Matomo

Cryptographic IP protection for AI/ML product | Cossack Labs
Case studies
Cryptographic IP protection for AI/ML product

Cryptographic IP protection for AI/ML product

DEC 2020 - JUNE 2021 Mobile application AI / ML
Cryptographic IP protection for AI/ML product

Overview

Industry

  • AI/ML
  • Media

Technology stack

  • iOS native, Android apps
  • GCP
  • Python, Go backend
  • ML / TensorFlow

Regulations

  • CCPA, GDPR, local privacy regulations
  • Encryption Export Regulations

Challenges

[01]

Protecting unique IP (ML models) against leakage and misuse.

Soon after the launch, this highly sophisticated and powerful machine learning technology enjoyed tremendous viral growth and popularity. The team faced the need to optimise the system design under load, meanwhile, their app became an object of envy for attackers and plagiarism.

[02]

Overnight success turned into a challenge:

how to secure this state-of-the-art tech without affecting the team and app performance, and stay adamant in meeting data security requirements for IP and PII. The team needed help in building specialized security defences to protect their ML models, APIs, and security coverage of the sensitive data life cycle across their apps, services, databases, and data lakes.

[03]

After careful study of companies

that design security systems and work with cryptography, they asked Cossack Labs' engineers for security advisory and engineering.

Technology requirements

Technology requirements

IP protection system

The protection system for TensorFlow ML models should minimize their lifetime and make them difficult to misuse. This includes on-device protection and API anti-fraud system.

Security that doesn't ruin UI/UX

Security measures should be seamlessly integrated across mobile apps, API, and backend infrastructure. End users shouldn't feel the struggle.

Flexible cryptographic layer

Cryptographic layer should work across platforms and be easy to maintain, giving the Customer's team the necessary flexibility for improving their product.

Our approach

Security as business value

Shotgun judgments and immediate decisions only do harm when trying to solve novel sophisticated problems. To ensure that we're focusing on issues of real relevance and priority to the Customer's business model, we started from risk assessment and threat modelling.

Risk analysis

At this stage, the Customer's team got equipped with a risk analysis of their applications and infrastructure specific needs, as well as a security strategy, all allowing them to prioritize security measures.

Moving hand in hand with dev team

Then, together with the app team, we've focused on incorporating security into all steps of SSDLC: designing a well-rounded set of security controls and processes that enable IP protection, PII protection, and application security.
Our approach

Solution

Elegant cryptographic scheme to link ML models with exact users:

Reverse engineering protections on mobile devices:

API protection and anti fraud system:

Defense in depth security measures:

Additional relevant materials

Results and outcomes

The resulting IP protection system is multi-layered and runs through applications and gateways of the Customer's systems. It is designed to stay out of sight and not introduce any unnecessary discomforts for developers and end-users. It combines cryptography, mobile application security, API security and anti-fraud modules.

In contrast with many features, security is a context-dependent non-functional requirement that is not something that could be "finally done". Integrating security into the existing system often leads to re-engineering and optimizing some modules, improving them from both security and UX point of view.

As an additional benefit from our engagement, Customer's engineering team had the experience of building sophisticated security controls that run through mobile, backend and cloud.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days