IP Library Granted Patent US 12,367,308
Granted Patent B2
US 12,367,308 · App. 18/214,814 · Granted Jul 22, 2025

Domain adaptation-based disguising of prompts for data privacy in foundation models

Inventors: Paulo Rodrigo Cavalin (Rio de Janeiro, BR); Julio Nogima (São Paulo, BR); Pedro Henrique Domingues (Rio de Janeiro, BR)
Assignee: International Business Machines Corporation
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,308
App. No.
18/214,814
Granted
Jul 22, 2025
Kind
B2
Abstract

A privacy-preserving method of accessing a model as a service (e.g., a language model) receives an input prompt authored in a first domain having data intended to be maintained private. In response, and using a conversion model, the input prompt authored in the first domain is converted to a second domain to create a converted input prompt. The converted input prompt preserves a semantic context of the input prompt. The converted input prompt is then delivered to the model as a service, which returns a response in the second domain. Using the conversion model, the response is then converted back into the first domain to create a converted response. The converted response has the semantic context of the input prompt. The converted response is provided as a reply to the input prompt. The conversion model may be trained using data collected from user interactions with the model as a service.

Claims (49)

1. A privacy-preserving method of accessing a model as a service, comprising:

receiving an input prompt authored in a first domain, the first domain including data intended to be maintained private;

responsive to receipt of the input prompt, and using a conversion model that is distinct from the model as a service, converting the input prompt authored in the first domain to a second domain to create a converted input prompt, the converted input prompt preserving a semantic context of the input prompt;

in lieu of providing the input prompt authored in the first domain to the model as a service, providing the converted input prompt;

receiving from the model as a service a response to the converted input prompt, the response being in the second domain;

responsive to receipt of the response, and using the conversion model, converting the response back into the first domain to create a converted response, the converted response having the semantic context of the input prompt; and

providing the converted response as a reply to the input prompt.

2. The method as described in claim 1 , further including training the conversion model.

3. The method as described in claim 2 , wherein the conversion model is trained using data collected from user interactions with the model as a service.

4. The method as described in claim 2 , further including selecting the second domain from one or more domains other than the first domain.

5. The method as described in claim 2 , wherein the conversion model is a language conversion model, and wherein training the language conversion model includes:

building a parallel corpus between data found in the first domain and data found in the second domain;

evaluating whether the parallel corpus satisfies a given threshold; and

when the parallel corpus satisfies the given threshold, training the language conversion model to learn the parallel corpus.

6. The method as described in claim 5 , further including validating the language conversion model against a labeled dataset of private data prior to deploying the language conversion model for inferencing in association with the model as a service.

7. The method as described in claim 1 , wherein the model as a service is deployed as one of: a language model, and an image model.

8. An apparatus, comprising:

a processor;

computer memory holding computer program instructions executed by the processor to enable privacy-preserving access to a model as a service, the computer program instructions comprising program code configured to:

receive an input prompt authored in a first domain, the first domain including data intended to be maintained private;

respond to receipt of the input prompt, and using a conversion model that is distinct from the model as a service, convert the input prompt authored in the first domain to a second domain to create a converted input prompt, the converted input prompt preserving a semantic context of the input prompt;

in lieu of providing the input prompt authored in the first domain to the model as a service, provide the converted input prompt;

receive from the model as a service a response to the converted input prompt, the response being in the second domain;

respond to receipt of the response, and using the conversion model, convert the response back into the first domain to create a converted response, the converted response having the semantic context of the input prompt; and

provide the converted response as a reply to the input prompt.

9. The apparatus as described in claim 8 , further including program code configured to train the conversion model.

10. The apparatus as described in claim 9 , wherein the conversion model is trained using data collected from user interactions with the model as a service.

11. The apparatus as described in claim 9 , wherein the conversion model is a language conversion model, and wherein the program code configured to train the language conversion model further includes program code to select the second domain from one or more domains other than the first domain.

12. The apparatus as described in claim 11 , wherein the program code configured to train the language conversion model further includes program code configured to:

build a parallel corpus between data found in the first domain and data found in the second domain;

evaluate whether the parallel corpus satisfies a given threshold; and

when the parallel corpus satisfies the given threshold, train the language conversion model to learn the parallel corpus.

13. The apparatus as described in claim 12 , further including program code to validate the language conversion model against a labeled dataset of private data prior to deploying the language conversion model for inferencing in association with the model as a service.

14. The apparatus as described in claim 8 , wherein the model as a service is deployed as one of: a language model, and an image model.

