arXiv:2509.06371cs.LG2025-09

研究手机端AI安全风险,揭示模型可被提取篡改

Breaking SafetyCore: Exploring the Risks of On-Device AI Deployment

  • 通过SafetyCore案例分析手机端AI漏洞
  • 实证攻击可绕过图像内容检测机制
  • 警示开发者注意设备端AI防护缺陷

随着软硬件进步,越来越多AI模型被部署在设备端,提升了隐私保护和降低了延迟,但也引入了与传统软件不同的安全风险。本文通过SafetyCore这一Android系统服务的真实案例,研究其内置敏感图像内容检测功能的安全部署。我们证明了攻击者可成功提取并操纵该设备端AI模型,从而绕过检测机制,使防护失效。分析揭示了设备端AI模型存在的安全隐患,并提供了实际攻击演示,为后续安全设计提供重要参考。

原文摘要 · Abstract (English)

Due to hardware and software improvements, an increasing number of AI models are deployed on-device. This shift enhances privacy and reduces latency, but also introduces security risks distinct from traditional software. In this article, we examine these risks through the real-world case study of SafetyCore, an Android system service incorporating sensitive image content detection. We demonstrate how the on-device AI model can be extracted and manipulated to bypass detection, effectively rendering the protection ineffective. Our analysis exposes vulnerabilities of on-device AI models and provides a practical demonstration of how adversaries can exploit them.

设备端AI安全漏洞模型提取

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。