Model assurance system, integrated model assurance system, model assurance method, and program

WO2026196471A1PCT designated stage Publication Date: 2026-09-24NT T INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/010677
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2026-09-24

Smart Images

  • Figure JP2025010677_24092026_PF_FP_ABST
    Figure JP2025010677_24092026_PF_FP_ABST
Patent Text Reader

Abstract

A report generation device of a model assurance system according to the present invention is configured as a TEE environment. The report generation device generates parameters in response to the input of a flag, generates a primitive trained model through machine learning in response to the input of the parameters as well as primitive training data, primitive hyperparameters, and a primitive algorithm used for learning together with the parameters, and generates a primitive report, a primitive signature, and a primitive key in response to the input of the primitive trained model, the primitive training data, the primitive hyperparameters, and the primitive algorithm, the primitive report being an attestation report including information concerning each of an execution environment of the report generation device, the parameters, the flag, the primitive training data, the primitive hyperparameters, the primitive algorithm, and the primitive trained model, the primitive signature assuring the authenticity of the primitive report, and the primitive key being used for accessing the primitive report. A verification device of the model assurance system verifies at least the primitive trained model or the content of the primitive report.
Need to check novelty before this filing date? Find Prior Art

Description

Model assurance system, integrated model assurance system, model assurance method, and program

[0001] This disclosure relates to AI (Artificial Intelligence) update assurance technology.

[0002] It is anticipated that we will enter a world where AI itself is bought, sold, and updated between companies. In such a world, ensuring the transparency of AI will require proving which data and models an AI was generated from, while maintaining the confidentiality of each piece of information. Traditionally, the provenance of AI has been guaranteed using zero-knowledge proof techniques, which prove that a certain operation was performed without revealing confidential information (see, for example, Non-Patent Document 1).

[0003] Sanjam Garg et al., “Experimenting with Zero-Knowledge Proofs of Training”, CCS2023

[0004] However, conventional technologies, such as the one described in Non-Patent Document 1 above, have the problem of slow proof generation speed.

[0005] Therefore, this disclosure aims to provide a technology that enables the execution of AI provenance assurance, while concealing data and model information, at a faster rate than zero-knowledge proofs in terms of computation and proof generation.

[0006] To solve the above problems, a model assurance system according to one aspect of this disclosure includes a report generator and a verification device. The report generator is configured as a TEE (Trusted Execution Environment) environment and generates parameters upon input of a predetermined signal, which is a flag. It generates a primitively trained model by machine learning upon input of the parameters and primitive training data, primitive hyperparameters, and primitive algorithm used for training together with the parameters. It generates a primitive report, which is an attestation report containing information about the execution environment of the report generator, parameters, flags, primitive training data, primitive hyperparameters, primitive algorithm, and primitively trained model, respectively, upon input of the primitively trained model, primitive training data, primitive hyperparameters, and primitive algorithm. It also generates a primitive signature that guarantees the authenticity of the primitive report and a primitive key for accessing the primitive report. The verification device verifies at least the primitively trained model or the contents of the primitive report.

[0007] According to the model assurance system disclosed herein, AI provenance assurance can be performed while concealing data and model information, and the computation and proof generation are faster than zero-knowledge proofs.

[0008] Figure 1 is a diagram showing an example of the functional configuration of a model assurance system according to the first embodiment. Figure 2 is a sequence diagram illustrating an example of a processing procedure performed in the model assurance system according to the first embodiment. Figure 3 is a diagram showing an example of the functional configuration of a model assurance system according to the second embodiment. Figure 4 is a sequence diagram illustrating an example of a processing procedure performed in the model assurance system according to the second embodiment. Figure 5 is a sequence diagram illustrating an example of a processing procedure performed in the model assurance system according to the second embodiment. Figure 6 is a diagram showing an example of the functional configuration of a model assurance system according to the third embodiment. Figure 7 is a sequence diagram illustrating an example of a processing procedure performed in the model assurance system according to the third embodiment. Figure 8 is a diagram showing an example of the functional configuration of an integrated model assurance system. Figure 9 is a diagram illustrating the functional configuration of a computer.

[0009] The embodiments of this disclosure will be described in detail below with reference to the figures. Furthermore, components having the same function will be given the same number, and redundant explanations will be omitted. Note that the term "third-party device," which appears multiple times in the following description, may refer to the same device, different devices, or some of multiple third-party devices may overlap. Also, the term "training data" in this disclosure is not limited to a single training data set, but also includes so-called datasets consisting of multiple training data sets.

[0010] [First Embodiment] The model assurance system of the first embodiment does not require external input of a machine learning model, but generates a trained model using data and a program (algorithm) as input. Instead of providing random initial parameters from an external source, the report generation device in the TEE environment is equipped with an initial parameter generation device, and the generation of an attestation report proves that it is the original model.

