#124 Sina Kian: Reshaping Privacy in the AI & Machine Learning Revolution

8 Jun 2023 · 57 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Eye on A.I. Podcast Episode #124: Sina Kian - Reshaping Privacy in the AI & Machine Learning Revolution

Overview In this episode, Craig S. Smith interviews Sina Kian, General Counsel and COO at Aleo, focusing on the transformative potential of zero-knowledge proofs in enhancing privacy within AI and machine learning. The discussion explores the interplay between privacy-preserving technologies and their applications across various domains, including social media and digital identity.

Key Concepts Discussed

  1. Zero-Knowledge Proofs
  2. Definition: A cryptographic method allowing one party to prove knowledge of a fact without revealing the fact itself.
  3. Applications:
  4. Protecting sensitive data in databases.
  5. Enabling machine learning models to train on data without exposing the underlying sensitive information.
  1. Aleo's Technology
  2. Focus: Building private blockchain-based applications that utilize zero-knowledge proofs.
  3. Functionality: Users can prove certain data characteristics without exposing the actual data, enhancing privacy.
  1. Integration with AI & Machine Learning
  2. Training Data: Discusses the importance of using sensitive data (such as medical or financial records) in AI without compromising privacy.
  3. Techniques Mentioned:
  4. Homomorphic encryption
  5. Federated learning
  6. Zero-knowledge proofs as a means to ensure privacy while allowing data use for AI.
  1. Digital Identity
  2. Vision: Create a passport-grade digital identity that can be utilized across multiple platforms without compromising user privacy.
  3. Benefits:
  4. Reduces the need to share sensitive data with every platform.
  5. Enhances security against identity fraud and data breaches.
  1. Privacy in Social Media
  2. Concerns: The current lack of accountability and the potential for misuse of user data.
  3. Proposal: Leverage Aleo's technology to ensure users' identities are authenticated while preserving their privacy.
  1. Government and Regulatory Interest
  2. Current Engagements: Conversations with U.S. government agencies regarding the potential of privacy-enhancing technologies.
  3. Regulatory Challenges: Navigating the definitions of securities in blockchain technology.
  1. Web 3.0 Relationship
  2. Definition: Web 3.0 refers to a decentralized internet where users have more control over their data.
  3. Connection to Aleo: Aleo's technology aligns with Web 3.0 principles by allowing decentralized ownership and transfer of digital assets.

Episode Highlights

  • Introduction of Sina Kian: Background in law and finance, transitioning to technology through Aleo.
  • Discussion on Blockchain and AI: How blockchain technology can integrate with AI for various applications, emphasizing data confidentiality.
  • Real-World Implementation Examples:
  • Potential applications in healthcare data sharing.
  • Digital identities for age verification on platforms.
  • Future of Machine Learning: The importance of privacy-preserving technologies in avoiding biases in machine learning models.
  • Open Source Development: Aleo’s strategy to build a community-driven open-source project for developers to create applications leveraging their technology.

Conclusion The episode provides insightful perspectives on how Aleo and zero-knowledge proofs can revolutionize privacy in AI and machine learning. By enhancing digital identities and ensuring data privacy, Aleo aims to reshape interactions in the digital world while addressing significant privacy concerns.

Additional Resources

  • Follow Craig Smith on Twitter: [@craigss](https://twitter.com/craigss)
  • Follow Eye on A.I. on Twitter: [@EyeOn_AI](https://twitter.com/EyeOn_AI)
  • Explore Aleo's technology: [Aleo.org](https://aleo.org)

---

This summary encapsulates the core discussions and insights from the podcast episode featuring Sina Kian, shedding light on the intersection of privacy technology and AI.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00When you think about machine learning or AI using databases, one of the most obvious questions is what's in those databases? And do we want to expose that to, in the context where I was talking about unaffiliated nodes, in this context to machine learning? You can use encryption to make data unavailable to the general public that may try to look at that data. But at the same time, if you put it on something like Elio, you can prove things about that data that are true or false or that fall within certain parameters and leverage that data without actually giving away identifying information. This week, I talk with Sina Kian, Chief Operating Officer of Alio, that's A-L-E-O, a platform for building private blockchain-based applications.

0:54Alio supports zero-knowledge proofs, a powerful tool to verify the correctness of a computation without revealing the input data or the computation itself. This makes Alio particularly useful in machine learning, where sensitive data such as medical records or financial information needs to be kept private, but has tremendous potential for training AI systems. Before we begin, I want to mention our sponsor NetSuite, Oracle's cloud-based enterprise resource planning software to help any business manage their financials, operations, and customer relationships in a single platform. For the first time in NetSuite's 22 years as the number one cloud financial system, you can defer payment on a full implementation for six months.

1:58No payment, no interest for six months for a full implementation of Oracle's NetSuite. To take advantage of this unprecedented financing offer, go to www.netsuite.com slash I on A I, that's E-Y-E-O-N-A-I, all run together. Now here's Sina. I've had a little bit of a look, but why don't we start by having you introduce yourself and then introduce Alio, and then I'll get into some questions. Okay, great. So my name is Sina Keehan. I'm general counsel and COO here at Alio. I graduated from law school. After law school, I clerked on the DC circuit for two years and then the Supreme Court for Chief Justice Roberts.

