence model (1040). Hereinafter, a graph may mean a graph formed by connections between nodes included in the layers. The graph included in the artificial intelligence model (1040) may be distinguished by operations (1045-1, 1045-2, 1045-3, 1045-4) included in the artificial intelligence model (1040).

[0186] As described above, the electronic device (101) may include a compressor (331) configured to compress data based on a compression algorithm, a decompressor (285) configured to decompress data based on a decompression algorithm corresponding to the compression algorithm, at least one processor (120), a non-volatile memory storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store weights associated with an artificial intelligence (AI) model in the non-volatile memory. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress, through the compressor (331), some of the weights related to the designated operation among the weights stored in the non-volatile memory based on a load request for the designated operation, and load them into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress, through the decompressor (285), some of the weights loaded in the compressed state into the first volatile memory and load them into the second volatile memory. The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to perform the specified operation based on the some weights loaded in the decompressed state into the second volatile memory.

[0187] As described above, the non-volatile memory, the first volatile memory, and the second volatile memory may be implemented through at least one processing circuit. For example, at least one of the non-volatile memory, the first volatile memory, and the second volatile memory may be included in a single SoC (system on a chip) (or integrated circuitry). However, the present invention is not limited thereto. The non-volatile memory, the first volatile memory, and the second volatile memory may be included in separate (or physically distinct) integrated circuits, respectively.

[0188] The compression algorithm may include an algorithm that changes the order of at least a portion of the data or encrypts the data while substantially maintaining the size of the data. The decompression algorithm may include an algorithm that changes the order of at least a portion of the data or decrypts the data while substantially maintaining the size of the data.

[0189] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to change the order of or encrypt at least a portion of the data of the some weights as at least part of an operation of compressing via the compressor (331). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to change the order of or decrypt at least a portion of the data of the some weights as at least part of an operation of decompressing via the decompressor (285).

[0190] The at least one processor (120) may include a neural processing unit (NPU). The NPU may include the second volatile memory.

[0191] The above decompressor may be included in at least one processor (120).

[0192] The at least one processor may include a central processing unit (CPU), a neural processing unit (NPU), and a graphic processing unit (GPU). The instructions, when executed by the CPU, may cause the electronic device (101) to store the weights in the non-volatile memory (260), compress some of the weights and load them into the first volatile memory, and decompress some of the weights and load them into the second volatile memory. The instructions, when executed by the NPU or the GPU, may cause the electronic device (101) to perform the specified operation based on the some of the weights loaded into the second volatile memory in the decompressed state.

[0193] The electronic device (101) may include a communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to obtain the AI ​​model including the weights from the server (108) via the communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the obtained AI model in the non-volatile memory (260).

[0194] The non-volatile memory may include a general area and a protected area. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to determine, based on the load request for the specified operation, one area of ​​the general area or the protected area in which the partial weights are stored.

[0195] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress some of the weights by the compressor (331) and load them into the first volatile memory, if the some of the weights are stored in the general area. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to bypass the compressor (331) and load the some of the weights by the compressor (331) so that the some of the weights are not compressed by the compressor (331), if the some of the weights are stored in the protected area.

[0196] As described above, the electronic device (101) may include a communication circuit (190), a compressor (331) configured to compress data based on a compression algorithm, a decompressor (285) configured to decompress data based on a decompression algorithm corresponding to the compression algorithm, at least one processor (120), a non-volatile memory storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to obtain an artificial intelligence (AI) model including weights from a server (108) via the communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress the weights included in the AI ​​model through the compressor (331) and store them in the non-volatile memory (260) based on a storage request for the weights. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some weights related to the designated operation among the weights in the compressed state stored in the non-volatile memory (260) in the compressed state into the first volatile memory. The above instructions, when executed individually or collectively by the at least one processor (120), may cause the electronic device (101) to decompress the weights loaded in the compressed state into the first volatile memory through the decompressor (285) and load them into the second volatile memory.The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to perform the specified operation based on the some weights loaded in the decompressed state into the second volatile memory.

[0197] The compression algorithm may include an algorithm that changes the order of at least a portion of the data or encrypts the data while substantially maintaining the size of the data. The decompression algorithm may include an algorithm that changes the order of at least a portion of the data or decrypts the data while substantially maintaining the size of the data.

