System, method, and computer program for monitoring use of a machine learning model
Patent Information
- Application Number
- PCT/EP2026/058689
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2026-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure EP2026058689_01102026_PF_FP_ABST
Abstract
Description
[0001] System, Method, and Computer Program for Monitoring Use of a Machine Learning Model
[0002] Field
[0003] The present disclosure relates to a system, a method, a computer program and a computer-readable medium comprising program code for monitoring use of a machine learning model.
[0004] Background
[0005] Model extraction attacks, like the CopyCat Attack, are a type of adversarial attack where the adversary attempts to replicate a target machine learning (ML) model by querying it and using its predictions to train a surrogate model. The surrogate model aims to approximate the behavior of the target model closely. Typically, the attacker has no direct access to the model’s weights and architecture; that is they only have access to the model's input-output behavior. For example, the attacker typically has API (Application Programming Interface) access to obtain predictions for given inputs. The attacker’s strategy is thus to generate a dataset to query the target model. The attacker sends the input data to the target model and collects the corresponding outputs (predictions, probabilities, or logits). Using the collected input-output pairs, the attacker trains their surrogate model. The surrogate model can have an architecture similar to the architecture of the target or a simpler one, depending on the attacker's goals and resources.
[0006] Typical defense methods against model extraction include output obfuscation, adding noise to predictions, or limiting query rates. However, these methods may also affect the user experience as they can degrade the model's utility, accessibility, or accuracy.
[0007] There may be a desire to provide an improved concept for mitigating model extraction attacks.
[0008] Summary
[0009] This desire is addressed by the subject matter of the independent claims.
[0010] Various examples of the present disclosure are based on the finding, that typical defense methods against model extraction, such as output obfuscation, adding noise to predictions,or limiting query rates, can degrade the model's utility, accessibility, or accuracy for users who do not engage in model extraction. In particular, while limiting the query rate of individual users is often performed to avoid model extraction, it may be unsuitable for scenarios in which an attacker attempts to extract only a tiny aspect of the machine learning model or for scenarios in which an application using API access to the machine learning model experiences rapid growth rates. Therefore, instead of (or in addition to) using onedimensional metrics, such as the query rate, the proposed concept is based on determining a pattern of requests to the machine learning model and evaluates this pattern to determine whether the user is likely performing model extraction or not. This way, degradation in performance can be avoided for legitimate users, while model extraction attacks can be mitigated even for users attempting to extract only a tiny aspect of the machine learning model.
[0011] A first aspect of the present disclosure relates to a system for monitoring use of a machine learning model. The system comprises at least one interface for obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface (API). The system further comprises processor circuitry configured to process the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model. The processor circuitry is configured to determine, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model. The processor circuitry is configured to control access to the machine learning model for the at least one user based on the information on the user performing model extraction. This way, the degradation in performance can be avoided for legitimate users, while model extraction attacks can be mitigated even for users attempting to extract only a tiny aspect of the machine learning model.
[0012] To determine the pattern of the user, quantitative measures may be calculated on the requests being made, and the quantitative measures may then be analyzed to determine the pattern of the user. For example, the rate of requests sent to the API per unit time (e.g., per second, minute, hour), a frequency of how often specific inputs or parameters are queried (in particular edge cases), a request batching behavior (i.e., a quantitative measure representing whether requests are sent as bursts, according to a defined pattern or spaced naturally), and / or a cumulative request volume per unit over time (e.g., over a sliding window) may be used as quantitative measures. For example, the act of determining the pattern may comprise determining a gradient or derivative of one or more quantitativemeasures of requests being made to access the machine learning model by the user over time. The act of determining the information on the user performing model extraction may be based on the gradient or derivative. Gradients and derivatives can often be used to determine patterns that are indicative of model extraction.
[0013] Not only can gradients and derivatives be used for the purpose of detecting model extraction, but histograms or other types of distributions may also be used for this purpose. For example, the act of determining the pattern may comprise determining a histogram or distribution of one or more quantitative measures of requests being made to access the machine learning model by the user over time. In this case, the quantitative measures may include one or more of a quantitative measure representing intervals between consecutive requests (e.g., such that a histogram of intervals can be determined, with broad distributions of requests being counter-indicative of model extraction and peaked histograms at fixed intervals (e.g., 2 seconds, 5 seconds etc.) being indicative of model extraction / automatic querying), a quantitative measure related to input features (such that a distribution of input features can be calculated and compared with a distribution of input features across multiple users), a quantitative measure indicative of IP (Internet Protocol) address distribution of the requests, or a quantitative measure related to the entropy of subsequent requests (with non-model extraction usage having a higher entropy than model extraction attacks due to model extraction following systematic patterns). For example, the act of determining the information on the user performing model extraction may be based on the histogram or distribution. Histograms and distributions are particularly useful for detecting systematic querying of the machine learning model.
[0014] Moreover, histograms and distributions can easily be compared with reference histograms and distributions to determine whether a pattern of usage is likely based on model extraction. Thus, the act of determining the information on the user performing model extraction may comprise comparing the histogram or distribution to one or more histograms or distributions being indicative of model extraction or one or more histograms or distributions being counter-indicative of model extraction.
[0015] Distributions and histograms may not only be compared to reference distributions or histograms, but also to distributions or histograms of the user’s prior behavior, to determine whether the behavior is consistent over time (e.g., to determine whether the user is focusing its requests on edge cases to improve the capabilities of the extracted model). Thus, the act of determining the information on the user performing model extraction may comprise comparing the histogram or the distribution to one or more histograms or distributions beingbased on requests to access the machine learning model by the user during one or more prior time intervals.
[0016] In many cases, an adversary trying to perform model extraction might not be interested in recreating the entire scope of the machine learning model but instead focus on a specific subset of functionality. For example, if the machine learning model is trained to perform image processing, the attacker might only be interested in the functionality of detecting faces in images and not in other image-related tasks. Such behavior may be harder to detect, as it requires fewer requests to compile a set of training data. Thus, the pattern (or multiple patterns) may be determined with respect to certain subsets of functionality. In other words, the act of determining the pattern may comprise determining (e.g., identifying) a pattern with respect to a subset of functionality of the machine learning model being accessed by the user. The act of determining the information on the user performing model extraction may be based on the pattern with respect to a subset of functionality of the machine learning model being accessed by the user. This way, more targeted detection of model extraction attacks on subsets of functionality can be performed.
