[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124754-en":3,"doc-seo-124754-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124754,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","Container-based Isolation for Managed On-device Machine Learning","Bundling ML models can weaken security and tightly couple model execution with application execution, making resource management and model lifecycle operations increasingly complex. This disclosure presents techniques for on-device machine learning using a function-based paradigm, where ML capabilities are exposed as isolated, containerized functions. On-device apps use IAM/roles to access one or more functions, gaining model security isolation from app security, continued availability during app failures, centralized monitoring and resource management, and a model registry mapping functions to deployed models.","Technical Disclosure Commons  \nDefensive Publications Series  \nDecember 2023  \nContainer-based Isolation for Managed On-device Machine Learning  \nHari Bhaskar S  \nFollow this and additional works at: [https://www.tdcommons.org/dpubs_series](https://www.tdcommons.org/dpubs_series)  \nRecommended Citation  \nS, Hari Bhaskar, \"Container-based Isolation for Managed On-device Machine Learning\", Technical Disclosure Commons,(December 04, 2023)  \n[https://www.tdcommons.org/dpubs_series/6471](https://www.tdcommons.org/dpubs_series/6471)  \nThis work is licensed under a Creative Commons Attribution 4.0 License.  \nThis Article is brought to you for free and open access by Technical Disclosure Commons. It has been accepted for inclusion in Defensive Publications Series by an authorized administrator of Technical Disclosure Commons.  \nContainer-based Isolation for Managed On-device Machine Learning  \nABSTRACT  \nBundling ML models can compromise model security and tightly couples model execution with application execution. Managing computing resources can be difficult if multiple applications access the same model and maintaining multiple ML models through their life cycle can become increasingly complex as the application grows. This disclosure describes techniques that utilize a function-based paradigm for on-device machine learning models. The functions can be implemented using various ML models, implemented in isolated containers. Per the techniques, on-device applications (e.g., mobile apps) can be defined with IAM/roles to access one or more functions that provide ML functionality. The techniques provide enhanced security by isolating model security from app security. Isolation also allows a model to continue to be available (to other applications) in case a particular application goes down. Further, the techniques enable centralized monitoring (e.g., through endpoint management services) to perform resource management. An on-device model registry is provided to maintain a mapping of functions to models deployed on device. Separating the model from the application also allows easier access control, versioning, and deployment.  \nKEYWORDS  \n● On-device machine learning (ML)  \n● Device runtime  \n● Container isolation  \n● Runtime isolation  \n● Model deployment  \n● Model security  \n● Stateless function call  \n● Model separation  \nPublished by Technical Disclosure Commons, 2023 2  \nBACKGROUND  \nOn-device machine learning (ML) models, included as part of the application, are utilized for various purposes such as image recognition and labeling, optical character recognition (OCR) or other text-related tasks, object detection, face detection/ recognition, etc. An on-device model is often a distilled version of a larger model deployed using a machine learning framework that supports lightweight on-device models and relatively more computeheavy models that can be deployed on a server, e.g., on a cloud server.  \nBundling ML models within applications poses several challenges. When a ML model  \nis part of an application, model security is reliant on application security and policies. This  \nimplies that model security can be compromised ifan application that includes the ML model is compromised. Further, the model execution runtime for bundled ML models is tightly coupled  \nto the application runtime. Additionally, managing resources can be difficult if multiple  \napplications access the same model. Maintaining multiple ML models through their life cycle  \ncan become increasingly complex as the application grows.  \nAlso, mobile device runtimes do not distinguish between applications and models.  \nTherefore, memory, storage, and processing resources for the ML model are not isolated thus  \npreventing efficient resource management. Also, any security handshake is tightly coupled  \nsince application access to Identity and Access Management (IAM, user roles, and/or  \npermissions is also used by the model. Still further, model upgrades, versioning, and l","cbCaipoDjg3X3ctZ","https://ap.wps.com/l/cbCaipoDjg3X3ctZ","pdf",254432,1,9,"English","en",105,"# Abstract\n# Background\n## Challenges of bundling ML models\n## Runtime and security coupling\n# Description\n## Function-based paradigm and container isolation\n## IAM roles and model registry\n## Centralized monitoring and lifecycle support","[{\"question\":\"What problem does bundling ML models into applications create?\",\"answer\":\"Bundling relies on application security for model protection, tightly couples model runtime to the app runtime, and makes shared-resource management and multi-model lifecycle maintenance harder as the application grows.\"},{\"question\":\"How do the described techniques improve security for on-device ML?\",\"answer\":\"They isolate model security from app security by deploying model-backed functions inside isolated containers, so models remain protected even if a using application is compromised.\"},{\"question\":\"What additional capabilities does the function-based, isolated-container approach enable?\",\"answer\":\"It supports model availability across applications during individual app failures, enables centralized monitoring for resource management, and uses an on-device model registry to map functions to models deployed on the device.\"}]","Container-based Isolation for Managed On-device Machine Learning | PDF",1785894310,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"container-based-isolation-for-managed-on-device-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/container-based-isolation-for-managed-on-device-machine-learning/124754/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does bundling ML models into applications create?","Question",{"text":75,"@type":76},"Bundling relies on application security for model protection, tightly couples model runtime to the app runtime, and makes shared-resource management and multi-model lifecycle maintenance harder as the application grows.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do the described techniques improve security for on-device ML?",{"text":80,"@type":76},"They isolate model security from app security by deploying model-backed functions inside isolated containers, so models remain protected even if a using application is compromised.",{"name":82,"@type":73,"acceptedAnswer":83},"What additional capabilities does the function-based, isolated-container approach enable?",{"text":84,"@type":76},"It supports model availability across applications during individual app failures, enables centralized monitoring for resource management, and uses an on-device model registry to map functions to models deployed on the device.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]