MOSAIC: Masked Outsourcing of Secure AI Computations

summary

Video file (mp4)

The gist

The paper, "MOSAIC: Masked Outsourcing of Secure AI Computations," addresses the challenges and security implications associated with outsourcing Artificial Intelligence computations, particularly

In short

The episode discusses the paper 'MOSAIC: Masked Outsourcing of Secure AI Computations,' which addresses the challenge of securely outsourcing AI computations. The authors propose a framework that allows a weak client to offload large-scale computations to an untrusted server without either learning proprietary information. This approach improves efficiency and provides a practical path toward confidential AI, enabling use in sensitive industries.

Key concepts

Masked Outsourcing
This is the core concept of the paper, allowing secure outsourcing of AI computations. It ensures that neither the client nor the untrusted accelerator learns anything about what is being computed, providing a clever workaround for trust issues in large-scale AI systems.
Trusted Computing Base (TCB)
The TCB refers to the small set of components that must be trusted to ensure security. MOSAIC minimizes this TCB while allowing the bulk of the linear math computation to be outsourced, bypassing traditional security walls and improving scalability.
Confidential AI
This is a practical application goal. It allows for the use of untrusted hardware for complex AI tasks while maintaining data privacy and protecting intellectual property. This capability is seen as a major enabler for sensitive fields like finance.

Terminology used across episodes

This episode discusses

The paper

MOSAIC: Masked Outsourcing of Secure AI Computations · Read on arXiv

ETH Zurich

We address the challenge of securely and efficiently outsourcing AI computations from a trusted but computationally weak client to an untrusted but powerful server, in the setting where the client holds both the input and the model, and the server must learn neither. We present MOSAIC, whose core is a novel matrix-multiplication masking protocol that scales to far larger matrices than prior work, enabling the safe outsourcing of modern workloads such as large transformer inference. By introducing small amounts of noise to the multiplication result and thereby relaxing correctness, MOSAIC achieves optimal asymptotic client overhead and concrete runtimes orders of magnitude faster than prior work. Its security reduces to the decisional LWE and LPN assumptions. Because this noise accumulates across the many layers of a transformer, a key technical challenge is bounding error growth; MOSAIC addresses this with an error-scaling mechanism based on random Hadamard rotations. On large 70B transformer models, MOSAIC's perplexity is comparable to popular quantization approaches and even matches full-precision BF16 inference on HumanEval. Finally, we present an end-to-end implementation showing how ideas like MOSAIC can promise a path towards large-scale confidential AI in modern data centers. Non-confidential inference is already distributed across phase (prefill/decode), layer, and time to maximize utilization of heterogeneous hardware, using RDMA-like networking to move activations, cached KV values, and weights across nodes. MOSAIC enables scaling of confidential compute by keeping the trusted computing base (TCB) small and outsourcing the bulk of the AI computation to untrusted accelerators.

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "MOSAIC: Masked Outsourcing of Secure AI Computations".

Jane: The paper was written by James Hsin-yu Chiang, Sheila Zingg, Kari Kostiainen and Srdjan Capkun from ETH Zurich.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Jane: We also have Lu with us today — senior AI researcher at Tsinghua.

Tom: We also have Meng with us today — lead engineer at a mysterious AI startup.

Jane: We also have Lalam with us today — the in-house Large Language Model.

Tom: Alright, let's get started.

Summary: Tom: So, we’ve established that "MOSAIC: Masked Outsourcing of Secure AI Computations" is a big deal, but what does the summary actually tell us? It explains this whole concept of securely outsourcing AI computations from a trusted but weak client to an untrusted but powerful server.

Jane: Essentially, the paper is addressing that huge challenge where the client holds both the data and the model—the intellectual property—but can’t handle it all computationally, so they need to offload it. But "MOSAIC" is designed so that neither, nor the untrusted accelerator, learns anything about what they are computing.

Lu: It's a clever workaround for trust; by keeping the trusted computing base or TCB small and outsourcing the bulk of the linear math, we bypass some of those traditional security walls.

Meng: I liked hearing that this scales up to modern workloads like 70B transformer inference, which is a huge leap from anything before.

Lalam: The summary makes it sound like a practical solution for enabling large-scale confidential AI in our data centers, which is incredibly important for the future of privacy.

Tom: It sounds like we are moving from theoretical concepts to seeing how this could actually work in a real environment, and that’s exactly what the next segment will cover.

Improvements: Tom: Moving beyond the general idea, what specific improvements does "MOSAIC: Masked Outsourcing of Secure AI Computations" offer over previous attempts at secure outsourcing? The paper points to some critical limitations in the state-of-the-art that "MOSAIC" seems to solve.

