Local Is Not a Sufficient Privacy Boundary: Governing OS-Integrated On-Device AI
As AI systems move into operating systems, privacy no longer turns only on whether a model runs locally. A local assistant may assemble email, calendar entries, files, screenshots, notifications, and app intents; retain embeddings or summaries; invoke tools; emit telemetry; or route difficult requests to cloud infrastructure. Local inference reduces some exposure, but it answers only one question: where computation occurs. It does not answer who may assemble context, what derived state persists, which actions are authorized, or how updates change the system's authority. We develop an OS-centered privacy framework for on-device AI that treats privacy as an institutional accountability problem rather than a deployment attribute. The framework specifies a threat model, a six-part privacy risk taxonomy, privacy-by-architecture controls, and a four-level audit rubric. We demonstrate the rubric through a documentation-bounded comparison of Apple Intelligence/Foundation Models, Android AICore/Gemini Nano, and Microsoft Recall. Meaningful privacy in on-device AI depends on constrained information flow, bounded authority, visible user control, and auditable governance across the operating-system lifecycle.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Active Membership Inference Attack under Local Differential Privacy in Federated Learning
Federated learning (FL) was originally regarded as a framework for collaborative learning among clients with data privacy protection through a coordinating server. In this paper, we propose a new active membership infere…
Federated LearningInference AttackMembership Inference AttackPrivacy PreservingAn Enhanced Privacy-preserving Federated Few-shot Learning Framework for Respiratory Disease Diagnosis
The labor-intensive nature of medical data annotation presents a significant challenge for respiratory disease diagnosis, resulting in a scarcity of high-quality labeled datasets in resource-constrained settings. Moreove…
DiagnosticFew-Shot LearningPrivacy PreservingJoint discovery of governing partial differential equations from multi-source datasets by competitive optimization
Discovering governing equations directly from observational data is a key step towards interpretable scientific machine learning. Current data-driven approaches typically operate on a single dataset, inherently limiting …
LSA-PINN: Linear Boundary Connectivity Loss for Solving PDEs on Complex Geometry
We present a novel loss formulation for efficient learning of complex dynamics from governing physics, typically described by partial differential equations (PDEs), using physics-informed neural networks (PINNs). In our …
Differential equations of electrodiffusion: constant field solutions, uniqueness, and new formulas of Goldman-Hodgkin-Katz type
The equations governing one-dimensional, steady-state electrodiffusion are considered when there are arbitrarily many mobile ionic species present, in any number of valence classes, possibly also with a uniform distribut…