Economic Incentives and Souls in Schelling-point Based Oracles by William George | Devcon Bogotá
Devcon·Sat, Oct 7, 2023, 12:00 AM
Speaker
Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. https://archive.devcon.org/archive/watch/6/economic-incentives-and-souls-in-schelling-point-based-oracles/ Schelling-point based oracles, such as Kleros, can be used to attribute soulbound tokens (SBTs) to individuals based on subjective evaluations of their backgrounds and expertise. Moreover, mechanisms using SBTs can complement economic incentives in such oracles; for example, an SBT-conscious random selection process can determine the voters on a given question. We will focus on how the interplay of economic and social elements in such systems can be designed to maximize resistance to attacks. Speaker(s): William George Skill level: Intermediate Track: Cryptoeconomics Keywords: oracles,soulbound,incentives Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon 6 was held in Bogotá, Colombia on Oct 11 - 14, 2022. Devcon is organized and presented by the Ethereum Foundation, with the support of our sponsors. To find out more, please visit https://ethereum.foundation/
Transcript
foreign [Music] thanks for being here so early in the morning so my name is William George I'm a mathematician and a researcher for declaros cooperative and indeed I'm going to be talking today about economic incentives uh and souls in the sense of soul-bound tokens these kind of social layers people are trying to add to ethereum to get Beyond just kind of limited Financial logic particularly in the context of shelling point-based oracles which close is an example of so I'll briefly Begin by describing plaros which will sort of like give a sense of the kind of examples we're interested in so claros is a blockchain-based dispute resolution platform uh what that means is that so imagine you have a small business owner who hires a freelancer uh and they put the payment for the free Lancer into an escrow on a smart contract and then if the smart business owner is happy with the work of the freelancer she'll just click a button and say okay great and release the money from the escrow but if she's not then what happens in Claro's is that um there's a crowd-sourced pool of people who are willing to rule on on whether the freelancer did good work and you pick some random selection of them uh and then they're incentivized to vote um for who was right in a given dispute based on what we call as a shell but a shelling point or a focal point so the idea is that they're incentivized to be coherent to vote the same way as kind of the broad Community consensus that ultimately the Oracle produces and then any given participant looks at the case thinks okay I think the small business owner has the honest position here and more I think everybody else all the other jurors people in the community are going to think that the small business owner was right so I want to vote for the small business owner because I think everybody else is going to vote for the small business owner because it's the distinguished decision and they all expect me to vote for the small business owner and ultimately this boils down to a notion of shelling points or focal points this is an idea introduced by Thomas shelling in the 1970s uh shelling went on to win the Nobel Prize that uh selling points are solutions that people tend to use when trying to coordinate in the absence of communication because they seem special or natural so here we have like a table of coordination game where everyone wants to either vote for x or I'll vote for y but they just want to vote for the same thing and then what people tend to coordinate around are kind of special seeming Solutions uh so here in Clarence we think of honest resolution disputes as a kind of as a shelling point or a focal point um others blockchain oracles that use this include of ideas related to this include ogre enuma uh so Claus is a kind of like Oracle specifically designed for dispute resolution but more broadly you can think of it as just being designed for the subjective decisions people need to make on a blockchain uh so another aspect of the title of my talk is souls and sold down tokens so for those of you who aren't familiar I'll briefly introduce them so the defining feature of Soul bound tokens uh and these are introduced by in this paper decentralized Society finding web 3 sold it was published a few months ago by while olhaver and budrin uh so these are tokens that first of all are non-transferable uh and generally are thought of as representing some social aspect of people uh like maybe you finish a course in blockchain from from some like online course and you get a diploma from that course like it doesn't make sense to transfer that to somebody else like you have a diploma representing your knowledge um maybe you win an award uh for for your your good work uh so these are things that represent some aspect of identity about you and an interesting thing that the authors of this paper discuss is that you can have negative Soul bound tokens so like a running example that they particularly consider involves it's trying to enable undercollateralized loans so by adding this sort of richer notion of identity you can have kind of enough information about somebody to judge whether they're credit worthy and should be given an under collateralized Loan in a kind of similar structure to how banks in the traditional world work uh because we have this