IP Library Granted Patent US 11,740,940
Granted Patent B2
US 11,740,940 · App. 16/598,318 · Granted Aug 29, 2023

Method and system for making an artifical intelligence inference using a watermark-inherited kernel for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06F9/5027G06F21/16G06N5/04G06N20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,740,940
App. No.
16/598,318
Filed
Oct 10, 2019
Granted
Aug 29, 2023
Kind
B2
Examiner
KIM, TAE K
Art Unit
2496
USPC
713/176
Abstract

In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator, includes receiving, at the DP accelerator, an artificial intelligence (AI) model that has been previously trained and a set of input data from a host processor; receiving, at the DP accelerator, a watermark kernel from the host processor; executing the watermark kernel within the DP accelerator on the AI model and the set of input data. The watermark kernel, when executed, is configured to: generate a new watermark by inheriting an existing watermark from a data object of the set of input data or the AI model, perform an AI inference using the AI model based on the input data to generate output data, and implant the new watermark within the output data. The DP accelerator then transmits output data having the new watermark implanted therein to the host processor.

Claims (46)

1. A computer-implemented method performed by a data processing (DP) accelerator, the method comprising:

receiving, at the DP accelerator from a host processor, an artificial intelligence (AI) model that has been previously trained and a set of input data;

receiving, at the DP accelerator from the host processor, a watermark kernel that is capable of inheriting a watermark;

executing the watermark kernel within the DP accelerator on the AI model and the set of input data, wherein the watermark kernel, when executed, is configured to:

generate a new watermark by inheriting an existing watermark from a data object of the set of input data or the AI model, wherein the watermark kernel is configured to:

extract the existing watermark from the data object of the set of input data or the AI model to obtain an inherited watermark, the existing watermark embedded in the received AI model or the set of input data; and

generate the new watermark using the inherited watermark,

perform an AI inference using the AI model based on the input data to generate output data, and

implant the new watermark within the output data; and

transmitting output data having the new watermark implanted therein to the host processor.

2. The method of claim 1 , wherein the existing watermark is embedded in one or more nodes of the artificial intelligence model.

3. The method of claim 2 , wherein the existing watermark is stored in one or more weight variables of the one or more nodes of the AI model.

4. The method of claim 2 , wherein the existing watermark is stored in one or more bias variables of the one or more nodes of the AI model.

5. The method of claim 1 , wherein the existing watermark is embedded in the set of input data.

6. The method of claim 1 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

7. The method of claim 1 , wherein the host processor and DP accelerator communicate over a link comprising a peripheral component interconnect express (PCIe) link.

8. A data processing (DP) accelerator, comprising:

an interface to receive an artificial intelligence (AI) model that has been previously trained and a set of input data and to receive a watermark kernel that is capable of inheriting a watermark from a host processor over a link; and

a kernel executor to execute the watermark kernel on the AI model and the set of input data, wherein the watermark kernel, when executed, is configured to

generate a new watermark by inheriting an existing watermark from a data object of the set of input data or the AI model, wherein the watermark kernel is configured to:

extract the existing watermark from the data object of the set of input data or the AI model to obtain an inherited watermark, the existing watermark embedded in the received AI model or the set of input data, and

generate the new watermark using the inherited watermark,

perform an AI inference using the artificial intelligence model, generating output date, and

implant the new watermark within the output data,

wherein the output data having the new watermark implanted therein is transmitted to the host processor over the link.

9. The DP accelerator of claim 8 , wherein the existing watermark is embedded in one or more nodes of the AI model.

10. The DP accelerator of claim 9 , wherein the existing watermark is stored in one or more weight variables of the one or more nodes of the AI model.

11. The DP accelerator of claim 9 , wherein the existing watermark is stored in one or more bias variables of the one or more nodes of the AI model.

12. The DP accelerator of claim 8 , wherein the existing watermark is embedded in the set of input data.

13. The DP accelerator of claim 8 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

14. The DP accelerator of claim 8 , wherein the link comprises a peripheral component interconnect express (PCIe) link.

15. A non-transitory machine-readable medium having instructions stored therein, which when executed by a data processing (DP) accelerator, cause the DP accelerator to perform operations, the operations comprising:

receiving, at the DP accelerator from a host processor, an artificial intelligence (AI) model that has been previously trained and a set of input data;

receiving, at the DP accelerator from the host processor, a watermark kernel that is capable of inheriting a watermark;

executing the watermark kernel within the DP accelerator on the AI model and the set of input data, wherein the watermark kernel, when executed, is configured to:

generate a new watermark by inheriting an existing watermark from a data object of the set of input data or the AI model, wherein the watermark kernel is configured to:

extract the existing watermark from the data object of the set of input data or the AI model to obtain an inherited watermark, the existing watermark embedded in the received AI model or the set of input data, and

generate the new watermark using the inherited watermark,

perform an AI inference using the AI model, generating output data, and

implant the new watermark within the output data; and

transmitting output data having the new watermark implanted therein to the host processor.

16. The machine-readable medium of claim 15 , wherein the existing watermark is embedded in one or more nodes of the AI model.

17. The machine-readable medium of claim 16 , wherein the existing watermark is stored in one or more weight variables of the one or more nodes of the AI model.

18. The machine-readable medium of claim 16 , wherein the existing watermark is stored in one or more bias variables of the one or more nodes of the AI model.

19. The machine-readable medium of claim 15 , wherein the existing watermark is embedded in the set of input data.

20. The machine-readable medium of claim 15 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 050690/0434 →
Continuity (1)
Related Publication 20210109793A1 · Apr 15, 2021