IP Library Granted Patent US 11,468,291
Granted Patent B2
US 11,468,291 · App. 16/145,287 · Granted Oct 11, 2022

Method for protecting a machine learning ensemble from copying

Inventors: Wilhelmus Petrus Adrianus Johannus Michiels (Reusel, NL); Gerardus Antonius Franciscus Derks (Dongen, NL)
Assignee: NXP B.V.
G06N3/0454G06N3/084G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,468,291
App. No.
16/145,287
Granted
Oct 11, 2022
Kind
B2
Abstract

A method is provided for protecting a machine learning ensemble. In the method, a plurality of machine learning models is combined to form a machine learning ensemble. A plurality of data elements for training the machine learning ensemble is provided. The machine learning ensemble is trained using the plurality of data elements to produce a trained machine learning ensemble. During an inference operating phase, an input is received by the machine learning ensemble. A piecewise function is used to pseudo-randomly choose one of the plurality of machine learning models to provide an output in response to the input. The use of a piecewise function hides which machine learning model provided the output, making the machine learning ensemble more difficult to copy.

Claims (33)

1. A method comprising:

providing a plurality of data elements for training a plurality of machine learning models combined into a machine learning ensemble;

training the plurality of machine learning models of the machine learning ensemble using the plurality of data elements to produce a trained machine learning ensemble; and

pseudo-randomly choosing, using a piecewise function, only one machine learning model of the plurality of machine learning models to receive an input, process the input, and provide an output in response to receiving the input during inference operation of the machine learning ensemble.

2. The method of claim 1 , wherein the piecewise function is further characterized as being a piecewise constant function.

3. The method of claim 1 , wherein each of the plurality of machine learning models is a neural network.

4. The method of claim 1 , wherein each machine learning model of the plurality of machine learning models has a different machine learning algorithm, and wherein the step of pseudo-randomly choosing takes the input as a seed for providing pseudo-randomness.

5. The method of claim 1 , wherein the pseudo-random function is defined as F:2 S →{0, 1, k−1} where s is a bit size of the input during the inference operation, and k is the number of machine learning models in the plurality of machine learning models.

6. The method of claim 1 , wherein training the machine learning ensemble uses a back-propagation training algorithm to produce the trained machine learning ensemble.

7. The method of claim 1 , wherein the training of each machine learning model of the plurality of machine learning models uses one of either a same training set selected from the plurality of data elements, different training sets that have one or more of the same data elements, and disjunct training sets.

8. The method of claim 1 , wherein all machine learning models of the plurality of machine learning models are binary classification models.

9. A method comprising:

combining a plurality of machine learning models into a machine learning ensemble;

providing a plurality of data elements for training the plurality of machine learning models of the machine learning ensemble;

training the machine learning ensemble using the plurality of data elements to produce a trained machine learning ensemble;

receiving an input during inference operation of the machine learning ensemble; and

pseudo-randomly choosing, using a piecewise constant function, only one machine learning model of the plurality of machine learning models to receive the input, process the input, and provide an output in response to the input.

10. The method of claim 9 , wherein each of the plurality of machine learning models is a neural network.

11. The method of claim 9 , wherein each machine learning model of the plurality of machine learning models has a different machine learning algorithm, and wherein the step of pseudo-randomly choosing takes the input as a seed for providing pseudo-randomness.

12. The method of claim 9 , wherein the pseudo-random function is defined as F:2 S →{0, 1, k−1} where s is a bit size of the input during the inference operation, and k is the number of machine learning models in the plurality of machine learning models.

13. The method of claim 9 , wherein training the machine learning ensemble uses a back-propagation training algorithm to produce the trained machine learning ensemble.

14. The method of claim 9 , wherein the training of each machine learning model of the plurality of machine learning models uses one of either a same training set selected from the plurality of data elements, different training sets that have one or more of the same data elements, and disjunct training sets.

15. The method of claim 9 , wherein all machine learning models of the plurality of machine learning models are binary classification models.

16. A method comprising:

combining a plurality of machine learning models into a machine learning ensemble;

providing a plurality of data elements for training the plurality of machine learning models of the machine learning ensemble, each machine learning model of the plurality of machine learning models are implemented differently;

training the plurality of machine learning models of the machine learning ensemble using the plurality of data elements to produce a trained machine learning ensemble;

receiving an input during inference operation of the machine learning ensemble; and

pseudo-randomly choosing, using a piecewise constant function, only one machine learning model of the plurality of machine learning models to receive the input, process the input, and provide an output in response to the input.

17. The method of claim 16 , wherein each machine learning model of the plurality of machine learning models is implemented with a different machine learning algorithm, and wherein the step of pseudo-randomly choosing takes the input as a seed for providing pseudo-randomness.

18. The method of claim 16 , training the plurality of machine learning models of the machine learning ensemble uses a back-propagation training algorithm to produce the trained machine learning ensemble.

19. The method of claim 16 , wherein each machine learning model of the plurality of machine learning models uses one of either a same training set selected from the plurality of data elements, different training sets that have one or more of the same data elements, and disjunct training sets.

20. The method of claim 16 , wherein all machine learning models of the plurality of machine learning models are binary classification models.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2018
From: MICHIELS, WILHELMUS PETRUS ADRIANUS JOHANNUS; DERKS, GERARDUS ANTONIUS FRANCISCUS
To: NXP B.V.
Reel/Frame 047161/0535 →
Continuity (1)
Related Publication 20200104673A1 · Apr 2, 2020
Cited By (2)
US 12,717,904 US 12,731,075