[0017] To determine the pattern with respect to a subset of functionality, various techniques may be used. For example, the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user may comprise determining a similarity of requests of the user to requests being associated with one of a plurality of pre-defined subsets of functionality of the machine learning model. In other words, knowing the capabilities of the machine learning model, requests may be stored that are associated with certain subsets of functionality of the machine learning model. These stored requests (or data derived from them, such as embeddings) can be used to determine whether the user is trying to perform model extraction on a subset of functionality.
[0018] Alternatively, or additionally, an automated approach may be used that does not require a priori storing requests associated with certain subsets of functionality of the machine learning model. Instead (or in addition), semantic similarities between requests may be determined and used to determine whether the user is focusing on a specific subset of functionality. For example, the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user may comprise determining a distribution of multi-dimensional representations (e.g., embeddings) of the respective requests, as used within the machine learning model. In machine learning, embeddings tend to encode the similarities between input or output data, making them suitable for determining whether the user’s requests focus on a subset of functionality.Again, the distribution of multi-dimensional representations may be compared to reference distributions to determine whether the user is likely engaging in model extraction. For example, the act of determining the information on the user performing model extraction may comprise comparing the distribution (of multi-dimensional representations) to one or more distributions (of multi-dimensional representations) that are indicative of model extraction with respect to a subset of functionality of the machine learning model or one or more distributions (of multi-dimensional representations) that are counter-indicative of model extraction with respect to a subset of functionality of the machine learning model. This way, suspicious patterns / distributions with respect to the multi-dimensional representations can be distinguished from unsuspicious distributions.
[0019] Another technique for determining whether the user is likely engaging in model extraction is based on using the requests that the user has already performed to train a surrogate machine learning model. This model can be evaluated to determine whether the previous requests have been suitable for adequately training the surrogate machine learning model. Accordingly, the processor circuitry may be configured to train a second machine learning model based on the requests being made by a user to access the machine learning model. The processor circuitry may be configured to compare an output of the machine learning model with the output of the second machine learning model for one or more validation requests. The processor circuitry may be configured to control access to the machine learning model for the user further based on the comparison. This way, model extraction can be stopped before the user is able to adequately replicate the machine learning model or a subset of its functionality.
[0020] Similar to the pattern-based determination of the information on the user performing model extraction of at least a subset of functionality of the machine learning model, the surrogate model-based determination may targe specific subset(s) of functionality. In other words, the act of determining the pattern may comprise determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, with the one or more validation requests being based on the subset of functionality. This way, the surrogate model can be tested with respect to the subset of functionality, such that model extraction can be determined even if the user is only trying to replicate the subset of functionality.
[0021] In most cases, it is unlikely that a clear-cut determination of whether the user engages in model extraction can be made. Therefore, to deal with the ambiguity, measures to restrict access to the machine learning model may be applied gradually based on a score indicatingthe likelihood of the user performing model extraction. In other words, the act of determining information on the user performing model extraction of at least a subset of functionality may comprise determining a score indicating a likelihood of the user performing model extraction. The act of controlling access to the machine learning model for the at least one user may comprise selecting at least one measure from a set of measures for controlling access to the machine learning model based on the score. This way, a gradual restriction of access may be implemented, designed to deter model extraction (or to collect further evidence of model extraction) while avoiding degradation of performance in cases where no model extraction is performed.
[0022] For example, the set of measures may comprise a plurality of measures being based on a plurality of different request limits per unit of time. Depending on the determined likelihood of the user performing model extraction, a suitable request limit per unit of time may be selected, e.g., with the request limit being lowered as the likelihood of the user performing model extraction increases.
[0023] Additionally, or alternatively, the set of measures may comprise one or more measures being based on manipulating or limiting information contained in responses being provided to the respective user. This way, information primarily relevant for training a surrogate model, such as an output distribution or certainty score of the machine learning model, can be omitted if the user is suspected of model extraction.
[0024] In the proposed concept, the focus is on monitoring the patterns that the user exhibit over time. Accordingly, the reaction to these patterns can also be adjusted over time. In other words, the at least one measure being selected may be adjusted based on a progression of the score over time.
[0025] A second aspect of the present disclosure relates to a corresponding computer-implemented method for monitoring use of a machine learning model. The method comprises obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface. The method comprises processing the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model. The method comprises determining, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model. The method comprisescontrolling access to the machine learning model for the at least one user based on the information on the user performing model extraction.
[0026] A third aspect of the present disclosure relates to a non-transitory, computer-readable medium comprising a program code that, when the program code is executed on a processor, a computer, or a programmable hardware component, causes the processor, computer, or programmable hardware component to perform the above method.
[0027] A fourth aspect of the present disclosure relates to a computer program having a program code for performing the above method when the computer program may be executed on a computer, a processor, or a programmable hardware component.
[0028] Brief description of the Figures
[0029] Some examples of apparatuses and / or methods will be described in the following by way of example only, and with reference to the accompanying figures, in which:
[0030] Fig. 1 shows a schematic diagram of an example of a system for monitoring use of a machine learning model; and
[0031] Fig. 2shows a flow chart of an example of a computer-implemented method for monitoring use of a machine learning model.
[0032] Detailed Description
[0033] Some examples are now described in more detail with reference to the enclosed figures. However, other possible examples are not limited to the features of these embodiments described in detail. Other examples may include modifications of the features as well as equivalents and alternatives to the features. Furthermore, the terminology used herein to describe certain examples should not be restrictive of further possible examples.
