#37 - The Only Defense Against AI with Uma Roy

Apr 23, 2026
YouTube
Apple Podcasts
Spotify

About this episode

Uma Roy is a cryptographer and cofounder of Succinct. We discuss how zero knowledge acts as a defense against AI, the challenges with AI detection tools, and how crypto makes digital media real again. If you are interested in the intersection of AI and cryptography, apply to Network School at https://ns.com (https://ns.com/).

Transcript

This transcript of the podcast was auto-generated and may include typos

0:00
Puma, welcome to the NRC podcast. Thanks for having me. Awesome, you want to introduce yourself briefly. Yeah, so I'm Co founder CEO of succinct succinct applied cryptography company. We probably best known for making the fastest 0 knowledge virtual machine ZKVM for short in the world known as SP1. For those of you who aren't aware, ZK is this really powerful cryptography technique where it lets you prove to someone else something is true without revealing all the details. Kind of the canonical real world example is that if I can prove to you that you know I'm over 21 without revealing my birthday or my home address or anything like that. So instead of showing a driver's license at a bar, you can just show them a proof of you know

0:45
that you're of age. We built this ZKVM which how can I describe it? I would say it's somewhat like a foundation model for cryptography. So if you want to prove really complex statements in ZK, such as a roll up state transition function or like very complex predicates, the thing we built makes it super easy. You just write normal code, you stick it in to ask P1 and outcomes the proof. And then, yeah, we made it super fast and really easy to use, which is awesome. And I would say right now, succinct. Although historically our ZKVM has been used mostly for approving blockchains and proving, proving roll up state transition functions and things like this. And like Ethereum and other chains, right now we're really excited about the potential of cryptography to solve a lot of the problems that AI poses. I think Balaji has been an

1:33
extensive tweeter about this topic for many years. You're very ahead of your time, honestly. And so, yeah, I think honestly, that's probably one of the most important things cryptography can do right now. And there's like a finally a clear catalyst. Every model released where the image stuff or video stuff gets better and better. It's like we need cryptography as a defense. So I think it's time for cryptography to be on like a societal stage right now. It's like a solution to all day I stuff. So I'm very excited about that. Awesome. So yeah, I actually actually many years ago, it partly actually because of AI, but also with social media when people are talking about misinformation, disinformation and so on and so forth. Years ago, I remember I tweeted

2:19
something and I was like, oh, so you want to ban lies on the Internet? OK, give me a function that says whether the Reman hypothesis is true, right. And so, you know, that's a reduction ad absurdum where we we don't know whether it's true and it could be true and it's plausible that it's true. But there's many things in math which have really arcane counter examples that, you know, you get up to N equals whatever and it's actually not true. And so, but as I thought about that, I was like, well, how would you code Trugal TRUGLE? You know, if you were actually, you know, going to do it, right, how would you do it? And The thing is, LLMS get you some of the way towards that,

3:05
right? Because they will take a statement and they'll do at least a probabilistic search at the literature and pull things up and so on and so forth, right? And The thing is though, of course, then those assertions themselves need to be underpinned, the citations. And then that's how you get to on chain everything. And so my view is like with LMS, actually you can, you can kind of show a version of this today. If you ask any LLM to summarize some major crypto hack, it will show you probably some link that shows some on chain block explorer record among other things. And so that's currently only used to document financial things like the on chain transaction, you know, during, let's say FTX had a hack or whatever during that period,

3:52
right? But as more and more things get logged on chain, then more and more references from L Lems will point to on chain events and we get what I call the Ledger of record. And I think succinct could be maybe a big part of that. So you had some slides. So maybe you you want to go through your slides? Oh yeah. What's your background by the You're born in the US, You what's? Your What's your spiel? The USI went to school at MIT, was a double major in math and CS. I've always really loved math. So that's kind of how I got into ZK. And yeah, I mean, ZK and cryptography have a lot of fascinating math, and that was really big the draw for me. And actually before Zika, I was doing some AI stuff. So I was like at Google Brain doing research into like early LLM.