2:53I practiced law at a firm called WilmerHale here in DC for a couple of years. Then I changed gears, actually went into the finance world, worked at Blackstone for about four years. And during that time in an investment capacity, I got very interested in the technology behind blockchains generally. And I met the folks over here at Alio, got very interested in what they were doing. I joined initially as VP of strategy and have since been promoted to COO and general counsel. So happy to talk about Alio itself. As background, I was also an advisor to the Privacy and Civil Liberties Oversight Board.

3:32So long been very interested in issues around privacy and how they work, consistent with sort of national security and other public policy goals that we have. So Alio, if you're going to step back if you think about blockchains generally. If the internet allowed unaffiliated nodes, which is to say computers, phones, other nodes like that, to communicate with each other, even though they're unaffiliated and have no reason to trust each other, blockchain sort of took that a step further and allowed those unaffiliated nodes to cooperate on a task and specifically on updating a ledger. Now, the mechanism by which they did that is basically yelling the answer out loud, which is one node will say, hey, Craig sent Sina one Bitcoin or one ETH or one whatever, and all the other nodes write it down.

4:30And so that's how they update the ledger in terms of like data. Now, if you and I, Craig, started talking about what are use cases for ledgers, we'd start talking about obviously the financial use cases, bank accounts, that sort of thing, maybe real estate titles. We start talking about healthcare records, vaccine records, maybe voting databases. And for almost all of those use cases, if not all of them, you want some level of data confidentiality and privacy, which is to say you don't want to yell the answer to the entire world of unaffiliated nodes that you don't know and maybe don't have great reason to trust.

5:11And so what we're doing at Alio is we're allowing the same thing to happen, but for the answers to be encrypted, which is to say they yell the encrypted answers out loud. And you can still verify that everything being said is true. You just don't know what the actual content is as a completely unaffiliated node. As a user, as a program, you may, but in terms of what you broadcast to the entire world, that's encrypted. And that unlocks a lot more use cases. So we're very excited about that. So that's a very long answer to help explain what we're doing at Alio. Yeah, well, that's interesting. And you're specifically targeting machine learning solutions.

5:52Is that right? The overlap between what we're doing in machine learning and AI is really, really interesting because there are a couple of interfaces here. The first is training data. When you think about machine learning or AI using databases, one of the most obvious questions is what's in those databases and do we want to expose that to, in the context where I was talking about, unaffiliated nodes in this context to machine learning? And so one technique that you could use is something called homomorphic encryption. Another one is federated learning. Another one is actually exactly what we're doing, which is using a kind of cryptography called zero knowledge proofs to prove information from data without actually revealing the underlying data, which would allow machine learning to train without necessarily having exposure to the kinds of data we don't want, machines we don't quite understand yet to have access to.

6:54Yeah. Go ahead. Just to slow down a little bit, so I'm familiar with homomorphic encryption, and I'm familiar with federated learning. How is this different from either of those? So a zero-knowledge proof is basically an application of cryptography that allows a user to prove something about a set of facts without actually sharing that underlying set of facts. So it's a particular, and as a statement has three features. First, the proof has to be complete, meaning if someone provides the proof, we know with certainty that the underlying statement being proven is true. The second is it must be impossible for someone to provide a zero knowledge proof of a particular statement if that statement is false.

7:51And then finally, and this is the key one that distinguishes it from some of the other techniques we're talking about, is the proof must be zero knowledge, meaning the proof must not reveal anything about the statement other than the fact that the statement is true. And so homomorphic encryption overlaps with that very significantly, but it's its own distinct field. And in a machine learning training scenario, how does that work? I mean, federated learning, you're sending the model out to, different data pools that various owners have and you're training and then coming back and updating the model so that that data never has to leave the possession of the owner And the only thing that goes back are the weights from the training exercise.

9:03In this case, where is the model if you're training a model? And where is the data? And yeah, how does it work? Yeah. So, okay. Take a very simple example. example. Imagine that we are looking at certain kinds of health data and we want to know if the health data shows correlate or is there something we can learn about it based on age, which is people under 21, they have certain traits. Over 21, they have certain traits. Over 65, do they have certain traits?

9:39And in that context, you could actually look at, sorry, Can you hear baby in the background? Yeah, it's okay. It's okay. It's fine. So in that context, you can actually look at the health traits you care about and get proofs about the age of the person without actually knowing anything else about the person. So if you imagine a human doing it, they may pull out files. They may see, for example, things like the race, the name, the ethnicity, the gender, and they may allow that to affect their thinking. But if you're having like a machine learning context where the only thing you want to do is isolate sort of a scan result and the date of birth, then you can actually have it only prove that, okay, here are the people who are over 21 and here's what's happening.

10:30And is there a correlation or is there not without actually ever having to look at anything else? And so in a way, you can sort of think of it as helping to blind the learning so that it doesn't consider factors we don't want it to consider. Yeah. And the data in that case resides, say, in a hospital database? Well, so if you're talking about a blockchain, you can actually put it literally on a blockchain and then it can be leveraged by hospitals, insurance companies, anything, except they won't actually have access to the personal underlying information. So it's a matter of how you structure the data.