[0034] Throughout the description of the figures same or similar reference numerals refer to same or similar elements and / or features, which may be identical or implemented in a modified form while providing the same or a similar function. The thickness of lines, layers and / or areas in the figures may also be exaggerated for clarification.When two elements A and B are combined using an “or”, this is to be understood as disclosing all possible combinations, i.e. only A, only B as well as A and B, unless expressly defined otherwise in the individual case. As an alternative wording for the same combinations, "at least one of A and B" or "A and / or B" may be used. This applies equivalently to combinations of more than two elements.
[0035] If a singular form, such as “a”, “an” and “the” is used and the use of only a single element is not defined as mandatory either explicitly or implicitly, further examples may also use several elements to implement the same function. If a function is described below as implemented using multiple elements, further examples may implement the same function using a single element or a single processing entity. It is further understood that the terms "include", "including", "comprise" and / or "comprising", when used, describe the presence of the specified features, integers, steps, operations, processes, elements, components and / or a group thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, processes, elements, components and / or a group thereof.
[0036] Various examples of the present disclosure provide dynamic protection against model extraction attacks by dynamic query limiting and output manipulation. A dynamic defense method is proposed. This defense method assumes that users interact with the machine learning model via an API; they can query the model and obtain output in the form of predictions (such as image classification or transaction approval / disapproval) or even probabilities or logits. The proposed dynamic defense method comprises one or more of the following components: a component for dynamic query limiting and output manipulation, and / or a service-side model extraction algorithm.
[0037] Fig. 1 shows a schematic diagram of an example of a system 10 for monitoring use of a machine learning model 110. The system 10 shown in Fig. 1 is a computer system. The system 10 may comprise circuitry to provide the functionality of the system 10. For example, the system 10 of Fig. 1 comprises at least one interface 12 (e.g., interface circuitry) and processor circuitry 14. Optionally, the system may further comprise memory / storage circuitry. For example, the processor circuitry 14 may be coupled with the at least one interface 12 and / or the memory / storage circuitry. For example, the processor circuitry 14 may provide the functionality of the system, in conjunction with at least one 12 (for communicating with other entities inside or outside the system 10, such as a server providing API access to the machine learning model or a logging server or service), and the memory / storage circuitry (for storing information, such as machine-readable instructions). In general, the functionality of the processor circuitry 14 may be implemented by the processorcircuitry 14 executing machine-readable instructions. Accordingly, any feature ascribed to the processor circuitry 14 may be defined by one or more instructions of a plurality of machine-readable instructions. The system 10 may comprise the machine-readable instructions, e.g., within the memory or storage circuitry.
[0038] In particular, the at least one interface 12 is suitable for obtaining information on requests being made, by at least one user 1, to access the machine learning model via an application programming interface 105. In other words, the processor circuitry 14 is configured to obtain the information on the requests being made, by the at least one user 1, to access the machine learning model via the API 105. In this context, it is the requests being made by the at least one user that are handled by the API 105. However, the retrieval of the information on the requests being made may also be performed via API 105 or via a separate API or retrieval facility.
[0039] The proposed concept is based on processing the information on the requests being made to access the machine learning model. In general, the information on the requests being made may comprise metadata of the requests being made, such as a time at which the request is obtained, an IP address of the user making the request, an API token being used to make the request, client version information of a client used to make the request. In some cases, the metadata may be aggregated by user (e.g., according to the API token being used, or according to an IP address or IP range being used). In some cases, the information on the requests being made may comprise content of the request being made, such as input data included in the requests that is to be input into the machine learning model. In some cases, the information on the requests being made may comprise, in addition to the input data, corresponding output data of the machine learning model.
[0040] The processor circuitry 14 is configured to process the information on the requests being made to access the machine learning model in order to determine, for the at least one user, a pattern of the requests being made to access the machine learning model. In this context, the pattern of the requests refers to observable regularities or anomalies in user behavior when accessing a model, derived from measurable attributes / sequences of API requests over time. For the purpose of detecting model extraction, such patterns may reflect systemic deviations from legitimate usage, such as sudden surges in request frequency / time density (e.g., bursts of high-volume requests within short windows of time), repeated targeting of specific input domains (e.g., edge-case parameters or systematic sampling of model inputs / outputs to infer logic), statistically unusual distributions of requests (e.g., clustering around certain input data ranges representing edge cases), and / or predictable sequentialbehavior suggesting automated probing (e.g., caused by methodically iterating over input permutations to reconstruct the model’s underlying function).
[0041] The information on the pattern is then used to determine, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model. These two tasks - determining the pattern, and using the pattern to determine the information on the user performing model extraction, are closely linked, as the determination of which patterns are indicative of model extraction being performed influences the patterns that are being determined. In the following, some examples are given with respect to patterns and their interpretation with respect to model extraction behavior.
[0042] In general terms, the owner of the model (through the system 10) observes the user’s behavior (i.e., the pattern or patterns of their behavior) when the users interact with the model. The owner may use a metric M (or several metrics, in which case M is an aggregation of them) to measure or represent the user’s behavior. The metric M can be or include one of (but not limited to) query count (overall, over a fixed time period such as a day or a year, or a combination), count of certain type(s) of queries (e.g., queries that appear to be centered around a sub-domain of the training set, and / or metrics related to a server-side model extraction algorithm (see below) if the model’s owner has implemented such an algorithm. In the latter case, M can be, for instance, the rate of agreement of the server-side extracted model with the original model.
[0043] In particular, the user can apply a technique used in automation to monitor the rate with which the metrics M increase, apply threshold-based alerts and then dynamically reduce the query limit according to a pre-defined function. This includes gradual acting based on unusual metrics distribution. For example, the owner of the target model can monitor the distribution of metrics on a model trained on queries entered by the user and compare it to the distribution as obtained by training a model on random queries. If the observed distribution varies significantly (for instance, if the gradient is significantly larger), then gradual actions may be applied. The gradual acting based on distribution of the metrics, and not just single action based on single value of the metrics, is one example for the determination of a pattern of behavior of the user.
[0044] In the following discussion, at least four mathematical techniques are presented that can be used for determining the pattern of the requests - the determination of a gradient of one or more quantitative measures representing the requests, the determination of derivatives ofthe one or more quantitative measures representing the requests, the determination of histograms of the one or more quantitative measures representing the requests, and the determination of other types of distributions of the one or more quantitative measures representing the requests.
