Decentralized Trust Graph Working Group Weekly Meeting - AM/EU Time Zone - 2026/09/16
Watch on YouTubeVideo summary
The Decentralized Trust Graph Working Group held its weekly meeting on September 16, 2026, focusing on significant advancements across several specialized task forces and technical initiatives. In the realm of risk assessment and harm prevention, Sanka detailed the transformation of their toolkit into a modular, portable set of power tools capable of verifying specifications across the entire portfolio; this stable solution, which has not yet incorporated AI, is now releasing weekly updates while the team prepares to shift from asynchronous to synchronous meetings for several weeks. Simultaneously, the Credentials Task Force reported progress on merging statement credentials into a new public namespace registry and adopting semantic versioning across specification repositories, with coordination underway between credential and zero-knowledge proof (ZKP) groups to target an implementer's draft by October for the Linux Plumbers Conference. The ZKP Task Force announced the completion of machine-checked construction records comprising sixteen proofs and clarified a division of labor where credential specifications define requirements while ZKP owners manage construction, bolstered by new collaborators from the Cyrus Foundation and the EU digital identity wallet benchmarking team.
Technical developments were highlighted by Glenn's announcement of extending Trust Tasks to Go and Dart languages, alongside a critical breaking change that upgrades the VTI stack from revision 2 to revision 3; this update aligns with the latest drafts and integrates post-quantum cryptography as a first-class citizen. A major conceptual presentation was delivered by Daniel, who proposed a "decision layer" within the Verifiable Trust Agent designed to mitigate user oversharing by reframing data interactions away from a suboptimal "Prisoner's Dilemma" toward a multi-round "Trust Game." Drawing on game theory, this decision support layer aims to influence variables such as discount factors and noise to encourage cooperation and minimize extraction gains, thereby helping users navigate the privacy paradox through rational assistance rather than simple consent mechanisms. This framework was subsequently discussed in relation to the VTC "ceremony" concept, which involves a coordinated set of tasks including triggers, requirements, verification, evaluation, and verdict, to ensure compatibility between their respective approaches.
The meeting also welcomed Reza from Quai, who announced the launch of the Verifiable Private Knowledge (VPK) working group as a sister initiative to DTG. The VPK group is dedicated to securing data before it is transmitted to third-party AI services by utilizing confidential vector search via partial homomorphic encryption, effectively preventing the inadvertent donation of intellectual property during Retrieval Augmented Generation workflows. In closing remarks, the group addressed the relationship between Tadal and existing community efforts, acknowledging that while full integration into the current landscape has not yet been realized, the concepts align well with ongoing work on the Decentralized Trust Graph and Trust over IP. The participants agreed to explore how Tadal's capabilities can be integrated or aligned with their initiatives, noting that further collaboration will occur after the Plumbers conference to determine the specific implications for the Decentralized Trust Graph, while also apologizing for a delay related to a previous HTX task force meeting.
Read the full video transcript
Oh, hi CHS.
>> Hello.
[laughter]
>> How are you?
>> Good.
We don't seem to have a lot of folks
joining us today.
Uh,
it's only one minute into the meeting,
so not too [clears throat] concerning.
Yeah. So, uh, Drummond is away today.
Uh,
he's, uh, at the Prohuman Conference.
So, all good stuff.
And uh unfortunately Martina is also
unable to make it today with a client
engagement.
Okay.
Uh
let's
get started. It is 3 minutes past.
So
the usual
policy
antitrust policy notice.
Um
uh you must uh everything must be
conducted in accordance with applicable
antitrust and competition law. Um and so
it's important we adhere to the agenda
which we'll go through shortly.
Um
and uh we ask that all contributors are
members of diff or of uh trust over IP.
Any new members? I don't think I spotted
anyone in the list.
Anyone like to introduce themselves?
Okay,
just pop this down.
Okay, it fills up quickly. [laughter]
Welcome everybody
watching.
I have to come back to this.
Okay. So, no new members that I can see.
Uh
any general announcements or news items
of interest?
No.
Okay.
Um, so let's step through the agenda.
Uh, so we're supposed to have general
announcements.
There are no actions from the previous
meeting at this stage that I'm aware of.
Um, we'll have an update from the task
forces,
uh, with the exception of VDS and agent
names.
Um, and then hopefully Daniel is here
to give us
>> Yes, I am.
>> to give us an introduction to
Tadal.
Uh, or how do you pronounce it,
Daniel? Is it tadada?
>> Tada. I don't even know. [laughter]
>> I think I think a bit like tadada, you
know.
>> Yeah, exactly.
>> Exactly. [laughter]
>> Got it.
>> Okay. Brilliant. So, we'll have an
introduction and that's our main special
topic.
Is there anything else that anyone would
like to add or change in the agenda?
Okay, let's get cracking.
So,
risk assessment and harms prevention.