4:39
So this is pre GPTI was doing some stuff with Bert back then. So I'm familiar with that world. And now it's like exciting to see the synthesis. Yes. I mean, you know, The thing is, I, you know, I was actually also in machine learning prior to the deep learning era, but from the standpoint of genomics and diagnostics and, and whatnot. And, you know, just to digress on that for a SECond before we get into the ZK stuff like, you know, all the stuff with hidden markup models and conditional random fields. And, you know, it was surprising to me that Transformers worked as well as they did to get long range context in there. It's even more surprising to be that diffusion models work and

5:24
and yet they do that, you know, you wouldn't necessarily intuit from the equations that they would work as well as they do in practice. I don't know if you have any thoughts on that. Maybe talk about that and then go to the next. I mean, when you're working on Bert, did you think obviously there was there were people who had the graphs of scaling and here's how it's going to go right. So there was some intuition that it could maybe get there, but it but it worked a lot. I mean, the jump between GPT 2 and GPT-3 and then ChatGPT in terms of usability was very non linear I think from, you know, right, go ahead. Maybe. Were you surprised by that? Oh, I mean, absolutely. I think even the close people closest to the Metal on this

6:09
stuff seemed surprised at like how well it's going. And even today, like the level of math problems they're solving and stuff like that. Yeah, I, I would say I, I was very surprised that this process, which, you know, with deep learning, there aren't really that many proofs. Like in cryptography, everything we do is proven like it's deterministic. You have very concrete bounds and proofs for everything. Yeah. And alarms is just, it's like, why does deep learning work kind of vibes based? But right now the vibes are really good. It works really well. Right. And I think it's funny because, well, actually go through your talk and let's talk. Go prove what's real. OK, cool. So, yeah, I mean, I think you one of your favorite quotes is

6:59
AI makes everything fake. Crypto makes a real gun. And yeah, I think like the problem is very clear now. AI makes everything fake and we're seeing that every single day. So it's like whether it's this DoorDash driver, you know, kind of faking the delivery. Maybe that's a little bit of a trivial example that went quite viral on X to something like, oh, is Jeffrey Epstein still alive? Or it's like the White House posting digitally altered pictures or it's politicians getting deepfaked or, you know, celebrities getting deepfaked doing all sorts of things. Like the problem is I think today is like extremely clear and it's only getting to be worse and worse as these models get better and better. So like the seed dance release recently of like the really good

7:44
video models that like, you know, can really impersonate any celebrity or any person. Like it's very clear that AI makes everything fake is kind of like a huge problem for the Internet. So yeah, that's like the problem statement. And then I think like one really interesting thing. So people have identified this problem statement. It's not, you know, that hard to understand why it's so problematic. I would say the state-of-the-art right now for trying to detect AI is use AI. So people have like, train these AI detectors to train models to say, hey, is something real or is like something from the model. And recently it's a thing. We did this, you know, benchmarking study to, you know, evaluate those claims and say,

8:29
hey, does AI detection actually work? And we published, you know, this data set of realistic AI images and tried to benchmark all the leading commercial detectors. And you can actually go to the website AI detection dot sync dot XYZ. But the resounding answer was like, yeah, the AI detection stuff is not robust and it just does not work. I'm going to slightly argue with you on this maybe, which is to say on text as opposed to images, right? So much so this reminds me a little bit of I'm not, I'm not really arguing with the results of your paper, but on the macro thing, right? And it's so with Snapchat, you know, it has a deterrent to

9:19
someone taking a screenshot of, you know, like like a disappearing message. Now, of course you or I or someone who's a computer scientist will say, well, there's still the analog hole. You can just hold up another phone and record it. And you know, if you want to, you can just take a SECond phone and record it. And that doesn't have the you know you can defeat it with a sufficiently motivated attacker relatively easily, right? However, most people aren't that motivated, and so the simple and dumb screenshot detection thing sets the norm and makes it relatively hard to do screenshots, right? Similar to how you know, you could people could work around the Twitter 140 character limit by pasting in screenshots of 140. You know, more than 140 characters, but they didn't for a long time, right?

10:04
And my view is that there's a lot of AI text on X, for example, that at least I can trivially detect. It's not this, it's that and the M dashes and so on and so forth, right? And there's certain people who just are clearly AI posters because of just the style. It's like this overdramatic kind of style. It's, it jumps out to you immediately when you see it because you see it a lot. It's like seeing the same person writing over and over, you know, and pangram.com or something like that feels pretty good at detecting ChatGPT type slop, which you see a lot of and clawed and ChatGPT, for whatever reason, a very similar text voice, I think right on this kind of thing. Yeah, I mean, I guess they're trained on the same data to a certain. Yes, whereas images, you know, maybe I, I guess it depends on

10:54
the class of image. I mean, obviously with hands and things like that. Gymnasts, they're finally starting to get good with gymnastics with, with sea dance because those are unusual poses, but they do like physics simulations, I guess to train them. I don't know, maybe you have a thought on that. You understand my point, right? Like AI detection may not work 100% of the time, but for text, I think it currently works well enough to get a lot of the ChatGPT type slop at a fairly high. Like you can certainly see it visually. You know, like a human can see it, then it then if it, if it's unsubtle enough for us to see. Let me pause there. Yeah, I I do agree that the tech stuff, at least right now, there are these watermarks almost like the M dash or the patterns you were saying like, oh, it's X,

11:39
this is X, not Y. But I, I still think that similar to images actually, like the study we did basically was you take an image that an AI generates. And by the way, these things are pretty good. Like I actually, I've gotten personally fooled a bunch of times. So empirically it seems to be really good. And then we did the study where you basically perturb the image a bit. So you blur it or you crop it or you add some like indiscernible Gaussian noise to the image and then the AI detectors all completely break. And I think even in text, that's kind of true, right? And I mean, who's to say using AI to help you write some of your tweets, maybe that's not even a bad thing necessarily, right?

