Virtual Private Knowledge Working Group (VPK WG) community call - 2026/09/14
Watch on YouTubeVideo summary
The Virtual Private Knowledge Working Group, hosted jointly by the Linux Foundation and the Trust Over IP Foundation, officially launched its inaugural call to establish a specialized initiative focused on securing personal and corporate data when interacting with untrusted third-party AI services. Led by Chair Reza Rasul and Co-Chair Mitchell Travis alongside other key participants from organizations like Singularity Net and OWASP, the group's primary mission is to construct a digital "firewall" that shifts the trust boundary to the client side. This approach ensures that sensitive information remains scrambled locally before transmission, effectively preventing malicious actors or state coercion from accessing raw intellectual property or personal data. To achieve this, the working group has defined three core task forces: developing lightweight algorithms for client-side chunking and scrambling that meet conversational speed requirements without heavy infrastructure; creating custom personal embedders where the embedding structure remains a secret known only to the data owner; and establishing a future qualification process to benchmark partial homomorphic encryption algorithms similar to NIST's AES standards, allowing market selection rather than mandating a single solution.
The technical discussions clarified that the group focuses specifically on "partial homomorphic encryption" rather than generalized confidential compute or the Model Context Protocol, acknowledging current challenges in securing LLM inference while prioritizing the security of knowledge base retrieval as an immediate goal. The conceptual framework for this system visualizes knowledge pathways through six distinct categories: Gates acting as boundary agents, Skills serving as delegation agents, Harness representing compute resources, Cannon functioning as memory, Federation managing connections, and Agreements defining value links. These elements generate unique patterns within a "tourist space geometry" that can be compressed into mathematical representations, facilitating smooth transitions between higher-dimensional geometries and standard 2D maps while maintaining distinct boundaries. This compression enables the creation of spliced information packets that record agent runtime and document consumption order via MCP servers, thereby enhancing data governance and trust in agent computations through fractional dimensions and obfuscation techniques that account for versioning changes.
To ensure the longevity and effectiveness of these initiatives, the group plans to transition its governance to a Linux Foundation GitHub repository while leveraging existing resources like Confluence and Zoom for collaboration. Strategic logistics include setting up Slack Connect with Singularity Net, updating their white paper, and seeking partnerships with vector database providers such as Pinecone and Qdrant to facilitate testing environments. The working group also intends to recruit founder members from various sectors and propose the use of AI agents to automate meeting summaries and governance discussions, streamlining administrative overhead. By confirming a weekly cadence for meetings at 9:00 a.m., with minutes distributed via the Linux Foundation calendar, Slack, and email, the group has laid a robust foundation for ongoing collaboration. Ultimately, this initiative aims to empower data owners by ensuring that their proprietary knowledge remains secure and private even as they leverage powerful external AI capabilities, marking a significant step forward in the evolution of trustworthy artificial intelligence ecosystems.
Read the full video transcript
Oh, we got some audio issues. Hang on a
second.
Let's see. I'll be right back.
Good morning.
Good morning. Happy Monday.
>> Happy Monday morning.
>> Good morning, Myra.
>> How you doing?
>> All right, there we go. Should be able
to get
>> So, this Zoom meeting is controlled by
the Linux Foundation. So, I was trying
to make Myra the co-host, but I don't
seem to be able to do that.
>> This is this part of the logistics we
need to figure out. Good morning,
Darren. Happy Monday. Good morning.
>> Let's wait for folks to roll in.
>> Um yeah, I think I need to
get um
the Slack channel
and and add people to it,
>> right? As people join here.
>> Mhm.
>> Yeah.
Let's just see if I can share.
Gosh, where do you stand in order to not
be in the way of the text? Okay. Um,
and I'm gonna just get ready. Great.
And let's see
what else.
>> It looks like everyone is already in the
VPK. Um, I I I'm not sure if I'm uh met
Sandra before.
>> Hi, really nice to meet you. I'm from
Singularity Net. I did mention to our
team that the call is ongoing. They have
all the links, but I don't know if
they're going to be able to make it. So,
good thing that it recorded.
>> And and I missed uh from from what your
affiliation was. Sorry.
>> Singularity.
>> Singularity. Gotcha. Gotcha. Okay. Thank
you. Nice to meet you, too.
>> Sandra, what we should do is um uh in
our Slack, we've both got different
Slack accounts um or Slack um yeah,
Slack groups. So, what we should do is
do that uh Slack Connect where all
Singularity members and all choir
members can be connected in a channel.
So, we need to figure that out. Um but
we've done that for different partner
organizations.
>> Yes, we can discuss that on the call
that we have today in 3 hours I believe.
>> Fantastic. Okay.
>> All right.
>> Well, very good. I'm going to kick off
um in the interest of time. Um and and
we're recording here. So, uh welcome
everybody. This is the kickoff meeting
for virtual private knowledge. It's a
work group under the Linux Foundation
under the Linux Trust Over IP
Foundation.
Okay. So, um I've got a short deck that
um will hopefully um uh explain what
we're going to go through today. Um it's
a welcome, it's a roll call. Um so,
let's just quickly take a roll call. My
name is Riza Rasul. I'm chair of Kai. Um
um and each of you should should
introduce yourselves.
>> Hi, I'm Darren Warner. Um I'm a a chief
technical architect in my uh day job and
um I've uh [sighs]
known Ki for many years now. Reza, you
and I go the lead code contributor.