I'm going to hand over here to Sanka
because he's been doing all the work on
this and has really
I I expressed it here transformed the
risk assessment and harms prevention
toolkit from a rusty bag of nails or a
bag of rusty nails to uh like a a
modular set of shiny power tools. Um
so it with [clears throat] this in mind
we want to uh resume the t task force
meetings so that we can work through and
and improve it together. Sankaan do you
want to explain where you've got to and
how you've been using it with respect to
the specifications?
Yeah, I'll be brief because uh I think
we the tool still doesn't merit all the
hype that we have in terms of describing
it. But anyways, uh so uh
the current tool is was primarily
focused on extending its capabilities to
do a couple of things. one is making it
a bit more modular and portable so that
any other working group can pick up and
use the tool to do the same kinds of
things. Uh then there is a bit of uh uh
ability or capabilities in the tool to
allow for uh checking specifications
uh checking across specifications,
checking across a composite of uh
specifications because at the end of the
day the the consumer experience of DTG
has would be a composite and uh given
how quickly the codebase has been
progressing for the VTC CDTG portfolio.
It has been useful for me to actually
continuously keep on testing uh
providing feedback to Glenn and Jeff uh
also trying to ensure through by
bothering them enough that the tool
isn't misbehaving and is actually
producing useful output. So I think
since the uh Cypress release it has been
very stable in terms of how it is being
uh analyzing the codebased changes uh
across the portfolio and producing
reports. Uh
the tool currently does not use any AI
even though it is designed in such a way
that if somebody wants to use it
alongside their agents that they run
they can absolutely do that and the
agents will do a lot of fantastic things
alongside with it. uh I will add to the
zoom chat a link to the uh documentation
that is published for the uh the tool
and that would allow you anyone who's
interested in idea figuring out uh what
exactly it does. Uh I try and make a
release every week so that any new
capabilities get released and and are
and available to everyone.
Thank you. And uh Glenn agrees with me
that more hype is needed, [laughter]
but maybe a different analogy. Um any
thoughts or questions for Sanka?
Okay. So my propos looking at the trust
over IP calendar my proposal is to put
the task force meetings in directly
before this this call
um and we'll run for a few weeks and see
where we get to and then slip back to
asynchronous mode um depending on you
know our agreement amongst ourselves.
So, um, anyone got any
preferences, strong preferences for that
not to be the time?
Okay, great. I'll go ahead and set that
up.
Uh, right, over to you, Jeff, for
credentials task force.
>> Thanks, Nikki. Uh bear with me. I've got
a throat problem so uh I can't talk very
well. Um we uh merged in the uh
statement credential after discussing it
yesterday during the uh credec task
force call. Um there's some fallout,
well not fallout, but some uh knock on
things that need to be done as a result
of that because they'll be uh well
create another repo to host a registry
of the predicates for those statement
credentials. So they they'll be in a
public namespace. There's we need to
figure out what that namespace is going
to be exactly. Drummond is talking with
the LFTT people about that right now
through email. So that's been merged
into the spec. Um it's been we've have a
few other issues and a couple PRs
outstanding still a new one got added
today. Um so there's a fair amount of
moving parts in that. So if anyone has
the time and the interest, you know,
please follow along. If you have
questions or suggestions, you know, or
really think something needs to be
changed, feel free to reach out in the
issues and or even create a PR if if you
feel strongly about it. But, um, we've
been having a pretty good cadence now
since about two weeks of trying to merge
things in. Um and uh yeah, we had a
we've [clears throat] also um excuse me
to we've also adapted semantic
versioning now thanks to Brendan in all
of the spec repos that are active. Um so
I think uh we we gave a little shout out
to the ZKP guys today in uh in a PR that
they've created in their repo about
that. So hopefully we can get that
coordinated across all the different
repos and that will make things easier
to see what what states of each document
align to which the other documents and
which states for that. So um thanks
again Brendan for spearheading that and
doing the work to get that uh in place.
Um
yeah, I think that's those are the main
items. uh you know Brendan uh Alberto
others who were on the call yesterday
feel free to add anything to that or if
there's any questions you know we can
field them now.
Yeah, nothing really to add. Um good
summary and yeah we're we're trying to
keep things moving. Um, we're trying to
merge things in um, you know, uh,
relatively quickly, so after a couple
days to allow for review, but that
doesn't mean that things can't be
changed and addressed after they're
merged in. So, um, you know, please keep
an eye on everything. Uh, you know,
review it when you can. uh provide your
comments or issues or PRs and uh yeah,
we're uh moving towards something, you
know, resilient and implementable. Um
so, uh please uh you know, your input's
welcome.
>> So, unless there's any questions, uh
Nikki, I think that's it from the
credentials task force. Thank you.
Thanks guys. So it sounds like you guys
you're going to be in good shape for the
plumbers conference in terms of the
status of the specification.
Is that right?
