Mobile device theft detection
By using an accelerometer and activity recognition to detect theft through acceleration spikes, the method enhances mobile device security by reducing false positives and securing personal information.
Patent Information
- Application Number
- PCT/US2025/022815
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-22
- Filing Date
- 2025-04-02
- Publication Date
- 2025-10-30
AI Technical Summary
Mobile devices are vulnerable to theft, especially when unlocked, allowing thieves to access personal information or resell them, despite existing deterrents like IMEI bans and factory reset hardening.
A mobile device uses an accelerometer to detect a spike in acceleration during a suspected theft, combined with activity recognition data before and after the spike to determine if the device was stolen, implementing security measures like locking the screen or sending alerts if theft is confirmed.
This method significantly reduces false positives in theft detection by requiring both acceleration and activity recognition data, effectively protecting user data and preventing unauthorized access.
Smart Images

Figure US2025022815_30102025_PF_FP_ABST
Abstract
Description
MOBILE DEVICE THEFT DETECTION
[0001] This application claims benefit of U.S. Provisional Application No. 63 / 637,008, filed April 22, 2024, , the entire contents of which is incorporated herein by reference.BACKGROUND
[0002] Mobile devices have been subject to a large amount of thefts in recent years. A common way that a mobile device is stolen is by snatching the mobile device from the owner while the owner is using the mobile device. Typically, if the owner is using the mobile device at the time the thief snatches the mobile device, the mobile device will be unlocked. If the thief can keep the mobile device unlocked after the snatch, in some scenarios, the thief can access the owner’s personal information, such as bank accounts, social media accounts, etc. Additionally, or in the alternative, regardless of whether the mobile device is locked, the thief can sell the mobile device.
[0003] In efforts to deter mobile device thefts, a ban list has been created that identifies International Mobile Equipment Identity (IMEI) numbers of the mobile phones that have been reported stolen. Carriers have the option to “opt-in” to a program that blocks each mobile phone on the ban list from their respective network. Additionally, in efforts to deter mobile device thefts, manufacturers have hardened factory reset provisions to make it more difficult to reset and resell a locked mobile device.
[0004] Despite these efforts to deter mobile device thefts, personal information of the owner remains vulnerable, especially if the thief steals the mobile device while the mobile device is unlocked.SUMMARY
[0005] A mobile device may be snatched (e.g., stolen) from an owner while the owner is using the mobile device (e.g., while the mobile device is unlocked). When the mobile device is snatched, the mobile device may experience a spike in acceleration. An accelerometer within the mobile device may detect the spike in acceleration. In response to detecting the spike in acceleration, a processor of the mobile device may compare (1) first activity recognition data generated by sensors of the mobile device prior to the spike in acceleration to (2) second activity recognition data generated by the sensors of the mobile device after the spike in acceleration. Based on the comparison, the processor may determine if the spike in acceleration is due to a theft of the mobile device. If the processor determines that the mobiledevice was stolen, the processor may implement security measures at the mobile device. As a non-limiting example, the processor may lock a screen of the mobile device to prevent a thief from accessing the personal information of the owner. For example, the processor may deactivate the screen of the mobile device and require a personal identification number (PIN) or biometric data of the owner to gain access to the mobile device (e.g., to unlock the mobile device). As another example of a security measure, the processor may create and send an email to the owner. The email may include links (e.g., user-selectable links) that, when selected, cause the processor to perform actions. As a non-limiting example, the email may include a link that, when selected, causes the processor to lock the screen of the mobile device, remotely erase data stored by the mobile device, or a enation thereof.
[0006] In a first example, a method for securing a mobile device includes performing, by a processor of the mobile device, a theft detection operation. The theft detection operation includes detecting a spike in acceleration associated with the mobile device. Detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device. The theft detection operation also includes determining an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device in response to detecting the spike in acceleration.The method also includes implementing, by the processor, one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0007] In a second example, a mobile device includes a memory and a processor coupled to the memory. The processor is configured to detect a spike in acceleration associated with the mobile device. Detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device. In response to detecting the spike in acceleration, the processor is configured to determine an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device. The processor is configured to implement one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0008] In a third example, a non-transitory computer-readable medium includes instructions that, when executed by a processor of a mobile device, cause the processor to perform operations. The operations include performing a theft detection operation. The theft detection operation includes detecting a spike in acceleration associated with the mobile device. Detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device. The theft detection operation also includes determining an indication of whether the mobile device was stolen based at least on activity recognitiondata generated by at least one sensor of the mobile device in response to detecting the spike in acceleration. The operations also include implementing one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0009] In a fourth example, a system may include various means for carrying out each of the operations of the first example.
[0010] These, as well as other examples, aspects, advantages, and alternatives, will become apparent to those of ordinary skill in the art by reading the following detailed description, with reference where appropriate to the accompanying drawings. Further, this summary and other descriptions and figures provided herein are intended to illustrate examples by way of example only and, as such, that numerous variations are possible. For instance, structural elements and process steps may be rearranged, combined, distributed, eliminated, or otherwise changed, while remaining within the scope of the examples as claimed.BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1A illustrates a first instance of a scene whereby a mobile device is stolen, in accordance with examples described herein.
[0012] Figure IB illustrates a second instance of the scene whereby the mobile device is stolen, in accordance with examples described herein.
[0013] Figure 2 illustrates a diagram of a mobile device, in accordance with examples described herein.
[0014] Figure 3 illustrates an example of the multistep theft detection operation for determining whether a mobile device was stolen, in accordance with examples described herein.
[0015] Figure 4 illustrates an example of applying post-processing filters to an output of the multistep theft detection operation, in accordance with examples described herein.
[0016] Figure 5 is a diagram illustrating training and inference phases of a machine -learning model, in accordance with examples described herein.
[0017] Figure 6 illustrates a flow chart, in accordance with examples described herein.DETAILED DESCRIPTION
[0018] Example methods, devices, and systems are described herein. It should be understood that the words “example” and “exemplary” are used herein to mean “serving as an example, instance, or illustration.” Any example or feature described herein as being an “example,” “exemplary,” and / or “illustrative” is not necessarily to be construed as preferred oradvantageous over other examples or features unless stated as such. Thus, other embodiments may be utilized and other changes may be made without departing from the scope of the subject matter presented herein.
[0019] Accordingly, the examples described herein are not meant to be limiting. It will be readily understood that the aspects of the present disclosure, as generally described herein, and illustrated in the figures, may be arranged, substituted, combined, separated, and designed in a wide variety of different configurations.
[0020] Further, unless context suggests otherwise, the features illustrated in each of the figures may be used in combination with one another. Thus, the figures should be generally viewed as component aspects of one or more overall examples, with the understanding that not all illustrated features are necessary for each example.
[0021] Particular examples are described herein with reference to the drawings. In the description, common features are designated by common reference numbers throughout the drawings. In some figures, multiple instances of a particular type of feature are used. Although these features are physically and / or logically distinct, the same reference number is used for each, and the different instances are distinguished by addition of a letter to the reference number. When the features as a group or a type are referred to herein (e.g., when no particular one of the features is being referenced), the reference number is used without a distinguishing letter. However, when one particular feature of multiple features of the same type is referred to herein, the reference number is used with the distinguishing letter. For example, referring to Figure 2, activity recognition data is illustrated and associated with reference numbers 242A and 242B. When referring to a particular instance of the activity recognition data, such as the activity recognition data 242A, the distinguishing letter “A” is used. However, when referring to any arbitrary instance of activity recognition data or to the activity recognition data as a group, the reference number 242 is used without a distinguishing letter.
[0022] Additionally, any enumeration of elements, blocks, or steps in this specification or the claims is for purposes of clarity. Thus, such enumeration should not be interpreted to require or imply that these elements, blocks, or steps adhere to a particular arrangement or are carried out in a particular order. Unless otherwise noted, figures are not drawn to scale.
