Live data from Hacker News

Google is making private AI practical with homomorphic encryption

blog.google

101–110 of 305 posts

Re: Google is making private AI practical with homomorphic encryption

#101

Earlier quoted context omitted.

You are very wrong about all of this btw.

You literally don’t know who I am or the roles I had. So unless you can tell me how many steps you were from Kent Walker and what you worked on I’m gonna bet a hell of a lot I know more than you. Edit to clarify my prior point: some of the technology makes it into the product, but the putative data protections do not. Why? Because there is always a work around, and ads legal will approve it every time.

> You literally don’t know who I am or the roles I had.

I'm now curious. Who are you?

Re: Google is making private AI practical with homomorphic encryption

#102

Have all the skeptics in this thread somehow forgot about Moore's law?

What, how is that relevant? the transistors on a microchip double about every two years. That’s descriptive, not prescriptive, so whatever you’re trying to imply about the future is kindof a toss up — there’s no promise the parents hold. And, it doesn’t really have to do with tfa, as far as I can tell? Do you perhaps mean Murphy’s law, “whatever can go wrong will go wrong”?

The top comment mentions a ~10^3 overhead. Am I crazy (or already old?) for thinking this is not a very large constant?

Re: Google is making private AI practical with homomorphic encryption

#103

Encryption or not, if it's on somebody else's server, it isn't yours. I don't believe Google has my best interest.

Unless all of your money is under your mattress, you're already making such decisions with a far more valuable asset.

Re: Google is making private AI practical with homomorphic encryption

#105

My master's thesis is on a topic in this field (Privacy Preserving ML) and from my understanding HE and other techniques have very high overheads(~10^3) on inference tasks and thus aren't very commercially viable.

Commercially viable for Google boils down to can they attribute ads behaviors to it or not. Then there’s a second tier of things that just make those wheels turn and if they do or don’t make ads revenue is nominally immaterial. The teams doing this stuff at Google are purely for show, none of this makes it into any real products. There’s the narrow exception of stuff like gboard, that does use privacy preserving ML/f…

GCP exists, friend. Right now industries are locked out of AI tools due to privacy laws.

If Google Cloud can offer FHE-powered tools, a hospital can run Google’s AI diagnostic models on encrypted brain scans without violating privacy laws.

FHE effectively removes the primary regulatory barrier keeping enterprise customers off the cloud.

Re: Google is making private AI practical with homomorphic encryption

#106

Great, private AI, at the cost of >1000x the resource usage. Because apparently AI companies weren't already using quite enough energy to cook the planet. The most private AI is the one running on my own hardware, not in some giant data center.

Aren't there already much more efficient ways to make inference private? Using regular encryption and secure enclaves, there are already providers that are roughly 2x the cost of normal providers. For example, https://tinfoil.sh/

If I used regular encryption to send my credit card information to an AI with fraud detection, the provider still needs to decrypt that data on their side at some point before it goes into the AI.

Using this other encryption, the provider has neither need nor capability to decrypt it on their end, so the user gets extra security.

Re: Google is making private AI practical with homomorphic encryption

#107
post #86

Great, private AI, at the cost of >1000x the resource usage. Because apparently AI companies weren't already using quite enough energy to cook the planet. The most private AI is the one running on my own hardware, not in some giant data center.

where does this factor "1000x" come from? I have doubts.

Most likely from above in thread.

There is no reason to believe it should be lower than that - or even that low. Or do you have access to research claiming such achievements?

Re: Google is making private AI practical with homomorphic encryption

#108

Earlier quoted context omitted.

What, how is that relevant? the transistors on a microchip double about every two years. That’s descriptive, not prescriptive, so whatever you’re trying to imply about the future is kindof a toss up — there’s no promise the parents hold. And, it doesn’t really have to do with tfa, as far as I can tell? Do you perhaps mean Murphy’s law, “whatever can go wrong will go wrong”?

The top comment mentions a ~10^3 overhead. Am I crazy (or already old?) for thinking this is not a very large constant?

Oh I see, you’re arguing that computer growth will make this more attractive. I think it’s a decent argument, although personally I find it unconvincing. More compute will be allocated between all the existing options, and I suspect it will go towards faster/better inference, instead of encryption. For most use cases people just don’t care much about encryption, and when feature prioritization comes around it always gets a back seat

Re: Google is making private AI practical with homomorphic encryption

#109
post #39

Earlier quoted context omitted.

I suspect that your one moment of thought follows many years of contemplation. Maybe you can fill us in on some of that background.

E2E encryption means that if the user loses the keys, there is no way to recover that even if they contact support and prove the data belongs to them.

> there is no way to recover that even if they contact support and prove the data belongs to them.

Eh, since Google's support doesn't exist in the first place, none of this really matters, and nothing is lost.

Re: Google is making private AI practical with homomorphic encryption

#110

Earlier quoted context omitted.

You are very wrong about all of this btw.

You literally don’t know who I am or the roles I had. So unless you can tell me how many steps you were from Kent Walker and what you worked on I’m gonna bet a hell of a lot I know more than you. Edit to clarify my prior point: some of the technology makes it into the product, but the putative data protections do not. Why? Because there is always a work around, and ads legal will approve it every time.

and you don't know who I am. I might have been closer to that work than you would know.
Post reply on HN