ML Model Obfuscation via Measurable Parameter Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing devices that implement proprietary machine learning features face the risk of reverse-engineering by rivals or unscrupulous users, who can gain insights into the feature's implementation by analyzing measurable parameters such as power consumption or electromagnetic emissions.

Innovation Solution

The method involves receiving input data describing machine learning model characteristics and determining obfuscation instructions to execute concurrently or sequentially with model instructions. These obfuscation instructions obscure the profile of measurable parameters associated with the model's execution, thereby masking the device's operational characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning features are implemented with proprietary processes to provide competitive advantage and improve security, then device functionality and security are improved, but the risk of reverse-engineering by rivals or unscrupulous users increases

Engineering Contradiction:
ImprovesecurityVSAvoidreverse-engineering risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces measurable parameter profiles (such as power consumption patterns, electromagnetic emissions, or thermal characteristics) as intermediary elements that indirectly reveal information about the machine learning model's structure and operation. These profiles serve as a mediator between the proprietary ML processes and external observers, allowing the system to maintain security while providing necessary functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent modifies measurable parameters (power consumption, electromagnetic emissions, thermal output) to obfuscate the underlying machine learning model characteristics. By changing these parameters through techniques such as adding noise, varying execution timing, or modifying hardware configuration, the system makes reverse-engineering difficult while preserving the model's functional capabilities.

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If obfuscation instructions are executed concurrently or sequentially with model instructions to mask operational characteristics, then reverse-engineering difficulty is improved, but device complexity increases

Engineering Contradiction:
Improvereverse-engineering difficultyVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent combines obfuscation instructions with model instructions to create a unified execution flow. The obfuscation mechanisms are merged into the existing hardware and software architecture, allowing concurrent or sequential execution without requiring separate dedicated obfuscation hardware. This integration approach increases reverse-engineering difficulty while minimizing the increase in overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent designs obfuscation instructions that can be executed on existing general-purpose or specialized hardware without requiring dedicated obfuscation hardware. The same processing units that execute the machine learning model also execute the obfuscation instructions, making the system universally applicable to different hardware platforms while avoiding additional complexity from specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250068972A1Method for Obfuscating Device Functionality
Publication Date: 2025.02.27 GOOGLE LLC
  • US20250068972A1 patent drawing
  • US20250068972A1 patent drawing
  • US20250068972A1 patent drawing

AI summary

A computer-implemented method performed on a device comprises receiving input data that describes one or more machine learning (ML) model characteristics of an ML model to be scheduled for execution by the device. The method further comprises determining, based on the one or more ML model characteristics of the ML model, one or more obfuscation instructions to execute concurrently or sequentially with execution of model instructions associated with the ML model. Execution of the one or more obfuscation instructions obfuscates a profile of a measurable parameter associated with the device executing the model instructions. The method further comprises executing the one or more determined obfuscation instructions concurrently or sequentially with execution of the model instructions.