Submind YouTube summaries
Thumbnail for Virtual Private Knowledge Working Group (VPK WG) community call - 2026/09/14

Virtual Private Knowledge Working Group (VPK WG) community call - 2026/09/14

Watch on YouTube

Video summary

The Virtual Private Knowledge Working Group, hosted jointly by the Linux Foundation and the Trust Over IP Foundation, officially launched its inaugural call to establish a specialized initiative focused on securing personal and corporate data when interacting with untrusted third-party AI services. Led by Chair Reza Rasul and Co-Chair Mitchell Travis alongside other key participants from organizations like Singularity Net and OWASP, the group's primary mission is to construct a digital "firewall" that shifts the trust boundary to the client side. This approach ensures that sensitive information remains scrambled locally before transmission, effectively preventing malicious actors or state coercion from accessing raw intellectual property or personal data. To achieve this, the working group has defined three core task forces: developing lightweight algorithms for client-side chunking and scrambling that meet conversational speed requirements without heavy infrastructure; creating custom personal embedders where the embedding structure remains a secret known only to the data owner; and establishing a future qualification process to benchmark partial homomorphic encryption algorithms similar to NIST's AES standards, allowing market selection rather than mandating a single solution. The technical discussions clarified that the group focuses specifically on "partial homomorphic encryption" rather than generalized confidential compute or the Model Context Protocol, acknowledging current challenges in securing LLM inference while prioritizing the security of knowledge base retrieval as an immediate goal. The conceptual framework for this system visualizes knowledge pathways through six distinct categories: Gates acting as boundary agents, Skills serving as delegation agents, Harness representing compute resources, Cannon functioning as memory, Federation managing connections, and Agreements defining value links. These elements generate unique patterns within a "tourist space geometry" that can be compressed into mathematical representations, facilitating smooth transitions between higher-dimensional geometries and standard 2D maps while maintaining distinct boundaries. This compression enables the creation of spliced information packets that record agent runtime and document consumption order via MCP servers, thereby enhancing data governance and trust in agent computations through fractional dimensions and obfuscation techniques that account for versioning changes. To ensure the longevity and effectiveness of these initiatives, the group plans to transition its governance to a Linux Foundation GitHub repository while leveraging existing resources like Confluence and Zoom for collaboration. Strategic logistics include setting up Slack Connect with Singularity Net, updating their white paper, and seeking partnerships with vector database providers such as Pinecone and Qdrant to facilitate testing environments. The working group also intends to recruit founder members from various sectors and propose the use of AI agents to automate meeting summaries and governance discussions, streamlining administrative overhead. By confirming a weekly cadence for meetings at 9:00 a.m., with minutes distributed via the Linux Foundation calendar, Slack, and email, the group has laid a robust foundation for ongoing collaboration. Ultimately, this initiative aims to empower data owners by ensuring that their proprietary knowledge remains secure and private even as they leverage powerful external AI capabilities, marking a significant step forward in the evolution of trustworthy artificial intelligence ecosystems.
Read the full video transcript
Oh, we got some audio issues. Hang on a second. Let's see. I'll be right back. Good morning. Good morning. Happy Monday. >> Happy Monday morning. >> Good morning, Myra. >> How you doing? >> All right, there we go. Should be able to get >> So, this Zoom meeting is controlled by the Linux Foundation. So, I was trying to make Myra the co-host, but I don't seem to be able to do that. >> This is this part of the logistics we need to figure out. Good morning, Darren. Happy Monday. Good morning. >> Let's wait for folks to roll in. >> Um yeah, I think I need to get um the Slack channel and and add people to it, >> right? As people join here. >> Mhm. >> Yeah. Let's just see if I can share. Gosh, where do you stand in order to not be in the way of the text? Okay. Um, and I'm gonna just get ready. Great. And let's see what else. >> It looks like everyone is already in the VPK. Um, I I I'm not sure if I'm uh met Sandra before. >> Hi, really nice to meet you. I'm from Singularity Net. I did mention to our team that the call is ongoing. They have all the links, but I don't know if they're going to be able to make it. So, good thing that it recorded. >> And and I missed uh from from what your affiliation was. Sorry. >> Singularity. >> Singularity. Gotcha. Gotcha. Okay. Thank you. Nice to meet you, too. >> Sandra, what we should do is um uh in our Slack, we've both got different Slack accounts um or Slack um yeah, Slack groups. So, what we should do is do that uh Slack Connect where all Singularity members and all choir members can be connected in a channel. So, we need to figure that out. Um but we've done that for different partner organizations. >> Yes, we can discuss that on the call that we have today in 3 hours I believe. >> Fantastic. Okay. >> All right. >> Well, very good. I'm going to kick off um in the interest of time. Um and and we're recording here. So, uh welcome everybody. This is the kickoff meeting for virtual private knowledge. It's a work group under the Linux Foundation under the Linux Trust Over IP Foundation. Okay. So, um I've got a short deck that um will hopefully um uh explain what we're going to go through today. Um it's a welcome, it's a roll call. Um so, let's just quickly take a roll call. My name is Riza Rasul. I'm chair of Kai. Um um and each of you should should introduce yourselves. >> Hi, I'm