Model Attestation Checker for ML Decision Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine learning-based decision systems are vulnerable to hacking and manipulation, particularly in critical applications like autonomous driving and healthcare, where tampering with training data or models can lead to severe consequences, and existing security measures are inadequate to fully mitigate these risks.

Innovation Solution

Implementing a method that uses a model attestation checker to verify the trustworthiness of machine learning models and input data through digital signatures and data attestations, ensuring only trusted models and data are used for decision-making, and providing result attestations to ensure accountability and prevent causative attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If machine learning models are used for automated decision-making in critical applications, then productivity and automation are improved, but security and reliability deteriorate due to vulnerability to hacking and manipulation

Engineering Contradiction:
Improveautomation of decision tasksVSAvoidsecurity against hacking
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary security verification by checking digital signatures and attestations of machine learning models before they are deployed for decision-making. The model attestation checker verifies the integrity and authenticity of models in advance, preventing compromised models from being used in critical applications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a model attestation checker as an intermediary component between the machine learning model source and the decision-making system. This intermediary verifies the digital signatures and attestations of models, acting as a security gatekeeper that prevents unauthorized or manipulated models from affecting the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification measures are implemented to check model trustworthiness, then reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvemodel trustworthiness verificationVSAvoidsecurity verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security verification where the model attestation checker autonomously verifies digital signatures and attestations without requiring manual intervention. The system automatically checks the cryptographic signatures and validates model integrity, reducing operational complexity while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If digital signature verification is performed on all machine learning models, then security against causative attacks is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveprotection against causative attacksVSAvoidmodel verification time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The digital signature verification is performed preliminarily during model deployment or update phases, rather than during every inference operation. This preliminary checking ensures security against causative attacks while minimizing the time impact on actual decision-making operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11574245B2Method for securing a machine learning based decision system
Publication Date: 2023.02.07 THALES DIS FRANCE SA
  • US11574245B2 patent drawing
  • US11574245B2 patent drawing
  • US11574245B2 patent drawing

AI summary

A system configured to perform decision tasks carried out by a machine learning engine operates with a machine learning model, and includes a training component for improving the machine learning model, a device for carrying out decisions based on a set of input data, and an interaction interface for switching the machine learning model between training component and a device that includes a model attestation checker. The device performs acquiring input data, and ascertaining at least one machine learning model over the interaction interface. The model attestation checker performs checking if said machine learning model is trusted by a model attestation, and considering, for decision making, only those machine learning models that are trusted. The machine learning engine performs carrying out the decision task for input data by using a trusted machine learning model, and providing a result attestation for the decision output.