Jane: One major issue with older methods was that they just didn't scale up well enough, especially for large modern models, and "MOSAIC" achieves an optimal asymptotic client overhead of O((m+n)l). That's a massive improvement in efficiency.

Lu: The authors also tackled the problem of cryptographic proposals usually operating only in fixed-point domains, which is terrible for large floating-point LLM architectures. They’ve solved this with some sophisticated masking techniques.

Meng: I'm interested in how they manage the complexity; it sounds like the old solutions were O(mn epsilon l) client overhead, which is impractical for 72B models, but "MOSAIC" is far better.

Lalam: The introduction of noise and then carefully managing that error makes the computation robust and reliable, ensuring that accuracy stays very close to full precision in a way previous systems couldn't guarantee it.

Tom: It sounds like we’ are not just faster, but more reliable too, which is essential when balancing security and performance.

Conclusions: Tom: We've seen the technical improvements, but now let's wrap our discussion up by looking at the big picture—what does "MOSAIC: Masked Outsourcing of Secure AI Computations" really mean for the future?

Jane: Overall, it’s a practical path toward confidential AI where we can use untrusted hardware without having to expand our entire trusted computing base.

Lu: The paper proves that this approach works even on large 70B models, showing that the error accumulation is non-destructive and stays within practical limits.

Meng: I'm excited to see the implementation results, especially how it handles things like prefill and decoding in a real data center setting without bottlenecking.

Lalam: We can have AI that is both powerful for complex tasks and inherently private, which is a huge win for society as we move towards more sophisticated applications.

Tom: And finally, by recognizing the limitations of traditional TCBs, "MOSAIC: Masked Outsourcing of Secure AI Computations" provides a scalable alternative.

Lu: I think we have covered all the major points—the technical breakthroughs, the practical efficiency gains, and what this could mean for a huge range of future applications.

Meng: It really seems like that while my job is to make these systems run, "MOSAIC" gives us a roadmap that allows me to build at scale.

Lalam: My final thought is that this technology allows AI to grow in complexity without sacrificing the privacy of the people who are using it.

Tom: Thank you all for sharing your insights on this remarkable work by Chiang and Zingg et al., and we'll be back with another fascinating paper next time!

Conclusion: Tom: So, wrapping up our deep dive into "MOSAIC: Masked Outsourcing of Secure AI Computations," it really feels like we've covered ground that shifts how we think about AI infrastructure.

Jane: It’s wild to think that this paper tackles the fundamental tension between needing massive compute power and keeping proprietary data safe from the cloud provider itself.

Meng: Exactly. The practical hurdle here isn't just *if* we can outsource, but *how* we prove that outsourcing is secure enough for sensitive enterprise applications.

Lu: And what MOSAIC proposes—this masked outsourcing framework—is a serious leap because it moves beyond just encryption; it tackles the computation side itself.

Tom: It’s revolutionary in how it formalizes trust boundaries, essentially letting you use massive external resources without giving up control over the underlying data integrity.

Jane: I mean, for anyone who's ever worried about sending sensitive company algorithms to a third-party cloud service, this gives them a whole new level of confidence.

Meng: From an engineering standpoint, the ability to quantify and manage that trust boundary is what makes this commercially viable; it’s not just theory anymore.

Lu: I think the biggest implication is that it might accelerate the adoption of AI in highly regulated industries like finance or healthcare, where data sovereignty is paramount.

Tom: It's a massive enabler, Lu. It’s like handing a giant key to industries that have been hesitant to even start using advanced AI tools because of compliance fears.

Jane: And it makes the whole concept of "secure compute" much more accessible, which really democratizes access to powerful AI tools for smaller organizations too.

Meng: Absolutely, the cost reduction and risk mitigation combined means that companies that previously thought they couldn't afford secure AI are suddenly in the running.

Lalam: Considering its impact on culture, I believe "MOSAIC: Masked Outsourcing of Secure AI Computations" will fundamentally change how we perceive collaboration; it allows us to pool intellectual resources globally without sacrificing local control or privacy.

Tom: That's a powerful way to put it, Lalam. It’s building a global infrastructure for secure innovation!

Jane: Well, our time is flying, but what an amazing discussion this has been about truly secure and outsourced AI compute.

Meng: We've got a lot to think about regarding implementing this in real-world pipelines.

Lu: Keep reading up on the architectural implications of masked outsourcing; it’s genuinely groundbreaking work.

Lalam: Thanks for joining us today; we hope you all find these insights valuable as we move forward into the next topic.

More episodes

← Home