Thank you so much.
>> Okay, who who's up next?
>> All right, I'm Jerome Mchuan. I'm
director of partnerships for Quai.
>> Thanks so much. Okay.
And
>> hello, I'm Mitchell or privacy mage. Um
I've been sort of I'm the privacy guy.
I'm interested in zero knowledge proofs
and um virtual private networks in that
sense and contributed to quai
contributed to trust over IP um as well.
So
>> fantastic adra.
>> Yes. I'm Myra Quaja. My day job is a
service delivery manager at TransUnion.
Um, and at Quai, I wear a lot of
different hats. Um, I'm one of the
officers of the board. Um, I'm involved
in the um,
uh, intern program, a lot of onboarding
meetings,
name it, I I I probably do something.
>> Yeah. In fact, Myra is the go-to person
where we've got uh administrative issues
>> and and if I can't help you, I'll know
at least who to point you to.
>> Fantastic. And and Sandra, you're you're
perhaps a quick word of introduction
from yourself.
>> Absolutely. So, I work in operations
helping on the partnership front at
Singularity and we were, you know, the
co-organizers of AJ26. So, we had the
opportunity to have you Reza as one of
the speakers.
>> Thank you so much. I enjoyed that. That
was a week-long immersion into the whole
area of gosh of of AGI and various
neuroscience and cognitive uh theories.
And we learned a lot from that. We're
we're largely computer scientists and
we're learning from the the folks in the
neuroscience and the biological and the
life sciences. Okay. So glad to have
you.
>> Yeah. Thank you so much. Roll call.
Done. Okay. So
as any organization starts we need to um
uh develop a all the ground the founding
documents like let's let's lock in on
what is our actual mission and make sure
we don't have mission creep um
uh all the sorts of things we need to um
adopt um bylaws and and uh make sure
we're we're talking with the same
vocabulary. So, it's probably useful to
do terminology. The great thing is that
we don't have to invent this all from
scratch. There is a sister organization
within Linux, and I'm just going to
borrow their template. And so, um, LFDT
uh um so Linux Foundation decentralized
trust working group is run by Drummond
Reed. Drummond would be on this call,
but he's in Sacramento today. Um so
we'll be just uh um using theirs. The
their workg groupoup started a year ago.
So they're reasonably mature and we're
just going to um uh make use of uh the
the sort of templates that they've
already got. We get a lot of support
from Linux. um the well the zoom
recordings and the calendaring and the
um the there is also um a confluence uh
workspace that we can we can um uh use
and then um but we also get the brand of
Linux and the credibility of Linux which
is super important and I think that the
thing we're working on now this uh the
virtual private knowledge is a missing a
missing link in the trust fabric of um
of AI itself. Okay. So um
we will we will look at um uh the the
charter um and the the IPR terms um and
then talk about you know workg groups
are long uh lived entities but they
spawn task forces which have got very
timebound goals. [snorts] And so we we
define three task forces within the work
group and um I'll talk more about those
in a bit. And then we'll start
delegating. Okay. Maybe nominate um uh
uh owners. We we don't have to do it on
this call, but um that that's the aim.
we need to have owners of each of the
task forces and uh and we'll we'll then
that that's a way of kind of delegating
um authority and and and and spreading
the load and then um then a Q&A and then
we'll we'll wrap up. Okay. So, let's
let's quickly go through this. I'm the
chair uh self-appointed but um uh we we
we should um uh visit that question
because we got some other heavy hitters
that have joined early on. Bruce Schneij
is um the renowned cryptographer. he
would also have been on this call except
he's got a a conflicting um uh meeting
and so uh but but I met him in uh in Los
Angeles and uh he very much wants to be
part of this um uh movement. Okay. Um
Mitch Travis is co-chair. Mitch, you're
you're okay with that role
uh amongst all your other
>> Yes, I do tend to take on a bunch of
co-chair positions, but happy to.
>> Right.
>> I think this is really important.
>> Um, Singularity Net is is one of the
founding members. Um and uh we
we hope to to learn from them and and
Ben Girtzel himself actually wrote quite
a bit about uh his ideas around
homamorphic encryption and the ways in
which we could um uh we could solve it
um more rigorously. and I appreciate his
brain power being lent to to this
endeavor. Um,
Solomon Satari is the director of
research at Quai. He's got a conflicting
meeting so he can't join.
>> I I am here actually.
>> Oh, he is there. His camera is off. Hey,
Solomon. How you doing?
>> Oh, my I think my camera's on too. I
think I I didn't maybe create my account
yet or something, but I I typed in my
name,
>> put as my or I can see you.
>> Okay,
>> we see you. Thank you very much. Why
don't you introduce yourself?
>> Yeah, I popped in like I popped in like
almost five minutes late, so it's that's
my fault, but um yeah, appreciate the
intro. Um I'm
uh working at Kai as Raza mentioned in
director research and uh mainly
interested in the um homorphic
encryption part this group. So that's
that's what I'm uh contributing and uh I
think I'm also co-chair. I may or may
not be coaching.
Yeah, we should we should uh um you're
you're co-chair as well. Okay. But maybe
what we should do is get is is get some
uh from from within Singularity. We'll
see um who else wants to participate
within your organization, Sandra. And um
there's going to be plenty of uh work to
do. Tom Joy is also a choir member. Not
sure if he's on the call. I don't see
his face, but uh he he um he is active
on the W3C and he's active within
Kawaii. And so uh he's he's useful to
have on this call for um helping bridge
similar um security uh initiatives that
are going on in other organizations.
