IP Library Granted Patent US 12,288,157
Granted Patent B2
US 12,288,157 · App. 17/592,072 · Granted Apr 29, 2025

Systems and methods for quantifying data leakage from a split layer

Inventors: Gharib Gharibi (Overland Park, MO); Andrew Rademacher (Kansas City, MO); Greg Storm (Parkville, MO); Riddhiman Das (Parkville, MO)
Assignee: Selfiee Corporation
G06N3/08G06N3/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,288,157
App. No.
17/592,072
Granted
Apr 29, 2025
Kind
B2
Abstract

A system and method are disclosed for providing an artificial intelligence platform. An example method includes examining part of a global neural network to locate a split layer in the global neural network, creating an equivalent model to the part of the global neural network of a same size but having opposite operations, generating smashed data based on an operation on input data by the part of the global neural network, training the equivalent model by inputting the smashed data to generate a second a mirrored copy of the input data, quantifying a distance between the input data and the second generated set of mirrored data to yield a value and, when the value is below a threshold, determining that a current location of the split layer in the global neural network is safe for a training process.

Claims (34)

1. A method comprising:

examining part of a global neural network to locate a split layer in the global neural network, the part of the global neural network implementing first operations, wherein the part of the global neural network implementing first operations comprises one or more neural network layers performing a respective function for each respective layer of the one or more neural network layers;

creating an equivalent model to the part of the global neural network of a same size but implementing second operations that are opposite operations in functionality in terms of model inversion and relative to the first operations of the part of the global neural network;

generating smashed data based on a first operation of the first operations on a first input data by the part of the global neural network;

training the equivalent model by inputting the smashed data to generate a second input data using a second operation of the second operations;

quantifying a distance between the first input data and the second input data to yield a value that represents a data leakage level; and

when the value is below a threshold, determining that a current location of the split layer in the global neural network is safe for a future training process for the global neural network.

2. The method of claim 1 , wherein the equivalent model applies a mean squared error function.

3. The method of claim 1 , wherein the generating of the smashed data comprises a warmup training task of the part of the global neural network.

4. The method of claim 1 , wherein, when the value is below the threshold, beginning a training process of the global neural network.

5. The method of claim 1 , wherein, when the value is at or above the threshold, declining a training process.

6. The method of claim 5 , further comprising requesting to move the split layer deeper into the global neural network.

7. The method of claim 6 , further comprising changing an architecture associated with the global neural network prior to approving of a training task.

8. The method of claim 1 , wherein a server sends the part of the global neural network to a client.

9. The method of claim 8 , wherein the client operates a tool that examines part of the global neural network to locate the split layer in the global neural network.

10. The method of claim 1 , wherein training the equivalent model comprises at least one of a split learning process and a blind learning process.

11. A system comprising:

a processor; and

a computer-readable storage device storing instructions which, when executed by the processor, cause the processor to perform operations comprising:

examining part of a global neural network to locate a split layer in the global neural network, the part of the global neural network implementing first operations, wherein the part of the global neural network implementing first operations comprises one or more neural network layers performing a respective function for each respective layer of the one or more neural network layers;

creating an equivalent model to the part of the global neural network of a same size but implementing second operations that are opposite operations in functionality in terms of model inversion and relative to the first operations of the part of the global neural network;

generating smashed data based on a first operation of the first operations on a first input data by the part of the global neural network;

training the equivalent model by inputting the smashed data to generate a second input data using a second operation of the second operations;

quantifying a distance between the first input data and the second input data to yield a value that represents a data leakage level; and

when the value is below a threshold, determining that a current location of the split layer in the global neural network is safe for a future training process for the global neural network.

12. The system of claim 11 , wherein the equivalent model applies a mean squared error function.

13. The system of claim 11 , wherein the generating of the smashed data comprises a warmup training task of the part of the global neural network.

14. The system of claim 11 , wherein, when the value is below the threshold, beginning a training process of the global neural network.