[0023] The techniques described herein improve the accuracy of mobile device theft detection by reducing the likelihood of false positives using a multistep operation. In particular, the techniques described herein provide a theft detection operation that utilizes (1) accelerometer data to detect a spike in acceleration of the mobile device that is representativeof someone “snatching” the mobile device and (2) activity recognition results to compare first detected user activity before the spike in acceleration to second detected user activity after the spike in acceleration. As used herein, detecting “a spike in acceleration” corresponds to detecting an instantaneous (or near instantaneous) increase in acceleration that exceeds a threshold value. Based at least on the accelerometer data and the activity recognition results, the mobile device may accurately determine if the mobile device was stolen.
[0024] To illustrate, the theft detection operation is based on the premise that if the mobile device is stolen (e.g., snatched from the hands of the owner), there is a relatively large likelihood that the mobile device would experience a spike in acceleration during the snatching motion and / or as the thief attempts to get away, either via foot or vehicle. Thus, a first factor to determine during the theft detection operation is whether the mobile device experienced a spike in acceleration.
[0025] The mobile device may include an accelerometer that detects acceleration of mobile device. The accelerometer generates acceleration data indicating whether the mobile device accelerated and / or how much (e.g., at what rate) the mobile device accelerated. The acceleration data is provided to a processor for use during the theft detection operation. In some implementations, one or more machine -learning models may be used to perform the theft detection operation, and the acceleration data along with other factors, as indicated below, may be used (e.g., provided as inputs to the one or more machine-learning models) to perform the theft detection operation. In the scenarios where a machine-learning model is used to perform the theft detection operation, the machine-learning model may be hosted completely on the mobile device to ensure that personal information of the owner is not shared with a remote server. For ease of description, the processor and / or the one or more machine-learning models may simply be referred to as “theft detection circuitry”.
[0026] Most notably, if a spike in acceleration is detected, activity recognition data generated by at least one sensor of the mobile device is provided as an additional input to the theft detection circuitry. The activity recognition data is usable to classify user activity (e.g., different types of physical motion of a user carrying the mobile device) prior to the detected spike in acceleration and after the detected spike in acceleration. As non-limiting examples, the activity recognition data may indicate whether a user of the mobile device is walking, running, resting, traveling in a vehicle, etc. To determine whether the activity recognition data supports a change in user activity that could indicate the theft of the mobile device, first activity recognition data (generated prior to detection of the spike in acceleration) and second activity recognition data (generated after detection of the spike in acceleration) are providedas inputs to the theft detection circuitry. Based at least on a comparison between the first activity recognition data and the second activity recognition data, the theft detection circuitry may generate a result (e.g., a confidence value) that indicates whether the mobile device was stolen. As a non-limiting example, if the first activity recognition data indicates that a user of the mobile device is walking and the second activity recognition data indicates that a user of the mobile device is sprinting, the theft detection circuitry may infer that the change in user activity could be indicative of a mobile device theft (e.g., a thief running away).
[0027] To further improve the accuracy of mobile device theft detection and reduce false positives, other factors may be considered and / or evaluated by the theft detection circuitry to determine whether the mobile device was stolen. As a non-limiting example, an indication of whether a particular application on the mobile device is activated after detection of the spike in acceleration may be provided to the theft detection circuitry. To illustrate, shortly after stealing the mobile device, a thief may (1) activate a camera application to keep the mobile device unlocked while running away or (2) activate a banking application to access financial information of the owner of the mobile device. Thus, if inputs to the theft detection circuitry indicate that one of these applications were activated shortly after detecting the spike in acceleration, the theft detection circuitry may determine there is a greater likelihood that the mobile device was stolen (e.g., generate a higher confidence value indicating the mobile device was stolen).
[0028] As another non-limiting example, an indication of whether the mobile device was disconnected from a local area network shortly after detection of the spike in acceleration may be provided to the theft detection circuitry. To illustrate, the owner may be connected to a local area network prior to the thief snatching the mobile device. After snatching the mobile device, the thief may run out of the range of the local area network, and as a result, the mobile device may be disconnected from the local area network. Thus, if inputs to the theft detection circuitry indicate that the mobile device disconnected from the local area network shortly after detecting the spike in acceleration, the theft detection circuitry may determine there is a greater likelihood that the mobile device was stolen.
[0029] As another non-limiting example, an indication of whether an auxiliary device (e.g., a personal watch, headphones, headsets, earphones, speakers, cars, etc.) has been disconnected from the mobile device shortly after detection of the spike in acceleration may be provided to the theft detection circuitry. To illustrate, prior to the thief snatching the mobile device, the owner may be utilizing an auxiliary device, such as a wired headset or a wireless headset (e.g., a Bluetooth headset). After snatching the mobile device, the auxiliary device maybecome disconnected. To illustrate, the wire may be physically disconnected from the mobile device as the thief runs away or the wireless headset may become out of range of the mobile device as the thief runs away. Thus, if inputs to the theft detection circuitry indicate that an auxiliary device has been disconnected shortly after detecting the spike in acceleration, the theft detection circuitry may determine there is a greater likelihood that the mobile device was stolen.
[0030] As another non-limiting example, a location of the mobile device may be provided to the theft detection circuitry. To illustrate, there is a lower degree of likelihood that the mobile device was stolen if the mobile device is in a trusted location, such as the owner’s home or the owner’s workplace. Thus, if positional inputs to the theft detection circuitry indicate that the mobile device is in a trusted location (e.g., a trusted environment) at the time of the spike in acceleration, the theft detection circuitry may determine there is a lower likelihood that the mobile device was stolen. However, if positional inputs to the theft detection circuitry indicate that the mobile device is not in a trusted location at the time of the spike in acceleration, the theft detection circuitry may determine there is a greater likelihood that the mobile device was stolen.
[0031] In response to an indication that the mobile device was stolen, the theft detection circuitry may implement security measures to protect the owner’s personal information. As a non-limiting example, the processor may lock the mobile device and require a personal identification number (PIN) or biometric data of the owner to gain access to the mobile device (e.g., to unlock the mobile device). In some examples, the processor may protect applications, settings, and credentials (e.g., passkeys) even if the thief knows the PIN, pattern or password to access the mobile device. For example, in some examples, if the mobile device is in an untrusted location, biometric data may be required to access sensitive information.
[0032] In some scenarios, the processor may not lock the mobile device in response to an indication that the mobile device was stolen. For example, if the mobile device is being used for an emergency call (e.g., a “911” call), the mobile device may not be locked in response to an indication that the mobile device was stolen. In other scenarios, the processor may not lock the mobile device in response to an indication that the mobile device was stolen while the owner was driving or if the mobile device was being used for active navigation.
[0033] In some scenarios, to reduce the amount of false positives that indicate the mobile device was stolen, the techniques described herein provide pre-processing filters to control activation of the theft detection operation. For example, a thief may typically steal themobile device while the device is in the owner’s hand (e.g., while the owner is using the mobile device). Thus, to reduce the amount of false positives, in some scenarios, the theft detection operation may trigger only if the screen of the mobile device is activated (e.g., the mobile device is unlocked), as the screen is typically activated if the mobile device is in the owner’s hand. As another example, the theft detection operation may trigger only if the mobile device is in an uncategorized location. For example, as described above, it is unlikely that a thief will snatch the mobile device from the owner while the owner is at work or at home. Thus, to reduce the amount of false positives, in some scenarios, the theft detection operation may trigger when the mobile device is in a public setting that has not been categorized by the owner. It should also be appreciated that by running the theft detection operation when the screen is activated and when the mobile device is not in a trusted location, power savings may be achieved because the theft detection operation may not be continuously running.