Um, yeah, I guess it depends on how you
define good shape, but but I mean it's
moving quite quickly and uh, you know,
it's getting further developed and I I
think we're all these new changes that
we're making are good ones and it feels
like it's it's coming together. You
know,
>> are we going to have
>> I don't know if we could say uh we'll
have it in its final state, whatever,
however you define that, it's going to
be a a growing thing no matter what. But
I think it's moved quite a bit since,
you know, compared to a month ago.
>> I'll
sorry for that.
>> I just want to add one um thing for
context just to mention in case folks
weren't aware. So the the cred and the
trust test spec are staying narrowly
scoped and we've added the VTI spec that
is going to be looking at cross linkage
issues, how to use things together. So,
um, just wanted to orient people. And
then, of course, the the ZKP task force.
So, it's it's a lot of moving parts, but
I think we're all trying to keep them
aligned and connected.
>> Yeah. My understanding from Drummond was
that the credec
was for it to be ready for public review
and uh
uh before the beginning of October
and then we would get as far as possible
on these other specifications.
But what I'm hearing is that they're
being developed in tandem as we agreed
some weeks ago that
you know we all understand they've got
to work together and and not in
isolation.
So
they'll be you know more or less
advanced um with [clears throat] the
trust specification being closest.
Does does that sound about right or am I
misunderstanding?
>> Yeah, I think you could say that. Well,
in the meantime, there's been code
developed alongside of it and we're
learning from the code and we're
realizing there's things that need to be
added. So um the there will be something
functional and usable by the Linux
plumbers conference and the spec will be
in line with what's being presented
there. Uh so yeah, I guess you could say
we're that would be sort of the target
of an implementers draft uh at at that
stage and we'd have what would be
considered viable for that.
Okay,
any other thoughts or comments?
>> Great.
Okay, over to you, Glenn.
>> Thank you, Nikki. So, couple of updates.
Trust continue to grow. Uh if you
haven't read Jeff's blog, I think he
articulated one of the side effects of
trust tasks on
everything you see in the UX, whether it
be the CLI or the web um portal for
VTC's or the browser plug-in. That's all
managed through the trust tasks. And uh
it's very quick, responsive,
and you don't really need to do much at
all on the UX side apart from the
design. You don't have to worry about,
you know, cryptographic handling and uh
a lot of those kind of low-level
complexities. Trust tasks hide all that
for you. Um we've extended so we had
Rust and Typescript as codegenerated
libraries from Trust Tasks that's now
being extended to Go and Dart
uh which brings in the Flutter community
as well. So that's exciting. Again, just
getting ready for Linux event and
open-source software EU, which is the
same week where we want to try and
remove any friction for developers to be
trying this out and interacting with a
VTA or a VTI uh as they see fit. We are
also I didn't put in his apologies,
Nikki. Um we are making another breaking
change across the VTI stack of shifting
from trust spanning protocol revision 2
to revision three um which has a number
of major breaking changes but
brings us back into alignment with the
latest TSP
um kind of draft version as well as
gives us postquantum computing
cryptography
uh by design into the messaging layer
which also trust tasks has been extended
to support all of the popular
postquantum uh cryptography methods as a
first class citizen. So there's a lot of
work going on and this is based on uh we
had a meeting with the Linux Foundation
team and the Berkeley team uh yesterday
and it's pretty clear that a design win
they want to showcase is uh ZKP with PQC
capability.
Any
thoughts or questions for Glenn?
Right, let's press on. We're whipping
through this agenda at a rate of not
very efficient.
Uh Scott or Mitch,
is that KP task force talking?
>> Sorry, I was on mute. Hi everyone.
Uh so we had a a great call yesterday.
Um the headline is that the spec is
becoming real. Mitchell showed a machine
checked spec of construction records. Um
this concept that he's been um pushing
of a effectively a cookbook in code.
There's 16 proofs so far and Glenn's
ADR00001 is the first composed one. Uh
we confirmed that that this task force
owns construction I love saying it 007
um the common control primitive. Um
that's the piece uh that issue nine and
four separate requirements all lean on.
Uh the division of labor is settled. the
credential spec writes the requirement
and all and a oneline allowance on the
VRC and we would own the construction.
Um we agreed a working model of
reviewing adjacent specs async rather
than blocking them which keeps everyone
moving and we have some new
collaborators joining us. Um,
uh, Leif with the Cyrus Foundation and
the, um, the EU digital identity wallet
benchmarking team will join us on the
29th to share what he's been seeing,
including real performance data across
major ZKP families. And I'm trying to
see if a gentleman I met, an engineer
from Prove Kit, which was released by
World, would would be interested in
joining as well. And the immediate next
step is Mitchell is finalizing the spec
so it renders publicly and then and then
more more people can review it.
>> Thank you Scott. Any thoughts or
questions for Scott?
