IP Library › Granted Patent US 12,634,111
Granted Patent B2
US 12,634,111 · App. 18/097,995 · Granted May 19, 2026

Verifying remote execution of machine learning inference under homomorphic encryption using permutations

Inventors: Eyal Kushnir (Kfar Vradim, IL); Ramy Masalha (Kafr Qari, IL); Omri Soceanu (Haifa, IL); Nir Drucker (Zichron Yaakov, IL)
Assignee: International Business Machines Corporation
H04L9/008G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,111
App. No.
18/097,995
Granted
May 19, 2026
Kind
B2
Abstract

A technique to remotely identify potential compromise of a service provider that performs homomorphic inferencing on a model. For a set of real data samples on which the inferencing is to take place, at least first and second permutations of a set of trigger samples are generated. Every set of samples (both trigger and real samples) are then sent for homomorphic inferencing on the model at least twice, and in a secret permutated way. To improve performance, a permutation is packaged with the real data samples prior to encryption using a general purpose data structure, a tile tensor, that allows users to store multi-dimensional arrays (tensors) of arbitrary shapes and sizes. In response to receiving one or more results from the HE-based model inferencing, a determination is made whether the service provider is compromised. Upon a determination that the service provider is compromised, a given mitigation action is taken.

Claims (38)

1 . A method for verifying proof of work of a service provider that performs homomorphic inferencing on a model, comprising:

generating a set of trigger samples;

packing the set of trigger samples together with each of first and second sets of real data samples, wherein the set of trigger samples are packed with the first set of real data samples in first encrypted data according to a first permutation, and wherein the set of trigger samples are packed with the second set of real data samples in second encrypted data according to a second permutation that differs from the first permutation;

forwarding the first and second encrypted data to the service provider for homomorphic encryption-based inferencing on the model;

receiving from the service provider one or more results;

based on the one or more results, determining whether the service provider is compromised; and

upon a determination that the service provider is compromised, taking a given mitigation action.

2 . The method as described in claim 1 wherein an ordering of the trigger samples in each of the first and second permutations is secret except to a verifier that determines whether the service provider is compromised.

3 . The method described in claim 2 wherein determining whether the service provider is compromised includes the verifier validating that at least one label predicated by the model for a sample in the set of trigger samples matches a label returned in the one or more results.

4 . The method as described in claim 2 wherein the verifier is one of: the data owner, an owner of the model, and a combination of the data owner and the model owner.

5 . The method as described in claim 1 wherein a sample in the set of trigger samples is one of: noise, a seed applied to a random number generator, and a data sample associated with at least one of the first second sets of real data samples and that has a given relationship to a classification boundary.

6 . The method as described in claim 1 wherein the first and second permutations are packed with the first and second set of real data samples as a tile tensor.

7 . An apparatus, comprising:

at least one processor;

computer memory holding computer program instructions executed by the at least one processor to verify proof of work of a service provider that performs homomorphic inferencing on a model, the computer program instructions comprising program code configured to:

generate a set of trigger samples;

pack the set of trigger samples together with each of first and second sets of real data samples, wherein the set of trigger samples are packed with the first set of real data samples in first encrypted data according to a first permutation, and wherein the set of trigger samples are packed with the second set of real data samples in second encrypted data according to a second permutation that differs from the first permutation;

forward the first and second encrypted data to the service provider for homomorphic encryption-based inferencing on the model;

receive from the service provider one or more results;

based on the one or more results, determine whether the service provider is compromised; and

upon a determination that the service provider is compromised, take a given mitigation action.

8 . The apparatus as described in claim 7 wherein an ordering of the trigger samples in each of the first and second permutations is secret except to a verifier that determines whether the service provider is compromised.

9 . The apparatus as described in claim 8 wherein the program code configured to determine whether the service provider is compromised includes program code to validate that at least one label predicated by the model for a sample in the set of trigger samples matches a label returned in the one or more results.

10 . The apparatus as described in claim 8 wherein the processing system is associated with a verifier that is one of: the data owner, an owner of the model, and a combination of the data owner and the model owner.

11 . The apparatus as described in claim 7 wherein a sample in the set of trigger samples is one of: noise, a seed applied to a random number generator, and a data sample associated with at least one of the first second sets of real data samples and that has a given relationship to a classification boundary.

12 . The apparatus as described in claim 7 wherein the first and second permutations are packed with the first and second set of real data samples as a tile tensor.

