{"id":"0c9e0624-b67b-41f2-8010-0b4f291c75cd","arxiv_id":"2607.00362","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":7.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"This SoK paper introduces the first systematic framework covering security pillars, attack landscape, and defense landscape for mobile on-device AI systems while identifying research gaps.","lead":"This paper provides the first systematization of knowledge on security attacks and defenses for mobile on-device AI systems that run models locally on phones. A smart generalist might read it to understand new privacy and security risks created when AI moves from the cloud to end-user devices.","discovery_kind":"review","skeptic_critique":{"model":"grok-4.3","headline":"Completeness of the literature survey remains the load-bearing assumption for the 'first comprehensive SoK' claim","rationale":"The reader's weakest_assumption is precisely the single point on which the 'first comprehensive' and 'first systematic framework' claims rest; no other technical or formal element (no proofs, no experiments) exists to shift the risk elsewhere. Full-text access does not remove this survey-validity risk, so the UNVERDICTED verdict is unaffected.","tokens_in":1685,"tokens_out":309,"duration_ms":17977,"concrete_test":"Locate the methodology or survey-scope subsection; extract the exact search strings, repositories, and date range used. Independently re-run the same query on Google Scholar and arXiv for 2020–2024; count how many of the top 30 results are cited and placed in the taxonomy. If >15 % of high-relevance papers are missing or mis-categorized, the completeness assumption fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The strongest claim requires that the surveyed body of work is representative enough to support a novel, systematic categorization into security pillars plus attack/defense landscapes without major omissions. This holds only if the authors' search process (databases, keywords, time bounds, inclusion rules) captured essentially all relevant MoAI papers; any systematic gap (e.g., under-coverage of hardware-side or federated-learning-adjacent attacks) would make the resulting framework incomplete rather than comprehensive.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper claims to present the first comprehensive systematization of knowledge (SoK) on Mobile on-device AI (MoAI) security. It covers security pillars, the attack landscape, and the defense landscape of MoAI systems, identifies unresolved gaps in current attack and defense research, and establishes the first systematic framework for understanding these landscapes. Companion resources are available via a GitHub repository.","tokens_in":1757,"tokens_out":287,"duration_ms":22874,"significance":"If the survey methodology is sound and the literature coverage complete, this would be a significant contribution as the first SoK in an emerging area. It would provide a useful framework and gap analysis to guide future work on secure MoAI systems. The public GitHub repository is a clear strength that supports community use and reproducibility of the surveyed resources.","major_comments":[{"comment":"Abstract: The central claim of presenting the 'first comprehensive' SoK depends on the surveyed body of work being representative. The abstract provides no explicit methodology for paper selection, search strategy, databases, keywords, time bounds, or inclusion/exclusion criteria. This detail is load-bearing for the comprehensiveness assertion; without it, the resulting categorization into pillars/attacks/defenses cannot be verified as complete rather than partial.","section":"Abstract"}],"minor_comments":[],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive feedback on our SoK manuscript. We address the single major comment below and agree that a revision is warranted.","responses":[{"response":"We agree that the abstract does not currently include explicit details on the survey methodology, which is necessary to support the claim of comprehensiveness. The full manuscript contains a dedicated systematization methodology section that specifies the search strategy (systematic queries across Google Scholar, IEEE Xplore, ACM Digital Library, and arXiv), keywords (combinations of 'mobile on-device AI', 'on-device inference security', 'model extraction', 'adversarial attack', etc.), time bounds (primarily 2017–2024 with key earlier foundational works), and inclusion/exclusion criteria (peer-reviewed papers and preprints focused on attacks or defenses for locally deployed mobile AI models, excluding purely cloud-based or non-AI mobile security work). To address the referee's point, we will revise the abstract to concisely summarize this methodology so that the central claim can be properly evaluated.","revision_made":"yes","referee_comment":"[Abstract] Abstract: The central claim of presenting the 'first comprehensive' SoK depends on the surveyed body of work being representative. The abstract provides no explicit methodology for paper selection, search strategy, databases, keywords, time bounds, or inclusion/exclusion criteria. This detail is load-bearing for the comprehensiveness assertion; without it, the resulting categorization into pillars/attacks/defenses cannot be verified as complete rather than partial."