15. The system of claim 11 , wherein, when the value is at or above the threshold, declining a training process.

16. The system of claim 15 , further comprising requesting to move the split layer deeper into the global neural network.

17. The system of claim 16 , further comprising changing an architecture associated with the global neural network prior to approving of a training task.

18. The system of claim 11 , wherein a server sends the part of the global neural network to a client.

19. The system of claim 18 , wherein the client operates a tool that examines part of the global neural network to locate the split layer in the global neural network.

20. The system of claim 11 , wherein training the equivalent model comprises at least one of a split learning process and a blind learning process.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2024
From: TRIPLEBLIND HOLDINGS, INC.
To: SELFIIE CORPORATION
Reel/Frame 068907/0556 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE SHOULD BE CORRECTED FROM TRIPLEBLIND HOLDING COMPANY TO TRIPLEBLIND HOLDINGS, INC. PREVIOUSLY RECORDED AT REEL: 67568 FRAME: 689. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 24, 2024
From: TRIPLEBLIND, INC.
To: TRIPLEBLIND HOLDINGS, INC.
Reel/Frame 068722/0100 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2024
From: TRIPLEBLIND, INC.
To: TRIPLEBLIND HOLDING COMPANY
Reel/Frame 067568/0689 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2022
From: GHARIBI, GHARIB; RADEMACHER, ANDREW; STORM, GREG; DAS, RIDDHIMAN
To: TRIPLEBLIND, INC.
Reel/Frame 060704/0514 →
Continuity (1)
Related Publication 20230306254A1 · Sep 28, 2023
References Cited (120)
US 1045208A · Spencer · 1912 [cited by applicant]
US 5410696A · Seki et al. · 1995 [cited by applicant]
US 6353816B1 · Tsukimoto · 2002 [cited by applicant]
US 9646043B1 · Aronvich · 2017 [cited by applicant]
US 10002029B1 · Bequet · 2018 [cited by applicant]
US 10362001B2 · Yan · 2019 [cited by applicant]
US 10419360B2 · Dawson · 2019 [cited by applicant]
US 10592012B2 · Dawson · 2020 [cited by applicant]
US 10560872B2 · Dawson · 2020 [cited by applicant]
US 10594623B2 · Dawson · 2020 [cited by applicant]
US 10623998B2 · Dawson · 2020 [cited by applicant]
US 10833871B2 · Ranellucci · 2020 [cited by applicant]
US 10902302B2 · Fu · 2021 [cited by applicant]
US 10924460B2 · Storm · 2021 [cited by applicant]
US 11195099B2 · Luo · 2021 [cited by applicant]
US 11316676B2 · Kinjo · 2022 [cited by applicant]
US 20060233377A1 · Chang · 2006 [cited by applicant]
US 20080082636A1 · Hofmann · 2008 [cited by applicant]
US 20080201721A1 · Little · 2008 [cited by applicant]
US 20090063485A1 · Schneider · 2009 [cited by applicant]
US 20100100864A1 · Plants · 2010 [cited by applicant]
US 20100281254A1 · Carro · 2010 [cited by applicant]
US 20110161091A1 · Freishtat · 2011 [cited by applicant]
US 20120047097A1 · Sengupta et al. · 2012 [cited by applicant]
US 20130124491A1 · Pepper · 2013 [cited by applicant]
US 20130272377A1 · Karczewicz · 2013 [cited by applicant]
US 20140108813A1 · Pauker · 2014 [cited by applicant]
US 20140371902A1 · McClelland · 2014 [cited by applicant]
