IP Library › Granted Patent US 12,572,650
Granted Patent B2
US 12,572,650 · App. 18/147,763 · Granted Mar 10, 2026

System and method for managing AI models using view level analysis

Inventors: Ofir Ezrielev (Be'er Sheva, IL); Amihai Savir (Newton, MA); Tomer Kushnir (Omer, IL)
Assignee: Dell Products L.P.
G06F21/56G06F21/554G06N5/04G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,650
App. No.
18/147,763
Granted
Mar 10, 2026
Kind
B2
Abstract

Methods and systems for managing an attack on an artificial intelligence (AI) model using view level analysis are disclosed. As AI models are updated over time using new training data, snapshots of the AI models may be obtained. The snapshots may include information regarding the training data used to train the AI model, the parameters of the AI model, and/or the inferences obtained from the AI model. A malicious party may perform an attack on the AI model by introducing poisoned training data through a data source. The content of supplied poisoned training data may be determined based on a view level into the AI model. The view level of the malicious party may be used to design countermeasures to mitigate and/or prevent future attacks to the AI model.

Claims (96)

1 . A method for managing an artificial intelligence (AI) model, comprising:

identifying a poisoned training dataset that was used to train an AI model instance; and

after identifying the poisoned training dataset:

identifying, based at least in part on the poisoned training dataset, a portion of a snapshot of the AI model instance that a malicious party had visibility into when selecting content of the poisoned training dataset by performing at least a training data view analysis to obtain a training data view analysis result, the training data view analysis comprising:

attempting to match a portion of the poisoned training dataset to a portion of a first ingest dataset obtained from a data source that did not provide the poisoned training dataset in order to identify a quantity of the poisoned training dataset that matches the first ingest dataset; and

making a first determination, using the quantity and a criterion associated with the quantity, regarding whether the malicious party had visibility into the first ingest dataset from the portion of the snapshot;

classifying an amount of information the malicious party has regarding the AI model instance based on the portion of the snapshot to obtain a view level classification, the view level classification being used to identify one or more systems that are compromised; and

performing a remediation based on the view level classification.

2 . The method of claim 1 , wherein identifying the portion of the snapshot further comprises:

performing a model weight view analysis to obtain a model weight view analysis result, the model weight view analysis being based on:

the poisoned training dataset,

a second ingest dataset from a data source that provided the poisoned training dataset, and

inferences generated using the second ingest dataset.

3 . The method of claim 2 , wherein performing the model weight view analysis comprises:

enumerating the poisoned training dataset to identify a first cardinality of a portion of the second ingest dataset;

enumerating the second ingest dataset to identify a second cardinality of the second ingest dataset;

obtaining, using the first cardinality and the second cardinality, a quantification statistic; and

based on the quantification statistic and a criterion for the quantification statistic, making a second determination regarding whether the malicious party had visibility into a model weight from the portion of the snapshot.

4 . The method of claim 3 , wherein the model weight view analysis result indicates:

in a first instance of the second determination where the quantification statistic satisfies the criterion:

that the malicious party had visibility of the model weight while selecting content of the poisoned training dataset; and

in a second instance of the second determination where the quantification statistic fails to satisfy the criterion:

that the malicious party did not have visibility of the model weight while selecting the content of the poisoned training dataset.

5 . The method of claim 4 , wherein

the training data view analysis is based on:

the poisoned training dataset,

the first ingest dataset, and

inferences generated using the first ingest dataset.

6 . The method of claim 5 , wherein performing the training data view analysis further comprises:

obtaining, using the quantity of the poisoned training dataset and before making the first determination, a second quantification statistic, wherein the first determination is made based on the second quantification statistic and the criterion associated with the quantity is a second criterion for the second quantification statistic.

7 . The method of claim 6 , wherein the training data view analysis result indicates:

in a first instance of the first determination where the second quantification statistic satisfies the second criterion:

that the malicious party had visibility of the first ingest dataset and the inferences generated using the first ingest dataset while selecting the content of the poisoned training dataset; and

in a second instance of the first determination where the second quantification statistic fails to satisfy the second criterion:

that the malicious party did not have visibility of the first ingest dataset and the inferences generated using the first ingest dataset while selecting the content of the poisoned training dataset.

8 . The method of claim 1 , wherein performing the remediation based on the view level classification comprises:

performing an action set to secure the one or more systems that are compromised.

