Who Watches the Watcher? Understanding Privacy and Power in AI — Transcript
Full transcript
- 0:07So next up we have who watches the
- 0:10watcher and it's moderated by Anubis and
- 0:13if we are discussing the parenting of AI
- 0:15then Anubis is the father of this
- 0:17conference. He's pulled it all together.
- 0:19So Anubis please come up and welcome on
- 0:22your uh panel and talk about who watches
- 0:24the watcher. Thank you.
- 0:28looking down. [music]
- 0:41>> Check. Check.
- 0:43>> All right. Thanks everybody for coming.
- 0:45I'm excited to dive into this panel.
- 0:47Bring my speakers on up to the stage,
- 0:49please.
- 0:59I am Anubis, the CMO of Secret Network
- 1:01Foundation.
- 1:02>> I'm going to be moderating this panel.
- 1:05Uh I think it's going to be a great
- 1:07conversation. We're going to dive into
- 1:09who watches the watcher, understanding
- 1:11privacy and power in artificial
- 1:14intelligence. I'm going to go ahead and
- 1:16pass it just around. Let all of the
- 1:18speakers go ahead and introduce
- 1:20themselves.
- 1:22>> Sure. Hey everyone. Uh, my name is
- 1:24Marshky.
- 1:25Uh, it's really good to be back in
- 1:27Toronto even though I live in San
- 1:28Francisco. Um, I'm a UFT uh, alumni. Any
- 1:33uft folks in the audience?
- 1:37No. Wow. Okay. Uh, so much for pandering
- 1:40to the audience. Um, yeah. So, I I work
- 1:44on Cella. I'm one of the co-founders of
- 1:45Cella, which is an EVM compatible um,
- 1:48L2. uh and uh recently we started
- 1:52self-protocol uh self-protocol is a uh
- 1:56zero knowledge privacy preserving uh
- 1:58decentralized identity protocol. Um who
- 2:02here has a passport? Anybody have a
- 2:04passport?
- 2:06Nobody has a passport. Okay, a few
- 2:08people are raising their hands. Amazing.
- 2:10Uh so passports nowadays have these NFC
- 2:13uh chips on them. uh they're called
- 2:16biometric passports and in there your
- 2:18biometric data is signed
- 2:20cryptographically with a certificate
- 2:22authority chain and so self-protocol
- 2:24basically verifies uh that certificate
- 2:28authority chain in zero knowledge so
- 2:30that you can prove onchain that you have
- 2:33a valid passport and better yet so that
- 2:36you can disclose uh information about
- 2:38yourself in a privacy preserving way uh
- 2:41with third party DAPs that you might
- 2:43want to interact with. So, think of it
- 2:45as a uh yeah, a really cool new uh
- 2:49mechanism that allows you to prove that
- 2:50you're a unique individual, that you're
- 2:52a human, that you're not an AA agent uh
- 2:54in a way that's very privacy preserving.
- 2:57Uh very relevant in this new agentic era
- 3:00that we're in right now. Um so, yeah,
- 3:02that's me.
- 3:04>> Hey everyone. Um I'll help Maric out. My
- 3:07co-founder went to uft, so at least uh
- 3:11we have another person. So uh anyways uh
- 3:14I'm Michael co-founder and CEO of uh
- 3:16ZeroG Labs. Uh quick background on
- 3:19myself. I started at uh Microsoft SAP
- 3:22Labs and then also worked at Bay &
- 3:23Company and Bridgewwater Associates and
- 3:25before ZeroG started web 2 unicorn
- 3:28called Garten that came out of Y
- 3:30Combinator and now ZeroG what we're
- 3:33building is the largest AI layer 1 uh
- 3:35ecosystem and as part of that we have a
- 3:38decentralized storage network. We've got
- 3:40a compute network that does inference
- 3:42and fine-tuning uh in a privacy
- 3:45preserving way using tees and we can
- 3:47definitely get into that. And then we
- 3:49have a layer one that's uh essentially
- 3:50infinitely scalable both on the data
- 3:53throughput and on the transactional
- 3:55level so that you can literally build
- 3:57anything on chain. So anything that's
- 3:58possible in web 2 including many AI
- 4:01applications you can now build uh fully
- 4:03on chain with our infrastructure.
