arXiv:2607.00362cs.CRcs.AI2026-07

首次系统梳理移动端AI安全攻防全景,为构建可信本地AI提供基础框架。

SoK: Attack and Defense Landscape of Mobile On-device AI Systems

论文配图:SoK: Attack and Defense Landscape of Mobile On-device AI Systems
图 1 · 摘自论文原文
  • 构建移动端AI安全的系统化知识体系,涵盖攻击与防御两大方向。
  • 揭示本地模型存储带来的新型安全风险,指出当前研究的未解难题。
  • 适合安全研究人员、移动端AI开发者及隐私保护关注者参考。

将本地部署的AI模型与传统移动软件组件结合的移动端AI(MoAI)系统正成为智能功能直接在终端设备上实现的关键范式。通过将推理从远程云服务转移到本地移动环境,此类系统实现了隐私保护、低延迟和离线可用的AI功能,但同时也因本地存储AI模型而引入新的安全风险。本文首次全面系统化地梳理了MoAI安全领域的知识,涵盖安全支柱、攻击态势和防御策略。我们进一步识别出现有攻防研究中的未解决问题,并指明未来研究的潜在方向。本工作建立了首个系统性框架,用于理解MoAI系统的攻防格局,为构建安全的MoAI系统和推动该关键领域研究奠定基础。配套资源见 https://github.com/Jinxhy/Awesome-MoAI-Security。

原文摘要 · Abstract (English)

Mobile on-device AI (MoAI) systems that integrate locally deployed AI models with conventional mobile software components are emerging as a key paradigm for delivering intelligent functionality directly on end-user devices. By moving inference from remote cloud services to the local mobile environment, such systems enable privacy-preserving, low-latency, and offline-capable AI functionality, yet introduce new security risks arising from the local storage of AI models. This paper presents the first comprehensive systematization of knowledge on MoAI security, covering security pillars, attack landscape, and defense landscape of MoAI systems. We further identify unresolved gaps in current attack and defense research and point to promising directions for future research in this emerging area. Our work establishes the first systematic framework for understanding the attack and defense landscapes of MoAI systems, serving as a foundation for building secure MoAI systems and advancing research in this critical domain. Companion resources are available at https://github.com/Jinxhy/Awesome-MoAI-Security.

移动AI安全攻防隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。