Yeah, Scott Glenn. Yeah, just want to
confirm
when we talked to the Berkeley team on
their ZKP,
is that the same ZKP your task force
like are you aligned on the methodology
or is it Berkeley is doing something
slightly different to what you're doing
which is different to what Siros is
doing? Just trying to get a
understanding on convergence or their
three different implementation models
that work side by side.
>> I know Mitchell's in transit right now,
but let's see if um
uh he if he can jump in and keep me
honest, but we're we're trying to get
that clarity too as to whether the
Berkeley team would be um contributing
directly to what we're doing or if
they're working on things where it's
interesting and we could borrow from it.
Uh so we're we're trying to figure that
out as well.
And with Leif,
we might need Drummond to close the loop
there. But going back to the kickoff of
this in April, the idea, I believe, was
that Leif would be a and his group could
be a constituent of the work we're
doing. They're looking for the specs and
the requirements we have so that they
can build against it. That is the
impression that I I still have from
months ago.
>> Okay. Uh I would just
stay we when we talk to Berkeley team
just because we're kind of two 3 weeks
out from plumbers that's not a lot of
time to implement ZKP end to end. Uh we
are trying to get code from them next
week and a integration point
either next week or very very early the
week after. Um,
and we have a weekly call set up to keep
everyone on both sides of that kind of
honest in the deliverables so that at
Plumbers we can get up on stage and
actually showcase ZKP
meeting the Berkeley white paper uh
research paper that they're also going
to publish at the event.
I see.
So
that may mean that there's deviation
in the short term which I think we
can be open and transparent about but if
we want to create um some awareness and
attention to this and as a capability
statement at plumbers event uh and again
Hart the CTO for Linux Foundation he's
pretty adamant it's kind of a non um
non-negotiable requirement from their
site.
>> Scott, what do you need to
work, you know, to advance this so that
Glenn and the team can
meet this requirement?
Is there anything you need from the
group that we can help with?
>> I am not sure yet. I think I'll have to
take this offline with Mitchell and
Drummond. Um
>> Okay.
Okay. Let us know if there's anything
obviously and that goes obviously for
all the specification authors. Uh,
is there anything that you're looking
for that you're not getting from the
group
um other than review of PRs and things
like that?
Uh, I think generally
the spirit of it is the reviews getting
more eyes on it, more people hitting
what we're doing to keep us honest and
um aware of
>> unknown unknowns to borrow from Donald
Rumsfeld years ago.
>> The Rumsfeld moment. Yeah.
>> Yeah. Yeah. Yeah. [laughter]
>> For all specs, please take time to
review
if you can. Hey, now this is on the
topic of Rumsfeld. Is it like that Scott
Bessett guy just a bad photocopy of him?
You know who I'm talking about?
>> Oh, like his face or how he acts?
>> His face. How he acts just his whole
vibe is just like, you know, deformed
child of Rumsfeld to me. But okay. Uh
>> I get what you're saying. I think he
just I think he has a fancier haircut.
But I see what you're saying. Yeah.
>> Yeah. But it's sort of like Yeah.
Plasticky, too. But all right.
Okay,
let's um
Okay. Uh
is Margie in the room?
No. Uh Daniel, would you be able to give
the DTG
uh human trust experience task force
reports
and then you can
>> smoothly move on to Tada.
>> All right.
>> Yeah, sure. I can quickly talk what we
discussed yesterday. So um so uh one
topic is always our uh standing
deliverables where we want to collect
best practices and also um work on a uh
pipeline to faster and better in more
easy create explainer videos.
[clears throat] There is a new video
available for you to check out. Um if
you want I can provide you with the
address uh shortly after the talk maybe
or you can find it in the HDX work uh
group uh repo. um these um the idea of
these translates is uh to uh have an
easy way to uh [clears throat] explain
this uh complicated concept and uh I I
did some more uh work on it to have
better results and it's quite nice but
for the moment we decided to uh
stop these activities just because um I
think the base that we want to explain
is not necessarily very stable right now
and we expect a lot of things to change
and this would make this effort
redundant and so please uh really be
patient with us. We're working on that
but the infrastructure is there. So
that's uh one thing and then we had a
broader discussion about the personas
and the faces and worlds that describe
these attributes that a persona can
have. This is still an ongoing
discussion. It's a very important one I
guess and uh and we all like the idea of
course of having these uh worlds to lead
a little bit also the user to uh
understand what faces are, what they
could be and what the attributes could
be. And we also thought we should think
of um
a way how to uh further enable the user
uh to define these attributes. uh so
that we may have an automated system
that extracts the information from
existing repository like a CV or
anything that helps the user to create
initial phases. However, this must
happen of course in the right privacy
context and uh and um yeah we still have
to probably do a little bit more
thinking about that how to uh make that
a natural experience.
I think these were my main uh discussion
points. Please uh uh add some future
points or additional points. Kie or
Nikki or whoever joined the call
yesterday, feel free to add them.