- 4:06Hello. And uh this is Chiao and I'm the
- 4:09co-founder also CEO of Kopus. So uh I'm
- 4:12an artist and uh do you have any artists
- 4:14here creating you know no matter what
- 4:18you like? Oh yeah we we do have a few
- 4:21and uh we we're a content creation
- 4:23platform and we're also making a a
- 4:26content discovery engine which based on
- 4:29what you are viewing uh it will
- 4:31recommend you more related content no
- 4:33matter where you're at. So just like you
- 4:35may also like section but anywhere you
- 4:37can visit and uh yes we we use zerog as
- 4:40our storage for for our content. So
- 4:44that's why we're here. Awesome. Uh hi
- 4:47everyone. I'm Sebastian C at Ember AI.
- 4:50Uh we are infrastructure for execution
- 4:53uh focused on di uh agents. Um I guess
- 4:57to plug maybe this uh we'll be releasing
- 5:00uh a framework to build agents that do
- 5:02things in DeFi, automate strategies of
- 5:04all kinds. Uh the arbitrum vibe kit. So
- 5:07it's uh meant to be a vibe coding
- 5:09experience only. So you have your own
- 5:11trading strategies you want to just
- 5:12automate for you. Um keep an eye on
- 5:15social media for that.
- 5:17>> Awesome. Awesome. A lot of really good
- 5:19projects here. And at Secret Network, we
- 5:23build decentralized confidential
- 5:24computing infrastructure for web 3 and
- 5:27AI. Uh, and what we're currently
- 5:31launching is the Secret AI platform. Uh,
- 5:34allowing users to basically own their
- 5:37own data in centralized AI uh, platforms
- 5:42such as Chat GPT.
- 5:44all the data when you use chat GPT open
- 5:48AAI sucks up all that data uses it for
- 5:50their own means and to train their
- 5:53models. Uh we believe that users should
- 5:55own that data and uh at least be paid
- 5:58for it if uh if they want to let someone
- 6:01else use it. Um so on that note, we're
- 6:06obviously very focused on privacy. Um
- 6:09this panel and this event is very
- 6:11focused on privacy. So I wanted to just
- 6:13ask each one of you, how does your
- 6:15projects focus on privacy? How do you
- 6:18approach privacy with your own
- 6:20platforms?
- 6:22>> Yeah, great question. So I think um
- 6:26yeah, so self by the way it's self.xyz
- 6:28if anybody wants to check it out. It's a
- 6:30really nice short memorable domain name.
- 6:32Um we use zk snarks uh to ensure
- 6:36privacy. Uh and you know it's funny
- 6:38because a lot of people talk about ZK
- 6:40projects these days and really uh what
- 6:42they mean is the the kind of snark part
- 6:45of ZK snarks right the succinct part if
- 6:48you look at ZK EVMs are not actually
- 6:50offering uh typically any privacy uh but
- 6:54for us we're actually using um you know
- 6:56the ZK part so the zero knowledge part
- 6:59of ZK snarks so if you're not familiar
- 7:01with that that's a lot of u very
- 7:03advanced math and cryptography uh some
- 7:06people call it moon math math uh and um
- 7:09it's pretty incredible. Uh but with this
- 7:12moon math, you can effectively prove
- 7:14statements uh without revealing um the
- 7:18inputs to those statements. And so you
- 7:20can prove for example uh using self uh
- 7:24that you are not on the OFAC list uh or
- 7:27that you are you know not um that you
- 7:31are an actual human with a passport uh
- 7:33without revealing you know the
- 7:35information on your passport. I mean the
- 7:37OFAC one is pretty interesting like you
- 7:40don't have to reveal your name, your
- 7:41birthday, which which country you're
- 7:43from. uh but yet you can prove that
- 7:45you're not on this you know US sanctions
- 7:48list uh that u you know many banks for
- 7:51example enforce um to you know prevent
- 7:54kind of moneyaundering and all of that
- 7:56and so it's really really interesting I
- 7:58think the the age is another really
- 8:00interesting one you can prove that
- 8:01you're over 18 or I guess in in Ontario
- 8:03over 19 without revealing your actual
- 8:06age and again we can do that with with
- 8:08this advanced cryptography uh which is
- 8:11just really really cool to
- 8:14That's really powerful. I I've always uh
- 8:17wondered why it is that every time we go
- 8:19to a store and we want to buy alcohol or
- 8:20whatever, uh why we have to show the
- 8:23cashier exactly where we live, where we
- 8:25sleep, you know, it just uh it's always
- 8:27bugged me. So, but on that same note,
- 8:30what's really cool about what you're
- 8:31building there is proof of humanity in
- 8:33in the age of AI. I think that's going
- 8:35to become more and more relevant uh and
- 8:37very just very important. So,
- 8:40>> yeah, absolutely.
