IP Library › Granted Patent US 12,462,069
Granted Patent B2
US 12,462,069 · App. 18/694,126 · Granted Nov 4, 2025

Method and a system for checking ownership and integrity of an ai model using distributed ledger technology (DLT)

Inventors: Manojkumar Somabhai Parmar (Ahmedabad, IN); Shrey Arvind Dabhi (Gujarat, IN); Sunder Naik Anjali (Bangalore, IN); Mayurbhai Thesia Yash (Gujarat, IN)
Assignees: Robert Bosch GmbH; Robert Bosch Engineering and Business Solutions Private Limited
G06F21/64G06F21/16G06N3/08G06N20/10H04L9/0897H04L9/3239H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,069
App. No.
18/694,126
Granted
Nov 4, 2025
Kind
B2
Abstract

A method is for checking an integrity of an artificial intelligence (AI) model using distributed ledger technology (DLT). The method leverages state-of-the-art watermarking mechanism and ties it up with DLT to generate proof of origin (provenance) in a tamper-proof way. The AI model is registered on the distributed ledger (DL) by uploading a full checksum, a selective checksum, watermark data, and at least a predefined output of the watermark data. A unique model ID is received upon registration. The ownership and integrity of AI model is then determined by matching the model and the output of the watermark data followed by verification of the full checksum and the selective checksum of the AI model.

Claims (31)

1 . A method for determining ownership and integrity of an artificial intelligence (AI) model using distributed ledger technology (DLT), wherein processing nodes of a plurality of processing nodes are linked by a distributed ledger (DL) over a network, and the method is performed by any one processing node of the plurality of processing nodes, the method comprising:

embedding a digital watermark in the AI model, during training of the AI model, using first watermark data and a predefined output of the first watermark data;

generating, by using a hashing technique, a full checksum and a selective checksum for the AI model;

registering the AI model on the DL by uploading the full checksum, the selective checksum, the first watermark data, and at least the predefined output of the first watermark data;

receiving, upon the registering of the AI model, a unique model identification (ID) of the AI model;

receiving the AI model, the unique model ID of the AI model, and at least the first watermark data as an input;

checking for registration of the AI model by matching the received unique model ID of the AI model with a stored model ID on the DL;

processing the first watermark data to get a processed output and matching the processed output with the predefined output of the first watermark data;

verifying the full checksum and the selective checksum of the AI model;

calculating an error for the AI model based on the selective checksum verification; and

determining the integrity of the AI model based on the calculated error.

2 . The method as claimed in claim 1 , wherein matching of the unique model ID of the AI model and the processing of the first watermark data indicates a positive acknowledgment of the ownership of the AI model.

3 . The method as claimed in claim 2 , wherein the positive acknowledgment of the ownership of the AI model and the full checksum verification indicates complete integrity of the AI model.

4 . The method as claimed in claim 1 , wherein the selective checksum is verified only when the full checksum verification fails.

5 . The method as claimed in claim 1 , wherein a rate of error decides a partial or no integrity of the AI model suggestive of tampering of the AI model.

6 . A computer system for determining ownership and integrity of an artificial intelligence (AI) model using distributed ledger technology (DLT), the computer system comprising:

a plurality of processing nodes linked by a distributed ledger (DL) over a network, each processing node of the plurality of processing nodes including a memory and a processor, wherein any one of the processing nodes of the plurality of processing nodes is configured to:

embed a digital watermark in the AI model, during training of the AI model, using first watermark data and a predefined output of the first watermark data;

generate, by using a hashing technique, a full checksum and at least one selective checksum for the AI model;

register the AI model on the DL by uploading the full checksum, the at least one selective checksum, the first watermark data, and at least the predefined output of the first watermark data,

receive a unique model ID of the AI model upon the registration of the AI model;

receive the AI model, the unique model ID of the AI model, and at least the first watermark data as an input;

check for registration of the AI model by matching the received unique model ID of the AI model with a stored model ID on the DL;

process the first watermark data to get a processed output and match the processed output with the predefined output of the first watermark data;

verify the full checksum and the at least one selective checksum of the AI model;

calculate an error for the AI model based on the at least one selective checksum verification; and

determine the integrity of the AI model based on the calculated error.

7 . The computer system as claimed in claim 6 , wherein matching of the unique model ID of the AI model and the processing of the first watermark data indicates positive acknowledgment of the ownership of the AI model.

8 . The computer system as claimed in claim 7 , wherein the positive acknowledgment of the ownership of the AI model and the full checksum verification indicates complete integrity of the AI model.

9 . The computer system as claimed in claim 6 , wherein the at least one selective checksum is verified only when the full checksum verification fails.

10 . The computer system as claimed in claim 6 , wherein a rate of error decides a partial or no integrity of the AI model suggestive of tampering of the AI model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2025
From: PARMAR, MANOJKUMAR SOMABHAI; DABHI, SHREY ARVIND; ANJALI, SUNDER NAIK; YASH, MAYURBHAI THESIA
To: ROBERT BOSCH GMBH; ROBERT BOSCH ENGINEERING AND BUSINESS SOLUTIONS
Reel/Frame 070044/0310 →
Priority Claims (1)
IN 2021 4103 2309 · Jul 19, 2021 · national
Continuity (1)
Related Publication 20240403493A1 · Dec 5, 2024
References Cited (18)
US 20040249480A1 · Lefebvre · 2004 [cited by examiner]
US 20190034763A1 · Guim Bernat · 2019 [cited by examiner]
US 20190370440A1 · Gu et al. · 2019 [cited by applicant]
US 20200320417A1 · Corning · 2020 [cited by examiner]
US 20210109790A1 · Cheng · 2021 [cited by examiner]
US 20210109792A1 · Cheng · 2021 [cited by examiner]
US 20210109793A1 · Cheng · 2021 [cited by examiner]
US 20210110312A1 · Cheng · 2021 [cited by examiner]
US 20210149733A1 · Cheng · 2021 [cited by examiner]
US 20210150002A1 · Cheng · 2021 [cited by examiner]
US 20210150406A1 · Cheng · 2021 [cited by examiner]
US 20210150411A1 · Coenders · 2021 [cited by examiner]
US 20210152600A1 · Cheng · 2021 [cited by examiner]
CN 112650985A · 2021 [cited by examiner]
CN 113497784A · 2021 [cited by examiner]
International Search Report corresponding to PCT Application No. PCT/EP2022/069875, mailed Nov. 4, 2022 (English language document) (4 pages). [cited by applicant]
Li et al., “DLBC: A Deep Learning-Based Consensus in Blockchains for Deep Learning Services”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Apr. 16, 2019 (13 pages). [cited by applicant]
Li et al., “Merkle-Sign: Watermarking Framework for Deep Neural Networks in Federated Learning”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Jul. 16, 2021 (13 pages). [cited by applicant]