IP Library Granted Patent US 11,481,678
Granted Patent B2
US 11,481,678 · App. 16/684,320 · Granted Oct 25, 2022

Systems and methods for learning new watermark algorithms for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06N20/00G06F21/44G06N5/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,678
App. No.
16/684,320
Granted
Oct 25, 2022
Kind
B2
Abstract

Embodiments of the disclosure relate to learning new watermark algorithms for artificial intelligence (AI) models for a data processing (DP) accelerator. In one embodiment, a system trains a watermark algorithm based on a predetermined set of criteria, where the watermark algorithm is trained to generate variations of the watermark algorithm. The system configures the watermark unit at runtime with a variation of the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

Claims (46)

1. A computer-implemented method for processing data by a data processing (DP) accelerator, the method comprising:

training a watermark algorithm by the DP accelerator based on a predetermined set of criteria, wherein the watermark algorithm is trained to generate variations of the watermark algorithm, wherein the set of criteria includes a change in inference accuracy of an artificial intelligence (AI) model having a watermark and pairing compatibility of the watermark and the AI model, wherein the training comprises:

determining an inference accuracy for the AI model without the watermark;

determining an inference accuracy for the AI model embedded with the watermark; and

determining a change in inference accuracy for the pairing; and

configuring a watermark unit at runtime with a variation of the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

2. The method of claim 1 , wherein the training comprises:

embedding the watermark into one or more AI models; and

scoring the AI models and watermark for pairing compatibility based on a compatibility scoring criteria.

3. The method of claim 1 , wherein the training is performed until a predetermined condition is achieved for the set of criteria or until a predetermined number of training iterations.

4. The method of claim 1 , further comprising:

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply the watermark algorithm to an AI model by the DP accelerator, applying the watermark algorithm to generate a watermark for the AI model;

embedding the watermark into the AI model; and

returning the AI model having the watermark to the application, wherein the watermark is used to authenticate the AI model.

5. The method of claim 1 , further comprising generating an AI model by training the AI model based on a set of training data.

6. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:

training a watermark algorithm by a data processing (DP) accelerator based on a predetermined set of criteria, wherein the watermark algorithm is trained to generate variations of the watermark algorithm, wherein the set of criteria includes a change in inference accuracy of an artificial intelligence (AI) model having a watermark and pairing compatibility of the watermark and the AI model, wherein the training comprises:

determining an inference accuracy for the AI model without the watermark;

determining an inference accuracy for the AI model embedded with the watermark; and

determining a change in inference accuracy for the pairing;

configuring a watermark unit at runtime with a variation of the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

7. The non-transitory machine-readable medium of claim 6 , wherein the training comprises:

embedding the watermark into one or more AI models; and

scoring the AI models and watermark for pairing compatibility based on a compatibility scoring criteria.

8. The non-transitory machine-readable medium of claim 6 , wherein the training is performed until a predetermined condition is achieved for the set of criteria or until a predetermined number of training iterations.

9. The non-transitory machine-readable medium of claim 6 , wherein the operations further comprise:

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply the watermark algorithm to an AI model by the DP accelerator, applying the watermark algorithm to generate a watermark for the AI model;

embedding the watermark into the AI model; and

returning the AI model having the watermark to the application, wherein the watermark is used to authenticate the AI model.

10. The non-transitory machine-readable medium of claim 6 , wherein the operations further comprise generating an AI model by training the AI model based on a set of training data.

11. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations, the operations including training a watermark algorithm by a data processing (DP) accelerator based on a predetermined set of criteria, wherein the watermark algorithm is trained to generate variations of the watermark algorithm, wherein the set of criteria includes a change in inference accuracy of an artificial intelligence (AI) model having a watermark and pairing compatibility of the watermark and the AI model, wherein the training comprises:

determining an inference accuracy for the AI model without the watermark;

determining an inference accuracy for the AI model embedded with the watermark; and

determining a change in inference accuracy for the pairing;

configuring a watermark unit at runtime with a variation of the watermark algorithm for the watermark algorithm to be used by the DP accelerator.

12. The system of claim 11 , wherein the training comprises:

embedding the watermark into one or more AI models; and

scoring the AI models and watermark for pairing compatibility based on a compatibility scoring criteria.

13. The system of claim 11 , wherein the training is performed until a predetermined condition is achieved for the set of criteria or until a predetermined number of training iterations.

14. The system of claim 11 , wherein the operations further comprise:

in response to a request received by a data processing (DP) accelerator, the request, sent by an application, to apply the watermark algorithm to an AI model by the DP accelerator, applying the watermark algorithm to generate a watermark for the AI model;

embedding the watermark into the AI model; and

returning the AI model having the watermark to the application, wherein the watermark is used to authenticate the AI model.

15. The system of claim 11 , wherein the operations further comprise generating an AI model by training the AI model based on a set of training data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 051013/0626 →
Continuity (1)
Related Publication 20210150406A1 · May 20, 2021