Security-Aware ML Model Pruning for Edge AI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge computing devices face challenges in supporting machine learning and artificial intelligence models due to resource constraints and increased vulnerability to cyberattacks, as conventional compression techniques prioritize size and performance over security, making them more susceptible to attacks.

Innovation Solution

The implementation of a security-aware compression method that leverages cybersecurity threat models to iteratively prune machine learning and artificial intelligence models, ensuring risk metrics are satisfied while maintaining performance, using a server that can operate with or without pre-installed operating systems or specific libraries, and supports executable file packages for multi-platform use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Volume of moving object

If conventional compression techniques are used to reduce model size for edge devices, then model complexity is reduced and size is decreased, but security vulnerability increases

Engineering Contradiction:
Improvemodel sizeVSAvoidsecurity vulnerability
Core Design Contradiction:
Volume of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by conducting security assessments and risk analyses before the model compression process. The system evaluates potential security vulnerabilities and establishes security constraints beforehand, then uses this information to guide the pruning process to remove only safe components while preserving security-critical parts of the model.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by continuously monitoring security metrics during the iterative pruning process. The system assesses security risk at each iteration and uses this feedback to adjust subsequent pruning decisions, ensuring that security requirements are maintained throughout the compression process.

Inventive Principle:
Principle #23Feedback

2Productivity

If model pruning is performed to compress ML/AI models for edge devices, then resource constraints are satisfied, but the models become more vulnerable to cyberattacks

Engineering Contradiction:
Improveresource efficiencyVSAvoidmodel security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies parameter changes by modifying the pruning process itself based on security parameters. The system changes how pruning is performed by incorporating security-aware heuristics and constraints, transforming the traditional compression approach into a security-conscious process that maintains reliability while improving resource efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary security assessments to identify which model components are critical for security before pruning begins. This allows the system to prioritize preservation of security-critical components while safely removing non-essential parts, achieving resource efficiency without compromising reliability.

Inventive Principle:
Principle #10Preliminary action

3Volume of moving object

If iterative pruning is performed to achieve compression, then model size decreases, but computational resources required for security assessment increase

Engineering Contradiction:
Improvemodel sizeVSAvoidcomputational resource consumption
Core Design Contradiction:
Volume of moving objectVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by performing security assessments on only the most critical model components rather than the entire model at each iteration. The system selectively evaluates security risks in pruned portions and uses this partial assessment to guide further pruning, reducing overall computational resource consumption while maintaining effective compression.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230289604A1Systems and methods for securing artificial intelligence systems for edge computing systems
Publication Date: 2023.09.14 ACCENTURE GLOBAL SOLUTIONS LTD
  • US20230289604A1 patent drawing
  • US20230289604A1 patent drawing
  • US20230289604A1 patent drawing

AI summary

Aspects of the present disclosure provide systems, methods, and computer-readable storage media that support security-aware compression of machine learning (ML) and/or artificial intelligence (AI) models, such as for use by edge computing systems. Aspects described herein leverage cybersecurity threat models, particularly models of ML/AI-based threats, during iterative pruning to improve security of compressed ML models. To illustrate, iterative pruning may be performed on a pre-trained ML model until stop criteria are satisfied. This iterative pruning may include pruning an input ML model based on pruning heuristic(s) to generate a candidate ML model, testing the candidate ML model based on attack model(s) to generate risk assessment metrics, and updating the heuristic(s) based on the risk assessment metrics. If the risk assessment metrics fail to satisfy the stop criteria, the candidate ML model may be provided as input to a next iteration of the iterative pruning.