[0034] Although the above examples describe implementing security measures to protect the owner’s personal information in response to detecting a theft of the mobile device, the security measures may also be implemented in response to detecting repeated incorrect PIN entries. In some examples, in response to detecting a theft of the mobile device or detecting repeated incorrect PIN entries, a notification may be sent to the owner that enables the owner to lock the mobile device. For example, the notification may be sent to an email address registered to the owner of the mobile device, and the owner may access his or her email from any device to lock the mobile device.
[0035] In some examples, in response to detecting repeated incorrect PIN entries, the processor may perform actions to slow down PIN guessing attempts. As a non-limiting example, the processor may increase the amount of time between generating prompts to enter the PIN. Additionally, or in the alternative, to deter thieves from stealing the mobile device, the processor may prevent clearing data from the mobile device (e.g., prevent wiping out the mobile device) unless an account password is entered.
[0036] Figure 1A illustrates a first instance 100A of a scene whereby a mobile device is stolen, in accordance with examples described herein. In the first instance 100A of the scene, a thief 110 is walking behind an owner 120 of a mobile device 130. The mobile device 130 may be a mobile phone, a tablet, a personal digital assistant (PDA), a laptop computer, etc. As depicted in Figure 1, the owner 120 of the mobile device 130 is using the mobile device 130 while walking. In particular, a screen of the mobile device 130 is unlocked as the thief 110 approaches the owner 120 of the mobile device 130. Because the screen of the mobiledevice 130 is unlocked, anybody that possesses the mobile device 130 may be able to access personal information of the owner 120, such as the owner’s 120 bank accounts, the owner’s 120 social media accounts, etc.
[0037] Figure IB illustrates a second instance 100B of the scene whereby the mobile device is stolen, in accordance with examples described herein. In the second instance 100B of the scene, the thief 110 snatched the mobile device 130 from the owner 120 and ran away from the owner 120 of the mobile device 130. Typically, the owner 120 may not have time to react and lock the mobile device 130 prior to the thief 110 running away. As a result, the personal information of the owner 120 may be accessible to the thief 110 if the thief 110 may keep the mobile device 130 unlocked.
[0038] As described below, the mobile device 130 may be configured to (1) perform a theft detection operation to determine whether the mobile device 130 was stolen and (2) automatically lock in response to a determination that the mobile device 130 was stolen. For example, when the thief 110 snatches the mobile device 130 from the owner 120, the mobile device 130 may experience a spike in acceleration. In particular, the spike in acceleration of the mobile device 130 may be based on the snatching motion and / or based on the thief 110 running away from the owner 120 after the snatch. An accelerometer within the mobile device 130 may detect the spike in acceleration. In response to the spike in acceleration, the processor may compare (1) first activity recognition data generated by sensors of the mobile device prior to the spike in acceleration to (2) second activity recognition data generated by the sensors of the mobile device after the spike in acceleration. Based on the comparison, the processor may determine if the spike in acceleration is due to a theft of the mobile device 130. If the processor determines that the mobile device 130 was stolen, the processor may implement security measures at the mobile device 130. As a non-limiting example, the processor may lock a screen of the mobile device 130 to prevent the thief 110 from accessing the personal information of the owner 120.
[0039] Figure 2 illustrates a diagram of the mobile device 130, in accordance with examples described herein. As described with respect to Figure 1, the mobile device 130 may be configured to perform a theft detection operation to determine whether the mobile device 130 was stolen and automatically lock in response to a determination that the mobile device 130 was stolen.
[0040] The mobile device 130 includes a processor 200 and a memory 202 coupled to the processor 200. The memory 202 may be a non-transitory computer-readable medium that stores instructions 203 that are executable by the processor 200 to perform the operationsdescribed herein. Specifically, the instructions 203 may be executable to cause the processor 200 to (1) perform the theft detection operation described herein and (2) implement the security measures described herein in response to detecting the mobile device 130 was stolen.
[0041] The mobile device 130 also includes a camera 204 coupled to the processor 200, a display screen 206 coupled to the processor 200, a network transceiver 208 coupled to the processor 200, an auxiliary device interface 214 coupled to the processor 200, and one or more sensors 216 coupled to the processor 200. The one or more sensors 216 may include an accelerometer 210, a proximity sensor 290, a light sensor 292, a microphone 294, and other sensors, as non-limiting examples. It should be understood that additional components (e.g., circuitry, hardware, etc.) ca may n be coupled to the processor 200. The components depicted in Figure 2 are merely for illustrative purposes and should not be construed as limiting.
[0042] The processor 200 includes a theft detection unit 220, an application status monitor 224, a network connectivity monitor 226, an auxiliary connectivity monitor 228, a face recognition unit 230, a security measure implementation unit 236, and a display screen status indicator 280. According to some implementations, one or more components of the processor 200 may be implemented using dedicated circuitry. As non-limiting examples, one or more components of the processor 200 may be implemented using application-specific integrated circuits (ASICs) or field-programmable gate array (FPGA) devices. According to some implementations, one or more components of the processor 200 may be implemented using software. As a non-limiting example, the processor 200 may execute the instructions 203 stored in the memory 202 to perform the operations of one or more components of the processor 200.
[0043] The processor 200 may be configured to perform a multistep theft detection operation that utilizes (1) acceleration data 212 to detect a spike 240 in acceleration of the mobile device 130 and (2) activity recognition data 242 to compare first detected user activity before the spike 240 in acceleration (e.g., pre-spike activity recognition results) to second detected user activity after the spike 240 in acceleration (e.g., post-spike activity recognition results). To illustrate, the multistep theft detection operation is based on the premise that if the mobile device 130 is stolen (e.g., snatched from the hands of the owner 120), there is a relatively large likelihood that the mobile device 130 experiences a spike 240 in acceleration during the snatching motion and / or as the thief 110 attempts to get away. Thus, a first factor to determine during the theft detection operation is whether the mobile device 130 experienced a spike 240 in acceleration.
[0044] To determine whether the mobile device 130 experiences a spike 240 in acceleration, the accelerometer 210 generates acceleration data 212 indicating whether the mobile device 130 accelerated and / or how much (e.g., at what rate) the mobile device 130 accelerated. The acceleration data 212 is provided to the theft detection unit 220. The theft detection unit 220 may be configured to detect a spike 240 in acceleration associated with the mobile device 130 based on the acceleration data 212. For example, the theft detection unit 220 may detect an instantaneous (or near instantaneous) increase in acceleration that exceeds a threshold value.
[0045] In some implementations, one or more machine -learning models 260 may be integrated into the theft detection unit 220 to perform at least a part of the multistep theft detection operation. For example, as described in greater detail with respect to Figure 3, in some implementations, the acceleration data 212 may be provided as an input to a classification model (e.g., a particular machine-learning model 260) to detect the acceleration spike 240.
[0046] In response to detecting the spike 240 in acceleration, the theft detection unit 220 may be configured to determine an indication of whether the mobile device 130 was stolen 264 (or not stolen 266) based at least on activity recognition data 242 generated by at least one of the sensors 216. The activity recognition data 242 is usable to classify user activity prior to the detected spike 240 in acceleration and after the detected spike 240 in acceleration. For example, the one or more sensors 216 may generate (1) first activity recognition data 242 A generated prior to the theft detection unit 220 detecting the spike 240 in acceleration and (2) second activity recognition data 242B generated after the theft detection unit 220 detects the spike 240 in acceleration. To determine whether the activity recognition data 242 supports a change in user activity that could indicate the theft of the mobile device 130, the first activity recognition data 242A and the second activity recognition data 242B are provided as inputs to the theft detection unit 220. In some implementations, the activity recognition data 242A, 242B are provided as inputs to the one or more machine-learning models 260. Based at least on a comparison between the first activity recognition data 242A and the second activity recognition data 242B, the theft detection unit 220 may generate a confidence value 262 that indicates whether (e.g., the likelihood) the mobile device 130 was stolen 264 (or not stolen 266). As a non-limiting example, if the first activity recognition data 242A indicates that a user of the mobile device 130 is walking and the second activity recognition data 242B indicates that a user of the mobile device 130 is running, the theft detection unit 220 may infer that the change in user activity could be indicative of a mobile device theft.
