Skip to content
#federated learning Review Open access

On-Device Privacy and Zero-Knowledge Storage in Mobile Applications: A Review with Attention to Cross-Platform React Native Development

Sep 2026 · Journal of Engineering Research and Reports · 0 citations
Advanced Malware Detection Techniques

TL;DR

This review synthesizes the research literature relevant to building such applications, with specific attention to the cross-platform reality in which much of the mobile ecosystem, prominently React Native applications, is actually built, and identifies directions for research and practice.

Abstract

Mobile applications hold the most intimate data that most people generate—messages, health signals, finances, locations, and journals—and the architectural question of where such data live in plaintext has become the defining privacy decision of app design. On-device privacy names one pole of the answer: data is processed, stored, and protected where it originates, and services are designed so that servers hold ciphertext they cannot read, an architecture popularly called zero-knowledge storage. This review synthesizes the research literature relevant to building such applications, with specific attention to the cross-platform reality in which much of the mobile ecosystem, prominently React Native applications, is actually built. It first fixes terminology, distinguishing the cryptographic meaning of zero knowledge from the architectural marketing usage, and organizes the threat models—curious servers, device compromise, network adversaries, and legal compulsion—against which designs are meaningfully compared. It then reviews the platform security foundations, hardware-backed keystores, trusted execution, biometric gating, and their documented limits; encrypted local storage, from key derivation through database encryption to searchable and oblivious techniques and their leakage trade-offs; end-to-end encrypted synchronization and the protocol lineage that made forward secrecy deployable; and on-device privacy-preserving computation, including local inference, differential privacy, and federated learning, with the attack literature that bounds their guarantees. The cross-platform layer receives dedicated treatment: the JavaScript runtime, bridge architecture, dependency supply chain, and the misuse findings of the mobile security measurement literature as they bear on React Native designs. The review closes with the recurring gaps—usable key recovery, metadata protection, and verification of zero-knowledge claims—and identifies directions for research and practice.

Read PDF

Similar papers

#federated learning Conference Open access Sep 2026

Federated Learning as a Privacy-Enhancing Framework: Risks, Protection Mechanisms, and Applications

This paper argues that federated learning should be evaluated as a privacy-enhancing framework rather than as a complete privacy guarantee, and proposes a comparat ive framework that asks what federated learning protects, what it still exposes, and which auxiliary mechanisms are needed in different application settings...

Zhi-Yue Zhang · 0 citations
#artificial intelligence Preprint Aug 2026

Auditing and Mitigating Privacy Leakage in Cloud-Edge Collaborative Decoding

CoVeil is proposed, a defense mechanism which dynamically optimizes transmitted signals to suppress leakage during decoding time while preserving the collaborative quality, and consistently improves the privacy-utility trade-off over existing baselines by reducing data leakage.

Ke-Jia Zhang, Tianyuan Zou, Zi-Xuan Gu et al. · 0 citations
Review Open access Aug 2026

A Survey on Privacy-Preserving Techniques for Cloud Data Processing Using Homomorphic Encryption and Federated Learning

This paper presents a structured review of privacy-preserving data processing techniques for cloud environments built on HE and FL, individually and in hybrid combination, and identifies promising directions for future research.

Shivendra Shukla, C. S. Gautam, Divyansh Tiwari · 0 citations

Doppio : Communication-Efficient and Secure Multi-Party Shuffle Differential Privacy

The augmented multi-party shuffle DP (AMP-SDP) model is proposed, which re-architects the data pipeline with a lightweight, versatile secret-shared intermediary layer that decentralizes trust while minimizing online communication costs and provides structural security hardening against both shuffler compromise and user-sid...

Wentao Dong, Yang Cao, Cong Wang et al. · 0 citations
Review Open access Aug 2026

Security and privacy challenges of RAG systems

This study presents a detailed, actionable approach to constructing secure, privacy-focused RAG systems and culminates in the Integrated Privacy-Preserving RAG Framework (IPRAG), a five-tier architecture supported by a three-phase deployment protocol.

Firoz Mohammed Ozman · 0 citations

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.