{"id":26225,"date":"2026-09-21T15:43:59","date_gmt":"2026-09-21T23:43:59","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai\/"},"modified":"2026-09-21T15:57:16","modified_gmt":"2026-09-21T23:57:16","slug":"crowdstrike-accelerates-real-time-data-classification-with-on-device-ai","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai\/","title":{"rendered":"CrowdStrike Accelerates Real-Time Data Classification with On-Device AI"},"content":{"rendered":"<div class=\"container-wp container-wp--main-content-blog aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-container-wp\" data-cmp-is=\"responsive-grid-container\" data-padding-left=\"16\" data-padding-right=\"16\" id=\"container-c9ab7dd884\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12\">\n<div class=\"headline aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-wp-headline\" id=\"headline-en-us\">\n<h1>CrowdStrike Accelerates Real-Time Data Classification with On-Device AI<\/h1>\n<div class=\"publish_info\">\n<p>September 16, 2026<\/p>\n<p><span>\u2022<\/span><br \/>\n<a href=\"\/en-us\/blog\/author.lior-ribak\/\" rel=\"author\" title=\"Posts by Lior Ribak\"><br \/>\n                Lior Ribak<\/a><br \/>\n<span>\u2022<\/span><br \/>\n<a href=\"\/en-us\/blog\/category.data-security\/\" title=\"Data Security\">Data Security<\/a>\n<\/p>\n<\/div>\n<div class=\"post_image\">\n<img alt=\"\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" decoding=\"async\" fetchpriority=\"high\" height=\"698\" src=\"https:\/\/www.crowdstrike.com\/content\/dam\/crowdstrike\/marketing\/en-us\/images\/blog\/main-images\/data-protection\/Blog-On-Device-AI-Main.jpg\" width=\"1060\"\/>\n<\/div>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"container-wp aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-container-wp\" data-cmp-is=\"simple-container\" id=\"container-4ebb4b219d\">\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-b1830bb152\">\n<span><\/p>\n<p>Modern data security depends on understanding sensitive data as it is created, accessed, and moved in real time directly on the endpoint.<\/p>\n<p>In addition to identifying predefined patterns such as credit card numbers or Social Security numbers, organizations must protect unstructured information including documents, chat logs, support tickets, AI prompts, medical records, and free-text fields. When protecting this data, understanding the meaning and context of the content is just as important as recognizing patterns.<\/p>\n<p>Consider the below message:<\/p>\n<blockquote>\n<p>\u201cHey, I set up the environment for you \u2013 the login is j.harrison and the passphrase we agreed on is Sunrise@2026\u201d<\/p>\n<\/blockquote>\n<p>There is no structured pattern to match; no username field, password label, or predefined format. A rule-based system would need to anticipate every possible way a person might share credentials in natural language, which would be impossible. Yet the meaning of this message is unambiguous: Someone is sharing account credentials in plain conversation.<\/p>\n<p>Language models understand the meaning and context of content, enabling accurate classification across a broader range of sensitive data. However, delivering accurate AI-powered classification locally introduces a difficult challenge: balancing model efficacy and computational feasibility.<\/p>\n<p>To address this challenge, CrowdStrike worked closely with Intel to introduce a new capability in CrowdStrike Falcon\u00ae Data Security that classifies sensitive data using language models that run on-device using dedicated hardware for AI. This is the first step in a broader strategy to extend our existing rule-based engines with AI-based classifications across a range of AI acceleration hardware, starting with Intel\u2019s NPU.<\/p>\n<h2>The Challenge: Powerful AI Running on the Device<\/h2>\n<p>The most capable language models contain billions of parameters and demand massive, GPU-backed cloud infrastructure to run. Cloud-based inference wasn\u2019t an option for endpoint security: Cloud latency introduces delays, and sending sensitive customer data off the device creates privacy considerations that Falcon Data Security strives to avoid.<\/p>\n<p>The most secure way to run these language models directly is on the device. However, running them on a traditional laptop CPU alone wasn\u2019t fast enough for real-time protection. Even the smallest relevant language model took too long to process large inputs, exceeding our strict real-time latency requirements for AI-based classification.<\/p>\n<p>Solving this challenge required rethinking the hardware story. Rather than accepting the tradeoffs of cloud inference or CPU-based processing, CrowdStrike saw an opportunity to get ahead of an emerging shift in enterprise hardware: the rise of dedicated, on-device AI acceleration. Our goal was to future-proof it for data security.