Watermark-Enabled Kernel for AI Inference Rights Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of effective digital rights protection for artificial intelligence models and a lack of proof that results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to ensure the authenticity and trustworthiness of AI model inferences.

Innovation Solution

The implementation of a watermarking system within AI models, where a watermark is embedded or inherited during training or inference processes, allowing the host device to validate the AI model's authenticity and associate inferences with the correct model, using a watermark-enabled kernel that can extract, implant, or inherit watermarks without affecting the model's performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If AI models are made portable and delegatable to secondary processing systems, then AI technology deployment flexibility is improved, but digital rights protection and trustworthiness of inferences deteriorate

Engineering Contradiction:
ImproveAI model portabilityVSAvoiddigital rights protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A watermarking system is introduced as an intermediary mechanism that embeds identifiable markers within AI model parameters and inference results. This watermark acts as a mediator that enables tracking and verification of AI model usage across different deployment environments, thereby maintaining digital rights protection while preserving model portability. The watermark is embedded in the AI model before deployment and can be extracted from inference outputs to verify authenticity and provenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Power

If AI models are delegated to remote systems or DP accelerators, then processing capability is improved, but proof of root of trust protection deteriorates

Engineering Contradiction:
Improveprocessing capabilityVSAvoidroot of trust proof
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

The system implements a feedback mechanism where watermarks embedded in the AI model are extracted from inference results and used to verify the authenticity and provenance of the processing. This closed-loop feedback enables the host system to confirm that the remote DP accelerator or cloud system is executing the authorized AI model, thereby maintaining root of trust proof even when processing capability is offloaded to external systems.

Inventive Principle:
Principle #23Feedback

3Reliability

If watermarking systems are implemented in AI models, then digital rights protection is improved, but model performance may deteriorate

Engineering Contradiction:
Improvedigital rights protectionVSAvoidmodel performance
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The watermarking system applies local quality modification by embedding watermarks in specific, localized regions of the AI model parameters rather than uniformly across the entire model. This selective embedding approach ensures that the watermark is integrated in a way that minimizes interference with the model's functional parameters, thereby maintaining high model performance while achieving effective digital rights protection through targeted watermark placement.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11645116B2Method and system for making an artificial intelligence inference using a watermark-enabled kernel for a data processing accelerator
Publication Date: 2023.05.09 BAIDU USA LLC
  • US11645116B2 patent drawing
  • US11645116B2 patent drawing
  • US11645116B2 patent drawing

AI summary

In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator, includes receiving, at the DP accelerator, first data representing an artificial intelligence (AI) model that has been previously trained from a host processor and a set of input data; receiving, at the DP accelerator, a watermark kernel from the host processor; and executing the watermark kernel within the DP accelerator on the AI model. The watermark kernel, when executed, is configured to: perform inference operations of the artificial intelligence model based on the input data to generate output data, and implant the watermark within the output data. The DP accelerator then transmits the output data having the watermark implanted therein to the host processor.