[0045] For example, the act of determining the pattern may comprise determining a gradient or derivative of one or more quantitative measures of requests being made to access the machine learning model by the user over time, and the act of determining the information on the user performing model extraction may be based on the gradient or derivative. For example, a gradient may be used if multiple quantitative measures are used, while a derivative may be used if a single quantitative measure is used. For example, a derivative can be determined on the frequency of requests being made by the user. If the derivative (d(requests) / dt) exceeds a threshold (e.g., requests surge from 50 requests / hour to 2000 requests / hour within an hour), this indicates aggressive probing, which is characteristic of automated model extraction attempts (caused by programmatically inputting a large number of different input values). This can be limited to specific inputs or parameters being queried (e.g., inputs known to be edge cases).
[0046] Another quantitative measure that can be analyzed using a gradient or derivative is a quantitative measure representing request batching behavior, i.e., a quantitative measure representing whether requests are sent as bursts, according to a defined pattern or spaced naturally. If this quantitative measure changes over time (e.g., as the bursts become larger or smaller, or as the defined pattern accelerates or decelerates), the derivative or gradient can be used to monitor this behavior and use it to determine the information on the user performing model extraction.
[0047] Not only gradients and derivatives can be used for the purpose of detecting model extraction, but histograms or other types of distributions may also be used for this purpose. For example, the act of determining the pattern may comprise determining a histogram or distribution of one or more quantitative measures of requests being made to access the machine learning model by the user over time. In this context, a distribution represents how values of a variable or dataset are spread out over a range. It represents the underlying probability of observing each possible value or range of values for that variable. A histogram is a specific representation of a distribution of numerical data, in which the numerical data is sorted into specified sub-ranges of the range of values (also called “buckets”), with the number of observations per bucket representing the respective distribution. Such distributions or histograms may be used to determine the information on the userperforming model extraction. In other words, the act of determining the information on the user performing model extraction may be based on the histogram or distribution.
[0048] For example, a histogram may be determined on a quantitative measure representing the time intervals between consecutive requests. If the histogram indicates that a large proportion of the time intervals fall into one specific bucket (e.g., two seconds, or five seconds, or the median time it takes to complete one request), the histogram is indicative of the user performing model extraction. If the histogram indicates that the time intervals are distributed over a broad range of buckets, the histogram is counter-indicative of the user performing model extraction.
[0049] Another quantitative measure that can be used relates to input features. In general, a machine learning model (and in particular a regressor or classification machine learning model) can take inputs across a defined input space defined by the inputs it accepts. For example, if a machine learning model takes 128x128 pixel images as input, the permutations across the pixels of the 128x128 pixel image define the input space of the machine learning model. If the machine learning model takes a time series of temperature values as input, all possible permutations of the temperature values define the input space for this machine learning model. The system may determine the distribution of the input values across the input space (across all or a sliding window of requests issued by the user) and use this distribution to determine the information on the user performing model extraction.
[0050] These histograms can be compared to various reference distributions or reference histograms. For example, the act of determining the information on the user performing model extraction may comprise comparing the histogram or distribution to one or more histograms or distributions being indicative of model extraction or one or more histograms or distributions being counter-indicative of model extraction. For example, the one or more histograms or distributions being counter-indicative of model extraction may be based on the entirety of users providing requests for accessing the machine learning model, or based on a subset of users that are known not to perform model extraction. The one or more histograms or distributions being indicative of model extraction may be generated using synthetic data or from requests of users that have been caught performing model extraction.
[0051] Alternatively, or additionally, the distribution or histogram may be compared to a distribution or histogram that is based on prior requests of the user. In other words, the act of determining the information on the user performing model extraction may comprisecomparing the histogram or distribution to one or more histograms or distributions that are on requests to access the machine learning model by the user during one or more prior time intervals. For example, if the distribution or histogram changes over time for the user, e.g., as the user moves towards probing edge cases, or as the user intensifies or de-intensifies model extraction, this may be deemed to be indicative of model extraction behavior.
[0052] In many cases, model extraction might not be performed on the entire machine learning model, but on a small subset of functionality of the machine learning model, e.g., a portion of the input space. For example, the attacker may aim to only extract a portion of the model that is of interest to them. The model owner can then measure an array of metrics covering each subset (of functionality) of interest (for instance, the performance of an image generation model on generating faces). These subsets can be both pre-defined by the model owner (as in the faces example) or derived from user queries / requests (i.e. where they are not explicitly anticipated). In both cases, subsets of the holdout dataset used to evaluate the model extraction efficiency are used to compute metrics. In the latter case, samples approximately belonging to the user’s subdomain must be chosen from known data (for example, by performing an embedding of the user’s queries followed by a nearest neighbors lookup on the holdout dataset).
[0053] These subsets may be taken into account when determining the pattern. Accordingly, the act of determining the pattern may comprise determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user. Furthermore, the act of determining the information on the user performing model extraction may be based on the pattern with respect to a subset of functionality of the machine learning model being accessed by the user. For example, the owner of the machine learning model may be aware of the different subsets of functionality that the machine learning model provides. In this case, the model owner may provide sample requests for the respective subsets of functionality, allowing the system 10 to determine whether the requests target a specific subset of functionality. In other words, the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user may comprise determining a similarity of requests of the user to requests being associated with one of a plurality of pre-defined subsets of functionality of the machine learning model. For example, a nearest neighbor lookup may be used to determine whether a request is associated with a pre-defined subset of functionality based on the request being associated with the pre-defined subset of functionality.In some cases, this approach may not be feasible, e.g., due to the large input space covered by the machine learning model. For example, if the machine learning model is a large language model, or a vision interpretation model, there may be too many different subsets of functionality, so that preparing suitable sample requests may be infeasible. In these cases, the internal representation of the requests, as used by the machine learning model, may be used to determine whether the user is targeting a specific subset of functionality. For example, the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user may comprise determining a distribution of multi-dimensional representations (e.g., embeddings) of the respective requests, as used within the machine learning model (e.g., as output by an input layer or by an encoder component of the machine learning model, in case an encoderdecoder approach is used in the machine learning model). For example, if more than 80% of the embeddings concentrate within a portion of the overall multi-dimensional space (embedding space), e.g., in a portion of the multi-dimensional space making up at most 10% of the multi-dimensional space, the user may be deemed to target a specific subset of functionality associated with that portion of the multi-dimensional space.