[0011] Figure 1 shows an example of the functional configuration of a model assurance system according to the first embodiment. The model assurance system 100A includes a report generation device 1, a verification device 3A, and a management device 4. The report generation device 1, the verification device 3A, and the management device 4 are connected via a network such as the Internet.

[0012] The report generation device 1 is configured as a TEE environment, which is an environment in which data tampering from external sources is restricted. The report generation device 1 has a parameter generation unit 11, a learning unit 12, and a report generation unit 13. The parameter generation unit 11 generates the initial parameter P upon input of a predetermined signal (for example, a flag F described later). The learning unit 12 receives the parameter P and the original learning data D. 0 , primitive hyperparameter H 0 , and primitive algorithm A 0 Based on the input, a primitive model M is trained using machine learning. 0 The report generation unit 13 generates the primitive trained model M. 0 And the pre-trained model is the original training data D. 0 And, the primitive hyperparameter H 0 And, primitive algorithm A0 and the input of the flag F, the execution environment of the report generation device 1, the parameter P, the flag F, the original learning data D 0 , the original hyperparameter H 0 , the original algorithm A 0 , and the original trained model M 0 which is an attestation report including information on each of the above, the original report R 0 and the original report R 0 the original signature σ that guarantees the authenticity of 0 and the original report R 0 the original key k for accessing 0 to generate the above. Note that TEE can be implemented with reference to, for example, the technology of Non-Patent Document 2 shown below.

[0013] (Non-Patent Document 2) AMD SEV-SNP," Strengthening VM Isolation with Integrity Protection and More", January,2020. <URL:https: / / www.amd.com / system / files / TechDocs / SEV-SNP-strengthening-vm-isolation-withintegrity-protection-and-more.pdf>

[0014] In a TEE environment, external data falsification is restricted, and data processing in plaintext is enabled. TEE is a technology that allows a verifier to verify whether there is falsification in TEE configuration information (CPU chip identifiers, boot firmware OVMF for virtual machines, initialized RAM disk initrd, kernel image file kernel-image, kernel command line kernel-cmdline, etc.) by using an attestation report signed by a hardware module that is a root of trust. However, the TEE disclosed in Non-Patent Document 2 does not have a mechanism for verifying the provenance of AI nor a mechanism for writing information related to AI into an attestation report, as will be described later.

[0015] The verification device 3A includes at least the original trained model M 0, or original report R 0 The contents will be verified. This verification will involve at least one of the following processes (1) to (4). However, for more accurate verification, it is preferable to perform all of (1) to (4). (1) Check whether the provided model (trained model) matches the model listed in the output of the attestation report by comparing hash values ​​or binaries. For example, raw report R 0 The primitively trained model M described within 0 The hash value (referred to here as "H(M')") and the original trained model M received by the verification device 3A. 0 The hash value (here, "H(M 0 )」」. The question is whether ) are equal, that is, (H(M')) == H(M 0 (2) Verify that flag F is 1. This verifies that it is the original model and that no model existed before it. (3) Verify the issued attestation report. Verification is performed using the original key k 0 Verify whether it is the correct TEE enclave key. (4) The original signature σ attached to the issued attestation report 0 , primitive key k 0 Use this to verify whether it has been tampered with. Verification can be done, for example, by Verify(R). 0 , σ 0 ,k 0 ) == Do it with 1.

[0016] Control device 4 generates the original report R 0 , primitive signature σ 0 , primitive key k 0 In addition, Report R, which will be discussed later. i , signature σ i , primitive key k iThe management device 4 manages the process by replacing each transaction with an attestation report, enabling the verification device 3A to verify the chain sequentially. A single model may branch into multiple paths depending on associated information such as training data and hyperparameters. The management device 4 can manage these branches according to their configuration. These aspects of the management device 4 are also true for the second embodiment.

[0017] The following describes the processing procedures performed in the model assurance system 100A. Figure 2 is a sequence diagram illustrating an example of the processing procedures performed in the model assurance system according to the first embodiment.

[0018] In step S101, a flag F, which is a predetermined signal indicating a command to generate a flag, is input to the parameter generation unit 11 of the report generation device 1 from a third-party device (not shown). Note that this flag F is not limited to input from a third-party device. For example, primitive algorithm A, which will be described later. 0 The system may be configured to generate flag F when input is received, or when parameter P (described later) is generated. Information about flag F is also transmitted to the report generation unit 13.

[0019] In step S102, the parameter generation unit 11 of the report generation device 1 generates parameter P based on the input of the flag F described above. The parameter generation unit 11 transmits parameter P to the learning unit 12 (step S103).

[0020] In step S104, the raw training data D used for learning is received from a third-party device (not shown) along with the flag F. 0 , primitive hyperparameter H 0 Primitive algorithm A 0 This data is then input to the learning unit 12 and the report generation unit 13.

