DATA TRANSMISSION WITH OBFUSCATION USING AN OBFUSCATION UNIT FOR A DATA PROCESSING (DP) ACCELERATOR
According to one embodiment, a host communicates with a data processing (DP) accelerator using an obfuscation scheme. The DP accelerator receives a training request from a host, the training request includes an obfuscated data that includes one or more AI models and/or training input data. The DP accelerator de-obfuscates, by an obfuscation unit of the DP accelerator, the obfuscated data to obtain the one or more AI models. The DP accelerator trains the one or more AI models based on the training input data.
1 . A method to de-obfuscate data, the method comprising:
receiving, by an data processing (DP) accelerator, a training request from a host over a link, the training request comprises an obfuscated data that includes one or more artificial intelligence (AI) models and/or training input data;
de-obfuscating, by an obfuscation unit of the DP accelerator, the obfuscated data to obtain the one or more AI models; and
training the one or more AI models based on the training input data.
2 . The method of claim 1 , further comprising:
selecting one of a plurality of obfuscation algorithms supported by the obfuscation unit; and
de-obfuscating, by a processor of the obfuscation unit, obfuscated data based on the selected obfuscation algorithm.
3 . The method of claim 2 , wherein the processor of the obfuscation unit is separate from a processor of the DP accelerator such that an obfuscation algorithm can be executed concurrently with execution of an AI model training.
4 . The method of claim 1 , wherein the obfuscated data comprises training input data and the AI model is trained based on the training input data.
5 . The method of claim 1 , wherein the obfuscation kernel algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.
6 . The method of claim 1 , wherein the obfuscation kernel algorithm is a control flow obfuscation algorithm.
7 . The method of claim 1 , further comprising:
receiving a request for one or more AI models from the host;
obfuscating, by the obfuscation unit, the requested one or more AI models; and
sending the obfuscated AI models to the host, wherein the host is to retrieve the AI models by de-obfuscating the obfuscated AI models.
8 . A method to obfuscate data, the method comprising:
generating, by a host, obfuscated data by obfuscating one or more artificial intelligence (AI) models and/or training input data;
generating a training request to perform an AI model training by a data processing (DP) accelerator, wherein the training request includes the obfuscated data; and
sending the training request to the DP accelerator, wherein an obfuscation unit of the DP accelerator applies an obfuscation algorithm to obtain the one or more AI models and/or training input data, wherein the one or more AI models is trained using the training input data.
9 . The method of claim 8 , further comprising receiving a training result from the DP accelerator.
10 . The method of claim 8 , further comprising selecting the obfuscation algorithm as one of a plurality of obfuscation algorithms supported by the obfuscation unit of the DP accelerator, wherein obfuscation or de-obfuscation is processed by a processor of the obfuscation unit of the DP accelerator using the selected obfuscation algorithm.
11 . The method of claim 8 , wherein the processor of the obfuscation unit is separate from a processor of the DP accelerator such that an obfuscation algorithm can be executed concurrently with execution of an AI model training.
12 . The method of claim 8 , wherein the obfuscation algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.
13 . The method of claim 8 , wherein the obfuscation kernel algorithm is a control flow obfuscation algorithm.
14 . The method of claim 8 , further comprising:
generating a request to retrieve one or more AI models from the DP accelerator;
receiving an obfuscated data representing obfuscated one or more AI models from the DP accelerator, wherein the host by de-obfuscating the obfuscated AI model; and
receiving an indication for an obfuscation algorithm from a plurality of obfuscation algorithm supported by the obfuscation unit of the DP accelerator;
de-obfuscating the obfuscated AI models to retrieve the AI models based on the indication.
15 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:
receiving, by an data processing (DP) accelerator, a training request from a host over a link, the training request comprises an obfuscated data that includes one or more artificial intelligence (AI) models and/or training input data;
de-obfuscating, by an obfuscation unit of the DP accelerator, the obfuscated data to obtain the one or more AI models; and
training the one or more AI models based on the training input data.
16 . The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise:
selecting one of a plurality of obfuscation algorithms supported by the obfuscation unit; and
de-obfuscating, by a processor of the obfuscation unit, obfuscated data based on the selected obfuscation algorithm.
17 . The method of claim 16 , wherein the processor of the obfuscation unit is separate from a processor of the DP accelerator such that an obfuscation algorithm can be executed concurrently with execution of an AI model training.
18 . The method of claim 15 , wherein the obfuscated data comprises training input data and the AI model is trained based on the training input data.
19 . The method of claim 15 , wherein the obfuscation kernel algorithm is a symmetric algorithm such that the same algorithm is used for both de-obfuscation and obfuscation.
20 . The method of claim 15 , wherein the obfuscation kernel algorithm is a control flow obfuscation algorithm.