IP Library › Granted Patent US 11,481,680
Granted Patent B2
US 11,481,680 · App. 16/851,507 · Granted Oct 25, 2022

Verifying confidential machine learning models

Inventors: Pankaj S. Dayama (Bangalore, IN); Nitin Singh (Bangalore, IN); Dhinakaran Vinayagamurthy (Bangalore, IN); Vinayaka Pandit (Bangalore, IN)
Assignee: International Business Machines Corporation
G06N20/00G06F11/3466G06F11/3608
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,680
App. No.
16/851,507
Filed
Apr 17, 2020
Granted
Oct 25, 2022
Kind
B2
Art Unit
2193
USPC
706/12
Abstract

Methods, systems, and computer program products for verifying confidential machine learning models are provided herein. A computer-implemented method includes obtaining (i) a set of training data and (ii) a request, from a requestor, for a machine learning model, wherein the request is accompanied by at least a set of test data; obtaining a commitment from a provider in response to the request, the commitment comprising a special hash corresponding to parameters of a candidate machine learning model trained on the set of training data; revealing the set of test data to the requestor; obtaining, from the requestor, (i) a claim of performance of the candidate machine learning model for the test data and (ii) a proof of the performance of the candidate machine learning model; and verifying the claimed performance for the requestor based on (i) the special hash and (ii) the proof of the claimed performance.

Claims (56)

1. A computer-implemented method, the method comprising:

obtaining (i) a set of training data and (ii) a request, from a requestor, for a machine learning model, wherein the request is accompanied by at least a set of test data;

obtaining a commitment from a provider in response to said request, the commitment comprising a special hash corresponding to parameters of a candidate machine learning model trained on the set of training data;

revealing the set of test data to said requestor;

obtaining, from the requestor, (i) a claim of performance of the candidate machine learning model for the test data and (ii) a proof of the performance of the candidate machine learning model; and

verifying the claimed performance for the requestor based on (i) the special hash and (ii) the proof of the claimed performance;

wherein the method is carried out by at least one computing device.

2. The computer-implemented method 1 , wherein the commitment comprises a hiding and binding commitment.

3. The computer-implemented method of claim 1 , wherein the proof of the claimed performance comprises a zero-knowledge performance proof.

4. The computer-implemented method of claim 1 , wherein the special hash maintains confidentiality of the machine learning model from said requestor.

5. The computer-implemented method of claim 1 , wherein the request comprises one or more performance constraints.

6. The computer-implemented method of claim 5 , wherein the one or more performance constraints comprise an accuracy constraint and/or a size constraint.

7. The computer-implemented method of claim 1 , comprising:

sending a request to the provider to verify that output, for a particular input provided by said requestor, corresponds to the candidate machine learning model.

8. The computer-implemented method of claim 7 , comprising:

obtaining a further proof from said requestor corresponding to the particular input; and

verifying the output based at least in part on the further proof.

9. The computer-implemented method of claim 1 , comprising:

providing the candidate machine learning model to the requestor; and

verifying that the provided candidate machine learning model is the same machine learning model used by the provider to generate the proof of the performance.

10. The computer-implemented method of claim 9 , wherein said verifying comprises:

generating a further special hash of the provided candidate machine learning model; and

verifying that the further special hash matches the special hash of the machine learning model used by the provider to generate the proof of the performance.

11. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computing device to cause the computing device:

to obtain (i) a set of training data and (ii) a request, from a requestor, for a machine learning model, wherein the request is accompanied by at least a set of test data;

to obtain a commitment from a provider in response to said request, the commitment comprising a special hash corresponding to parameters of a candidate machine learning model trained on the set of training data;

to reveal the set of test data to said requestor;

to obtain, from the requestor, (i) a claim of performance of the candidate machine learning model for the test data and (ii) a proof of the performance of the candidate machine learning model; and

to verify the claimed performance for the requestor based on (i) the special hash and (ii) the proof of the claimed performance.

12. The computer program product of claim 11 , wherein the commitment comprises a hiding and binding commitment.

13. The computer program product of claim 11 , wherein the proof of the claimed performance comprises a zero-knowledge performance proof.

14. The computer program product of claim 11 , wherein the special hash protects a confidentiality of the machine learning model from said requestor.

15. The computer program product of claim 14 , wherein the request comprises one or more performance constraints, the one or more performance constraints comprising an accuracy constraint and/or a size constraint.

16. The computer program product of claim 11 , wherein the program instructions executable by a computing device further cause the computing device:

to send a request to the provider to verify that output, for a particular input provided by said requestor, corresponds to the candidate machine learning model;

to obtain a further proof from said requestor corresponding to the particular input; and

to verify the output based at least in part on the further proof.

17. A system comprising:

a memory; and

at least one processor operably coupled to the memory and configured for:

obtaining (i) a set of training data and (ii) a request, from a requestor, for a machine learning model, wherein the request is accompanied by at least a set of test data;

obtaining a commitment from a provider in response to said request, the commitment comprising a special hash corresponding to parameters of a candidate machine learning model trained on the set of training data;

revealing the set of test data to said requestor;

obtaining, from the requestor, (i) a claim of performance of the candidate machine learning model for the test data and (ii) a proof of the performance of the candidate machine learning model; and

verifying the claimed performance for the requestor based on (i) the special hash and (ii) the proof of the claimed performance.

18. A computer-implemented method, the method comprising:

obtaining at least one first commitment corresponding to a competition for building a machine learning model based on one or more criteria, the at least one first commitment comprising (i) a set of training data and (ii) a set of test data;

revealing the set of training data to a plurality of competitors of said competition;

obtaining, from said plurality of competitors, a plurality of second commitments corresponding to sets of machine learning model parameters of candidate machine learning models, the candidate machine learning models built based on (i) said set of training data and (ii) said one or more criteria;

revealing, based on said at least one first commitment, the set of test data to said plurality of competitors;

obtaining, from said plurality of competitors, (i) claims of performance of the candidate machine learning models on said set of test data and (ii) zero-knowledge proofs of the claimed performance;

verifying the claimed performances based on (i) the plurality of second commitments and (ii) the zero-knowledge proofs; and

selecting a winner of said competition based at least in part on said verifying, while maintaining confidentiality of said plurality of candidate machine learning models;

wherein the method is carried out by at least one computing device.

19. The computer-implemented method of claim 18 , wherein each of the plurality of second commitments comprises a hiding and binding commitment.

20. The computer-implemented method of claim 18 , wherein the one or more criteria correspond to a type of prediction to be output by said machine learning model.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE 1ST CONVEYING PARTY NAME PREVIOUSLY RECORDED AT REEL: 52427 FRAME: 482. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 21, 2020
From: DAYAMA, PANKAJ S.; SINGH, NITIN; VINAYAGAMURTHY, DHINAKARAN; PANDIT, VINAYAKA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 052453/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2020
From: DAYAMA, PANKAJ; SINGH, NITIN; VINAYAGAMURTHY, DHINAKARAN; PANDIT, VINAYAKA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 052427/0482 →
Continuity (1)
Related Publication 20210326746A1 · Oct 21, 2021
Cited By (1)
US 12,748,894