ML System Package Selection via Security Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current machine learning systems face challenges in managing security vulnerabilities of software packages used in their construction, leading to potential security risks and inefficiencies in production systems due to manual updates and lack of automated handling during model training.

Innovation Solution

A method for generating a machine learning system that selects software packages based on package-specific security vulnerability metadata and security vulnerability constraints, allowing for automated handling of security aspects during training and updates, thereby optimizing security and functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual updates and management of software packages are used in machine learning systems, then flexibility and control are maintained, but security vulnerability management becomes inefficient and time-consuming

Engineering Contradiction:
Improvesecurity update efficiencyVSAvoidtime for manual security updates
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs automated security vulnerability management by self-evaluating package metadata, automatically selecting secure packages, and generating updated machine learning systems without requiring manual intervention for security updates

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security vulnerability constraints are defined in advance, and package metadata is pre-evaluated for security issues before system generation, allowing secure packages to be selected automatically during system construction rather than requiring post-deployment updates

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security vulnerability constraints are strictly enforced during package selection, then system security is improved, but the available pool of software packages is reduced

Engineering Contradiction:
Improvesystem securityVSAvoidpackage selection flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Security vulnerability constraints are defined as adjustable parameters that specify acceptable vulnerability thresholds. The system evaluates package metadata against these parameterized constraints, allowing flexible adjustment of security requirements based on specific needs while maintaining automated enforcement

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Package metadata acts as an intermediary that carries security vulnerability information from software packages to the selection process. This metadata enables automated evaluation and filtering of packages based on security constraints without requiring direct manual inspection

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive security vulnerability metadata is collected and evaluated for all software packages, then security assessment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidmetadata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Security vulnerability information is extracted from comprehensive package metadata into specific, evaluable constraints. The system extracts relevant security attributes from metadata and evaluates them against defined constraints, simplifying the processing while maintaining assessment accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250021659A1Security vulnerability constraints for machine learning systems
Publication Date: 2025.01.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250021659A1 patent drawing
  • US20250021659A1 patent drawing
  • US20250021659A1 patent drawing

AI summary

Disclosed herein is a computer implemented method for generating a machine learning system from software packages. The software packages comprise package specific security vulnerability metadata. The method comprises receiving a specification of the machine learning system, wherein the specification comprises security vulnerability constraints. The method further comprises selecting the software packages from a collection of software packages using the specification and by comparing the package specific security vulnerability metadata to the security vulnerability constraints. The method further comprises generating the machine learning system using the selected software packages. The method further comprises training the machine learning system using the specification.