Advancing Private AI Compute with secure, server-side memory
Introducing private, server-side memory to Private AI Compute for personal AI.
Private AI Compute architecture will now offer persistent, cross-device AI memory with stringent on-device privacy safeguards. The advancement addresses the growing capability and intuitiveness of AI, which can remember crucial information, comprehend its surroundings, and act per user commands. Privacy and trust are integral to realizing this potential, ensuring user data remains confidential and secure as AI systems progress to deliver continuous support across various devices.
Today, the company is unveiling how it will incorporate private, server-side memory into its Private AI Compute platform. This innovation tackles a longstanding challenge in contemporary AI: how to provide a digital assistant with long-term continuity across devices while adhering to stringent privacy standards usually confined to on-device processing.
With this new technical ability, a persistent memory layer will function as a secure digital vault in the cloud. In this model, the data required to assist users is securely stored in dedicated, encrypted storage, while the cryptographic keys needed to access it are solely on the user's personal devices. This ensures the data remains inaccessible to anyone else, even Google.
The accompanying diagram illustrates how this enhancement to Private AI Compute will function. When an AI model needs to access information to assist a user, an authenticated, end-to-end encrypted channel links the device to a protected, isolated environment in the cloud. This space, or "secure enclave," temporarily decrypts the user's data in isolated memory to process the request, saves additional context, and immediately re-encrypts it, maintaining the user's privacy as if the data never left their device.
This evolution is crucial for meeting the computing demands of the AI era. Traditionally, local, on-device processing has been the gold standard for privacy. However, cutting-edge AI models frequently necessitate more computational power than a single device can deliver. Integrating sophisticated AI into personal assistants requires finding a solution to harness the power of the cloud while guaranteeing personal data remains as protected as if it never left the user's device.
Previously, Google introduced its Private AI Compute platform, enabling users to execute intricate tasks in hardware-isolated cloud enclaves. However, this technology, along with comparable solutions worldwide, has been strictly "stateless," erasing all context as soon as a task concludes. Workarounds, such as AI saving a list of personal facts and preferences, are insufficient to support the rich, continuous experiences users anticipate from personal AI.
Accomplishing this level of assistance necessitates engineering a method for cloud-scale AI to securely retain context over time and across devices, enabling seamless assistance like pulling up assembly instructions from one device viewed through another, or resuming complex conversations across mobile and web platforms. Private AI Compute is engineered to enable this kind of smooth assistance while maintaining the information it relies on to remember securely.
However, user trust in that system's privacy is equally important. Building trust begins with transparency. To this end, alongside the updated technical whitepaper, the company is releasing a tamper-proof public record of its server software. Devices running Private AI Compute will be able to verify the authenticity and integrity of our software before transmitting any personal data.
Furthermore, the company is providing an update on its technical methods, including the results of an independent audit by a leading cybersecurity firm. By sharing these resources, the company invites the broader privacy community to verify Private AI Compute's protections. Introducing private, persistent memory to Private AI Compute demonstrates how deeply personal assistance can be designed with privacy in mind.
The company extends an invitation to the community to examine the updated Private AI Compute Technical Brief and the system architecture, security proofs, and verification protocols. This research was co-developed by Google DeepMind, Platforms & Devices, Core, and Cloud teams. The company also expresses gratitude to Four Flynn, Jay Yagnik, and David Kleidermacher for their executive sponsorship of this initiative.
Written by urgent.news from Google DeepMind's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.