IP Library › Granted Patent US 12,265,838
Granted Patent B2
US 12,265,838 · App. 17/840,652 · Granted Apr 1, 2025

Model protection system

Inventors: Chih-Hsiang Hsiao (Hsinchu, TW); Pei-Lun Suei (Hsinchu, TW); Yu-Chi Chu (Hsinchu, TW)
Assignee: MEDIATEK INC.
G06F9/45558G06F3/0659G06F21/53G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,838
App. No.
17/840,652
Granted
Apr 1, 2025
Kind
B2
Abstract

A system for model protection includes a processor. The processor is arranged to execute a guest virtual machine (VM), a primary VM, and a hypervisor. The guest VM includes a model, and is arranged to send at least one command to a command hub. The primary VM is arranged to refer to the at least one command sent from the command hub to manage and configure a protection setting for a protected model derived from the model. The hypervisor is arranged to receive a safety setting command sent by the primary VM, and manage and configure the safety protection component according to the safety setting command, to set a read-only mode of the protected model.

Claims (33)

1. A system for artificial intelligence (AI) model protection, comprising:

a processor, arranged to execute:

a guest virtual machine (VM), wherein the guest VM comprises an AI model, and the guest VM is arranged to send at least one command to a command hub;

a primary VM, wherein the primary VM is arranged to receive the at least one command sent from the command hub, and refer to the at least one command to manage and configure a protection setting for a protected AI model that is derived from the AI model; and

a hypervisor, arranged to receive a safety setting command sent by the primary VM, and manage and configure a safety protection component according to the safety setting command, to set a read-only mode of the protected AI model; and

a transmission interface, arranged to bind the primary VM to the hypervisor, and perform communications between the primary VM and the hypervisor.

2. The system of claim 1 , wherein the processor is further arranged to execute the command hub that is a software module integrated in the hypervisor.

3. The system of claim 1 , further comprising:

the command hub;

wherein the command hub is a hardware component external to the hypervisor executed on the processor.

4. The system of claim 1 , wherein the AI model is injected to a kernel of an operating system running on the guest VM, and the protected AI model is derived from the AI model injected to the kernel.

5. The system of claim 1 , wherein the AI model is injected to a shared memory between an operating system running on the guest VM and a kernel of the operating system, and the protected AI model is derived from the AI model injected to the shared memory.

6. The system of claim 1 , wherein the processor is further arranged to execute:

an isolated execution environment, arranged to verify a signature of the protected AI model, to ensure safety of the protected AI model before the computations are performed on the protected AI model by a direct memory access (DMA) circuit.

7. The system of claim 6 , wherein the hypervisor is further arranged to set a no-read/write mode of the protected AI model by managing and configuring the safety protection component according to the safety setting command.

8. The system of claim 1 , wherein the at least one command comprises a first command for AI model protection and a second command for AI model verification, and the primary VM further comprises:

a verifier, arranged to verify a signature of the protected AI model according to the second command, to ensure safety of the protected AI model before the computations are performed on the protected AI model by a direct memory access (DMA) circuit.

9. The system of claim 1 , wherein the AI model is a crypted AI model, and the processor is further arranged to execute:

an isolated execution environment, arranged to perform decryption on the crypted AI model to generate the protected AI model.

10. The system of claim 1 , wherein the AI model is a crypted AI model, the at least one command comprises a first command for AI model protection and a second command for AI model decryption, and the primary VM is further arranged to perform decryption on the crypted AI model according to the second command, to generate the protected AI model.

11. The system of claim 1 , wherein the safety protection component comprises a memory management unit (MMU) or a memory protection unit (MPU).

12. A non-transitory machine-readable medium for storing a program code, wherein when loaded and executed by a processor, the program code instructs the processor to execute:

a guest virtual machine (VM), wherein the guest VM comprises an artificial intelligence (AI) model, and the guest VM is arranged to send at least one command to a command hub;

a primary VM, wherein the primary VM is arranged to receive the at least one command sent from the command hub, and refer to the at least one command to manage and configure a protection setting for a protected AI model that is derived from the AI model; and

a hypervisor, arranged to receive a safety setting command sent by the primary VM, and manage and configure a safety protection component according to the safety setting command, to set a read-only mode of the protected AI model;

wherein the primary VM is bound to the hypervisor when communications between the primary VM and the hypervisor is performed.