- 8:42All right. And Michael, go ahead.
- 8:44>> Yeah. For us, uh, the way we think about
- 8:46privacy is, uh, because we have
- 8:49different layers to our infrastructure,
- 8:51different, uh, aspects of privacy matter
- 8:54at these different layers. So, for
- 8:55example, on the layer one, it would be
- 8:57can you do private transactions. So, we
- 9:00haven't implemented that, but that's
- 9:01something that we're looking uh at in
- 9:03the future. uh what we have is on the
- 9:06for example storage layer you could
- 9:08easily encrypt your data and that allows
- 9:11a sense of privacy and technically we're
- 9:13also agnostic to what kind of privacy
- 9:16methodology you want to use. So if in
- 9:18the future FHE becomes uh compute
- 9:21inintensive enough then you can
- 9:23definitely use that from a storage
- 9:24perspective as well. So we don't
- 9:26necessarily want to prescribe what the
- 9:28privacy methodology is but really enable
- 9:30it through our infrastructure. Uh on the
- 9:34compute side that's where it gets kind
- 9:35of interesting because different
- 9:37approaches have actually been tried. So
- 9:39ZKML
- 9:40um SPML TML FHML are all different ways
- 9:46of approaching um inference and other
- 9:49type of compute applications through a
- 9:51privacy lens. But the issue that we
- 9:54found is that none of them are really
- 9:56production ready for consumer use cases
- 9:58besides TML because the overhead that
- 10:02you have between TE and kind of regular
- 10:04let's say inference that's not
- 10:05verifiable not private is almost zero
- 10:08and so you could use it in the same way
- 10:10as if you would uh you know chat GPT but
- 10:12with an open source model running in an
- 10:15TML which is stands for trusted
- 10:17execution environment on an H100 Nvidia
- 10:20card and So that's why we've chosen to
- 10:24support that at the moment, but we
- 10:26definitely can also support ZQML and
- 10:29FHTML and all these other verification
- 10:31methodologies. It's just that if you
- 10:34wait an hour for a token to appear,
- 10:36that's not a great user experience. So
- 10:38for certain use cases, that makes sense,
- 10:40but they're very very limited. And so we
- 10:42primarily use TE's. The way TE's work,
- 10:45it's a hardware based methodology. So
- 10:47there is actually an environment on that
- 10:49graphics card that's completely private.
- 10:51So you can run computations in that
- 10:53environment and then verify that
- 10:55something happened in that environment
- 10:56without outsiders knowing about it. And
- 10:59so it's quite powerful. It works very
- 11:02well. But there's a downside to it as
- 11:04well. You have to trust the hardware
- 11:05manufacturer. If the hardware
- 11:07manufacturer for some reason builds in a
- 11:09back door for a government entity, you
- 11:11don't necessarily know about it. And so
- 11:14it may not be the end solution, but it's
- 11:16the most practical solution at the
- 11:17moment that we've chosen to support just
- 11:20from a a way of kind of working with
- 11:22these systems, but definitely want to
- 11:24support other methodologies in the
- 11:25future.
