On-Device Is Not Private: Measuring Membership Leakage in Lightweight Sensor Anomaly Detectors

Compressed-TinyML pipelines apply distillation, quantization and pruning to fit lightweight anomaly detectors onto resource-constrained sensor nodes. Such frameworks are routinely called privacy-aware on the strength of on-device inference or noisy federated updates rather than any measured guarantee, yet that assumption is rarely tested with a membership-inference attack. Across six multivariate time-series datasets (sensor, facility and finance) and four compact reconstruction-autoencoder architectures (84 experimental cells), a detector accurate enough to deploy (detection AUC 0.878) is vulnerable to a reconstruction-error membership-inference attack (attack AUC 0.688; true-positive rate 0.074 at a 1% false-positive rate). A gradient-noise defense (gradient clipping with additive Gaussian noise) reduces measured leakage to near chance (attack AUC 0.508 as scored, 0.517 oriented away from chance, not exact chance; TPR cut 4.8-fold) at a utility cost of 0.054 in detection AUC (paired Cohen’s d=4.06 for the leakage drop, bootstrap 95% CI [0.145,0.210]), consistently across all datasets (one-sided paired Wilcoxon p=0.0156), while the utility change is nominal (p=0.031, d=1.36). Exported and executed as a real INT8 ONNX artifact, the model shrinks 3.2× but shows no evidence of improved privacy (mean leakage rises slightly; improvement test p=0.95, worsening test p=0.078, neither significant) and runs slower on average on a desktop CPU, so quantization is a storage optimization only. The primary attack is the loss-threshold attack; a shadow-model check on a subset reaches the same qualitative conclusion. The defense is not formal differential privacy, but the finding is clear: on-device processing does not imply privacy; the privacy of a compressed sensor detector must be measured, not assumed.

Authors

Institutions

Publication Details

Journal
Machine Learning and Knowledge Extraction
Published
2026-10-08
DOI
https://doi.org/10.3390/make8100320
Primary Topic
Privacy-Preserving Technologies in Data
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

On-Device Is Not Private: Measuring Membership Leakage in Lightweight Sensor Anomaly Detectors

Vikram Puri, Aman Kataria, Sita Rani, Aditi Kataria et al.
Machine Learning and Knowledge Extraction
Privacy-Preserving Technologies in Data
article

On-Device Is Not Private: Measuring Membership Leakage in Lightweight Sensor Anomaly Detectors

Vikram Puri, Aman Kataria, Sita Rani, Aditi Kataria, Manpinder Singh Panesar
article en

Abstract

Compressed-TinyML pipelines apply distillation, quantization and pruning to fit lightweight anomaly detectors onto resource-constrained sensor nodes. Such frameworks are routinely called privacy-aware on the strength of on-device inference or noisy federated updates rather than any measured guarantee, yet that assumption is rarely tested with a membership-inference attack. Across six multivariate time-series datasets (sensor, facility and finance) and four compact reconstruction-autoencoder architectures (84 experimental cells), a detector accurate enough to deploy (detection AUC 0.878) is vulnerable to a reconstruction-error membership-inference attack (attack AUC 0.688; true-positive rate 0.074 at a 1% false-positive rate). A gradient-noise defense (gradient clipping with additive Gaussian noise) reduces measured leakage to near chance (attack AUC 0.508 as scored, 0.517 oriented away from chance, not exact chance; TPR cut 4.8-fold) at a utility cost of 0.054 in detection AUC (paired Cohen’s d=4.06 for the leakage drop, bootstrap 95% CI [0.145,0.210]), consistently across all datasets (one-sided paired Wilcoxon p=0.0156), while the utility change is nominal (p=0.031, d=1.36). Exported and executed as a real INT8 ONNX artifact, the model shrinks 3.2× but shows no evidence of improved privacy (mean leakage rises slightly; improvement test p=0.95, worsening test p=0.078, neither significant) and runs slower on average on a desktop CPU, so quantization is a storage optimization only. The primary attack is the loss-threshold attack; a shadow-model check on a subset reaches the same qualitative conclusion. The defense is not formal differential privacy, but the finding is clear: on-device processing does not imply privacy; the privacy of a compressed sensor detector must be measured, not assumed.

Machine Learning and Knowledge ExtractionVol. 8(10)
Chandigarh University (IN), National Institute of Technology Kurukshetra (IN), Lovely Professional University (IN), Guru Nanak Dev University (IN), Duy Tan University (VN), Kurukshetra University (IN), Graphic Era University (IN)
Openalex Percentile: Top 12%
Privacy-Preserving Technologies in Data
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.