Darren Warner. Um I'm a a chief technical architect in my uh day job and um I've uh [sighs] known Ki for many years now. Reza, you and I go the lead code contributor. Thank you so much. >> Okay, who who's up next? >> All right, I'm Jerome Mchuan. I'm director of partnerships for Quai. >> Thanks so much. Okay. And >> hello, I'm Mitchell or privacy mage. Um I've been sort of I'm the privacy guy. I'm interested in zero knowledge proofs and um virtual private networks in that sense and contributed to quai contributed to trust over IP um as well. So >> fantastic adra. >> Yes. I'm Myra Quaja. My day job is a service delivery manager at TransUnion. Um, and at Quai, I wear a lot of different hats. Um, I'm one of the officers of the board. Um, I'm involved in the um, uh, intern program, a lot of onboarding meetings, name it, I I I probably do something. >> Yeah. In fact, Myra is the go-to person where we've got uh administrative issues >> and and if I can't help you, I'll know at least who to point you to. >> Fantastic. And and Sandra, you're you're perhaps a quick word of introduction from yourself. >> Absolutely. So, I work in operations helping on the partnership front at Singularity and we were, you know, the co-organizers of AJ26. So, we had the opportunity to have you Reza as one of the speakers. >> Thank you so much. I enjoyed that. That was a week-long immersion into the whole area of gosh of of AGI and various neuroscience and cognitive uh theories. And we learned a lot from that. We're we're largely computer scientists and we're learning from the the folks in the neuroscience and the biological and the life sciences. Okay. So glad to have you. >> Yeah. Thank you so much. Roll call. Done. Okay. So as any organization starts we need to um uh develop a all the ground the founding documents like let's let's lock in on what is our actual mission and make sure we don't have mission creep um uh all the sorts of things we need to um adopt um bylaws and and uh make sure we're we're talking with the same vocabulary. So, it's probably useful to do terminology. The great thing is that we don't have to invent this all from scratch. There is a sister organization within Linux, and I'm just going to borrow their template. And so, um, LFDT uh um so Linux Foundation decentralized trust working group is run by Drummond Reed. Drummond would be on this call, but he's in Sacramento today. Um so we'll be just uh um using theirs. The their workg groupoup started a year ago. So they're reasonably mature and we're just going to um uh make use of uh the the sort of templates that they've already got. We get a lot of support from Linux. um the well the zoom recordings and the calendaring and the um the there is also um a confluence uh workspace that we can we can um uh use and then um but we also get the brand of Linux and the credibility of Linux which is super important and I think that the thing we're working on now this uh the virtual private knowledge is a missing a missing link in the trust fabric of um of AI itself. Okay. So um we will we will look at um uh the the charter um and the the IPR terms um and then talk about you know workg groups are long uh lived entities but they spawn task forces which have got very timebound goals. [snorts] And so we we define three task forces within the work group and um I'll talk more about those in a bit. And then we'll start delegating. Okay. Maybe nominate um uh uh owners. We we don't have to do it on this call, but um that that's the aim. we need to have owners of each of the task forces and uh and we'll we'll then that that's a way of kind of delegating um authority and and and and spreading the load and then um then a Q&A and then we'll we'll wrap up. Okay. So, let's let's quickly go through this. I'm the chair uh self-appointed but um uh we we we should um uh visit that question because we got some other heavy hitters that have joined early on. Bruce Schneij is um the renowned cryptographer. he would also have been on this call except he's got a a conflicting um uh meeting and so uh but but I met him in uh in Los Angeles and uh he very much wants to be part of this um uh movement. Okay. Um Mitch Travis is co-chair. Mitch, you're you're okay with that role uh amongst all your other >> Yes, I do tend to take on a bunch of co-chair positions, but happy to. >> Right. >> I think this is really important. >> Um, Singularity Net is is one of the founding members. Um and uh we we hope to to learn from them and and Ben Girtzel himself actually wrote quite a bit about uh his ideas around homamorphic encryption and the ways in which we could um uh we could solve it um more rigorously. and I appreciate his brain power being lent to to this endeavor. Um, Solomon Satari is the director of research at Quai. He's got a conflicting meeting so he can't join. >> I I am here actually. >> Oh, he is there. His camera is off. Hey, Solomon. How you doing? >> Oh, my I think my camera's on too. I think I I didn't maybe create my account yet or something, but I I typed in my name, >> put as my or I can see you. >> Okay, >> we see you. Thank you very much. Why don't you introduce yourself? >> Yeah, I popped in like I popped in like almost five minutes late, so it's that's my fault, but um yeah, appreciate the intro. Um I'm uh working at Kai as Raza mentioned in director research and uh mainly interested in the um homorphic encryption part this group. So that's that's what I'm uh contributing and uh I think I'm also co-chair. I may or may not be coaching. Yeah, we should we should uh um you're you're co-chair as well. Okay. But maybe what we should do is get is is get some uh from from within Singularity. We'll see um who else wants to participate within your organization, Sandra. And um there's going to be plenty of uh work to do. Tom Joy is also a choir member. Not sure if he's on the call. I don't see his face, but uh he he um he is active on the W3C and he's active within Kawaii. And so uh he's he's useful to have on this call for um helping bridge similar um security uh initiatives that are going on in other organizations. Okay. So let's just be clear on terminology. We get we get um held up on this quite a bit. We should probably refer