<\/p>\n<h2>Using Dedicated AI Hardware<\/h2>\n<p>Modern processors offer dedicated hardware built for AI workloads: the integrated GPU and the <a href=\"https:\/\/intel.github.io\/intel-npu-acceleration-library\/npu.html\" rel=\"noopener noreferrer\" target=\"_blank\">neural processing unit (NPU)<\/a>, a dedicated AI accelerator optimized for AI inference.<\/p>\n<p>Recognizing the potential of dedicated AI acceleration, CrowdStrike worked closely with Intel to release first-to-market support for AI-enhanced data protection on Intel\u00ae Core\u2122 Ultra-powered AI PCs. CrowdStrike developed OpenVINO-supported, NPU-optimized models to get the best performance on Intel hardware. Through joint engineering and early access to Intel\u2019s AI PC architecture, we worked together to optimize inference on the NPU and validate that real-world enterprise security that workloads could execute with the latency, efficiency, and consistency required for always-on protection.\n<\/p>\n<p>This work builds on CrowdStrike and Intel\u2019s broader focus on securing the next generation of AI PCs. We combined Falcon Data Security\u2019s on-device AI-powered classification with Intel\u2019s AI acceleration to help organizations protect sensitive data without sacrificing performance or privacy.\u00a0<\/p>\n<p>To understand the value of AI-accelerated hardware, we benchmarked inference latency on common documents across all three compute options on Intel Core Ultra 7 (Series 2) hardware:<\/p>\n<\/p>\n<p><\/span>\n<\/div>\n<\/div>\n<div class=\"image\">\n<div class=\"cmp-image\" data-asset-id=\"2bdf693a-8f05-4762-a4eb-0e4e988eeebb\" data-cmp-hook-image=\"imageV3\" data-cmp-is=\"image\" data-target-location=\"false\" data-title=\"*differs according to input size&lt;br&gt;Figure 1. Average inference latency measured on the NPU, GPU, and CPU\" id=\"image-en-us-differs-according-to-inp\" itemscope=\"\" itemtype=\"http:\/\/schema.org\/ImageObject\">\n<img alt=\"Figure 1. Average inference latency measured on the NPU, GPU, and CPU\" class=\"cmp-image__image\" decoding=\"async\" itemprop=\"contentUrl\" loading=\"lazy\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-On-Device-AI-1?wid=1070&amp;hei=708&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/><br \/>\n<svg class=\"cmp-image__play-icon__image-alt\">\n<use href=\"#play-alt\" xlink:href=\"#play-alt\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<span class=\"cmp-image__title\" itemprop=\"caption\">*differs according to input size<br \/>Figure 1. Average inference latency measured on the NPU, GPU, and CPU<\/span>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-77f414fe8c\">\n<span><\/p>\n<p>The improvement was dramatic. Dedicated AI hardware made this additional on-device AI-based classification feature possible.<\/p>\n<h2>Why the NPU Over the GPU<\/h2>\n<p>While benchmarks show the integrated GPU delivers the fastest raw inference speed, raw performance wasn\u2019t our only goal. Because Falcon Data Security runs continuously in the background, two other factors were equally important:<\/p>\n<ul>\n<li>The NPU is designed for low power consumption. Running intensive inference on a GPU while a laptop is unplugged can rapidly drain the battery.<\/li>\n<li>The NPU is built for sustained AI workloads. The GPU can be heavily utilized for graphics rendering, making it an unreliable and potentially disruptive resource.<\/li>\n<\/ul>\n<p>The NPU provides consistent performance while minimizing power consumption and avoiding competition with graphics workloads. It helps ensure security runs seamlessly in the background while users maintain productivity across multiple applications and workflows.\u00a0<\/p>\n<h2>Deploying AI to the Endpoint<\/h2>\n<p>Falcon Data Security language models are built and trained in Python using PyTorch, the industry standard for research and experimentation. However, the CrowdStrike Falcon\u00ae sensor doesn\u2019t carry a Python runtime, and bundling one is impractical given the size and resource constraints of endpoint deployment.<\/p>\n<p>To solve this problem, we integrated with <a href=\"https:\/\/onnxruntime.ai\/\" rel=\"noopener noreferrer\" target=\"_blank\">ONNX Runtime<\/a>, a widely used open-source framework for fast, cross-platform inference that runs directly on the endpoint without any Python dependency.<\/p>\n<p>ONNX Runtime\u2019s Execution Provider architecture also means customers aren\u2019t locked into a single hardware story. This pluggable layer maps the same model to different hardware backends. As enterprise hardware evolves and new AI accelerators emerge, the provider can be swapped without retraining the model, changing the pipeline, or creating gaps in coverage.