Rendered at 17:21:25 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
bmenrigh 2 minutes ago [-]
Has FHE really progressed so far that it's now so efficient that doing computation on an encrypted prompt is feasible? I thought even basic operations like FHE addition were still thousands of times more complex. The only mention in the article I see is:
> But while homomorphic encryption has a nontrivial cost overhead, it shifts the capability/privacy trade-off to a question of cost. And the cost of homomorphic encryption is rapidly decreasing.
Which doesn't spell out exactly hon "nontrivial" the cost overhead still is.
sabretooth1405 26 minutes ago [-]
My master's thesis is on a topic in this field (Privacy Preserving ML) and from my understanding HE and other techniques have very high overheads(~10^3) on inference tasks and thus aren't very commercially viable.
Cider9986 22 minutes ago [-]
This is the same Google that doesn't have e2ee on their password manager by default. Like WTF, it's a password manager.
amazingamazing 8 minutes ago [-]
If you think about it for a moment you will realize the average user does not want that.
filup 28 minutes ago [-]
Proper encryption means the ciphertext is indistinguishable from noise. So...in order to be able to process on it, you have to make it not indistinguishable from noise.
So I take offense to the term FHE. It's a oxymoron.
The whole thing immidiatly stands out as a sham to build trust where it's gone.
Ar-Curunir 3 minutes ago [-]
[delayed]
pluto_modadic 23 minutes ago [-]
they could have gone with an oblivious transfer approach (where it's working on what looks like multiple problems at once, you don't know which)
drdeca 23 minutes ago [-]
Eh? With secret sharing one can do computation on a shared secret where it is provable that no individual party can recover any information about the data with their share alone.
I don’t see why you conclude that FHE couldn’t be close to as secure as that. (Like, not information theoretically, but with computationally bounded adversaries.)
filup 2 minutes ago [-]
I'm not saying that you can't design a system for secure cloud computing.
Deukhoofd 37 minutes ago [-]
It sounds neat, but I do wonder how viable this is commercially. How high do we rate the chances that governments around the world will step in before another kind of E2E is rolled out.
29 minutes ago [-]
oulipo 7 minutes ago [-]
Zama.ai is also a player in this space
FloatArtifact 2 hours ago [-]
Encryption or not, if it's on somebody else's server, it isn't yours. I don't believe Google has my best interest.
u1hcw9nx 2 hours ago [-]
With Fully Homomorphic Encryption it's nobody elses.
The basic idea of of the project is to remove the need for trust.
unsungNovelty 58 minutes ago [-]
It's google. They are good at engineering. Not at creating trust. After the bizillionth time they have broken trust, there is no need for benefit of the doubt.
Plont 28 minutes ago [-]
Yeah. Google is an ad business. Their entire motive for getting invested in AI is ad revenue. We're supposed to believe they just... won't turn on the money fountain? After going into the red for their data center investments? Hell nah.
I'd expect this to be something like the Google Ad ID: technically separated from what Google considers personal information, but trivially easy to tie back to an individual person and to other information about that person.
They're continually breaking trust by illegally scraping up the internet to feed to their plagiarism machine, which they are now asking us to trust with more data. It's not a compelling arguement.
throwaway27448 29 minutes ago [-]
There's more to life than branding.
tonyhart7 28 minutes ago [-]
so what's the option ??? Meta ?? xAi ?? or OpenAI ???
unsungNovelty 20 minutes ago [-]
Why should there by any reason to look at the above ones? We are talking about this B2C company which effects a lot of our lives. The discussion isn't about that or this. The discussion is about JUST this specific company.
an0malous 4 minutes ago [-]
Apple?
thih9 49 minutes ago [-]
To what end?
krunck 55 minutes ago [-]
It's FHE for "cryptographically-secure private AI inference" not for every other service where they snoop into your behavioral information.
kccqzy 23 minutes ago [-]
This kind of attitude is really disrespectful of decades of progress in cryptography. Without even considering homomorphic encryption, classic encryption is specifically designed to make intermediate nodes such as ISP dumb pipes that do not know the contents of communication. The ISP can store your communications on their server however they want.
If you don’t agree with this model, I’m afraid modern cryptography doesn’t have anything to offer.
jewel 5 minutes ago [-]
[delayed]
jrm4 15 minutes ago [-]
Correct. I appreciate the theoretical technology here, but I believe a great deal of harm is done by the fact that people are not likely to understand exactly what this means.
Which is to say, I believe that google is strongly implying the falsehood of "no one at Google can read your stuff."
LoganDark 39 minutes ago [-]
One flaw with FHE is that it guarantees only that you need the key to see the inputs or outputs of the computation, but not necessarily that the computation is the one you want. For example, the computation could be adversarial for certain inputs, or an adversary could insert their own computation first (or last).
noman-land 23 minutes ago [-]
100% not an expert but my understanding was that part of what you are proving by signing the computation is that the computation itself was performed specifically as agreed to. I may be mixing this up with zero knowledge proofs.
LoganDark 18 minutes ago [-]
If this were the case it would be necessary to send the entire model weights in response to every request which would be a bit inconvenient.
noident 53 minutes ago [-]
Does this rely on the Trust Me Bro model, or is there some way for the client to verify that the provider actually isn't able to see your inputs?
I want to read a whitepaper but all I can find is the tl;dw conference presentation
eslaught 46 minutes ago [-]
The linked project page [1] claims to be fully homomorphic. Assuming the claim holds (I haven't verified it), then there is provably no way for Google or anyone else to obtain any information from the encrypted data or computation performed on them.
FHE is traditionally horrifically slow, so it's hard to imagine running anything beyond toy models with it. They list some applications on the original article page, but (presumably) they must be dramatically stripped down in order to run within any reasonable time budget. This is not going to run anything like a Sol/Opus any time soon.
Related, I'd seen this blog [0] posted on HN a few years back that gave a nice run down on the "programmable cryptography" space which introduce FHE and a few other neat concepts. Really enjoyed the read and learned some new terms.
> But while homomorphic encryption has a nontrivial cost overhead, it shifts the capability/privacy trade-off to a question of cost. And the cost of homomorphic encryption is rapidly decreasing.
Which doesn't spell out exactly hon "nontrivial" the cost overhead still is.
So I take offense to the term FHE. It's a oxymoron.
The whole thing immidiatly stands out as a sham to build trust where it's gone.
I don’t see why you conclude that FHE couldn’t be close to as secure as that. (Like, not information theoretically, but with computationally bounded adversaries.)
The basic idea of of the project is to remove the need for trust.
I'd expect this to be something like the Google Ad ID: technically separated from what Google considers personal information, but trivially easy to tie back to an individual person and to other information about that person.
They're continually breaking trust by illegally scraping up the internet to feed to their plagiarism machine, which they are now asking us to trust with more data. It's not a compelling arguement.
If you don’t agree with this model, I’m afraid modern cryptography doesn’t have anything to offer.
Which is to say, I believe that google is strongly implying the falsehood of "no one at Google can read your stuff."
I want to read a whitepaper but all I can find is the tl;dw conference presentation
FHE is traditionally horrifically slow, so it's hard to imagine running anything beyond toy models with it. They list some applications on the original article page, but (presumably) they must be dramatically stripped down in order to run within any reasonable time budget. This is not going to run anything like a Sol/Opus any time soon.
[1]: https://heir.dev/
[0] https://0xparc.org/blog/programmable-cryptography-1