AI Model Watermarking for Data Processing Accelerator Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of effective digital rights protection for machine-learning models, and there is no proof that results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to authenticate and verify the authenticity of AI models used in secondary processing systems.

Innovation Solution

A watermark is embedded into the AI model, which is then signed and verified using a security key pair, allowing the host device to authenticate the AI model before using it, ensuring digital rights protection and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a machine-learning model is made portable and accessible for inference, then the model can be widely utilized across different systems, but the model becomes vulnerable to unauthorized use and lacks digital rights protection

Engineering Contradiction:
Improvemodel portabilityVSAvoiddigital rights protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding a watermark into the machine-learning model before it is deployed for inference. This watermark is inserted during the model preparation phase, allowing the model to be portable and executable while carrying embedded identification information that enables later verification of its authenticity and authorization status.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a watermark as a mediating element between the model owner and the inference system. The watermark serves as a trusted indicator that bridges the gap between model portability and rights protection, allowing the DP accelerator to verify model authenticity without restricting the model's ability to be executed on different systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If processing tasks are delegated to a secondary processing system like a DP accelerator, then processing capability is enhanced, but there is no proof that results are protected by a root of trust system

Engineering Contradiction:
Improveprocessing capabilityVSAvoidroot of trust verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-embedding a watermark into the machine-learning model before it is executed on the DP accelerator. This watermark contains identification information that enables the DP accelerator to verify the model's authenticity and authorization status during inference, establishing a root of trust without compromising processing capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The watermark acts as an intermediary that enables trust verification between the model owner and the DP accelerator. The DP accelerator can extract and verify the watermark to confirm the model is authorized, creating a reliable chain of trust that allows enhanced processing capability while maintaining security guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If no watermark or authentication mechanism is used, then the system operates with simplicity and speed, but the authenticity of AI models cannot be verified

Engineering Contradiction:
Improvesystem simplicityVSAvoidmodel authenticity verification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by embedding the watermark during model preparation, so that during inference the DP accelerator can quickly extract and verify the watermark without complex authentication procedures. This maintains ease of operation during actual use while enabling precise authenticity verification through the pre-inserted watermark.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a simplified verification approach by copying the identification information from the watermark into a verification structure that can be quickly checked. This allows the system to maintain operational simplicity while achieving accurate authenticity verification through the embedded watermark data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11574032B2Systems and methods for signing an AI model with a watermark for a data processing accelerator
Publication Date: 2023.02.07 BAIDU USA LLC
  • US11574032B2 patent drawing
  • US11574032B2 patent drawing
  • US11574032B2 patent drawing

AI summary

Embodiments of the disclosure relates to signing of an artificial intelligence (AI) model with a watermark for a data processing (DP) accelerator. In one embodiment, in response to a request received by the data processing accelerator, the request sent by an application to embed digital rights protection to an AI model, a system generates a watermark for the AI model based on a watermark algorithm. The system embeds the watermark onto the AI model. The system signs the AI model having the embedded watermark to generate a signature. The system returns the signature and the AI model having the embedded watermark back to the application, where the signature is used to authenticate the watermark and/or the AI model.