Uppsats

How do AI model deployed on cloud and on-premises platforms differ in terms of data privacy, security and risk?

Master-uppsats

Uppsala universitet/Institutionen för informatik och media

Publicerad: 2026

Språk: Engelska

Sammanfattning

The growing adoption of artificial intelligence has made the choice between cloud-based andon-premises AI deployment a critical governance decision. Despite its significance, empiricalevidence on how these architectures differ in terms of data privacy, security, resilience, andreliability remains limited. This study addresses that gap through a controlled experimentalinvestigation using the NIST AI Risk Management Framework (AI RMF) (Tabassi 2023) as theprimary evaluative framework. Two deployment environments were subjected to sevenstructured experiments: an on-premises configuration comprising AnythingLLM, Ollama, andMicrosoft Phi-4 Mini Instruct on a Windows 11 Pro laptop, and a cloud configuration using thesame model deployed via Microsoft Azure AI Foundry. Using an identical model in bothenvironments ensures all observed differences are attributable solely to deploymentarchitecture. The findings reveal fundamentally different risk profiles across all four NIST AIRMF dimensions. In the privacy dimension, the on-premises deployment transmitted 0% ofpackets externally, while the cloud transmitted 84.9% to Azure servers over TLS andadditionally exposed document content during the embedding process. Both deploymentsretained PII in local storage after session termination. In the security dimension, bothdeployments resisted all adversarial prompt injection attacks at the model level; the clouddeployment additionally provided infrastructure-level protection through Azure Content Safety.In the resilience dimension, the on-premises deployment achieved 100% task completion underboth full offline and mid-inference disruption conditions, while the cloud deployment achieved0% with no automatic recovery. In the reliability dimension, the on-premises deploymentachieved 40% full constraint compliance across five independent runs, outperforming the clouddeployment’s 20% and avoiding the multi-constraint failure observed in Run 5. This studycontributes the first empirical comparison of cloud and on-premises AI risk across all four NISTAI RMF dimensions, the first empirical characterisation of the AnythingLLM and Ollamastack’s security and privacy properties, and a reusable template for NIST AI RMF-aligneddeployment risk assessment.

Information

Lärosäte / institution
Uppsala universitet/Institutionen för informatik och media
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.