richer notion of identity but then if you don't pay your loan on time maybe you get a soul bound token that says you know late payments and then going forward you kind of have to present people the bad with the good you can't get rid of the negative sell down tokens short of burning the whole wallet and starting over with a new identity uh but when you present your wallet to someone they'll be able to see okay they won this award and had this this uh this diploma but uh he had a late payment and they make sort of a balances kind of evaluations on your identity using all this information together uh so a related concept that has to do with sort of social layers on blockchains but is a little different uh is something called proof of personhood so particularly uh the Claro's team developed proof of humanity which is an example of a proof of personhood protocol so this is supposed to be a civil resistant tool it's a registered list of of human beings such that no human being can be able to get more than one identity on the list uh and if there's another dispute about whether someone has a duplicate profile or doesn't meet the criteria that triggers a Claris dispute uh so how this works is that you submit this video saying that I'm a real human and I'm not already on the richest trade uh and then you provide a deposit and you go into like a pending submission challenge period where if somebody challenges you it'll result in dispute but if nobody challenges you or you win your eventual dispute you eventually get on the list um but if you're not a human being or you're a duplicate uh then you when you submit to the list then this decentralized ecosystem of Challengers will say no you don't you know you know you don't satisfy the rules and this will raise a Clarence jury that rules in the same kind of subjective Oracle way that I described before using selling points uh okay so now sort of an interesting thing about proof of humanity is how people remove themselves from the list uh and they do that by providing another video they provide a video that says Okay I want to remove myself uh and what's interesting about this is that maybe in a future version of proof of humanity if you had a soul-bound wallet uh that um has your various cell bound tokens in it then maybe it's tied to your proof of humanity profile address and if you remove yourself and resubmit with a new address it can just automatically point to the new profile and this allows like a very interesting kind of social recovery um like rather than just having social recovery based on you know your friends saying that you are who you say are now you're being verified by this like broad community and moreover this has an interesting sort of philosophical point about how we think of identity on blockchains normally we think of someone's core identity as having a private key that allows them to sign some messages but here what's fundamentally defines your ability to interact with these slow down tokens is your ability to make these videos which is a bit different uh so that that's something interesting another way that these proof of personhood ideas relate to slow down tokens is that um how gets to questions about how you distribute subout tokens to begin with so I imagine they'll someday be a rich ecosystem of slowdown tokens they will be distributed potentially in different ways a sort of a natural thing to do is if there's an institution that can attest to whatever you like aspect of your identity the solvent token represents then it would just issue to that directly like you come to Devcon and get a pull-up and like some organizer sign some message saying yep she was here pulp awarded into the auto appears automatically in your wallet maybe your blockchain based like course online has some some University attached to it and they sign something and give you your spt um but like maybe you don't the institution that's like naturally giving out the tokens it would test your identity just isn't equipped for this they're not very blockchain friendly moreover maybe there's some aspect of some sobound token that doesn't naturally have an institution behind it and something you could do is create a career a list similar to how proof of humanity Works where you claim that you deserve a cell bound token you say I'm an expert in subject X you submit a deposit you do the same kind of thing people can challenge you you provide your portfolio like previous Works proofs of your expertise uh and if you make it onto the list you get a sellbound token saying that you're an expert okay so now I'm going to change switch gears a bit and talk about how these social layers interact with the kinds of Economic Security models that we traditionally have in a lot of crypto economic systems uh and my two running examples here will be Claro's Euro selection and quadratic funding which is the sort of motivating example of a lot of the decentralized society paper uh so how does your selection currently work in claros well people stick a token and then each token has an equal chance of being drawn and you kind of are forced to do that if you don't have another form of civil resistance because if you try to give people like unequal weight uh say people that have tons of tokens or like weighted quadratically or something then people would have an incentive to just cut up their tokens over multiple addresses to try to pretend to be different people uh so you're kind of stuck with this like linear odds of being