Back to updates
UpdatedJul 21, 2026

Awesome-MoAI-Security — Updated!

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and energy-latency attacks alongside obfuscation, TEE, and watermarking defenses.

Share

Awesome Mobile On-Device AI Security

SoK: Attack and Defense Landscape of Mobile On-device AI Systems

Mobile on-device AI systems execute AI models locally through ML frameworks such as LiteRT/TFLite, Core ML, ExecuTorch, ONNX, and hardware-backed accelerators. This repo tracks the security research needed to understand and protect such systems, as the local storage of on-device models introduces new security risks.

Overview of a Mobile On-Device AI system

Overview of a Mobile On-Device AI system

Contents

Reading roadmap

New to MoAI security? Start here:

  1. Understand the ecosystem. Read empirical studies on deep learning apps and on-device models in Android/iOS apps.
  2. Learn the core risk. Study model extraction and model protection papers, because local model residency is the central security shift in MoAI systems.
  3. Understand the attack surfaces. Study how MoAI attacks arise across input interfaces, model artifacts, runtime execution, and hardware-backed environments.
  4. Connect defenses to the surfaces. Examine how MoAI defenses protect these surfaces across pre-deployment, runtime execution, and post-deployment phases.
  5. Look forward. Explore new security challenges in on-device training, on-device GenAI, and agentic MoAI systems.
A minimal first-week reading path for newcomers to MOAI security.


•  A First Look at Deep Learning Apps on Smartphones
•  A First Look at On-device Models in iOS Apps


•  Mind Your Weight(s): A Large-scale Study on Insufficient ML Model Protection in Mobile Apps


•  Robustness of On-device Models: Adversarial Attack to Deep Learning Models on Android Apps
•  DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload Injection
•  Typhon Unleashed: Practical Adversarial Weight Attacks Against On-Device Deep Learning Models
•  Energy-Latency Attacks to On-Device Neural Networks via Sponge Poisoning


•  ModelObfuscator: Obfuscating Model Information to Protect Deployed ML-based Systems
•  ShadowNet: A Secure and Efficient On-device Model Inference System
•  THEMIS: Towards Practical IP Protection for Post-Deployment On-Device DL Models

Taxonomy at a glance

MoAI security pillarWhat it protectsRepresentative attacksRepresentative defenses
User-governed input integrityThe end-to-end integrity of user inputs, from mobile data acquisition to model-input handoffAdversarial Attacks, Backdoor Attacks, Energy-latency Attacks-
Device-resident model securityDeployed model artifacts and all post-deployment forms in which models are stored, loaded, transformed, or materialized on devicesAdversarial Attacks, Backdoor Attacks, Adversarial Weight Attacks, Model Stealing Attacks, Energy-latency AttacksModel Obfuscation, Model Authorization, TEE, Model Watermarking
Device-native environment confinementSensitive inference computation and runtime states across the mobile OS, AI runtime, memory subsystem, and hardware-backed execution environmentsModel Stealing Attacks, Energy-latency AttacksModel Obfuscation, TEE

Cross-pillar Security Analysis

Cross-pillar security analysis of attacks and open problems in MoAI systems. Cross-pillar security analysis of defenses and open problems in MoAI systems.

Attacks on MoAI systems

Model Similarity Exploitation

Categories