No, I think that was a pretty good
summary. Uh so again uh this is uh to
support the VTI work for the plumbers
conference. So uh there's some input
into
uh this discussion which I've put in the
chat and um again you know all welcome
there.
Uh okay do you want to
>> go on to Tadal and I'll give you the
screen share. Happy to do that. Yes. Let
me find
the right screen to share. Yeah, that
should work. So I'm very happy to have
the opportunity to present to you a uh a
concept that is very close to my heart
and is based on on a lot of researches
has been done in the last years and it
it might not be the most important in
terms of pressing concept to discuss now
with the plumbers conference coming up
but I still think it is worth to have a
special topic IC about that. Um and
that's because it it addresses a very uh
deep problem and the deep problem that
also motivated me to join this
initiative here. Um this is like the
missing layer uh the missing trust of
disclosure and agency layer.
Now we will have uh these wallets very
shortly. millions of people will have
these wallets, but there is still a big
uh problem that is unsolved. We know
already now and this is also based on on
recent research of a colleague of mine
here that I met in Geneva in CERN and
and reminded me of the importance of
that topic. Um we already know that the
the user will be a little bit
overwhelmed because this kind of new
technology and this uh zero knowledge
proofs and this uh selective disclosure
uh documents are not necessarily part of
the current mental model of user. And we
also know from the past from information
economics also that a user tends to
share much more data than he thinks he
should share. So if you ask people would
you share this information they would
all say no but in fact they have already
done that multiple times. Say we face
this privacy paradox all the time and
from business side we face the data
collection dilemma. So that they should
actually know a lot about consumers but
they should not know about consumers. So
it's a real dilemma and the um colleague
here of mine Sheila I hope she can join
one of our calls in the future. They did
uh some extensive research on this
oversharing problem in the context of
the upcoming uh release of uh wallets
especially with the EU ID and also with
a focus on the Swiss ID and what what
all these organizations that now try to
implement this technology by end of the
year already notice is that this is an
unsolved issue. oversharing is going to
happen. And uh here uh Sheila brought up
also some of these numbers of of their
research. So they uh did a lot of
experiments um because this is a really
hard thing to observe from a scientific
perspective. So you cannot have a
natural experiment about that because
exactly of this privacy paradox. So
people would not answer the right way
probably. But you can simulate that. You
can um do some expert panels and so on.
And they found out in certain situations
that people actually really overshare
also with these kind of wallets and that
even an official ID has been shared for
a news website by 20% and that's way too
much. So that is not yet the answer. and
they identified the need to have this
decision layer that supports the
individual uh and is not only a consent
button because if we build a VTA that is
only a consent button or a outsource
delegated consent button or the medical
consent button we we don't solve the
problem here and they constructed an
assistant here that was able to
intervene via notching at the point of
uh disclosure and then they were able to
reduce this oversharing by a significant
rate. And this research that uh these
ETH colleagues do resonates very well
with my my earlier research in this
area. I I didn't look at it from a
security perspective how how they did
but I looked at it rather from
aformational
economic aspect and especially also
using game theory to design models about
it and the interesting thing here and I
I really want to keep that more or less
short today is that we can I'm really
convinced that we can introduce such a
layer in in a system like our VTI our
trust infrastructure and that this layer
can really sit within the variable trust
agent because that's the ideal place to
position something like that and why
could it work because in game
theoretical model you see or you can
model these kind of situations of data
sharing and that's also what I did and
there is a a huge document It's about 50
pages. It's also linked in the material
and I'm habitant to derive also an issue
maybe from that to be a bit more
specific so that not everyone needs to
read the 50 pages. But the interesting
part here is that we model this
interaction. We can uh find out uh what
can we influence which variables do we
need to influence and how we can do
that. And one of these variables that is
quite interesting is this delta here.
And the delta is the discount factor of
a future payoffs from a collaboration.
So in a game theory, it's pretty simple.
Just look at two parties, yourself and
another party, and you're relying on
this party and you want you have two
options whether to cooperate or to
defect. And also the other party has
these two options. And when uh the
someone defects and the game stops, of
course, you only have one iteration. But
the idea is also to uh look into future
values to have multiple iterations. And
now you probably think uh that uh
companies are not really interested in
that because because also hit and run is
a very popular model. But the findings
here is is is quite prominent that even
with the low with a very small discount
factor of 1/3 say this is 0.33
um uh of future gains there is still a
lot of uh uh effort or willingness to
cooperate. So it doesn't take too much.
You don't need to have the big value in
the future. you have to discount that
like a discounted cash flow but uh all
these rate that you need to have so you
need to be higher or the same like
one/ird is not that high so even with a
little bit of motivation you can
convince someone to play the game
correctly
um now
>> yes sorry yes please
>> yeah what are the game what are the
rules of the game precisely
>> oh no yeah I will come to that a little
bit later if I if I may h yeah uh so I I
want to explain that even further later
but um just keep with me if that's okay
and we can discuss afterwards um so I
just want to first um also tell you
where I see this uh layer this title
decision layer it could sit on top of
the VTA of course the VTA sits on the
infrastructure and the human is
interacting with the VTA anyway so this
layer could sit very well in between.