13 . A computer program product in a non-transitory computer readable medium, the computer program product holding computer program instructions executed by at least one processor in a processing system to verify proof of work of a service provider that performs homomorphic inferencing on a model, the computer program instructions comprising program code configured to:

generate a set of trigger samples;

pack the set of trigger samples together with each of first and second sets of real data samples, wherein the set of trigger samples are packed with the first set of real data samples in first encrypted data according to a first permutation, and wherein the set of trigger samples are packed with the second set of real data samples in second encrypted data according to a second permutation that differs from the first permutation;

forward the first and second encrypted data to the service provider for homomorphic encryption-based inferencing on the model;

receive from the service provider one or more results;

based on the one or more results, determine whether the service provider is compromised; and

upon a determination that the service provider is compromised, take a given mitigation action.

14 . The computer program product as described in claim 13 wherein an ordering of the trigger samples in each of the first and second permutations is secret except to a verifier that determines whether the service provider is compromised.

15 . The computer program product as described in claim 14 wherein the program code configured to determine whether the service provider is compromised includes program code to validate that at least one label predicated by the model for a sample in the set of trigger samples matches a label returned in the one or more results.

16 . The computer program product as described in claim 14 wherein the processing system is associated with a verifier that is one of: the data owner, an owner of the model, and a combination of the data owner and the model owner.

17 . The computer program product as described in claim 13 wherein a sample in the set of trigger samples is one of: noise, a seed applied to a random number generator, and a data sample associated with at least one of the first second sets of real data samples and that has a given relationship to a classification boundary.

18 . The computer program product as described in claim 13 wherein the first and second permutations are packed with the first and second set of real data samples as a tile tensor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2023
From: KUSHNIR, EYAL; MASALHA, RAMY; SOCEANU, OMRI; DRUCKER, NIR
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062399/0586 →
Continuity (1)
Related Publication 20240243898A1 · Jul 18, 2024
References Cited (15)
US 20190370440A1 · Gu · 2019 [cited by examiner]
US 20220114249A1 · Grancharov et al. · 2022 [cited by applicant]
Xu, Guowen, et al. “Secure and verifiable inference in deep neural networks.” Proceedings of the 36th Annual Computer Security Applications Conference. 2020. (Year: 2020). [cited by examiner]
Li, Fangqi, Shilin Wang, and Yun Zhu. “Solving the capsulation attack against backdoor-based deep neural network watermarks by reversing triggers.” arXiv preprint arXiv:2208.14127 (2022). (Year: 2022). [cited by examiner]
Cao et al., “IPGuard: Protecting Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary”, ASIA CCS '21: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Se… [cited by applicant]
Weng et al., “pvCNN: Privacy-Preserving and Verifiable Convolutional Neural Network Testing”, arXiv:2201.09186v3 [cs.CR] May 28, 2023, 16 pages. [cited by applicant]
Xu et al., “Secure and Verifiable Inference in Deep Neural Networks”, ACSAC '20: Proceedings of the 36th Annual Computer Security Applications Conference, Dec. 8, 2020, pp. 784-797. [cited by applicant]
Zhang et al., “Protecting Intellectual Property of Deep Neural Networks with Watermarking”, ASIACCS '18: Proceedings of the 2018 on Asia Conference on Computer and Communications Security, May 29, 2018, pp. 159-172. [cited by applicant]
Chen et al., “SecureNets: Secure Inference of Deep Neural Networks on an Untrusted Cloud,” Proceedings of the 10th Asian Conference on Machine Learning, PMLR 2018. [cited by applicant]
Ghodsi, et al., “SafetyNets: Verifiable Execution of Deep Neural Networks on an Untrusted Cloud,” ResearchGate, Jun. 2017. [cited by applicant]
He, et al., “VerlDeep: Verifying Integrity of Deep Neural Networks through Sensitive-Sample Fingerprinting,” arXiv:1808.03277v2 [cs_CR] Aug. 20, 2018. [cited by applicant]
Yadollahi, et al., “Robust Black-box Watermarking for Deep Neural Network using Inverse Document Frequency,” arXiv:2103.05590v1 [cs.CR] Mar. 9, 2021. [cited by applicant]
Natarajan, et al., “CHEM-MIX: Combining Homomorphic Encryption with Trusted Execution Environments for Two-Party Oblivious Inference in the Cloud,” Cryptology ePrint Archive, 2021. [cited by applicant]
Aharoni, et al., “HE-PEx: Efficient Machine Learning Under Homomorphic Encryption Using Pruning, Permutation and Expansion,” arXiv:2207.03384v1 [cs_CR] Jul. 7, 2022. [cited by applicant]
Aharoni, et al., “HeLayers: A Tile Tensors Framework for Large Neural Networks on Encrypted Data,” arXiv:2011.01805v3 [cs.CR] Jan. 1, 2023. [cited by applicant]