Protecting On-Device AI Inference: A Systematic Review of Attacks and Defence Mechanisms

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Tsiatsikas, Zisis, Fakis, Alexandros, Karopoulos, Georgios, Kouliaridis, Vasileios, Anagnostopoulos, Marios
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910269085581312
author Tsiatsikas, Zisis
Fakis, Alexandros
Karopoulos, Georgios
Kouliaridis, Vasileios
Anagnostopoulos, Marios
author_facet Tsiatsikas, Zisis
Fakis, Alexandros
Karopoulos, Georgios
Kouliaridis, Vasileios
Anagnostopoulos, Marios
contents The need for secure and private Artificial Intelligence (AI) and Machine Learning (ML) on edge and mobile devices has increased the necessity of protecting the architecture of these systems from threats to both security and privacy. With an ever-increasing number of pre-trained AI models being used on mobile platforms for client-side inference, there are rising concerns about the risks associated with the theft/extraction of AI models, adversarial attacks on AI models, and data breaches. As a result of this trend, a variety of defence mechanisms have been proposed to protect against these threats. These include Trusted Execution Environments (TEEs), homomorphic encryption, obfuscation, and differential privacy, among others. However, current surveys largely focus on edge intelligence, which includes distributed training, and thus overlook security and privacy issues that are specific to on-device AI inference. To the best of our knowledge, this paper presents the first comprehensive review of threats and corresponding defence mechanisms targeting on-device inference. Our results show that the attack and defence literature are unbalanced: approximately one quarter of the surveyed attack papers focus on Intellectual Property (IP) attacks, whereas half of the defence solutions tackle the same issue. More importantly, some attack categories have no defence paper associated to them, such as adversarial attacks that account for roughly one third of the attack literature. This asymmetry between known attacks and available mitigations highlights clear opportunities for future research on securing on-device AI inference.
format Preprint
id arxiv_https___arxiv_org_abs_2605_29450
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Protecting On-Device AI Inference: A Systematic Review of Attacks and Defence Mechanisms
Tsiatsikas, Zisis
Fakis, Alexandros
Karopoulos, Georgios
Kouliaridis, Vasileios
Anagnostopoulos, Marios
Cryptography and Security
The need for secure and private Artificial Intelligence (AI) and Machine Learning (ML) on edge and mobile devices has increased the necessity of protecting the architecture of these systems from threats to both security and privacy. With an ever-increasing number of pre-trained AI models being used on mobile platforms for client-side inference, there are rising concerns about the risks associated with the theft/extraction of AI models, adversarial attacks on AI models, and data breaches. As a result of this trend, a variety of defence mechanisms have been proposed to protect against these threats. These include Trusted Execution Environments (TEEs), homomorphic encryption, obfuscation, and differential privacy, among others. However, current surveys largely focus on edge intelligence, which includes distributed training, and thus overlook security and privacy issues that are specific to on-device AI inference. To the best of our knowledge, this paper presents the first comprehensive review of threats and corresponding defence mechanisms targeting on-device inference. Our results show that the attack and defence literature are unbalanced: approximately one quarter of the surveyed attack papers focus on Intellectual Property (IP) attacks, whereas half of the defence solutions tackle the same issue. More importantly, some attack categories have no defence paper associated to them, such as adversarial attacks that account for roughly one third of the attack literature. This asymmetry between known attacks and available mitigations highlights clear opportunities for future research on securing on-device AI inference.
title Protecting On-Device AI Inference: A Systematic Review of Attacks and Defence Mechanisms
topic Cryptography and Security
url https://arxiv.org/abs/2605.29450