[0021] In step S105, the learning unit 12 of the report generation device 1 processes the parameter P and the original learning data D 0 And, the primitive hyperparameter H 0 And, primitive algorithm A 0Using this, a primitively trained model M is created through machine learning. 0 The learning unit 12 generates the primitive trained model M. 0 This is sent to the report generation unit 13 (step S106).

[0022] In step S107, the report generation unit 13 of the report generation device 1 generates the original trained model M 0 And, the original training data D 0 And, the primitive hyperparameter H 0 And, primitive algorithm A 0 Based on the input of flag F, the execution environment of report generation device 1, parameter P, flag F, and primitive training data D are determined. 0 , primitive hyperparameter H 0 Primitive algorithm A 0 , and the primitively trained model M 0 The original report R is an attestation report containing information about each of them. 0 And, Primitive Report R 0 Original signature σ guaranteeing authenticity 0 And, Primitive Report R 0 Primitive key k to access 0 The report generation unit 13 generates the primitive trained model M. 0 , Primitive Report R 0 , primitive signature σ 0 , and primitive key k 0 The original report R is sent to the verification device 3A (step S108). 0 To ensure confidentiality, at least the original training data D 0 , primitive hyperparameter H 0 Primitive algorithm A 0 , and the primitively trained model M 0 Regarding this, it is generated using a method that can guarantee confidentiality, such as a hash value. Also, when the management device 4 manages the information, the report generation unit 13 generates the original report R 0 , primitive signature σ 0 , primitive key k 0 This information is also sent to the management device 4.

[0023] In step S109, the verification device 3A performs at least one of the processes (1) to (4) described above, thereby obtaining the original signature σ as necessary. 0 and primitive key k 0 Using this, at least a primitively trained model M 0 , or original report R 0 Verify the contents.

[0024] By using the model assurance system 100A of this disclosure, the report generation device 1 has a TEE, and processing within the model assurance system 100 is possible in plain text. Therefore, the execution of AI provenance assurance can be performed and proof generation is faster than zero-knowledge proof.

[0025] [Second Embodiment] Unlike the third embodiment described later, the model assurance system of the second embodiment is configured such that the verification device performs the model's provenance verification. Therefore, the attestation report generated by the report generation device does not include provenance information, and the verification device performs the model's provenance verification using the management device.

[0026] Figure 3 shows an example of the functional configuration of a model assurance system according to the second embodiment. The model assurance system 100B includes a report generation device 2, a verification device 3B, and a management device 4. The report generation device 2, the verification device 3B, and the management device 4 are connected via a network such as the Internet.

[0027] The report generation device 2 is configured as a TEE environment, which is an environment in which data tampering from external sources is restricted. The report generation device 2 has a learning unit 22 and a report generation unit 23.

[0028] The learning unit 22 is a trained model M, which is a trained model generated by the previous machine learning (the last machine learning performed before the input). i-1 (Hereafter also referred to as the "previous generation trained model") and the trained model M i-1 This is used as the training model, and the trained model M i-1 Training data D used for learning i , hyperparameter H i , and algorithm Ai and generates a trained model M by machine learning based on the input i .

[0029] The report generation unit 23 receives inputs of the trained model M i-1 , training data D i , hyperparameter H i , algorithm A i , and the trained model M i , and generates: report R which is an attestation report including information about each of the execution environment of the report generation device 2, the trained model M i-1 , training data D i , hyperparameter H i , algorithm A i , and the trained model M i ; signature σ that guarantees the authenticity of the report R i ; and key k for accessing the report R i i ; and key k for accessing the report R i i .

[0030] The verification device 3B comprises a provenance verification device 34B and a report generation unit 33B.

[0031] The provenance verification device 34B, as necessary, uses the signature σ i and key k i to execute a first process of verifying the content of at least the trained model M i or the report R i . Based on information of a learning model M included in the report R i the provenance verification device 34B obtains, from a predetermined device such as the management device 4, for example: a report R that is an attestation report corresponding to the learning model M i-1 based on information of the learning model M i-1 that is an attestation report corresponding to the learning model M (hereinafter also referred to as a "previous-generation report"), a signature σ that guarantees the authenticity of the report R i-1 (hereinafter also referred to as a "previous-generation signature"), and a key k for accessing the report R i-1 that guarantees the authenticity of the report R (hereinafter also referred to as a "previous-generation key"), and as necessary, uses the signature σ i-1 (hereinafter also referred to as a "previous-generation signature"), and a key k for accessing the report R i-1 for accessing the report R i-1 (hereinafter also referred to as a "previous-generation key"), which is obtained from a predetermined device such as the management device 4, and as necessary, the signature σ i-1 and the key k​​i-1 Using at least a trained model M i-1 , or Report R i-1 The second process is executed to verify the contents of the history verification device 34B. i-1 The target is the learning model M i-1 The trained model M is a trained model generated by machine learning immediately prior to this. i-2 The third process is performed by replacing the model with the model trained two generations ago (hereinafter also referred to as the "model trained two generations ago") and performing the second process, and the third process is repeated until there are no more items to be processed by the third process.