9 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing an artificial intelligence (AI) model, the operations comprising:

identifying a poisoned training dataset that was used to train an AI model instance; and

after identifying the poisoned training dataset:

identifying, based at least in part on the poisoned training dataset, a portion of a snapshot of the AI model instance that a malicious party had visibility into when selecting content of the poisoned training dataset by performing at least a training data view analysis to obtain a training data view analysis result, the training data view analysis comprising:

attempting to match a portion of the poisoned training dataset to a portion of a first ingest dataset obtained from a data source that did not provide the poisoned training dataset in order to identify a quantity of the poisoned training dataset that matches the first ingest dataset; and

making a first determination, using the quantity and a criterion associated with the quantity, regarding whether the malicious party had visibility into the first ingest dataset from the portion of the snapshot;

classifying an amount of information the malicious party has regarding the AI model instance based on the portion of the snapshot to obtain a view level classification, the view level classification being used to identify one or more systems that are compromised; and

performing a remediation based on the view level classification.

10 . The non-transitory machine-readable medium of claim 9 , wherein identifying the portion of the snapshot further comprises:

performing a model weight view analysis to obtain a model weight view analysis result, the model weight view analysis being based on:

the poisoned training dataset,

a second ingest dataset from a data source that provided the poisoned training dataset, and

inferences generated using the second ingest dataset.

11 . The non-transitory machine-readable medium of claim 10 , wherein performing the model weight view analysis comprises:

enumerating the poisoned training dataset to identify a first cardinality of a portion of the second ingest dataset;

enumerating the second ingest dataset to identify a second cardinality of the second ingest dataset;

obtaining, using the first cardinality and the second cardinality, a quantification statistic; and

based on the quantification statistic and a criterion for the quantification statistic, making a second determination regarding whether the malicious party had visibility into a model weight from the portion of the snapshot.

12 . The non-transitory machine-readable medium of claim 11 , wherein the model weight view analysis result indicates:

in a first instance of the second determination where the quantification statistic satisfies the criterion:

that the malicious party had visibility of the model weight while selecting content of the poisoned training dataset; and

in a second instance of the second determination where the quantification statistic fails to satisfy the criterion:

that the malicious party did not have visibility of the model weight while selecting the content of the poisoned training dataset.

13 . The non-transitory machine-readable medium of claim 12 , wherein

the training data view analysis being based on:

the poisoned training dataset,

the first ingest dataset, and

inferences generated using the first ingest dataset.

14 . The non-transitory machine-readable medium of claim 13 , wherein performing the training data view analysis further comprises:

obtaining, using the quantity of the poisoned training dataset and before making the first determination, a second quantification statistic, wherein the first determination is made based on the second quantification statistic and the criterion associated with the quantity is a second criterion for the second quantification statistic.

15 . The non-transitory machine-readable medium of claim 9 , wherein performing the remediation based on the view level classification comprises:

performing an action set to secure the one or more systems that are compromised.

16 . A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing an artificial intelligence (AI) model, the operations comprising:

identifying a poisoned training dataset that was used to train an AI model instance; and

after identifying the poisoned training dataset:

identifying, based at least in part on the poisoned training dataset, a portion of a snapshot of the AI model instance that a malicious party had visibility into when selecting content of the poisoned training dataset by performing at least a training data view analysis to obtain a training data view analysis result, the training data view analysis comprising:

attempting to match a portion of the poisoned training dataset to a portion of a first ingest dataset obtained from a data source that did not provide the poisoned training dataset in order to identify a quantity of the poisoned training dataset that matches the first ingest dataset; and

making a first determination, using the quantity and a criterion associated with the quantity, regarding whether the malicious party had visibility into the first ingest dataset from the portion of the snapshot;

classifying an amount of information the malicious party has regarding the AI model instance based on the portion of the snapshot to obtain a view level classification, the view level classification being used to identify one or more systems that are compromised; and

performing a remediation based on the view level classification.

17 . The data processing system of claim 16 , wherein identifying the portion of the snapshot further comprises:

performing a model weight view analysis to obtain a model weight view analysis result, the model weight view analysis being based on:

the poisoned training dataset,

a second ingest dataset from a data source that provided the poisoned training dataset, and

inferences generated using the second ingest dataset.

18 . The data processing system of claim 17 , wherein performing the model weight view analysis comprises:

enumerating the poisoned training dataset to identify a first cardinality of a portion of the second ingest dataset;

enumerating the second ingest dataset to identify a second cardinality of the second ingest dataset;

obtaining, using the first cardinality and the second cardinality, a quantification statistic; and

based on the quantification statistic and a criterion for the quantification statistic, making a second determination regarding whether the malicious party had visibility into a model weight from the portion of the snapshot.