And before we now go into the game
discussion, um we were able to uh uh
derive already clear capabilities that
we need or that I think we should have a
look at to implement in our uh
verifiable trust infrastructure and
these can be seen as buckets of
functional requirements and um they
originate from all these researchers. So
it's a combined view
uh but they go in the same direction. So
we need or if possible we should make
sure that our VTA is uh able to
understand the situation on the game
we're playing and that there is a
decision support layer and also that the
user is then supported in acting and
that we can learn from that and that is
the main benefit of course of such a
system that you have a feedback loop
that provides additional information and
makes this information as symmetric app
a little bit small in the next round. Um
to be a little bit more specific and I
would really love us to uh work maybe on
such capabilities
is um that we need to know a little bit
something about the parties and I guess
there is information around but that is
going to be the big art how to uh find
the right signals for this kind of uh
understanding. But first of all, we need
to know a little bit more about the
request. And also in the AU and in
Switzerland, you will have quite a lot
of information here because if someone
asks, a party asks for information, they
need to be pre-registered in some
registries with their need. So they
already have kind of a proposal uh
signed what they are going to need and
this is being checked by whether the EU
or Switzerland. So there's always this
registry that is looking at that. But um
that's not necessarily enough because
our VTA needs to understand what to
share because this is indeed a game and
uh you can share uh nothing or and not
participate or you can share a lot or
you can share only a minimal amount and
also my other belief is that we should
look at that incrementally. So in
different rounds so that we can also
extend the amount of data shared and in
order to do that we need to know about
the request. We need also to know about
the principle. Principal in this case is
the uh the person that the VTA is caring
about and maybe about his preferences or
her preferences to be able to make this
judgment.
Uh then um of course I don't want to go
into everything here and that's pretty
much also detailed in the studies. Um
but um well the the interesting part is
now to uh come up with an idea for the
uh user what to do or what uh strategy
to follow and I will show you the the uh
different kind of strategies later. So
now a little word about the game we play
and I'm happy to go into details here
but it it's kind of a an interesting um
piece of mathematics. Uh so it's not
bulletproof and do not look at these
variables and all these levers in
equations as as constants. They are not.
It's rather about the mechanism how the
game works. And this is then a very good
thing to model in game theory. And I
want to start with what kind of game
we're playing. And this is something I
currently see as a a rather big mistake
everyone is doing. Uh so if you have
read our your US president's [laughter]
recent note about uh what is needed in
terms of uh guidelines or or guard rails
for AI development and that we probably
should not slow it down but we only need
a strong person like a strong president.
um and then that everyone needs to fight
against a partner that does it anyway
like China we are then in a complete
wrong game and uh that's maybe the most
important takeaway I want to give you in
this uh special topic here so the
temptation is very high to see this as a
prisoners dilemma game that is one of
the most um famous games in in in game
theory where two parties act
simultaneously. They can cooperate or
defect. If both would cooperate, the
value would be very high. But like
prisoners that have to blame someone
else to get a lower sentence, um they
would probably not cooperate. And this
is then what we call the Nash
equilibrium,
which is a situation you will find
yourself in that is stable. It's a
dominant strategy. But unfortunately it
leads to a very low uh utility. So the
combined utility will be very low and
that's exactly unfortunately also what
we're doing this political debate now M
Mr. Trump. So if you have your old
guardrails or strategy is a tit for that
strategy and that you have to force
developments before someone else does it
you're trapped in this uh prisoners
dilemma. And that's also the case if you
look at it in data sharing. If you think
that I cannot give all my private data
to Google because they will do uh too
much business with it and I don't get
something back then it's not a very good
strategy. And the opposite like the big
corporations that only harvest your data
and earn a fortune of it. but probably
happening or happened so far is also not
a very good strategy because they are
all not an optimum outcome. So we need
to look at this uh from another games
perspective and that's rather the the
theories of the trust games and the
difference the rules of the games they
are quite different. said um in a trust
game um we have multiple iterations. We
only don't only look at one iteration
and we have of course uh information as
symmetry and that's [clears throat] what
what we always have but in trust even
more and what we also have is we have
some noise and we have vulnerabilities.