[0032] The report generation unit 33B performs a process separate from the first to third processes performed by the provenance verification device 34B, which generates the original report R 0 Report R i After it is generated, the original report R 0 Report R i Verify the contents.

[0033] The provenance verification unit 34B and the report verification unit 33B perform at least one of the following processes (1) to (4). However, to perform more accurate verification, it is preferable to perform all of (1) to (4). (1) Compare the hash value or binary to see if the passed model matches the model described in the output of the attestation report. (2) Verify whether flag F is 1. This verifies that it is the original model and that no model existed before it. (3) Verify the issued attestation report. Verification is performed using the original key k 0 or key k i Verify whether it is the correct TEE enclave key. (4) Signature (original signature σ) attached to the issued attestation report. 0 , signature σ i ), verification key (original key k 0 , key k i ) is used to verify whether it has been tampered with. Verification is performed using Verify(R). 0 , σ 0 ,k 0 ) == 1, or Verify(R i , σ i ,ki ) == Do it with 1.

[0034] The following describes the processing procedures performed in the model assurance system 100B. Figures 4 and 5 are sequence diagrams illustrating an example of the processing procedures performed in the model assurance system according to the second embodiment.

[0035] In step S201, the trained model M i-1 and the trained model M i-1 This is used as the training model, and the trained model M i-1 Training data D used for learning i , hyperparameter H i , and algorithm A i This information is input to the learning unit 22 and the report generation unit 23 from a third-party device (not shown).

[0036] In step S202, the learning unit 22 learns the learned model M i-1 And, training data D i , hyperparameter H i , and algorithm A i A pre-trained model M is used with machine learning. i The learning unit 22 generates the trained model M. i The report is sent to the report generation unit 23 (step S203).

[0037] In step S204, the report generation unit 23 generates the trained model M i-1 And, training data D i And, hyperparameter H i Algorithm A i and the trained model M i Based on this input, the execution environment of the report generation device 2 and the trained model M are generated. i-1 And, training data D i And, hyperparameter H i Algorithm A i and the trained model M i Report R contains information on each of them. i And, Report R i Signature guaranteeing authenticity σ i And, Report R i Key k to accessi The report generation unit 23 generates the trained model M. i And, Report R i And, signature σ i And, key k i The results are sent to the verification device 3B and the management device 4 (step S205). i To ensure confidentiality, at least the trained model M i-1 And, training data D i And, hyperparameter H i Algorithm A i and the trained model M i For example, it is generated using a method that can guarantee certain characteristics, such as hash values.

[0038] In step S206, the report verification unit 33B of the verification device 3B signs σ as necessary. i and key k i Using the trained model M, i , or Report R i Verify the contents.

[0039] Step S206 performs at least one of the following processes (1) to (4). However, to perform more accurate verification, it is preferable to perform all of (1) to (4). (1) Trained model M i-1 Report R i (1) Verify that it matches the model described in (2). Verification is performed by comparing hash values ​​or binaries. (2) Verify that flag F is 1. This verifies that it is the original model and that no model existed before it. (3) Original report R i The primitive key k i Verify whether it is the correct key for the TEE enclave. (4) Original report R i Original signature σ associated with i , primitive key k i We use this to verify whether it has been tampered with. That is, verify(R) i ,σ i ,k i ) = = Verify 1.

[0040] The history verification unit 34B of the verification device 3B, separately from the report verification unit 33B, performs the following on the history of the trained model: 0 We will trace back and verify this.

[0041] Control device 4 generates the original report R 0 , primitive signature σ 0 , primitive key k 0 Port R i , signature σ i , and key k i And manages. For example, if n is an integer greater than or equal to 1, and i is 1, 2, 3, ..., n, then there are n model assurance systems 100B. To identify each model assurance system 100B, i is used as an index. For example, as shown in Figure 8 later, model assurance system 100B when i is 1 1 This is the original trained model M generated by the model assurance system 100A. 0 The model is used for training, and if i is 2 or greater, the model guarantee system 100B i This is the Model Guarantee System 100B i-1 The trained model M generated by i-1 Let's assume that this was used as the training model. As a result, the model-guaranteed system 100B n This is the trained model M n Let's assume that the following has been generated. The following description of the second embodiment will refer to the trained model M. n Starting from there, the primitive trained model M 0 Let's explain using the example of verifying up to this point. The history verification unit 34B of the verification device 3B verifies the learned model M, which is the last model to be learned. n The verification process is repeated in the reverse order of the generation sequence.