12:25
Like ultimately, like content is content and maybe you're saying something interesting with the AI help. But like a lot of people do these tricks where they're like get the output from GPT and then they tell GP remove all the M dashes and then then it's not detectable. No, it's true. I I guess The thing is. So here's my view on that. It's my emerging view. So at least here's our current standard on this. We so at NS our our rule is no public undisclosed AI, right. So why do I say that? Well, first is people can just go full AI and full AI means like because AI is a shortcut. Yeah, and as a shortcut, I think it's a good term because people

13:10
can take too many shortcuts and they fake it and they don't know what they're doing and so on. The more expert you are, the more legitimate it is to take a shortcut because you know how to do it the normal way, right? And it's like writing down a theorem without doing the full proof every time it's right using a function call route that there's a reason that people use shortcuts. OK, but they can overuse them fine. So the alternative is no AI, which is a lot of people actually are going to go to. And there's like an anti AI fine, but no public undisclosed AII think in 4 words. It captures so you can use private AI and that's undisclosed because you're going and editing your own stuff, right? I mean, you're, you're or like you're editing code. Who cares? You're using it for yourself, right? Public disclosed AI when whether it's a watermark at the bottom right or it's like an animation,

13:55
a comic, a movie, something like that, no one can get mad because you're not trying to pull one over on on somebody, right? It's public undisclosed AI that gets people mad. And at least if I analyze my own reaction on that, I don't when someone is sending me something that's obviously AII think they are either stupid or lazy. Why? They're stupid because they can't see the obvious AI tells like they send an AI slop slide deck or they have AAI web page that has a lot of like it's one thing if they say, hey, this is a prototype, check it out. OK, fine. Right, But that's disclosed AI if it's undisclosed and it's

14:41
just got like a wall of AI cause AI tends to, you know, in AI images, they're more full of people than normal images by default. You know, if you've noticed, unless you actually pull that back, right? Like their outdoor scenes have too many people often, right? And that's like 1 tell, right? And similarly, AI pages and AI slide decks are not succinct. Yeah. They're just really right. And so either they're dumb and they can't tell what's good, or they're lazy and they're hitting a few keys and then sending me a bunch of slop and I have to go through it. And fundamentally they're taxing the other side. It's like someone leaving a voice memo for. You. You know, like I have to verify everything because they didn't verify everything. And so when they whenever I get

15:28
an AI message from somebody, I downweight them because of that. And I and I down with them as a poster and so on and so forth because they, they just, they're taking shortcuts in a way that makes me question their judgement. Yeah, if he gets good enough that go ahead, say what you're going to. Say, Well, I think one reason the fake images and fake text is a little different is I mean, historically you could just write whatever words you want. Even pre AI you could just write a bunch of things that were not true, like you could lie. So I think humans are very used to critically evaluating the text they see because like people can always just write whatever.

16:13
I think we're much less used to being able to critically evaluate images we see. Historically, it was pretty hard. I mean, OK, you had things like Photoshop and this and that, but like, you know, it'd be pretty hard to really fake something elaborate or like fake, for example, the president of the United States doing like a one minute long video saying whatever. You just could not have done that in the past. And now with the AI tools, it's very easy to do that. So, so it's really interesting you say that and, and I want to continue your presentation. My I agree and I'll give a partial counter argument, which is I actually think most of the images and videos people have seen are television or movies

16:58
until recently. And those were actually all fictional and synthetic. And so they kind of live within a world where some significant fraction of their inbound training data is fictional, as seen by the extent to which people reference, I don't know, Star Wars or The Handmaid's Tale or something like that, like the, you know, Harry Potter. That's actually more real for many people than actual history. But that's like disclosed. It is disclosed, but I don't think they can actually go ahead say, say, say, say. Yeah, I was just going to say it. That is disclosed in that you know it's not, you know, it's made-up. I, I think you and I know it's made-up, but I, but I think, OK, here's my argument on this and