uh refrain from using the word homamorphic encryption and and just be be careful to use partial homomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomorphic encryption. Uh a I' I've just been pulled up on it many times when when um when filing uh when when when talking about this publicly. Um, we're not aiming to solve generalized confidential compute. Um, that's a great worthy long-term goal. Um, that NIST is in fact um, uh, running a confidential compute uh, initiative and a call for uh, proposals. That's solving a bigger problem than the one we're trying to solve. We're trying to solve the problem of the privacy of individuals data of personal data um or company data when um when you engage with third-party untrusted um AI services and specifically we're focusing on the um on the repository of of knowledge. So we call it VPK deliberately to mimic VPN because we see it as a firewall. We see it as um uh a network component that could sit at the boundary of your trusted um uh perimeter and anything that crosses that perimeter goes through the VPK um and is scrambled such that it it is it remains scrambled in situ in at rest uh on an untrusted service provider. that service provider can provide service, you know, their fast infrastructure, their fast compute, their massively redundant storage and all the things that you want to rent from um third party systems where you don't have the infrastructure yourself, but you don't also want to donate to them your intellectual property and your personal private data. So the role of VPK is to provide that mathematical security. Okay. So, um we should also um I I sort of uh um cheekily suggested that we're building SMCP early on and uh the Linux Foundation took umbrage to that. They said, "Well, we now own the trademark of MCP and we prefer it if you don't infringe on that trademark." So, for now, we're not going to have that argument, even though it's been the tradition within the internet to put an S in front of insecure protocols um to make them secure. Uh FTP has SFTP. Um the shell has SSH with an extra S in front of it. Um all sorts of, you know, the copy program CP. >> No relitigating in this. >> No, you're trying not to do this. remember >> trying not to relitigate. Okay. And and and buddy in here is Steve Vitka. Steve, why don't you introduce yourself? >> Yeah. So, I am Quai's head of policy and I am trying to formulate policy that will allow all the stuff that's been going on with hugging face and so forth not to happen anymore. Because instead of a a rogue agent society being built, we can instead build a responsible fiduciary agent society. >> Great. Let's take an extra pause there. I see some more people have joined and Myra, if you could add them to the roll call. We also have um Scott Blie. Scott, tell us introduce yourself. >> The first thing I want to say is Steve, I really appreciate the way you expressed that the fiduciary agent. That's pretty it's pretty phenomenal way to get that point across. Um I'm Scott Bllye. I've been lightly involved with Quai. Maybe that's even a generous way to put it. Um but I'm I've I've been a fan and I've been looking for the the the right opportunity to dive in more deeply. Uh happy to be a part of this. I'm not a cryptographer, so I'm not exactly sure what uh what where I'm going to fit in this particular puzzle. Uh but I'm here for it. I'm involved with postquantum cryptography not in the um academic sense but in the how do we help organizations establish um proper procedures and runbooks and risk management methodologies in order to uh deal with these challenges. Um I've been in IT forever uh security for quite a long time. Um I currently primarily function as a VC so and as a consultant and and run projects and uh etc. So here to here to help however I can. >> Thanks so much Scott. Great great to see you. Thanks for joining the call. We also >> John Vicaro on the call. John, why don't you introduce yourself? >> Good morning everybody. Um I'm the plumber in Quai. I keep the pipes uh hopefully clear and running. Um before I retired, I was doing basically that same thing. Uh I've been a contractor. I've been a director of IT um in various roles. So um but my role here at Quai is to watch the infrastructure to help plan infrastructure expansion. Um I work with Darren on deployments. Um, so and I'm also involved in some of the back office stuff. So, um, I'm a little I wear a couple of hats. >> Definitely the plumber and the guy that that just keeps keeps the the the the trains on the track. Thank you very much. Um, okay. So, let's let's uh let's briefly let's continue here. Um, so we're just clear, but I I I appreciate Steve actually uh created a um a dictionary of terms and we probably for this work group, we're going to need a dictionary of terms because there lots of terms that can fly about and we need just make sure that we're honest uh and we're using the right terms and we're communicating effectively amongst each other. So that's probably one of the first delegations and I know it's the thing that Steve loves to do is create taxonomies and uh so that we're all talking the same stuff. We're not talking over each other. Thanks so much. Um okay. So uh we think that actually and this is actually in discussion with Steve. He pointed out that actually the brief is broader than MCP. It's not just um the the model context protocol. It's not just the way that you communicate the context um to an external uh model. Uh in fact, it's it's it's more to do with securing knowledge bases. And so um I'm I'm not I'm not uh hurt about their their push back around SMCP. Okay. So, but we are we are committed to um to open source um and uh while Linux is quite flexible, they say you could have mixed motives. You could say you um yeah, you've got an open source project, but you could have um intentions to commercialize it. Um and and so those are the sort of discussions early on in the formation of of a work group that need to be ironed out. Um and we could say it's free for personal use, but commercial entities need to seek a license and that's a valid um approach that that that they they accommodate within work groups. Um okay, let's let's crack on. Um yeah, exactly. This