AI Model Watermarking for Data Processing Accelerator Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of effective digital rights protection for machine-learning models, and there is no proof that results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to authenticate and verify the authenticity of AI models used in secondary processing systems.
Innovation Solution
A watermark is embedded into the AI model, which is then signed and verified using a security key pair, allowing the host device to authenticate the AI model before using it, ensuring digital rights protection and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a machine-learning model is made portable and accessible for inference, then the model can be widely utilized across different systems, but the model becomes vulnerable to unauthorized use and lacks digital rights protection
Solution Approach 1:
The patent applies preliminary action by embedding a watermark into the machine-learning model before it is deployed for inference. This watermark is inserted during the model preparation phase, allowing the model to be portable and executable while carrying embedded identification information that enables later verification of its authenticity and authorization status.
Solution Approach 2:
The patent uses an intermediary approach by introducing a watermark as a mediating element between the model owner and the inference system. The watermark serves as a trusted indicator that bridges the gap between model portability and rights protection, allowing the DP accelerator to verify model authenticity without restricting the model's ability to be executed on different systems.
2Productivity
If processing tasks are delegated to a secondary processing system like a DP accelerator, then processing capability is enhanced, but there is no proof that results are protected by a root of trust system
Solution Approach 1:
The patent applies preliminary action by pre-embedding a watermark into the machine-learning model before it is executed on the DP accelerator. This watermark contains identification information that enables the DP accelerator to verify the model's authenticity and authorization status during inference, establishing a root of trust without compromising processing capability.
Solution Approach 2:
The watermark acts as an intermediary that enables trust verification between the model owner and the DP accelerator. The DP accelerator can extract and verify the watermark to confirm the model is authorized, creating a reliable chain of trust that allows enhanced processing capability while maintaining security guarantees.
3Ease of operation
If no watermark or authentication mechanism is used, then the system operates with simplicity and speed, but the authenticity of AI models cannot be verified
Solution Approach 1:
The patent applies preliminary action by embedding the watermark during model preparation, so that during inference the DP accelerator can quickly extract and verify the watermark without complex authentication procedures. This maintains ease of operation during actual use while enabling precise authenticity verification through the pre-inserted watermark.
Solution Approach 2:
The patent uses a simplified verification approach by copying the identification information from the watermark into a verification structure that can be quickly checked. This allows the system to maintain operational simplicity while achieving accurate authenticity verification through the embedded watermark data.
Data Source
AI summary
Embodiments of the disclosure relates to signing of an artificial intelligence (AI) model with a watermark for a data processing (DP) accelerator. In one embodiment, in response to a request received by the data processing accelerator, the request sent by an application to embed digital rights protection to an AI model, a system generates a watermark for the AI model based on a watermark algorithm. The system embeds the watermark onto the AI model. The system signs the AI model having the embedded watermark to generate a signature. The system returns the signature and the AI model having the embedded watermark back to the application, where the signature is used to authenticate the watermark and/or the AI model.


