IP Library › Granted Patent US 12,001,577
Granted Patent B1
US 12,001,577 · App. 17/491,380 · Granted Jun 4, 2024

Encrypted machine learning models

Inventors: Yuanjun Xiong (Seattle, WA); Jia Bi Zhang (Kirkland, WA); Bing Shuai (Seattle, WA); Juan Pablo Escalona Garcia (Edmonds, WA)
Assignee: Amazon Technologies, Inc.
G06F21/6218G06N3/04H04L9/008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,577
App. No.
17/491,380
Granted
Jun 4, 2024
Kind
B1
Abstract

A machine learning model, such as a neural network, is partially encrypted with a homomorphic encryption scheme. Application of the machine learning model to data includes performing operations on plaintext and encrypting results of operations for input to other operations that are performed over cyphertext. Ciphertext output of such operations can be provided to a service that is able to decrypt the ciphertext output.

Claims (35)

1. A computer-implemented method, comprising:

obtaining input data to be processed using a machine learning model, the obtained input data being in plaintext form;

using a first portion of the machine learning model, comprising a first set of layers of a neural network, to calculate plaintext intermediate data, the first portion of the machine learning model, comprising a second set of layers of the neural network, in plaintext form and a second portion of the machine learning model in ciphertext form according to a homomorphic encryption scheme;

using the homomorphic encryption scheme to encrypt the plaintext intermediate data to obtain ciphertext intermediate data;

using the second portion of the machine learning model to obtain, without decrypting the ciphertext intermediate data, encrypted output data according to the homomorphic encryption scheme; and

transmitting a request to a service to cause the service to decrypt the encrypted output data and provide corresponding plaintext output data in response to the request.

2. The computer-implemented method of claim 1 , wherein the second portion of the machine learning model comprises neural network components that are individually encrypted.

3. The computer-implemented method of claim 1 , wherein the method is performed by a computing device and the service runs in a trusted execution environment of the computing device.

4. A system, comprising:

one or more processors; and

memory that stores computer-executable instructions that are executable by the one or more processors to cause the system to:

obtain data indicating a portion of a machine learning model, comprising a set of layers of a neural network, to encrypt;

obtain a partially encrypted machine learning model by at least encrypting the portion of the model using a cipher of a homomorphic encryption scheme; and

provide the partially encrypted machine learning model to a device that lacks an ability to decrypt the encrypted portion of the partially encrypted machine learning model.

5. The system of claim 4 , wherein the partially encrypted machine learning model comprises a set of instructions executable by the device to cause the device to encrypt output of a first portion of the partially encrypted machine learning model to allow the encrypted output to be used as input into another portion of the machine learning model.

6. The system of claim 4 , wherein the instructions further comprise instructions executable to cause the system to:

receive a request to decrypt output of the partially encrypted machine learning model;

decrypt the output to obtain plaintext output; and

provide the plaintext output in response to the request.

7. The system of claim 4 , wherein the instructions further comprise instructions executable to cause the system to add noise to plaintext output of the neural network to obfuscate the plaintext output.

8. The system of claim 4 , wherein the data indicating the first portion of the machine learning model to encrypt is obtained via a user interface that allows a user to select one or more portions of the machine learning model to encrypt.

9. The system of claim 4 , wherein the instructions further comprise instructions executable to obtain encrypted updated portions of the machine learning model from multiple devices that include the device and combine the multiple updated portions.

10. The system of claim 4 , wherein the machine learning model is a neural network and wherein the encrypted portion of the model comprises one or more hidden layers of the neural network.

11. The system of claim 4 , wherein the system has access to a private key of a public/private key pair and the instructions that cause the system to provide the partially encrypted machine learning model additionally cause the system to provide a public key of the public/private key pair.

12. A non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to:

obtain ciphertext input data based on plaintext input data, the ciphertext input data being output a cipher of a homomorphic encryption scheme;

obtain ciphertext output data by at least applying a first portion of a machine learning model to the ciphertext input data, the machine learning model comprising the first portion with a first set of layers of a neural network, and a second portion with a second set of layers of the neural network, the first portion being encrypted according to the homomorphic encryption scheme and the second portion being in plaintext form; and

obtain plaintext output data by causing the ciphertext output data to be decrypted.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the instructions that cause the computer system to obtain the plaintext output data are executable by the one or more processors to cause the computer system to transmit a request to a service to cause the service to use cryptographic material to decrypt the ciphertext output data to obtain the plaintext output data and provide the plaintext output data in response to the request.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions that cause the computer system to obtain the plaintext output data are executable by the one or more processors to cause the computer system to cause a secure execution environment of the computer system to decrypt the ciphertext output data.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the plaintext output comprises inferencing output of the machine learning model.

16. The non-transitory computer-readable storage medium of claim 12 , wherein the homomorphic encryption scheme is a fully homomorphic encryption scheme.

17. The non-transitory computer-readable storage medium of claim 12 , wherein causing the ciphertext output data to be decrypted further comprises causing noise to be added to the plaintext output.

18. The non-transitory computer-readable storage medium of claim 12 , wherein the instructions further comprise instructions executable by the one or more processors to cause the computer system to further train the machine learning model based on the plaintext output.

19. The non-transitory computer-readable storage medium of claim 12 , wherein the machine learning model is comprised of a neural network with individually encrypted components, the components comprising neural network weights.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: XIONG, YUANJUN; ZHANG, JIA BI; SHUAI, BING; ESCALONA GARCIA, JUAN PABLO
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 057663/0146 →
Cited By (10)
US 12,316,741 US 12,362,905 US 12,362,906 US 12,381,710 US 12,549,359 US 12,591,785 US 12,634,116 US 12,647,248 US 12,665,886 US 12,732,340