ChatGPT - Solving AI’s Privacy Issue

There is no doubt that AI, and in particular Large Language Models (LLMs) such as ChatGPT will have a tremendous impact on society, perhaps even more than the Internet did before. From education to healthcare, movies to music, art to finance, not a single industry isn’t being disrupted by AI.

While foundational models that are trained on generic, publicly accessible data are powerful, they really become useful when contextualised for a given task or user, either through fine-tuning on private data, or pre-prompting with contextual information before sending in a query.

In both cases however there is a major privacy issue: all this private data goes to the company operating the service!

This is why several countries and companies, such as Italy and Samsung, are now limiting the use of ChatGPT and alike. Without strong privacy guarantees, the risk of data breach and manipulation is simply too high. 
Can cryptography solve the privacy problem?

Fortunately, there is a way to both use AI and keep our data private: Fully Homomorphic Encryption (FHE) is a new encryption technique that enables computing on encrypted data, without actually decrypting it. And it may be a way to bridge the gap between the effective use of AI and keeping our data private.

When applied to AI, it works in the following way:

  1.  The user encrypts their data and query using a secret key that they only know
  2.  The encrypted data is then sent to the server running the AI model, which then processes it encrypted, producing a result which itself is encrypted. At no point does the server see the data, everything is done blindly!
  3.  The user then decrypts the response from the AI, revealing its content. 

What this means is that for users, nothing changes: they send queries and get an answer, but since the data is encrypted both in transit and during processing, nobody can see it: neither the company offering the service, nor governments or hackers. It’s end-to-end encryption for AI!

Of course, privacy is just a drop in a broader ocean of LLM-associated challenges that also involve discussions around copyright and unconscious bias, and FHE will therefore not offer a silver bullet to all the practical issues currently being discussed. However, it has the potential to evolve into a key piece of the current puzzle.

Why Aren’t We Using This Already?

The reason why FHE isn’t being used in widespread applications today, is because up until recently, it was too slow, too complicated and too limited to be useful. It took a PhD in cryptography to do a simple encrypted multiplication, and that would take minutes to complete. But thanks to recent development breakthroughs from a number of  companies and academic institutions, as well as hardware acceleration efforts from companies such as Intel and Cornami, homomorphic encryption is quickly becoming a reality. 

On the usability side, developers no longer need to know cryptography to use FHE. They can simply use homomorphic compilers to write Python code and have it automatically converted to an encrypted equivalent. On the feature side, we are also no longer limited to a handful of encrypted additions and multiplications. Anything is now doable in FHE, from deep neural networks to blockchain smart contracts to genomics. The only thing missing is performance.

Using traditional CPUs and GPUs to run ChatGPT encrypted end-to-end would cost tens of thousands of dollars per query, vs a few cents if the data isn’t encrypted. This means we need at least 100,000x better performance if we want FHE to be cost effective enough that it becomes the norm.

Thankfully, we have a solution: hardware acceleration. By creating dedicated chips for homomorphic encryption, we can make it anywhere from 1,000x to 10,000x faster, while simultaneously being 5-10x cheaper than conventional chips. Together, this means the 100,000x cost improvement we are looking for is within reach, and likely to happen in the next 5 years as these accelerators become available commercially.

While privacy isn’t the only issue with AI, it is a major hurdle for global adoption. Without it, we would need to trust a handful of companies with our most private information, or not use AI at all.

This is why homomorphic encryption is such a big deal: it solves the AI privacy dilemma, by allowing us to both use AI and keep our data private! Because in the end, if AIs don’t know anything about us, perhaps they won’t be able to harm us as much.

Dr Rand Hindi is CEO of  Zama

Image: Shubham Dhage

You Might Also Read:

Guidelines For AI Systems Development:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Too Many Corporate Employees Ignore Cyber Security
OxCyber - Not for Profit Cyber Security Community »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Arxan Technologies

Arxan Technologies

Arxan is a leader of application attack-prevention and self-protection products for Internet of Things (IoT), Mobile, Desktop, and other applications.

Authenware

Authenware

AuthenWare delivers the highest level of identity security based on behavioral biometrics.

Guidewire

Guidewire

Guidewire Cyence™ Risk Analytics is a cloud-native economic cyber risk modeling solution built to help the insurance industry quantify cyber risk exposures.

Netresec

Netresec

Netresec is an independent software vendor with focus on the network security field. We specialize in software for network forensics and analysis of network traffic.

SKOUT Secure Intelligence

SKOUT Secure Intelligence

SkOUT Secure Intelligence (formerly Oxford Solutions) provides cyber security monitoring services to organizations around the globe.

PrivateVPN

PrivateVPN

PrivateVPN is a Virtual Private Network services provider offering secure encrypted access to the internet.

Assertion

Assertion

Assertion secures your collaboration (UC/CC) systems from cyber risks. Enforcing the right set of controls and monitoring them continually brings down risk to acceptable levels.

Osirium

Osirium

The Osirium PxM Privileged Access Management platform addresses both security and compliance requirements by defining who gets access to what and when.

World Congress on Industrial Control Systems Security (WCICSS)

World Congress on Industrial Control Systems Security (WCICSS)

The World Congress on Industrial Control Systems Security (WCICSS) is focused on emerging trends in protection of industrial control systems.

Prodera Group

Prodera Group

Prodera Group is a specialist technology consulting partner trusted to help navigate the complex and dynamic lifecycle of change and transformation.

LTIMindtree

LTIMindtree

LTIMindtree is a new kind of technology consulting firm. We help businesses transform – from core to experience – to thrive in the marketplace of the future.

Unit21

Unit21

Unit21 helps protect businesses against adversaries through a simple API and dashboard for detecting and managing money laundering, fraud, and other sophisticated risks across multiple industries.

NARIS

NARIS

NARIS is the leading provider of an integrated Governance, Risk and Compliance platform called NARIS GRC.

Wazuh

Wazuh

Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.

Digital Security Authority (DSA)

Digital Security Authority (DSA)

The establishment of the Digital Security Authority, which incorporates the National CSIRT, is crucial to significantly raising the cybersecurity posture and capabilities of Cyprus.

Enterprise Strategy Group

Enterprise Strategy Group

Enterprise Strategy Group, a division of TechTarget, is an IT analyst, research, validation, and strategy firm that provides market intelligence and actionable insight to the global IT community.