AI security threat model:
A comprehensive approach
From threat model to mitigation plan: How to secure AI inside mobile apps
AI is now inside the app—not just behind it. As organizations embed AI directly into mobile experiences, the number and complexity of threats have exploded.
This new paper by Dr. Anton Tkachenko introduces a complete AI security framework for identifying, categorizing, and prioritizing risks across device, model, application, and agent levels. It also shows how Promon’s protection layers map to these threats to defend against real-world AI attacks.
What you'll learn
- The 49 key AI threats targeting on-device and embedded models
- How to classify and prioritize AI risks across your app ecosystem
- Practical defense strategies based on OWASP, MITRE, and NIST frameworks
- How Promon’s Shield, Data Protect, and Code Protect mitigate the most critical AI threats
Want to request an AI security assessment?
Meet with a Promon expert to understand and strengthen your on-device AI security posture.
As AI moves onto the device, new attack surfaces emerge, from model theft to runtime tampering. Our experts help you pinpoint risks and strengthen protection where it matters most.
Stay updated on the latest news on
application security
-
Security research
App Threat Report Q3 2026: GPU debugger abuse in Android apps
GPU debugging tools were built to help developers inspect rendering. But the same mechanisms can become an injection path when turned against a shipping app. Our research shows how Vulkan layers can be abused on Android, with mobile games as a particularly attractive target.23 Sep 2026
Benjamin Adolphi
-
Mobile app security
What ‘proven’ actually means in application attestation
Application attestation should prove more than that the right code was delivered. It must show that the protected runtime is still intact and operating without detected interference when trust is granted.2 Sep 2026
Shaun Cooney
-
Compliance
EUDI Wallet security: What the Architecture and Reference Framework says about runtime trust
Certification establishes an important security baseline. Wallet Providers must still verify genuine Wallet Instances, monitor operational security posture, and respond when trust changes. Here is what the current Architecture and Reference Framework (ARF) says, what it leaves open, and what mobile wallet teams should examine next.27 Aug 2026
Volker Gerstenberger
-
Mobile app security
Build it. Prove it. Then release the data: Runtime trust for the browser
Your applications run on devices and browsers you don’t control. Attempting to make those environments trustworthy isn't the answer. Instead, create a protected runtime inside them, verify its state, and only then allow sensitive data to enter.24 Aug 2026
Shaun Cooney
-
Compliance
Fighting mobile fraud in the UAE: What bank leaders need to know about CBUAE Notice 2176
CBUAE Notice 2176 gives UAE financial institutions an urgent set of actions against Android malware. It also makes the mobile app, its runtime environment, and the evidence it produces part of the fraud response.18 Aug 2026
Paul Fox
-
Development
Promon completes acquisition of Codesealer, extending protection to web applications and the APIs behind them
Promon Shield for Web™ brings Promon’s protection model to web applications running in the browser. Server-side attestation gives organizations proof they can use when deciding whether selected API endpoints should release data.12 Aug 2026
Promon
-
Mobile app security
DEX encryption done right: Raising the bar for Android attackers
DEX encryption raises the cost of static analysis and reverse engineering. The hard part is protecting the decryption key, preserving app launch performance, and accounting for what happens after the code is decrypted.5 Aug 2026
Caner Kaya
-
Security research
Application Shielding is placed in the Slope of Enlightenment in the 2026 Gartner® Hype Cycle™ for Secure Software Engineering
Application Shielding continues to move into mainstream adoption in a maturing mobile-first market.28 Jul 2026
Promon
Blogs
Keep up with the latest developments in iOS and Android security, code obfuscation, compliance, API protection, and more.
View all