IP Library Patent Application 16869082
Patent Application
App. No. 16/869,082

METHOD FOR OBFUSCATED AI MODEL TRAINING FOR DATA PROCESSING ACCELERATORS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/869,082
Abstract

Embodiments of the disclosure discloses a method to obfuscate AI models. In one embodiment, a host communicates with a data processing (DP) accelerator to request an AI training by the DP accelerator. The DP accelerator (or system) receives an AI model training request from a host, where the AI model training request includes one or more model-obfuscation kernel algorithms, one or more AI models, and/or training input data. In response to receiving the AI model training request, the system trains the one or more AI models based on the training input data. In some embodiments, AI accelerator already has a copy of the AI model. After the AI models are trained, the system obfuscates, using the one or more model-obfuscation kernel algorithms, the one or more trained AI models. The system sends the obfuscated one or more trained AI models to the host.

Claims (33)

1 . A method to obfuscate artificial intelligence (AI) models, the method comprising:

receiving, by a data processing (DP) accelerator, an AI model training request from a host, wherein the AI model training request comprises one or more model-obfuscation kernel algorithms, one or more AI models, and/or training input data;

in response to receiving the AI model training request, training, by the DP accelerator, the one or more AI models based on the training input data;

in response to training completion, obfuscating, using the one or more model-obfuscation kernel algorithms, one or more trained AI models; and

sending, by the DP accelerator, the obfuscated one or more trained AI models to the host.

2 . The method of claim 1 , wherein the one or more model-obfuscation kernel algorithms are generated by the host, and wherein one or more corresponding model-de-obfuscation kernel algorithms are used by the host to de-obfuscate the obfuscated one or more AI models to retrieve the one or more AI models.

3 . The method of claim 1 , wherein the one or more model-obfuscation kernel algorithms are received on a same communication channel as the training request.

4 . The method of claim 1 , wherein the one or more model-obfuscation kernel algorithms include a shift left or shift right algorithm applied to data containers for weight and/or bias values of the one or more AI models.

5 . The method of claim 1 , wherein the one or more model-obfuscation kernel algorithms include a deterministic algorithm or a probabilistic algorithm.

6 . The method of claim 1 , wherein the one or more model-obfuscation kernel algorithms are expiring algorithms that expire after some predetermined periods of time have lapsed, wherein if a model-obfuscation kernel algorithm expires, a derived model-obfuscation kernel algorithm is to replace the expired algorithm.

7 . The method of claim 6 , wherein the training request includes a metadata specifying the predetermined periods of time before the one or more model-obfuscation kernel algorithms expire.

8 . A data processing (DP) accelerator, comprising:

an interface to receive an AI model training request from a host, wherein the AI model training request comprises one or more model-obfuscation kernel algorithms, one or more AI models, and training input data;

a training unit, in response to receiving the AI model training request, to train the one or more AI models based on the training input data; and

an obfuscation unit to obfuscate one or more trained AI models using the one or more model-obfuscation kernel algorithms and to send the obfuscated one or more trained AI models to the host.

9 . The DP accelerator of claim 8 , wherein the one or more model-obfuscation kernel algorithms are generated by the host, and wherein one or more corresponding model-de-obfuscation kernel algorithms are used by the host to de-obfuscate the obfuscated one or more AI models to retrieve the one or more AI models.

10 . The DP accelerator of claim 8 , wherein the one or more model-obfuscation kernel algorithms are received on a same communication channel as the training request.

11 . The DP accelerator of claim 8 , wherein the one or more model-obfuscation kernel algorithms include a shift left or shift right algorithm applied to bit representations for weight and/or bias of the one or more AI models.

12 . The DP accelerator of claim 8 , wherein the one or more model-obfuscation kernel algorithms include a deterministic algorithm or a probabilistic algorithm.

13 . The DP accelerator of claim 8 , wherein the one or more model-obfuscation kernel algorithms are expiring algorithms that expire after some predetermined periods of time have lapsed, wherein if a model-obfuscation kernel algorithm expires, a derived model-obfuscation kernel algorithm is to replace the expired algorithm.

14 . The DP accelerator of claim 13 , wherein the training request includes a metadata specifying the predetermined periods of time before the one or more model-obfuscation kernel algorithms expire.

15 . A method to de-obfuscate artificial intelligence (AI) models, the method comprising:

generating one or more model-obfuscation kernel algorithms to obfuscate one or more AI models;

generating a training request to perform an AI training by a data processing (DP) accelerator, wherein the training request includes training input data, the one or more model-obfuscation kernel algorithms and one or more AI models;

sending the training request to a DP accelerator;

in response to the sending, receiving one or more obfuscated AI models from the DP accelerator; and

de-obfuscating the one or more obfuscated AI models using one or more model-de-obfuscation kernel algorithms corresponding to the one or more model-obfuscation kernel algorithms to retrieve the one or more AI models.

16 . The method of claim 15 , wherein the one or more model-obfuscation kernel algorithms are used by the DP accelerator to obfuscate the one or more AI models that has been trained.

17 . The method of claim 15 , wherein the one or more model-obfuscation kernel algorithms are sent on a same communication channel as the training request.

18 . The method of claim 15 , wherein the one or more model-obfuscation kernel algorithms include a shift left or shift right algorithm applied to bit representations for weight and/or bias of the one or more AI models.

19 . The method of claim 15 , wherein the one or more model-obfuscation kernel algorithms include a deterministic algorithm or a probabilistic algorithm.

20 . The method of claim 15 , wherein the one or more model-obfuscation kernel algorithms are expiring algorithms that expire after some predetermined periods of time have lapsed, wherein if a model-obfuscation kernel algorithm expires, a derived model-obfuscation kernel algorithm is to replace the expired algorithm.

21 . The method of claim 20 , wherein the training request includes a metadata specifying the predetermined periods of time before the one or more model-obfuscation kernel algorithms expire.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2020
From: CHENG, YUEQIANG; ZHU, HEFEI
To: BAIDU USA LLC
Reel/Frame 052602/0532 →