17:46
let's continue. But the I call it Jurassic Ballpark, like, you know, Jurassic Park has the scene where, see, I'm actually referencing A fictional movie scene to explain fictional movie scenes. Very Meta. OK, so Jurassic Park has the scene where the dinosaurs have amphibian DNA spliced in because the scientists didn't know what to make of that part. So they spliced in amphibian DNA and that leads to, you know, the dinosaurs reproducing. The point being that when we are dealing with a situation that we don't have personal experience of, like we don't have personal data on, you implicitly rely on some movie you've seen about that area to tell you how it's like. For example, unless you've

18:33
actually been if, unless you've worked at CIA or you know, people at Palantir, you don't really understand what the actual CIA is as opposed to the movie version. You think the movie version is in the ballpark and even if it's like more dramatized or whatever, right? And, and it's often just totally not. And so that's why I mean, like, you're right that we kind of know it's fictional, but we don't know what reality is. And so often we think that the fictional is just a jazzed up version of the real as opposed to like totally, totally, totally off. So anyway, so the reason, the reason I say that is I think there's a huge opportunity. One of the things I want to fund at some point is people taking actual history and then using AI to dramatize it.

19:22
So now it's actually more fictional. It's fictional but factual, fictional depiction of real events, you know? Anyway, keep going. I mean to digress. Keep going. There's all these examples and like, it's actually pretty fascinating, so. You're the receipts. Yeah. I mean, even, I mean, this is like kind of maybe a mundane example, but we did all these, we had a bunch of different categories of like real cases where AI deepfakes could be somewhat harmful. And 1 is just, you know, receipts and like reimbursements. And we had AI generate a bunch of images that were like taking a real receipt and modifying the numbers to be much greater than they actually were, like by an order of magnitude. And then we put them through these AI image detectors and. it's turns out like, you know, they're OK They're like, oh, this is a 36% chance it's

20:09
AI. This is a 44% chance it's AI. Maybe what's the original somethings? These are actually real photos. No, I mean, but did what did the original come up as 0%? Oh, I don't have those numbers here, but I think it was like pretty accurate so. Because the reason, yeah, the reason I ask is I'd love to see that data if you can pull it at some point. Because even if the detector was saying 36% if it could, if it had variance, you could rescale the axis, you know what I mean? Like if the if the real photos were left shifted relative to the fake photos, you could recast it as. You know, like a binary classifier problem. Yeah, like basically the distribution of real, like the

20:54
distribution of fake. But then the problem is if you just do simple perturbations to the AI generated stuff like you add a simple blur or noising. And I mean if you are looking at the video of this and not the podcast, you can see these basically look pretty identical to the human eye. The AI detector says 4% chance this is AI. So it's just not robust. Wow, Interesting. OK. And that's like, that's true across a variety of examples. And then that's even true across a variety of problems. So we did like, some other examples, OK, This one's maybe a little more higher stakes. You take a picture of a car that's not damaged. You add AI to like, add dents in scratches. Maybe you're doing insurance fraud. Again, similar story. The AI says, hey, OK, like the

21:40
original version when you just do naive, like, hey, grok, tell me like add dents, the AI detector will say, hey, it's like 44% chance or something like that. But when you add some trivial blurring and noising, the AI detector goes down to like 2%. So OK, there's, there's other, you know, then there then we took pictures of like real editorial photos. So you can imagine like war zones or like, you know, other journalism or famous political leaders and like kind of similar story across all these different categories of images. And so our conclusion from this study was that AI detection is a dead end, like fundamentally. And I think if you think about how these models are trained, it kind of makes sense. Like when you're training these

22:26
models, you're optimizing some sort of lost function from like the generation to like the manifold of real data. And you're literally optimizing so that the things you spit outlook statistically very similar to the real data. And so it's not that difficult to imagine that it's going to be very hard to detect what's real and what's fake because the models are being trained to minimize that. And there's actually like a bunch of work without going into too much detail. And also, I, I mean, obviously I'm no longer an AI researcher, so I'm not like super in the weeds here, but there's a bunch of work done at MIT and by a bunch of other people on adversarial examples where basically they had these detectors back then it was these image net classifiers. And then they added, they did a

23:13
similar study, they added like some simple noise and stuff like that. And then they found that the image classifiers more robust to these adversarial perturbations. So you could always kind of find some perturbation of an image. Like you would take an image of a panda, you would add some simple blurring. It would look the same to a human, but then the classifier would flip from panda to like dog. Right. And this is this is to do with basically just the fact that you would never actually see a point of that kind in the like the manifold of where pandas live. You could perturb it out to the manifold where dogs live because there was no training data along that vector. Typically it's like very thin on that axis. Yeah, again, I, I don't like, I