11:09You can have it traditionally sort of be on a database where it's like managed. In that case, you don't need a blockchain to accomplish anything I'm talking about at all. You can leverage something like$0.00 Crucible without a blockchain, or you can look at a world where you put it on a blockchain, it's completely encrypted, which means that no one can go to the blockchain and see your personal information or these health records, but you can, if you opt in, provide proofs of certain characteristics about it so that it can be studied. So it's a way of allowing your users to have a lot more sovereignty over their data.

11:44What can be exposed? How can it be exposed? And then you can combine that with machine learning to be more precise about what you're studying and what you're looking at when you're looking at data sets, as opposed to allowing machine learning to just go at it, come back with whatever it may come back with. Because what we know already is the data sets aren't totally neutral. They reflect human biases. And we may allow or permit machine learning algorithms to adopt those human biases without even understanding that we're doing that. So this allows us to adopt more safeguards against something like that.

12:20Think of it as using encryption to obscure what you're putting onto a database. The same way your passwords are obscured, same way all sorts of sensitive information is obscured, your credit card information, when you send it to the internet, you're not sending your literal credit card information. It hashes so that if your data packet is intercepted along the way, people don't actually have your credit card number. So similarly, you can use encryption to make data unavailable to the general public that may try to look at that data. But at the same time, if you put it on something like Elio, you can prove things about that data that are true or false or that fall within certain parameters and leverage that data without actually giving away identifying information.

13:11And you can tailor the parameters of that however you like. It's totally an open design space. And so this is very new. It's very, very, very early. and it's kind of ripe for creative thinking. Given that you have this tool that allows you to upload information, protect that information such that it's with encryption and yet be able to draw inferences from it and understand facts and correlations from it, how do you best leverage this? One of the interesting things, so there are two things going on here. There's the machine learning aspect and there's a blockchain aspect. What's interesting about the blockchain aspect is how it allows you to leverage something that doesn't have to live on one platform.

13:56So it's not just one hospital doing this. Every hospital can put their data together in something like this, and they can all benefit from all of the data that they're cumulatively providing without having to reveal anything about their patients to the world, without having to compromise their patients' privacy, and with getting their patients' consent of this. And they can allow their patients to retain ongoing sovereignty over this, which is to withdraw, do whatever they want, to own their data. And so thinking about how a system like that enables better forms of machine learning, I think is just a totally ripe design space, not only for products, but just philosophically.

14:40at the computer science level, at the level of theory, and at the level of actual practice. It's just totally new. And I think it's very, very exciting. And that's just on the training part. There's a lot more that helps with, and I sort of hinted at this, with actually like the output, how you can help control what factors are being looked at. And also, so take one of the products we're working on that we think is a good use case for our blockchain, which is digital identity. We allow, through this product, folks to be able to upload facts about their digital identity. It could be their passport.

15:24You can scan your passport onto a blockchain. And then you can leverage that passport going forward across platforms, completely agnostic to the platform. which is to say, right now, we all take for granted the status quo. If you go to Amazon, you give them your information. You go to Walmart, you give them your information. You go to some random website, you give them your information. But you could actually just have passport-grade digital identification that you leverage at each of these websites without actually having to reveal much more about yourself, depending on the website, depending on the nature of your relationship with them.

15:58Now, combine that with what's going on in something like machine learning, it doesn't have to just be your passport. It could be your vaccine records. It could be anything. And then you can allow machine learning to, you can allow a more competitive machine learning landscape, which is to say you can take that same data to multiple different algorithms and allow them all to train and try to come up with something from it, as opposed to having the data live on just Google or just Microsoft, where one company, We're sort of relying on one company to do its best with that. And it's a much more open source view of the world.

16:37It's a much more competitive view of the world. You know, one of the troubling things when you look at AI is how singular it seems to feel. You know, one or two or just a handful of companies potentially can own this space because of their access to data. But if you could open up that data in a way that is privacy preserving for the people whose data it is, then you can allow a lot more competition. And if you sort of believe classical theory, competition is going to result in better innovation, better products, and more responsiveness to the policy concerns that many have raised around AI. Are you familiar with Oasis Labs?

17:18I've heard of them, yeah. Yeah, because it sounds similar. They have a combination of secure hardware and cryptographic techniques to allow privacy preserving computation on the blockchain. But they have kind of a blend of strategies. strategies so from for alio's uh users uh uh all of this happens through a web interface or through an API and uh does uh yeah explain how it works from the from yeah what we're building is an open source protocol that we're hoping to launch later this year when this open source protocol launches, our audience for that is actually developers. It's people who build the applications we're talking about.

18:23We're not, for example, building a healthcare application at the moment, but I believe as people learn about what we're building, they'll start to see the potential for the things that we're talking about, which is, okay, you can leverage this open source blockchain and you can build an application on top of it that uses, for example, It funnels certain kinds of data, puts it on this blockchain in a highly secured way, and then allows it to be leveraged going forward. And one of the reasons I came up with healthcare is everyone kind of intuitively understands there's something wrong with the way healthcare records work.

18:59You have your primary care physician when you're younger. Maybe you move. Maybe they retire. It's very hard to get your records. A lot of people don't know if they were vaccinated, when they were vaccinated, what they were vaccinated against. in that environment to actually get together, okay, who is everyone who's had a screen for colon cancer? What are our accuracy rates? Who's doing it better? It's very hard because the data is so fragmented. And one of the reasons it's good for the data to be fragmented is because it's privacy preserving. If all the doctors just said, hey, everyone, here's the scan for my latest patient, then your information would be sort of revealed to the whole world.

