Privacy-Preserving Custom Embeddings for On-Device Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for delivering digital content to user devices risk compromising user privacy by transmitting sensitive data across networks, particularly with the deprecation of third-party cookies, and impose significant computational burdens on client devices.

Innovation Solution

A secure distribution system generates custom user embeddings on client devices, using isolated execution environments and transformation functions to select relevant digital components without exposing user data, reducing the need for sensitive information transmission and minimizing computational load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user data is transmitted across networks for content delivery, then personalized content delivery is improved, but user privacy is compromised

Engineering Contradiction:
Improvepersonalized content deliveryVSAvoiduser privacy compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential embedding weights from user data, transmitting minimal information across networks while retaining the ability to deliver personalized content. This separates the critical personalized information from the sensitive user data, achieving content personalization without compromising privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of sending user data to servers for processing, the patent inverts the approach by generating embeddings locally on client devices and sending only the resulting weights to the secure distribution system. This reverses the traditional data flow direction, keeping sensitive data local while achieving centralized content distribution.

Inventive Principle:
Principle #13The other way round (Inversion)

2Object-affected harmful factors

If custom user embeddings are generated on client devices, then user privacy is enhanced, but computational burden on client devices increases

Engineering Contradiction:
Improveuser privacyVSAvoidcomputational burden
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by generating only the necessary embedding weights locally rather than processing complete user data. This partial computation approach maintains privacy benefits while significantly reducing the computational burden compared to full data processing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary computation of embedding weights on client devices before data leaves the device. This preliminary action prepares the data in a privacy-preserving format, reducing the need for complex computations later and minimizing the overall computational burden.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If sensitive user information is transmitted across networks, then content personalization is improved, but data security risks increase

Engineering Contradiction:
Improvecontent personalizationVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts only the essential embedding weights from sensitive user information, transmitting minimal data across networks. This extraction approach maintains content personalization capability while dramatically reducing data security risks by leaving the majority of sensitive information on local devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates simplified copies of user data in the form of embedding weights that capture essential personalization information without containing sensitive details. These copies can be transmitted safely across networks while the original sensitive data remains secured on client devices.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12411982B2Privacy preserving custom embeddings
Publication Date: 2025.09.09 GOOGLE LLC
  • US12411982B2 patent drawing
  • US12411982B2 patent drawing
  • US12411982B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for selecting and distributing digital components to client devices in ways that protect user privacy and confidential data of content platforms and/or digital component providers are described. In one aspect, a method includes receiving, by a secure distribution system and from a client device of a user, a digital component request that includes, for each of multiple content platforms that distribute digital components to users, a corresponding user embedding comprising weights indicative of the relevance of multiple features to the user. The secure distribution system provides each user embedding as input to a respective isolated execution environment for the content platform corresponding to the user embedding, wherein the secure distribution system hosts each isolated execution environment. Digital component selection data generated based on the user embedding is received from each isolated execution environment.