[0047] To reduce the number of false positives generated by the theft detection unit 220, the processor 200 may use post-processing filters that consider other factors that contribute to a determination of whether the mobile device 130 was stolen 264. As a non-limiting example, the application status monitor 224 may be configured to determine whether a particular application 244 has been activated within a particular period of time after detecting the spike 240 in acceleration. As used herein, the “particular period of time” after detecting the spike 240 in acceleration may correspond to a short time window (e.g., between one second and two minutes) before the mobile device 130 locks due to user inactivity. In some implementations, the particular application 244 corresponds to a camera application 244A. In other implementations, the particular application 244 corresponds to a banking application 244B. To illustrate, shortly after stealing the mobile device 130, the thief 110 may (1) activate the camera application 244 A to keep the mobile device 130 unlocked while running away or (2) activate the banking application 244B to access financial information of the owner 120 of the mobile device 130. Thus, the processor 200 may determine that the mobile device 130 was stolen 264 (e.g., the processor 200 may increase the confidence value 262 indicating that the mobile device 130 was stolen 264) based, at least in part, on a determination that the particular application 244 has been activated within the particular period of time.
[0048] As another non-limiting example of using post-processing filters to reduce the number of false positives, the network connectivity monitor 226 may be configured to determine whether the mobile device 130 has been disconnected from a particular local area network within a particular period of time after detecting the spike 240 in acceleration. To illustrate, the owner 120 may be connected to a local area network, such as an Institute of Electrical and Electronics Engineers (IEEE) 802. 11 network, prior to the thief 110 snatching the mobile device 130. After snatching the mobile device 130, the thief 110 may run out of the range of the local area network, and as a result, the mobile device 130 may be disconnected from the local area network. Thus, the processor 200 may use network connectivity data 246 to determine that the mobile device 130 was stolen 264 (e.g., the processor 200 may increase the confidence value 262 indicating that the mobile device 130 was stolen 264) based, at least in part, on a determination that the mobile device 130 has been disconnected from the particular local area network within the particular period of time.
[0049] As another non-limiting example of using post-processing filters to reduce the number of false positives, the auxiliary connectivity monitor 228 may be configured to determine whether an auxiliary device has been disconnected from the auxiliary device interface 214 ofthe mobile device 130 within a particular period of time after detecting the spike 240 in acceleration. To illustrate, prior to the thief 110 snatching the mobile device 130, the owner 120 may be utilizing an auxiliary device, such as a wired headset or a wireless headset. After snatching the mobile device 130, the auxiliary device may become disconnected. To illustrate, the wire may be physically disconnected from the mobile device 130 as the thief 110 runs away or the wireless headset may become out of range of the mobile device 130 as the thief 110 runs away. Thus, the processor 200 may use auxiliary device connectivity data 248 to determine that the mobile device 130 was stolen 264 (e.g., the processor 200 may increase the confidence value 262 indicating that the mobile device 130 was stolen 264) based, at least in part, on a determination that the auxiliary device has been disconnected from the mobile device 130 within the particular period of time.
[0050] As another non-limiting example of using post-processing filters to reduce the number of false positives, in conjunction with the camera 204, the face recognition unit 230 may be configured to determine, after detection of the spike 240 in acceleration, whether a face recognition application recognizes a user attempting to use the mobile device 130. For example, based on face recognition data 250 generated by the face recognition unit 230, the processor 200 may determine that the mobile device 130 was stolen 264 (e.g., the processor 200 may increase the confidence value 262 indicating that the mobile device 130 was stolen 264) based, at least in part, on a determination that the face recognition application fails to recognize the user attempting to use the mobile device 130.
[0051] In some scenarios, to reduce the amount of false positives that indicate the mobile device 130 was stolen, the processor 200 may use pre-processing filters to control activation of the multistep theft detection operation. For example, the thief 110 may typically steal the mobile device 130 while the mobile device 130 is in the owner’s hand (e.g., while the owner 120 is using the mobile device 130) in a public setting.
[0052] Thus, to reduce the amount of false positives, in some scenarios, the processor 200 may be configured to determine, based on the display screen status indicator 280, whether the mobile device 130 is activated and unlocked. If the display screen 206 is locked 233A, the multistep theft detection operation may not trigger in response to detecting the spike 240 in acceleration. However, if the display screen 206 is unlocked 233B, the multistep theft operation may trigger in response to detecting the spike 240 in acceleration. Thus, in some scenarios, the multistep theft detection operation may trigger only if the display screen 206 of the mobile device 130 is activated (e.g., the mobile device 130 is unlocked), as the display screen 206 is typically activated if the mobile device 130 is in the owner’s hand.
[0053] As another example, in some scenarios, the multistep theft detection operation may trigger only if the mobile device 130 is not in a trusted location. For example, it is unlikely that a thief 110 will snatch the mobile device 130 from the owner 120 while the owner 120 is at work or at home. Thus, to reduce the amount of false positives, in some scenarios, the theft detection operation may trigger when the mobile device 130 is in a public setting that has not been categorized by the owner 120. The processor 200 may use location data 282 (e.g., Global Positioning System (GPS) data) obtained by the sensors 216 to determine whether the mobile device 130 is in a trusted location. The theft detection operation may be performed in response to a determination that the mobile device 130 is not in a trusted location.
[0054] According to one implementation, to determine whether the mobile device 130 is in the trusted location, the processor 200 may determine whether the mobile device 130 is connected to a familiar local area network (e.g., a local area network previously connected to by the mobile device 130). The processor 200 may determine that the mobile device 130 is not within the trusted location in response to a determination that the mobile device 130 is not connected to the familiar local area network.
[0055] It should be appreciated that by only running the theft detection operation when the screen is activated and when the mobile device is not in a trusted location, power savings may be achieved because the theft detection operation may not be continuously running
[0056] In response to the theft detection unit 220 determining that the mobile device was stolen 264 (e.g., if the confidence value 262 indicates the mobile device 130 was stolen 264), the security measure implementation unit 236 may be configured to perform one or more security measures 270. As a non-limiting example, the security measure implementation unit 236 may lock 272 the mobile device 130. To illustrate, the security measure implementation unit 236 may deactivate the display screen 206 of the mobile device 130 and require a correct PIN (entered via a user interface 207) or biometric data of the owner 120 to gain access to the mobile device 130 (e.g., to unlock the mobile device 130). As another non-limiting example of the security measures 270, the security measure implementation unit 236 may initiate communication of an IMEI number of the mobile device 130 to a ban list so that carriers block the mobile device 130 from their networks. As yet another non-limiting example of the security measures 270, the security measure implementation unit 236 may initiate a factory reset 274 of the mobile device 130.
[0057] The techniques described with respect to Figures 1-2 may improve the accuracy of mobile device theft detection by reducing the likelihood of false positives using a multistepoperation. In particular, the techniques utilize accelerometer data to detect the spike 240 in acceleration of the mobile device 130 that is representative of someone “snatching” the mobile device 130. Only in response to detection of the spike 240 does utilize activity recognition data 242 compare first detected user activity before the spike 240 in acceleration to second detected user activity after the spike 240 in acceleration. Thus, by requiring detection of the spike 240 before comparing pre-spike activity recognition to post-spike activity recognition, false positives strictly based on activity recognition may be reduced.
[0058] Figure 3 illustrates an example of the multistep theft detection operation for determining whether a mobile device was stolen, in accordance with examples described herein. In particular, the multistep theft detection operation described with respect to Figure 3 may be implemented by the processor 200 to determine whether the mobile device 130 was stolen.
