New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

The Synergy of AI and Trusted Execution Environments (TEEs) - Martin Leclercq | iExec

ETH Belgrade CommunityTue, Oct 7, 2025, 12:00 AM

Unlocking the Potential of Confidential AI: The Synergy of AI and Trusted Execution Environments (TEEs) - Martin Leclercq | iExec

Transcript

Okay, let's talk about confidential AI and it won't be too technical. Just one slide I promise. So what you will learn today over the next 10 minutes I will talk a bit about history story because we are quite OG company um confidential computing SJX and a lot of stuff and and the important role we are playing in the confidential AI uh environment and decentralized confidential computing who in this audience know what is confidential AI just raise your hand one two okay cool so You will probably learn something today. I really hope so. So let's start.

Sorry. So we started in 2017 two cycle to be market and we are still here and we launched decentralized marketplace for computing power worked with blockchain. We built some developer tools uh enabling builders to use confidential computing easily in their project and then add the monetization the data monetization within the web3 ecosystem and everything comes together together and lead to the confidential AI and we considering uh ourself like the trust layer of deepin and AI and you will understand why soon. So privacy is a hum a human fundamental human right. I think we all agree with that.

But privacy it's not only about uh privacy token tornado stuff. It's way more and there is a lot of protocol working on it. We are part of the decentralized confidential computing alliance. We are more than 30 protocol with oasis protocol. they are there uh here today uh and other and every protocol work with different privacy tech like FH fullorphic encryption MPC multi-art computation ZK and regarding we are working with TE trusted execution environment and I think we are on the only one able to run legacy application in this confidential environment but what is this special environment.

Wow. Don't be afraid. This this is a more technical slide. TE and confidential computing. Think of TED a really confidential vault in your computing environment.

Basically you see uh we are working it's a hardware based technology and we are working with Intel chipset SGX and TDX and you see the red box labeled enclave it's where the magic happen with this chipset inside there is a small part of the memory creating what we call an enclave and everything that happen in it remain totally private. and confidential everything even the cloud ad means the CS admin mean nobody can access to it means I see some no yeah keep it for the Q&A time just after so yeah everything remain confidential and there is two key features isolation as I said enclave isolates the computing process and the data through a physical partitioning and the attend station report. That's cool because you can prove and you can get some adistations that all you done all you've done in this enclave have been done privately with a special hardware. That's pretty cool. And if we are focusing on what happened uh with EXC, we are able to run application in it.

So you can bootstrap an application then you can send it in this enclave and we got everything to make it compatible with SJX and TDX. And the cool stuff it's you can run you can even run AI model. I think you get it. It's why I'm going to talk about confidential AI. If I'm able to run an AI model in this private environment, it means I can compute data, make inference in a private way and that's really really cool.

So about the technology, I talked about chipset. We work with SJX chipset software gu extension. It's pretty cool because it protect an application. But even better, we've got a new brand new technology called TDX. It's for trust domain extension.

It means you can now run an entire VM in this enclave. So a quick board Intel is GX. It's quite old technology 2015. Intel TDX 2023. It's not because it's new that we will use only this technology.

We are keep we're keeping uh IntellJ for specific needs. But what is cool with TDX it means no incomp no library incompatibilities. It means you can develop any kind of application and you can compute data in every way you want and then send it in this enclave easily because it's an entire VM running in it. You may think, "Okay, Martin, that's pretty cool, but confidential computing sounds a bit complex. How could I use your technology?"

And I've got an answer. I have generator. It's a new tool. We just launched it. It's a CLI common tool.

And literally in one command, you can bootstrap a privacy preserving application. You just need to install the package. Then you just need to run I app in it and bam the magic happens. You've got an application on your local computer and you are able then to customize it and just click just run I apply TDX and you will be able to launch deploy this application in a confidential environment. That's really amazing cuz you can think about different kind of use cases like I want to provide my health data my really private data and I would like to train a model your model with it but I don't want you able to see my data okay let's make it in this enclave with this technology so dcc decentralized confidential computing these approach you you know now what is confidential computing and ate we added the blockchain layer for tokenization data tokenization um governance role and ownership it means when you are producting and process your data it's your data and the cool stuff is with the governance role you can set some u monetization mechanism for instance I would say okay I will authorize you to train your model with my private data, but I want you to pay me $10 and you can do it with our technology.