is what we we've these are the current IPR terms that we have in place for this workg group. Um it we should leave it open to discussion for a while if there are opinions on how we should refine this. Um I'm proposing that even between now it's now you know we're we're now in September we can allow the whole rest of this year even to solidify the exact IPR terms that we are going to use. Um we don't have um sufficient voices here on the call. So we should we should u be open to to making that um flexible. Okay. Um so I talked about three task forces, three task forces um that we um we propose. One is the VPK protocol specification. It might help if I actually um if I actually talk a bit more about what VPK is and we can um actually um so if you just go and search for VPK, you'll find our white paper. And I'm going to blow that up. And let's dwell on this diagram here and maybe zoom into it a bit more. Let's go. Come on. Plus plus plus. There we go. Okay. Boom. There we go. That's That's big enough. Okay. Um, so this diagram over here shows um shows that way. No, it shows that way. There we go. It shows um the classic Alice and Bob um cast of characters. And for the last 40 years in cyber security, we've been obsessing about securing the link between Alice and Bob. Bob's the data owner, the custodian of the data. Alice is someone that's trying to communicate with Bob and access the data. They trust each other. But in the middle comes Eve. Eve is the eavesdropper that is either playing a man-in-the-middle attack or um or just eavesdropping, wiretapping the line. And for the last 40 years, cryptography and and cyber security has been about trying to secure the pipe between Alice and Bob. It's not it's not uh been about securing the data at rest. Um, Alice trusts Bob, Bob trusts Alice, uh, but Eve gets in the middle and I think the Eve problem is largely solved. Um, so for Alice, Alice thinks as Bob as her service provider and trusts Bob and um is now not worried about the threat that Eve poses. But there is a threat and the call is actually coming from within within the house within Bob's house. Bob does not have the infrastructure to for instance allow natural language search of a multi-ter knowledge base. It's just too much. He wants to be able to do that, but in order to in order to do that, he has to outsource that capability to a third party. So Bob could be a doctor with um a thousand patients records, 10,000 patients, multi- terabytes of of clinical notes and uh all all of the intensely private HIPPO protected um uh material. He wants to be able to search up the natural language. He sends it to a service provider called Sam. Sam represents service and malice. Um Sam's motives are not the same as Bob. Sam's professed business model is that any data that gets sent to him is is to resell to uh mine for advertising opportunities to um to uh traine his next model even. And we see many um operators uh regarding data as their um the the the new oil. um it's theirs for the extraction and refinement. Okay. So really the course coming from in the house we really need to focus on this boundary here. The boundary around Bob. Um >> now just to be clear Sam could be as simple as something is just a cloud provider by Google or whoever. In other words it could be really supposedly innocuous looking service. We're just holding your data for you but there's all this stuff secretly in the background. Okay. It's you're absolutely right, Steve. I was filling in a grant application to the Open Technology Fund and they said, um, we want you to focus on the use cases of repressive regimes. Okay, what what does that mean? They said, well, this service operator could be well-meaning. They could be trustworthy. However, a state actor comes and approaches them with a warrant or maybe just with simple coercion to reveal confidential client information and if that information is held in clear text, that's it. You know, they they hand it over. In fact, they will be they will have to hand it over. If Bob was in fact a a defense attorney and had the client notes of all of his clients um and that case history and the communications and so on, of course, a a state actor would come and compel Sam to hand over that data. So, they could be trustworthy and the malice they represent is not their malice. It could be the malice of someone that coerces them. And the other point in in repressive regimes is Sam does not is not protected by the client attorney privilege. It does not extend to him. If this was a client and this was the attorney, the the the communications between them is is protected. But that communication here is not protected by client attorney privilege and in you know in other regimes that that is not respected anywhere. So, um, you're absolutely right, Steve. This could be a a a trustworthy act. You might think, okay, I don't trust Sam Alman. Look, it's no accident that I call this character Sam. Um, I don't trust Sam Alman. I trust Daario. But hey, you know, when Dario's company now gets owned by a private equity firm a decade from now, um, and and he's he's he's retired, um, you your data is still there and it's there forever. If you've sent it to them ever in the clear, it's there forever. And, um, you you don't have any way of calling it back. You um, that's the problem with clear text transfers. So all of SAS AI SAS services work by you having to send that data in clear text. You can't send to chat GPTO. Here's my context document. Super sensitive. Can I send it to you zipped with a password? Uh they said no. You could have to send us the password for us to be able to work on it. Okay. So that's the problem we're trying to solve. Um let me go back here to um so so that's why we need to focus on the VPK protocol specification because the trust boundary has actually moved um the trust boundary has moved um to the left. it has before. Um, Bob would just pass that data in clear text to Sam. Sam would then take the the the clear text, he would chunk it up, he would run embedding um to vectorize the data. Then he would have the data in a vector database. Bob would send queries that Alice sent. He would just simply transmit those in clear text to Sam and Sam