24:01
wasn't in this research line. So my naive like way I think about it is like just these are such high dimensional decision boundaries. Like we're going to mess up at some point and like there's going to be some point in the decision boundary where you think it's a dog, but like too human, it looks like a panda and like it's just inevitable because like the you're just operating over such like a high dimensional SPACe. That's kind of how I think about it. There's a. There's actually a like the pedal width versus length thing the I like there's this Irish data set in R I'll bring this up. Here. Oh yeah, yeah, it's the famous Yeah, I I've heard. Of the famous 1, you know what I'm talking about, right? And so it's like like something like this is probably a 3D actually, you know what a better one is, like Swiss roll or

24:47
something like that, right? In 3D, basically. Let's see if I can pull this up. So something like this, So Swiss roll, right, is sort of something where you have like the yellow category and the green category, aquamarine, light yellow, blue, right? And in three SPACe, they're clearly distinct. But if, and let's say this was, you know, the panda and this is the dog or something like that. If you put a vector and you perturbed it in such a way that you had a point that was, I don't know, 60% of the way towards this blue part and there's no normal points that existed here in image SPACe. That's my intuition for how the

25:34
perturbation works. I should look that up. But that's that's certainly how it works with low dimensional things and probably something like that works with higher dimensional. And you know, similarly to the this, the pedal went with one over here. Anyway, I want to I want to get into succinct because this is the probabilistic. Let's get into your deterministic go, go, go. So this this also, if you had something over here that'd be outside of the training set, you could misclassify it as, you know, as a circle when it was actually a triangle or vice versa. OK, go, go, go. Yeah, yeah, we're we. So we fully established that, yeah, the AI detecting AI. So it was like not going to work. That seems bad. So it's the same. Well, OK, AI makes everything fake.

26:19
That's what you said. What's the what's the solution? Crypto makes it real again. So we're big believers of that. It's the same. Doesn't apply to cryptography company. So now like, let's dive into what that actually means. So today, like, how does content actually get posted online? I mean, basically first it gets captured whether it's on like a smartphone or a camera or a microphone for audio or some other sensor. Then it goes through some editing, whether it's like Photoshop or these AI editing tools, and then it gets published. So it's like across social media, news services, news wires, traditional media, YouTube, and then it gets consumed. So you look at the content and you say like you, you just look at the content. So that's kind of like the

27:04
current life cycle. And yeah, throughout all of this, there's like no verification. So it would be impossible for you to tell if something's real or something's fake. Now, how does crypto help with this? So this is like what we're building at Succinct, but we think there's this notion of basically what we call the provable technology stack. So at every point in this like capture, edit, publish, consume, life cycle, you insert in cryptography and provable technology to prove it's real. So to start when you capture. Something yeah, this is exact. This is you must have taken some of my content and maybe yeah, yeah, OK. a lot of it is very inspired by, like, a lot of your work, yeah.

27:50
OK, well, this is great. So basically there's a crypto camera and then chain of custody Ledger of record public verification. Exactly this. Exactly the stuff that I've wanted out there for whether it's scientific experiments or something. OK, keep going. I'm listening. I, I, I know this, but say, say what you're going to say. Yeah, yeah. I mean, and yeah, like all credit words do, I think you identified that this is the solution maybe like 5 years ahead of its time, five years ahead of the problem. But and you're, you're always very ahead of your time. So a lot of this stuff is like very inspired by your work. And I, I think there's a lot of other like, I think Marc Andreessen has talked about this actually. And I'll get to this later. Like the head of Instagram is now talking about this. But yeah, OK, just to get into what is approvable tech stock. So I capture things are captured on hardware devices.

28:36
Hardware devices can have private keys that are binded to the device. So you have a cryptographic chip with the key. That's kind of how you can think of it. And basically like as the raw sensor data is coming into the camera, the cryptographic chip signs like the content of the raw sensor data and it binds like the content being captured to the specific device time and location. So that's cryptographic capture. Then as the content gets edited, you have this like chain of custody and chain of edits. So there's a cryptographically signed manifest for every transformation you do, whether it's like cropping or color correction or grading or things like that. And you basically keep this append only record of what's going on to the image.

29:22
And then finally, you publish the piece of content and the manifest of the original signature when it got captured to the chain of edits and you publish that to a unbiased permanent Ledger, which is like this Ledger record. And then when the content actually gets consumed, so it's like in some front end, whether it's YouTube or Instagram or X, the front end integrates with the Ledger and it basically verifies all the signatures, verifies they're real and displays that information to the user. And you know, if the user wants more information, they can just click and like verify all the signatures for themselves. So today on most content platforms, we have the blue check mark for like your verified identity.

