IP Library › Granted Patent US 12,705,531
Granted Patent B2
US 12,705,531 · App. 17/582,715 · Granted Aug 11, 2026

Electronic device for performing computation based on artificial intelligence model and operation method thereof

Inventors: Hayoon Yi (Suwon-si, KR); Jaewoo Seo (Suwon-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06N20/00G06F21/53G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,705,531
App. No.
17/582,715
Filed
Jan 24, 2022
Granted
Aug 11, 2026
Kind
B2
Art Unit
2148
USPC
706/4
Abstract

According to various embodiments, an electronic device may be provided, the electronic device comprising a memory and at least one processor, wherein the at least one processor is configured to by applying a noise value to weight values of at least a part of a plurality of layers included in an artificial intelligence model stored in the electronic device, obtain the weight values to which the noise value is applied, when an event for executing the artificial intelligence model is identified, obtain, based on computation of data input to the at least a part of the plurality of layers, computation data by using the weight values to which the noise value is applied, and obtain output data, based on the obtained computation data and the applied noise value.

Claims (72)

1 . An electronic device comprising:

a memory storing instructions; and

at least one processor, wherein the at least one processor is configured to perform an operation based on a plurality of execution environments, the plurality of execution environments comprising a rich execution environment and a trusted execution environment, and the instructions which, when executed by the at least one processor, cause the electronic device to:

by applying a noise value to weight values of at least a part of a plurality of layers included in an artificial intelligence model stored in the electronic device in the trusted execution environment, obtain the weight values to which the noise value is applied, and

when an event for executing the artificial intelligence model is identified,

obtain computation data by computing, in the rich execution environment, data input to the at least a part of the plurality of layers, by using the weight values to which the noise value is applied, and

obtain output data, based on the obtained computation data and the applied noise value, in the trusted execution environment,

wherein a first part of the memory is assigned to the rich execution environment and a second part of the memory is assigned to the trusted execution environment,

wherein the artificial intelligence model is stored in the second part of the memory and the second part is not accessible to the at least one processor in the rich execution environment, and

wherein the first part of the memory is accessible to the at least one processor in the rich execution environment and in the trusted execution environment.

2 . The electronic device of claim 1 ,

wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

generate, in the trusted execution environment, the noise value.

3 . The electronic device of claim 1 ,

wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

store, in the trusted execution environment, the weight values to which the noise value is applied, in the first part of the memory; and

obtain, in the rich execution environment, the weight values to which the noise value is applied by accessing the first part of the memory.

4 . The electronic device of claim 3 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

select the noise value from among values within a designated range, and the values within the designated range comprise values smaller than 0.9 or values equal to or larger than 1.1.

5 . The electronic device of claim 1 , further comprising a plurality of computation devices for performing computation based on the artificial intelligence model, wherein the plurality of computation devices are assigned to the rich execution environment among the plurality of execution environments,

wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

compute, in the rich execution environment by using the plurality of computation devices, the data input to the at least a part of the plurality of layers, based on the weight values to which the noise value is applied.

6 . The electronic device of claim 1 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

generate, in the trusted execution environment, first noise values corresponding to input data to be input to the at least a part of the plurality of layers.

7 . The electronic device of claim 6 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

generate each of the first noise values, by randomly selecting a value from a range of values of the input data.

8 . The electronic device of claim 6 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

when the event for executing the artificial intelligence model is identified, by applying the first noise values to the data input to the at least a part of the plurality of layers in the trusted execution environment, obtain the data to which the first noise values are applied, and

change, based on the obtaining of the data to which the first noise values are applied, an execution environment of the electronic device from the trusted execution environment to the rich execution environment.

9 . The electronic device of claim 8 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

compute, in the rich execution environment, based on the weight values to which the noise value is applied, the data to which the first noise values are applied.

10 . The electronic device of claim 6 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

generate, based on the weight values of the at least a part of the plurality of layers of the artificial intelligence model, the first noise values, and a bias, first values in the trusted execution environment, and

pre-store the generated first values in a part of the memory.

11 . The electronic device of claim 10 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

obtain the output data, based on computation of the pre-stored first values and the computation data obtained in the rich execution environment.

12 . The electronic device of claim 1 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

identify a state of the electronic device, and

generate the noise value in the trusted execution environment when the state of the electronic device corresponds to an idle state.

13 . The electronic device of claim 12 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

identify a number of layers for which the noise value is generated, among the plurality of layers of the artificial intelligence model;

select, based on the identified number of layers being smaller than a preset value, a partial layer from among layers for which no noise value is generated; and

generate the noise value associated with the selected partial layer.

14 . The electronic device of claim 13 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

refrain from generating the noise value associated with a first layer among the plurality of layers of the artificial intelligence model.

15 . The electronic device of claim 1 , wherein the instructions which, when executed by the at least one processor, cause the electronic device to:

when the event is identified, identify whether the noise value for the at least a part of the plurality of layers of the artificial intelligence model is stored in the electronic device,

compute, based on the weight values of the at least a part of the plurality of layers, the data input to the part of the plurality of layers, in the trusted execution environment when no noise value is stored in the electronic device, and

compute, based on the weight values of the at least a part of the plurality of layers to which the noise value is applied, the data input to the part of the plurality of layers, in the rich execution environment when the noise value is stored in the electronic device.