Okay. So let's just be clear on
terminology. We get we get um held up on
this quite a bit. We should probably
refer uh refrain from using the word
homamorphic encryption and and just be
be careful to use partial
homomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomomorphic
encryption. Uh a I' I've just been
pulled up on it many times when when um
when filing
uh when when when talking about this
publicly. Um, we're not aiming to solve
generalized confidential compute. Um,
that's a great worthy long-term goal.
Um, that NIST is in fact um, uh, running
a confidential compute uh, initiative
and a call for uh, proposals. That's
solving a bigger problem than the one
we're trying to solve. We're trying to
solve the problem of the privacy of
individuals data of personal data um or
company data when um when you engage
with third-party
untrusted
um AI services and specifically we're
focusing on the um
on the repository of of knowledge. So we
call it VPK deliberately to mimic VPN
because we see it as a firewall. We see
it as um uh a network component that
could sit at the boundary of your
trusted um uh perimeter and anything
that crosses that perimeter goes through
the VPK
um and is scrambled such that it it is
it remains scrambled in situ in at rest
uh on an untrusted service provider.
that service provider can provide
service, you know, their fast
infrastructure, their fast compute,
their massively redundant storage and
all the things that you want to rent
from um third party systems where you
don't have the infrastructure yourself,
but you don't also want to donate to
them your intellectual property and your
personal private data. So the role of
VPK is to provide that mathematical
security.
Okay. So, um
we should also
um I I
sort of uh um cheekily suggested that
we're building SMCP early on and uh the
Linux Foundation took umbrage to that.
They said, "Well, we now own the
trademark of MCP and we prefer it if you
don't infringe on that trademark." So,
for now, we're not going to have that
argument, even though it's been the
tradition within the internet to put an
S in front of insecure protocols
um to make them secure. Uh FTP has SFTP.
Um the shell has SSH with an extra S in
front of it. Um all sorts of, you know,
the copy program CP.
>> No relitigating in this.
>> No, you're trying not to do this.
remember
>> trying not to relitigate. Okay. And and
and buddy in here is Steve Vitka. Steve,
why don't you introduce yourself?
>> Yeah. So, I am Quai's head of policy and
I am trying to formulate policy that
will allow all the stuff that's been
going on with hugging face and so forth
not to happen anymore. Because instead
of a a rogue agent society being built,
we can instead build a responsible
fiduciary agent society.
>> Great. Let's take an extra pause there.
I see some more people have joined and
Myra, if you could add them to the roll
call. We also have um Scott Blie. Scott,
tell us introduce yourself.
>> The first thing I want to say is Steve,
I really appreciate the way you
expressed that the fiduciary agent.
That's pretty it's pretty phenomenal way
to get that point across. Um I'm Scott
Bllye. I've been lightly involved with
Quai. Maybe that's even a generous way
to put it. Um but I'm I've I've been a
fan and I've been looking for the the
the right opportunity to dive in more
deeply. Uh happy to be a part of this.
I'm not a cryptographer, so I'm not
exactly sure what uh what where I'm
going to fit in this particular puzzle.
Uh but I'm here for it. I'm involved
with postquantum cryptography not in the
um academic sense but in the how do we
help organizations establish um proper
procedures and runbooks and risk
management methodologies in order to uh
deal with these challenges. Um I've been
in IT forever uh security for quite a
long time. Um I currently primarily
function as a VC so and as a consultant
and and run projects and uh etc. So here
to here to help however I can.
>> Thanks so much Scott. Great great to see
you. Thanks for joining the call. We
also
>> John Vicaro on the call. John, why don't
you introduce yourself?
>> Good morning everybody. Um I'm the
plumber in Quai. I keep the pipes uh
hopefully clear and running. Um
before I retired, I was doing basically
that same thing. Uh I've been a
contractor. I've been a director of IT
um in various roles. So
um but my role here at Quai is to watch
the infrastructure to help plan
infrastructure expansion. Um I work with
Darren on deployments.
Um, so
and I'm also involved in some of the
back office stuff. So, um, I'm a little
I wear a couple of hats.
>> Definitely the plumber and the guy that
that just keeps keeps the the the the
trains on the track. Thank you very
much. Um, okay. So,
let's let's uh let's briefly let's
continue here. Um, so we're just clear,
but I I I appreciate Steve actually uh
created a um a dictionary of terms and
we probably for this work group, we're
going to need a dictionary of terms
because there lots of terms that can fly
about and we need just make sure that
we're honest uh and we're using the
right terms and we're communicating
effectively amongst each other. So
that's probably one of the first
delegations and I know it's the thing
that Steve loves to do is create
taxonomies and uh so that we're all
talking the same stuff. We're not
talking over each other. Thanks so much.