[0198] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to change the order of or encrypt at least a portion of the data of the weights as at least part of an operation of compressing via the compressor (331). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to change the order of or decrypt at least a portion of the data of the weights as at least part of an operation of decompressing via the decompressor (285).

[0199] The at least one processor (120) may include a neural processing unit (NPU). The NPU may include the second volatile memory.

[0200] The above decompressor may be included in at least one processor (120).

[0201] The at least one processor may include a central processing unit (CPU), a neural processing unit (NPU), and a graphic processing unit (GPU). The instructions, when executed by the CPU, may cause the electronic device (101) to obtain the AI ​​model, compress the weights and store them in the non-volatile memory (260), load some of the weights into the first volatile memory, and decompress the some of the weights and load them into the second volatile memory. The instructions, when executed by the NPU or the GPU, may cause the electronic device (101) to perform the specified operation based on the some of the weights loaded into the second volatile memory in the decompressed state.

[0202] The non-volatile memory may include a general area and a protected area. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to determine, based on the load request for the specified operation, one area of ​​the general area or the protected area in which the partial weights are stored.

[0203] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress some of the weights by the compressor (331) and load them into the first volatile memory, if the some of the weights are stored in the general area. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to bypass the compressor (331) and load the some of the weights by the compressor (331) so that the some of the weights are not compressed by the compressor (331), if the some of the weights are stored in the protected area.

[0204] As described above, the electronic device (101) may include a communication circuit (190), a decompressor (285) configured to decompress data based on a decompression algorithm, at least one processor (120), a non-volatile memory storing instructions, a first volatile memory, and a second volatile memory. The instructions may be loaded into the first volatile memory. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to obtain an AI (artificial intelligence) model including weights in a compressed state from a server (108) through the communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the weights in the compressed state in the non-volatile memory (260) based on a storage request for the weights. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some of the weights related to the designated operation among the weights in the compressed state into the first volatile memory in the compressed state. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress the some of the weights loaded in the compressed state into the first volatile memory through the decompressor (285) and load them into the second volatile memory.The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to perform the specified operation based on the some weights loaded in the decompressed state into the second volatile memory.

[0205] As described above, the method performed in the electronic device (101) may include an operation of storing weights related to an artificial intelligence (AI) model in a non-volatile memory. The method may include an operation of compressing some of the weights related to the specified operation among the weights stored in the non-volatile memory through a compressor (331) and loading the compressed weights into a first volatile memory based on a load request for a specified operation. The method may include an operation of decompressing some of the weights loaded in the compressed state into the first volatile memory through a decompressor (285) and loading the compressed weights into a second volatile memory. The method may include an operation of performing the specified operation based on some of the weights loaded in the decompressed state into the second volatile memory.

[0206] As described above, a non-transitory computer-readable recording medium can store a program including instructions. The instructions, when individually or collectively executed by at least one processor (120) of the electronic device (101), can cause the electronic device (101) to store weights associated with an artificial intelligence (AI) model in a non-volatile memory. The instructions, when individually or collectively executed by at least one processor (120) of the electronic device (101), can cause the electronic device (101) to compress, through a compressor (331), some weights associated with a designated operation among the weights stored in the non-volatile memory based on a load request for a designated operation and load the compressed weights into a first volatile memory. The instructions, when individually or collectively executed by at least one processor (120) of the electronic device (101), may cause the electronic device (101) to decompress the some weights loaded in the compressed state into the first volatile memory through the decompressor (285) and load them into the second volatile memory. The instructions, when individually or collectively executed by at least one processor (120) of the electronic device (101), may cause the electronic device (101) to perform the specified operation based on the some weights loaded in the decompressed state into the second volatile memory.

[0207] As described above, the electronic device (101) may include a DMA (direct memory access) controller (230) including a compressor (331) that compresses data based on a compression algorithm, a decompressor (285) that decompresses data based on a decompression algorithm corresponding to the compression algorithm, at least one processor (120) including a processing circuit, a storage (260) that stores weights associated with an artificial intelligence (AI) model, and a memory (240) located external to the at least one processor (120) and that temporarily stores instructions when used by the at least one processor (120). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to identify an area on the storage (260) in which some of the weights associated with the designated operation among the weights are stored, based on a load request for the designated operation. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some of the weights into the memory (240) by bypassing the compressor (331) based on the fact that the weights are stored in a general area on the storage (260). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some of the weights into the memory (240) in a compressed state through the compressor (331) based on the fact that the weights are stored in a protected area on the storage (260).The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress the portion of weights loaded into the memory (240) through the decompressor (285). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to perform the specified operation based on the portion of weights decompressed through the processor (120).