- 11:27>> I love that answer. It's uh at secret
- 11:30network, we also use TEES and for much
- 11:32the same reason. Uh there's other very
- 11:35powerful encryption technologies for
- 11:37confidential computing and each one has
- 11:39its own place. uh for example ZK is very
- 11:42good for something like an ID
- 11:43verification but for uh AI inference
- 11:47it's just not going to work something
- 11:49like a TE uh which has a a faster and
- 11:52more efficient throughput uh is what's
- 11:54needed
- 11:55>> there are people working on that it's
- 11:56going to happen
- 11:57>> oh I think so yeah you're there is
- 12:00people doing some very good work
- 12:02>> yeah he was saying uh people are working
- 12:03on it will happen and I would agree
- 12:05there's some use cases where if it's a
- 12:07very small parameter model it's it works
- 12:10works okay especially on like edge
- 12:11devices where you can use some type of
- 12:13ZKML methodology but for larger scale
- 12:16models even like 7 billion parameters it
- 12:18already starts breaking down because
- 12:20it's a lot of latency you're introducing
- 12:22with the methodology
- 12:24I I've always figured that the future is
- 12:26going to be multi-technology not just
- 12:28multi-chain and so a mixture of a TE
- 12:31with ZK FHE uh and one of my favorites
- 12:36is actually MPC and and TE as a
- 12:39combination
- 12:40By combining the two or two or more, you
- 12:43get very powerful use cases.
- 12:46>> Oh, were you gonna say something?
- 12:52>> I'll pass it.
- 12:55>> All right. And ciao, same question. How
- 12:58how does how does your project approach
- 13:00privacy?
- 13:01>> Well, so like one great thing uh about
- 13:04web three is uh they can keep you off
- 13:06from authority. And recently you have
- 13:09found like a very interesting uh product
- 13:11market fit is the fanfiction writers in
- 13:14China. Uh because uh there are lots of
- 13:16fanfiction uh websites have been taken
- 13:19down and the police even go to invite
- 13:21those writers uh for some tea party and
- 13:24what we what we do is like we allow the
- 13:27wallet only login. So first like nobody
- 13:30will know like who writes those
- 13:31fanfictions and keep you safe from the
- 13:34biggest authority. And uh another thing
- 13:37is like we support uh crypto
- 13:39transactions and uh these are all like
- 13:42web two writers but right now they are
- 13:43learning to login with their wallets and
- 13:45also u to earn with their wallets. So
- 13:48it's a safer way to them uh for them to
- 13:51no matter where they live basically. And
- 13:53the second thing is how we protect the
- 13:54content creators right you want to you
- 13:56don't want your own content to be um
- 13:59pirated or learned by the AI very
- 14:00easily. So what we do is we have like a
- 14:03like a maze. If we detect there's a AI
- 14:06agent trying to visit our uh creators
- 14:09page like trying to scrap out some
- 14:11content uh we'll just generate random
- 14:13content for them. So it if the creators
- 14:16are actually writing about a Harry
- 14:17Potter's fanfiction, it might just
- 14:19generate them like a Amazon River um uh
- 14:23ecology study uh just totally random
- 14:26nonsense and uh good luck with those AI
- 14:28agents. Yeah, that's what we the two
- 14:30main thing we do to protect the privacy
- 14:33uh for our users.
- 14:36>> Um I I think everyone that's working
- 14:38closer to the end user and kind of on
- 14:39the application layer ends up with this
- 14:41temptation to in AI make very simple
- 14:44user experiences that require a lot of
- 14:46data and kind of a lot of personal
- 14:48information from people. Um it's really
- 14:51important when you're thinking about how
- 14:53to build the systems to try to separate
- 14:55those two things and within reason,
- 14:57right? Um, obviously people are looking
- 15:00for that automation, but there there are
- 15:02ways to let them own that information,
- 15:04right? For us specifically, I mean,
- 15:05we're dealing with DeFi execution. It's
- 15:07all about, you know, owning your own
- 15:08strategies. We do take a lot of, uh,
- 15:12data points that can give you good
- 15:15suggestions, help you, you know, explore
- 15:17the world in a more curated manner. uh
- 15:20but the the key of this conversation I
- 15:23think lies around making sure that the
- 15:25data that you are using is not leaving
- 15:27the user's possession right maybe you
- 15:29get permissions to access it maybe your
- 15:31systems built out in a way that you'd
- 15:33never need to touch it um so you know
- 15:35for us distributing this as an open
- 15:37framework and letting people build out
- 15:38whatever strategies they want on their
- 15:40own computers owning their own code is
- 15:42uh I don't know kind of the the best of
- 15:44both worlds in a way
- 15:47>> awesome awesome So,
- 15:50one of the things to really consider in
- 15:53in the AI space and privacy uh in
- 15:57centralized AI systems,
- 16:00you know who to go after if there's a
- 16:02large data leak that that exposes a
- 16:04bunch of sensitive information. You know
- 16:06that you can go after open AI. You know
- 16:09who's responsible. Now, in decentralized
- 16:12AI, it's a bit different because you
- 16:15don't know who's hosting the the
- 16:17servers. you don't know who owns the
- 16:19hardware. So my next question is really
- 16:21double clicking into that. Um in your
- 16:24opinion, who should be responsible for
- 16:27setting privacy standards in
- 16:29decentralized AI?
