Watermark-Enabled Kernel for AI Model Digital Rights Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of effective digital rights protection for artificial intelligence models, and there is no proof that the results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to ensure the authenticity and trustworthiness of AI model inferences.

Innovation Solution

The implementation of a watermarking system within AI models, where a watermark is embedded or inherited during training and inference processes, allowing the host device to validate the AI model's authenticity and associate inferences with the correct model source, using watermark-enabled kernels that can extract, implant, or inherit watermarks without affecting the model's functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If AI models are deployed for processing tasks, then productivity and functionality are improved, but digital rights protection and authenticity verification are insufficient

Engineering Contradiction:
ImproveAI model processing capabilityVSAvoiddigital rights protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A watermark is embedded into the AI model during the training phase before deployment. This preliminary action ensures that authenticity verification capability is built into the model itself, allowing reliable digital rights protection without affecting the model's processing productivity when deployed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If AI models are ported and utilized without authorization, then ease of operation is improved, but security and control are worsened

Engineering Contradiction:
ImproveAI model portabilityVSAvoidunauthorized use
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A watermark acts as an intermediary identifier embedded in the AI model. It enables tracking and verification of model usage without restricting portability. The watermark allows authorized operations while providing detection capability for unauthorized use, thus maintaining ease of operation while reducing harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If processing tasks are delegated to secondary systems, then productivity is improved, but trust verification is worsened

Engineering Contradiction:
Improveprocessing throughputVSAvoidroot of trust verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The watermark is nested within the AI model structure itself, embedded in the model's parameters or architecture. This nested verification mechanism travels with the model when delegated to secondary systems, enabling trust verification at any processing location without compromising productivity.

Inventive Principle:
Principle #7Nested doll (Nesting)

4Reliability

If watermarks are embedded in AI models, then digital rights protection is improved, but model complexity increases

Engineering Contradiction:
Improveauthenticity verificationVSAvoidmodel structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The watermark is embedded locally in specific regions of the model parameter space or in dedicated watermark layers, rather than uniformly throughout the entire model. This localized approach provides authenticity verification capability while minimizing impact on overall model structure and complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11709712B2Method and system for artificial intelligence model training using a watermark-enabled kernel for a data processing accelerator
Publication Date: 2023.07.25 BAIDU USA LLC
  • US11709712B2 patent drawing
  • US11709712B2 patent drawing
  • US11709712B2 patent drawing

AI summary

In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator, includes receiving, at the DP accelerator, first data representing a set of training data from a host processor; receiving, at the DP accelerator, a watermark kernel from the host processor; and executing the watermark kernel within the DP accelerator on an artificial intelligence (AI) model. The watermark kernel, when executed, is configured to: generate a new watermark by inheriting an existing watermark from a data object of the set of training data, train the AI model using the set of training data, and implant the new watermark within the AI model during training of the AI model. The DP accelerator then transmits second data representing the trained AI model having the new watermark implanted therein to the host processor.