So once data is shared you cannot take
it back. So it's already gone. the
damage happened in round one and you
need to cater for that in the next
round. So this is the the basic
mechanism of of game theoretical
analysis and you can then model quite
easily such trust games. And the idea
here is that we tried then with all the
intervention strategies um the
mechanisms that we identify in the
capabilities that that we need. we can
model quite a nice layer that uh helps
us to find a very good dominant strategy
for both parties in a long term in
multiple rounds. But this also means
that we have to identify things we need
to influence and these are these nasty
variables here a G or a Q. So cannot go
into all the details here but it the
mechanism is very simple. So what we
need to do is we need to be able to
influence a little bit this this um um
variables in the equation to make
cooperation work for all parties. And
that also means that we need to be able
to cut the gain from extraction with
minimization for example. So to cut
damages we need to be able to influence
what we understand. For example, here
the the alpha is a false positive rate
for trust assessment. So we need to have
a little bit more information to that
correctly. But if we have all these uh
or understand a little bit these
mechanisms, these variables of the
equation and if we have uh some
capabilities that influence the single
ones, then we can try to find a spot uh
where everyone cooperates and combined
number is higher than if utility is
higher than only for one party.
And last but not least also with this
kind of modeling we can then also
recommend concrete strategies here to u
to recommend. So if we start this game
or data sharing we can only share what
is required or we can try to reduce it
if we don't believe in the honesty of
the other party. And the very important
thing here is and this is also seen here
in in the equations we need to have the
ability to recover. So if for example
alpha is very high means we have a lot
of noise in the game then we should not
stop the game we should not exit the
game. It's much more beneficial if we
try to recover maybe by reducing the
amount of data shares but then expand
later so that we size the entire horizon
of the game and and are able to u get
the full benefit. that this is very
theoretical of course but there is
always a truth in it and I really think
if you look at these models there are
not too many factors that we need to
care about but I also think that we
should care about these uh uh these
variables to make a very successful um
solution that not only is cryptographic
technically correct but actually
supports the user in his biggest dilemma
that he faces meaning that he doesn't
really understand what it is about and
the human beings probably need a little
bit of help or assistant a rational
assistant here that helps him with this
challenge. So that's it. A long talk.
Happy to for you your questions.
>> Yeah. Well, I'm going to I I recognize
these four variables from my own work. I
I work in game theory a lot and
>> cool future agent society. So uh this is
very uh this is a good um potential
framework for developing you know some
experimental
simulations and how agents would uh
potentially behave in those simulations.
So I do have some questions still about
the details. So what you're saying here
is that the steps in the game are at
each step both parties choose to
disclose. So most both take a disclosure
action. Then they look then they analyze
what they've received and then choose to
make another disclosure action. However,
there's no other form of communication
going on between the parties. In other
words, they're not, for example,
negotiating what they're going to
disclose to each other in the next
disclosure step. They're just taking uh
self assessments and and choosing what
to disclose based upon the previous type
of data that they received. Is that
correct?
>> That is it is that is correct. Yes.
Yeah. Uh and of course this is probably
uh one of the limitations here. Yeah. Uh
of these kind of games. But um I I would
argue from the point of view that today
we know information it's way riskier or
there's even less information as as when
you try that. And what we already also
found out in in some tests here is that
only a uh a proof or a I say a big uh
statement of why I need this and that
amount of data can already influence the
usage. So a big statement looks very
convincing and we have a bias again. So
the user is not acting rationally. So
whatever we can use to help in this
non-negotiable but instant first moves
would be a benefit. So that's what I
would argue here. But you're of course
right. I mean there could be a lot of
research done in in finding more
information in this noisy environments.
Yeah.
>> Right. Yeah. Hope that helps. [laughter]
>> Makes it a little more efficient
potentially. Okay.
>> Yeah. Yeah. Sure. Yeah. Brandon, you
also have a question, please.
>> Yes. Uh, thank you. No, this is very
interesting. Um, one of the things that
I've been thinking about, uh, with
relation to our work here in this
working group, and I just wonder if
you've, um, thought about it in relation
to your work is the the ILE E, uh, 7012
standard about uh, sometimes called my
terms um, you know, machine readable
terms. Um, you know, particularly in
regard to what should be disclosed and
to whom. So, um, I just wanted to
mention that in case you haven't looked
into it. Um uh I'll put a note in the in
the chat here.
>> Uh but it's uh it's not about the
strategy so much as just you know the
mechanism um uh that we might be using
of saying okay what what should you know
what am I allowing to be disclosed and
to whom under what terms etc. So um just
wanted to see if you had any thoughts on
it and and you know make you aware of it
if you weren't. No, no, no. I that's
true. I didn't look too deep into it,
but I'm aware of it of the existence of
that. And that's of course something
that goes exactly into that direction
and informs especially the first uh
layer of the understanding also with the
preferences.
So yeah, that's definitely an important
part. And my my only question here is
what can we also bring in or do
differently
now that we have the opportunity to
shape something new?
>> But thanks
>> Daniel. This is Reza from Quai. Um on
Monday we launched the VPK working
group. So it's a sister working group to
decentralized trust. Um the mission is
to secure our data before we send it to
a third-party AI service. Uh for now
we're focusing on just um confidential
vector search using partial homamorphic
encryption. And um so that will make
sure that we're not inadvertently
dulging our whole corpus of intellectual
property when we send a context
document. um or some repository up to uh
a search. We can still search by um uh
natural language on a third party hosted
system um and they can't see the data.