[0054] Instead of, or in addition to, determining the portion of the multi-dimensional space in which the requests concentrate, the distribution of the multi-dimensional representations may be compared to one or more reference distributions to determine the information on the user performing model extraction. Accordingly, the act of determining the information on the user performing model extraction may comprise comparing the distribution of the multidimensional representations to one or more distributions of multi-dimensional representations being indicative of model extraction with respect to a subset of functionality of the machine learning model or one or more distributions of multi-dimensional representations being counter-indicative of model extraction with respect to a subset of functionality of the machine learning model.
[0055] In some examples, a service-side model extraction algorithm may be used. The model owner (through system 10) may carefully monitor the user’s number of queries. For example, the system may measure the total number of queries per user, and / or the number of queries in a fixed time period, such as a day, a month or a year. After the user’s query number rises above a certain threshold (Threshold 0), the owner may begin model extraction using the inputs / outputs of the requests corresponding to the particular user, e.g., doing so iteratively after each fixed amount of new queries. In each iteration, a surrogate model may be trained and a metric M (such as agreement rate with the target model) may be computed. In other words, the processor circuitry 14 may be configured to train a secondmachine learning model based on the requests being made by a user to access the machine learning model, compare an output of the machine learning model with that of the second machine learning model for one or more validation requests (to determine the metric M). After the metrics rise above a certain pre-defined threshold (Threshold 1), the user may be flagged as potential model extractor, so a dynamic query limit and potential output manipulation may be introduced, as will be discussed below. In other words, the processor circuitry may control access to the machine learning model for the user further based on the comparison between the outputs of the machine learning model and the second machine learning model. For example, the time when a user is flagged may be depend on the number of queries they make as well as the type of queries. For instance, a user not attempting to extract the model will typically be allowed more queries before being flagged than a user that is submitting queries designed carefully to optimize model extraction. Typically, the model owner may measure the metrics on a holdout dataset (being used for the validation requests) which is not known to the attacker. Alternatively, or additionally, subsequent requests of the user may be used as validation requests.
[0056] Similar to the case of determining the pattern, also the training and validation of the second machine learning model may be targeted to a subset of functionality. In other words, as outlined above, the act of determining the pattern may comprise determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, and the one or more validation requests may be based on the subset of functionality. In particular, the one or more validation requests may be selected based on the subset of functionality accessed by the user.
[0057] The processor circuitry 14 is configured to control access to the machine learning model for the at least one user based on the information on the user performing model extraction. In various examples of the present disclosure, a gradual and dynamic approach may be used to limit access to the machine learning model. For example, a score indicating a likelihood that the user is performing model extraction may be determined (based on the pattern and / or based on the comparison between the output of the machine learning model and the output of the second machine learning model) and used to determine whether and how to limit access to the machine learning model. Accordingly, the act of determining information on the user performing model extraction of at least a subset of functionality may comprise determining a score indicating a likelihood of the user performing model extraction (based on the pattern and / or based on the comparison between the output of the machine learning model and the output of the second machine learning model).For example, once a user has been flagged as a potential model extractor, one or more of the following measures are put into place. For example, a dynamic query limit may be applied. As soon as metrics M (e.g., the score or an aspect of the score) for the particular user exceeds a pre-defined Threshold 1, the user may be flagged as a potential model extractor. When this happens, a query limit and potentially also output manipulation may be introduced, in a dynamic way. For instance, first a daily query limit may be set, while metrics M are carefully monitored. If M raises even further, exceeding a pre-set Threshold 2, then the daily query limit may be further reduced to a smaller value L2. This may then be repeated iteratively upon a pre-defined list {(T1, L1), (T2, L2),..., (Tn, Ln)}. Accordingly, the act of controlling access to the machine learning model for the at least one user may comprise selecting at least one measure from a set of measures for controlling access to the machine learning model based on the score. In the above example, the set of measures comprises a plurality of measures being based on a plurality of different request limits (L1, L2, ...,Ln) per unit of time (e.g., per day in the above example). The selection of the measure(s) is dynamic; i.e., the at least one measure selected may be adjusted based on a progression of the score over time.
[0058] In addition, or as an alternative to, the dynamic query limit, the outputs of the machine learning model can be manipulated such that they steer a potential model extractor away from replicating the model’s behavior while leaving the important components of the output intact or semi-intact. Accordingly, the set of measures may comprise one or more measures being based on manipulating or limiting information contained in responses being provided to the respective user. The precise manner in which this can be performed depends on the type of output (classification model, next-token-prediction model, etc.) and whether the machine learning model just outputs discrete labels or discloses deeper information, such as full or top-k probability distributions over sub-leading outputs. For example, in the latter case, where a user receives top-k output probabilities from the model, distortion methods can be applied that skew the output distribution while leaving the label (i.e. the argmax) unchanged. Similarly to the reduced query limit, the user may observe changes in output distribution if they are monitoring it.
[0059] For example, the at least one interface 12 may correspond to one or more inputs and / or outputs for receiving and / or transmitting information, which may be in digital (bit) values according to a specified code, within a module, between modules or between modules of different entities. For example, the at least one interface 12 may comprise circuitry configured to receive and / or transmit information.For example, the processor circuitry 14 may be implemented using one or more processing units, one or more processing devices, any means for processing, such as a processor, a computer or a programmable hardware component being operable with accordingly adapted software. In other words, the described function of the processor circuitry 14 may as well be implemented in software, which is then executed on one or more programmable hardware components. Such hardware components may comprise a general-purpose processor, a Digital Signal Processor (DSP), a micro-controller, etc.