19:39And that's not an attractive sort of way of creating machine learning, enabling data. But what I'm talking about, if there are developers out there listening to this and they're thinking, oh, that's my wheelhouse, they're our audience because they should be building, experimenting with how to do this. And when I say this, I mean, create an application that allows you to upload this specific kind of data or any kind of help data allows you to leverage it and gives you the benefit of access to the data without actually compromising any individual's personal information. And our laws aren't completely foreign to this.

20:23Our census law, for example, allows the Census Bureau to analyze data and to publish reports on that data so long as it's functionally anonymizing, which is to say the nature of the publication doesn't give away. It's not so specific that it would give away who it's talking about, right? So collecting data and preserving its privacy while benefiting from it is not foreign to us. This is just a totally new tool that I think is going to be really enhancing for the AI machine learning space. Yeah, and it's open source. So the business plan for Alio is to open source it, get it widely adopted, and then offer sort of expert services or consulting on specific applications.

21:18uh applications exactly right yeah yeah who's the competition i mean are there other open source projects like this i know this has been an active space i mentioned oasis labs uh i've had don song uh who's the the berkeley professor behind it on the podcast uh but i frankly haven't looked at any of this for a long time. Do you, is there a competition? First of all, I think I would do terrible injustice to all the really talented people out there working on this from one angle or another. So I would be reluctant to sort of have a list. Right now, I don't think of it as a competitive space. What do I mean by that?

22:02I sort of think of it as an innovative space where everyone's trying to build out what the technology can enable at an infrastructure level. and then what's enabled on top of that is really, really incredible. And then that's sort of when competition kicks in. So now when I see people working in this space, I sort of view them as really important in a sense partners because they're doing R &D, they're doing the marketing. And the reality is there are computer scientists, very smart computer scientists like Dan Bonet over at Stanford who know this inside and out. But the world of developers, they're still learning about this.

22:38And so anyone kind of introducing these tools to the world, explaining these are tools you can use, I view as sort of a partner. It's just too early to think of. It's sort of being like, who are the competitors, you know, around the Internet in the 1980s? Like you could conceptualize competitors, but it's just a little too early to think of the space that way.

23:01What is ZKML I see on your website? Yeah, so ZK in our space is a common way of saying zero knowledge. Okay. So it's zero knowledge machine learning, which is to say machine learning based on an algorithm that does not have access to the underlying data, can only draw inferences from it. Yeah. So where are you in the project right now? You say that it has not been launched or, yeah. Yeah, we're in the midst of our test at three. And so we just opened up the ability to deploy applications, and we've had many hundreds of applications deployed on our testnet. So far, it's working really well. The point of our testnet is to identify bugs, to invite an open source community to sort of begin the project of making this a global open source project, as opposed to something that we own or are particularly important for.

24:05because, as you said, we'd like to pivot to applications and enabling use cases on top of it. Yeah, and how large is your developer base right now, people that are participating? Yeah, there are lots of different ways to measure it. There's the programs that are being deployed. There's the nodes that are being run, many thousands. Right now, what I find heartening is that there's a very enthusiastic core group of folks thinking about zero knowledge on our testnet, on other projects. And that group seems to be getting larger and the contributors are increasing in what feels to be exponential with exponential numbers.

25:00So we're sort of very heartened by all the trends we're seeing there. And then the number of people who are not computer scientists who are familiar with zero knowledge proofs is increasing. The Treasury Department released a report referencing them. The Office of Science and Technology Policy at the White House is getting familiar with this technology. So the audience for this is growing really, really fast. And we're very excited about that. And I think it's time for the machine learning world to recognize the Venn diagram overlap here because it's very interesting. I mean, let me give you another way that this can be leveraged that I think intersects with machine learning and the user experience online.

25:46So right now, if you go to Amazon or Walmart from the United States, through your IP address, roughly knows not only you're in the United States, but like maybe what city you're in and maybe even more specific than that. And you don't think too much about it, but the products that it shows you are a function of that. So what's available to you given where you are. And if you went to France, you'd have a slightly different experience. And if you went to another country, maybe you'd have a very different experience or no experience at all. So that's to say that the internet currently, and by extension, any machine learning model on top of that, understands where you are and gives you an experience that's somewhat tailored to that.

26:26We could also build it so that, let's just take the digital identity concept. Amazon or Walmart or the next website would know that you're under 12 or under 18 or over 21. And you wouldn't think too much about it, but what's available changes. Is alcohol on the website? Is certain adult content on the website? Or dangerous things on the website? You know, things that 12-year-olds should be playing with on the website. And as a result, the machine learning that's built on top of that could also be leveraging that information, again, without knowing name, date of birth, anything specific to the individual, just that, hey, maybe certain things are age appropriate.

27:12Maybe we don't want machine learning for children of a certain age. Or maybe if we do want it, we want it tailored a certain way and we have certain public policy goals that matter. So having credentials like this that can be leveraged and that the entire internet would be responsive to has the trickle-down effect of any sort of what I'll broadly call machine learning on top of that, sort of watching the user experience, seeing how the user interacts would be sensitive to that particular criteria. And so you can imagine when you're thinking about TikTok or social media, that this could be very important, especially to parents.

