IP Library Granted Patent US 11,579,928
Granted Patent B2
US 11,579,928 · App. 16/684,295 · Granted Feb 14, 2023

Systems and methods for configuring a watermark unit with watermark algorithms for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06F9/5027G06F21/16G06F21/44G06N20/00G06F2221/0733
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,579,928
App. No.
16/684,295
Granted
Feb 14, 2023
Kind
B2
Abstract

Embodiments of the disclosure relate to configuring a watermark unit with watermark algorithms for artificial intelligence (AI) models for a data processing (DP) accelerator. In one embodiment, in response to a request received by a DP accelerator, the request, sent by an application, to apply a watermark algorithm to an AI model by the DP accelerator, a system determines that the watermark algorithm is not available at a watermark unit of the DP accelerator. The system sends a request for the watermark algorithm. The system receives the watermark algorithm by the DP accelerator. The system configures the watermark unit at runtime with the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

Claims (50)

1. A computer-implemented method for processing data by a data processing (DP) accelerator, the method comprising:

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply a watermark algorithm to an artificial intelligence (AI) model by the DP accelerator, determining that the watermark algorithm is not available for application to the AI model at a watermark unit of the DP accelerator, wherein application of the watermark algorithm to the AI model generates a watermark for the AI model;

sending a request for the watermark algorithm in response to determination the watermark algorithm is not available for application to the AI model at the watermark unit of the DP accelerator;

receiving the watermark algorithm by the DP accelerator; and

configuring the watermark unit at runtime with the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

2. The method of claim 1 , further comprising:

embedding the watermark into the AI model based on the watermark algorithm; and

returning the AI model having the embedded watermark back to the application, wherein the watermark is used to authenticate the AI model.

3. The method of claim 2 , further comprising:

signing the AI model with the watermark to generate a signature, wherein the signature is used to authenticate the AI with the watermark for a two-factor authentication.

4. The method of claim 1 , wherein the watermark algorithm is provided by a cloud provider, or a user of the cloud provider, or the application.

5. The method of claim 1 , wherein the watermark algorithm is received via a dedicated communication channel, wherein the communication channel is configured by a cloud provider.

6. The method of claim 1 , further comprising generating the AI model by training the AI model based on a set of training data.

7. The method of claim 1 , further comprising:

receiving a pre-trained AI model; and

retraining the AI model by training the AI model based on a set of training data.

8. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply a watermark algorithm to an artificial intelligence (AI) model by the DP accelerator, determining that the watermark algorithm is not available for application to the AI model at a watermark unit of the DP accelerator, wherein application of the watermark algorithm to the AI model generates a watermark for the AI model;

sending a request for the watermark algorithm in response to determination the watermark algorithm is not available for application to the AI model at the watermark unit of the DP accelerator;

receiving the watermark algorithm by the DP accelerator; and

configuring the watermark unit at runtime with the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

9. The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:

embedding the watermark into the AI model based on the watermark algorithm; and

returning the AI model having the embedded watermark back to the application, wherein the watermark is used to authenticate the AI model.

10. The non-transitory machine-readable medium of claim 9 , wherein the operations further comprise:

signing the AI model with the watermark to generate a signature, wherein the signature is used to authenticate the AI with the watermark for a two-factor authentication.

11. The non-transitory machine-readable medium of claim 8 , wherein the watermark algorithm is provided by a cloud provider, or a user of the cloud provider, or the application.

12. The non-transitory machine-readable medium of claim 8 , wherein the watermark algorithm is received via a dedicated communication channel, wherein the communication channel is configured by a cloud provider.

13. The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise generating the AI model by training the AI model based on a set of training data.

14. The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:

receiving a pre-trained AI model; and

retraining the AI model by training the AI model based on a set of training data.

15. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations, the operations including

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply a watermark algorithm to an artificial intelligence (AI) model by the DP accelerator, determining that the watermark algorithm is not available for application to the AI model at a watermark unit of the DP accelerator, wherein application of the watermark algorithm to the AI model generates a watermark for the AI model;

sending a request for the watermark algorithm in response to determination the watermark algorithm is not available for application to the AI model at the watermark unit of the DP accelerator;

receiving the watermark algorithm by the DP accelerator; and

configuring the watermark unit at runtime with the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

16. The system of claim 15 , wherein the operations further comprise:

embedding the watermark into the AI model based on the watermark algorithm; and

returning the AI model having the embedded watermark back to the application, wherein the watermark is used to authenticate the AI model.

17. The system of claim 16 , wherein the operations further comprise:

signing the AI model with the watermark to generate a signature, wherein the signature is used to authenticate the AI with the watermark for a two-factor authentication.

18. The system of claim 15 , wherein the watermark algorithm is provided by a cloud provider, or a user of the cloud provider, or the application.

19. The system of claim 15 , wherein the watermark algorithm is received via a dedicated communication channel, wherein the communication channel is configured by a cloud provider.

20. The system of claim 15 , wherein the operations further comprise generating the AI model by training the AI model based on a set of training data.

21. The system of claim 15 , wherein the operations further comprise:

receiving a pre-trained AI model; and

retraining the AI model by training the AI model based on a set of training data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 051013/0460 →
Continuity (1)
Related Publication 20210149733A1 · May 20, 2021