US 20150242136A1 · Lin · 2015 [cited by applicant]
US 20150288662A1 · Bilogrevic · 2015 [cited by applicant]
US 20150324690A1 · Chilimbi · 2015 [cited by examiner]
US 20150371132A1 · Gemello · 2015 [cited by applicant]
US 20160103901A1 · Kadav · 2016 [cited by applicant]
US 20160294550A1 · French · 2016 [cited by applicant]
US 20160335440A1 · Clark · 2016 [cited by applicant]
US 20160342608A1 · Burshteyn · 2016 [cited by applicant]
US 20170026342A1 · Sidana · 2017 [cited by applicant]
US 20170116520A1 · Min · 2017 [cited by applicant]
US 20170149796A1 · Gvili · 2017 [cited by applicant]
US 20170228547A1 · Smith · 2017 [cited by applicant]
US 20170323196A1 · Gibson · 2017 [cited by applicant]
US 20170359321A1 · Rindal · 2017 [cited by applicant]
US 20170372201A1 · Gupta · 2017 [cited by applicant]
US 20180039884A1 · Dalton · 2018 [cited by applicant]
US 20180041477A1 · Shaposhnik · 2018 [cited by applicant]
US 20180330237A1 · Yoshiyama · 2018 [cited by applicant]
US 20180129900A1 · Kiraly · 2018 [cited by applicant]
US 20180157972A1 · Hu · 2018 [cited by applicant]
US 20180227296A1 · Joshi · 2018 [cited by applicant]
US 20180367509A1 · O'Hare · 2018 [cited by applicant]
US 20190005399A1 · Noguchi · 2019 [cited by applicant]
US 20190065989A1 · Kida · 2019 [cited by examiner]
US 20190130265A1 · Ling · 2019 [cited by applicant]
US 20190228299A1 · Chandran · 2019 [cited by applicant]
US 20190286973A1 · Kovvuri · 2019 [cited by applicant]
US 20190294805A1 · Taylor · 2019 [cited by applicant]
US 20190312772A1 · Zhao · 2019 [cited by applicant]
US 20190332944A1 · Bai · 2019 [cited by applicant]
US 20190372760A1 · Zheng · 2019 [cited by applicant]
US 20200036510A1 · Gomez · 2020 [cited by applicant]
US 20200044862A1 · Yadlin · 2020 [cited by applicant]
US 20200125933A1 · Aldea Lopez · 2020 [cited by applicant]
US 20200158745A1 · Tian · 2020 [cited by applicant]
US 20200184044A1 · Zatloukal · 2020 [cited by applicant]
US 20200186528A1 · Fan · 2020 [cited by applicant]
US 20200193279A1 · Hostetler · 2020 [cited by examiner]
US 20200202184A1 · Shrestha · 2020 [cited by applicant]
US 20200226284A1 · Yin et al. · 2020 [cited by applicant]
US 20200228313A1 · Storm · 2020 [cited by applicant]
US 20200265301A1 · Burger · 2020 [cited by applicant]
US 20200286145A1 · Storm · 2020 [cited by applicant]
US 20200296128A1 · Wentz · 2020 [cited by applicant]
US 20200304293A1 · Gama · 2020 [cited by applicant]
US 20200322141A1 · Kinjo · 2020 [cited by applicant]
US 20200342288A1 · Xi · 2020 [cited by applicant]
US 20200342394A1 · Moore et al. · 2020 [cited by applicant]
US 20200372360A1 · Vu · 2020 [cited by examiner]
US 20200394316A1 · Boehler · 2020 [cited by applicant]
US 20200402625A1 · Aravamudan · 2020 [cited by applicant]
US 20210019605A1 · Rouhani · 2021 [cited by applicant]
US 20210026860A1 · Wang · 2021 [cited by applicant]
US 20210035330A1 · Xie · 2021 [cited by applicant]
US 20210064760A1 · Sharma · 2021 [cited by applicant]
US 20210117578A1 · Cheruvu · 2021 [cited by applicant]
US 20210142177A1 · Mallya · 2021 [cited by applicant]
US 20210150024A1 · Zhang · 2021 [cited by applicant]
US 20210157912A1 · Kruthiveti Subrahmanyeswara Sai · 2021 [cited by applicant]