27:54Yeah, it's, so that application relies on kind of the passport idea, the ID for an individual that then is accessed by whoever

28:15wants to access that individual? I mean, how would that work? Yeah, so think about how it currently works, which is you go to buy wine on a website, they ask you, are you 21? You click yes, that's the end of the questioning, which probably good enough security for wine. We probably don't have an epidemic of minors ordering wine on websites. But where you have greater concerns, maybe you want something more than just data that an individual can arbitrarily input. You know, if they know they just need to pick something that says they're over 18 or over 21, they'll just pick it. And so you can have a lot of fake identities.

28:50I mean, this applies in so many contexts, by the way, Craig. If you look over at, like, ticket sales, something like 40 % of ticket sales are sold to bots. So put aside a human lying about itself. It's just like something that's trained to lie to the actual merchant. You can replace that with something where you have, again, passport grade identification, which can't be faked, digitally signed by the U.S. government, can be authenticated against the U.S. government database. and that would be the identifying credential. And so the ability of a child to suggest they're over 21 or the ability of someone to suggest they're a US citizen when in fact they're a North Korean citizen, I think it limits that very significantly because you're talking about passport grade security where some of these websites just have clicked through, you're 21.

29:47and and to to develop that uh and that that uh there would be a key or something that yes someone would use there'd be a combination of a of a private key which is specifically the individual uh and live scan which is to say something to so if i had your private key uh you know the live scan would show actually it's not craig even though he has craig's private key uh and in the case of parents, you can imagine introducing multi-party computation or other things so that maybe there are even two or three keys are necessary for login. It's just a matter of how you, again, it's an open design space.

Read the full transcript

30:25It's how you want to design it. But this is introducing the ability to have one digital identification that is passport grade across all these websites, as opposed to you go to TikTok, you share your passport information with them. You go to, But, you know, Instagram, you share your past sharing your passport information with everyone. And by the way, none of these websites really want to be responsible for collecting that kind of information. Right. Now, on the other side of it, what's I think particularly interesting for policymakers and for and for a lot of parents out there is that once you introduce technology like this, the the excuse for, for example, a website that has like adult content to not be screening out minors goes down very, very significantly.

31:10They can't say, oh, we didn't know, they tricked us. It's you have a way to figure this out, right? And that also applies to anyone collecting data, which is to say their excuse for holding your data in this honeypot that hackers find very attractive goes down. Once you introduce technology like this, that's no longer necessary. Now let's go over to like AI, what we're specifically talking about. Right now, when we talk about data privacy, it's typically sort of a privacy policy, you know, a long scroll down thing about what they're going to do with your data that many people don't read, they click through, they move on.

31:44But you can start introducing data minimization. Again, not foreign to the Census Bureau. And it's just a concept that says you have to use reasonably available technologies to minimize what you're doing with people's privacy. Right. And in many contexts, I think that's going to be very attractive. It's going to be attractive from a product design perspective, which is to say even if policymakers said nothing about it, users may have preferences. But from the perspective of policymakers who, you know, at least with Western values, we care a lot about people's privacy, what that means for their dignity.

32:21And so we are not going to have like our government go and collect everyone's data and like feed it into some sort of machine learning exercise. We maybe other countries would do that, but we wouldn't. Now, this is a very interesting way of saying, okay, well, we can continue with the machine learning. We can actually pioneer this technology, but we don't have to invade people's privacy to do it. So what is it going to take for widespread adoption, which is always the case with these things? I mean, I've listened to so many ideas or proposals that sound great, but until you reach the tipping point where it's widespread and generally accepted, it remains kind of a niche.

33:18Yeah, I think that's completely right. And there's a difference between having theoretical conversations and actual solutions that are adopted in practice. If you look at zero-knowledge proofs, they were invented as a concept in the 1980s. Five, six years ago, the time it took to do one transaction for a zero-knowledge proof, orders of magnitude slower than today. That's a result of investment in R &D that's happening in the United States and happening globally. And that time is going down and it's scaling better and better and better and faster. And what happens with these systems is as we get better at doing it on the software side, we can actually specialize hardware to do it faster and faster and optimize at the hardware side.

34:02And that's the transition from having something like a CPU to a GPU to even in certain circumstances, an application-specific integrated circuit, which does one thing, but does it very, very fast and optimized, right? So that starts to make this practical for large scale uses, like whether it's credit card data or health records, that kind of thing. So we're getting closer and closer to technologically of being there. So if you think about the Internet, when it first starts and it sort of dial up and it's very, very slow. And we could talk about video streaming in that in those days, but it's it has to get faster.

34:40And the way it gets faster is more investment. And the way you get more invested is you get more excitement about what it's actually capable of. So I think to answer your question, what it takes is more people learning about the potential here, more people experimenting with design space, support from the government in terms of R &D around privacy enhancing technologies as a way to enhance how we do AI and machine learning. And just more experimentation, as I said. that will, if this design space proves itself out, and I think it will, encourage more investment, and you'll see it scale better and faster.