[0042] In step S301 (Figure 5), the provenance verification unit 34B of the verification device 3B performs the learned model M n The information is sent to the management device 4, and report R n Request to send the report R. Management device 4 will send the report R in response to the request. n And the signature σ associated with it n and key k n The data is sent to the verification device 3B (step S302).

[0043] In step S303, the provenance verification unit 34B signs σ as necessary. n and key k n Using the trained model M, n , or Report R n Verify the contents. For example, Verify(R n , σ n ,k n ) == 1, verify and the verification result Z n Generates.

[0044] In step S304, the provenance verification unit 34B of the verification device 3B displays the report R n The pre-trained model M included n-1 The information is sent to the management device 4, and report R n-1 Request to send the report R. Management device 4 will send the report R in response to the request. n-1 And the signature σ associated with it n-1 and key k n-1 The data is transmitted to the verification device 3B (step S305).

[0045] In step S306, the provenance verification unit 34B signs σ as necessary. n-1 and key k n-1 Using this, at least a trained model M n-1 , or Report R n-1 Verify the contents. Verification can be done, for example, by using Verify(σ n-1 , R n-1 ,k n-1 ) == 1, verify and the verification result Z n-1 Generates.

[0046] From now on, at least the primitively trained model M 0 , or original report R 0 Steps S304 to S306 are repeated until the contents of are verified. That is, the history verification device 34B verifies the learned model M i-1 The target is the trained model M i-1 The trained model M is a trained model generated by machine learning immediately prior to this. i-2(Hereinafter also referred to as the "two-generation-old trained model") is replaced, and the same process as in steps S304 to S306 above is repeated to train the trained model M i-2 The process described in steps S304 to S306 above is repeated until there are no more items to process, and finally the verification result Z 0 Generates.

[0047] That is, in step S401, the provenance verification unit 34B of the verification device 3B receives report R 1 The pre-trained model M included 0 The information is transmitted to the management device 4, and the original report R 0 Request to send the original report R. The control device 4 will send the original report R in response to the request. 0 And the signature σ associated with it 0 and key k 0 The data is transmitted to the verification device 3B (step S402).

[0048] In step S403, the provenance verification unit 34B signs σ as necessary. 0 and key k 0 Using this, the primitively trained model M 0 , or original report R 0 Verify the contents. Verification can be done, for example, by using Verify(σ 0 , R 0 ,k 0 ) == 1, verify and the verification result Z 0 Generates.

[0049] Verification Result Z 0 This includes the results of the history verification unit 34B's verification of whether flag F is 1. This allows us to verify that it is the original model and that no models existed before it.

[0050] By using the model assurance system 100B of this disclosure, the report generation device 2 has a TEE, and processing within the model assurance system 100B is possible in plain text. Therefore, the execution of AI provenance assurance can be performed and proof generation is faster than zero-knowledge proof.

[0051] [Third Embodiment] The model assurance system 100C of the third embodiment performs model provenance verification within the TEE and includes provenance information in the attestation report. Therefore, a separate management device is not required, and the verification device can verify the model provenance information simultaneously by verifying the attestation report once.

[0052] Figure 6 shows an example of the functional configuration of a model assurance system according to the third embodiment. The model assurance system 100C includes a report generation device 5 and a verification device 3C. The report generation device 5 and the verification device 3C are connected via a network such as the Internet.

[0053] The report generation device 5 is configured as a TEE environment, which is an environment in which data tampering from external sources is restricted. The report generation device 5 has a learning unit 52, a report generation unit 53, and a verification unit 54.

[0054] The learning unit 52 is a trained model M, which is a trained model generated by the previous machine learning operation. j-1 (Hereafter also referred to as the "previous generation trained model") and the trained model M j-1 This is used as the training model, and the trained model M j-1 Training data D used for learning j , hyperparameter H j , and algorithm A j With this input, the machine learning-trained model M j Generates.

[0055] The verification unit 54 is Report R, which is an attestation report corresponding to the previous generation trained model. j-1 (Hereafter also referred to as the "Previous Generation Report") and Report R j-1 Signature guaranteeing authenticity σ j-1 (Hereafter also referred to as "the previous generation signature") and Report R j-1 Key k to access j-1 (Hereafter also referred to as the "previous generation key") and, using this, Report R j-1 Verification Result Z is the result of verifying the contents. j-1 (Hereafter referred to as "the previous generation verification result") is generated.

[0056] The report generation unit 53 generates the trained model M j and the trained model M j-1 And, training data D j And, hyperparameter H j and algorithm A j Verification result Z j-1 Using the trained model M j Report R is the corresponding attestation report. j And, Report R j Signature guaranteeing authenticity σ j And, Report R j Key k to access j And, it generates.

[0057] Verification device 3C uses the trained model M j And, Report R j And, if necessary, sign σ j and key k j Using this, at least a trained model M j , or trained model M j Corresponding Report R j The contents were verified, and the verification result Z j Generates.