- 16:32>> Yeah, it's an interesting question. Um
- 16:36I mean I think ultimately it's it's it's
- 16:38going to have to be initially um the
- 16:42decentralized projects, right? I think
- 16:44initially this will be too complicated
- 16:45for regulators to step in and I think if
- 16:47regulators do it uh immediately I think
- 16:50they may also um struggle a little bit
- 16:52to understand all the nuances but if the
- 16:55if the projects themselves if the you
- 16:57know the the open source community
- 16:59doesn't do it quickly uh then you know
- 17:02certainly bad things could happen uh and
- 17:05then we might see an overreaction from
- 17:07from regulators uh and so in in a way
- 17:09that could be even worse and so I think
- 17:11it it it's certainly going to be um you
- 17:14know the people in this room, the people
- 17:16working on these systems um you know I
- 17:19think we have to be as thoughtful and
- 17:20and careful as possible. I mean this is
- 17:23a crazy transition that we're going
- 17:25through. Uh I mean it's really hard to
- 17:27even predict what's going to happen in
- 17:29the next 5 to 10 years. Uh if AGI really
- 17:32happens, you know, everything about our
- 17:34lives may may change just overnight. And
- 17:37I have a lot of conviction that, you
- 17:38know, decentralized systems are going to
- 17:40be the ones that are are going to be
- 17:42preventing concentrations of power,
- 17:44ensuring that people's data remains
- 17:47private. Um, I mean, just think about
- 17:49how much data you share with, you know,
- 17:51Chad GPT these days. It's crazy. I mean,
- 17:54the amount of information that they know
- 17:55about you. Um, there's there's a lot of
- 17:58a lot of risk there. Um and so yeah, I
- 18:02think it's it's going to be, you know,
- 18:03it's going to fall on all of us.
- 18:06>> Absolutely. At at Secret Network, we
- 18:09we're building the infrastructure, so we
- 18:11always come at that infrastructure
- 18:12level. Um and to be honest, part of that
- 18:15is because it's it's just a need. So
- 18:18many people building in the space aren't
- 18:19even thinking about the word privacy. So
- 18:21if we can make it easy for anybody to go
- 18:24ahead and just plug in build uh the same
- 18:26way they would build anything but add
- 18:28that privacy you know that's that's the
- 18:30best case in my opinion. Yeah, maybe
- 18:32just a quick followup. You know, the
- 18:34topic of world came up in the in the
- 18:36panel before and there was a lot of um
- 18:39um concern about, you know, people
- 18:41sharing their iris information. You
- 18:43know, that's a type of data that, you
- 18:45know, I think um a lot of people have
- 18:47have concerns about sharing and it's
- 18:50really important in this future where
- 18:51we're going to be, you know, thinking
- 18:52about um um how do we how do we give
- 18:56UBIS, how do we differentiate between
- 18:58humans and agents, right? Right. I think
- 19:00this is the reason why world is is
- 19:01solving it in this way. And I think one
- 19:03thing that's really nice about self is
- 19:05that it solves it in a way that doesn't
- 19:07require you to share your your Iris
- 19:09information. Right? You already have a
- 19:11biometric passport. Um EU IDs at hard
- 19:14systems. There's a lot of ID systems
- 19:16that have these cryptographic primitives
- 19:18that we can then bring on chain in
- 19:19privacy preserving ways. And we think
- 19:21that that's going to be a really really
- 19:24great way uh to protect users data as we
- 19:27kind of go through this crazy transition
- 19:29that's uh coming about.