>> Yeah.
>> Okay.
>> You're very interesting.
>> Uh can you just uh repeat that res? I'm
trying to record it. I've got some uh
>> working on some dot dot dot vector
search and homorphic encryption to
enable
discovery. Confidential discovery is
that
>> confidential vector search. So
>> Lord bless us. What's that?
>> What's that? Okay. So most of us when we
engage with um uh chat GPT or claude we
upload a document and then we ask
questions about the document and that
class of application is called rag
retrieval augmented generation.
>> It it's asking questions of a document.
Now,
as as Daniel said, we are inadvertently
dulging the entire document in clear
text, not just the parts that are
relevant to the question we're asking.
And they own it forever. Um, in the
terms and conditions of of Sam Alman, he
says he owns the data. He's free to
resell it. He's free to train his model
on it. He's free to mine it for
advertising opportunities. So, um, and
then Dario says, "I'll never do that.
Don't worry. Here's my pinky promise."
But hey, once companies go public and
they owned by private equity, those
terms and conditions, which are
changeable in their terms and
conditions, will change. So, how do we
protect ourselves? uh whether we're an
individual or whether we're a
corporation that doesn't want to
inadvertently
uh donate their intellectual property to
um to these services. Um so we've
developed a mechanism and we've
developed a mechanism where you can
scramble the vectors. So you vectorize
locally, you scramble the vectors and
now the vectors are stored remotely. The
vectors are stillable.
in their in their encrypted form except
the host now never sees the data. Um and
then the chat completion we haven't
secured but um we're working on that. So
eventually we'll have in this working
group we'll have
um ways of securing the entire
>> now and when you say check you're just
talking basic inference [snorts] doing
basic chat
>> uh as opposed to
>> that's what you mean by chat completion
I'm just identifying the
>> yeah chat completion yeah so in in rag
there are two phases there's the
retrieval phase where chunks of docu
your documents ments are extracted based
on a cosign similarity or vector search.
Um, and your document might have, you
know, you might have 10 terabytes of
documents that is deeply sensitive.
Let's say you're a um a defense attorney
and you've got all your client records
um or you're a doctor and you've got all
your patient records. Way too much for
you to search locally um using natural
language. So, you upload that. But we we
now have the ability for you to upload
that in a scrambled form. Um such that
it's still searchable in its scrambled
form. Then um whether you run the chat
completion the inference part locally
which will be then you've got it
completely secure or remotely on another
service that's up to you. Um but uh that
that's the the mission of the VPK
working group is to standardize the
protocol first and then have a call for
proposals for algorithms that can
conform to the protocol.
Okay, that's enough me. [laughter]
>> That's really interesting. Thank you for
that. So we've got we're two minutes off
uh the hour. Uh Glenn, you noted in the
chat
uh trust ceremony at the VTC level work
with this framework or be compatible
with the structure. Do you want to speak
about that?
>> Sure. Uh first of all, great work,
Daniel. I really enjoyed it. Uh
>> complex subject and making it a little
entertaining, not an easy feat. But in
the VTC, one of the early aspects was
the concept of a ceremony which was just
a coordinated set of tasks to do
something complex and we kind of broke
them up as you know there's something
that triggers you and using your
language which I quite like you know
there's something that triggers the game
then you've got to gather what are the
requirements
that are the input to the game and then
there was you know kind of a
verification
What are the facts then? And then an
evaluation, then a verdict, and then
there's
>> some form of side effects that come out
of that process. Do you see that
>> working alongside Tadal?
Um, is Tadal kind of replacing that?
Should we be thinking differently about
ceremony? just trying to figure out, you
know, how
how Tadal could fit into
what we're doing on the community. And I
know you talked about the VTA, but
actually it's the VTC in many ways that
also has the strong need for this um
>> well these are good question and didn't
uh integrate it in the current landscape
yet but I what you tell me is is quite
similar to how I imagine that. Yeah.
>> Okay. Okay. So, I'm quite sure that we
can make that fit or or that some of
these capabilities if not yet present we
should think about how we could
integrate it. Yeah.
>> Yeah. Okay. Cool. So, you're saying this
is uh it could work with and potentially
align. Okay. Good. Good.
>> Sure. Yeah.
>> Thank you.
>> Thank you very much, Daniel. Uh and
apologies to those who attended the HTX
task force meeting yesterday. a little
bit of a a sequel there. Um
so we just wanted to introduce that and
then after the plumbers conference we
can perhaps come back together and think
about
um what this could mean for uh
decentralized trust graph um or if it's
related to other aspects of what goes on
in trust over IP. Thank you all very
much for your time and see you guys next
week. Take care. Bye.
>> Thank you.
>> Thanks, Nikki.