IP Library Granted Patent US 11,588,796
Granted Patent B2
US 11,588,796 · App. 16/568,127 · Granted Feb 21, 2023

Data transmission with obfuscation for a data processing (DP) accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Hefei Zhu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
H04L63/0435G06N5/04H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,796
App. No.
16/568,127
Granted
Feb 21, 2023
Kind
B2
Abstract

According to one embodiment, a host communicates with a data processing (DP) accelerator using an obfuscation scheme. The DP accelerator receives an obfuscation kernel algorithm (or obfuscation algorithm), where the obfuscation kernel algorithm is used to obfuscate and de-obfuscate data in communication with a host. The DP accelerator de-obfuscates, using the obfuscation kernel algorithm, obfuscated data received from the host for a prediction request to obtain one or more AI models. The DP accelerator generates prediction results by applying the one or more AI models to a prediction input. The DP accelerator obfuscates, using the obfuscation kernel algorithm, the prediction results. The DP accelerator sends the obfuscated prediction results to the host, where the host retrieves the prediction results by de-obfuscating the obfuscated prediction results.

Claims (41)

1. A method to de-obfuscate data, the method comprising:

receiving, by a data processing (DP) accelerator, an obfuscation kernel algorithm, wherein the obfuscation kernel algorithm is used to obfuscate and de-obfuscate data in communication with a host over a link;

de-obfuscating, using the obfuscation kernel algorithm, obfuscated data received from the host for a prediction request to obtain one or more artificial intelligence (AI) models, wherein the obfuscated data comprises the one or more AI models that are obfuscated based on the obfuscation kernel algorithm and the obfuscated one or more AI models are sent by the host for the prediction request, wherein the obfuscation kernel algorithm includes a symmetric algorithm or an asymmetric algorithm to obscure the one or more AI models in communication, wherein the obfuscation kernel algorithm comprises at least one of: letter obfuscation, name obfuscation, data obfuscation, or control flow obfuscation;

generating prediction results by applying the one or more AI models to a prediction input;

obfuscating, using the obfuscation kernel algorithm, the prediction results; and

sending the obfuscated prediction results to the host over the link, wherein the host retrieves the prediction results by de-obfuscating the obfuscated prediction results.

2. The method of claim 1 , wherein the obfuscation kernel algorithm is generated by the host.

3. The method of claim 1 , wherein the obfuscation kernel algorithm is received on a dedicated communication channel different than a data channel for communicating the obfuscated data.

4. The method of claim 1 , wherein the obfuscated data comprises training input data and the one or more AI models is trained using the training input data.

5. The method of claim 1 , wherein the obfuscation kernel algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.

6. The method of claim 1 , wherein the obfuscation kernel algorithm is a name based obfuscation algorithm.

7. The method of claim 1 , further comprising:

receiving a request for one or more AI models from the host;

obfuscating the requested one or more AI models; and

sending the obfuscated AI models to the host, wherein the host is to retrieve the AI models by de-obfuscating the obfuscated AI models.

8. A method to obfuscate data, the method comprising:

generating, at a host, a prediction request to perform an artificial intelligence (AI) prediction by a data processing (DP) accelerator using one or more AI models, wherein the prediction request includes an obfuscated data obfuscating the one or more AI models based on an obfuscation kernel algorithm, wherein the obfuscation kernel algorithm includes a symmetric algorithm or an asymmetric algorithm to obscure the one or more AI models in communication, wherein the obfuscation kernel algorithm comprises at least one of: letter obfuscation, name obfuscation, data obfuscation, or control flow obfuscation;

sending the obfuscation kernel algorithm and the prediction request to the DP accelerator over a link, wherein the prediction request includes the obfuscated one or more AI models and the obfuscated data is de-obfuscated by the DP accelerator, using the obfuscation kernel algorithm, to obtain the one or more AI models to generate prediction results, wherein the prediction results are obfuscated, using the obfuscation kernel algorithm, by the DP accelerator;

receiving the obfuscated prediction results from the DP accelerator over the link; and

de-obfuscating the obfuscated prediction results to retrieve the prediction results.

9. The method of claim 8 , wherein the obfuscation kernel algorithm is generated by the host.

10. The method of claim 8 , wherein the obfuscation kernel algorithm is transmitted on a dedicated communication channel different than a data channel for communicating the obfuscated data.

11. The method of claim 8 , wherein the obfuscated data comprises training input data and the one or more AI models is trained using the training input data.

12. The method of claim 8 , wherein the obfuscation kernel algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.

13. The method of claim 8 , wherein the obfuscation kernel algorithm is a name based obfuscation algorithm.

14. The method of claim 8 , further comprising:

generating a request to retrieve one or more AI models from the DP accelerator;

sending the request to the DP accelerator;

receiving obfuscated data representing the one or more AI models from the DP accelerator; and

de-obfuscating the obfuscated AI models to retrieve the AI models.

15. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:

receiving, by a data processing (DP) accelerator, an obfuscation kernel algorithm, wherein the obfuscation kernel algorithm is used to obfuscate and de-obfuscate data in communication with a host over a link;

de-obfuscating, using the obfuscation kernel algorithm, obfuscated data received from the host for a prediction request to obtain one or more artificial intelligence (AI) models, wherein the obfuscated data comprises the one or more AI models that are obfuscated based on the obfuscation kernel algorithm and the obfuscated one or more AI models are sent by the host for the prediction request, wherein the obfuscation kernel algorithm includes a symmetric algorithm or an asymmetric algorithm to obscure the one or more AI models in communication, wherein the obfuscation kernel algorithm comprises at least one of: letter obfuscation, name obfuscation, data obfuscation, or control flow obfuscation;

generating prediction results by applying the one or more AI models to a prediction input;

obfuscating, using the obfuscation kernel algorithm, the prediction results; and

sending the obfuscated prediction results to the host, wherein the host retrieves the prediction results by de-obfuscating the obfuscated prediction results.

16. The non-transitory machine-readable medium of claim 15 , wherein the obfuscation kernel algorithm is generated by the host.

17. The non-transitory machine-readable medium of claim 15 , wherein the obfuscation kernel algorithm is received on a dedicated communication channel different than a data channel for communicating the obfuscated data.

18. The non-transitory machine-readable medium of claim 15 , wherein the obfuscated data comprises training input data and the one or more AI models is trained using the training input data.

19. The non-transitory machine-readable medium of claim 15 , wherein the obfuscation kernel algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.

20. The non-transitory machine-readable medium of claim 15 , wherein the obfuscation kernel algorithm is a name based obfuscation algorithm.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2019
From: CHENG, YUEQIANG; ZHU, HEFEI
To: BAIDU USA LLC
Reel/Frame 050387/0913 →
Continuity (1)
Related Publication 20210075775A1 · Mar 11, 2021
Cited By (1)
US 12,717,908