[0059] According to a first step 310 of the multistep theft detection operation, the acceleration data 212 is used to identify (e.g., detect) the spike 240 in acceleration associated with the mobile device 130. For example, the spike 240 in acceleration may be identified in response to detecting an instantaneous (or near instantaneous) increase in acceleration that exceeds a threshold value. In response to identifying the spike 240 in acceleration, a classification model 360A may be configured to determine whether the mobile device was stolen based on activity recognition data 242 and the acceleration data 212, as described with respect to a second step 320 of the multistep theft detection operation.
[0060] According to the second step 320 of the multistep theft detection operation, in response to detecting the spike 240 in acceleration, the first activity recognition data 242A generated prior to the spike 240 in acceleration and the second activity recognition data 242B generated after the spike 240 in acceleration are provided to a machine -learning activity theft detection model 360B. The machine -learning activity theft detection model 360B may correspond to at least one of the one or more machine -learning models 260 described with respect to Figure 2. Based at least on a comparison between the first activity recognition data 242A and the second activity recognition data 242B, the machine-learning activity recognition theft detection model 360B may generate the confidence value 262 that indicates whether the mobile device 130 was stolen 264 (or not stolen 266). As a non-limiting example, if the first activity recognition data 242A indicates that a user of the mobile device 130 is walking and the second activity recognition data 242B indicates that a user of the mobile device 130 is running, the theft detection unit 220 may infer that the change in user activity could be indicative of a mobile device theft.
[0061] The multistep theft detection operation of Figure 3 may improve the accuracy of mobile device theft detection by reducing the likelihood of false positives. In particular, the multistep theft detection operation utilizes accelerometer data to detect the spike 240 in acceleration of the mobile device 130 that is representative of someone “snatching” the mobile device 130. Only in response to detection of the spike 240 does the multistep theft detection operation utilize activity recognition data 242 to compare first detected user activity before the spike 240 in acceleration to second detected user activity after the spike 240 in acceleration. Thus, by requiring detection of the spike 240 before comparing pre-spike activity recognition to post-spike activity recognition, false positives strictly based on activity recognition may be reduced.
[0062] Figure 4 illustrates an example of applying post-processing filters to an output of the multistep theft detection operation, in accordance with examples described herein. The techniques described with respect to Figure 4 may be implemented by the processor 200 to determine whether the mobile device 130 was stolen.
[0063] In Figure 4, the confidence value 262 is provided to one or more post-processing filters 410. The one or more post-processing filters 410 may determine whether the mobile device 130 was stolen 264 (e.g., update the confidence value 262) based on one or more other factors. As non-limiting examples, the one or more other factors may include an indication of whether a particular application 244 (e.g., the camera application 244A and / or the banking application 244B) on the mobile device 130 is activated after detecting the spike 240 in acceleration, an indication of whether the mobile device 130 is disconnected from a local area network after detecting the spike 240 in acceleration, an indication of whether an auxiliary device has been disconnected from the mobile device 130 after detecting the spike 240 in acceleration, or a location of the mobile device 130.
[0064] Based on the factors applied by the post-processing filters 410, an updated confidence value 462 is generated. Thus, the techniques described with respect to Figure 4 further reduce the likelihood of generating a false positive by adding post-processing filters 410 to the confidence value 262.
[0065] Figure 5 shows a diagram 500 illustrating a training phase 502 and an inference phase 504 of trained machine-learning model(s) 532, in accordance with examples. According to some examples, the trained machine-learning model(s) 532 may correspond to the one or more machine-learning models 260, the classification model 360A, or the machine-learning activity recognition theft detection model 360B. Some machine-learning techniques involve training one or more machine -learning algorithms on an input set of training data to recognizepaterns in the training data and provide output inferences and / or predictions about (paterns in the) training data. The resulting trained machine -learning algorithm may be termed as a trained machine-learning model. For example, Figure 5 shows the training phase 502 where machine -learning algorithm(s) 520 are being trained on training data 510 to become trained machine-learning model(s) 532. Then, during the inference phase 504, the trained machinelearning model(s) 532 may receive input data 530 and one or more inference / prediction requests 540 (perhaps as part of the input data 530) and responsively provide as an output one or more inferences and / or prediction(s) 550.
[0066] As such, the trained machine -learning model(s) 532 may include one or more models of machine-learning algorithm(s) 520. The machine -learning algorithm(s) 520 may include, but are not limited to: an artificial neural network (e.g., a herein-described convolutional neural networks, a recurrent neural network, a Bayesian network, a hidden Markov model, a Markov decision process, a logistic regression function, a support vector machine, a suitable statistical machine-learning algorithm, and / or a heuristic machine-learning system). The machine -learning algorithm(s) 520 may be supervised or unsupervised, and may implement any suitable combination of online and offline learning.
[0067] In some examples, the machine-learning algorithm(s) 520 and / or the trained machinelearning model(s) 532 may be accelerated using on-device coprocessors, such as graphic processing units (GPUs), tensor processing units (TPUs), digital signal processors (DSPs), and / or application specific integrated circuits (ASICs). Such on-device coprocessors may be used to speed up the machine -learning algorithm(s) 520 and / or the trained machine-learning model(s) 532. In some examples, the trained machine -learning model(s) 532 may be trained, resided and executed to provide inferences on a particular computing device, and / or otherwise may make inferences for the particular computing device.
[0068] During the training phase 502, the machine-learning algorithm(s) 520 may be trained by providing at least the training data 510 as training input using unsupervised, supervised, semi-supervised, and / or reinforcement learning techniques. Unsupervised learning involves providing a portion (or all) of the training data 510 to the machine -learning algorithm(s) 520 and the machine -learning algorithm(s) 520 determining one or more output inferences based on the provided portion (or all) of the training data 510. Supervised learning involves providing a portion of the training data 510 to the machine-learning algorithm(s) 520, with the machine-learning algorithm(s) 520 determining one or more output inferences based on the provided portion of the training data 510, and the output inference(s) are either accepted or corrected based on correct results associated with the training data 510. In some examples,supervised learning of the machine-learning algorithm(s) 520 may be governed by a set of rules and / or a set of labels for the training input, and the set of rules and / or set of labels may be used to correct inferences of the machine-learning algorithm(s) 520.
[0069] Semi-supervised learning involves having correct results for part, but not all, of the training data 510. During semi-supervised learning, supervised learning is used for a portion of the training data 510 having correct results, and unsupervised learning is used for a portion of the training data 510 not having correct results. Reinforcement learning involves the machine -learning algorithm(s) 520 receiving a reward signal regarding a prior inference, where the reward signal may be a numerical value. During reinforcement learning, the machine -learning algorithm(s) 520 may output an inference and receive a reward signal in response, where the machine-learning algorithm(s) 520 are configured to try to maximize the numerical value of the reward signal. In some examples, reinforcement learning also utilizes a value function that provides a numerical value representing an expected total of the numerical values provided by the reward signal over time. In some examples, the machinelearning algorithm(s) 520 and / or the trained machine-learning model(s) 532 may be trained using other machine-learning techniques, including but not limited to, incremental learning and curriculum learning.
[0070] In some examples, the machine-learning algorithm(s) 520 and / or the trained machinelearning model(s) 532 may use transfer learning techniques. For example, transfer learning techniques may involve the trained machine-learning model(s) 532 being pre-trained on one set of data and additionally trained using the training data 510. More particularly, the machine-learning algorithm(s) 520 may be pre-trained on data from one or more computing devices and a resulting trained machine-learning model provided to a particular computing device, where the particular computing device is intended to execute the trained machinelearning model during the inference phase 504. Then, during the training phase 502, the pretrained machine-learning model may be additionally trained using the training data 510, where the training data 510 may be derived from kernel and non-kemel data of the particular computing device. This further training of the machine-learning algorithm(s) 520 and / or the pre-trained machine -learning model using the training data 510 of the particular computing device’s data may be performed using either supervised or unsupervised learning. Once the machine -learning algorithm(s) 520 and / or the pre-trained machine-learning model has been trained on at least the training data 510, the training phase 502 may be completed. The trained resulting machine-learning model may be utilized as at least one of the trained machine learning model(s) 532.