would do the the search through the entire document set using cosign similarity and return the chunks to back to Bob and then Bob would be able to um deliver that answer to to Alice and maybe Bob runs hey a local LLM to to um massage that those those return chunks. into um an answer. But now we're saying the job of chunking and embedding now is something Bob has to do. Bob has to chunk, has to embed, has to scramble, and he has to do that locally. And so it makes zero sense if Bob has outsourced this because he doesn't have the infrastructure only to have to implement this VPK um firewall that uh is very compute inensive and uh does not allow sort of a real time uh query and response uh for the data. So when we go back here, we look at the VPK protocol specification, we need to um know that the use case is for a uh conversational speed type of interaction or faster than that. But we we need to make sure it meets performance requirements. And we need to make sure it um it accommodates the the fact that the chunking and embedding and scrambling happen client side, not server side. >> But at the same time, you're making the point that Bob doesn't have systems that are powerful enough to do all this stuff alone. >> Exactly. So, we're looking for lightweight um algorithms that um that that can support the VPK protocol. And look, we we wouldn't this this isn't an impossible dream. We've we've proposed a number of them. We've we've workshopped a number of lightweight partial homamorphic algorithms and um uh we've benchmarked vector embedding systems and we've got published articles on that already. So this has been a year or two's worth of research has been the precursor to this working group. Okay. So as well as um the uh VPK protocol specification task force um uh we will also kick off a task force around custom personal embedding. Okay. So embedding [clears throat] has been generalized. Typically you embed using a a you go to hugging face and you say okay I'm I I want to pull down an efficient um embedding model. It really doesn't take a long time to embed. It's not a comput inensive task. The models are quite small and they take chunks of text and they transform them into vectors. Um currently embedders are generalized embedders. um because both sides need to understand um the embedding format. But in this case the embedding format can be custom because the other side does not need to understand the embedding format. If both the query and the um uploaded data coming from Bob or coming through Bob um it means that Bob can control the um the embedded and it's been shown and there's literature um around it that tuning and customizing an embedder for a knowledge domain that's closer to the knowledge base um actually increases the accuracy of the um the vector search. So that's one plus. It also means that the embedded and the parameters around the embedder become part of the secret that only Bob knows. Bob never shares that embed structure the the embedder with Sam doesn't need to because both the query and the uh initial ingested document have gone through the same embedded. Okay. So we'll kick off a work group to um uh not a work group a task force to scour the literature come up with some custom embedders and uh these these become the the secrets that Bob will wield. Okay. Now there is a third task force but it's gated at the moment. it's gated by the uh by the protocol and at least we we we can't kick it off until we've got a a a VPK protocol, at least a preliminary spec. Um 30 years ago when I was a young engineer, NIST kicked off um the AES call for proposals. It was when dees um the the the current or the previous um encryption standard was running out of steam. um it was shown to be crackable and then we progressed to triple dez as a a stop gap while um this call for papers call for proposals um uh su progressed eventually n anointed one algorithm the rindal algorithm and that is now the AES um algorithm it was quickly standardized and that is what's securing the internet it's securing e-commerce it's secure banking. Um so we suggest that a similar NIST style call for proposals is needed uh in order to um move uh VPK forward. VPK is the protocol specification but the algorithms that conform to it um uh need to be identified. Turns out that the literature is full of partial homamorphic algorithms. Um we at Quai we created a number of our own. Um we then took it to the Society of Industrial and Applied Mathematics and the and we convened a work group at Pomona College um and um a couple more algorithms came out of that and then um CKKS is probably the the gold standard for homamorphic encryption and that's already in the Microsoft seal library. Um we're looking for algorithms that um are somewhere in the middle of that spectrum. Um that are practical to use that can conform to the specification and um uh and and they they don't need to be they don't need to be exhaustively sort of in CPA um compliant. They need to be just good enough. So it's not we're not anointing a single algorithm like a like NIST was. Instead what we want to do is um qualify them. We want to benchmark them. we want to uh red team and stress test them and then we can basically just put um we can just categorize the algorithms and allow the market to choose what they want to choose for their um >> and once again you're only speaking of embedding algorithms here correct >> no this this is now the PH moved on from embedding so the partial homamorphic encryption algorithms >> but okay so that's what I'm saying so You're separating it out. So you're So embedding things and then rotating transforming the embedding are two separate things. We're calling those two. >> Exactly. Yeah. >> Yeah. Okay. I My mistake was I was calling all one thing. Okay. Got it. >> Okay. >> Can I jump in for one second and and uh >> Yeah, go ahead. >> kind of do a a lay person's translation. We're running into some similar stuff in the postquantum encryption space wherein we know that quantum machines when they exist will be able to crack existing encryption. So it's very similar to the problem that we're talking about here which is we want someone to be able to work with this data but we know that maybe