drawn in terms of weight and then every time you draw someone the odds of the next draw don't change like in any given draw that that 45 person still has 45 percent uh and then you can look do sort of a binomial distribution calculation and look at the total odds that the you know like a large sticker will get a majority of the votes on a given case uh so that's an economic security system uh whose security model basically boils down to not and no one having more than 50 percent of the stake uh and um particularly like Clarence has an appeal system without going into too much of the details you can get larger and larger panels of jurors and particularly if you have a really large panel of jurors it is very unlikely that anyone would be able to get a majority of the votes on that panel without actually having 50 of the stake okay so that's like a purely Economic Security model uh quadratic funding my the other motivating example suppose you have different participants one Decay and they submit contributions C1 to CK uh to a project p uh and then the idea here is for those of you who aren't already familiar with it is it like quadratic funding is used often to kind of kind of give matching grants often for public goods according to this formula there uh and you might look like a kind of strange formula if you're not previously familiar with it but like notice the square root in the first term it basically has the effect that if people submit a lot uh then their contribution tapers out because like square roots you know grow a lot and then kind of level off uh so one individual who submits like a tremendous amount of contribution doesn't have too big an effect even though like they're the more they contribute the more of an effect they have with better to get a big matching Grant is to have lots of people contribute because each person contributing gives you an extra term in this sum uh and then as an example suppose on the left um we have someone with you know an Innovative ethereum project that wants a public that's a public good and wants a grant and on the right we have like a fake proposal by someone who's just like please give me a grant but I'm not going to do anything uh and the person on the left you know they get contributions from a lot of different people uh and you notice they get like a pretty good total subsidy whereas the person on the right is the only person that he's he is the only person that contributes to his proposal uh and you notice that his total subsidy is zero uh and generally if only one person contributes to a given proposal the subsidy is zero uh but this depends on having a good proof of person to the scheme uh and you can imagine if your proof of a person this game was broken then the attacker can like pretend to be and different people each making a small contribution instead of one person making a large contribution uh and can basically steal the subsidy pool um so your security model is your proof of person it's game needs to be secure uh now what if I consider jury selection in Claro's with a proof of person at scheme where each person can only each person has to be on proof of humanity or president's game in order to be drawn and you can only be drawn once uh then the first draw and kind of the same as before uh so maybe the the 45 dude gets a draw uh and but then he can't be drawn against everybody else's odds go up and you necessarily draw three different people and the overall odds of anyone getting more than two spots is zero what happens if I have an insecure proof of person at scheme like take the pessimistic case someone just completely breaks proof of personhood and the attacker has tons of profiles uh then the first draw well nothing happens and the attacker can be drawn more than once because he has all these profiles and he probably cut up his stake into different profiles so the attacker is still in this pool somebody else gets drawn and now she can't be drawn again because she only had one profile uh and so the attacker's odds and everybody else's odds go up a little bit uh and then on the last Hospital the attacker has a slightly higher chance than he did before of getting more than half of the votes but what's interesting here is that it didn't like he broke completely broke the proof of person in this game but still doesn't completely break this security it's not like he has an overwhelming chance of getting all the votes uh so the security model here is that either your proof of person needs to be secure or No One controls more than x percent of the stake well what's X it depends exactly on how many jury spots there are in the distribution of the other stickers if you have like a handful of whales in your staking pool then when you remove one of them the attacker's odds go up a lot but if your staking pool is really well distributed it has lots of people with small Stakes then X can approach 50 percent uh where the attacker needs as much resources as he did under the model without proof of personhood so these like economic and social layers layer together and don't like only slightly kind of dilute the security of one another and add multiple layers of you know different kinds of security without having to choose am I going to like have a Social Security or Economic Security so that's really nice uh so now like an extension of this that we're interested in and research doing research on is what if you try to wait people by sbts can you do something that's kind of like this