[0208] The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to read some of the weights loaded into the memory (240) through the DMA controller (230) in response to a read request of the at least one processor (120). The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress the read some of the weights through the decompressor (285).

[0209] The electronic device (101) may include a communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to obtain the AI ​​model including the weights from the server (108) via the communication circuit (190). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the obtained AI model including the weights in the storage (260).

[0210] The weights of the AI ​​model obtained from the server (108) through the communication circuit (190) and before being stored in the storage (260) can be compressed by the compression algorithm.

[0211] The DMA controller (230) and the at least one processor (120) may be included in a single integrated circuit. The at least one processor (120) may be an application processor (120). The decompressor (285) of the DMA controller (230) may be configured to decompress some of the weights stored in the L1 cache (421, 425) of the at least one processor (120) and then input the decompressed weights into a register of the at least one processor (120). The DMA controller (230) and the at least one processor (120) may be included in different integrated circuits. The DMA controller (230) and the at least one processor (120) may be connected to each other so as to be communicatively connected via a bus. The at least one processor (120) may be a graphics processing unit and / or a neural network processing unit.

[0212] The above compression algorithm may be a lossless compression algorithm.

[0213] The DMA controller (230) may include another compressor (281) that compresses data based on the compression algorithm. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress other weights through the other compressor (281) based on a storage request for other weights stored in the processor (120). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the compressed other weights in the memory (240). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the compressed other weights stored in the memory (240) in the storage (260).

[0214] The instructions may include another decompressor (335) that decompresses data based on the decompression algorithm. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to identify an area on the storage (260) where other weights are stored based on a storage request for other weights stored in the memory (240). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to bypass the other decompressor (335) and store the other weights in the storage (260) based on the other weights being stored in a general area on the storage (260). The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the other weights in a decompressed state through the other decompressor (335) in the storage (260) based on the other weights being stored in a protected area on the storage (260).

[0215] As described above, the method may be performed in the electronic device (101). The method may include an operation of identifying an area on the storage (260) in which some of the weights related to the specified operation among the weights related to the AI ​​(artificial intelligence) model are stored, based on a load request for a specified operation. The method may include an operation of loading some of the weights into the memory (240) by bypassing the compressor (331) based on the fact that the some of the weights are stored in the general area on the storage (260). The method may include an operation of loading some of the weights into the memory (240) in a compressed state through the compressor (331) based on the fact that the some of the weights are stored in the protected area on the storage (260). The method may include an operation of decompressing some of the weights loaded into the memory (240) through a decompressor (285) of a direct memory access (DMA) controller (230). The above method may include an operation of performing the specified operation based on some of the decompressed weights through the processor (120).

[0216] The method may include an operation of reading some of the weights loaded into the memory (240) through the DMA controller (230) in response to a read request from the processor (120). The method may include an operation of decompressing the read some of the weights through the decompressor (285).

[0217] The method may include an operation of obtaining the AI ​​model including the weights from the server (108) via a communication circuit (190). The method may include an operation of storing the obtained AI model including the weights in the storage (260).

[0218] The weights of the AI ​​model obtained from the server (108) through the communication circuit (190) and before being stored in the storage (260) can be compressed by the compression algorithm.

[0219] The method may include an operation of compressing other weights through another compressor (281) based on a storage request for other weights stored in the processor (120). The method may include an operation of storing the compressed other weights in the memory (240). The method may include an operation of storing the compressed other weights stored in the memory (240) in the storage (260).

[0220] The method may include an operation of identifying an area on the storage (260) where other weights are stored based on a storage request for other weights stored in the memory (240). The method may include an operation of storing the other weights in the storage (260) by bypassing the other decompressor (335) based on the other weights being stored in a general area on the storage (260). The method may include an operation of storing the other weights in the storage (260) in a decompressed state through the other decompressor (335) based on the other weights being stored in a protected area on the storage (260).

