IP Library Granted Patent US 11,574,032
Granted Patent B2
US 11,574,032 · App. 16/684,248 · Granted Feb 7, 2023

Systems and methods for signing an AI model with a watermark for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06F21/16G06N20/00H04L9/3073H04L9/3242H04L9/3247G06F2221/0733
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,574,032
App. No.
16/684,248
Granted
Feb 7, 2023
Kind
B2
Abstract

Embodiments of the disclosure relates to signing of an artificial intelligence (AI) model with a watermark for a data processing (DP) accelerator. In one embodiment, in response to a request received by the data processing accelerator, the request sent by an application to embed digital rights protection to an AI model, a system generates a watermark for the AI model based on a watermark algorithm. The system embeds the watermark onto the AI model. The system signs the AI model having the embedded watermark to generate a signature. The system returns the signature and the AI model having the embedded watermark back to the application, where the signature is used to authenticate the watermark and/or the AI model.

Claims (50)

1. A computer-implemented method for processing data by a data processing accelerator, the method comprising:

in response to a request received by a data processing accelerator, the request sent by an application to apply a watermark to an artificial intelligence (AI) model, generating a watermark for the AI model based on a watermark algorithm;

embedding the watermark onto the AI model;

signing the AI model having the embedded watermark to generate a signature, wherein signing the AI model having the embedded watermark comprises:

generating a security key pair by a security unit of the data processing accelerator;

generating a hash for the AI model having the embedded watermark; and

encrypting the hash using a private key of the security key pair to sign the AI model having the embedded watermark; and

returning the signature and the AI model having the embedded watermark back to the application, wherein the signature is used to verify the watermark and/or the AI model.

2. The method of claim 1 , further comprising generating the AI model by training the AI model based on a set of training data.

3. The method of claim 1 , further comprising:

receiving a pre-trained AI model; and

retraining the AI model by training the AI model based on a set of training data.

4. The method of claim 1 , wherein a public key of the security key pair is used to decrypt the hash to verify the signature for the watermark and/or the AI model.

5. The method of claim 4 , further comprising:

extracting the watermark from the AI model; and

verifying the both the extracted watermark and the signature for a two-factor verification.

6. The method of claim 1 , wherein the security unit includes a root credential hardened onto the security unit, wherein the security key pair is a plurality of key pairs generated based on the root credential of the security unit and the security key pair is selected by the watermark algorithm to sign the AI model having the embedded watermark.

7. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations, the operations including

in response to a request received by a data processing accelerator, the request sent by an application to apply a watermark to an artificial intelligence (AI) model, generating a watermark for the AI model based on a watermark algorithm;

embedding the watermark onto the AI model;

signing the AI model having the embedded watermark to generate a signature, wherein signing the AI model having the embedded watermark comprises:

generating a security key pair by a security unit of the data processing accelerator;

generating a hash for the AI model having the embedded watermark; and

encrypting the hash using a private key of the security key pair to sign the AI model having the embedded watermark; and

returning the signature and the AI model having the embedded watermark back to the application, wherein the signature is used to verify the watermark and/or the AI model.

8. The system of claim 7 , wherein the operations further comprise generating the AI model by training the AI model based on a set of training data.

9. The system of claim 7 , wherein the operations further comprise:

receiving a pre-trained AI model; and

retraining the AI model by training the AI model based on a set of training data.

10. The system of claim 7 , wherein a public key of the security key pair is used to decrypt the hash to verify the signature for the watermark and/or the AI model.

11. The system of claim 10 , further comprising:

extracting the watermark from the AI model; and

verifying the both the extracted watermark and the signature for a two-factor verification.

12. The system of claim 7 , wherein the security unit includes a root credential hardened onto the security unit, wherein the security key pair is a plurality of key pairs generated based on the root credential of the security unit and the security key pair is selected by the watermark algorithm to sign the AI model having the embedded watermark.

13. A computer-implemented method for processing data by a data processing accelerator, the method comprising:

sending a request by an application to a data processing accelerator, the request to:

generate a watermark for an artificial intelligence (AI) model based on a watermark algorithm,

embed the watermark onto the AI model, wherein the AI model having the embedded watermark is signed by:

generating a security key pair by a security unit of the data processing accelerator,

generating a hash for the AI model having the embedded watermark, and

encrypting the hash using a private key of the security key pair to sign the AI model having the embedded watermark, and

generate a signature for the AI model with the watermark based on a security key pair; and

receiving the signature, wherein the signature is used to verify the watermark and/or the AI model.

14. The method of claim 13 , further comprising sending a set of training data to the data processing accelerator to train the AI model based on the set of training data.

15. The method of claim 13 , further comprising sending a pre-trained AI model to the data processing accelerator, wherein the AI model is retrained based on a set of training data.

16. The method of claim 13 , wherein a public key of the security key pair is used to decrypt the hash to verify the signature for the watermark and/or the AI model.

17. The method of claim 16 , wherein the verification includes extracting the watermark from the AI model, and further verifying the extracted watermark for a two-factor verification.

18. The method of claim 13 , wherein the security unit includes a root credential hardened onto the security unit, wherein the security key pair is a plurality of key pairs generated based on the root credential of the security unit and the security key pair is selected by the watermark algorithm to sign the AI model having the embedded watermark.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 051013/0262 →
Continuity (1)
Related Publication 20210150002A1 · May 20, 2021
Cited By (3)
US 12,355,868 US 12,694,079 US 12,700,998