Private AI Model Fine-Tuning Using Trusted Execution Enclaves

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Training AI models on sensitive data poses privacy concerns, as it requires direct access to raw data, which may be unacceptable or illegal, and public datasets are often generic, biased, or malicious, leading to ineffective model performance.

Innovation Solution

A privacy-preserving method is provided where AI models are trained and fine-tuned using private data stored in secure data stores like Solid, ensuring secure access and fine-grained control, allowing users to maintain data privacy and relevance through personalized models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If AI models are trained on private data to achieve personalized and relevant results, then model performance and relevance are improved, but data privacy and security are compromised due to direct access requirements

Engineering Contradiction:
Improvemodel performanceVSAvoiddata privacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces trusted execution environments (TEEs) as intermediary hardware layers that enable secure data processing. The TEE creates an isolated enclave where private data can be accessed and processed by AI models without exposing the raw data to external parties. This mediator resolves the contradiction by allowing model training on private data while maintaining privacy through hardware-enforced security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the data access model by changing the security parameters from traditional encryption/decryption to hardware-based trusted execution. Instead of relying on software security measures, the system uses TEEs to fundamentally alter how data is protected during processing, enabling direct model access to private data while maintaining security through hardware trust roots and enclave isolation mechanisms.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If private data is accessed directly for model training, then training effectiveness is improved, but security and legal compliance deteriorate

Engineering Contradiction:
Improvetraining effectivenessVSAvoidsecurity compliance
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The TEE acts as a compliant intermediary that satisfies both training effectiveness and security compliance requirements. It provides a controlled environment where data can be processed for training while maintaining auditability and security guarantees required by regulations. The hardware-enforced boundaries ensure that data processing meets compliance standards while preserving training effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security setup by establishing TEE enclaves and configuring security policies before data processing begins. This preliminary action ensures that security and compliance requirements are built into the training process from the start, rather than being added as afterthoughts, thereby maintaining both training effectiveness and regulatory compliance.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If public datasets are used for model training to avoid privacy issues, then data security is improved, but model relevance and performance deteriorate due to generic and biased data

Engineering Contradiction:
Improvedata securityVSAvoidmodel relevance
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The TEE serves as a mediator that enables the use of private data without the security risks associated with traditional direct access. By providing a secure processing environment, it allows organizations to leverage their own private datasets for training, thereby achieving both data security and model relevance simultaneously, rather than having to choose between public and private data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables local customization of training data by allowing each organization to use their own private datasets within TEEs. This local quality approach ensures that models are trained on organization-specific data, improving relevance and reducing bias while maintaining security through the TEE's isolated processing environment.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If fine-tuning is performed on base models using private data, then model personalization is improved, but data exposure risk increases

Engineering Contradiction:
Improvemodel personalizationVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The TEE provides a secure intermediary environment for fine-tuning operations, allowing models to be personalized with private data without exposing the underlying sensitive information. The enclave architecture enables gradient computation and parameter updates during fine-tuning while keeping the private data confined within the secure boundary, thus achieving personalization without data exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The fine-tuning process is segmented into operations that occur within the TEE enclave and operations that occur outside. Only model parameters and gradients (not raw private data) are transferred between the enclave and external systems. This segmentation allows personalization to proceed while maintaining data privacy, as the sensitive data never leaves the secure enclave during the fine-tuning process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260065133A1Privacy-preserving access and use of AI models using private data sets
Publication Date: 2026.03.05 INRUPT INC
  • US20260065133A1 patent drawing
  • US20260065133A1 patent drawing
  • US20260065133A1 patent drawing

AI summary

A privacy-preserving method of accessing and using an AI model. That access and use is provided as a service in association with a linked data operating environment. In this environment, applications have secure and permissioned access in an interoperable manner to private data that is stored in one or more online private data stores. The AI model is trained using one or more access sets of private data that are stored in the linked data operating environment. Typically, the model (e.g., a language model, an image-generation (diffusion) model, or the like) is uniquely associated with an entity whose access set of private data is used for model training. To facilitate multi-use training and use, the model comprises a base model that is fine-tuned using the private data access set to generate a fine-tuned model. The fine-tuned model can be further tuned efficiently as data in the underlying access sets changes.