That's cool. Let's talk a bit about right now because you know what is confidential computing? Decentralized confidential computing. So, let's go to the confidential AI. I think everybody here is using Chad GPT.

Who got a pro plan? Who is paying for? Wow. who is using for free. So it means if you are using chat GPT for free you are providing your data to uh to open a yeah if you are using deepseek or other I don't know other model for free you are providing your data it means the model is training is currently training with your data it's not a not at all private and honestly sometime you are chatting it's it's become more easier like you are chatting with chat GPT oh what do you think of that oh let me send you my you you can send some private private data elf data and asking some question about it but wow that's crazy you should really be careful because you all all know about deepsek datalics and it could definitely happen with big big tech like open AI and even more even more with AI agent because we are entering in the new age AI agent is way more powerful and I'm using it myself with MCP server with a lot of new tech and I can now interact with all my tools like I can interact with Gmail, Google, Google calendar, everything else just by prompting in AI.

So if you want to get more accurate answer it needs you need to provide more data and honestly my child GPT it's a problem it should be private he know everything about my life everything and you can you can try you can try you can ask him like can you can you just uh describe my profile based on what you know about me you definitely you will be scared you will scare it's really scary so oh I clicked So yeah, AI agents and it's become more critical more and more because they will know everything about us. It's it's why we need confidential AI approach. We need AI model running in a private envir environment or got a privacy tech in a way or another. It can be technology but it can be other uh you can think about hybrid pets. You can combine ZK with MPC, with TE, whatever.

But we need confidential AI. We need to keep our data private. And confidential AI is the merge between DCC, decentralized confidential computing and AI. It means learning AI model in this deep infrastructure. And the cool stuff is you can now monetize everything all the AI pipeline.

You can monetize monetize each step. You can monetize the model inference. You can monetize your data. You will provide to train a model. You can monetize your model.

You're already trained. That's pretty cool. So let's earn some money with our private data without release it, without leak it. And a cool project we've done, it's Elisa OS. I think you all know who is Elisa.

What is Eliza OS framework? It's a pretty cool AI framework able to do a lot of stuff. And what we've done, we actually we're currently running Eliza OS framework in a TDX environment and each currently uh running uh and managing a Twitter account by itself. So in a confidential way, nobody can alter it. Is completely autonomous and is running in this private environment.

But you can think about a lot of different use cases like everybody got some private data in research like you've got a bunch of climate change data and you want to train a model with it. Why not financial stuff? All the defi uh ecosystem needs some need more privacy health care even more really cool stuff. We are sponsoring this hackathon and um a builders come to us and he say I will build something with the human genome and scientist will be able to train or analyze human genome in your TEE and be able to find if there is some genetic disease. So I can provide provide my human genome without um leak it.

So that's that's crazy and it's exactly what I really love Hackathon. So if you've got an AI project, let's build it but with privacy by design, transparency, confidential computing, and decentralized infrastructure. We joined another alliance because we love alliance. We love working with other protocol. We joined the AI unbundled alliance with aier a lot of different uh protocol working with AI.

And to wrap up this conference just a few announcements quite cool you know everything about it 1 million ecosystem fund and we want to promote and grow our AI ecosystem. We've got we launched an ecosystem fund Elisa Intelix I talk about it and we are building new partnership and the best part my favorite one we currently ate running our tech on our side chain called Belor but we are deploying our privacy tech on L2. So soon at the end of the month you will be able to access all the EXC infrastructure on other layer 2 and that's pretty amazing. So we are keep growing promoting helping our builders and that's all. Thank you very much.

I hope you learn some stuff about confidential computing decentralized confidential computing and confidential AI. In my opinion, we need to keep everything private even more int artificial intelligence. Thank you. Any question? No, not too technical question because I only the developer relation at exec.

All right, crystal clear. If you've got any question, I'm going back to the EXC booth and feel free to come drink a coffee and talk about confidential AI. Thank you.

All right. Thank you, Martin. Uh will

Automatic transcript — names and jargon may be misspelled.