5 ms·
BlindAI API: An open-source and privacy-first OpenAI alternative
- cosentiyes 4y ago"We can’t listen to your queries and no other party can. Privacy is built by design in our solution." I don't really understand the technical solution behind this statement. Isn't this just e2e encryption up until you decrypt the query to pass to the LLM? ML operating via homomorphic encryption is very far away and OpenChatKit is just a standard self-hosted LLM. This seems more like "self host on semi trusted azure compute that isn't owned by openai and the model performance will be far worse than gpt4"?
- DanyWin 4y agoThank you for your input! We are not using homomorphic encryption as it would be too slow. We are working on hosting OpenChatKit inside a secure enclave that benefits from hardware isolation to protect data while it is in clear for the application of the AI model. We have developed an attestation system that does not rely on Cloud providers, but is closer to the ones provided by hardware provider, for instance Intel. You can find more about our attestation here: https://blindai-preview.mithrilsecurity.io/en/latest/docs/advanced/security/remote_attestation/ https://blindai-preview.mithrilsecurity.io/en/latest/docs/ad... The goal of our work is to provide a more transparent and privacy-friendly interface for people working in sensitive industries to leverage LLMs. With the attestation mechanism, technical proofs can be given regarding the fact that data will not be used for any other purpose than inference.
- warkdarrior 4y agoWhat kind of GPUs do you support inside the secure enclaves?
- DanyWin 4y agoWe should support Nvidia H100 Confidential GPUs once this option is available on Cloud Providers
- danShumway 4y agoTheir FAQ actually brings this up, but... > You might find other AI APIs available online. Those companies might put in place encryption in transit or at rest, but the companies running those APIs end up decrypting your data to apply their model. > This means they eventually see all data you send to them, could leverage it for their interest, or get your data compromised without your knowledge! > BlindAI API uses cutting-edge encryption mechanisms with secure enclaves so that even our admins cannot see the data sent to our AI models, and therefore cannot compromise our users' data. Same question, what do they mean by a secure enclave? Homomorphic encryption is the only way that I can think of to really securely do this? Unless maybe they have decryption built into the LLM somehow so it only gets decrypted in RAM? But that still seems like it shouldn't be treated as E2EE. E2EE means something, it shouldn't be used this lightly if all they mean is that they're promising not to touch the data on a machine. I feel like I need to see a lot more details before I get excited about this. More to the point, given the progress happening on LLaMa right now, it's hard to get excited about even homorphic encrypted models, because I strongly suspect that on-device/on-premise models are going to end up being the better solution for data privacy. This mattered more before it was possible to run an LLM on a high-end laptop.
- DanyWin 4y agoI see your point. We have been creating content to democratize Confidential Computing, which is a field leveraging hardware-based (instead of software based like Homomorphic encryption) solutions to protect data in use. I have a video from a webinar here: https://youtu.be/a2nprLS6bSA?t=1882 https://youtu.be/a2nprLS6bSA?t=1882, we have some examples in our blog https://blog.mithrilsecurity.io/privacy-voice-ai-with-blindai/ https://blog.mithrilsecurity.io/privacy-voice-ai-with-blinda..., and we will release a series where we show to use secure enclaves by building a KMS with secure enclaves. I don't necessarily agree with your statement regarding deployment on laptop. Not everyone has the skill/hardware to deploy such models, and providing simple APIs to leverage those, especially if the model is complex, could bring a lot of value to users in our opinion. We have seen hospitals wanting a simple API to do speech to text for medical voice notes and they just want an app on their old phones. I hardly see them deploying a 1B Whisper model for this use case. Using BlindAI would allow them to have state-of-the-art AI, without having to worry about showing their data to us.
- rozal 4y agoWhat's not to understand? It's called lying, people do this.
- Wronnay 4y agoI like the J. R. R. Tolkien reference of the company name... Did you check the copyright situation? I guess the Tolkien Estate could try to sue you guys if you get successful...
- silentsanctuary 4y agoI think the relevant legal mechanism would be a trademark, and in order for it to be a legal issue, you would need to be operating in the same business space as an existing registered trademark holder (because then you might cause confusion between yours and their products/services). Copyright generally doesn't apply in the case of a single word.
- zyl1n 4y agoOpenAI is in a very good place if potential competitors have to use its name to explain their services.
- boredemployee 4y agoand it seems that everyone is surfing the AI suffix hype, even though there are no "I" at all, but applied statistics doing plausible jobs
- hndamien 4y agoPerhaps intelligence is just applied statistics.
- wokwokwok 4y agoIs it self hosted? Yes => secure. No => not secure. QED. Unless you have the power to define your own information boundaries (eg. via your own security in your own cloud account, or your own network), you can't assume privacy is protected. Any kind of privacy assurance is only as good as the word of the salesman. Would you send your medical records to an arbitrary 3rd party? Would you send your production code base to an arbitrary 3rd party? There are very few entities that people trust for this (eg. AWS) because they have a history, reputation and audit history to support their claims.
