IP Library Granted Patent US 11,582,260
Granted Patent B2
US 11,582,260 · App. 16/684,345 · Granted Feb 14, 2023

Systems and methods for verifying a watermark of an AI model for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
H04L63/20G06F21/16G06N5/04G06N20/00H04L9/3247G06F2221/0746
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,582,260
App. No.
16/684,345
Granted
Feb 14, 2023
Kind
B2
Abstract

Embodiments of the disclosure relate to verifying a watermark of an artificial intelligence (AI) model for a data processing (DP) accelerator. In one embodiment, a system receives an inference request from an application. The system extracts the watermark from an AI model having the watermark. The system verifies the extracted watermark based on a policy. The system applies the AI model having a watermark to a set of inference inputs to generate inference results. The system sends a verification proof and the inference results to the application.

Claims (42)

1. A computer-implemented method for processing data by a data processing (DP) accelerator, the method comprising:

receiving an inference request from an application executed by a host;

extracting a watermark from an artificial intelligence (AI) model having the watermark by a data processing (DP) accelerator;

extracting a watermark type indicator based on metadata associated with the AI model;

determining a policy from a plurality of policies based on the watermark type indicator, wherein each of the plurality of policies corresponds to a type of watermark algorithm that generated the watermark, wherein a first type of watermark algorithm adds one or more dummy layers and/or alters one or more weights of an AI model and a second type of watermark algorithm alters a training subroutine to include a hidden set of training data to train the AI model;

determining a type of watermark algorithm that generated the watermark based on the policy;

verifying the extracted watermark based on the determined type of watermark algorithm;

applying the AI model having the watermark to a set of inference inputs to generate inference results; and

sending a verification proof and the inference results to the application.

2. The method of claim 1 , wherein the inference results are generated after the extracted watermark is verified successfully based on the policy.

3. The method of claim 1 , wherein the policy includes a criterion that the AI model contain a verifiable watermark generated by a DP accelerator and the watermark includes a machine recognizable watermark for verification.

4. The method of claim 1 , wherein the policy includes a criterion that a signature for the AI model having the watermark is successfully verified.

5. The method of claim 1 , wherein a different policy is applied to a different version of a watermark algorithm.

6. The method of claim 1 , wherein the verification proof includes a signature for a result of the inference request.

7. A data processing (DP) accelerator, comprising:

a hardware processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations, the operations including receiving an inference request from an application executed by a host;

extracting a watermark from an artificial intelligence (AI) model having the watermark;

extracting a watermark type indicator based on metadata associated with the AI model;

determining a policy from a plurality of policies based on the watermark type indicator, wherein each of the plurality of policies corresponds to a type of watermark algorithm that generated the watermark, wherein a first type of watermark algorithm adds one or more dummy layers and/or alters one or more weights of an AI model and a second type of watermark algorithm alters a training subroutine to include a hidden set of training data to train the AI model;

determining a type of watermark algorithm that generated the watermark based on the policy;

verifying the extracted watermark based on the determined type of watermark algorithm;

applying the AI model having the watermark to a set of inference inputs to generate inference results; and

sending a verification proof and the inference results to the application.

8. The DP accelerator of claim 7 , wherein the inference results are generated after the extracted watermark is verified successfully based on the policy.

9. The DP accelerator of claim 7 , wherein the policy includes a criterion that the AI model contain a verifiable watermark generated by a DP accelerator and the watermark includes a machine recognizable watermark for verification.

10. The DP accelerator of claim 7 , wherein the policy includes a criterion that a signature for the AI model having the watermark is successfully verified.

11. The DP accelerator of claim 7 , wherein a different policy is applied to a different version of a watermark algorithm.

12. The DP accelerator of claim 7 , wherein the verification proof includes a signature for a result of the inference request.

13. A computer-implemented method for processing data by a data processing (DP) accelerator, the method comprising:

sending an inference request by an application to a data processing (DP) accelerator, the request to generate inference results by applying an artificial intelligence (AI) model with a watermark to inference inputs, wherein the request includes a request to

extract the watermark from the AI model having the watermark by the DP accelerator,

extract a watermark type indicator based on metadata associated with the AI model,

determine a policy from a plurality of policies based on the watermark type indicator, wherein each of the plurality of policies corresponds to a type of watermark algorithm that generated the watermark, wherein a first type of watermark algorithm adds one or more dummy layers and/or alters one or more weights of an AI model and a second type of watermark algorithm alters a training subroutine to include a hidden set of training data to train the AI model, and

determine a type of watermark algorithm that generated the watermark based on the policy;

verify the extracted watermark based on the determined type of watermark algorithm; and

receiving a verification proof and the inference results by the application.

14. The method of claim 13 , wherein the inference results are generated after the extracted watermark is verified successfully based on the policy.

15. The method of claim 13 , wherein the policy includes a criterion that the AI model contain a verifiable watermark generated by a DP accelerator and the watermark includes a machine recognizable watermark for verification.

16. The method of claim 13 , wherein the policy includes a criterion that a signature for the AI model having the watermark is successfully verified.

17. The method of claim 13 , wherein a different policy is applied to a different version of a watermark algorithm.

18. The method of claim 13 , wherein the verification proof includes a signature for a result of the inference request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 051013/0824 →
Continuity (1)
Related Publication 20210152600A1 · May 20, 2021
Cited By (2)
US 12,470,381 US 12,700,998