Um okay. So uh
we think that actually and this is
actually in discussion with Steve. He
pointed out that actually the brief is
broader than MCP. It's not just um the
the model context protocol. It's not
just the way that you communicate the
context um to an external uh model. Uh
in fact, it's it's it's more to do with
securing knowledge bases. And so um
I'm I'm not I'm not uh hurt about their
their push back around SMCP. Okay. So,
but we are we are committed to um
to open source um and uh while Linux is
quite flexible, they say you could have
mixed motives. You could say you um
yeah, you've got an open source project,
but you could have um intentions to
commercialize it. Um and and so those
are the sort of discussions early on in
the formation of of a work group that
need to be ironed out. Um and we could
say it's free for personal use, but
commercial entities need to seek a
license and that's a valid um approach
that that that they they accommodate
within work groups. Um okay, let's let's
crack on. Um
yeah, exactly. This is what we we've
these are the current IPR terms that we
have in place for this workg group. Um
it we should leave it open to discussion
for a while if there are opinions on how
we should refine this. Um I'm proposing
that even between now it's now you know
we're we're now in September we can
allow the whole rest of this year even
to solidify the exact IPR terms that we
are going to use. Um we don't have um
sufficient voices here on the call. So
we should we should u be open to to
making that um flexible.
Okay. Um
so I talked about three task forces,
three task forces um that we um we
propose. One is
the VPK protocol specification.
It might help if I actually um if I
actually talk a bit more about what VPK
is and we can um actually um
so if you just go and
search for VPK, you'll find our white
paper. And I'm going to blow that up.
And let's dwell on this diagram here and
maybe zoom into it a bit more. Let's go.
Come on. Plus plus plus. There we go.
Okay.
Boom. There we go. That's That's big
enough. Okay. Um, so this diagram over
here shows
um shows that way. No, it shows that
way. There we go. It shows um the
classic Alice and Bob um cast of
characters. And for the last 40 years in
cyber security, we've been obsessing
about securing the link between Alice
and Bob. Bob's the data owner, the
custodian of the data. Alice is someone
that's trying to communicate with Bob
and access the data. They trust each
other. But in the middle comes Eve. Eve
is the eavesdropper that is either
playing a man-in-the-middle attack or um
or just eavesdropping, wiretapping the
line. And for the last 40 years,
cryptography and and cyber security has
been about trying to secure the pipe
between Alice and Bob. It's not
it's not uh been about securing the data
at rest. Um,
Alice trusts Bob, Bob trusts Alice, uh,
but Eve gets in the middle and I think
the Eve problem is largely solved. Um,
so
for Alice, Alice thinks as Bob as her
service provider
and trusts Bob and um is now not worried
about the threat that Eve poses. But
there is a threat and the call is
actually coming from within within the
house within Bob's house. Bob does not
have the infrastructure to for instance
allow natural language search of a
multi-ter
knowledge base.
It's just too much. He wants to be able
to do that, but in order to in order to
do that, he has to outsource that
capability to a third party.
So Bob could be a doctor with um a
thousand patients records, 10,000
patients, multi- terabytes of of
clinical notes and uh all all of the
intensely private HIPPO protected um uh
material. He wants to be able to search
up the natural language. He sends it to
a service provider called Sam. Sam
represents service and malice.
Um
Sam's motives are not the same as Bob.
Sam's professed business model is that
any data that gets sent to him is is to
resell to uh mine for advertising
opportunities to um to uh traine his
next model even. And we see many um
operators uh regarding data as their um
the the the new oil. um it's theirs for
the extraction and refinement. Okay. So
really the course coming from in the
house we really need to focus on this
boundary here. The boundary around Bob.
Um
>> now just to be clear Sam could be as
simple as something is just a cloud
provider by Google or whoever. In other
words it could be really supposedly
innocuous looking service. We're just
holding your data for you but there's
all this stuff secretly in the
background. Okay. It's you're absolutely
right, Steve. I was filling in a grant
application to the Open Technology Fund
and they said, um, we want you to focus
on the use cases of repressive regimes.
Okay, what what does that mean? They
said, well, this service operator could
be well-meaning. They could be
trustworthy. However, a state actor
comes and approaches them with a warrant
or maybe just with simple coercion to
reveal confidential client information
and if that information is held in clear
text, that's it. You know, they they
hand it over. In fact, they will be they
will have to hand it over. If Bob was in
fact a a defense attorney and had the
client notes of all of his clients um
and that case history and the
communications and so on, of course, a a
state actor would come and compel Sam to
hand over that data. So, they could be
trustworthy and the malice they
represent is not their malice. It could
be the malice of someone that coerces
them. And the other point in in
repressive regimes is Sam does not is
not protected by the client attorney
privilege. It does not extend to him. If
this was a client and this was the
attorney, the the the communications
between them is is protected. But that
communication here is not protected by
client attorney privilege and in you
know in other regimes that that is not
respected anywhere. So, um, you're
absolutely right, Steve. This could be a
a a trustworthy act. You might think,
okay, I don't trust Sam Alman. Look,
it's no accident that I call this
character Sam. Um, I don't trust Sam
Alman. I trust Daario. But hey, you
know, when Dario's company now gets
owned by a private equity firm a decade
from now, um, and and he's he's he's
retired, um,
you your data is still there and it's
there forever. If you've sent it to them
ever in the clear, it's there forever.
And, um, you you don't have any way of
calling it back. You um, that's the
problem with clear text transfers. So
all of SAS AI SAS services work by you
having to send that data in clear text.
You can't send to chat GPTO. Here's my
context document. Super sensitive. Can I
send it to you zipped with a password?
Uh they said no. You could have to send
us the password for us to be able to
work on it. Okay. So that's the problem
we're trying to solve. Um let me go back
here
to um
so so that's why we need to focus on the
VPK protocol specification
because the trust boundary has actually
moved um the trust boundary has moved um
to the left. it has before. Um, Bob
would just pass that data in clear text
to Sam. Sam would then take the the the
clear text, he would chunk it up, he
would run embedding
um to vectorize the data. Then he would
have the data in a vector database.