19 . The data processing system of claim 18 , wherein the model weight view analysis result indicates:

in a first instance of the second determination where the quantification statistic satisfies the criterion:

that the malicious party had visibility of the model weight while selecting content of the poisoned training dataset; and

in a second instance of the second determination where the quantification statistic fails to satisfy the criterion:

that the malicious party did not have visibility of the model weight while selecting the content of the poisoned training dataset.

20 . The data processing system of claim 16 , wherein performing the remediation based on the view level classification comprises:

performing an action set to secure the one or more systems that are compromised.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2022
From: EZRIELEV, OFIR; SAVIR, AMIHAI; KUSHNIR, TOMER
To: DELL PRODUCTS L.P.
Reel/Frame 062244/0886 →
Continuity (1)
Related Publication 20240220615A1 · Jul 4, 2024
References Cited (76)
US 10936969B2 · Patel et al. · 2021 [cited by applicant]
US 11087170B2 · Malaya · 2021 [cited by applicant]
US 11487963B2 · Angel · 2022 [cited by applicant]
US 11544501B2 · Dong · 2023 [cited by applicant]
US 11636726B2 · Purohit · 2023 [cited by applicant]
US 11645515B2 · Angel · 2023 [cited by applicant]
US 11689566B2 · Baracaldo-Angel · 2023 [cited by applicant]
US 11785024B2 · Karam · 2023 [cited by applicant]
US 11797672B1 · Beveridge · 2023 [cited by applicant]
US 11829193B2 · Shukla · 2023 [cited by applicant]
US 11847217B2 · Healy · 2023 [cited by applicant]
US 11921903B1 · Beveridge · 2024 [cited by applicant]
US 11991240B2 · Ezrielev et al. · 2024 [cited by applicant]
US 12032541B2 · Hasabnis · 2024 [cited by applicant]
US 12126640B2 · Woodworth · 2024 [cited by applicant]
US 12143405B2 · Chen Kaidi · 2024 [cited by applicant]
US 12175008B2 · Ezrielev et al. · 2024 [cited by applicant]
US 20170177860A1 · Suarez · 2017 [cited by applicant]
US 20180255023A1 · Whaley · 2018 [cited by applicant]
US 20190377873A1 · Murphy · 2019 [cited by applicant]
US 20190384790A1 · Bequet · 2019 [cited by applicant]
US 20200019821A1 · Baracaldo-Angel · 2020 [cited by applicant]
US 20200050945A1 · Chen · 2020 [cited by applicant]
US 20200057857A1 · Roytman · 2020 [cited by applicant]
US 20200082097A1 · Poliakov · 2020 [cited by applicant]
US 20200082270A1 · Gu · 2020 [cited by applicant]
US 20200134374A1 · Oros · 2020 [cited by applicant]
US 20200244674A1 · Arzani · 2020 [cited by applicant]
US 20210073685A1 · Veshchikov · 2021 [cited by applicant]
US 20210081708A1 · Angel · 2021 [cited by examiner]
US 20210081831A1 · Angel · 2021 [cited by applicant]
US 20210097400A1 · Lee · 2021 [cited by applicant]
US 20210209512A1 · Gaddam et al. · 2021 [cited by applicant]
US 20210303695A1 · Grosse · 2021 [cited by examiner]
US 20210374247A1 · Sultana · 2021 [cited by examiner]
US 20210398020A1 · Ahmad et al. · 2021 [cited by applicant]
US 20220166782A1 · Zoldi · 2022 [cited by applicant]
US 20220179840A1 · Chatterjee · 2022 [cited by applicant]
US 20220368706A1 · Tang · 2022 [cited by applicant]
US 20220414492A1 · Jezewski · 2022 [cited by applicant]
US 20230004654A1 · Jurzak · 2023 [cited by applicant]
US 20230079112A1 · Cheruvu · 2023 [cited by applicant]
US 20230134218A1 · Semenov · 2023 [cited by applicant]
US 20230148116A1 · Stokes, III · 2023 [cited by examiner]
US 20230164162A1 · Lee · 2023 [cited by applicant]
US 20230222385A1 · Shimizu · 2023 [cited by examiner]
US 20230274003A1 · Liu · 2023 [cited by examiner]
US 20230274192A1 · Wang · 2023 [cited by applicant]
US 20230421629A1 · Ezrielev · 2023 [cited by applicant]
US 20240015019A1 · Sneider · 2024 [cited by applicant]
US 20240020580A1 · Brower · 2024 [cited by applicant]