- 19:33>> Yeah. So just uh our own spin on kind of
- 19:36the question who's to blame if something
- 19:38happens at OpenAI you have a centralized
- 19:40authority and you could then extend that
- 19:43analogy and say well in a decentralized
- 19:45way you have the protocol so shouldn't
- 19:47the protocol be to blame. Um, but that's
- 19:51kind of like saying the individual
- 19:53actors that are trying to attack the
- 19:55protocol are then the ones that should
- 19:58be responsible, but the protocol itself
- 19:59is to blame. So the analogy doesn't
- 20:02fully extend in that way. What the
- 20:04protocol can be responsible for though
- 20:06is to put in safeguards. So for example,
- 20:09we have something called AI alignment
- 20:11nodes that we're currently researching
- 20:13and in the future we want them to
- 20:15basically uh figure things out like
- 20:17model drift, uh negative behavior by AI
- 20:20agents,
- 20:22um kind of data poisoning attacks, those
- 20:25types of things that really influence
- 20:26the functioning of the protocol. So we
- 20:28definitely want to be responsible for
- 20:30that, but we can't possibly predict all
- 20:33attack vectors. And so there will be
- 20:34protocol upgrades over time, but it's
- 20:37really kind of nefarious actors that
- 20:38will try to attack the network in one
- 20:40way or another. And so the best that we
- 20:42can do is to ensure that there is
- 20:44slashing or economic incentive
- 20:45conditions so that these types of
- 20:47situations don't occur in the first
- 20:49place. And there's probably a finite set
- 20:51of things that can be attack vectors
- 20:53that we can think through and then
- 20:54through experience keep upgrading the
- 20:56protocol over time. So that's something
- 20:58that we can take responsibility for.
- 20:59Sure.
- 21:02>> Uh I totally agree. And if you can't if
- 21:06it's hard to go after uh the the like
- 21:09the sellers, it's probably like easy a
- 21:12little bit more easy to go after the
- 21:14buyers. And uh I I I need I think as a
- 21:18content creator background uh they need
- 21:20better regulations for um about like how
- 21:24AI no matter if it's decentralized or
- 21:26centralized AI to steal I mean kind of
- 21:29steal or learn from people's content
- 21:31because uh every law including the IP
- 21:34law uh works very differently from every
- 21:36country and uh your your content might
- 21:39be safe uh by law in one area doesn't
- 21:42mean that you content is safe
- 21:45uh everywhere. So we do need uh u we do
- 21:48need like regulations and also uh
- 21:50decentralized uh uh storage providers uh
- 21:54which basically do less KYC to their
- 21:57users. So they just know like even
- 21:59though they know the content they don't
- 22:00know where to come from I mean it's it's
- 22:03still better for users that what we can
- 22:05do for best for right now.
- 22:07>> Just to jump in real quick because I
- 22:09think we're we're shorting time. I I
- 22:11want to talk about the government
- 22:12approach to this. It's definitely not
- 22:14the most popular take in web 3
- 22:16especially, but there is a
- 22:18responsibility to I don't know give a a
- 22:21high level guideline that will
- 22:23potentially be broken by private
- 22:24businesses, but that exploration needs
- 22:26to be held back in my opinion uh to some
- 22:29degree by the government. Right? I I
- 22:30don't think we can trust uh private
- 22:33interest to 100% put individual uh I
- 22:37don't know best benefit in the first.
- 22:40>> Awesome. Yeah. I think I think one of
- 22:42the big things that we all really should
- 22:45think about is is how we can improve the
- 22:47education in the space on on these
- 22:49issues. Uh we are out of time, but I
- 22:52want to just thank each and every one of
- 22:54you for coming up here um and for
- 22:56sharing. Uh it's been a great panel.
- 22:59>> Thanks everyone.
- 23:01>> Thank you.
About this transcript
This page contains the full transcript of Who Watches the Watcher? Understanding Privacy and Power in AI by Secret Network, generated from the public captions YouTube serves with the video. The transcript has 3,937 words across 571 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.