Bob would send queries that Alice sent.
He would just simply transmit those in
clear text to Sam and Sam would do the
the search through the entire document
set using cosign similarity and return
the chunks to back to Bob and then Bob
would be able to um deliver that answer
to to Alice and maybe Bob runs hey a
local LLM to to um massage that those
those return chunks. into um an answer.
But
now we're saying the job of chunking and
embedding now is something Bob has to
do. Bob has to chunk, has to embed, has
to scramble, and he has to do that
locally.
And so it makes zero sense if Bob has
outsourced this because he doesn't have
the infrastructure only to have to
implement this VPK
um firewall that uh is very compute
inensive and uh does not allow sort of a
real time uh query and response uh for
the data. So when we go back here, we
look at the VPK protocol specification,
we need to um
know that the use case is for a uh
conversational speed type of interaction
or faster than that. But we we need to
make sure it meets performance
requirements. And we need to make sure
it um it accommodates the the fact that
the chunking and embedding and
scrambling happen client side, not
server side.
>> But at the same time, you're making the
point that Bob doesn't have systems that
are powerful enough to do all this stuff
alone.
>> Exactly. So, we're looking for
lightweight um algorithms that um that
that can support the VPK protocol. And
look, we we wouldn't this this isn't an
impossible dream. We've we've proposed a
number of them. We've we've workshopped
a number of lightweight partial
homamorphic algorithms and um uh we've
benchmarked vector embedding systems and
we've got published articles on that
already. So this has been a year or
two's worth of research has been the
precursor to this working group. Okay.
So as well as um the uh VPK protocol
specification task force um uh we will
also kick off a task force around custom
personal embedding.
Okay. So embedding [clears throat] has
been generalized. Typically you embed
using a a you go to hugging face and you
say okay I'm I I want to pull down an
efficient um embedding model. It really
doesn't take a long time to embed. It's
not a comput inensive task. The models
are quite small and they take chunks of
text and they transform them into
vectors. Um currently embedders are
generalized embedders. um because
both sides need to understand um the
embedding format.
But in this case the embedding format
can be custom because the other side
does not need to understand the
embedding format. If both the query and
the um uploaded data coming from Bob or
coming through Bob um
it means that Bob can control the um the
embedded and it's been shown and there's
literature um around it that tuning and
customizing an embedder for a knowledge
domain that's closer to the knowledge
base um actually increases the accuracy
of the um the vector search. So that's
one plus. It also means that the
embedded and the parameters around the
embedder become part of the secret that
only Bob knows. Bob never shares that
embed structure the the embedder with
Sam doesn't need to because both the
query and the uh initial ingested
document have gone through the same
embedded. Okay. So we'll kick off a work
group to um uh not a work group a task
force to scour the literature come up
with some custom embedders and uh these
these become the the secrets that Bob
will wield. Okay.
Now there is a third task force but it's
gated at the moment. it's gated by the
uh by the protocol and at least we we we
can't kick it off until we've got a a a
VPK protocol, at least a preliminary
spec. Um 30 years ago when I was a young
engineer, NIST kicked off um the AES
call for proposals. It was when dees um
the the the current or the previous um
encryption standard was running out of
steam. um it was shown to be crackable
and then we progressed to triple dez as
a a stop gap while um this call for
papers call for proposals um uh su
progressed eventually n anointed one
algorithm the rindal algorithm and that
is now the AES um algorithm it was
quickly standardized and that is what's
securing
the internet it's securing e-commerce
it's secure banking. Um so we suggest
that a similar NIST style call for
proposals is needed uh in order to
um move uh VPK forward. VPK is the
protocol specification but the
algorithms that conform to it um uh need
to be identified. Turns out that the
literature is full of partial
homamorphic algorithms. Um we at Quai we
created a number of our own. Um we then
took it to the Society of Industrial and
Applied Mathematics and the and we
convened a work group at Pomona College
um and um a couple more algorithms came
out of that and then um CKKS is probably
the the gold standard for homamorphic
encryption and that's already in the
Microsoft seal library. Um we're looking
for algorithms that um are somewhere in
the middle of that spectrum. Um that are
practical to use that can conform to the
specification
and um uh and and they they don't need
to be
they don't need to be exhaustively
sort of in CPA um compliant. They need
to be just good enough. So it's not
we're not anointing a single algorithm
like a like NIST was. Instead what we
want to do is um qualify them. We want
to benchmark them. we want to uh red
team and stress test them and then we
can basically just put um we can just
categorize the algorithms and allow the
market to choose what they want to
choose for their um
>> and once again you're only speaking of
embedding algorithms here correct
>> no this this is now the PH moved on from
embedding so the partial homamorphic
encryption algorithms
>> but
okay so that's what I'm saying so You're
separating it out. So you're So
embedding things and then rotating
transforming the embedding are two
separate things. We're calling those
two.
>> Exactly. Yeah.
>> Yeah. Okay. I My mistake was I was
calling all one thing. Okay. Got it.
>> Okay.
>> Can I jump in for one second and and uh
>> Yeah, go ahead.
>> kind of do a a lay person's translation.