13. The non-transitory machine-readable medium of claim 12 , wherein the program code further instructs the processor to execute the command hub that is a software module integrated in the hypervisor.

14. The non-transitory machine-readable medium of claim 12 , wherein the command hub is implemented by a hardware component.

15. The non-transitory machine-readable medium of claim 12 , wherein the AI model is injected to a kernel of an operating system running on the guest VM, and the protected AI model is derived from the AI model injected to the kernel.

16. The non-transitory machine-readable medium for of claim 12 , wherein the AI model is injected to a shared memory between an operating system running on the guest VM and a kernel of the operating system, and the protected AI model is derived from the AI model injected to the shared memory.

17. The non-transitory machine-readable medium for storing a program code of claim 12 , wherein the program code further instructs the processor to execute an isolated execution environment, and the isolated execution environment is arranged to verify a signature of the protected AI model, to ensure safety of the protected AI model before the computations are performed on the protected AI model.

18. The non-transitory machine-readable medium of claim 17 , wherein the hypervisor is further arranged to set a no-read/write mode of the protected AI model by managing and configuring the safety protection component according to the safety setting command.

19. The non-transitory machine-readable medium of claim 12 , wherein the AI model is a crypted AI model, the program code further instructs the processor to execute an isolated execution environment, and the isolated execution environment is arranged to perform decryption on the crypted AI model to generate the protected AI model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2022
From: HSIAO, CHIH-HSIANG; SUEI, PEI-LUN; CHU, YU-CHI
To: MEDIATEK INC.
Reel/Frame 060202/0895 →
Continuity (3)
Provisional Application 63324643 · Mar 29, 2022
Provisional Application 63245235 · Sep 17, 2021
Related Publication 20230092808A1 · Mar 23, 2023
References Cited (33)
US 9520994B2 · Ponsini · 2016 [cited by examiner]
US 10395029B1 · Steinberg · 2019 [cited by examiner]
US 12073005B2 · Knierim · 2024 [cited by examiner]
US 20090089527A1 · Schoenberg · 2009 [cited by examiner]
US 20120047580A1 · Smith · 2012 [cited by examiner]
US 20130347131A1 · Mooring · 2013 [cited by examiner]
US 20170149778A1 · Gill · 2017 [cited by examiner]
US 20180189092A1 · Sanchez Leighton · 2018 [cited by examiner]
US 20190026035A1 · Gokhale · 2019 [cited by examiner]
US 20200019697A1 · Shen · 2020 [cited by examiner]
US 20210026950A1 · Ionescu · 2021 [cited by examiner]
US 20210149741A1 · Mooring · 2021 [cited by examiner]
US 20210240638A1 · Deutsch · 2021 [cited by examiner]
US 20220019698A1 · Durham · 2022 [cited by examiner]
US 20220045853A1 · Buendgen · 2022 [cited by examiner]
US 20220350631A1 · Parry-Barwick · 2022 [cited by examiner]
US 20230092808A1 · Hsiao · 2023 [cited by examiner]
US 20230169343A1 · Lin · 2023 [cited by examiner]
CN 103258150A · 2013 [cited by applicant]
CN 107924441A · 2018 [cited by applicant]
CN 109086100A · 2018 [cited by applicant]
CN 113330723A · 2021 [cited by applicant]
EP 2606450A2 · 2013 [cited by applicant]
EP 2606450A3 · 2013 [cited by applicant]
EP 2606450B1 · 2015 [cited by applicant]
TW 200842646 · 2008 [cited by applicant]
TW 201833775A · 2018 [cited by applicant]
TW 201944280A · 2019 [cited by applicant]
TW 202113648A · 2021 [cited by applicant]
TW 202125224A · 2021 [cited by applicant]
Hsiao, the specification, including the claims, and drawings in the U.S. Appl. No. 17/853,950 , filed Jun. 320, 2022. [cited by applicant]
Search Report mailed/issued on Feb. 10, 2023 for EP application No. 22186802.9, pp. 1˜10. [cited by applicant]
Hsiao, the specification, including the claims, and drawings in the U.S. Appl. No. 17/849,694, filed Jun. 26, 2022. [cited by applicant]