[0071] In particular, once the training phase 502 has been completed, the trained machinelearning model(s) 532 may be provided to a computing device, if not already on the computing device. The inference phase 504 may begin after training the machine-learning model(s) 532 are provided to the particular computing device.
[0072] During the inference phase 504, the trained machine-learning model(s) 532 may receive the input data 530 and generate and output one or more corresponding inferences and / or prediction(s) 550 about the input data 530. As such, the input data 530 may be used as an input to the trained machine -learning model(s) 532 for providing corresponding inference(s) and / or prediction(s) 550 to kernel components and non-kemel components. For example, the trained machine -learning model(s) 532 may generate inference(s) and / or prediction(s) 550 in response to one or more inference / prediction requests 540. In some examples, the trained machine-learning model(s) 532 may be executed by a portion of other software. For example, the trained machine-learning model(s) 532 may be executed by an inference or prediction daemon to be readily available to provide inferences and / or predictions upon request. The input data 530 may include data from the particular computing device executing the trained machine-learning model(s) 532 and / or input data from one or more computing devices other than the particular computing device.
[0073] If the trained machine -learning model 532 corresponds to the one or more machinelearning models 260, the input data 530 may include the acceleration data 212, the first activity recognition data 242A, or the second activity recognition data 242B. Other types of input data are possible as well. Inference(s) and / or prediction(s) 550 may include other output data produced by the trained machine-learning model(s) 532 operating on the input data 530 (and the training data 510). In some examples, the trained machine-learning model(s) 532 may use output inference(s) and / or prediction(s) 550 as input feedback 560. The trained machine -learning model(s) 532 may also rely on past inferences as inputs for generating new inferences.
[0074] Convolutional neural networks and / or deep neural networks used herein may be an example of the machine-learning algorithm(s) 520. After training, the trained version of a convolutional neural network may be an example of the trained machine -learning model(s) 532. In this approach, an example of the one or more inference / prediction requests 540 may be the confidence value 262 indicative of the likelihood that the mobile device 130 was stolen.
[0075] Figure 6 illustrates a flow chart of operations 600 related to a new technology. Operations 600 may be carried out by the mobile device 130 among other possibilities. Theexamples of Figure 6 may be simplified by the removal of any one or more of the features shown therein. Further, these examples may be combined with features, aspects, and / or implementations of any of the previous figures or otherwise described herein.
[0076] Operations 600 includes detecting, by a processor of a mobile device, a spike in acceleration associated with the mobile device, at block 602. Detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device. For example, referring to Figures 1-2, the accelerometer 210 generates the acceleration data 212 indicating whether the mobile device 130 accelerated and / or how much (e.g., at what rate) the mobile device 130 accelerated. The acceleration data 212 is provided to the theft detection unit 220. The theft detection unit 220 may be configured to detect a spike 240 in acceleration associated with the mobile device 130 based on the acceleration data 212. For example, the theft detection unit 220 may detect an instantaneous (or near instantaneous) increase in acceleration that exceeds a threshold value.
[0077] Operations 600 also includes, in response to detecting the spike in acceleration, determining an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device, at block 604. For example, referring to Figures 1-2, the theft detection unit 220 determines an indication of whether the mobile device 130 was stolen 264 based at least on activity recognition data 242 generated by the one or more sensors 216 of the mobile device 130 in response to detecting the spike 240 in acceleration.
[0078] Operations 600 also includes implementing, by the processor, one or more security measures at the mobile device in response to a determination that the mobile device was stolen, at block 606. For example, referring to Figures 1-2, the security measure implementation unit 236 implements one or more security measures 270 at the mobile device 130 in response to a determination that the mobile device 130 was stolen 264. According to one implementation, the one or more security measures include locking the mobile device 130.
[0079] According to one implementation of operations 600, detecting the spike in acceleration includes detecting an instantaneous increase in acceleration that exceeds a threshold value. For example, referring to Figure 2, to detect the spike 240 in acceleration, the theft detection unit 220 may detect an instantaneous increase in acceleration that exceeds a threshold value.
[0080] According to one implementation of operations 600, the acceleration data and the activity recognition data are provided as inputs to a machine-learning model hosted by theprocessor. For example, referring to Figure 2, the acceleration data 212 and the activity recognition data 242 are provided as inputs to the one or more machine-learning models 260 hosted by the processor 200. According to one implementation of operations 600, the determination of whether the mobile device was stolen is based on an output of the machinelearning model. For example, referring to Figure 2, the confidence value 262 indicating whether the mobile device 130 was stolen 264 is based on an output of the one or more machine-learning models 260.
[0081] According to one implementation, determining the indication of whether the mobile device was stolen includes comparing first activity recognition data generated prior to detecting the spike in acceleration to second activity recognition data generated after detecting the spike in acceleration. For example, referring to Figure 2, the theft detection unit 220 (or the machine-learning model 360B) compares the first activity recognition data 242A generated prior to the spike 240 in acceleration to the second activity recognition data 242B generated after the spike 240 in acceleration. The indication of whether the mobile device was stolen may be based on comparing the first activity recognition data to the second activity recognition data. For example, referring to Figure 2, the theft detection unit 220 (or the machine-learning model 360B) generates the confidence value 262 based on comparing the first activity recognition data 242A to the second activity recognition data 242B.According to one implementation of operations 600, the activity recognition data is usable to classify user activity.
[0082] According to one implementation of operations 600, determining the indication of whether the mobile device 130 was stolen 264 is based on at least one other factor (e.g., a post-processing filter). As non-limiting examples, the other factor may include at least one of an indication of whether a particular application 244 on the mobile device 130 is activated after detecting the spike 240 in acceleration, an indication of whether the mobile device 130 is disconnected from a local area network after detecting the spike 240 in acceleration, an indication of whether an auxiliary device has been disconnected from the mobile device 130 after detecting the spike 240 in acceleration, or a location of the mobile device 130.According to one implementation of operations 600, the particular application 244 corresponds to a camera application 244A or a banking application 244B.
[0083] According to one implementation, determining the indication of whether the mobile device was stolen also includes determining whether a particular application on the mobile device has been activated within a particular period of time after detecting the spike in acceleration. For example, referring to Figure 2, the processor 200 may determine whetherthe camera application 244A or the banking application 244B has been activated within a particular period of time after detection of the spike 240 in acceleration. Operations 600 may also include determining that the mobile device was stolen based, at least in part, on a determination that the particular application has been activated within the particular period of time. For example, referring to Figure 2, the processor 200 may determine that the mobile device 130 was stolen 264 based, at least in part, on a determination that the application 244 has been activated within the particular period of time.
[0084] According to one implementation, determining the indication of whether the mobile device was stolen also includes determining whether the mobile device has been disconnected from a particular local area network within a particular period of time after detecting the spike in acceleration. For example, referring to Figure 2, the processor 200 may determine whether the mobile device 130 has been disconnected from a local area network within a particular period of time after detecting the spike 240 in acceleration. Operations 600 may also include determining that the mobile device was stolen based, at least in part, on a determination that the mobile device has been disconnected from the particular local area network within the particular time period. For example, referring to Figure 2, the processor 200 may determine that the mobile device 130 was stolen 264 based, at least in part, on a determination that the mobile device 130 has been disconnected from the local area network within the particular period of time.
[0085] According to one implementation, determining the indication of whether the mobile device was stolen also includes determining whether an auxiliary device has been disconnected from the mobile device within a particular period of time after detecting the spike in acceleration. For example, referring to Figure 2, the processor 200 may determine whether an auxiliary device has been disconnected from the mobile device 130 within a particular period of time after detecting the spike 240 in acceleration. Operations 600 may also include determining that the mobile device was stolen based, at least in part, on a determination that the auxiliary device has been disconnected from the mobile device within the particular period of time. For example, referring to Figure 2, the processor 200 may determine that the mobile device 130 was stolen 264 based, at least in part, on a determination that the auxiliary device has been disconnected from the mobile device 130 within the particular period of time.
