Watermark-Enabled Kernel for AI Model Digital Rights Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of effective digital rights protection for artificial intelligence models, and there is no proof that the results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to ensure the authenticity and trustworthiness of AI model inferences.
Innovation Solution
The implementation of a watermarking system within AI models, where a watermark is embedded or inherited during training and inference processes, allowing the host device to validate the AI model's authenticity and associate inferences with the correct model source, using watermark-enabled kernels that can extract, implant, or inherit watermarks without affecting the model's functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If AI models are deployed for processing tasks, then productivity and functionality are improved, but digital rights protection and authenticity verification are insufficient
Solution Approach 1:
A watermark is embedded into the AI model during the training phase before deployment. This preliminary action ensures that authenticity verification capability is built into the model itself, allowing reliable digital rights protection without affecting the model's processing productivity when deployed.
2Ease of operation
If AI models are ported and utilized without authorization, then ease of operation is improved, but security and control are worsened
Solution Approach 1:
A watermark acts as an intermediary identifier embedded in the AI model. It enables tracking and verification of model usage without restricting portability. The watermark allows authorized operations while providing detection capability for unauthorized use, thus maintaining ease of operation while reducing harmful factors.
3Productivity
If processing tasks are delegated to secondary systems, then productivity is improved, but trust verification is worsened
Solution Approach 1:
The watermark is nested within the AI model structure itself, embedded in the model's parameters or architecture. This nested verification mechanism travels with the model when delegated to secondary systems, enabling trust verification at any processing location without compromising productivity.
4Reliability
If watermarks are embedded in AI models, then digital rights protection is improved, but model complexity increases
Solution Approach 1:
The watermark is embedded locally in specific regions of the model parameter space or in dedicated watermark layers, rather than uniformly throughout the entire model. This localized approach provides authenticity verification capability while minimizing impact on overall model structure and complexity.
Data Source
AI summary
In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator, includes receiving, at the DP accelerator, first data representing a set of training data from a host processor; receiving, at the DP accelerator, a watermark kernel from the host processor; and executing the watermark kernel within the DP accelerator on an artificial intelligence (AI) model. The watermark kernel, when executed, is configured to: generate a new watermark by inheriting an existing watermark from a data object of the set of training data, train the AI model using the set of training data, and implant the new watermark within the AI model during training of the AI model. The DP accelerator then transmits second data representing the trained AI model having the new watermark implanted therein to the host processor.