[0221] As described above, a non-transitory computer-readable recording medium may store a program including instructions. The instructions, when individually or collectively executed by at least one processor (120) of the electronic device (101), may cause the electronic device (101) to identify an area on the storage (260) where some of the weights related to the designated operation among the weights are stored, based on a load request for the designated operation. The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some of the weights into the memory (240) by bypassing the compressor (331), based on the some of the weights being stored in a general area on the storage (260). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to load some of the weights into the memory (240) in a compressed state through the compressor (331), based on the weights being stored in a protected area on the storage (260). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress the weights loaded into the memory (240) through the decompressor (285) of the direct memory access (DMA) controller (230). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to perform the specified operation based on the decompressed weights through the processor (120).

[0222] The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to read some of the weights loaded into the memory (240) through the DMA controller (230) in response to a read request of the processor (120). The above instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to decompress the read some of the weights through the decompressor (285).

[0223] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to compress other weights, through another compressor (281), based on a storage request for other weights stored in the processor (120). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the compressed other weights in the memory (240). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to store the compressed other weights stored in the memory (240) in the storage (260).

[0224] The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to identify an area on the storage (260) where other weights are stored based on a storage request for other weights stored in the memory (240). The instructions, when individually or collectively executed by the at least one processor (120), may cause the electronic device (101) to bypass another decompressor (335) and store the other weights in the storage (260) based on the other weights being stored in a general area on the storage (260). The above instructions, when executed individually or collectively by the at least one processor (120), may cause the electronic device (101) to store the other weights in a decompressed state through the other decompressor (335) in the storage (260) based on the other weights being stored in the protected area on the storage (260). In this way, the electronic device improves data transmission and reception performance by compressing or decompressing data through the compressor module. In addition, the electronic device (101) may transmit or receive data in a twisted state by compressing or decompressing data through the compressor module (411, 415), and thus, even if the data of the AI ​​model is stolen from the storage and memory, it may be difficult for a malicious user to reconstruct the AI ​​model through the stolen data.

[0225] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.

[0226] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another component (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0227] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0228] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0229] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., a compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0230] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (101), A compressor (331) that compresses data based on a compression algorithm; A decompressor (285) that decompresses data based on a decompression algorithm corresponding to the above compression algorithm; At least one processor (120); Non-volatile memory that stores instructions, First volatile memory, and Contains a second volatile memory, The instructions are loaded into the first volatile memory, and when the instructions are individually or collectively executed by the at least one processor (120), the electronic device (101) Store the weights related to the AI ​​(artificial intelligence) model in the non-volatile memory, Based on a load request for a specified operation, some of the weights related to the specified operation among the weights stored in the non-volatile memory are compressed through the compressor (331) and loaded into the first volatile memory, and some of the weights correspond to some of the weights. Some of the weights loaded in the compressed state into the first volatile memory are decompressed through the decompressor (285) and loaded into the second volatile memory, Causing the specified operation to be performed based on the some weights loaded in the decompressed state into the second volatile memory. Electronic devices.

2. In claim 1, The compression algorithm includes an algorithm that changes the order of or encrypts at least a portion of the data while maintaining the size of the data, The above decompression algorithm includes an algorithm that changes or decrypts the order of at least a part of the data to its original order while maintaining the size of the data. Electronic devices.

3. In any one of the preceding claims, The above instructions, when individually or collectively executed by the at least one processor (120), cause the electronic device (101) to: As at least part of the operation of compressing through the above compressor (331), changing the order of or encrypting some of the weights, As at least part of the operation of decompressing through the above decompressor (285), causing the order of the above some weights to be changed back to the original or decoded, Electronic devices.

4. In any one of the preceding claims, The above at least one processor (120) includes a neural processing unit (NPU), The above NPU includes the second volatile memory, Electronic devices.

5. In any one of the preceding claims, The above decompressor is included in at least one processor (120). Electronic devices.

6. In any one of the preceding claims, The at least one processor includes a central processing unit (CPU), a neural processing unit (NPU), and a graphic processing unit (GPU), The above instructions, when executed by the CPU, cause the electronic device (101) to: Store the above weights in the non-volatile memory (260), Compressing some of the above weights and loading them into the first volatile memory, and Causing some of the above weights to be decompressed and loaded into the second volatile memory, The above instructions, when executed by the NPU or the GPU, cause the electronic device (101) to: Causing the specified operation to be performed based on the some weights loaded into the second volatile memory in the decompressed state. Electronic devices.