pulling in Social information but with an even more Rich way uh so here people have different kinds of sbts some people have a diploma from there that blockchain course other people got their pull-up from devcons and people will want to contest want a hackathon or something uh and then an idea that's introduced in the decentralized society paper um so they consider various ways that you can weight people's contributions to quadratic funding uh and one of them in particular is very general so that's what I'm going to focus on and it's called the offset match uh and the idea here is that you assign correlation scores between the participants you say okay like participant I has so many slow down tokens and she shares so many of them with participant K so I'm going to give this creates like a like a correlation score out of that and then I'm going to solve for these weights Alpha um that uh solve this like weird system of equations so that looks kind of abstract but I'll show some examples and give some of my think how I think about this uh so here the woman in the blue shirt uh has two po has two spts and she shares one of them with the great dude and the green shirt so the correlations are the half and if you solve for the alphas you get these outfits uh and notice that like the idea here is to kind of give weights to anti-correlated groups if like there's one group that has an spt that's like really common and they're all kind of aligned with each other because as sort of evidenced by having the same sbts they should get less weight uh so here like tons of people have the diploma so each one of them kind of gets less weight uh whereas the two people that have other co-ops collectively they get more weight uh however there's this like weird Quirk where the women with the blue shirt got no weight and the dude with the green shark out like more weight uh so I'll come back to that Quirk um but um so then how what's the kind of philosophy behind this so you have these like systems of equations you have this like big Matrix of all the correlation coefficients and then you're trying to solve for this row Matrix of the alphas uh and if you squint and you take like a really extreme case and you're like okay like all of the participants probably fall into like a handful of clusters and the Clusters are really highly correlated with each other but not very correlated with the other clusters uh then you get a kind of Matrix equation that looks like this so like in each of the blocks with the ones those are clusters of people that are very similar between each other but then zeros show that they're not very correlated with the others and then if you solve this Matrix equation it basically gives you one equation per block uh and it says each of the blocks gets roughly equal weight uh and that weight is shared over the people in the block so if you have tons of people in your group in your cluster as characterized by the syllable tokens they have uh they don't get as much weight as like a smaller block that has like different experiences and different cell bound tokens that each one of them will get more weight uh so this has some issues and the people the authors of the centralized Society paper already point out some of these points and they you know they sort of propose this as a place to start to think about these issues uh so first of all the alphas may not be exist and they may not be unique if they do exist moreover you can produce negative Alphas uh there are ways you can sort of like patch this you could say okay I got a negative Alpha I'm just going to round to zero that might mess a little bit with your linear algebra philosophy uh generally this handles how much weight you give it to groups pretty well uh but it doesn't necessarily distribute that weight naturally to individuals uh so like there's a tendency based on how the linear algebra Works to give participants with a subsuper set of spts compared to somebody else zero weight and this was that Quirk that happened with the woman in the blue shirt she had strictly more spts than somebody else um and um so the motivation for the quad the centralized Society authors was to modify this formula for matching in quadratic funding to put Alphas under the square root so now in order to get a big matching Grant you not only want to have lots of contributions for lots of different people you want those people to have big outfits and how do they get big Alphas well by representing groups that like don't have so many people in them and generally in order to get a big matching Grant you're going to need a lot of people from different groups uh contributing to your project uh From clarence's perspective so this is what brings me to this uh you could imagine re-weighting the stakes people have by the alphas so you could use these these like formulas over here for people's drawing odds so we have this example from before we get the same weights that we had before and now like the woman that has 40 stake she doesn't have very she has very common sbts so that kind of dilutes her influence a bit uh whereas like other people with less stake but uncommon sbts get get more of a chance of being drawn and this is a potentially natural thing to do uh at using spts at all in Clarence to sort of like interface with zero selection uh will it allow us to have an explicit procedure where in some courts in some decisions in order to be drawn you need to have expertise in relevant cases by having an expertise