US 20240048977A1 · Marzban · 2024 [cited by applicant]
US 20240119153A1 · Ludmir · 2024 [cited by applicant]
US 20240364534A1 · Ezrielev · 2024 [cited by applicant]
US 20250053664A1 · Cameron · 2025 [cited by applicant]
US 20250055762A1 · Walker · 2025 [cited by applicant]
WO WO2020040777A1 · 2020 [cited by examiner]
WO WO2021213626A1 · 2021 [cited by examiner]
WO 2022216142A1 · 2022 [cited by applicant]
WO 2023111287A1 · 2023 [cited by applicant]
Paduraru, Ciprian, Marius-Constantin Melemciuc, and Bogdan Ghimis. “Fuzz Testing with Dynamic Taint Analysis based Tools for Faster Code Coverage.” ICSOFT 19 (2019): 82-93. (Year: 2019). [cited by examiner]
Jiang, Bingchen, and Zhao Li. “Defending against backdoor attack on graph nerual network by explainability.” arXiv preprint arXiv:2209.02902, 10 pages, (Year: 2022). [cited by examiner]
Raghavan, Vijay, Thomas Mazzuchi, and Shahram Sarkani. “Discover Artificial Intelligence: An improved real time detection of data poisoning attacks in deep learning vision systems”, 17 pages, Discover 2022, (Year: 2022). [cited by examiner]
Anastasovski, Goce, “Classification of Malicious Web Traffic” (2013), Graduate Theses, Dissertations, and Problem Reports 153 (118 Pages). [cited by applicant]
Joshi, Naveen, “Is The Data Used For Training Your Machine Learning Model Safe?”, Technology For You, Jul. 28, 2022, <https://www.technologyforyou.org/is-the-data-used-for-training-your-machine-learning-model-safe/> (3 … [cited by applicant]
Wang, Siruo et al., “Methods for correcting inference based on outcomes predicted by machine learning.” Proceedings of the National Academy of Sciences 117.48 (2020): 30266-30275. (10 Pages). [cited by applicant]
Rauschmayr, Nathalie et al., “Detecting and analyzing incorrect model predictions with Amazon SageMaker Model Monitor and Debugger”, AWS Machine Learning Blog, Jul. 9, 2020, <https://aws.amazon.com/blogs/machine-learnin… [cited by applicant]
Higgins, Kelly Jackson, “Honeypot Stings Attackers With Counterattacks”, Dark Reading, Mar. 26, 2013, <https://www.darkreading.com/vulnerabilities-threats/honeypot-stings-attackers-with-counterattacks> (4 Pages). [cited by applicant]
Susmelj, Igor, “The Data You Don't Need: Removing Redundant Samples”, Towards Data Science, Mar. 19, 2020, <https://towardsdatascience.com/the-data-you-don-t-need-removing-redundant-samples-6bfd07c1516c> (10 Pages). [cited by applicant]
“The Machine Learning Minefield—How to Avoid Getting Hit by Machine Learning Poisoning” retrieved from <https://ayc-data.com > Mar. 22, 2022 > data-poisoning> on May 1, 2025 (10 pages). [cited by applicant]
Zhang et al., “FL Detector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious Clients”, Available at https://arxiv.org/abs/2207.092009 (Year: 2022), (11 pages). [cited by applicant]
Tran et al., “Manipulating Machine Learning Poisoning Attacks and Countermeasures for Regression Learning”, 32nd Conference on Neural Information Processing Systems (NeurIPS 2018), Montreal, Canada; 2018, pp. 1-11 (Year… [cited by applicant]
Zeng et al., “CNNComparator: Comparative Analytics of Convolutional Neural Networks”, arXiv: 1710.05285v1 [cs.LG] Oct. 15, 2017, pp. 1-5 (Year: 2017), (5 pages). [cited by applicant]
Hendrycks et al., “Natural Adversarial Examples”, arXiv:1907.07174v4[cs.LG] Mar. 4, 2021; pp. 1-16 (Year:2021), (16 pages). [cited by applicant]
Xu et al., “Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks”, In Network and Distributed Systems Security Symposium (NDSS) 2018, San Diego, Feb. 2018; arXiv:1704.01155v2 [cs.CV] Dec. 5, 2017; p… [cited by applicant]
Lao; “Reorienting Machine Learning Education Towards Tinkerers and ML-Engaged Citizens”, Doctoral Dissertation; Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science; 2020; pp.… [cited by applicant]