Protected Machine Learning Fine-Tuning Without Data Disclosure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users of a machine learning model who are not the owners of the base model or do not possess the tuning algorithm face challenges in fine-tuning the model without disclosing proprietary information to the tune initiator system.
Innovation Solution
A protected environment is used for fine-tuning, where the tune initiator system provides input via a visible channel and proprietary information is accessed via a non-visible channel, allowing the formation of a fine-tuned model without direct access by the initiator system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the tune initiator system has direct access to the base model and tuning algorithm for fine-tuning, then the fine-tuning process is efficient and straightforward, but proprietary information is disclosed to the tune initiator system
Solution Approach 1:
The patent introduces a trusted third-party platform as an intermediary that hosts the base model and tuning algorithm in a protected environment. This platform enables the fine-tuning process by mediating between the base model owner and the tune initiator system, allowing the initiator to provide training data and receive fine-tuned models without direct access to proprietary information. The intermediary resolves the contradiction by facilitating efficient collaboration while maintaining security through controlled access mechanisms.
2Adaptability or versatility
If the base model provider shares proprietary information with the tune initiator system, then collaboration is enabled, but security and protection of proprietary data are compromised
Solution Approach 1:
The patent segments the fine-tuning process into distinct components that can be executed in a protected environment. The base model, tuning algorithm, and training data are separated and processed through controlled interfaces. This segmentation allows collaboration by enabling each party to contribute their respective components while maintaining security through isolated execution environments that prevent unauthorized access to proprietary information.
Solution Approach 2:
The patent creates a protected, isolated environment (analogous to an inert atmosphere) where the base model and tuning algorithm reside during the fine-tuning process. This secure environment acts as a sandbox that allows collaboration activities to occur without exposing proprietary information to external threats or unauthorized access, thereby maintaining data security while enabling versatile collaboration.
3Reliability
If a protected environment is used for fine-tuning with non-visible channels, then proprietary information is protected, but system complexity increases
Solution Approach 1:
The trusted third-party platform serves as an intermediary that manages the complexity of the protected environment infrastructure. By centralizing security management, access control, and environment provisioning functions in the intermediary, the patent reduces the burden on individual participants while maintaining robust protection for proprietary information. The intermediary absorbs the system complexity, allowing users to benefit from security without directly managing the complex infrastructure.
Data Source
AI summary
The fine-tuning of a machine learning model in a protected environment. Input (e.g., training data) received from the tune initiator system that instructs the tuning occur is received over a channel that is visible to the tune initiator system. Proprietary input is received from another party over a secure connection that is not visible to the tune initiator system. These inputs are then used to fine-tune a machine learning model to thereby form a fine-tuned machine learning model. The resulting fine-tuned machine learning model is then stored in the protected environment such that the fine-tuned machine learning model is available for the tune initiator system to provide input data to and receive output data from, but such that the tuned model cannot be directly accessed by the tune initiator system.