16 . An operation method of an electronic device comprising a memory and at least one processor, the at least one processor being configured to perform an operation based on a plurality of execution environments, the plurality of execution environments comprising a rich execution environment and a trusted execution environment, the method comprising:

by applying a noise value to weight values of at least a part of a plurality of layers included in an artificial intelligence model stored in the electronic device, obtaining the weight values to which the noise value is applied in the trusted execution environment; and

when an event for executing the artificial intelligence model is identified,

obtaining computation data by computing, in the rich execution environment, data input to the at least a part of the plurality of layers, by using the weight values to which the noise value is applied; and

obtaining output data, based on the obtained computation data and the applied noise value, in the trusted execution environment,

wherein a first part of the memory is assigned to the rich execution environment, and a second part of the memory is assigned to the trusted execution environment,

wherein the artificial intelligence model is stored in the second part of the memory and the second part is not accessible to the at least one processor in the rich execution environment, and

wherein the first part of the memory is accessible to the at least one processor in the rich execution environment and in the trusted execution environment.

17 . The method of claim 16 , further comprising:

generating, in the trusted execution environment, the noise value.

18 . The method of claim 17 , further comprising:

storing, in the trusted execution environment, the weight values to which the noise value is applied, in the first part of the memory; and

obtaining the weight values to which the noise value is applied by accessing the first part of the memory, in the rich execution environment.

19 . The method of claim 18 , wherein the noise value is configured to be selected from among values within a designated range, and

wherein the values within the designated range comprise values smaller than 0.9 or values equal to or larger than 1.1.

20 . A non-transitory storage medium storing computer-readable instructions which, when executed by at least one processor of an electronic device, cause the electronic device to perform operations, the operations comprising:

by applying a noise value to weight values of at least a part of a plurality of layers included in an artificial intelligence model stored in the electronic device, obtaining the weight values to which the noise value is applied in a trusted execution environment; and

when an event for executing the artificial intelligence model is identified,

obtaining computation data by computing, in a rich execution environment, data input to the at least a part of the plurality of layers, by using the weight values to which the noise value is applied; and

obtaining output data, based on the obtained computation data and the applied noise value, in the trusted execution environment,

wherein a first part of a memory is assigned to the rich execution environment and a second part of the memory is assigned to the trusted execution environment,

wherein the artificial intelligence model is stored in the second part of the memory and the second part is not accessible to the at least one processor in the rich execution environment, and

wherein the first part of the memory is accessible to the at least one processor in the rich execution environment and in the trusted execution environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2022
From: YI, HAYOON; SEO, JAEWOO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 058747/0396 →
Priority Claims (2)
KR 10-2021-0013108 · Jan 29, 2021 · national
KR 10-2021-0054594 · Apr 27, 2021 · national
Continuity (2)
Continuation PCTKR2022000803 · Jan 17, 2022
Related Publication 20220245515A1 · Aug 4, 2022
References Cited (36)
US 10657293B1 · Wei et al. · 2020 [cited by applicant]
US 20130019111A1 · Martin · 2013 [cited by applicant]
US 20130219508A1 · Lee et al. · 2013 [cited by applicant]
US 20160057619A1 · Lopez · 2016 [cited by applicant]
US 20170055175A1 · Leroux et al. · 2017 [cited by applicant]
US 20180129893A1 · Son et al. · 2018 [cited by applicant]
US 20180268306A1 · Laine et al. · 2018 [cited by applicant]
US 20180336479A1 · Guttmann · 2018 [cited by applicant]
US 20190025813A1 · Cella et al. · 2019 [cited by applicant]
US 20190197357A1 · Anderson et al. · 2019 [cited by applicant]
US 20190205517A1 · Moulin et al. · 2019 [cited by applicant]
US 20190251298A1 · Zhu et al. · 2019 [cited by applicant]
US 20200074202A1 · Kim et al. · 2020 [cited by applicant]
US 20200104701A1 · Lee et al. · 2020 [cited by applicant]
US 20200293944A1 · Furukawa et al. · 2020 [cited by applicant]
US 20200328876A1 · Gouget et al. · 2020 [cited by applicant]
US 20200380374A1 · Foret · 2020 [cited by examiner]
US 20210192360A1 · Bitauld · 2021 [cited by examiner]
CN 107683625A · 2018 [cited by applicant]
CN 110674528A · 2020 [cited by applicant]
CN 112182645A · 2020 [cited by applicant]
CN 111814189A · 2020 [cited by applicant]
CN 112132270A · 2020 [cited by applicant]
KR 1020200025200A · 2020 [cited by applicant]
WO 2014018575A2 · 2014 [cited by applicant]
WO 2016140548A1 · 2016 [cited by applicant]
WO 2020122902A1 · 2020 [cited by applicant]
Communication dated Apr. 3, 2024 issued by the European Patent Office in European Application No. 22746132.4. [cited by applicant]
Tramer et al., “Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware”, International Conference on Learning Representations, XP080888704, Jun. 8, 2018, pp. 1-15 (15 pages total). [cited by applicant]
Florian Tramér et al., “Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware”, ICLR 2019, arXiv:1806.03287v2, Feb. 27, 2019, 19 pages. [cited by applicant]
International Search Report (PCT/ISA/210) and Written Opinion (PCT/ISA/237) dated Apr. 27, 2022 issued by the International Searching Authority in International Application No. PCT/KR2022/000803. [cited by applicant]
He, Z., et al., “Parametric Noise Injection: Trainable Randomness to Improve Deep Neural Network Robustness Against Adversarial Attack”, 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 58… [cited by applicant]
Adesuyi, T., et al., “A Neuron Noise-Injection Technique for Privacy Preserving Deep Neural Networks”, Open Computer Science, vol. 10, Issue 1, 2020, pp. 137-152. [cited by applicant]
Communication dated Sep. 24, 2025 issued by the European Patent Office in European Patent Application No. 22746132.4. [cited by applicant]
Communication dated Dec. 23, 2025, issued by the State Intellectual Property Office of PR China in Chinese Application No. 202280008324.2. [cited by applicant]
Communication dated May 20, 2026, issued by the China National Intellectual Property Administration in Chinese Application No. 202280008324.2. [cited by applicant]