it's going to be crackable right we know they may be able to read it. So one of the approaches that's being taken and it's very pragmatic and it sounds if I'm inter if I'm understanding you correctly it sounds like kind of a flavor of what you're getting at which is to say that we may not be able to achieve a real AES style mathematical like assurance that this is uncrackable. But what we can do is construct a solution to the problem that reduces the blast radius of any key compromise to such an extent that it doesn't that the value of that compromise doesn't exceed the value of the effort that that goes into it. It's the same idea of putting a better lock on a door. A bad guy can still get through the lock. They're going to be able to crack it. They're going to be able to pick it. How long do you have? And then your surrounding mechanisms of having a camera, having an alarm are meant to get help there that that augments the capability of the lock. Is that kind of what you're getting at with the good enough idea? Okay, >> you're you're absolutely correct. Um it's it's uh I guess the economics of hacking. You know, you would you would target a hacker would target um you know, a massive honeypot where they need to crack it once and then they've got access to all the data. And the easy things if you if you say, well, if you hack this, you've only hacked it for one >> session or for one customer or Yeah. then then it's then it's not a scalable hack for that. >> And it's also that the data isn't revealed in that sort of binary way. You have, you know, an inference about the data. Remember, you're you're trying to infer what the embedding algorithm is. So, as a result, the results you get are only inferences at the end anyway. You only have a certain you can't be sure that that's what it actually says ever. Really, >> your your point is is is correct here. In fact, when we go back here, um when uh part of the protocol is um Bob sends scrambled vectors to Sam, Sam stores them. Later on, Alice issues a query. Bob scramles that query knowing what the relevant key is to to Sam. When Sam searches through the terabytes of records, Sam does not return the chunks. Sam returns the index of the chunks with the similarity scores. So the data never travels back on the return wire, but the index of of the database record comes back. Sam's already got the original copy here. Knows the mapping between the original data and the um the >> You mean Bob does? You said Sam. You know, >> sorry. Sorry. You're right. Bob does. Bob knows that. And so the reordering of the records becomes part of the key material that that Bob wields. >> That's almost a tokenization then, isn't it? >> It is. It is. Yeah. And and so even a a man-in-the-middle attack here, if Eve were to try and intercept this, Eve would not be able to glean. Well, we need to we need to rigorously quantify what Eve can glean. And then the other strategy is to have multiple SAMs is to shard the data across multiple SAMs such that you can have a different key for each one. And so to your point, Scott, about a scalable hack, um it would require massive collusion between all of these SAMs in order to um in in order to uh um uh piece back um and and reconstruct the the knowledge base if they did manage to crack one. >> Can I just make a point here? >> Yeah, go ahead. >> All right. So basically there going to be two different types of setups in this situation. So Bob can either keep his own, you know, chunks so that the baseline data on his own stuff and he's only using SAM to help him do a distributed vector search at a quicker speed. or you can keep those chunks with SAM, but they have to be encrypted in a different encryption uh methodology so that Bob can then identify them, pull them back from SAM and then decrypt them locally. So there's those two different setups >> that yeah, that that could work as well. You're right. Um and >> let me ask one one question and I may be jumping ahead. [clears throat] >> Yeah. For inference to work though, the LLMs need to be able to understand the text that's being processed in order to do their um let's say statistical analysis of where this text appears next to other text. And so understanding encrypted text and how that relates to other unencrypted text sounds like the point where this falls apart. Now that's a later problem. >> It's you're right, the chat completion part is a later problem. So, at the moment, we we're focusing on securing the entire knowledge base, not the individual chat completion um requests, which might reveal a little bit. Now, one uh way that Bob could solve that is by running an LLM locally. um uh now that he might not have sufficient compute for that. I mean but but you know he's got Mo's law on his side and and uh that might not be the the problem of scalability but okay so um I was speaking with Ben Girtzil at the at the conference and I said okay here's what we've solved already we think we've solved the retrieval part of rag but we haven't solved the generation part of rag the the inference section um how would you approach it and he went silent for a and uh then after the conference he sent me a very long uh essay on you know ways that he'd approach it. I think we've got some techniques within quet to approach it um with our distributed LLM where we shard the LLM inference across multiple nodes. Um and we can leverage the unexplainability of the neural network. Uh, as you get deeper into the network, you start up where I'm I'm gonna um run the first few blocks of my um of the of the uh of the LLM inference and the last blocks, but then they follow a circuit through different nodes of various trust levels and um we're going to see we need to quantify whether that is hackable uh and to what level it's hackable and what level of collusion is needed. But you're right, VPK is not at the moment, its scope is not to focus on the chat completion problem. We could kick off a task force um to to solve secure inference. Uh I think we need to get this first part, the retrieval part nailed down and then go after secure inference and that could be our fourth um task force. >> Really, I know it's an adjunct, but I'd love to read that essay. Um, you