[0060] More details and aspects of the system 10 are mentioned in connection with the proposed concept or one or more examples described above or below (e.g. Fig. 2). The system 10 may comprise one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.
[0061] Fig. 2 shows a flow chart of an example of a corresponding computer-implemented method for monitoring use of a machine learning model. The method comprises obtaining 210 information on requests being made, by at least one user, to access the machine learning model via an application programming interface. The method comprises processing 220 the information on the requests being made to access the machine learning model to determine 230, for the at least one user, a pattern of the requests being made to access the machine learning model. Optionally, the method further comprises training 240 a second machine learning model and comparing 250 the output of the machine learning model with that of the second machine learning model. The method comprises determining 260, for the at least one user and based on the pattern (and optionally based on the comparison), information on the user performing model extraction of at least a subset of functionality of the machine learning model. The method comprises controlling 270 access to the machine learning model for the at least one user based on the information on the user performing model extraction. For example, the method of Fig. 1 may be performed by a computer system, such as the system 10 of Fig. 1. Features introduced in connection with the system 10 of Fig. 1 may likewise be included in the corresponding method of Fig. 2.
[0062] More details and aspects of the method are mentioned in connection with the proposed concept or one or more examples described above or below (e.g. Fig. 1). The method may comprise one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.
[0063] At least some embodiments are based on using a machine learning model or machine learning algorithm. Machine learning refers to algorithms and statistical models thatcomputer systems may use to perform a specific task without using explicit instructions, instead relying on models and inference. For example, in machine learning, instead of a rule-based transformation of data, a transformation of data may be used, that is inferred from an analysis of historical and / or training data. For example, the content of images may be analyzed using a machine learning model or using a machine learning algorithm. In order for the machine learning model to analyze the content of an image, the machine learning model may be trained using training images as input and training content information as output. By training the machine learning model with a large number of training images and associated training content information, the machine learning model “learns” to recognize the content of the images, so the content of images that are not included of the training images can be recognized using the machine learning model. The same principle may be used for other kinds of sensor data as well: By training a machine learning model using training sensor data and a desired output, the machine learning model “learns” a transformation between the sensor data and the output, which can be used to provide an output based on non-training sensor data provided to the machine learning model.
[0064] Machine learning models are trained using training input data. The examples specified above use a training method called “supervised learning”. In supervised learning, the machine learning model is trained using a plurality of training samples, wherein each sample may comprise a plurality of input data values, and a plurality of desired output values, i.e. , each training sample is associated with a desired output value. By specifying both training samples and desired output values, the machine learning model “learns” which output value to provide based on an input sample that is similar to the samples provided during the training. Apart from supervised learning, semi-supervised learning may be used. In semi-supervised learning, some of the training samples lack a corresponding desired output value. Supervised learning may be based on a supervised learning algorithm, e.g., a classification algorithm, a regression algorithm or a similarity learning algorithm. Classification algorithms may be used when the outputs are restricted to a limited set of values, i.e., the input is classified to one of the limited set of values. Regression algorithms may be used when the outputs may have any numerical value (within a range). Similarity learning algorithms are similar to both classification and regression algorithms, but are based on learning from examples using a similarity function that measures how similar or related two objects are. For example, the machine learning model of Figs. 1 and 2 may be a classifier, a regressor, or a next token prediction model (such as a large language model).Apart from supervised or semi-supervised learning, unsupervised learning may be used to train the machine learning model. In unsupervised learning, (only) input data might be supplied, and an unsupervised learning algorithm may be used to find structure in the input data, e.g., by grouping or clustering the input data, finding commonalities in the data. Clustering is the assignment of input data comprising a plurality of input values into subsets (clusters) so that input values within the same cluster are similar according to one or more (pre-defined) similarity criteria, while being dissimilar to input values that are included in other clusters.
[0065] Reinforcement learning is a third group of machine learning algorithms. In other words, reinforcement learning may be used to train the machine learning model. In reinforcement learning, one or more software actors (called “software agents”) are trained to take actions in an environment. Based on the taken actions, a reward is calculated. Reinforcement learning is based on training the one or more software agents to choose the actions such, that the cumulative reward is increased, leading to software agents that become better at the task they are given (as evidenced by increasing rewards).
[0066] Furthermore, some techniques may be applied to some of the machine learning algorithms. For example, feature learning may be used. In other words, the machine learning model may at least partially be trained using feature learning, and / or the machine learning algorithm may comprise a feature learning component. Feature learning algorithms, which may be called representation learning algorithms, may preserve the information in their input, but also transform it in a way that makes it useful, often as a pre-processing step before performing classification or predictions. Feature learning may be based on principal components analysis or cluster analysis, for example.
[0067] In some examples, anomaly detection (i.e. , outlier detection) may be used, which is aimed at providing an identification of input values that raise suspicions by differing significantly from the majority of input or training data. In other words, the machine learning model may at least partially be trained using anomaly detection, and / or the machine learning algorithm may comprise an anomaly detection component.
[0068] In some examples, the machine learning algorithm may use a decision tree as a predictive model. In other words, the machine learning model may be based on a decision tree. In a decision tree, observations about an item (e.g., a set of input values) may be represented by the branches of the decision tree, and an output value corresponding to the item may be represented by the leaves of the decision tree. Decision trees may support both discretevalues and continuous values as output values. If discrete values are used, the decision tree may be denoted a classification tree, if continuous values are used, the decision tree may be denoted a regression tree.
[0069] Association rules are a further technique that may be used in machine learning algorithms. In other words, the machine learning model may be based on one or more association rules. Association rules are created by identifying relationships between variables in large amounts of data. The machine learning algorithm may identify and / or utilize one or more relational rules that represent the knowledge that is derived from the data. The rules may e.g., be used to store, manipulate or apply the knowledge.
[0070] Machine learning algorithms are usually based on a machine learning model. In other words, the term “machine learning algorithm” may denote a set of instructions that may be used to create, train or use a machine learning model. The term “machine learning model” may denote a data structure and / or set of rules that represents the learned knowledge, e.g., based on the training performed by the machine learning algorithm. In embodiments, the usage of a machine learning algorithm may imply the usage of an underlying machine learning model (or of a plurality of underlying machine learning models). The usage of a machine learning model may imply that the machine learning model and / or the data structure / set of rules that is the machine learning model is trained by a machine learning algorithm.
