IP Library Granted Patent US 11,409,845
Granted Patent B2
US 11,409,845 · App. 16/250,074 · Granted Aug 9, 2022

Method for determining if a machine learning model has been copied

Inventors: Nikita Veshchikov (Brussels, BE); Joppe Willem Bos (Wijgmaal, BE); Simon Johann Friedberger (Heverlee, BE)
Assignee: NXP B.V.
G06F21/12G06K9/6259G06N20/00G06F11/10G06F2221/0724H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,845
App. No.
16/250,074
Filed
Jan 17, 2019
Granted
Aug 9, 2022
Kind
B2
Art Unit
2114
USPC
706/20
Abstract

A method is provided for detecting copying of a machine learning model. A plurality of inputs is provided to a first machine learning model. The first machine learning model provides a plurality of output values. A sequence of bits of a master input is divided into a plurality of subsets of bits. The master input may be an image. Each subset of the plurality of subsets of bits corresponds to one of the plurality of output values. An ordered sequence of the inputs is generated based on the plurality of subsets of bits. The ordered sequence of the inputs is inputted to a second machine learning model. It is then determined if output values from the second machine learning model reproduces the predetermined master input. If the predetermined master input is reproduced, the second machine learning model is a copy of the first machine learning model.

Claims (47)

1. A method for detecting copying of a machine learning model, the method comprising:

inputting a plurality of inputs into a first machine learning model, and in response, the first machine learning model providing a plurality of output values;

generating a sequence of bits to represent a predetermined master input;

dividing the sequence of bits into a plurality of subsets of bits, wherein each subset of the plurality of subsets of bits corresponds to one of the plurality of output values;

generating an ordered sequence of the inputs based on the plurality of subsets of bits;

inputting the ordered sequence of inputs to a second machine learning model, and in response, receiving an output value from the second machine learning model for each input of the ordered sequence of inputs; and

determining if the output values from the second machine learning model reproduces the predetermined master input, wherein if the predetermined master input is reproduced, the second machine learning model is a copy of the first machine learning model.

2. The method of claim 1 , wherein the predetermined master input comprises one of an image, music, text, or video.

3. The method of claim 1 , wherein dividing the sequence of bits further comprises applying an error correction code to the sequence of bits.

4. The method of claim 3 , wherein the error correction code is one of Hamming code, Reed-Solomon error correction code, and Walsh-Hadamard code.

5. The method of claim 1 , further comprising:

applying a one-way function to the sequence of bits to produce a seal;

adding a date and time stamp to the seal; and

making the seal unmodifiable.

6. The method of claim 5 , wherein making the seal unmodifiable further comprises inserting the seal into a blockchain.

7. The method of claim 1 , wherein the machine learning model is a classification type of machine learning model.

8. The method of claim 1 , wherein the plurality of output values is a plurality of probabilities that the first machine learning model is providing correct results.

9. The method of claim 1 , wherein the plurality of output values is a plurality of categories for classifying the plurality of inputs.

10. A method for detecting copying of a first machine learning model, the method comprising:

categorizing a plurality of non-problem domain inputs into a plurality of categories using the first machine learning model, the plurality of categories represented by a corresponding plurality of output values, wherein each of the plurality of non-problem domain inputs is assigned to one of the plurality of categories;

generating a sequence of bits to represent a predetermined master input;

dividing the sequence of bits into a plurality of subsets of bits, wherein each subset of the plurality of subsets of bits corresponds to one of the plurality of output values;

generating an ordered sequence of the non-problem domain inputs based on the plurality of subsets of bits;

inputting the ordered sequence of the non-problem domain inputs to a second machine learning model, and in response, receiving an output category value from the second machine learning model for each of the ordered sequence of the non-problem domain inputs; and

determining if the output category values reproduces the predetermined master input.

11. The method of claim 10 , wherein the predetermined master input comprises one of an image, music, text, and video.

12. The method of claim 10 , wherein generating a sequence of bits to represent a predetermined master input further comprises applying an error correction code to the sequence of bits.

13. The method of claim 10 , further comprising:

applying a one-way function to the sequence of bits to produce a seal;

adding a date and time stamp to the seal; and

making the seal unmodifiable.

14. The method of claim 13 , wherein making the seal unmodifiable further comprises inserting the seal into a blockchain.

15. The method of claim 10 , wherein determining if the output category values reproduce the predetermined master input further comprises determining that the second machine learning model is a copy of the first machine learning model if the predetermined master input is reproduced.

16. A method for detecting copying of a first machine learning model, the method comprising:

inputting a plurality of non-problem domain inputs into the first machine learning model, and in response, the first machine learning model providing a plurality of output values;

generating a sequence of bits to represent a predetermined master input;

dividing the sequence of bits into a plurality of subsets of bits, wherein each subset of the plurality of subsets of bits corresponds to one of the plurality of output values;

generating an ordered sequence of the non-problem domain objects based on the plurality of subsets of bits;

inputting the ordered sequence of the non-problem domain inputs to a second machine learning model, and in response, receiving an output value from the second machine learning model for each input of the ordered sequence of the non-problem domain inputs;

determining if the output values received from the second machine learning model reproduces the predetermined master input;

applying a one-way function to the sequence of bits to produce a seal;

adding a date and time stamp to the seal; and

making the seal unmodifiable.

17. The method of claim 16 , wherein making the seal unmodifiable further comprises inputting the seal into a blockchain.

18. The method of claim 16 , wherein determining if the output values from the second machine learning model reproduce the predetermined master input further comprises determining that the second machine learning model is a copy of the first machine learning model if the predetermined master input is reproduced.

19. The method of claim 16 , wherein generating a sequence of bits to represent a predetermined master input further comprises applying an error correction code to the sequence of bits.

20. The method of claim 19 , wherein the error correction code is one of Hamming code, Reed-Solomon error correction code, and Walsh-Hadamard code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2019
From: VESHCHIKOV, NIKITA; BOS, JOPPE WILLEM; FRIEDBERGER, SIMON JOHANN
To: NXP B.V.
Reel/Frame 048045/0678 →
Continuity (1)
Related Publication 20200233936A1 · Jul 23, 2020
Cited By (1)
US 12,346,417