AI Model Watermark Verification for Data Processing Accelerators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of effective digital rights protection for machine-learning models, and there is no proof that results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to verify the authenticity and authorization of AI models used in secondary processing systems.

Innovation Solution

A watermarking system is implemented where a watermark is embedded into AI models, and a signature is generated and verified to authenticate the model, ensuring that only authorized models are used in data processing accelerators, with the watermark being extracted and verified before inference tasks are performed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If machine-learning models are made portable and reusable without authorization, then ease of operation and adaptability improve, but digital rights protection and reliability deteriorate

Engineering Contradiction:
Improveportability of AI modelVSAvoiddigital rights protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A watermark is embedded into the AI model before it is deployed or transferred to secondary processing systems. This preliminary action ensures that the model carries authentication information that can be verified later, allowing the model to be portable while maintaining digital rights protection through pre-established trust mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The watermark acts as an intermediary element between the AI model and the verification system. It provides a mechanism for secondary processing systems to verify the authenticity and authorization of the model without requiring direct authorization protocols, thus enabling portability while maintaining reliability through the intermediary verification layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If AI models are deployed in secondary processing systems without verification, then adaptability and ease of operation improve, but reliability and trustworthiness deteriorate

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidroot of trust verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The watermark is embedded into the AI model in advance, before deployment to secondary processing systems. This allows the model to be adapted and deployed flexibly across different systems while the pre-embedded watermark enables subsequent verification of authenticity and authorization, maintaining reliability without restricting adaptability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The watermark serves as a verifiable copy or representation of the model's authorization credentials. Secondary processing systems can verify the watermark to confirm the model's authenticity without needing to access the original authorization source, enabling flexible deployment while maintaining trust through verifiable copies

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11582260B2Systems and methods for verifying a watermark of an AI model for a data processing accelerator
Publication Date: 2023.02.14 BAIDU USA LLC
  • US11582260B2 patent drawing
  • US11582260B2 patent drawing
  • US11582260B2 patent drawing

AI summary

Embodiments of the disclosure relate to verifying a watermark of an artificial intelligence (AI) model for a data processing (DP) accelerator. In one embodiment, a system receives an inference request from an application. The system extracts the watermark from an AI model having the watermark. The system verifies the extracted watermark based on a policy. The system applies the AI model having a watermark to a set of inference inputs to generate inference results. The system sends a verification proof and the inference results to the application.