IP Library Granted Patent US 11,645,116
Granted Patent B2
US 11,645,116 · App. 16/598,192 · Granted May 9, 2023

Method and system for making an artificial intelligence inference using a watermark-enabled kernel for a data processing accelerator

Inventors: Yueqiang Cheng (Sunnyvale, CA); Yong Liu (Sunnyvale, CA)
Assignees: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
G06F9/5027G06F21/16G06N5/04G06N20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,645,116
App. No.
16/598,192
Granted
May 9, 2023
Kind
B2
Abstract

In one embodiment, a computer-implemented method performed by a data processing (DP) accelerator, includes receiving, at the DP accelerator, first data representing an artificial intelligence (AI) model that has been previously trained from a host processor and a set of input data; receiving, at the DP accelerator, a watermark kernel from the host processor; and executing the watermark kernel within the DP accelerator on the AI model. The watermark kernel, when executed, is configured to: perform inference operations of the artificial intelligence model based on the input data to generate output data, and implant the watermark within the output data. The DP accelerator then transmits the output data having the watermark implanted therein to the host processor.

Claims (38)

1. A computer-implemented method performed by a data processing (DP) accelerator, the method comprising:

receiving, at the DP accelerator from a host processor, a trained artificial intelligence (AI) model, a watermark kernel, and a set of input data;

executing, by the DP accelerator, the watermark kernel on the trained AI model, wherein the executing further comprises:

performing, by the AI model, inference operations on the set of input data to produce output data;

extracting, by the watermark kernel, a watermark from the AI model; and

implanting, by the watermark kernel, the watermark into the output data; and

transmitting, from the DP accelerator, the output data comprising the implanted watermark to the host processor.

2. The method of claim 1 , further comprising receiving a second set of input data from the host processor, wherein the watermark kernel is executed on the second set of input data, and wherein the watermark is generated based on the second set of input data.

3. The method of claim 2 , wherein the second set of input data includes information describing the watermark.

4. The method of claim 1 , wherein implanting the watermark in the AI model comprises embedding the watermark in one or more nodes of the AI model.

5. The method of claim 4 , wherein the watermark is stored in one or more weight variables of the one or more nodes of the AI model.

6. The method of claim 4 , wherein the watermark is stored in one or more bias variables of the one or more nodes of the AI model.

7. The method of claim 1 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

8. The method of claim 1 , wherein the host processor and DP accelerator communicate over a link that comprises a peripheral component interconnect express (PCIe) link.

9. A data processing (DP) accelerator, comprising:

an interface to receive first data representing an artificial intelligence (AI) model that has been previously trained, a set of input data, and to receive a watermark kernel from a host processor; and

a kernel executor to execute the watermark kernel on the AI model, wherein the watermark kernel, when executed, is configured to:

perform inference operations of the AI model on the set of input data to produce output data;

extract a watermark from the AI model; and

implant the watermark into the output data; and

wherein the output data generated from the inference operations having the watermark implanted therein is transmitted to the host processor.

10. The DP accelerator of claim 9 , wherein a second set of input data is further received from the host processor, wherein the watermark kernel is executed on the set of input data, and wherein the watermark is generated based on the set of input data.

11. The DP accelerator of claim 10 , wherein the second set of input data includes information describing the watermark.

12. The DP accelerator of claim 9 , wherein implanting the watermark in the AI model comprises embedding the watermark in one or more nodes of the AI model.

13. The DP accelerator of claim 12 , wherein the watermark is stored in one or more weight variables of the one or more nodes of the AI model.

14. The DP accelerator of claim 12 , wherein the watermark is stored in one or more bias variables of the one or more nodes of the AI model.

15. The DP accelerator of claim 9 , wherein the host processor is a central processing unit (CPU) and the DP accelerator is a general-purpose processing unit (GPU).

16. The DP accelerator of claim 9 , wherein the host processor and DP accelerator communicate over a link that comprises a peripheral component interconnect express (PCIe) link.

17. A non-transitory machine-readable medium having instructions stored therein, which when executed by a data processing (DP) accelerator, cause the DP accelerator to perform operations, the operations comprising:

receiving, at the DP accelerator from a host processor, a trained artificial intelligence (AI) model, a watermark kernel, and a set of input data;

executing, by the DP accelerator, the watermark kernel on the trained AI model, wherein the executing further comprises:

performing, by the AI model, inference operations on the set of input data to produce output data;

extracting, by the watermark kernel, a watermark from the AI model; and

implanting, by the watermark kernel, the watermark into the output data; and

transmitting, from the DP accelerator, the output data comprising the implanted watermark to the host processor.

18. The machine-readable medium of claim 17 , wherein the operations further comprise receiving a second set of input data from the host processor, wherein the watermark kernel is executed on the second set of input data, and wherein the watermark is generated based on the second set of input data.

19. The machine-readable medium of claim 18 , wherein the second set of input data includes information describing the watermark.

20. The machine-readable medium of claim 17 , wherein implanting the watermark in the AI model comprises embedding the watermark in one or more nodes of the AI model.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: BAIDU USA LLC
To: BAIDU USA LLC; KUNLUNXIN TECHNOLOGY (BEIJING) COMPANY LIMITED
Reel/Frame 057829/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2019
From: CHENG, YUEQIANG; LIU, YONG
To: BAIDU USA LLC
Reel/Frame 050690/0348 →
Continuity (1)
Related Publication 20210109791A1 · Apr 15, 2021