ML Model Ownership Verification via Embedded Markers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for an improved security framework to detect whether a machine learning (ML) model has been copied or not, and to trace the source of the ML model for auditing purposes.

Innovation Solution

A method and system where a manufacturer embeds at least one marker in an electronic file, allowing the ML model to determine if it belongs to the manufacturer by processing the file according to a second processing strategy when the marker is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ML models are deployed as a service in remote systems with minimal configuration, then ease of operation and accessibility are improved, but security and protection against copying deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding markers into training data before the ML model is trained. This proactive measure ensures that ownership verification capability is built into the model during the training phase, allowing security protection to be automatically activated when the model is deployed as a service without requiring additional configuration or setup later.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If ML models are protected from copying through traditional methods, then security is improved, but the models become less adaptable and harder to deploy flexibly

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements self-service by enabling the ML model to automatically verify its own ownership through embedded markers during inference. The model autonomously processes input data, detects embedded markers, and determines whether it is operating on authorized data without requiring external verification systems, thus maintaining both security and adaptability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses copying in the form of embedding marker copies into training data. These markers are replicated throughout the training dataset, and the ML model learns to recognize these copied marker patterns, enabling ownership verification while maintaining model flexibility and deployability across different systems.

Inventive Principle:
Principle #26Copying

3Measurement precision

If markers are embedded in training data to detect copied models, then detection capability is improved, but the complexity of the training process increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomplexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies merging by combining the ownership verification function with the normal training process. Markers are embedded directly into the training data alongside regular training samples, and the ML model is trained to perform both its primary function and marker detection simultaneously, eliminating the need for separate verification systems and reducing overall complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3861490B1Identification of copied ML model
Publication Date: 2025.06.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3861490B1 patent drawingFigure 1~4
  • EP3861490B1 patent drawingFigure 2
  • EP3861490B1 patent drawingFigure 3

AI summary

There is provided mechanisms for a manufacturer of an ML model to embed at least one marker in an electronic file. A method comprises obtaining the electronic file. The electronic file represents content that causes the ML model to determine an output for the electronic file according to a first processing strategy. The method comprises embedding, in the electronic file, the at least one marker that, only when detected by the ML model, causes the output of the electronic file to be determined according to a second processing strategy. The second processing strategy is unrelated to the first processing strategy and deterministically defined by the at least one marker.