that says that you were an expert in that case so currently claros has like a game theoretic mechanism to discourage people from sticking where they're not experts but this would allow us to have like an explicit mechanism that's an extra layer of security more generally by having people that come from anti-correlated groups as have different spts attest to different experiences uh you get a tying into like wisdom of the crowd's ideas there's been a lot of research that shows that groups of diverse problem solvers or groups of different experiences can often produce better results than more monolithic groups uh so potentially we could produce better decisions by by having this social layer in class uh but you have to ask okay what's the security model here uh what happens particularly if an attacker breaks the distribution of an spt uh if there are lots of spts being ordered by lots of different entities you know maybe some of them will be more secure than others uh and then you have other questions like are the participants incentivized to keep the spts all in the same address or split them up like you you want people to sort of take their identity well it's you want people to have at least certain aspects of that they're all in the same wallet rather than having like different sbts on each one like one spt per wallet or something uh um and um so imagine this for the first point what happens if an spt is broken a simple example so imagine that like the attacker can break the distribution of this like diploma he hacks into Coursera or whatever and like can produce tons of profiles with the diploma if you have a group as evidenced by this that sort of pulled out of this like clustering algorithm anti-correlation mechanism that has that's basically just characterized by having the diploma uh then the attacker can perfectly copy them he can make an infinite number of profiles or a large number of profiles that exactly mimic people in the group so he can steal all of their weight and that's inevitable you know no matter what weighting you use uh what's a more interesting question is what happens if the attacker well what happens if the group is characterized by having ksbts so I have a group of people like most of whom have the same ksbts you know maybe they share a few ksbts with other people but mostly like they have those ksbts and other groups don't uh and the attacker just breaks one of the sbts the diploma uh well then now you get this like back to the block Matrix you have something that looks like like this now the correlation between the attacker and the victims is like one over K because he has one of their sbts and you can solve for this and under the offset match or the offset weighting uh the uh the attacker still takes almost all the weight because of this Quirk with people of supersets and subsets uh where super people with super sets of spts don't don't get any weight uh so that's not great but like you know you could imagine adapting this somehow to try to be resistant to this kind of attack ultimately you would want something that kind of looks like what we had with proof of personhood being matched with the economic staking where adding this social layer kind of adds security and mesh as well with the existing Economic Security uh so some there are other potential waiting schemes one could imagine uh so this idea is related to eigenvector centrality uh it's some similar to the idea used in the pagerank algorithm uh so in the original version of eigenvector centrality there's not this like one over in the in the equation uh and conveniently simply enough you can kind of turn it into a measure of anti-correlation or anti-centrality just by putting one over uh so this still doesn't fully work it's a little more resistant than the the offset match to the the um this like question of what happens if the attacker breaks one of the the tokens uh so more research can be done here uh I know Glenn wild at least is also thinking about some of these things he had some similar ideas about econvector centrality that uses a different formula uh so we can continue to think about like what one could put here that would be attack resistance in the most robust way uh and just to conclude so proof of personal protocols can provide a natural base layer for certain types of social recovery in some cases distributions of svts uh ideas developed around weight and quadratic funding contributions by spts are also relevant to other applications like juror selection maybe you have some airdrop and you want to give your airdrop to a diverse member people contribute to your community in a lot of different ways who've interacted with their protocol in different ways and maybe that could be expressed by having different spts uh and but as we move from a purely economic model to economic proof of personhood proof of personal economic plus spts this can have effects on our security model and like the ideal thing to have is to layer security so that as we add these things like the system gets more and more secure rather than having to have to make sacrifices or we dilute the economic security uh but there are questions about various security models what happens if an spt gets broken and do users have an incentive disclosure spts so um if there's time for questions I'd be happy to take some questions thank you very much William we have a space for questions if someone have any questions
Automatic transcript — names and jargon may be misspelled.