ML Vulnerability Assessment for Poisoning and Model Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for detecting and defending against machine learning model attacks are not integrated into a platform, leading to inefficiencies in resource consumption and compromised security, as they fail to detect and correct various attacks such as model manipulation, data poisoning, and model extraction.

Innovation Solution

An assessment system that performs data veracity, adversarial example, membership inference, and model extraction assessments to identify and correct vulnerabilities in machine learning models, providing defensive capabilities and secure APIs to mitigate these attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate techniques are used to detect and defend against machine learning model attacks, then comprehensive security coverage is achieved, but resource consumption and system complexity increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate attack detection and defense techniques (data poisoning detection, adversarial example detection, model extraction prevention, membership inference protection) into a single integrated assessment system. This consolidation maintains comprehensive security coverage while reducing system complexity by unified the interface and resource management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The assessment system is designed as a universal platform that performs multiple security assessment functions through a single system. It can detect various types of attacks (data poisoning, adversarial examples, model extraction, membership inference) and provide defensive capabilities across different machine learning models, achieving multi-functionality without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security assessments are performed on machine learning models, then vulnerabilities are identified and corrected, but computing and networking resources are consumed

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The assessment system performs security evaluations before machine learning models are deployed or updated. By conducting data veracity assessments, adversarial example assessments, membership inference assessments, and model extraction assessments in advance, vulnerabilities are identified and corrected before they can be exploited, maintaining high detection accuracy while allowing efficient model deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The assessment system is designed to efficiently utilize computing and networking resources by implementing optimized assessment algorithms. It performs comprehensive security checks while managing resource consumption through intelligent scheduling and execution of assessment tasks, reducing unnecessary resource wastage.

Inventive Principle:
Principle #25Self-service

3Productivity

If security assessments are integrated into a unified platform, then resource efficiency improves, but the ability to detect specialized attacks may be reduced

Engineering Contradiction:
Improveresource efficiencyVSAvoidattack detection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The integrated assessment system is divided into distinct modular assessment components: data veracity assessment module, adversarial example assessment module, membership inference assessment module, and model extraction assessment module. Each module specializes in detecting specific attack types, maintaining high detection precision while benefiting from the efficiency of unified resource management at the platform level.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12566861B2Identifying and correcting vulnerabilities in machine learning models
Publication Date: 2026.03.03 ACCENTURE GLOBAL SOLUTIONS LTD
  • US12566861B2 patent drawing
  • US12566861B2 patent drawing
  • US12566861B2 patent drawing

AI summary

A device may receive a machine learning model and training data utilized to train the machine learning model, and may perform a data veracity assessment of the training data to identify and remove poisoned data from the training data. The device may perform an adversarial assessment of the machine learning model to generate adversarial attacks and to provide defensive capabilities for the adversarial attacks, and may perform a membership inference assessment of the machine learning model to generate membership inference attacks and to provide secure training data as a defense for the membership inference attacks. The device may perform a model extraction assessment of the machine learning model to identify model extraction vulnerabilities and to provide a secure application programming interface as a defense to the model extraction vulnerabilities, and may perform actions based on results of one or more of the assessments.