[0058] The following describes the processing procedures performed in the model assurance system 100C. Figure 7 is a sequence diagram illustrating an example of the processing procedures performed in the model assurance system according to the third embodiment.

[0059] In step S501, the trained model M j-1 and the trained model M j-1 This is used as the training model, and the trained model M j-1 Training data D used for learning j , hyperparameter H j , and algorithm A j This information is input to the learning unit 52 and the report generation unit 53 from a third-party device (not shown).

[0060] In step S502, the learning unit 52 learns the learned model M j-1 And, training data D j , hyperparameter H j, and algorithm A j A pre-trained model M is used with machine learning. j The learning unit 52 generates the trained model M. j The report is sent to the report generation unit 53 (step S503).

[0061] In step S504, Report R j-1 And, signature σ j-1 And, key k j-1 This information is input to the verification unit 54 from a third-party device (not shown).

[0062] In step S505, the verification unit 54 of the report generation device 5 signs σ as necessary. j-1 And, key k j-1 Using at least a trained model M j-1 , or Report R j-1 The contents were verified, and the verification result Z j-1 The following is generated. Verification is performed in the same way as in step S206 of the second embodiment, when i is replaced with j. Verification unit 54 generates verification result Z j-1 The report is sent to the report generation unit 53 (step S506).

[0063] In step S507, the report generation unit 53 generates the trained model M j-1 And, training data D j And, hyperparameter H j Algorithm A j and the trained model M j Verification result Z j-1 Using the execution environment of the report generation device 5 and the trained model M, j-1 And, training data D j And, hyperparameter H j Algorithm A j and the trained model M j Report R is an attestation report containing information about each of them. j And, Report R j Signature guaranteeing authenticity σ j And, Report R j Key k to access j The report generation unit 53 generates the trained model M. j Report Rj , signature σ j , and key k j This is sent to the verification device 3C (step S508). Note that report R j To ensure confidentiality, at least the trained model M j-1 And, training data D j And, hyperparameter H j Algorithm A j and the trained model M j For example, it is generated using a method that can guarantee certain characteristics, such as hash values.

[0064] In step S509, the verification device 3C signs σ as necessary. j and key k j Using the trained model M, j , or Report R j The contents of this will be verified. The verification will be performed in the same way as when i is replaced with j in step S206 of the second embodiment.

[0065] By using the model assurance system 100C of this disclosure, the report generation device 5 has a TEE (Technical Element), and processing within the model assurance system 100C is possible in plain text. In addition, the report generation device 5 has a verification unit 54 that verifies the provenance history. Therefore, the provenance assurance of AI can be performed and proof generated at a faster rate than zero-knowledge proof.

[0066] [Integrated Model Assurance System] Figure 8 is a diagram showing an example of the functional configuration of the integrated model assurance system. The integrated model assurance system 1000 shown in Figure 8 is configured using the first to third embodiments described above.

[0067] If there are n model assurance systems 100B consisting of n integers n and i such that n is an integer greater than or equal to 1, and i is 1, 2, 3, ..., n, then the subscript i is used to identify these models assurance systems 100B. i (Hereafter referred to as the "i-th model assurance system.") The integrated model assurance system 1000 consists of a model assurance system 100A and n model assurance systems 100B. i It has a part that is composed of the following.

[0068] If i is 1, Model Guarantee System 100B 1 This is the original trained model M generated by the model assurance system 100A. 0 This is used as the training model. If i is 2 or greater, the model guarantee system 100B is used. i This is the Model Guarantee System 100B i-1 The trained model M generated by i This will be used as the training model.

[0069] If there are m model assurance systems 100C consisting of m integers m, j is 1, 2, 3, ..., m, then the subscript j is used to identify these model assurance systems 100C. j (Hereafter referred to as the "j-th model assurance system.") The integrated model assurance system 1000 consists of a model assurance system 100A and m model assurance systems 100C j It has a part that is composed of the following.

[0070] If j is 1, Model Guarantee System 100C 1 This is the original trained model M generated by the model assurance system 100A. 0 This is used as the training model. If j is 2 or greater, the model guarantee system 100C is used. i This is the Model Guarantee System 100C j-1 The trained model M generated by j This will be used as the training model.

[0071] In the integrated model assurance system 1000 of this disclosure, model assurance systems 100A, 100B, and 100C all have TEEs, and processing in plain text is possible within the report generation device 1, update proof device 2, and report generation device 5 of each system. Furthermore, each system verifies the provenance history. Therefore, the provenance assurance of AI can be performed and proof generated at a faster rate than zero-knowledge proof.