[0086] According to one implementation, determining the indication of whether the mobile device was stolen includes determining, after detecting the spike in acceleration, whether a face recognition application recognizes a user attempting to use the mobile device. Forexample, referring to Figure 2, the processor 200 may determine, after the spike 240 in acceleration, whether a face recognition application recognizes a user attempting to use the mobile device 130. Operations 600 may also include determining that the mobile device was stolen based, at least in part, on a determination that the face recognition application fails to recognize the user attempting to use the mobile device. For example, referring to Figure 2, the processor 200 may determine that the mobile device 130 was stolen 264 based, at least in part, on a determination that the face recognition application fails to recognize the user attempting to use the mobile device 130.
[0087] According to one implementation, operations 600 includes determining, by the processor, whether a screen associated with the mobile device is activated and unlocked. The theft detection operation is performed in response to a determination that the screen is activated and unlocked. For example, referring to Figure 2, the processor 200 may determine whether the display screen 206 is activated and unlocked. The theft detection operation may be performed in response to a determination that the display screen 206 is activated and unlocked.
[0088] According to one implementation, operations 600 includes determining, by the processor, whether the mobile device is in a trusted location. The theft detection operation is performed in response to a determination that the mobile device is not in a trusted location. Determining whether the mobile device is in the trusted location may include determining whether the mobile device is connected to a particular local area network. The particular local area network corresponds to a local area network previously connected to by the mobile device. Operations 600 may include determining that the mobile device is not within the trusted location in response to a determination that the mobile device is not connected to the particular local area network.
[0089] Operations 600 of Figure 6 may improve the accuracy of mobile device theft detection by reducing the likelihood of false positives using a multistep operation. In particular, operations 600 utilizes accelerometer data to detect the spike 240 in acceleration of the mobile device 130 that is representative of someone “snatching” the mobile device 130. Only in response to detection of the spike 240 does operations 600 utilize activity recognition data 242 to compare first detected user activity before the spike 240 in acceleration to second detected user activity after the spike 240 in acceleration. Thus, by requiring detection of the spike 240 before comparing pre-spike activity recognition to post-spike activity recognition, false positives strictly based on activity recognition may be reduced.
[0090] The present disclosure is not to be limited in terms of the particular examples described in this application, which are intended as illustrations of various aspects. Many modifications and variations may be made without departing from its scope, as will be apparent to those skilled in the art. Functionally equivalent methods and apparatuses within the scope of the disclosure, in addition to those described herein, will be apparent to those skilled in the art from the foregoing descriptions. Such modifications and variations are intended to fall within the scope of the appended claims.
[0091] The above detailed description describes various features and operations of the disclosed systems, devices, and methods with reference to the accompanying figures. In the figures, similar symbols typically identify similar components, unless context dictates otherwise. The examples described herein and in the figures are not meant to be limiting. Other examples may be utilized, and other changes may be made, without departing from the scope of the subject matter presented herein. It will be readily understood that the aspects of the present disclosure, as generally described herein, and illustrated in the figures, may be arranged, substituted, combined, separated, and designed in a wide variety of different configurations.
[0092] With respect to any or all of the message flow diagrams, scenarios, and flow charts in the figures and as discussed herein, each step, block, and / or communication may represent a processing of information and / or a transmission of information in accordance with example embodiments. Alternative embodiments are included within the scope of these example embodiments. In these alternative embodiments, for example, operations described as steps, blocks, transmissions, communications, requests, responses, and / or messages may be executed out of order from that shown or discussed, including substantially concurrently or in reverse order, depending on the functionality involved. Further, more or fewer blocks and / or operations may be used with any of the message flow diagrams, scenarios, and flow charts discussed herein, and these message flow diagrams, scenarios, and flow charts may be combined with one another, in part or in whole.
[0093] A step or block that represents a processing of information may correspond to circuitry that may be configured to perform the specific logical functions of a herein- described method or technique. Alternatively or additionally, a block that represents a processing of information may correspond to a module, a segment, or a portion of program code (including related data). The program code may include one or more instructions executable by a processor for implementing specific logical operations or actions in the method or technique. The program code and / or related data may be stored on any type ofcomputer readable medium such as a storage device including random access memory (RAM), a disk drive, a solid state drive, or another storage medium.
[0094] The computer readable medium may also include non-transitory computer readable media such as computer readable media that store data for short periods of time like register memory, processor cache, and RAM. The computer readable media may also include non- transitory computer readable media that store program code and / or data for longer periods of time. Thus, the computer readable media may include secondary or persistent long term storage, like read only memory (ROM), optical or magnetic disks, solid state drives, compact-disc read only memory (CD-ROM), for example. The computer readable media may also be any other volatile or non-volatile storage systems. A computer readable medium may be considered a computer readable storage medium, for example, or a tangible storage device.
[0095] Moreover, a step or block that represents one or more information transmissions may correspond to information transmissions between software and / or hardware modules in the same physical device. However, other information transmissions may be between software modules and / or hardware modules in different physical devices.
[0096] The particular arrangements shown in the figures should not be viewed as limiting. It should be understood that other examples may include more or less of each element shown in a given figure. Further, some of the illustrated elements may be combined or omitted. Yet further, an example may include elements that are not illustrated in the figures.
[0097] Examples.
[0098] Example 1. A method for securing a mobile device, the method comprising: performing, by a processor of the mobile device, a theft detection operation comprising: detecting a spike in acceleration associated with the mobile device, wherein detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device; and in response to detecting the spike in acceleration, determining an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device; and implementing, by the processor, one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0099] Example 2. The method of example 1, wherein detecting the spike in acceleration comprises detecting an instantaneous increase in acceleration that exceeds a threshold value.
[0100] Example 3. The method of any of example 1 or 2, wherein the acceleration data and the activity recognition data are provided as inputs to a machine -learning model hosted by theprocessor, and wherein the determination of whether the mobile device was stolen is based on an output of the machine-learning model.
[0101] Examples 4. The method of any of examples 1-3, wherein determining the indication of whether the mobile device was stolen comprises: comparing first activity recognition data generated prior to detecting the spike acceleration to second activity recognition data generated after detecting the spike acceleration, wherein the indication of whether the mobile device was stolen is based on comparing the first activity recognition data to the second activity recognition data.
[0102] Example 5. The method of any of examples 1-4, wherein the activity recognition data is usable to classify user activity.
[0103] Example 6. The method of any of examples 1-5, wherein determining the indication of whether the mobile device was stolen is based on at least one other factor.
[0104] Example 7. The method of example 6, wherein the at least one other factor includes at least one of an indication of whether a particular application on the mobile device is activated after detecting the spike in acceleration, an indication of whether the mobile device is disconnected from a local area network after detecting the spike in acceleration, an indication of whether an auxiliary device has been disconnected from the mobile device after detecting the spike in acceleration, or a location of the mobile device.
[0105] Example 8. The method of example 7, wherein the particular application corresponds to a camera application or a banking application.
[0106] Example 9. The method of example 6, wherein determining the indication of whether the mobile device was stolen further comprises: determining whether a particular application on the mobile device has been activated within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the particular application has been activated within the particular period of time.
[0107] Example 10. The method of example 6, wherein determining the indication of whether the mobile device was stolen further comprises: determining whether the mobile device has been disconnected from a particular local area network within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the mobile device has been disconnected from the particular local area network within the particular period of time.
[0108] Example 11. The method of example 6, wherein determining the indication of whether the mobile device was stolen comprises: determining whether an auxiliary device hasbeen disconnected from the mobile device within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the auxiliary device has been disconnected from the mobile device within the particular period of time.