[0071] For example, the machine learning model may be an artificial neural network (ANN). ANNs are systems that are inspired by biological neural networks, such as can be found in a brain. ANNs comprise a plurality of interconnected nodes and a plurality of connections, so-called edges, between the nodes. There are usually three types of nodes, input nodes that receiving input values, hidden nodes that are (only) connected to other nodes, and output nodes that provide output values. Each node may represent an artificial neuron. Each edge may transmit information, from one node to another. The output of a node may be defined as a (non-linear) function of the sum of its inputs. The inputs of a node may be used in the function based on a “weight” of the edge or of the node that provides the input. The weight of nodes and / or of edges may be adjusted in the learning process. In other words, the training of an artificial neural network may comprise adjusting the weights of the nodes and / or edges of the artificial neural network, i.e., to achieve a desired output for a given input. In at least some embodiments, the machine learning model may be deep neural network, e.g., a neural network comprising one or more layers of hidden nodes (i.e., hidden layers), preferably a plurality of layers of hidden nodes.Alternatively, the machine learning model may be a support vector machine. Support vector machines (i.e., support vector networks) are supervised learning models with associated learning algorithms that may be used to analyze data, e.g., in classification or regression analysis. Support vector machines may be trained by providing an input with a plurality of training input values that belong to one of two categories. The support vector machine may be trained to assign a new input value to one of the two categories. Alternatively, the machine learning model may be a Bayesian network, which is a probabilistic directed acyclic graphical model. A Bayesian network may represent a set of random variables and their conditional dependencies using a directed acyclic graph. Alternatively, the machine learning model may be based on a genetic algorithm, which is a search algorithm and heuristic technique that mimics the process of natural selection.
[0072] The following examples pertain to further embodiments of the present disclosure:
[0073] (1) A system for monitoring use of a machine learning model, the system comprising: at least one interface for obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface; and
[0074] processor circuitry configured to:
[0075] process the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model, and
[0076] determine, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model, and
[0077] control access to the machine learning model for the at least one user based on the information on the user performing model extraction.
[0078] (2) The system according to (1), wherein the act of determining the pattern comprises determining a gradient or derivative of one or more quantitative measures of requests being made to access the machine learning model by the user over time, with the act of determining the information on the user performing model extraction being based on the gradient or derivative.
[0079] (3) The system according to one of (1) or (2), wherein the act of determining the pattern comprises determining a histogram or distribution of one or more quantitativemeasures of requests being made to access the machine learning model by the user over time, with the act of determining the information on the user performing model extraction being based on the histogram or distribution.
[0080] (4) The system according to (3), wherein the act of determining the information on the user performing model extraction comprises comparing the histogram or distribution to one or more histograms or distributions being indicative of model extraction or one or more histograms or distributions being counter-indicative of model extraction.
[0081] (5) The system according to one of (3) or (4), wherein the act of determining the information on the user performing model extraction comprises comparing the histogram or distribution to one or more histograms or distributions being based on requests to access the machine learning model by the user during one or more prior time intervals.
[0082] (6) The system according to one of (1) to (5), wherein the act of determining the pattern comprises determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, with the act of determining the information on the user performing model extraction being based on the pattern with respect to a subset of functionality of the machine learning model being accessed by the user.
[0083] (7) The system according to (6), wherein the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user comprises determining a similarity of requests of the user to requests being associated with one of a plurality of pre-defined subsets of functionality of the machine learning model.
[0084] (8) The system according to one of (6) or (7), wherein the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user comprises determining a distribution of multi-dimensional representations of the respective requests, as used within the machine learning model.
[0085] (9) The system according to (8), wherein the act of determining the information on the user performing model extraction comprises comparing the distribution to one or more distributions being indicative of model extraction with respect to a subset offunctionality of the machine learning model or one or more distributions being counter-indicative of model extraction with respect to a subset of functionality of the machine learning model.
[0086] (10) The system according to one of (1) to (9), wherein the processor circuitry is configured to train a second machine learning model based on the requests being made by a user to access the machine learning model, compare an output of the machine learning model and of the second machine learning model for one or more validation requests, and control access to the machine learning model for the user further based on the comparison.
[0087] (11) The system according to (10) wherein the act of determining the pattern comprises determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, with the one or more validation requests being based on the subset of functionality.
[0088] (12) The system according to one of (1) to (11), wherein the act of determining information on the user performing model extraction of at least a subset of functionality comprises determining a score indicating a likelihood of the user performing model extraction, with the act of controlling access to the machine learning model for the at least one user comprising selecting at least one measure from a set of measures for controlling access to the machine learning model based on the score.
[0089] (13) The system according to (12), wherein the set of measures comprises a plurality of measures being based on a plurality of different request limits per unit of time.
[0090] (14) The system according to (12) or (13), wherein the set of measures comprises one or more measures being based on manipulating or limiting information contained in responses being provided to the respective user.
[0091] (15) The system according to one of (12) to (14), wherein the at least one measure being selected is adjusted based on a progression of the score over time.
[0092] (16) A computer-implemented method for monitoring use of a machine learning model, the method comprising:obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface;
[0093] processing the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model;
[0094] determining, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model; and
[0095] controlling access to the machine learning model for the at least one user based on the information on the user performing model extraction.
[0096] (17) A non-transitory, computer-readable medium comprising a program code that, when the program code is executed on a processor, a computer, or a programmable hardware component, causes the processor, computer, or programmable hardware component to perform the method of (16).
[0097] (18) A computer program having a program code for performing the method of (16) when the computer program is executed on a computer, a processor, or a programmable hardware component.
[0098] The aspects and features described in relation to a particular one of the previous examples may also be combined with one or more of the further examples to replace an identical or similar feature of that further example or to additionally introduce the features into the further example.
