Earlier quoted context omitted.
You're downplaying the implication of "moving one part of the architecture to the client". This inversion of the model means the user is sovereign over their data. It means ad fraud (responsible for billions lost) is dealt a massive blow. It means the publisher doesn't have to watch hand after hand take from their revenue before it reaches them. It means the user, finally, can get paid for the limited commodity calle…
Theoretically, could the (server-side) records of which ads the local machine learning decided to serve be reverse engineered to extract most of tracking info? Local AI keeps sending this guy ads for shoes and cottage cheese == this guys keeps searching for shoes and cottage cheese?
We have a passionate group of security-minded folks internally who have been exploring ways to game the system, and closing those holes preemptively.
I'd love to see us publish something in the future about specific types of attacks which work on the present-day model, but not on our model. Additionally, what types of new attacks could be possible, and how we've prepared.
Suffice it to say, having the home-field (the user's machine) advantage is going to play well in our favor.
Great topic!