IP Library Granted Patent US 11,775,347
Granted Patent B2
US 11,775,347 · App. 16/598,129 · Granted Oct 3, 2023

Method for implanting a watermark in a trained artificial intelligence model for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06F9/5027G06F21/16G06N5/04G06N20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,775,347
App. No.
16/598,129
Filed
Oct 10, 2019
Granted
Oct 3, 2023
Kind
B2
Examiner
KIM, TAE K
Art Unit
2496
USPC
713/176
Abstract

In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator includes receiving, at the DP accelerator, first data representing an artificial intelligence (AI) model that has been previously trained from a host processor; receiving, at the DP accelerator, a request to implant a watermark in the AI model from the host processor; and implanting, by the DP accelerator, the watermark within the AI model. The DP accelerator then transmits second data representing the AI model having the watermark implanted therein to the host processor. In embodiment, the method further includes extracting, at the DP accelerator, a watermark algorithm identifier (ID) from the request to implant a watermark; and generating the watermark using a watermark algorithm identified by the watermark algorithm ID.

Claims (35)

1. A computer-implemented method performed by a data processing (DP) accelerator, the method comprising:

receiving, at the DP accelerator, first data representing an artificial intelligence (AI) model that has been previously trained from a host processor;

receiving, at the DP accelerator, a request to implant a watermark in the AI model from the host processor, the request including a watermark algorithm identifier (ID) selected by the host processor;

generating the watermark using a watermark algorithm identified by the watermark algorithm ID;

implanting, by the DP accelerator, the generated watermark within the AI model; and

transmitting second data representing the AI model having the watermark implanted therein to the host processor.

2. The method of claim 1 , further comprising:

extracting, at the DP accelerator, the watermark algorithm ID from the request to implant a watermark.

3. The method of claim 1 , wherein implanting the watermark in the AI model comprises embedding the watermark in one or more nodes of the AI model.

4. The method of claim 3 , wherein the watermark is stored in one or more weight variables of the one or more nodes of the AI model.

5. The method of claim 3 , wherein the watermark is stored in one or more bias variables of the one or more nodes of the AI model.

6. The method of claim 1 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

7. The method of claim 1 , wherein the receiving at the DP accelerator is over a link that comprises a peripheral component interconnect express (PCIe) channel.

8. A data processing (DP) accelerator, comprising:

an interface to receive first data representing an artificial intelligence (AI) model that has been previously trained and to receive a request to implant a watermark in the AI model from a host processor, the request including a watermark algorithm identifier (ID) selected by the host processor; and

a watermarking unit coupled to the interface to generate the watermarking using a watermark algorithm identified by the watermark algorithm ID, to implant the generated watermark within the AI model and to transmit second data representing the AI model having the watermark implanted therein to the host processor.

9. The DP accelerator of claim 8 , wherein the watermark unit comprises a watermark generator configured to:

extract the watermark algorithm ID from the request to implant a watermark; and.

10. The DP accelerator of claim 8 , wherein in implanting the watermark in the AI model, the watermark unit is configured to embed the watermark in one or more nodes of the AI model.

11. The DP accelerator of claim 10 , wherein the watermark is stored in one or more weight variables of the one or more nodes of the AI model.

12. The DP accelerator of claim 10 , wherein the watermark is stored in one or more bias variables of the one or more nodes of the AI model.

13. The DP accelerator of claim 8 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

14. The DP accelerator of claim 8 , wherein the receiving the previously trained AI model and transmitting the second data is performed over a link that comprises a peripheral component interconnect express (PCIe) channel.

15. A non-transitory machine-readable medium having instructions stored therein, which when executed by a data processing (DP) accelerator, cause the DP accelerator to perform operations, the operations comprising:

receiving, at the DP accelerator, first data representing an artificial intelligence (AI) model that has been previously trained from a host processor;

receiving, at the DP accelerator, a request to implant a watermark in the AI model from the host processor, the request including a watermark algorithm identifier (ID) selected by the host processor;

generating the watermark using a watermark algorithm identified by the watermark algorithm ID;

implanting, by the DP accelerator, the generated watermark within the AI model; and

transmitting second data representing the AI model having the watermark implanted therein to the host processor.

16. The machine-readable medium of claim 15 , wherein the operations further comprise:

extracting, at the DP accelerator, the watermark algorithm ID from the request to implant a watermark.

17. The machine-readable medium of claim 15 , wherein implanting the watermark in the AI model comprises embedding the watermark in one or more nodes of the AI model.

18. The machine-readable medium of claim 17 , wherein the watermark is stored in one or more weight variables of the one or more nodes of the AI model.

19. The machine-readable medium of claim 17 , wherein the watermark is stored in one or more bias variables of the one or more nodes of the AI model.

20. The machine-readable medium of claim 15 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 050690/0179 →
Continuity (1)
Related Publication 20210109790A1 · Apr 15, 2021
Cited By (1)
US 12,609,909