<\/p>\n<p>We integrated the OpenVINO Execution Provider to interface directly with Intel\u2019s NPU.<\/p>\n<\/p>\n<p><\/span>\n<\/div>\n<\/div>\n<div class=\"image\">\n<div class=\"cmp-image\" data-asset-id=\"8e1947a1-b58b-4911-9cf5-f19157066c44\" data-cmp-hook-image=\"imageV3\" data-cmp-is=\"image\" data-target-location=\"false\" data-title=\"Figure 2. ONNX Runtime with OpenVINO Execution Provider\" id=\"image-en-us-figure-2--onnx-runtime-wi\" itemscope=\"\" itemtype=\"http:\/\/schema.org\/ImageObject\">\n<img alt=\"Figure 2. ONNX Runtime with OpenVINO Execution Provider\" class=\"cmp-image__image\" decoding=\"async\" itemprop=\"contentUrl\" loading=\"lazy\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-On-Device-AI-2?wid=1070&amp;hei=708&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/><br \/>\n<svg class=\"cmp-image__play-icon__image-alt\">\n<use href=\"#play-alt\" xlink:href=\"#play-alt\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<span class=\"cmp-image__title\" itemprop=\"caption\">Figure 2. ONNX Runtime with OpenVINO Execution Provider<\/span>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-4b6b36e1d5\">\n<span><\/p>\n<p>The model itself travels as a single ONNX artifact, which is a portable, self-contained representation of the entire computation graph, operations and weights alike, converted directly from PyTorch. This single model is validated once and runs across supported enterprise environments.\u00a0<\/p>\n<h2>Optimizing Models for the Endpoint<\/h2>\n<p>Beyond hardware selection, deploying capable AI on endpoint devices meant the models themselves needed to be carefully optimized.<\/p>\n<p>We started by training a large, high-efficacy classification model on a carefully curated dataset of both real-world and synthetic data. Then, we trained several candidate student models using teacher-student knowledge distillation of the larger model. Each candidate model varied in key architectural attributes such as the number of hidden layers and activation functions. We then applied FP16 quantization to all candidates to further reduce their footprint.<\/p>\n<\/p>\n<p><\/span>\n<\/div>\n<\/div>\n<div class=\"image\">\n<div class=\"cmp-image\" data-asset-id=\"fd3c420f-cb9b-4d3b-9cef-e8ace320ba0c\" data-cmp-hook-image=\"imageV3\" data-cmp-is=\"image\" data-target-location=\"false\" data-title=\"Figure 3. Model distillation\" id=\"image-en-us-figure-3--model-distillat\" itemscope=\"\" itemtype=\"http:\/\/schema.org\/ImageObject\">\n<img alt=\"Figure 3. Model distillation\" class=\"cmp-image__image\" decoding=\"async\" itemprop=\"contentUrl\" loading=\"lazy\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-On-Device-AI-3?wid=1070&amp;hei=708&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/><br \/>\n<svg class=\"cmp-image__play-icon__image-alt\">\n<use href=\"#play-alt\" xlink:href=\"#play-alt\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<span class=\"cmp-image__title\" itemprop=\"caption\">Figure 3. Model distillation<\/span>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-3c10c928a1\">\n<span><\/p>\n<p>Each model was then benchmarked across two dimensions: runtime performance and classification efficacy. The winning architecture best balanced both, and the results exceeded our expectations.<\/p>\n<p>Our final on-device model uses less than 5% of the teacher\u2019s parameters yet achieves remarkably close classification efficacy. This demonstrated that with the right distillation strategy and architecture search, the gap between cloud-scale AI and edge AI can be made surprisingly small.<\/p>\n<h2>One Model, Multiple Environments<\/h2>\n<p>What we built on top of Intel\u2019s hardware doesn\u2019t stop there. The same foundation extends across every major platform and AI accelerator.<\/p>\n<p>The same model powers Falcon Data Security for Cloud on Linux-based EC2 instances with NVIDIA GPUs. One Execution Provider swap separates an on-device NPU deployment from a cloud-scale GPU deployment.<\/p>\n<p>We are bringing the same experience to macOS through CoreML, Apple\u2019s native AI inference framework, targeting the Apple Neural Engine (ANE) directly. The result is identical: real-time classification, on-device, with no data leaving the machine.<\/p>\n<p>By bringing context-aware AI directly to the endpoint, Falcon Data Security extends protection to a broader range of sensitive data modern organizations create and share, with this capability set to grow as AI acceleration hardware becomes more widely adopted.