设备端AI隐私不能只看是否本地运行,还需管控信息流动与权限。
Local Is Not a Sufficient Privacy Boundary: Governing OS-Integrated On-Device AI
- 从系统层面构建隐私框架,关注信息汇聚与权限控制
- 提出六类隐私风险与四层审计标准,可评估三类设备AI系统
- 适合关注设备安全、系统设计的开发者与政策制定者
随着AI系统集成进操作系统,隐私不再仅取决于模型是否本地运行。本地助手可能聚合邮件、日历、文件、截图、通知及应用意图;保留嵌入向量或摘要;调用工具;发送遥测数据;或将复杂请求路由至云端。本地推理虽减少部分暴露,但仅解决计算位置问题,未回答谁可汇聚上下文、哪些衍生状态留存、哪些操作被授权,以及更新如何改变系统权限。本文提出以操作系统为中心的隐私框架,将隐私视为制度问责问题而非部署属性。该框架包含威胁模型、六类隐私风险分类、隐私优先架构控制及四级审计标准。通过文档限定对比苹果智能/基础模型、安卓AICore/Gemini Nano和微软Recall,验证了该标准的有效性。设备端AI的真正隐私依赖于受限的信息流、有限的权限、可见的用户控制,以及贯穿操作系统生命周期的可审计治理。
原文摘要 · Abstract (English)
As AI systems move into operating systems, privacy no longer turns only on whether a model runs locally. A local assistant may assemble email, calendar entries, files, screenshots, notifications, and app intents; retain embeddings or summaries; invoke tools; emit telemetry; or route difficult requests to cloud infrastructure. Local inference reduces some exposure, but it answers only one question: where computation occurs. It does not answer who may assemble context, what derived state persists, which actions are authorized, or how updates change the system's authority. We develop an OS-centered privacy framework for on-device AI that treats privacy as an institutional accountability problem rather than a deployment attribute. The framework specifies a threat model, a six-part privacy risk taxonomy, privacy-by-architecture controls, and a four-level audit rubric. We demonstrate the rubric through a documentation-bounded comparison of Apple Intelligence/Foundation Models, Android AICore/Gemini Nano, and Microsoft Recall. Meaningful privacy in on-device AI depends on constrained information flow, bounded authority, visible user control, and auditable governance across the operating-system lifecycle.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。