US 20210194668A1 · Masters · 2021 [cited by applicant]
US 20210248268A1 · Ardhanari · 2021 [cited by applicant]
US 20210266170A1 · Rossi · 2021 [cited by applicant]
US 20210314140A1 · Stephenson · 2021 [cited by applicant]
US 20210334621A1 · Shimizu · 2021 [cited by applicant]
US 20210350357A1 · Lafontaine · 2021 [cited by applicant]
US 20210357859A1 · Malvankar · 2021 [cited by applicant]
US 20210374502A1 · Roth · 2021 [cited by examiner]
US 20210385069A1 · Reid · 2021 [cited by applicant]
US 20210406386A1 · Ortiz · 2021 [cited by applicant]
US 20220004654A1 · Patel · 2022 [cited by applicant]
US 20220012672A1 · Inman · 2022 [cited by applicant]
US 20220038271A1 · Ranellucci · 2022 [cited by applicant]
US 20220050921A1 · LaFever · 2022 [cited by applicant]
US 20220051276A1 · Zelocchi · 2022 [cited by applicant]
US 20220108026A1 · Ortiz · 2022 [cited by applicant]
US 20220121731A1 · Growth · 2022 [cited by applicant]
US 20220247548A1 · Boehler · 2022 [cited by applicant]
US 20220300618A1 · Ding · 2022 [cited by examiner]
WO WO2021119365 · 2021 [cited by applicant]
WO WO2021119367 · 2021 [cited by applicant]
Chandra Thapa, “SplitFed: When Federated Learning Meets Split Learning”, Submitted on Apr. 25, 2020 (v1), arXiv:2004.12088 [cs.LG] (Year: 2020). [cited by examiner]
Ads at al.(“Multi-limb Split Learning for Tumor Classification on Vertically Distributed Data”), Date of Conference: Dec. 5-7, 2021, IEEE (Year: 2021). [cited by examiner]
Gawali at al.(“Comparison of Privacy-Preserving Distributed Deep Learning Methods in Healthcare”, 2020) (Year: 2020). [cited by examiner]
Khan et al. (“Security Analysis of SplitFed Learning”, 2022): (Year: 2022). [cited by examiner]
Abuadbba at al.(“Can WeUseSplit Learning on 1D CNNModels for Privacy Preserving Training?”, ASIA CCS '20, Oct. 5-9, 2020, Taipei, Taiwan (Year: 2020). [cited by examiner]
Zhu et al. (“Deep Leakage from Gradients”, NeurIPS 2019) (Year: 2019). [cited by examiner]
Thapa et al., “SplitFed: When Federated Learning Meets Split Learning”, Cornell University Library/Computer Science/Machine Learning, Apr. 25, 2020, [online] [retrieved on Dec. 15, 2021] Retrieved from the Internet URL:… [cited by applicant]
Brisimi et al. “Federated learning of predictive models from federated electronic health records”, International Journal of Medical Informatics, Apr. 2018, retrieved on Jan. 18, 2021 from http://www.ncbi.nlm.nih/gov/pmc… [cited by applicant]
Abedi, Ali, and Shehroz S. Khan. “FedSL: Federated Split Learning on Distributed Sequential Data in Recurrent Neural Networks”, arXiv preprint arXiv:2011.03180 (Year 2021). [cited by applicant]
Nir Bitansky et al., “Post-quantum Zero Knowledge in Constant Rounds”; Jun. 2020; 48 pages (Year 2020). [cited by applicant]
Lui et al., “Federated Forest”, Arxiv.org, Cornell University Library, May 24, 2019, XP081662771, DOI: 10.1109/TBDATA.2020.2992755, Sections 3, 4, 5; Figure 1. (Year: 2019). [cited by applicant]
Ads et al., “Multi-limb Split Learning for Tumor Classification on Vertically Distributed Data”, Date of Conference: Dec. 5-7, 2021, IEEE (Year: 2021). [cited by applicant]