ML Model Obfuscation via Measurable Parameter Masking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing devices that implement proprietary machine learning features face the risk of reverse-engineering by rivals or unscrupulous users, who can gain insights into the feature's implementation by analyzing measurable parameters such as power consumption or electromagnetic emissions.
Innovation Solution
The method involves receiving input data describing machine learning model characteristics and determining obfuscation instructions to execute concurrently or sequentially with model instructions. These obfuscation instructions obscure the profile of measurable parameters associated with the model's execution, thereby masking the device's operational characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If machine learning features are implemented with proprietary processes to provide competitive advantage and improve security, then device functionality and security are improved, but the risk of reverse-engineering by rivals or unscrupulous users increases
Solution Approach 1:
The patent introduces measurable parameter profiles (such as power consumption patterns, electromagnetic emissions, or thermal characteristics) as intermediary elements that indirectly reveal information about the machine learning model's structure and operation. These profiles serve as a mediator between the proprietary ML processes and external observers, allowing the system to maintain security while providing necessary functionality.
Solution Approach 2:
The patent modifies measurable parameters (power consumption, electromagnetic emissions, thermal output) to obfuscate the underlying machine learning model characteristics. By changing these parameters through techniques such as adding noise, varying execution timing, or modifying hardware configuration, the system makes reverse-engineering difficult while preserving the model's functional capabilities.
2Difficulty of detecting and measuring
If obfuscation instructions are executed concurrently or sequentially with model instructions to mask operational characteristics, then reverse-engineering difficulty is improved, but device complexity increases
Solution Approach 1:
The patent combines obfuscation instructions with model instructions to create a unified execution flow. The obfuscation mechanisms are merged into the existing hardware and software architecture, allowing concurrent or sequential execution without requiring separate dedicated obfuscation hardware. This integration approach increases reverse-engineering difficulty while minimizing the increase in overall system complexity.
Solution Approach 2:
The patent designs obfuscation instructions that can be executed on existing general-purpose or specialized hardware without requiring dedicated obfuscation hardware. The same processing units that execute the machine learning model also execute the obfuscation instructions, making the system universally applicable to different hardware platforms while avoiding additional complexity from specialized components.
Data Source
AI summary
A computer-implemented method performed on a device comprises receiving input data that describes one or more machine learning (ML) model characteristics of an ML model to be scheduled for execution by the device. The method further comprises determining, based on the one or more ML model characteristics of the ML model, one or more obfuscation instructions to execute concurrently or sequentially with execution of model instructions associated with the ML model. Execution of the one or more obfuscation instructions obfuscates a profile of a measurable parameter associated with the device executing the model instructions. The method further comprises executing the one or more determined obfuscation instructions concurrently or sequentially with execution of the model instructions.


