Society & Economicspreprint2026-08-01

SIPPA: A Service-Initiated Privacy-Preserving Personalization Architecture for User-Owned On-Device AI Agents

Open access0 citations

Abstract

Personalization is commonly implemented as a platform-centric capability in which service providers collect and retain user data, then use it to optimize personalized outputs. Although this model improves recommendation quality, it couples personalization utility with the service-side concentration of user information. Studies from 2003-2006 recognized this tension and explored user-side data, but practical intelligence, interoperable personalization request contracts, and joint utility/privacy evaluation were unavailable. This paper revisits that unfinished agenda and proposes SIPPA, a Service-Initiated Privacy-Preserving Personalization Architecture for user-owned on-device AI agents. SIPPA defines a versioned request/policy/response contract in which an authenticated service principal requests a task-facing personalization artifact; a user-side agent applies preapproved local policy to three local-use eligibility classes and returns an `allow`, `transform`, `degrade`, or `refuse` result. Direct transfer of local profile elements is prohibited in v1, and a deterministic output guard constrains candidate identifiers, score precision, payload size, and explanations. The contribution is deliberately narrower than general privacy-policy or authorization standards: SIPPA profiles those foundations for personalization-specific artifacts and makes task-preserving transformation and utility-reducing degradation explicit. The paper supplies a machine-readable schema, traceable examples, and a falsifiable evaluation plan covering utility, privacy, decision correctness, and latency.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-01

Authors: Kengo Yamazaki