- DanyWin 4y agoI agree. But there are hardware based solutions called secure enclaves that enables software companies hosted on AWS (like us) to serve a SaaS to users without technically seeing the data. This can be verified remotely even before sending data to us with attestation. This is called AWS Nitro Enclave and this is one of the hardware we will cover. You can find more about it here: https://aws.amazon.com/ec2/nitro/nitro-enclaves/ https://aws.amazon.com/ec2/nitro/nitro-enclaves/
- wokwokwok 4y agoOk, I'll bite. I'm happy to be wrong if I am wrong... This document [1] defines a Nitro Enclave as an application image that runs in a secure runtime with no external networking. This document [2] shows how you build a secure image. You basically take an image (like [3]) and run `nitro-cli build-enclave ...`. Ok... so explain to me: - Given that the image you build has to contain 1) private data (mine) and 2) private models (yours). If I build the container image, how do you protect your models? (because I did, to access the base image) If you build the container image, how do I know you didn't access my data? (because you did, to build the image) What am I not getting? [1] - https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html https://docs.aws.amazon.com/enclaves/latest/user/nitro-encla... [2] - https://docs.aws.amazon.com/enclaves/latest/user/getting-started.html#run https://docs.aws.amazon.com/enclaves/latest/user/getting-sta... [3] - https://github.com/aws/aws-nitro-enclaves-cli/blob/main/examples/x86_64/hello/Dockerfile https://github.com/aws/aws-nitro-enclaves-cli/blob/main/exam...
- avx56 4y agoIt's not much of a competitor with this performance. From the OpenChatKit model they claim to be using: > Write a rhyming poem about ray tracing OpenChatKit: The sun is shining The birds are singing, and the flowers are blooming. I'm so glad that I'm alive, and I'm so glad that I'm here. I'm so glad that I'm alive, and I'm so glad that I'm here. I'm so glad that I'm alive, and I'm so glad that I'm here. [repeated several more times] ChatGPT: In a world of graphics, sharp and bright, Where realism is the ultimate sight, There's a technique that takes the lead, It's called ray tracing, indeed! Ray tracing is a visual art, That sets the scene right from the start, By tracing rays of light in the air, It creates an image beyond compare.
- dragonwriter 4y agoIt actually wasn’t that long ago that GPT based models (including Copilot) frequently got stuck in loops like that; I'm... not taking that as a big negative sign. Yeajz its behind the closed SOTA. That’s where you expect an open competitor to start.
- DanyWin 4y agoTo me OpenChatKit is just a first step towards better and better open-source models. Other actors like AWS and Hugging Face are also working on that and Hugging Face has already proved its ability to train and make available LLMs on a huge scale like Bloom. I think it's just the beginning and the open-source community will provide very competitive LLMs.
- rvz 4y ago> I think it's just the beginning and the open-source community will provide very competitive LLMs. It is indeed. The way to challenge OpenAI's offerings is with open-source AI models. Even better when they achieve and surpass GPT-4 level capabilities. They (OpenAI) cannot win the race to the bottom or $0. Stable Diffusion (and even the leaked Facebook LLaMa) is already at the finish line and more alternatives will also be there to surpass GPT-3 and 4 and will release them for free in the open. Eventually, Open source AI models will eventually disrupt closed ones. Just like how DALLE-2 has been disrupted quickly by Stable Diffusion.
- wenyuanyu 4y agoThe scale and capability of LLMs are increasing exponentially... To me, this is a bit like trying hard on a workable privacy-first 80286, when OpenAI and other folks have been releasing Pentium or maybe i7 or Apple Silicon next year...
- LoganDark 4y agothis looks to be nothing but a python library with a wait list—is there any sort of playground or ChatGPT-like interface to see what the capabilities are?
- DanyWin 4y agoYes there will be. We are going to launch it soon, we just had to finish some work with the recent security audit. We have a live example of providing a GPT model inside a secure enclave here: https://huggingface.co/spaces/mithril-security/blindai https://huggingface.co/spaces/mithril-security/blindai We will soon release one with OpenChatKit.
- dragonwriter 4y agoIts selling points are the privacy model of its hosting, and that ot is using an open source engine. The engine is OpenChatKit from Together: https://www.together.xyz/blog/openchatkit https://www.together.xyz/blog/openchatkit
- blintz 4y agoWhat if instead of trying to evaluate these models privately, which tends to have a lot of overhead, we instead try to mix lots of user queries and send them in batches? We could use enclaves to do the mixing, and while there’s be added latency, we could achieve model outputs that are (by definition) at the current state of the art for LLMs. We would not hide the contents of queries, but we’d at least hide who is making which queries.
- ctoth 4y agoAs a blind person who is at an access technology conference whose primary topic this week is AI all I can say is this is gonna be a crowded namespace.
- dang 4y ago"Coming soon", "Join the waitlist", etc. generally mean this work isn't ready to be discussed on HN. Once there's something for people to try out, or at least some substantive information about what it actually is and how it actually works, it will be possible to have a good HN thread about it. https://hn.algolia.com/?dateRange=all&page=0&prefix=false&sort=byDate&type=comment&query=%22no%20harm%20in%20waiting%22%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
- tempaccount420 4y agoWouldn't be surprised if 0 code was written for this yet. People test interest this way before they start writing a single line of code.
- dang 4y agoYup and that's one good reason to wait for something substantive.
- DanyWin 4y agoThe project is not far from there, we are only weeks away before release. BlindAI has been around for almost two years and is open source. We are improving on it with recent hardware and AI models, but this is not just communication stunt. I apologize though for not providing as much as content as you would expect but we will do our best to provide something of value to the AI & privacy community ASAP.
- dang 4y agoSounds good!
- mclightning 4y agoOpen...Confidential bold letters...join waiting list. When did English language change so much? I can't keep up as a foreigner anymore.
- deleted 4y ago[deleted]