Protecting On-Device AI Inference: A Systematic Review of Attacks and Defence Mechanisms

📅 2026-05-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the critical security and privacy threats confronting on-device AI inference—such as model stealing, adversarial attacks, and data leakage—for which a systematic survey has been notably absent. It presents the first comprehensive review of attack vectors and defense mechanisms tailored to edge and mobile environments, with a specific focus on security challenges unique to client-side inference. Through a structured evaluation of key techniques—including Trusted Execution Environments (TEEs), homomorphic encryption, model obfuscation, and differential privacy—the work reveals a pronounced asymmetry between attack and defense research: approximately one-third of attack studies target adversarial methods yet lack effective countermeasures, while half of defensive efforts prioritize intellectual property protection, highlighting a significant imbalance in the field. This survey fills an important gap and offers clear guidance for future research directions.
📝 Abstract
The need for secure and private Artificial Intelligence (AI) and Machine Learning (ML) on edge and mobile devices has increased the necessity of protecting the architecture of these systems from threats to both security and privacy. With an ever-increasing number of pre-trained AI models being used on mobile platforms for client-side inference, there are rising concerns about the risks associated with the theft/extraction of AI models, adversarial attacks on AI models, and data breaches. As a result of this trend, a variety of defence mechanisms have been proposed to protect against these threats. These include Trusted Execution Environments (TEEs), homomorphic encryption, obfuscation, and differential privacy, among others. However, current surveys largely focus on edge intelligence, which includes distributed training, and thus overlook security and privacy issues that are specific to on-device AI inference. To the best of our knowledge, this paper presents the first comprehensive review of threats and corresponding defence mechanisms targeting on-device inference. Our results show that the attack and defence literature are unbalanced: approximately one quarter of the surveyed attack papers focus on Intellectual Property (IP) attacks, whereas half of the defence solutions tackle the same issue. More importantly, some attack categories have no defence paper associated to them, such as adversarial attacks that account for roughly one third of the attack literature. This asymmetry between known attacks and available mitigations highlights clear opportunities for future research on securing on-device AI inference.
Problem

Research questions and friction points this paper is trying to address.

on-device AI inference
security
privacy
adversarial attacks
model extraction
Innovation

Methods, ideas, or system contributions that make the work stand out.

on-device AI inference
systematic review
security and privacy
attack-defense asymmetry
Trusted Execution Environments
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Zisis Tsiatsikas
Zisis Tsiatsikas
University of the Aegean - Mitel Networks
Computer SecurityNetwork Security
A
Alexandros Fakis
Department of Information and Communication Systems Engineering, University of the Aegean, Samos, 83200, Greece
G
Georgios Karopoulos
European Commission, Joint Research Centre (JRC), Ispra, 21027, Italy
V
Vasileios Kouliaridis
European Food Safety Authority (EFSA), Parma, 43126, Italy
Marios Anagnostopoulos
Marios Anagnostopoulos
Assistant Professor, Democritus University of Thrace
ICT security and privacyDNS SecurityBotnetsDDoS attacks