[0072] The model assurance system and integrated model assurance system disclosed herein have a TEE environment, enabling proof and verification while keeping models, parameters, and data confidential. Furthermore, by using attestation reports generated by the TEE to prove the update process of AI models, low-cost and high-speed update proof is possible without incurring unnecessary proof costs. By having the attestation reports managed by a management device or management department, it is possible not only to guarantee a single AI update but also to prove and verify its history (update history).

[0073] The first to third embodiments of the model assurance system and the integrated model assurance system have been described above. The model assurance system and integrated model assurance system of this disclosure allow a third party to verify how and where an AI model was created. Furthermore, by writing the input model, data, hyperparameters, algorithms, etc., into an attestation report, anyone can reproduce the creation of that model. In other words, a reproducible AI model can be realized. In addition, if a model malfunctions, the chain of verification provided in this disclosure can be used to track which model performed the learning that caused the malfunction.

[0074] Furthermore, the device (terminal) may also be used for using the device, system, or method of disclosure via a network (telecommunication line). The "device (terminal) for use" may be equipped with functions necessary to obtain the effects of implementing the device, system, or method of disclosure (for example, control functions, decoding functions, restoration functions, input / output functions, etc.).

[0075] [Processors, Programs, Recording Media] The functions realized by the components described herein may be implemented in a circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to realize the functions described herein. A processor includes transistors and other circuits and is considered a circuitry or processing circuitry. A processor may be a programmed processor that executes a program stored in memory.

[0076] In this specification, circuitry, unit, and means are hardware programmed to perform or execute the functions described herein. Such hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein.

[0077] If the hardware is a processor that is considered to be a type of circuitry, then the circuitry, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.

[0078] The various processes described above can be carried out by loading a program that executes each step of the above method into the recording unit 2020 of the computer 2000 shown in Figure 9, and then causing the control unit 2010, input unit 2030, output unit 2040, display unit 2050, etc. to operate.

[0079] The program describing this process can be recorded on a computer-readable recording medium. Any computer-readable recording medium can be used, such as a magnetic recording device, optical disc, magneto-optical recording medium, or semiconductor memory.

[0080] A program describing this process may be included in a computer program product.

[0081] Furthermore, this program may be distributed, for example, by selling, transferring, or lending portable recording media such as DVDs or CD-ROMs on which the program is recorded. Alternatively, the program may be stored in the storage device of a server computer and distributed by transferring the program from the server computer to other computers via a network.

[0082] A computer executing such a program may, for example, first store the program recorded on a portable storage medium or a program transferred from a server computer in its own storage device. Then, when processing is to be executed, the computer reads the program stored on its own storage medium and executes the processing according to the read program. Alternatively, the computer may directly read the program from the portable storage medium and execute the processing according to that program, or it may sequentially execute the processing according to the received program each time a program is transferred to it from a server computer. Furthermore, the processing may be executed using a so-called ASP (Application Service Provider) type service, where the processing function is realized only by issuing execution instructions and obtaining results, without transferring the program from the server computer to this computer.In addition, the processing may be executed using a so-called SaaS (Software as a Service) type service, where a part of the server computer is made available to the user along with the program. Furthermore, the term "program" in this form includes information used for processing by an electronic computer that is equivalent to a program (data, etc., that is not a direct instruction to the computer but has the property of defining the processing of the computer).

[0083] Furthermore, in this configuration, the device is configured by executing a predetermined program on a computer, but at least a part of these processes may be implemented in hardware.

Claims

1. A model assurance system comprising a report generation device and a verification device, wherein the report generation device is configured as a TEE (Trusted Execution Environment), generates parameters upon input of a flag which is a predetermined signal, generates a primitively trained model by machine learning upon input of the parameters and primitive training data, primitive hyperparameters, and primitive algorithm which are used for training together with the parameters, generates a primitive report which is an attestation report containing information about the execution environment of the report generation device, the parameters, the flag, the primitive training data, the primitive hyperparameters, the primitive algorithm, and the primitively trained model, respectively, generates a primitive signature which guarantees the authenticity of the primitive report, and a primitive key which accesses the primitive report, and the verification device which verifies at least the primitively trained model or the contents of the primitive report.

2. A model assurance system including a report generation device and a verification device, wherein the report generation device is configured as a TEE (Trusted Execution Environment) environment and generates a trained model by machine learning by inputting a previous-generation trained model which is a trained model generated by the most recent machine learning, and training data, hyperparameters, and algorithms used to train the previous-generation trained model, which are used as the training model; generates an attestation report which is a report containing information about the execution environment of the report generation device, the previous-generation trained model, the training data, the hyperparameters, the algorithm, and the trained model, respectively, a signature that guarantees the authenticity of the attestation report, and a key for accessing the attestation report, wherein the verification device executes a first process that verifies at least the contents of the trained model or the attestation report. A model assurance system that, based on the information of the previous-generation trained model contained in the attestation report, obtains from a predetermined device a previous-generation report which is the attestation report corresponding to the previous-generation trained model, a previous-generation signature which is a signature guaranteeing the authenticity of the previous-generation report, and a previous-generation key which is a key for accessing the previous-generation report, and performs a second process which verifies at least the contents of the previous-generation trained model or the previous-generation report; performs a third process which replaces the target of the previous-generation trained model in the second process with a second-generation trained model which is a trained model generated by machine learning immediately preceding the previous-generation trained model, and performs the second process, and repeats the third process until there are no more targets for the third process.