We're running into some similar stuff in
the postquantum encryption space wherein
we know that
quantum machines when they exist will be
able to crack existing encryption. So
it's very similar to the problem that
we're talking about here which is we
want someone to be able to work with
this data but we know that maybe it's
going to be crackable right we know they
may be able to read it. So one of the
approaches that's being taken and it's
very pragmatic and it sounds if I'm
inter if I'm understanding you correctly
it sounds like kind of a flavor of what
you're getting at which is to say that
we may not be able to achieve a real AES
style mathematical like assurance that
this is uncrackable. But what we can do
is construct a solution to the problem
that reduces the blast radius of any key
compromise to such an extent that it
doesn't that the value of that
compromise doesn't exceed the value of
the effort that that goes into it. It's
the same idea of putting a better lock
on a door. A bad guy can still get
through the lock. They're going to be
able to crack it. They're going to be
able to pick it. How long do you have?
And then your surrounding mechanisms of
having a camera, having an alarm are
meant to get help there that that
augments the capability of the lock. Is
that kind of what you're getting at with
the good enough idea? Okay,
>> you're you're absolutely correct. Um
it's it's uh I guess the economics of
hacking. You know, you would you would
target a hacker would target um you
know, a massive honeypot where they need
to crack it once and then they've got
access to all the data. And the easy
things if you if you say, well, if you
hack this, you've only hacked it for one
>> session or for one customer or Yeah.
then then it's then it's not a scalable
hack for that.
>> And it's also that the data isn't
revealed in that sort of binary way. You
have, you know, an inference about the
data. Remember, you're you're trying to
infer what the embedding algorithm is.
So, as a result, the results you get are
only inferences at the end anyway. You
only have a certain you can't be sure
that that's what it actually says ever.
Really,
>> your your point is is is correct here.
In fact, when we go back here, um when
uh part of the protocol is um
Bob sends scrambled vectors to Sam, Sam
stores them. Later on, Alice issues a
query. Bob scramles that query knowing
what the relevant key is to to Sam. When
Sam searches through the terabytes of
records, Sam does not return the chunks.
Sam returns the index of the chunks with
the similarity scores. So the data never
travels back on the return wire, but the
index of of the database record comes
back. Sam's already got the original
copy here. Knows the mapping between the
original data and the um the
>> You mean Bob does? You said Sam. You
know,
>> sorry. Sorry. You're right. Bob does.
Bob knows that. And so the reordering of
the records becomes part of the key
material that that Bob wields.
>> That's almost a tokenization then, isn't
it?
>> It is. It is. Yeah. And and so even a a
man-in-the-middle attack here, if Eve
were to try and intercept this, Eve
would not be able to glean. Well, we
need to we need to rigorously quantify
what Eve can glean. And then the other
strategy is to have multiple SAMs is to
shard the data across multiple SAMs such
that you can have a different key for
each one. And so to your point, Scott,
about a scalable hack, um it would
require massive collusion between all of
these SAMs in order to um in in order to
uh um uh piece back um and and
reconstruct the the knowledge base if
they did manage to crack one.
>> Can I just make a point here?
>> Yeah, go ahead.
>> All right. So basically there going to
be two different types of setups in this
situation. So Bob can either keep his
own, you know, chunks so that the
baseline data on his own stuff and he's
only using SAM to help him do a
distributed vector search at a quicker
speed. or you can keep those chunks with
SAM, but they have to be encrypted in a
different encryption uh methodology so
that Bob can then identify them, pull
them back from SAM and then decrypt them
locally. So there's those two different
setups
>> that yeah, that that could work as well.
You're right. Um and
>> let me ask one one question and I may be
jumping ahead. [clears throat]
>> Yeah. For inference to work though, the
LLMs need to be able to understand the
text that's being processed in order to
do their um let's say statistical
analysis of where this text appears next
to other text. And so understanding
encrypted text and how that relates to
other unencrypted text sounds like the
point where this falls apart. Now that's
a later problem.
>> It's you're right, the chat completion
part is a later problem. So, at the
moment, we we're focusing on securing
the entire knowledge base, not the
individual chat completion um requests,
which might reveal a little bit. Now,
one uh way that
Bob could solve that is by running an
LLM locally.
um uh now
that he might not have sufficient
compute for that. I mean but but you
know he's got Mo's law on his side and
and uh that might not be the the problem
of scalability but okay so um I was
speaking with Ben Girtzil at the at the
conference and I said okay here's what
we've solved already we think we've
solved the retrieval part of rag but we
haven't solved the generation part of
rag the the inference section um how
would you approach it and he went silent
for a
and uh then after the conference he sent
me a very long uh essay on you know ways
that he'd approach it. I think we've got
some techniques within quet to approach
it um with our distributed LLM where we
shard the LLM inference across multiple
nodes. Um and we can leverage the
unexplainability of the neural network.
Uh, as you get deeper into the network,
you start up where I'm I'm gonna um run
the first few blocks of my um of the of
the uh of the LLM inference and the last
blocks, but then they follow a circuit
through different nodes of various trust
levels and um we're going to see we need
to quantify whether that is hackable uh
and to what level it's hackable and what
level of collusion is needed.
But you're right, VPK is not at the
moment, its scope is not to focus on the
chat completion problem. We could kick
off a task force um to to solve secure
inference.
Uh I think we need to get this first
part, the retrieval part nailed down and
then go after secure inference and that
could be our fourth um task force.
