[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117922-en":3,"doc-seo-117922-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":11,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},117922,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","On Device Security Agent to Mitigate Inference Attacks on Machine Learning Models","On-device machine learning enables deployment of models on end-user devices, but trained models can leak information about training data and decision logic when exposed to inference attacks. Adversaries can exploit unprotected open-ended models by taking devices offline, then issuing many inference queries to extract data patterns, labels, feature importance, or attribute-level information, sometimes resulting in data loss and compliance risk. The disclosure presents an on-device security agent that monitors inference request patterns and model responses, computes a risk score, enforces mitigation actions, and can share permitted inference artifacts with a cloud security agent for policy generation.","Technical Disclosure Commons  \nDefensive Publications Series  \nJuly 2023  \nOn Device Security Agent to Mitigate Inference Attacks on Machine Learning Models  \nHari Bhaskar S  \nFollow this and additional works at: [https://www.tdcommons.org/dpubs_series](https://www.tdcommons.org/dpubs_series)  \nRecommended Citation  \nS, Hari Bhaskar, \"On Device Security Agent to Mitigate Inference Attacks on Machine Learning Models\", Technical Disclosure Commons,(July 06, 2023)  \n[https://www.tdcommons.org/dpubs_series/6032](https://www.tdcommons.org/dpubs_series/6032)  \nThis work is licensed under a Creative Commons Attribution 4.0 License.  \nThis Article is brought to you for free and open access by Technical Disclosure Commons. It has been accepted for inclusion in Defensive Publications Series by an authorized administrator of Technical Disclosure Commons.  \nOn Device Security Agent to Mitigate Inference Attacks on Machine Learning Models  \nABSTRACT  \nThe advent ofon-device machine learning allows developers to deploy models on end  \nuser devices. A trained machine learning model can be a representation of the dataset used to  \ntrain the model and may carry knowledge of decision making based on training. Malicious actors  \ncan perform inference attacks to exploit open-ended, unprotected on-device machine learning  \nmodels, e.g., by taking the device offline to block information from being sent to the cloud and  \nsending several inference requests to extract the patterns of data and/or training of the machine  \nlearning model. This disclosure describes an on-device security agent that monitors the patterns  \nof inference requests to an on-device machine learning model and the corresponding responses  \nprovided by the model. The inference agent can implement rules or a lightweight machine  \nlearning model to analyze the inference requests to determine a risk score and can take actions to mitigate inference attacks. Further, with user permission, the inference agent can send inference  \ndata including requests received and responses provided by a model to a cloud-based security  \nagent. The cloud-based security agent can analyze such data to generate security policies for the  \non-device security agent.  \nKEYWORDS  \n● Inference attack ● Query pattern  \n● On-device inference ● Label extraction  \n● Offline inference ● Feature importance  \n● Black box adversarial attack ● Attribute inference  \n● ML model security ● Inference velocity  \n● Security agent  \nPublished by Technical Disclosure Commons, 2023 2  \nBACKGROUND  \nThe advent ofon-device machine learning allows developers to deploy models on enduser devices. On-device execution of machine learning models is made possible because of better device capabilities, such as higher amounts of random access memory (RAM), better and larger local storage, dedicated machine learning hardware, and higher processing power.  \nMachine learning (ML) models that power a variety of features on a mobile device maybe accessed both when the device is online (connected to the internet) and offline. In some cases, an on-device ML model may be a lightweight or distilled version of a larger server-side model. A trained machine learning model can be a representation of the dataset that is used to train the model and carries the knowledge of decision making based on the training. There is therefore a possibility that malicious actors can exploit open-ended, unprotected on-device machine learning models.  \nSuch attacks, referred to as inference attacks, may be rendered possible by taking the device offline by turning off the network connectivity to mobile and/or Wi-Fi networks. This blocks information that is sent to the cloud from the on-device model. While such information upload is blocked, the malicious actor may send several inference requests to better understand the patterns of data and training of the machine-learning model. This is possibly a data loss  \nscenario. Furthermore, while a device is offline, the atta","cbCailYbOfZdJrRu","https://ap.wps.com/l/cbCailYbOfZdJrRu","pdf",218109,1,"English","en",105,"# Background\n## On-device machine learning and exposure\n## Inference attacks via offline mode\n## Threats, risks, and lack of protection\n# Description\n## On-device security agent monitoring\n## Risk scoring and mitigation actions\n## Optional cloud-based security policy generation","[{\"question\":\"What are inference attacks against on-device machine learning models?\",\"answer\":\"Inference attacks exploit open-ended, unprotected on-device models by sending inference requests that help adversaries extract patterns related to the dataset and training. The attacks are commonly enabled by taking the device offline to block cloud communication.\"},{\"question\":\"How does the on-device security agent reduce the risk of inference attacks?\",\"answer\":\"The agent continually monitors inference request patterns and the corresponding model responses. It can apply rules or a lightweight model to compute a risk score and trigger mitigation actions to prevent or limit attack progress.\"},{\"question\":\"How can the system use a cloud security agent to improve protections?\",\"answer\":\"With user permission, the inference agent can send inference data, including requests and responses, to a cloud-based security agent. The cloud agent analyzes the data to generate security policies for the on-device agent.\"}]","On Device Security Agent to Mitigate Inference Attacks on Machine Learning Models | PDF",1785680386,20,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"on-device-security-agent-to-mitigate-inference-attacks-on-machine-learning-models","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/on-device-security-agent-to-mitigate-inference-attacks-on-machine-learning-models/117922/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":22,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What are inference attacks against on-device machine learning models?","Question",{"text":74,"@type":75},"Inference attacks exploit open-ended, unprotected on-device models by sending inference requests that help adversaries extract patterns related to the dataset and training. The attacks are commonly enabled by taking the device offline to block cloud communication.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does the on-device security agent reduce the risk of inference attacks?",{"text":79,"@type":75},"The agent continually monitors inference request patterns and the corresponding model responses. It can apply rules or a lightweight model to compute a risk score and trigger mitigation actions to prevent or limit attack progress.",{"name":81,"@type":72,"acceptedAnswer":82},"How can the system use a cloud security agent to improve protections?",{"text":83,"@type":75},"With user permission, the inference agent can send inference data, including requests and responses, to a cloud-based security agent. The cloud agent analyzes the data to generate security policies for the on-device agent.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":28,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":28,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":28,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]