15. A computer program product in a non-transitory computer readable medium, the computer program product holding computer program instructions that, when executed by a processor in a host processing system, enable privacy-preserving access to a model as a service, the computer program instructions comprising program code configured to:

receive an input prompt authored in a first domain, the first domain including data intended to be maintained private;

respond to receipt of the input prompt, and using a conversion model that is distinct from the model as a service, convert the input prompt authored in the first domain to a second domain to create a converted input prompt, the converted input prompt preserving a semantic context of the input prompt;

in lieu of providing the input prompt authored in the first domain to the model as a service, provide the converted input prompt;

receive from the model as a service a response to the converted input prompt, the response being in the second domain;

respond to receipt of the response, and using the conversion model, convert the response back into the first domain to create a converted response, the converted response having the semantic context of the input prompt; and

provide the converted response as a reply to the input prompt.

16. The computer program product as described in claim 15 , further including program code configured to train the conversion model.

17. The computer program product as described in claim 16 , wherein the conversion model is trained using data collected from user interactions with the model as a service.

18. The computer program product as described in claim 16 , wherein the conversion model is a language conversion model, and wherein the program code configured to train the language conversion model further includes program code to select the second domain from one or more domains other than the first domain.

19. The computer program product as described in claim 18 , wherein the program code configured to train the language conversion model further includes program code configured to:

build a parallel corpus between data found in the first domain and data found in the second domain;

evaluate whether the parallel corpus satisfies a given threshold; and

when the parallel corpus satisfies the given threshold, train the language conversion model to learn the parallel corpus.

20. The computer program product as described in claim 19 , further including program code to validate the language conversion model against a labeled dataset of private data prior to deploying the language conversion model for inferencing in association with the model as a service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2024
From: RODRIGO CAVALIN, PAULO; NOGIMA, JULIO; DOMINGUES, PEDRO HENRIQUE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066334/0844 →
Continuity (1)
Related Publication 20250005182A1 · Jan 2, 2025
References Cited (25)
US 7765310B2 · Graveline et al. · 2010 [cited by applicant]
US 8140502B2 · Francis et al. · 2012 [cited by applicant]
US 10181049B1 · El Defrawy et al. · 2019 [cited by applicant]
US 10268834B2 · Pourzandi et al. · 2019 [cited by applicant]
US 10346627B2 · Kaliski, Jr. · 2019 [cited by applicant]
US 10810313B2 · Cannings et al. · 2020 [cited by applicant]
US 11139958B2 · Smith et al. · 2021 [cited by applicant]
US 20170372226A1 · Costa et al. · 2017 [cited by applicant]
US 20220391768A1 · Li et al. · 2022 [cited by applicant]
US 20240402801A1 · Shutzberg · 2024 [cited by examiner]
US 20240430233A1 · Tanner · 2024 [cited by examiner]
KR 102432003B1 · 2022 [cited by applicant]
WO 2022078021A1 · 2022 [cited by applicant]
Zhao, et al., “Learning Domain Invariant Prompt for Vision-Language Models,” arXiv:2212.04196v2 [cs.CV] Mar. 31, 2023. [cited by applicant]
Zhao, et al. “FedPrompt: Communication-Efficient and Privacy-Preserving Prompt Tuning in Federated Learning,” arXiv:2208.12268v3 [cs.LG] Jan. 24, 2023. [cited by applicant]
Sun, et al., “Black-Box Tuning for Language-Model-as-a-Service,” arXiv:2201.03514v4 [cs.CL] Jun. 27, 2022. [cited by applicant]
Chen, et al., “AdaPrompt: Adaptive Model Training for Prompt-based NLP,” arXiv:2202.04824v2 [cs.CL] Nov. 18, 2022. [cited by applicant]
Huang, et al., “TextHide: Tackling Data Privacy in Language Understanding Tasks,” EMNLP 2020, pp. 1368-1382 Nov. 16, 2020. [cited by applicant]
Han, et al., “Privacy-Preserving Multi-Source Domain Adaptation for Medical Data,” IEEE Journal of Biomedical and Health Informatics, May 2022. [cited by applicant]
An, el al., “A Privacy-Preserving Unsupervised Domain Adaptation Framework for Clinical Text Analysis,” arXiv:2201.07317v1 [cs.CL] Jan. 18, 2022. [cited by applicant]
Cavalin, et al., “From Disjoint Sets to Parallel Data To Train SeqZSeq Models For Sentiment Transfer,” EMNLP 2020, pp. 689-698, Nov. 16, 2020. [cited by applicant]
Vaswani, et al., “Attention is All You Need,” 31st Conference on Neural Information Processing Systems (NIPS 2017). [cited by applicant]
“Prompt papers”, retrieved from web https://github.com/thunlp/PromptPapers, Mar. 2023, 15 pages. [cited by applicant]
David et al, “PADA: Example-based Prompt Learning for on-the-fly Adaptation to Unseen Domains”, Transactions of the Association for Computational Linguistics, Apr. 11, 2022, pp. 414-433, https://direct.mit.edu/tacl/arti… [cited by applicant]
Dowlin et al. “CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy”, Proceedings of Machine Learning Research, 2016, 12 pages, https://proceedings.mlr.press/v48/gilad-bachrach16.pdf. [cited by applicant]