>> Really, I know it's an adjunct, but I'd
love to read that essay. Um, you know,
we've had some conversations about that
and I I I I don't have any core answer
to uh uh the the homamorphic inference
>> right question right now.
>> Yeah. Yeah. You you're actually we don't
have an answer for it because at the
moment LLMs are written where your
prompt that goes into the the input
layer is in clear text and the output is
in clear text. There's no mechanism for
having um encrypted weights and where
you pass an encrypted prompt and it
gives you an encrypted answer back uh
and then you get to decrypt it.
If I could add something here.
>> Part of the research that I'm doing is
not on the first prompt but there there
is a way that you can build like the
opposite the inverse of a zero knowledge
proof where you have the prover and the
verifier separated and both of them hash
um their understanding of that um
inference or prompt. And then in the
future once trust is established between
those two agents they can just share the
hashes and they can know that each other
that hash equals that full document of
information. So that kind of gets into
this like SAM side of the um scrambling
and the and the hashing. That's
something I've been I've been working on
and built a harness around that sort of
verifiability
um of the knowledge and agree with a lot
of the statements people have um made
prior that we need to focus on like the
not having like a one-sizefits-all
encryption that solves this but being
sort of iterative on using techniques
like obfiscation as well in the middle
and making the bits and the bites just
like when you do have an attacker making
the yield so low that it becomes like an
economic thing. Even if they've got the
compute of the universe, they don't see
a point in attacking that.
>> Right. So,
um
Mitch, I'm I'm looking forward to that.
So, two things down. Yes,
>> if if I want to let me just tie it in
correctly. So, so two things that I want
to also mention in this call. Um,
I'd like for us to come to a decision on
how we communicate using AI agents early
on. Um, if there's going to be some
Yeah, within the group, if there's going
to be some sort of spec or repo or
something like that. Um, I've got a
bunch of agents that have different
protocols and discussion systems for for
governance that I'd happily propose, but
we need to make that a discussion that
we decide on um early on. Uh cuz things
go really quickly if you start having
our agents talk to each other, but then
it gets into like a different language
altogether and we end up becoming
translators in working group calls. So,
just want to put that on the table early
on. Um, but I think it's important that
we do sort of build this with agents in
mind in tandem and have our agents like
doing a weekly VPK sync of the
discussions and pulling in our own
private virtual knowledge stores, right?
And pro providing inference and insight
in that way. So, want to include that.
Um, and I think that that pretty much
summarizes the the outcomes that I I was
thinking. Mitch, I think that's really
important. Um, so we do have a VPK workg
groupoup um channel on Slack. Um, what
I'm proposing is that we develop an
automation and that that Slack has the
sort of automation harness already. Um,
and I've integrated Claude into Slack.
And so that's like a a general
integration and to take the Zoom
recordings uh of of each of our meetings
and our discussions and just create
summaries so so they can go in but also
um uh just keep the the the follow-up
going. I love what what Singularity has
in their Slack um group. They've got
Hugo. Hugo is their um automated bot
that is is in there. It's a bit chatty
[laughter]
and and a bit naggy and you know, but it
keeps it keeps the conversation going
and uh and but but but follows up with
individuals as well. Um and I think
we've got uh the capability of uh of
doing the same thing um with Claude and
Slack. Um
>> yeah,
>> and also if if the spec ends up in
GitHub, we can follow suit of the way
that GitHub discussions
>> um can be kind of controlled by AI in a
way.
>> I've just had a good experience in the
>> um trust over IP um
working groups when that's been adopted.
>> Yeah. So the GitHub conversations um and
that opens it up to a broader audience
rather than the fairly closed internal
Slack conversations. Um and so yeah I've
uh
>> yeah I've also had good experiences with
trust IP GitHub discussions.
Okay. So, GitHub's also one of the we
we've currently got our own GitHub repo,
but u this work will continue now uh
under the um Linux Foundation's GitHub
repo. That's all part of the logistics
we need to set up over the next week or
so. Um so, a couple of um items to three
items to follow up on. Uh, one is we
should probably um take the white paper
that's on the website now and um start
marking that up and and have a revised
version, but now it's under the workg
groupoup governance and um it should it
should incorporate all of the the recent
thinking that that white paper that's on
the website um is something that was
written um three months ago, maybe even
six months ago. So, it's it's a bit
dated. Um, and we can we can bring it up
today.
>> And I actually just started messing
around with the website a little this
morning. So, get the exact text you want
to describe the this workg group because
I think that needs to go on the
homepage.
>> I think you're absolutely right. I think
we need to, you know, really super crisp
mission statement. Um,
and we're still in the phase where we
are recruiting founder members. I'd like
to get some heavy hitters. We've got a
handshake agreement with OWASP to join.
Um and uh but that's the OWASP LA
chapter. I'd like to get the national
OWASP um Steve Wilson to to be part of
this. And then let's see if we can get I
don't know a vector database company
like Quadrant that offers Quadrant in
the cloud to to be the test case to show
hey our vector database in the cloud
operates perfectly when the client has
got VPK running.
The idea is that
>> yeah it requires no accommodation by the
service provider.
>> No accommodation no integration
necessary. It just works and um that
would be a great test.
Jordan Jordan just had um I don't
remember if you were there that night,
but he at the DevOps LA meetup, he had a
>> Pine Cone.
>> Yeah. Yeah, exactly. Yes, he had.