}],"tokens_in":1232,"tokens_out":332,"duration_ms":25768,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main takeaway is that this paper pulls together attacks and defenses for on-device mobile AI into one place with a new structure around security pillars, attack types, and defenses, plus a GitHub repo of resources. That structure and the gap analysis are the actual new pieces; prior work covered individual attacks but not this combined view.\n\nIt does a reasonable job describing how standard threats like model extraction or adversarial examples change when the model runs locally on a phone instead of in the cloud. The repo link is a concrete plus that lets others build on the list without starting from scratch.\n\nThe soft spot is the load-bearing assumption that the surveyed papers are representative enough to support the framework without big omissions. The abstract gives no search method, databases, keywords, or inclusion rules, so any gaps in hardware-side attacks, federated setups, or specific mobile runtimes would make the categorization incomplete rather than comprehensive. That is not a minor detail when the title claims the first full systematization.\n\nNo math or empirical claims are at issue here, and the citations follow normal survey patterns. The work is aimed at people already in mobile security or starting research in on-device AI who need a map of the space. It is worth sending to peer review because a solid version of this could cut down on repeated effort in a fast-moving area, provided the authors add transparent methodology and justify the coverage in revision.","headline":"This SoK gives a usable organizing framework for mobile on-device AI security but its 'first comprehensive' claim rests on survey coverage that the abstract leaves unshown.","tokens_in":2247,"tokens_out":359,"would_cite":true,"duration_ms":19148,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"This SoK creates the first systematic framework for attacks and defenses in mobile on-device AI systems.","keywords":["mobile on-device AI","security","attacks","defenses","SoK","systematization of knowledge","on-device inference"],"falsifier":"A substantial body of MoAI security research that cannot be placed into the proposed categories or a clear major omission that the survey missed.","tokens_in":2574,"feed_emoji":"🔒","tokens_out":381,"duration_ms":19539,"temperature":0.7,"pith_summary":"Mobile on-device AI runs models locally on phones and tablets instead of sending data to the cloud, which brings privacy and speed benefits but also new risks from storing models on the device. The paper surveys existing research to organize these risks into security pillars, an attack landscape, and a defense landscape. It identifies gaps where current work falls short and points to future directions. A reader would care because the framework gives developers and researchers a shared map for securing these systems rather than treating threats case by case.","feed_headline":"First survey maps attacks and defenses for mobile on-device AI","feed_subtitle":"It organizes security pillars, local-model risks, and protections into one framework that future work can build on.","key_machinery":"The systematic framework that categorizes MoAI security into pillars, attack landscape, and defense landscape.","core_discovery":"The paper presents the first comprehensive systematization of knowledge on MoAI security by covering the security pillars, attack landscape, and defense landscape of MoAI systems while establishing the first systematic framework for understanding these landscapes and identifying unresolved research gaps.","pith_inferences":[],"forward_implications":[],"fun_headline_variants":["SoK maps attacks and defenses in mobile on-device AI","Attack and defense SoK for mobile on-device AI","Survey covers security landscape of mobile on-device AI","Mobile on-device AI attacks and defenses systematized"],"cache_read_input_tokens":64,"weakest_assumption_plain":"The published work surveyed is complete and representative enough to support a full categorization into pillars, attacks, and defenses without major omissions.","fun_headline_variants_meta":{"raw":{"variants":["SoK maps attacks and defenses in mobile on-device AI","Attack and defense SoK for mobile on-device AI","Survey covers security landscape of mobile on-device AI","Mobile on-device AI attacks and defenses systematized"]},"model":"grok-4.3","cost_usd":0.007198,"raw_usage":{"total_tokens":3198,"prompt_tokens":584,"num_sources_used":0,"completion_tokens":60,"cost_in_usd_ticks":71978000,"prompt_tokens_details":{"text_tokens":584,"audio_tokens":0,"image_tokens":0,"cached_tokens":64},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":2554,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":584,"tokens_out":60,"duration_ms":26686,"temperature":1.0,"reasoning_tokens":2554,"cache_read_input_tokens":64,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-02T11:43:07.919107+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"A substantial body of MoAI security research that cannot be placed into the proposed categories or a clear major omission that the survey missed.","supporting_citations":[],"review_version":1}