[0099] Examples may further be or relate to a (computer) program including a program code to execute one or more of the above methods when the program is executed on a computer, processor or other programmable hardware component. Thus, steps, operations or processes of different ones of the methods described above may also be executed by programmed computers, processors or other programmable hardware components. Examples may also cover program storage devices, such as digital data storage media, which are machine-, processor- or computer-readable and encode and / or contain machineexecutable, processor-executable or computer-executable programs and instructions. Program storage devices may include or be digital storage devices, magnetic storage media such as magnetic disks and magnetic tapes, hard disk drives, or optically readable digital data storage media, for example. Other examples may also include computers, processors, control units, (field) programmable logic arrays ((F)PLAs), (field) programmable gate arrays((F)PGAs), graphics processor units (GPU), application-specific integrated circuits (ASICs), integrated circuits (ICs) or system-on-a-chip (SoCs) systems programmed to execute the steps of the methods described above.
[0100] It is further understood that the disclosure of several steps, processes, operations or functions disclosed in the description or claims shall not be construed to imply that these operations are necessarily dependent on the order described, unless explicitly stated in the individual case or necessary for technical reasons. Therefore, the previous description does not limit the execution of several steps or functions to a certain order. Furthermore, in further examples, a single step, function, process or operation may include and / or be broken up into several sub-steps, -functions, -processes or -operations.
[0101] If some aspects have been described in relation to a device or system, these aspects should also be understood as a description of the corresponding method. For example, a block, device or functional aspect of the device or system may correspond to a feature, such as a method step, of the corresponding method. Accordingly, aspects described in relation to a method shall also be understood as a description of a corresponding block, a corresponding element, a property or a functional feature of a corresponding device or a corresponding system.
[0102] The following claims are hereby incorporated in the detailed description, wherein each claim may stand on its own as a separate example. It should also be noted that although in the claims a dependent claim refers to a particular combination with one or more other claims, other examples may also include a combination of the dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby explicitly proposed, unless it is stated in the individual case that a particular combination is not intended. Furthermore, features of a claim should also be included for any other independent claim, even if that claim is not directly defined as dependent on that other independent claim.
Claims
ClaimsWhat is claimed is:
1. A system for monitoring use of a machine learning model, the system comprising: at least one interface for obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface; andprocessor circuitry configured to:process the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model, anddetermine, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model, andcontrol access to the machine learning model for the at least one user based on the information on the user performing model extraction.
2. The system according to claim 1, wherein the act of determining the pattern comprises determining a gradient or derivative of one or more quantitative measures of requests being made to access the machine learning model by the user over time, with the act of determining the information on the user performing model extraction being based on the gradient or derivative.
3. The system according to claim 1, wherein the act of determining the pattern comprises determining a histogram or distribution of one or more quantitative measures of requests being made to access the machine learning model by the user over time, with the act of determining the information on the user performing model extraction being based on the histogram or distribution.
4. The system according to claim 3, wherein the act of determining the information on the user performing model extraction comprises comparing the histogram or distribution to one or more histograms or distributions being indicative of model extraction or one or more histograms or distributions being counter-indicative of model extraction.
5. The system according to claim 3, wherein the act of determining the information on the user performing model extraction comprises comparing the histogram or distribution to one or more histograms or distributions being based on requests to access the machine learning model by the user during one or more prior time intervals.
6. The system according to claim 1, wherein the act of determining the pattern comprises determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, with the act of determining the information on the user performing model extraction being based on the pattern with respect to a subset of functionality of the machine learning model being accessed by the user.
7. The system according to claim 6, wherein the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user comprises determining a similarity of requests of the user to requests being associated with one of a plurality of pre-defined subsets of functionality of the machine learning model.
8. The system according to claim 6, wherein the act of determining the pattern with respect to a subset of functionality of the machine learning model being accessed by the user comprises determining a distribution of multi-dimensional representations of the respective requests, as used within the machine learning model.
9. The system according to claim 8, wherein the act of determining the information on the user performing model extraction comprises comparing the distribution to one or more distributions being indicative of model extraction with respect to a subset of functionality of the machine learning model or one or more distributions being counterindicative of model extraction with respect to a subset of functionality of the machine learning model.
10. The system according to claim 1, wherein the processor circuitry is configured to train a second machine learning model based on the requests being made by a user to access the machine learning model, compare an output of the machine learning model and of the second machine learning model for one or more validation requests, and control access to the machine learning model for the user further based on the comparison.
11. The system according to claim 10, wherein the act of determining the pattern comprises determining a pattern with respect to a subset of functionality of the machine learning model being accessed by the user, with the one or more validation requests being based on the subset of functionality.
12. The system according to claim 1, wherein the act of determining information on the user performing model extraction of at least a subset of functionality comprises determining a score indicating a likelihood of the user performing model extraction, with the act of controlling access to the machine learning model for the at least one user comprising selecting at least one measure from a set of measures for controlling access to the machine learning model based on the score.
13. The system according to claim 12, wherein the set of measures comprises a plurality of measures being based on a plurality of different request limits per unit of time.
14. The system according to claim 12, wherein the set of measures comprises one or more measures being based on manipulating or limiting information contained in responses being provided to the respective user.
15. The system according to claim 12, wherein the at least one measure being selected is adjusted based on a progression of the score over time.
16. A computer-implemented method for monitoring use of a machine learning model, the method comprising:obtaining information on requests being made, by at least one user, to access the machine learning model via an application programming interface;processing the information on the requests being made to access the machine learning model to determine, for the at least one user, a pattern of the requests being made to access the machine learning model;determining, for the at least one user and based on the pattern, information on the user performing model extraction of at least a subset of functionality of the machine learning model; andcontrolling access to the machine learning model for the at least one user based on the information on the user performing model extraction.
17. A non-transitory, computer-readable medium comprising a program code that, when the program code is executed on a processor, a computer, or a programmable hardware component, causes the processor, computer, or programmable hardware component to perform the method of claim 16.
18. A computer program having a program code for performing the method of claim 16 when the computer program is executed on a computer, a processor, or a programmable hardware component.