30:07
You can imagine in the future, maybe all content comes with a pink check mark that says, hey, this content is like actually real. And like, here's the device and here's like the series of transformations that happened to it. Very cool. So OK, keep going. So, yeah, this is the provable tech stack and this is like all the stuff we're building at succinct. And yeah, I, I think to your point, you talked about this for a really long time, which is like very cool. And I think finally, like other people are starting to catch on 'cause like the problem is finally very evident. So there's this quote from Adam Maseri, who runs. Draftily sign a capture? Yep. Yeah, he posted at the at the start of 2026. He posted like, hey, here's Instagrams, like kind of what we're thinking about, what I'm

30:52
thinking about right now. And he says that basically we're going to move from assuming what we see is real by default to starting with skepticism. So he's kind of identifying this like AI mix everything fake problem. And then he said, OK, platforms like Instagram will do good work identifying AI content, but they'll get worse at it over time. As AI gets better, it will be more practical to fingerprint real media than fake media. And then this is kind of like the thesis of Prove What's real and all this cryptography stuff. Camera manufacturers will cryptographically sign images that capture, creating a chain of custody. So, yeah, I mean, even like people like Adam who are running Instagramers saying that crypto,

31:37
crypto is going, cryptography is going to be the solution to this like AI, the problems that AI creates for like content platform. That's right. Now, I think actually crypto, social and AI are all interlinked here because another piece of this which is actually implicit in like the first part of what he's saying, starting with skepticism, pay attention to who is sharing something and why. I think actually AI and crypto together are going to result in, you know, like you know, I think the future is China versus the Internet. Did we talk about that? I have you heard me say it. Talk right about that. I've heard you say a little bit about it. So I think the future is a billion person Chinese super state or 1000 million person network states. Why? Because everybody thinks about AI improving productivity.

32:25
But that was only true within a tribe where you can trust, you know, you can share information and whether we call it indexing or surveillance, right? Because 1 is good and one is consensual and one is bad and one is not, right? So it is indexing everything and it's learning everything and it doesn't really miss like a single remark somewhere AI can pull out a remark from like 3 years ago and surface it and synthesize in a way that no human you know, or, or you'd have to have a very attentive smart human human. It was human limited that level of surveillance from before, right? So or that level of synthesis, you know, the to look over every commit anDeFind SECurity holes from years ago. It's amazing, right? But that operates within the tribe, outside the tribe.

33:13
It's spam, it's scams, it's slop, right? And so basically the cost of production goes way down, but the cost of verification goes way up. And so this part about paying attention to who is sharing something and why, I think another big piece of this is Web3 of trust. So you take web of trust like I trust you because I know you and I've known you in person. And when you cryptographically sign something on a camera, there is the human part of that as well as the machine part. Like ultimately, if I wasn't actually there with you in the room, I have to trust at some point some human assertion that this data, because I can see it on chain, that it was stamped at

34:00
this time. And there's various proofs that one can put on there, like proof of location, proof of this, proof of that. But ultimately at like you as a human have to tell me that you didn't manipulate it before you cryptographically signed it. Like you, you, because you could do something upstream, like the analog hole upstream, you know, the equivalent of putting something in front of the camera, right? And we can make it hard to do that. We can make it impossible to do that and unless like every single camera has one of these. And I think maybe it'll get there eventually, but there'll also be a demand for those things that don't have these kind of like burner phones, you know what I mean? Right. And so and, and there's so many phones out there. There's billions of phones that do not have crypto chips in them that you, you know, like, just

34:47
like you can get an old laptop, you could get a fake able phone, you know, right. And people will also revolt against too much tracking or what have you. You know, they wanted to be free, whatever. Anyway, I think that's another piece of this is the full supply chain of custody includes the person who's sending it to you. And so who is sharing something and why if they're within your crypto tribe, crypto thinks tribally natively and AI is going to make people think tribally necessarily. And so everything reduces to digital tribes where digital borders and physical borders become the same. And China's the biggest digital tribe of all because they can centrally moderate all of their chat apps and so on and so forth. Like they just whatever AI

35:32
detection stuff they roll out and WeChat, they can force human verification and so on. And say I have just a central choke point where basically a billion people get on boarded into whatever AI detection prevention, fake detection things they want. But the rest of the world doesn't have the same level of I mean, Google and others can roll out certain levels of things, but they've almost opted for a more anarchic standard because of the whole freedom of speech fight, right, which I get, but there's a there's a under correction and an over correction on anything. And what you want is consensual moderation, I think anyway. So it's a compliment to what you're saying. Keep going. Yeah, I, I think what you're, I think in the future, like it's not, I don't imagine a feature where every photo posted on Instagram is required that it's real 'cause like, I mean some AI pictures are really cool or like