35:19So from my perspective, when people talk about something like blockchain, we've long been in that like 1970s to 1980s era for the internet, which is the concepts have been introduced. There is this new and interesting thing we can do, but it's not quite practical yet. And we're getting closer. And the only distinction between, in my mind, between the timeline for the internet and the timeline for something like blockchain technology is open source systems tend to have a lot more eyes on them and they tend to move a little bit faster, right? So it's not a small group of resources doing it. Anyone can open up Bitcoin's code or the next project's code and learn from it and build on it.

36:04Yeah. Yeah. Has the government expressed interest in this or are you working with any government agencies to include them in the open source project? Yeah. So the White House Office of Science and Technology Policy invited comment letters earlier this year on privacy enhancing technologies generally. we issued a comment letter in response to that. There's a lot of interest on the Hill in terms of privacy enhancing technologies, especially as it relates to machine learning. There's a lot of interest around digital identity. I think people understand that we can do identity better. We can do it in a way that increases compliance, that increases reliability, and also increases privacy, which is kind of an interesting combination.

36:55Usually those concepts are seen as intention. As it relates to blockchain generally, I think we've been a little bit tripped up on threshold questions about, you know, whether a particular token is a security or not a security. There are these open regulatory questions that I have confidence will resolve over time. And I think, especially as it relates to crypto, there's been a lot of focus on the asset itself, because it's invited this speculative frenzy around the value of some of them. Everyone's heard some story about how somebody got very rich off of a Bitcoin or a Dogecoin or the next thing.

37:36And so a lot of the social commentary has been around those asset values. But one of the insights that we had is if you look at Bitcoin, for example, it's not just a ledger for Bitcoin, it's a ledger for identity. Each one of those public addresses is an implied identity. Now, it's transparent, which means once anyone figures out that it's your address, they'll know your whole transaction history. So it's not really workable for a lot of the ledger uses we've talked about. But if you add a little bit of privacy to that, you can actually add a lot of meat to what the identity holds and what it says and how it can be leveraged.

38:12And so those are the insights I think that will take this technology to the next level. And I think the government's very interested in that and they should be. How does this project intersect with the Web 3.0 or Web 3? Yeah. If I understand the term Web3 charitably, I think what it's getting at is the ability for nodes, i.e. computers on the internet, to hold and transfer digital assets. In the past, when we think about that, we sort of had this copy-paste problem that's required in intermediary, which is say, take music. If I have a song and I sell you the song, I can just copy paste it locally and tell you the song.

39:00And so now there's two of them. And then the value of the music plummets because there's infinite supply. And one of the things that Bitcoin did is actually come up with a way to enforce scarcity without requiring an intermediary to own all of that. Because once you introduce the intermediary to own all of that, if you take, for example, a health record, they become a very powerful, almost monopoly that is the owner of records that you don't want them necessarily to own. Right. So insofar as Web3 references the ability of nodes to own assets, transfer assets, we're very much sort of within that definition.

39:45in that this would be a decentralized open source project that allows hospitals or anyone to build on top of it something where credentials and assets can be moved around and leveraged without necessarily meeting any particular intermediary. So let's presume that this becomes widely adopted. from a consumer's point of view for the ID, what would I have to do to get my ID key and then use it on various websites? Yeah. So if this is adopted, the consumer could use their phone to scan their passport. Your passport has a chip that allows it to be scanned. to be scanned. So you can scan and upload all your information onto, um, one for like, let's just say there's a, a project emerges called like ALEO ID.

40:51Um, you can upload it through ALEO ID and then that project ALEO ID would have to go to, you know, the e-commerce websites, the, uh, where, wherever and have them integrate so that when the user shows up to the website uh that underlying id is leveraged um for example to make sure that content is age appropriate so that would require the open source project and and i presume there's a there's a foundation in addition to the private company is that right yeah yeah so so imagine there's the open source project that's just the layer that exists then a team would come a company would come it could be for profit it could be just it could be non-profit it could be the government um and they would build an interface that allows people to say okay we're going to scan our passports uh onto the blockchain and then that company would go to whoever uh amazon or a gaming company right you can go to gaming company you can say okay the amount of bloodshed or violence or whatever should be limited for this age group or certain games can't be downloaded by this age group and so when you go to that website the same way for example you have single sign-on with like google or or anything or just you can even do it as like a the way ip addresses work which is the user doesn't need to experience anything you can just go to the website leverage that those credentials and then get the appropriate experience based on those credentials without ever telling the website again, hey, I'm Craig, I'm this age, or hey, I'm Sina, I'm this gender or this country of origin, the other things that are on your passport.

42:43So just to take a simple analogy to visualize what this looks like in the real world, if you go to an event and you're on the guest list and they give you a wristband, and the wristband indicates, for example, you're over 21 and you're on the guest list. The bartender never asks for your ID in that context. They just know from your wristband that you belong there and that you're over 21. Without the wristband, you would show the bartender who you don't know your name, your address, your date of birth, the issuing state of your id all this all this information has nothing to do with you getting a drink at an event and so this is kind of like a digital wristband where when you show up the the experience is tailored based on uh who you are without actually having to reveal who you are to your counterpart right and the and when you say you show up in the physical case you're wearing a wristband And in this case, it's this key that represents your identity on the blockchain.

