[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119293-en":3,"doc-seo-119293-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119293,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",6,"Technology","Locking Machine Learning Models into Hardware - Feasibility of Hardware-Based Access Restriction - Abstract","Modern machine learning models represent valuable IP and business advantage, yet deploying them on-device risks inevitable leakage through reverse engineering or unauthorized execution. Confidential computing approaches like multi-party computation and homomorphic encryption remain difficult to adopt widely. The paper proposes ML-specific locking mechanisms that restrict model usability to authorized hardware, making unauthorized deployment inconvenient or impossible even if the model is compromised. Experiments show locking can be achieved by enforcing hardware-dependent representations or binding computation to hardware characteristics with negligible overhead.","Locking Machine Learning Models into Hardware  \narXiv :2405 .20990v2 [ cs .CR] 8 Mar 2025  \nEleanor Clifford*  \nImperial College London [eleanor.clifford@cl.cam.ac.uk](eleanor.clifford@cl.cam.ac.uk)  \nAdhithya Saravanan*  \nUniversity of Cambridge [aps85@cam.ac.uk](aps85@cam.ac.uk)  \nYiren Zhao Imperial College London [a.zhao@imperial.ac.uk](a.zhao@imperial.ac.uk)  \nRobert Mullins  \nUniversity of Cambridge [robert.mullins@cl.cam.ac.uk](robert.mullins@cl.cam.ac.uk)  \nAbstract—Modern machine learning (ML) models are expensive IP and business competitiveness often depends on keeping this IP confidential. This in turn restricts how these models are deployed; for example, it is unclear how to deploy a model on-device without inevitably leaking the underlying model. At the sametime, confidential computing technologies such as multi-party computation or homomorphic encryption remain impractical for wide adoption. In this paper, we take a different approach and investigate the feasibility of ML-specific mechanisms that deter unauthorized model use by restricting the model to only be usable on specific hardware, making adoption on unauthorized hardware inconvenient. That way, even if IP is compromised, it cannot be trivially used without specialised hardware or major model adjustment. In a sense, we seek to enable cheap locking of machine learning models into specific hardware. We demonstrate that locking mechanisms are feasible by either targeting efficiency of model representations, making such models incompatible with quantization, or tying the model’s operation to specific characteristics of hardware, such as the number of clock cycles for arithmetic operations. We demonstrate that locking comes with negligible overheads, while significantly restricting usability of the resultant model on unauthorized hardware.  \nIndex Terms—machine learning, security, governance, hardware  \nI. INTRODUCTION  \nThe monetary expenditures associated with developing machine learning (ML) models are increasing rapidly with the advent of large generative models. Models with over a trillion parameters are now being trained on web-scale data [1] . These models have become valuable Intellectual Property (IP) assets, yet ensuring their competitive edge remainsuncompromised when deployed on-device proves challenging. Competitors may reverse engineer the model’s architecture and parameters, redeploying it on their software and hardware stack. Concurrently, governance of Machine Learning models is a concern [2] . Especially in safety-critical applications, it maybe necessary to limit model execution to special authenticated settings. Here, we usually rely on hardware and software combinations to prevent model use on unverified platforms, which may lead to the potential misuse of the model.  \nExisting ML governance and IP protection methods can be classified into two categories: namely policies and centralised serving. Policy-based methods focus on either access control or licensing. For example, accessing LLaMA models requires  \n*Equal contribution  \nHarry Langford*  \nUniversity of Cambridge [hjel2@cam.ac.uk](hjel2@cam.ac.uk)  \nCheng Zhang  \nImperial College London [cheng.zhang122@imperial.ac.uk](cheng.zhang122@imperial.ac.uk)  \nIlia Shumailov  \nGoogle Deepmind [iliashumailov@google.com](iliashumailov@google.com)  \nJamie Hayes  \nGoogle Deepmind [jamhay@google.com](jamhay@google.com)  \nSpecialised model cannot run or is inefficient on unauthorised hardware  convert model into representations unique to hardware  \n use hardware fingerprint to condition model  \nAuthorised hardware Unauthorised hardware  \nFig. 1. A high-level illustration of how ML Hardware Locking functions: the locked model resists efficient, or any, deployment by adversaries on unauthorized hardware stacks. This resistance occurs because unauthorized hardware devices inherently lack support for some hardware operation or are unable to match the hardware properties of the authorized hardware.  \nuser","cbCaiu7DOQECTOjU","https://ap.wps.com/l/cbCaiu7DOQECTOjU","pdf",1276658,1,19,"English","en",105,"# Introduction\n## Motivation: IP leakage and governance challenges\n## Existing approaches and their limitations\n# Proposed approach: ML hardware locking\n## Core idea and threat model\n# Locking mechanisms\n## Representation incompatibility with quantization\n## Hardware-aware computation tying","[{\"question\":\"为什么在终端设备部署机器学习模型会面临IP泄露风险？\",\"answer\":\"模型在终端部署时可能被对手反向工程其架构与参数，从而在自己的软件与硬件栈上重新部署，导致IP竞争优势受损。\"},{\"question\":\"为什么传统的保密计算技术难以广泛应用？\",\"answer\":\"文中指出，多方计算或同态加密等保密计算技术仍不够实用，限制了其大规模采用。\"},{\"question\":\"论文提出的“硬件锁定”机制如何提高未授权使用的难度？\",\"answer\":\"通过将模型限制为只能在特定硬件上可用，使得即使模型被盗或被逆向，未授权硬件上的部署会变得不可能或极其困难；可通过硬件相关表示或将计算绑定到硬件特性实现。\"}]","Locking Machine Learning Models into Hardware - Feasibility of Hardware-Based Access Restriction - Abstract | PDF",1785723561,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"locking-machine-learning-models-into-hardware-feasibility-of-hardware-based-access-restriction-abstract","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/locking-machine-learning-models-into-hardware-feasibility-of-hardware-based-access-restriction-abstract/119293/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"为什么在终端设备部署机器学习模型会面临IP泄露风险？","Question",{"text":75,"@type":76},"模型在终端部署时可能被对手反向工程其架构与参数，从而在自己的软件与硬件栈上重新部署，导致IP竞争优势受损。","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"为什么传统的保密计算技术难以广泛应用？",{"text":80,"@type":76},"文中指出，多方计算或同态加密等保密计算技术仍不够实用，限制了其大规模采用。",{"name":82,"@type":73,"acceptedAnswer":83},"论文提出的“硬件锁定”机制如何提高未授权使用的难度？",{"text":84,"@type":76},"通过将模型限制为只能在特定硬件上可用，使得即使模型被盗或被逆向，未授权硬件上的部署会变得不可能或极其困难；可通过硬件相关表示或将计算绑定到硬件特性实现。","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]