36:18
really interesting. I think it's more like to your point of consensual moderation, it's like if you want to prove something's real, and I think a lot of people deeply care about that. Well, then now you finally using cryptography actually of the tools to do that. And then, yeah, if you want to and if you want to follow content creators that have those capabilities or only post real stuff, you can do that. And then, you know, social media is one thing, but obviously for things like journalism, I think Nikita Beer, who's the head of product at X tweeted about this. There's these accounts posting totally fake pictures from the Iranian war and it's like pretty bad. And like people are getting misinformed. And so obviously that's like not OK. And I think this sort of technology, I, I'm hopeful will help with much higher stakes situations or, you know,

37:06
political ads or like what the president is saying or things like that, I think will be really important to like prove what's real there. Great. OK, cool. All right, keep going. Cool. I mean, yeah, I think the rest of the slides are just like a little more detail about what's going on. So already today you said that, you know how many cameras actually have this cryptographic chip. Well, fun fact, every single iPhone does have a SECure enclave that has this capability. And so, you know, interacting with these enclaves across all the device types is really hard. And so we've built this SDK to kind of provide a unified experience for people. Who is it free? How far? How's how's it cost? How much does it cost? Yeah, yeah. The SDK, well, it's not published yet, but we're going to publish it. OK, I want to try I I will

37:51
Commission some apps on this once you publish this. Oh, OK. Yeah, yeah, that'll be cool. That is actually the foundation of a new kind of media. Yes, Yeah, yeah, I, yes, yeah, I think there's a lot of potential there. I think incentivizing decentralized media collection in an AI, first crypto, first social, first mobile, first Internet, first way, this is like a missing piece of that where we have all of these quote reporters from around the world and on any topic that we care about. We can incentivize first party reporting where we pay in crypto and we verify in crypto, where we pay in cryptocurrency and verify with cryptography.

38:36
We essentially have like a decentralized news outlet. So this is something that I want to get going and maybe we can collaborate on this. We can talk about this right after this. Yeah, that would be very cool. And yeah, but citizen journalism like you kind of, well, especially now with the AI generation stuff, you actually do need a way to verify that it's actually real. And so I I totally agree with this. And I think we would focus it on the news of the network state and startup societies and cryptocurrency and technology biotech areas that I think are not well covered, but should be because they are for tech decision makers. So because The thing is, news is a huge topic, right?

39:23
And rather than the news of the state, we focus on the news of the network. And those types of things that are like with a relatively small amount of money, you could get much more coverage of them because they're more important for technical decision makers. And that's kind of the niche that all of these tech outlets basically abdicated. And actually in part the reason they abdicated is because a full time journalist is like a professional journalist is often somebody who doesn't actually know technology because if they did, they wouldn't be a full time journalist. They'd be actually like a player on the field, right building. So moreover, by being a, quote, full time journalist, they're loyal to the journalist tribe as opposed to technologist tribe.

40:09
And technologist tribe is taking away revenue from journalist tribe. So a lot of their coverage is very hostile. So the way we solve both of those problems in my view is rather than one full time journalist making, I don't know, 50K, whatever it is, we have 50 part time journalists who earn $1000 bounties for writing up what they know. And because they have domain knowledge, if they write up one article a year, we're good, right? So that's like NS News. And so maybe we can integrate. Yeah, yeah, Yeah, we OK. Yeah, we should talk about that. Yeah. You can build that with our stuff now. It's like pretty. The whole point of that I see is it makes it easy. OK, great. Go keep going and let's talk more. Cool. Yeah. Then there's the provable edit history part where after you get the provable capture, you do all the stuff you want to do with

40:56
it. And there's actually these existing standards for it called C2 PA, which kind of tracks, which is a Metadata standard that kind of tracks. OK, who, what series of edits did you do? What production did you do? And then it appends it to a manifest. And then finally, after you've kind of compiled the proof of capture, the proof of edits, it gets published to this thing which you came up with this name, the Ledger of record, which is this like open, unbiased, you know, place where all this content gets published. And then that's where all the content that gets displayed in front ends. So for example, Instagram or X or whatever, it can read from this Ledger, which is basically just a database of like what is actually real or not.

