Watermark Unit Configuration for AI Model Authenticity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of effective digital rights protection for machine-learning models, and there is no proof that results produced by data processing accelerators are protected by a 'root of trust' system, making it difficult to verify the authenticity and authorization of AI models used in secondary processing systems.
Innovation Solution
A watermark unit is configured with watermark algorithms in data processing accelerators to embed digital rights protection into AI models, allowing for verification and authentication of the models before inference tasks, ensuring that only authorized models are used and that the results are trusted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If watermark algorithms are embedded into AI models for digital rights protection, then the authenticity and authorization verification capability is improved, but the device complexity increases
Solution Approach 1:
The patent divides the watermarking functionality into a separate watermark unit within the data processing accelerator, independent from the main AI model execution units. This segmentation allows the watermark algorithms to be configured and managed separately, reducing the complexity burden on the core AI processing architecture while maintaining verification capabilities.
Solution Approach 2:
The system performs preliminary configuration of the watermark unit with appropriate watermark algorithms before the AI model execution begins. The watermark unit is pre-configured with the necessary algorithms and parameters, so that when the AI model needs to be verified, the watermarking functionality is already in place and ready for immediate operation, avoiding complex runtime configuration decisions.
2Adaptability or versatility
If multiple watermark algorithms are supported for different AI model types, then the adaptability is improved, but the device complexity increases
Solution Approach 1:
The watermark unit is designed with dynamic configurability, allowing it to adapt to different AI model types and watermark algorithm requirements through runtime configuration rather than requiring separate hardwired paths for each algorithm type. This dynamic approach enables the system to support multiple algorithms while maintaining a unified, manageable architecture.
Solution Approach 2:
The watermark unit is designed as a universal module that can handle multiple types of watermark algorithms through a single unified interface. Rather than requiring separate dedicated units for different algorithm types, the universal watermark unit can be configured to execute various algorithms as needed, reducing overall system complexity while maintaining versatility.
Data Source
AI summary
Embodiments of the disclosure relate to configuring a watermark unit with watermark algorithms for artificial intelligence (AI) models for a data processing (DP) accelerator. In one embodiment, in response to a request received by a DP accelerator, the request, sent by an application, to apply a watermark algorithm to an AI model by the DP accelerator, a system determines that the watermark algorithm is not available at a watermark unit of the DP accelerator. The system sends a request for the watermark algorithm. The system receives the watermark algorithm by the DP accelerator. The system configures the watermark unit at runtime with the watermark algorithm for the watermark algorithm to be used by the DP accelerator.


