Protected Machine Learning Fine-Tuning Without Data Disclosure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of a machine learning model who are not the owners of the base model or do not possess the tuning algorithm face challenges in fine-tuning the model without disclosing proprietary information to the tune initiator system.

Innovation Solution

A protected environment is used for fine-tuning, where the tune initiator system provides input via a visible channel and proprietary information is accessed via a non-visible channel, allowing the formation of a fine-tuned model without direct access by the initiator system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the tune initiator system has direct access to the base model and tuning algorithm for fine-tuning, then the fine-tuning process is efficient and straightforward, but proprietary information is disclosed to the tune initiator system

Engineering Contradiction:
Improvefine-tuning efficiencyVSAvoidproprietary information disclosure
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces a trusted third-party platform as an intermediary that hosts the base model and tuning algorithm in a protected environment. This platform enables the fine-tuning process by mediating between the base model owner and the tune initiator system, allowing the initiator to provide training data and receive fine-tuned models without direct access to proprietary information. The intermediary resolves the contradiction by facilitating efficient collaboration while maintaining security through controlled access mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the base model provider shares proprietary information with the tune initiator system, then collaboration is enabled, but security and protection of proprietary data are compromised

Engineering Contradiction:
Improvecollaboration capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the fine-tuning process into distinct components that can be executed in a protected environment. The base model, tuning algorithm, and training data are separated and processed through controlled interfaces. This segmentation allows collaboration by enabling each party to contribute their respective components while maintaining security through isolated execution environments that prevent unauthorized access to proprietary information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a protected, isolated environment (analogous to an inert atmosphere) where the base model and tuning algorithm reside during the fine-tuning process. This secure environment acts as a sandbox that allows collaboration activities to occur without exposing proprietary information to external threats or unauthorized access, thereby maintaining data security while enabling versatile collaboration.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If a protected environment is used for fine-tuning with non-visible channels, then proprietary information is protected, but system complexity increases

Engineering Contradiction:
Improveproprietary data protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted third-party platform serves as an intermediary that manages the complexity of the protected environment infrastructure. By centralizing security management, access control, and environment provisioning functions in the intermediary, the patent reduces the burden on individual participants while maintaining robust protection for proprietary information. The intermediary absorbs the system complexity, allowing users to benefit from security without directly managing the complex infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250225232A1Protected fine-tuning of a machine learning model
Publication Date: 2025.07.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250225232A1 patent drawing
  • US20250225232A1 patent drawing
  • US20250225232A1 patent drawing

AI summary

The fine-tuning of a machine learning model in a protected environment. Input (e.g., training data) received from the tune initiator system that instructs the tuning occur is received over a channel that is visible to the tune initiator system. Proprietary input is received from another party over a secure connection that is not visible to the tune initiator system. These inputs are then used to fine-tune a machine learning model to thereby form a fine-tuned machine learning model. The resulting fine-tuned machine learning model is then stored in the protected environment such that the fine-tuned machine learning model is available for the tune initiator system to provide input data to and receive output data from, but such that the tuned model cannot be directly accessed by the tune initiator system.