know, we've had some conversations about that and I I I I don't have any core answer to uh uh the the homamorphic inference >> right question right now. >> Yeah. Yeah. You you're actually we don't have an answer for it because at the moment LLMs are written where your prompt that goes into the the input layer is in clear text and the output is in clear text. There's no mechanism for having um encrypted weights and where you pass an encrypted prompt and it gives you an encrypted answer back uh and then you get to decrypt it. If I could add something here. >> Part of the research that I'm doing is not on the first prompt but there there is a way that you can build like the opposite the inverse of a zero knowledge proof where you have the prover and the verifier separated and both of them hash um their understanding of that um inference or prompt. And then in the future once trust is established between those two agents they can just share the hashes and they can know that each other that hash equals that full document of information. So that kind of gets into this like SAM side of the um scrambling and the and the hashing. That's something I've been I've been working on and built a harness around that sort of verifiability um of the knowledge and agree with a lot of the statements people have um made prior that we need to focus on like the not having like a one-sizefits-all encryption that solves this but being sort of iterative on using techniques like obfiscation as well in the middle and making the bits and the bites just like when you do have an attacker making the yield so low that it becomes like an economic thing. Even if they've got the compute of the universe, they don't see a point in attacking that. >> Right. So, um Mitch, I'm I'm looking forward to that. So, two things down. Yes, >> if if I want to let me just tie it in correctly. So, so two things that I want to also mention in this call. Um, I'd like for us to come to a decision on how we communicate using AI agents early on. Um, if there's going to be some Yeah, within the group, if there's going to be some sort of spec or repo or something like that. Um, I've got a bunch of agents that have different protocols and discussion systems for for governance that I'd happily propose, but we need to make that a discussion that we decide on um early on. Uh cuz things go really quickly if you start having our agents talk to each other, but then it gets into like a different language altogether and we end up becoming translators in working group calls. So, just want to put that on the table early on. Um, but I think it's important that we do sort of build this with agents in mind in tandem and have our agents like doing a weekly VPK sync of the discussions and pulling in our own private virtual knowledge stores, right? And pro providing inference and insight in that way. So, want to include that. Um, and I think that that pretty much summarizes the the outcomes that I I was thinking. Mitch, I think that's really important. Um, so we do have a VPK workg groupoup um channel on Slack. Um, what I'm proposing is that we develop an automation and that that Slack has the sort of automation harness already. Um, and I've integrated Claude into Slack. And so that's like a a general integration and to take the Zoom recordings uh of of each of our meetings and our discussions and just create summaries so so they can go in but also um uh just keep the the the follow-up going. I love what what Singularity has in their Slack um group. They've got Hugo. Hugo is their um automated bot that is is in there. It's a bit chatty [laughter] and and a bit naggy and you know, but it keeps it keeps the conversation going and uh and but but but follows up with individuals as well. Um and I think we've got uh the capability of uh of doing the same thing um with Claude and Slack. Um >> yeah, >> and also if if the spec ends up in GitHub, we can follow suit of the way that GitHub discussions >> um can be kind of controlled by AI in a way. >> I've just had a good experience in the >> um trust over IP um working groups when that's been adopted. >> Yeah. So the GitHub conversations um and that opens it up to a broader audience rather than the fairly closed internal Slack conversations. Um and so yeah I've uh >> yeah I've also had good experiences with trust IP GitHub discussions. Okay. So, GitHub's also one of the we we've currently got our own GitHub repo, but u this work will continue now uh under the um Linux Foundation's GitHub repo. That's all part of the logistics we need to set up over the next week or so. Um so, a couple of um items to three items to follow up on. Uh, one is we should probably um take the white paper that's on the website now and um start marking that up and and have a revised version, but now it's under the workg groupoup governance and um it should it should incorporate all of the the recent thinking that that white paper that's on the website um is something that was written um three months ago, maybe even six months ago. So, it's it's a bit dated. Um, and we can we can bring it up today. >> And I actually just started messing around with the website a little this morning. So, get the exact text you want to describe the this workg group because I think that needs to go on the homepage. >> I think you're absolutely right. I think we need to, you know, really super crisp mission statement. Um, and we're still in the phase where we are recruiting founder members. I'd like to get some heavy hitters. We've got a handshake agreement with OWASP to join. Um and uh but that's the OWASP LA chapter. I'd like to get the national OWASP um Steve Wilson to to be part of this. And then let's see if we can get I don't know a vector database company like Quadrant that offers Quadrant in the cloud to to be the test case to show hey our vector database in the cloud operates perfectly when the client has got VPK running. The idea is that >> yeah it requires no accommodation by the service provider. >> No accommodation no integration necessary. It just works and um that would be a great test. Jordan Jordan just had um I don't remember if you were there that night, but he at the DevOps LA meetup, he had a >> Pine