Every time a smart thermostat, fitness tracker, or home security camera sends data to a cloud server, it exposes personal information that could be intercepted or misused. This fellowship aims to redesign how consumer Internet of Things (IoT) devices handle analytics, so that sensitive data never has to leave the device in the first place. Current systems force a trade-off: either users give up privacy to get personalised services, or they lock everything down and lose functionality. This project tackles that all-or-nothing problem by building a framework where models run directly on the device, using the latest security features in edge hardware. Service providers can verify that the model is authentic and untampered, while users keep their raw data private. The approach also integrates auditing and dynamic policy controls, so different users and regulators can set their own rules. If successful, this could reshape the economics of consumer IoT. It would allow sensitive analytics—such as health monitoring or behavioural insights—to happen lawfully without centralised data collection. Device manufacturers, network operators, and regulators would gain a shared technical foundation for trust, potentially unlocking new services that are currently blocked by privacy laws. The work is applied and architectural, not fundamental science, and aims for deployment within the next generation of edge devices.
View original technical description
Vision: In this fellowship, I aim to address a major challenge in the adoption of user-centred privacy-enhancing technologies: Can we leverage novel architectures to provide private, trusted, personalised, and dynamically- configurable models on consumer devices to cater for heterogenous environments and user requirements? Importantly, such properties must provide assurances for the data integrity and model authenticity/trustworthiness, while respecting the privacy of the individuals taking part in training and improving such models. Innovation and adoption in this space require collaborations between device manufacturers, platform providers, network operators, regulators, and the users. The objectives of this fellowship will take us far beyond the status-quo, one-size-fits-all solutions, providing a framework for personalised, trustworthy, and confidential edge computing, with ability to respect dynamic policies, in particular when dealing with sensitive models and data from the consumer Internet of Things (IoT) devices. In this fellowship, I aim to address these challenges by designing and evaluating an ecosystem where analytics from, and interaction with, consumer IoT devices can happen with trust in the model and authenticity, while enabling auditing and personalisation, hence pushing today's boundaries on all-or-nothing privacy and enabling new economic models. This approach requires designing for capabilities beyond the current trusted memory and processing limitations of the devices, and a cooperative dialogue and ecosystem involving service providers, ISPs, regulators, device manufacturers, and the end users. By designing our framework around the latest architectural and security features in edge devices, before they become commercially available, we provision for Model Privacy and a User-Centred IoT ecosystem, where service providers can have trust in the authenticity, attestability, and trustworthiness of the valuable models running on user devices, without the users having to reveal sensitive personal information to these cloud-based centralised systems. This approach will enable advanced and sensitive edge-based analytics to be performed, without jeopardising the individuals' privacy. Importantly, we aim to integrate mechanisms for data authenticity and attestation into our proposed framework, to enable trust in models and the data used by them. Such privacy-preserving technologies have the capacity to enable new form of sensitive analytics, without sharing raw data and thereby providing legal balancing capabilities that might enable certain sensitive (or currently unlawful) data analysis.
Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.
Is something wrong? Let us know