Computer System for AI Model Robustness Without Model Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to ensure the robustness and security of artificial intelligence models throughout their lifecycle, especially when multiple stakeholders with varying levels of trust are involved, as they do not assess the inherent trustworthiness or modifications that affect model robustness.

Innovation Solution

A computer system with a storage unit and a processing unit separates the model from the evaluation process, allowing external systems to assess robustness indicators without direct access to the model, using attack models and databases to evaluate vulnerability, precision, and confidence levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the model is stored on a computer system accessible to all actors, then the model is accessible to all stakeholders for their respective tasks, but the security of the model is compromised because each actor can know all components of the model making it subject to external attacks

Engineering Contradiction:
ImproveAccessibility of model to stakeholdersVSAvoidSecurity of model
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the model into multiple versions stored in a database, with each version representing a specific state of the model at different points in its lifecycle. This allows controlled access to specific versions rather than the entire model, enabling stakeholders to work with authorized versions while maintaining security. The segmentation of model versions combined with access control lists ensures that actors can only access and modify versions they are authorized for.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a version control system with access control lists. This intermediary layer sits between the stakeholders and the model, mediating access requests. The system tracks modifications, manages versioning, and enforces access permissions, allowing multiple actors to work with the model without direct exposure to its complete structure, thus maintaining security while enabling collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MLSecOps technology is used to guarantee security throughout the model lifecycle, then the model is protected from attacks and modifications are tracked, but the inherent trust and robustness of the model are not assessed

Engineering Contradiction:
ImproveSecurity of model throughout lifecycleVSAvoidAssessment of model robustness and trust
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms through automated testing and evaluation systems that continuously assess model robustness and trustworthiness. The system performs automated tests on model versions, evaluates their performance and security properties, and provides feedback that informs subsequent version development. This feedback loop enables ongoing assessment of model robustness while maintaining security through the version control and access control framework.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the model is made accessible for evolution and improvement, then new constraints and performance requirements can be incorporated, but the model becomes vulnerable to attacks and robustness cannot be guaranteed

Engineering Contradiction:
ImproveAbility of model to evolve and improveVSAvoidVulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing automated security testing, robustness evaluation, and validation on model versions before they are deployed or made accessible to stakeholders. The system pre-assesses potential vulnerabilities and security issues through automated tests, and only allows progression of versions that meet predefined security and robustness criteria. This preliminary security assessment prevents vulnerable models from being deployed while still enabling evolution through controlled versioning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4579531A1Computer system, implementation method and computer program product set thereof
Publication Date: 2025.07.02 THALES SA
  • EP4579531A1 patent drawingFigure 1
  • EP4579531A1 patent drawingFigure 2
  • EP4579531A1 patent drawing

AI summary

The present invention relates to a computer system (10) comprising a storage unit (25) capable of receiving, from a first external system (15), an artificial intelligence model, called the model to be tested (35), and capable of storing the model to be tested (35). The model to be tested (35) is a classification model capable of classifying an input data item among a plurality of distinct classes. The computer system (10) further comprises a processing unit (30) capable of receiving, from a second external system (25), a request (37) for evaluating the robustness of the model to be tested (35). The processing unit (30) is capable of evaluating at least one indicator quantifying the robustness of the model to be tested (35), and of sending, to the second external system (30), the or each indicator quantifying the robustness evaluated. The storage unit (25) and the processing unit (30) are distinct.