Cone. >> Yeah. Yeah, exactly. Yes, he had. >> I'd love I'd love an intro. So, Pine Cone is a non-opensource I think they're closed source, but but still it should it should just work. So, I'd love an intro to the Pine Cone guy. I think he did send me an intro actually. >> Okay, good. >> So, I I'll follow up there. Okay. So, logistics, Dave Boswell and Minu are people to follow up with. Um, I think Myra, if you could take on one of them. I'll take on I've got a call scheduled with Dave Boswell for tomorrow. Um and then um Myra, I'll I'll I'll invite you to that call as well, but we should probably also get um a call with Minu um about all the other infrastructure um logistics that of of around the work group. Okay, we we are we are nicely at time. There's five minutes of Q&A left and then and then next steps. Okay. So, let's let's just dwell on the Q&A. Are there any questions? I know Sandra, you've been silent throughout this. Does is is Singularity on board with >> uh Yes. So, I was taking all in. I know that some of the team members that you're going to be talking with in two hours have more background. So I was trying to understand, you know, everything from from the foundations up. >> Fantastic. Thank you so much. And I really appreciate um the enthusiasm that Singularity has shown uh in in in all of this and I think we we are uh going to be doing something important for the industry. Okay. Um let us let's see who have we not heard from actually Mitch um normally you you >> perhaps yeah a good visualization of what we're trying to do is needed and maybe you can just uh >> us with um >> the source cooking recently. I'm going to stop sharing. >> Um, so VPK here, I'll give this one uh so I've built a wiki space and this wiki space is kind of it's a public private knowledge space, but there are actually two. So there's the localhost version of the federated wiki and then there's the public version of the wiki which is like a HTML snapshot of what is a local um federated wiki that is just yeah wiki structure um but I've actually visualized it in a way that I've um given some sort of tourist space geometry using these six um categories. The gates is the boundary agent, skills is the delegation agent, the harness is the compute, the cannon is the memory, the federation is kind of the connections. So all of us here and then the agreements. So the value agreements are also synonymous with links in the sort of guide or the wiki space. Um so this then creates these sort of unique patterns of pathways through knowledge base. Mhm. >> And when you can generate a pathway through a knowledge base on a Taurus, um you get cool maths. And when you compress things to cool maths, then you can turn it into these sort of um spliced and and diced information packets that Sam is interested in trying to trying to attack, but has a problem when attacking. um the transition between when it goes to like the Taurus four or 5D geometry and then just the 2D map. It's also interesting to see. So you can see like the the boundaries are still the boundaries. The skills are still the skills and this creates like a notion that you based on where within this sort of knowledge base >> that was some sort of dimensionality slider that you had going on there. Yeah. Yeah. Yeah. Yeah. It's kind of It's kind of fun. Right here, I'll I'll zoom in on the so you can see the the golden ratio moment. So, they kind of fold in on each other in order to create the um Taurus shape. So, then they're >> But okay, so the Taurus shape has how many dimensions? >> It's six or Yeah. >> Okay. I think >> it's five or six D space, but I could be wrong. You should double check. I'm pretty sure it's six. And >> And somehow this is smooth. So you've got fractional dimensions somehow being represented, too. Okay. >> Yeah. And it's it's about Yeah. pathing through um on this dimensional dimensionality and then changing it in order to so this is like the pattern and all you do is share the pattern through the knowledge base and then the the LLM is going to be able to be like oh yeah ABC I can actually record the runtime for example this dot here if an MCP server was observing this um I could record that I observed this pattern for a certain amount of time which means that my agent was consuming these particular documents in this particular order through the wiki space. Um and that adds to some qualities in the governance of the data and the information and like how much you trust the agents computing the right thing on the right path. Um >> right. So then the agents in the future instead of just sharing >> hashes that point to chunks can now share hashes that point to pathways and so forth you get another layer of of compression and inscrutability. Got it. >> Yep. And then it's the trajectory based on that current state of the private knowledge base which then creates even more obiscation for like when the knowledge base changes in the future and we get this like step change in signatures being used. It's like the well that was only for this version. I add like 10 extra wikis and I tend to add on average like 30 wiks a week to the research knowledge base. That means I'm versioning the like hash pathway but there is still this like provenence chain of um these like trajectories through. So these are all like just So here's an example of just a pathway through like I would just hyperlink all the way through. >> Last time and I've got >> Yeah, sorry. Things get exciting when I start showing. >> Let's just wrap quickly. Um, thanks so much everybody for um for participating on this kickoff call and um we're confirming a weekly cadence of this meeting at this time slot, the 9:00 a.m. time slot. Um and uh you'll find it on the Linux Foundation um calendar, but it's also publicized elsewhere. Um thanks so much. I will um distill this into some minutes and they'll be posted in the VPK Slack channel, but I'll also email them out to all of you. Thank you very much. I'm going to hop on to our intern group which is waiting for me now. >> Just good clarity. So, a Taurus is actually two-dimensional object lives inside a three-dimensional and fourdimensional space. >> Thanks so much. Cheers everyone. >> Keep on. [laughter] It's a wrap.