<\/p>\n<h4>Additional Resources<\/h4>\n<ul>\n<li><i><a href=\"https:\/\/www.crowdstrike.com\/en-us\/platform\/data-security\/\" rel=\"noopener noreferrer\" target=\"_blank\">Learn more about Falcon Data Security<\/a>: See how CrowdStrike secures sensitive data across endpoint, SaaS, GenAI, browser, and cloud environments.<\/i><\/li>\n<li><i><a href=\"https:\/\/www.crowdstrike.com\/en-us\/platform\/data-security\/demo\/\" rel=\"noopener noreferrer\" target=\"_blank\">Schedule a demo<\/a>: Talk with CrowdStrike about securing sensitive data wherever it lives and moves.<\/i><\/li>\n<\/ul>\n<p><\/span>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"sociallinks aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-social-links\" data-target-location=\"false\" id=\"sociallinks-en-us\">\n<a class=\"cmp-social-links__link\" href=\"https:\/\/www.linkedin.com\/shareArticle\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<svg class=\"cmp-social-links__link__icon\">\n<use href=\"#linked-in\" xlink:href=\"#linked-in\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<\/a><br \/>\n<a class=\"cmp-social-links__link\" href=\"https:\/\/twitter.com\/share\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<svg class=\"cmp-social-links__link__icon\">\n<use href=\"#twitter-x-logo\" xlink:href=\"#twitter-x-logo\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<\/a><br \/>\n<!-- Personal Website Section -->\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"separator aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-separator\" data-cmp-is=\"separator\" data-is-vertical=\"false\" data-separator-color=\"#C4C4C4\" data-separator-height=\"1\" data-separator-width=\"1\" data-target-location=\"false\" id=\"separator-separator-134c17cf63\">\n<hr class=\"cmp-separator__horizontal-rule\" data-cmp-hook-separator=\"hr\"\/>\n<\/div>\n<\/div>\n<div class=\"container responsivegrid aem-GridColumn aem-GridColumn--default--12\">\n<div data-attribute-name=\"data-promo-xf\" data-cmp-is=\"xf-container\" data-target-location=\"false\">\n<\/div>\n<\/div>\n<div class=\"relatedcontent aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-wp-related-content\" data-target-location=\"false\" id=\"relatedcontent-en-us\">\n<h4>Related Content<\/h4>\n<div class=\"row recent_articles\">\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/after-executive-order-14409-next-steps-for-securing-ai\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"After Executive Order 14409: Next Steps for Securing AI\" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-ExecOrder?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Securing AI | Jun 17, 2026\n                    <\/div>\n<h6>After Executive Order 14409: Next Steps for Securing AI<\/h6>\n<\/div>\n<p><\/a><br \/>\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/iso-42001-2023-and-new-reality-of-cloud-ai-data-risk\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"ISO 42001:2023 and the New Reality of Cloud AI Data Risk\" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-Data-Protection-Day-2026?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Data Security | Jun 04, 2026\n                    <\/div>\n<h6>ISO 42001:2023 and the New Reality of Cloud AI Data Risk<\/h6>\n<\/div>\n<p><\/a><br \/>\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/how-to-stop-ai-driven-data-loss\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"How to Stop AI-Driven Data Loss\" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-DataLeakage?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Endpoint Security &amp; XDR | Jun 02, 2026\n                    <\/div>\n<h6>How to Stop AI-Driven Data Loss<\/h6>\n<\/div>\n<p><\/a>\n<\/div>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"responsivegrid aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CrowdStrike Accelerates Real-Time Data Classification with On-Device AISeptember 16, 2026\u2022Lior Ribak\u2022Data SecurityModern data security depends on understanding sensitive data as it is created, accessed, and moved in real time directly on the endpoint.In addition to identifying predefined patterns such as credit card numbers or Social Security numbers, organizations must protect unstructured information including documents, chat logs, support tickets, AI prompts, medical records, and free-text fi<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32776],"tags":[],"class_list":["post-26225","post","type-post","status-publish","format-standard","hentry","category-crowdstrike"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26225"}],"version-history":[{"count":1,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26225\/revisions"}],"predecessor-version":[{"id":26232,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26225\/revisions\/26232"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}