3. A model assurance system including a report generation device and a verification device, wherein the report generation device is configured as a TEE (Trusted Execution Environment) environment, generates a trained model by machine learning using the input of a previous-generation trained model which is a trained model generated by the most recent machine learning, and training data, hyperparameters, and algorithms used to train the previous-generation trained model, with the previous-generation trained model as the training model, and generates a previous-generation verification result which is a verification result of verifying the contents of at least the previous-generation trained model or the previous-generation report which is an attestation report corresponding to the previous-generation trained model, generates an attestation report corresponding to the trained model, a signature guaranteeing the authenticity of the attestation report, and a key for accessing the attestation report using the trained model, the previous-generation trained model, the training data, the hyperparameters, the algorithm, and the previous-generation verification result, and the verification device verifies at least the contents of the trained model or the attestation report corresponding to the trained model.

4. Let j be 1, 2, 3, ..., m, and the model assurance system according to claim 3 consisting of m units be referred to as the j-th model assurance system, and an integrated model assurance system comprising the model assurance system according to claim 1 and at least one of the j-th model assurance systems, wherein when j is 1, the j-th model assurance system uses a trained model generated by the model assurance system as a training model, and when j is 2 or more, the j-th model assurance system uses a trained model generated by the j-1th model assurance system as a training model.

5. A model assurance method performed by a model assurance system including a report generation device configured as a TEE (Trusted Execution Environment) environment and a model verification device, wherein the report generation device generates parameters upon input of a flag which is a predetermined signal; generates a primitively trained model by machine learning upon input of the parameters and primitive training data, primitive hyperparameters, and primitive algorithm used for training together with the parameters; generates a primitive report which is an attestation report containing information about the execution environment of the report generation device, the parameters, the flag, the primitive training data, the primitive hyperparameters, the primitive algorithm, and the primitively trained model, respectively, upon input of the primitively trained model, the primitive training data, the primitive hyperparameters, and the primitive algorithm; generates a primitive signature which guarantees the authenticity of the primitive report; and generates a primitive key which accesses the primitive report; and the verification device which verifies at least the primitively trained model or the contents of the primitive report.

6. A model assurance method performed by a model assurance system including a report generation device and a verification device configured as a TEE (Trusted Execution Environment), wherein the report generation device generates a trained model by machine learning based on inputs of a previous-generation trained model which is a trained model generated by the most recent machine learning, and training data, hyperparameters, and an algorithm used to train the previous-generation trained model, which is used as the training model; generates an attestation report which is a report containing information about the execution environment of the report generation device, the previous-generation trained model, the training data, the hyperparameters, the algorithm, and the trained model, respectively, a signature that guarantees the authenticity of the attestation report, and a key for accessing the attestation report, and the verification device executes a first process that verifies at least the contents of the trained model or the attestation report. A model assurance method comprising: obtaining from a predetermined device a previous generation report which is the attestation report corresponding to the previous generation trained model, a previous generation signature which is the signature guaranteeing the authenticity of the previous generation report, and a previous generation key which is the key for accessing the previous generation report, based on the information of the previous generation trained model contained in the attestation report, and performing a second process in which the contents of at least the previous generation trained model or the previous generation report are verified; performing a third process in which the target of the previous generation trained model in the second process is replaced with a second generation trained model which is a trained model generated by machine learning immediately preceding the previous generation trained model, and performing the second process again, and repeating the third process until there are no more targets for the third process.

7. A model assurance method performed by a model assurance system including a report generation device and a verification device configured as a TEE (Trusted Execution Environment), wherein the report generation device generates a trained model by machine learning using a previous-generation trained model, which is a trained model generated by the most recent machine learning, and the previous-generation trained model as a training model, with training data, hyperparameters, and an algorithm used for training the previous-generation trained model as input; generates a previous-generation verification result, which is a verification result of verifying the contents of at least the previous-generation trained model or the previous-generation report, which is an attestation report corresponding to the previous-generation trained model; generates an attestation report corresponding to the trained model, a signature guaranteeing the authenticity of the attestation report, and a key for accessing the attestation report using the trained model, the previous-generation trained model, the training data, the hyperparameters, the algorithm, and the previous-generation verification result; and the verification device verifies the contents of at least the trained model or the attestation report corresponding to the trained model. Model warranty method.

8. A program for causing a computer to operate the model assurance system described in any one of claims 1 to 3.