[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119987-en":3,"doc-seo-119987-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119987,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","SODA - Protecting Proprietary Information in On-Device Machine Learning Models","Low-end hardware growth has accelerated edge machine learning services that use contextual user data to deliver personalization while reducing latency and reliance on centralized infrastructure. On-device deployment, however, can expose proprietary information of the service provider through adversarial exploitation. This work studies how simple attacks can extract embedded proprietary value and enable profit maximization and content theft. It proposes SODA, an end-to-end deployment and serving framework that detects adversarial usage with 89% accuracy in under 50 queries, with minimal impact on performance, latency, and storage.","SODA: Protecting Proprietary Information in On-Device Machine  \nLearning Models  \nAkanksha Atrey 1 , Ritwik Sinha2 , Saayan Mitra2 , Prashant Shenoy 1  \n1University of Massachusetts Amherst, 2Adobe Research  \n[aatrey@cs.umass.edu](aatrey@cs.umass.edu),{risinha, [smitra}@adobe.com](smitra}@adobe.com), [shenoy@cs.umass.edu](shenoy@cs.umass.edu)  \narXiv :2312 . 15036v1 [ cs .LG] 22 Dec 2023  \nABSTRACT  \nThe growth of low-end hardware has led to a proliferation of machine learning-based services in edge applications. These applications gather contextual information about users and provide some services, such as personalized offers, through a machine learning (ML) model. A growing practice has been to deploy such ML modelson the user’s device to reduce latency, maintain user privacy, and minimize continuous reliance on a centralized source. However, deploying ML models on the user’s edge device can leak proprietary information about the service provider. In this work, we investigate on-device ML models that are used to provide mobile services and demonstrate how simple attacks can leak proprietary information of the service provider. We show that different adversaries can easily exploit such models to maximize their profit and accomplish content theft. Motivated by the need to thwart such attacks, we present an end-to-end framework, SODA, for deploying and serving on edge devices while defending against adversarial usage. Our results demonstrate that SODA can detect adversarial usage with 89% accuracy in less than 50 queries with minimal impact on service performance, latency, and storage.  \nCCS CONCEPTS  \n• Security and privacy → Intrusion/anomaly detection and malware mitigation; • Computing methodologies → Distributed artificial intelligence; Machine learning.  \nKEYWORDS  \non-device, machine learning, proprietary information, privacy  \nACM Reference Format:  \nAkanksha Atrey1 , Ritwik Sinha2 , Saayan Mitra2 , Prashant Shenoy1. 2023. SODA: Protecting Proprietary Information in On-Device Machine Learning Models. In The Eighth ACM/IEEE Symposium on Edge Computing (SEC’23), December 6–9, 2023, Wilmington, DE, USA. ACM, New York, NY, USA, 12 pages. [https://doi.org/10.1145/3583740.3626617](https://doi.org/10.1145/3583740.3626617)  \n1 INTRODUCTION  \nThe ubiquity of machine learning (ML) models in distributed applications such as fitness tracking, entertainment recommendations, virtual personal assistance, and social media services has changed  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission [and/or a fee. Request permissions from permissions@acm.org](and/or a fee. Request permissions from permissions@acm.org).  \nSEC’23, December 6–9, 2023, Wilmington, DE, USA  \n© 2023 Copyright held by the owner/author(s) . Publication rights licensed to ACM. ACM ISBN 979-8-4007-0123-8/23/12. . . $15.00  \n[https://doi.org/10.1145/3583740.3626617](https://doi.org/10.1145/3583740.3626617)  \nthe way humans interact with their devices. This proliferation has led to consumers being more proactive and conscious about their choices, including about what data leaves their edge devices [11] and the need for faster response times [6] . This implies that ML-based predictions and recommendations cannot be conducted in a centralized manner and require them to be served closer to where the consumer is. For instance, consider a personalization model that takes as input the context of the user and recommends entertainment choices. With the advancement of low-end hardware technologies [1–3], this in","cbCaijzFA7lqbt7u","https://ap.wps.com/l/cbCaijzFA7lqbt7u","pdf",1190979,1,12,"English","en",105,"# Abstract\n# Introduction\n## Edge deployment benefits and risks\n## Prior model-stealing work vs. proprietary extraction\n# Proposed work: SODA\n## Threat model and objectives\n## Detection approach and evaluation","[{\"question\":\"Why do services deploy machine learning models on users’ edge devices?\",\"answer\":\"Edge deployment reduces latency, preserves privacy by keeping user data processing on-device, enables offline inference, and lowers cloud compute costs.\"},{\"question\":\"What is the core risk of on-device machine learning models for service providers?\",\"answer\":\"Models can be exploited outside the provider’s natural cloud security perimeter, allowing adversaries to leak proprietary information embedded in the model.\"},{\"question\":\"How does SODA help defend against adversarial usage of on-device models?\",\"answer\":\"SODA provides an end-to-end deployment and serving framework to detect adversarial usage with 89% accuracy in fewer than 50 queries while minimally affecting performance, latency, and storage.\"}]","SODA - Protecting Proprietary Information in On-Device Machine Learning Models | PDF",1785727501,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"soda-protecting-proprietary-information-in-on-device-machine-learning-models","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/soda-protecting-proprietary-information-in-on-device-machine-learning-models/119987/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do services deploy machine learning models on users’ edge devices?","Question",{"text":75,"@type":76},"Edge deployment reduces latency, preserves privacy by keeping user data processing on-device, enables offline inference, and lowers cloud compute costs.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the core risk of on-device machine learning models for service providers?",{"text":80,"@type":76},"Models can be exploited outside the provider’s natural cloud security perimeter, allowing adversaries to leak proprietary information embedded in the model.",{"name":82,"@type":73,"acceptedAnswer":83},"How does SODA help defend against adversarial usage of on-device models?",{"text":84,"@type":76},"SODA provides an end-to-end deployment and serving framework to detect adversarial usage with 89% accuracy in fewer than 50 queries while minimally affecting performance, latency, and storage.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]