7. In any one of the preceding claims, Includes a communication circuit (190), The above instructions, when individually or collectively executed by the at least one processor (120), cause the electronic device (101) to: Through the above communication circuit (190), the AI ​​model including the weights is obtained from the server (108), Causing the acquired AI model to be stored in the non-volatile memory (260), Electronic devices.

8. In any one of the preceding claims, The above non-volatile memory includes a general area and a protected area, The above instructions, when individually or collectively executed by the at least one processor (120), cause the electronic device (101) to: Based on the load request for the above-mentioned operation, one area among the general area or the protected area is determined in which the weights are stored, If some of the above weights are stored in the general area, the above weights are compressed through the compressor (331) and loaded into the first volatile memory, If some of the above weights are stored in the protection area, causing the above weights to be loaded into the first volatile memory by bypassing the compressor (331) so as not to be compressed through the compressor (331). Electronic devices.

9. In an electronic device (101), Communication circuit (190); A compressor (331) that compresses data based on a compression algorithm; A decompressor (285) that decompresses data based on a decompression algorithm corresponding to the above compression algorithm; At least one processor (120); Non-volatile memory that stores instructions, First volatile memory, and Contains a second volatile memory, The instructions are loaded into the first volatile memory, and when the instructions are individually or collectively executed by the at least one processor (120), the electronic device (101) Through the above communication circuit (190), an AI (artificial intelligence) model including weights is obtained from the server (108), Based on the storage request for the above weights, the weights included in the AI ​​model are compressed through the compressor (331) and stored in the non-volatile memory (260). Loading some of the weights related to a specified operation among the weights in a compressed state stored in the non-volatile memory (260) into the first volatile memory in a compressed state, and the some of the weights correspond to some of the weights, Some of the weights loaded in the compressed state into the first volatile memory are decompressed through the decompressor (285) and loaded into the second volatile memory, Causing the specified operation to be performed based on the some weights loaded in the decompressed state into the second volatile memory. Electronic devices.

10. In claim 9, The compression algorithm includes an algorithm that changes the order of or encrypts at least a portion of the data while maintaining the size of the data, The above decompression algorithm includes an algorithm that changes or decrypts the order of at least a part of the data to its original order while maintaining the size of the data. Electronic devices.

11. In any one of claims 9 to 10, The above instructions, when individually or collectively executed by the at least one processor (120), cause the electronic device (101) to: As at least part of the operation of compressing through the above compressor (331), changing the order of at least part of the data of the above weights or encrypting them, As at least a part of the operation of decompressing through the decompressor (285), causing the order of at least a part of the data of the some weights to be changed back to the original or decoded, Electronic devices.

12. In any one of claims 9 to 11, The above at least one processor (120) includes a neural processing unit (NPU), The above NPU includes the second volatile memory, Electronic devices.

13. In any one of claims 9 to 12, The above decompressor is included in at least one processor (120). Electronic devices.

14. In any one of claims 9 to 13, The at least one processor includes a central processing unit (CPU), a neural processing unit (NPU), and a graphic processing unit (GPU), The above instructions, when executed by the CPU, cause the electronic device (101) to: Obtain the above AI model, The above weights are compressed and stored in the non-volatile memory (260), Loading some of the above weights into the first volatile memory, and Causing some of the above weights to be decompressed and loaded into the second volatile memory, The above instructions, when executed by the NPU or the GPU, cause the electronic device (101) to: Causing the specified operation to be performed based on the some weights loaded into the second volatile memory in the decompressed state. Electronic devices.

15. In any one of claims 9 to 14, The above non-volatile memory includes a general area and a protected area, The above instructions, when individually or collectively executed by the at least one processor (120), cause the electronic device (101) to: Based on the load request for the above-mentioned operation, one area among the general area or the protected area is determined in which the weights are stored, If some of the above weights are stored in the general area, the above weights are compressed through the compressor (331) and loaded into the first volatile memory, If some of the above weights are stored in the protection area, causing the above weights to be loaded into the first volatile memory by bypassing the compressor (331) so as not to be compressed through the compressor (331). Electronic devices.

Citation Information

Patent Citations

  • AI model processing method, AI model operation method and AI model processing device

    CN116050469A

  • Neural network accelerator system for image super-resolution and implementation method thereof

    CN116468088A

  • Deep learning accelerator with variable data encoder / decoder

    KR102383962B1

  • Operation accelerator and compression method

    US20210216483A1

  • Semiconductor device

    US20240054083A1