43:58You would enter that when you're registering with the website? Or would that be tied to your, I don't know, your IP address? Yeah, there's a couple of ways to do this. I mean, it could be tied to your actual particular device. So you sign into your device, right, with your face scan, and it could automatically leverage those credentials. It could be on a per website basis, the way you do Google single sign-on. There are a lot of, again, it's very early. I think it's too early to predict what the winning product looks like. But from the user's experience, I would hope that product is seamless. I would hope it protects their privacy.

44:34And I hope that it would help them have an experience online that's appropriate, especially for their age. You know, again, nine-year-olds on the internet, different experience than 40-year-olds on the internet. And I think those are things that we can build in reliably now. And the old excuses about, well, it's impossible to verify age or it's prohibitive. Those, I think, are going to fade away. And I also hope that what it means is the days of us giving away our addresses and our dates of birth and other personal information to hundreds of websites, none of which exists because they're particularly good at security.

45:10They're e-commerce. They have different missions. Their mission is not security. and exposing ourselves in these centralized honeypots all across the internet just to have an internet experience. I hope that we can look back soon and see that for what it is, which is a security nightmare that compromises the user experience in totally unacceptable ways. I mean, when is the last time anyone even had an emotional response to a major hack? We've had OPM hacked. we've had those who keep our credit scores hacked you know that's as much data as as you could possibly want from the perspective of a hacker and much of this is needlessly kept yeah yeah and then from the point of view of uh like a hospital that has a lot of data that wants to make it available to a machine learning training exercise, there would be some...

46:16Yeah, you can build a mechanism that allows you to do that. What I really like about this is that the mechanism can be agnostic to the machine learning counterparty. Right now, we've sort of built a system that rewards monopolists or oligopolists in the sense that they can go and do the paperwork of collecting the data. And then they're the only ones who have like a stab at this. But all of us know intuitively, if you stipulate the patient data is protected, it's better to have 10, 20, 30 companies competing to do this better. right and we we can more enable that as we learn to play with encryption as a design tool so that we can actually invite competition into machine learning instead of taking for granted as many do now that the biggest companies are inherently already the winners what's the the next step for you guys then i mean if presumably you say there's a foundation and then the company I mean, if people want to explore this, certainly they can go to alio.org.

47:27That's A-L-E-O dot O-R-G. But I would guess there is a whole GitHub page or repository or something where people can get involved in the open source project. Open source. There's a GitHub repo. We are testing that it's currently live. They can actually go and deploy applications, you can simple, very simple applications, or we welcome more complex applications just to sort of learn how this works. We have a language called Leo, which abstracts away a lot of the hard cryptography and makes it accessible to developers more generally. They can experiment with Leo, learn to use that. We welcome feedback.

48:17We welcome any sort of feedback, whether it's we're looking for bugs, we have a bug bounty, but we also what makes it better from a developer's perspective. Because the next steps, our priorities are to take this from the realm of computer science and make it available in the realm of engineering and developers and people who are just typical coders. right because then once you open up that audience it it can go outside of my theorizing about what's interesting and they can actually put rubber to the road and figure out what works from a product perspective and I think when it really gets interesting is when you start having product managers think about who are end users what is the best experience for them what facilitates distribution the questions that make this a practical reality as opposed to a very neat computer science breakthrough that's theoretically interesting.

49:15You know, as I said, I've talked to people about this over the last five years, similar kinds of things. Do you have a sense? It's a little bit like autonomous vehicles. uh we've been talking about it for a long time and and we're still waiting do you have a sense when when this whether it's uh alio's solution or oasis lab solution or somebody else's solution how long it will be before we're actually using this stuff in our daily lives yeah look i think it's up to the open source community who work on this. It's up to us. It's up to all the other projects that are working on this to make this more like the internet in the early 1990s than the internet in the late 1970s, which is to say, educate people, show them the tools, show them the possibilities, publish blog posts, thinking about different solutions.

50:25We had one of our computer scientist Ian Myers published a paper on identity. We took that paper and used it to build out a proof of concept around the digital identity product, which is looking really attractive already. So in some sense, these products are, I think, you know, on a 12, 18 month timeline in terms of like being practically available. Now, whether teams execute on 12, 18 month timelines, that's a different question. But I think something like digital identity is currently plausible and is very, very interesting. And it's something that should be, I think, a very high priority for governments in particular, because it's a really attractive way of making the mess of the internet in terms of like hackers, all the stuff we've been talking about, the data that's available privacy a lot less messy and a lot more user-friendly.

51:21Yeah. The more complicated things that we've discussed, which is making healthcare data broadly available to multiple teams of scientists, you know, the issue there is less a technological issue, as is the case with electronic health records, and more getting the institutions that are currently incumbents and how they own data and how they monetize data. Sometimes the incentives aren't perfectly aligned there, and that could be a longer process. So there's the technology, which is like closing in on availability. And from here on out, I think the main thing is educating people and increasing its ability to scale.

51:58And then there's just sort of the real world dynamics of where is an easier place to disrupt? Where are there incumbents who are going to be very resistant? That sort of thing. Yeah. Are you talking to any of the big social media platforms? um you know what one of my pet peeves is is uh twitter because of the enormous amount of sort of toxic speech that goes on there and um you know i wish elon musk would require people to register their twitter accounts under their own names uh i think it would it would you know you would see a lot of that toxic speech disappear. It's a great point. I mean, it's amazing the extent to which the social media experience has disappointed many, many people.