>> I'd love I'd love an intro. So, Pine
Cone is a non-opensource I think they're
closed source, but but still it should
it should just work. So, I'd love an
intro to the Pine Cone guy. I think he
did send me an intro actually.
>> Okay, good.
>> So, I I'll follow up there. Okay. So,
logistics, Dave Boswell and Minu are
people to follow up with. Um, I think
Myra, if you could take on one of them.
I'll take on I've got a call scheduled
with Dave Boswell for tomorrow. Um and
then um Myra, I'll I'll I'll invite you
to that call as well, but we should
probably also get um a call with Minu um
about all the other infrastructure
um logistics that of of around the work
group. Okay,
we we are we are nicely at time. There's
five minutes of Q&A left and then and
then next steps. Okay. So, let's let's
just dwell on the Q&A. Are there any
questions?
I know Sandra, you've been silent
throughout this. Does is is Singularity
on board with
>> uh Yes. So, I was taking all in. I know
that some of the team members that
you're going to be talking with in two
hours have more background. So I was
trying to understand, you know,
everything from from the foundations up.
>> Fantastic. Thank you so much. And I
really appreciate um the enthusiasm that
Singularity has shown uh in in in all of
this and I think we we are uh going to
be doing something important for the
industry. Okay. Um
let us
let's see who have we not heard from
actually Mitch um normally you you
>> perhaps yeah a good visualization
of what we're trying to do is needed and
maybe you can just uh
>> us with um
>> the source cooking recently. I'm going
to stop sharing.
>> Um,
so VPK
here, I'll give this one
uh so I've built a wiki space and this
wiki space is kind of it's a public
private knowledge space, but there are
actually two. So there's the localhost
version of the federated wiki and then
there's the public version of the wiki
which is like a HTML snapshot of what is
a local um federated wiki that is just
yeah wiki structure um but I've actually
visualized it in a way that I've um
given some sort of tourist space
geometry using these six
um categories. The gates is the boundary
agent, skills is the delegation agent,
the harness is the compute, the cannon
is the memory, the federation is kind of
the connections. So all of us here and
then the agreements. So the value
agreements are also synonymous with
links in the sort of guide or the wiki
space. Um so this then creates these
sort of unique patterns of pathways
through knowledge base. Mhm.
>> And when you can generate a pathway
through a knowledge base on a Taurus, um
you get cool maths. And when you
compress things to cool maths, then you
can turn it into these sort of
um spliced and and diced information
packets that Sam is interested in trying
to trying to attack, but has a problem
when attacking. um the transition
between when it goes to like the Taurus
four or 5D geometry and then just the 2D
map. It's also interesting to see. So
you can see like the the boundaries are
still the boundaries. The skills are
still the skills and this creates like a
notion that you based on where within
this sort of knowledge base
>> that was some sort of dimensionality
slider that you had going on there.
Yeah. Yeah. Yeah. Yeah. It's kind of
It's kind of fun. Right here, I'll I'll
zoom in on the so you can see the the
golden ratio moment.
So, they kind of fold in on each other
in order to
create the
um Taurus shape. So, then they're
>> But okay, so the Taurus shape has how
many dimensions?
>> It's six or
Yeah.
>> Okay. I think
>> it's five or six D space, but I could be
wrong. You should double check. I'm
pretty sure it's six. And
>> And somehow this is smooth. So you've
got fractional dimensions somehow being
represented, too. Okay.
>> Yeah. And it's it's about Yeah. pathing
through um on this dimensional
dimensionality and then changing it in
order to so this is like the pattern and
all you do is share the pattern through
the knowledge base and then the the LLM
is going to be able to be like oh yeah
ABC I can actually record the runtime
for example this dot here if an MCP
server was observing this um I could
record that I observed this pattern for
a certain amount of time which means
that my agent was consuming these
particular documents in this particular
order through the wiki space. Um and
that adds to
some qualities in the governance of the
data and the information and like how
much you trust the agents computing the
right thing on the right path. Um
>> right. So then the agents in the future
instead of just sharing
>> hashes that point to chunks can now
share hashes that point to pathways and
so forth you get another layer of of
compression and inscrutability. Got it.
>> Yep. And then it's the trajectory based
on that current state of the private
knowledge base which then creates even
more obiscation for like when the
knowledge base changes in the future and
we get this like step change in
signatures being used. It's like the
well that was only for this version. I
add like 10 extra wikis and I tend to
add on average like 30 wiks a week to
the research knowledge base. That means
I'm versioning the like hash pathway but
there is still this like provenence
chain of um these like trajectories
through. So these are all like just So
here's an example of just a pathway
through like I would just hyperlink all
the way through.
>> Last time and I've got
>> Yeah, sorry. Things get exciting when I
start showing.
>> Let's just wrap quickly. Um, thanks so
much everybody for um for participating
on this kickoff call and um we're
confirming a weekly cadence of this
meeting at this time slot, the 9:00 a.m.
time slot. Um and uh you'll find it on
the Linux Foundation um calendar, but
it's also publicized elsewhere. Um
thanks so much. I will um distill this
into some minutes and they'll be posted
in the VPK Slack channel, but I'll also
email them out to all of you. Thank you
very much. I'm going to hop on to our
intern group which is waiting for me
now.
>> Just good clarity. So, a Taurus is
actually two-dimensional object lives
inside a three-dimensional and
fourdimensional space.
>> Thanks so much. Cheers everyone.
>> Keep on. [laughter] It's a wrap.