[0109] Example 12. The method of example 6, wherein determining the indication of whether the mobile device was stolen comprises: determining, after detecting the spike in acceleration, whether a face recognition application recognizes a user attempting to use the mobile device; and determining that the mobile device was stolen based, at least in part, on a determination that the face recognition application fails to recognize the user attempting to use the mobile device.
[0110] Example 13. The method of any of examples 1-12, further comprising determining, by the processor, whether a screen associated with the mobile device is activated and unlocked, wherein the theft detection operation is performed in response to a determination that the screen is activated and unlocked.
[0111] Example 14. The method of any of examples 1-13, further comprising determining, by the processor, whether the mobile device is in a trusted location, wherein the theft detection operation is performed in response to a determination that the mobile device is not in a trusted location.
[0112] Example 15. The method of example 14, wherein determining whether the mobile device is in the trusted location comprises: determining whether the mobile device is connected to a particular local area network, wherein the particular local area network corresponds to a local area network previously connected to by the mobile device; and determining that the mobile device is not within the trusted location in response to a determination that the mobile device is not connected to the particular local area network.
[0113] Example 16. The method of any of examples 1-15, wherein the one or more security measures comprises locking the mobile device.
[0114] Example 17. The method of any of examples 1-16, wherein the one or more security measures comprises sending an email that includes links that, when selected, cause the processor to perform particular actions, wherein the particular actions include locking the mobile device, remotely erasing data stored by the mobile device, or both.
[0115] Example 18. The method of any of examples 1-17, wherein the one or more security measures comprises communicating an International Mobile Equipment Identity (IMEI) number of the mobile device to a ban list.
[0116] Example 19. The method of any of examples 1-18, wherein the one or more security measures comprises initiating a factory reset of the mobile device.
[0117] Example 20. The method of any of examples 1-19, wherein the one or more security measures comprises increasing an amount of time between generating a prompt to enter a passcode to access the mobile device after an unsuccessful attempt.
[0118] Example 21. The method of any of examples 1-20, wherein the one or more security measures comprises preventing deletion of data stored on the mobile device unless an account password is entered.
[0119] Example 22. A mobile device comprising: a memory; and a processor coupled to the memory, the processor configured to: detect a spike in acceleration associated with the mobile device, wherein detecting the spike acceleration is based on acceleration data generated by an accelerometer of the mobile device; and in response to detecting the spike in acceleration, determine an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device; and implement one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0120] Example 23. The mobile device of example 22, wherein the acceleration data and the activity recognition data are provided as inputs to a machine-learning model hosted by the processor, and wherein the determination of whether the mobile device was stolen is based on an output of the machine-learning model.
[0121] Example 24. The mobile device of any of examples 22 and 23, wherein, to determine the indication of whether the mobile device was stolen, the processor is configured to: compare first activity recognition data generated prior to detecting the spike in acceleration to second activity recognition data generated after detecting the spike in acceleration, wherein the indication of whether the mobile device was stolen is based on comparing the first activity recognition data to the second activity recognition data.
[0122] Example 25. A non-transitory computer-readable medium comprising instructions that, when executed by a processor of a mobile device, cause the processor to perform operations comprising: performing, by a processor of the mobile device, a theft detection operation comprising: detecting a spike in acceleration associated with the mobile device, wherein detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device; and in response to detecting the spike in acceleration, determining an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device; and implementing, bythe processor, one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
[0123] Example 26. A computing system comprising means for performing any combination of the methods of examples 1-21.
[0124] Example 27. A non-transitory computer-readable storage medium encoded with instructions that, when executed by one or more processors of a computing device, cause the one or more processors to perform any combination of the methods of examples 1-21.
[0125] Example 28. A computer program comprising instructions that, when executed, cause one or more processors to perform any of the methods of examples 1-21.
[0126] While various aspects and examples have been disclosed herein, other aspects and examples will be apparent to those skilled in the art. The various aspects and examples disclosed herein are for the purpose of illustration and are not intended to be limiting, with the true scope being indicated by the following claims.
Claims
WHAT IS CLAIMED IS:
1. A method for securing a mobile device, the method comprising: performing, by a processor of the mobile device, a theft detection operation comprising: detecting a spike in acceleration associated with the mobile device, wherein detecting the spike in acceleration is based on acceleration data generated by an accelerometer of the mobile device; and in response to detecting the spike in acceleration, determining an indication of whether the mobile device was stolen based at least on activity recognition data generated by at least one sensor of the mobile device; and implementing, by the processor, one or more security measures at the mobile device in response to a determination that the mobile device was stolen.
2. The method of claim 1, wherein detecting the spike in acceleration comprises detecting an instantaneous increase in acceleration that exceeds a threshold value.
3. The method of claim 1, further comprising: providing the acceleration data and the activity recognition data as inputs to a machine -learning model hosted by the processor, wherein determining whether the mobile device was stolen is based on an output of the machine-learning model.
4. The method of claim 1, wherein determining the indication of whether the mobile device was stolen comprises: comparing first activity recognition data generated prior to detecting the spike in acceleration to second activity recognition data generated after detecting the spike in acceleration, wherein the indication of whether the mobile device was stolen is based on comparing the first activity recognition data to the second activity recognition data.
5. The method of claim 1, wherein determining the indication of whether the mobile device was stolen further comprises: determining whether a particular application on the mobile device has been activated within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the particular application has been activated within the particular period of time.
6. The method of claim 1, wherein determining the indication of whether the mobile device was stolen further comprises: determining whether the mobile device has been disconnected from a particular local area network within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the mobile device has been disconnected from the particular local area network within the particular period of time.
7. The method of claim 1, wherein determining the indication of whether the mobile device was stolen comprises: determining whether an auxiliary device has been disconnected from the mobile device within a particular period of time after detecting the spike in acceleration; and determining that the mobile device was stolen based, at least in part, on a determination that the auxiliary device has been disconnected from the mobile device within the particular period of time.
8. The method of claim 1, wherein determining the indication of whether the mobile device was stolen comprises: determining, after detecting the spike in acceleration, whether a face recognition application recognizes a user attempting to use the mobile device; and determining that the mobile device was stolen based, at least in part, on a determination that the face recognition application fails to recognize the user attempting to use the mobile device.
9. The method of claim 1, further comprising: determining, by the processor, whether a screen associated with the mobile device is activated and unlocked, wherein the theft detection operation is performed in response to a determination that the screen is activated and unlocked.
10. The method of claim 1, further comprising: determining whether the mobile device is connected to a particular local area network, wherein the particular local area network corresponds to a local area network previously connected to by the mobile device; and responsive to determining that the mobile device is not connected to the particular local area network, determining that the mobile device is not within a trusted location, wherein the theft detection operation is performed in response to determining that the mobile device is not in a trusted location.
11. The method of claim 1, wherein the one or more security measures comprises sending an email that includes links that, when selected, cause the processor to perform particular actions, wherein the particular actions include locking the mobile device, remotely erasing data stored by the mobile device, or both.
12. The method of claim 1, wherein the one or more security measures includes at least one of: locking the mobile device, communicating an International Mobile Equipment Identity (IMEI) number of the mobile device to a ban list, initiating a factory reset of the mobile device, increasing an amount of time between generating a prompt to enter a passcode to access the mobile device after an unsuccessful attempt, and preventing deletion of data stored on the mobile device unless an account password is entered.
13. A computing system comprising means for performing any of the methods of claims 1- 12.
14. A non-transitory computer-readable medium comprising instructions that, when executed by a processor of a mobile device, cause the processor to perform the methods of any of claims 1-12.
15. A computer program product comprising instructions that, when executed, cause one or more processors to perform the methods of any of claims 1-12.
Citation Information
Patent Citations
Terminal anti-theft method and device, computer device and computer readable storage medium
CN107979692A
A method, device and computer-readable storage medium for burglar alarm control
CN112489339B
Automatic Intelligent Local Device Fraud Detection
US20160210450A1
US202463637008P