52:54And it's also amazing the extent to which not having control and sovereignty over our data has been used against us. If you mentioned in 2010, for example, that social media would result in data leakage such that foreign adversaries could use that data and leverage it to make us mad at our neighbors and us yelling about more things and the blood pressure of our country to go up, it just would have seemed a little bit implausible. How would they do that? Why would we respond that way? It seems a little silly. And yet, that's sort of what's happened. Our data has been, rather than something we own, it's been turned against us.

53:39on the pros side, it's like maybe the advertisements you see are a little bit more relevant. And on the cons side, the country is more divided because they're spiraling with bots and they don't know they're interacting with bots and there's a lot less accountability. So I think it's a really, really wise thing to point out. And from our perspective, it would be very attractive to start leveraging things like identity in a privacy-preserving way that authenticate what's happening. I mean, one of the things, Craig, we didn't talk about the near-term risk of what people broadly call AI is the ability to fake content.

54:14We're all familiar with faking an identity in the sense that there are all these bots that are clearly not humans, but there's also increasingly what we understand of fake news, but fake quotes, fake audio files. Over time, there's going to be fake visuals, fake video. And the ability to authenticate data and content by linking it back to users without exposing the privacy of those users is a very attractive proposition. Because you can say, okay, well, that actually did not come from the phone they're suggesting it came from. And we don't need to actually reveal anyone's data. We just know that it's a non-authenticated image and therefore highly much more suspect.

54:57Um, so I think not just social media, but the ability to authenticate in a courtroom, actual content, like the person say that, and you, you may know as well as I, but if you go and look for like videos that are faking what politicians are saying, you're getting increasingly persuasive looking and sounding stuff. Uh, and so authenticating while preserving privacy, uh, highly attractive, particularly in the context of social media. Yeah. But are there conversations going on with any of those social media platforms about this technology? No, we haven't had direct conversations, but I think that would be really attractive.

55:39Our focus over the past two or three years has been completely on the computer science and converting it into sort of an engineering reality. But now's the time, you know, and I think we would be very interested in talking to Elon over at Twitter or any of these platforms about integrating this to provide their users better experience. I mean, there's just no way. They're monetizing data and that is their business model in many ways. But there are things happening on social media that is not the intent of the owners of these social media platforms and that they would acknowledge as bad. and they don't know what to do with it and they're not particularly incentivized to know what to do with it.

56:18So we'd be very happy to talk about solutions on that front. Okay, so that's it for this week. I want to thank Sino for his time and I'd like you again to consider visiting netsuite.com backslash ionai if you're interested in a full implementation of Oracle's software with no down payment and no interest for six months. As always, you can find a transcript of this episode on our website, eye-on.ai. I find that you see a lot of things and understand things reading a transcript that you miss with purely audio or visual. And remember, the singularity may not be near, but AI is changing your world, so pay attention.

From the publisher

Welcome to episode #124 of the Eye on AI podcast, where we bring you the latest insights into the fascinating world of artificial intelligence. In this episode, Craig Smith is joined by Sina Kian, General Counsel and COO at Aleo, as they dive deep into the revolutionary realm of zero-knowledge proofs.

Join us as we explore the incredible potential of zero-knowledge proofs in safeguarding sensitive data while leveraging it for machine learning and AI applications. Sina Kian provides shares how this innovative technology can reshape privacy, digital identity, and even social media authentication.

During this conversation, we delve into the power of privacy-preserving blockchain technology and its far-reaching impact across industries. Discover how Aleo is at the forefront of making digital identity more secure and how it can be seamlessly integrated across platforms without compromising sensitive information.

We examine the future of machine learning and AI, unraveling the role that digital identity plays in accessing products and content based on location. As we venture into the depths of the social media landscape, we also explore the risks and rewards associated with user data and privacy. Gain insights into how privacy-preserving technology can shield user information and authenticate data and content without compromising privacy.

This conversation will discusses the potential of zero-knowledge proofs and privacy-preserving technology, offering a glimpse into how they will shape the future of machine learning and AI.

(00:00) Preview

(00:41) Introduction

(02:28) Sina Kian's background in Aleo & blockchain  

(05:49) Blockchain's integration with AI & machine learning

(11:48) How data is protected in blockchain technology

(12:25) Use cases of encryption with Aleo

(18:53) How Aleo works with an open source protocol

(24:13) Aleo's progress in developing its open source project

(31:13) Why social media platforms capture your data

(34:16) How can you find widespread adoption?

(35:43) How the government are getting involved in digital identity

(41:53) How data privacy integrates to Web 3.0

(45:15) Blockchain's implementation in the real world

(48:43) Next steps from Aleo

(53:53) Social media interaction with privacy 

 

Craig Smith Twitter: https://twitter.com/craigss

Eye on A.I. Twitter: https://twitter.com/EyeOn_AI

 

More from Eye On A.I.

All 266 episodes
#124 Sina Kian: Reshaping Privacy in the AI & Machine Learning RevolutionEye On A.I. · 57 min
Listen in VO