On-device Vault for Privacy-Preserving Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are uncomfortable with the collection and distribution of personalized data by internet services, leading to generalized user experiences as they block data sharing, which limits the effectiveness of personalized recommendations.

Innovation Solution

A method and system that utilize an on-device vault to store sensitive user data, generating user and candidate vectors based on personal data, and applying a global model to determine interaction propensities without exposing data to external parties, enabling personalized recommendations while preserving user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If services collect and distribute personalized data to build user profiles, then recommendation effectiveness is improved, but user privacy is compromised

Engineering Contradiction:
Improverecommendation effectivenessVSAvoiduser privacy compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an on-device vault as an intermediary component that stores sensitive user data locally and provides controlled access to machine learning models. This vault acts as a mediator between the user's personal data and the recommendation system, enabling personalized recommendations while preventing direct exposure of raw personal data to external services, thus resolving the contradiction between recommendation effectiveness and user privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If users block data collection to preserve privacy, then user privacy is protected, but recommendation personalization deteriorates

Engineering Contradiction:
Improveuser privacy protectionVSAvoidrecommendation personalization
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent extracts sensitive personal data into a separate on-device vault that is isolated from external access. By taking out the personal data from the general data flow and storing it in a dedicated secure location with controlled access, the system enables privacy-protected personalization where users can choose to share only specific data with specific applications, maintaining both privacy protection and recommendation personalization

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If personalized data is shared with external services, then recommendation accuracy is improved, but user control over data is reduced

Engineering Contradiction:
Improverecommendation accuracyVSAvoiduser control over data
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling users to directly control which applications can access their personal data through the on-device vault. Users can grant or revoke access permissions at any time without needing to interact with external services, maintaining both recommendation accuracy through selective data sharing and user control over their personal information

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11907963B2On-device privacy-preservation and personalization
Publication Date: 2024.02.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11907963B2 patent drawing
  • US11907963B2 patent drawing
  • US11907963B2 patent drawing

AI summary

Personalization with on-device privacy preservation is provided by receiving, at a user device, a generalized recommendation from a remote provider backend, which include a plurality of candidate items responsive to a request from an application running on the user device; generating a plurality of candidate vectors corresponding to the plurality of candidate items representing a corresponding candidate item in a binary format across a plurality of metrics associated with the plurality of candidate items; generating a user vector based on personal data stored on the user device, the user vector representing a user in a binary format across one or more metrics associated with the personal data; determining interaction propensities based on the user vector and the plurality of candidate vectors according to a global model run on the user device; and displaying, on the user device, the plurality of candidate items according to the interaction propensities.