41:46
So that's kind of our vision for provable technologies and like the whole stack. And yeah, we kind of imagined that this stuff will show up one day in every single app, every single real picture on the Internet will have a pink check mark that says it's real with all the signatures and all the cryptographic proof. And you can, anyone viewing a picture can just look at that and know what's actually real. So that's our kind of vision for how cryptography is going to solve a lot of the problems posed by AI. Amazing. OK, so which people should go to succinct dot XYZ? Yeah, people can go to Succinct dot XYZ or follow us on Twitter at Succinct Labs and we will be

42:35
posting, we're building this whole stack and we're going to be releasing like a lot of products and related technologies, you know, in the in the coming months. OK, awesome. OK, so. It'd be interesting to hear kind of your vision for how you think this is going to, like be put into the world or like, yeah, you've been talking about these ideas for so long. I'm just curious to know like more about why I got what got you excited about it and like how you think this is going to like proliferate? Sure. So. Well, what got me excited about this, you know, in the 90s, like, you know, when I was, I was a kid then. So I'm about maybe 10-15 years older than you, something like that. Or I would never presume to know your age or whatever.

43:21
Just saying like probably, probably in that ballpark, right? In the 90s, nobody cared about politics. It was something where it was literally being interested in politics was like being interested in the train tables or the bus schedule or something like that, you know, and it was genuinely something, why would you care about this legislative this and that? No one cares. And you cared about music, movies, sports, video games, whatever, right? It was just a vacation from history. And so, like, for much of my life, I was essentially just an apolitical academic and all I care about was math, computer science, fine formatics, all that kind of stuff.

44:08
And then after, you know, essentially the full political breakdown of arguably you can, you can argue when it started 2000 and one 2008, 2015, 2020. Everyone's got a different moment, right? The, you know, there's a saying which is amazing Tweet. If the news is fake, imagine history. OK. And you actually start, you know, realizing a lot of the movies in the 90s, we're almost like the collective unconscious was putting out movies like The Matrix, Eternal Sunshine of the Spotless Mind, The Game, Dark City, Fight Club, 12 Monkeys,

44:55
all of which were essentially about your, you know, memento, right? Your memory playing tricks on you. And in some sense, the world was not what it seemed, right? The Truman Show, right? The Truman Show, The Matrix, all of these are like you're living in a constructed world, right? Memento, your memory of the past isn't the same, right? And it was as if, like almost the collective world was waking up to realize that the centralized century of the 20th century was an illusion in some ways and that there's more to the past. And they've, they'd sort of been, you know, hypnotized, zombified or what have you. And so putting those together, you know, I started asking questions like, how do we actually know what's really true?

45:40
Like, let me give an example, maybe a seemingly trivial example, but this is in the network state book. Let's even take F equals MA. How would how would you actually know that's true? If you track it all the way back? Ultimately, there are scatter plots, you know, when people rolling balls down incline planes, right, where they are taking X and YS and correlating them and then effectively doing a line fit that is then generalized into this deterministic physical law, right? Underpinning everything that we think is true is ultimately a set of observations that you could track all the way back to Newton, like, you know, the famous, you know, apocryphal apple falling down, right?

46:26
Like what you think you know is true. If you can track back all the citations all the way back to root. That's the reason that we think it's true. Why is that actually sometimes important to do? Well, I'm, I'm forgetting this is a whole complicated story and I, I think it's something like there's the story about vitamin CI believe in medicine. I'm probably getting this wrong and I'll look it up, but it's, it's like vitamin C supplementation, but it's what was it spinach? There was like a there's a whole medical story. Hold on, let me find this. The iron myth, right? Spinach is a good source of iron, right? And this is one of those things where somebody tried to track it back and it was, it was either

47:15
this or something else where when you try to track the citations all the way back, it was a complicated mixture of multiple mistake and citations on top of each other. I think this is it here. Let's look at this a sudden thing. I think this is it. Basically the complex and convoluted myths is one call for want of a less complex name, the iron decimal point error myth. And essentially it is a decimal error knowledge gap.

48:11
It's like it's like a myth piled on top of a myth. It's like something complicated enough that I have to go and remember it right. But you can look at this, this document, the point being that is a concrete example of something where someone literally dug through every citation going all the way back and they found that the thing that people thought was solid was actually based on nothing, right? All kinds of social sciences failed the reproducibility crisis in this way, right? So all kinds of political science, history, social science is something we're now with LLMS, we can back solve and go all the way back, right? Because it's, it's much better search right. So you can track it all the way back to all the original citations behind a claim, right.

48:58
You can push it pretty hard to do that deep research, whatever you want to call it. Like, you know, the team of agents saying that Grok has can pull like 1000 sources or something like that much faster than a human can. And so now we can really remember that true goal thing that I was talking about. We can really start interrogating. It's almost like the, you know, the Bertrand Russell program in math of really trying to put math on an axiomatic basis, right? And really trying to have as few axioms as possible when he builds the whole thing from set theory. and I think it's like on page 347 he says and thus we proved that 1 + 1 = 2. You. Know the thing I'm talking about, right? It's like, it's like a famous thing in math, right? So you're probably aware of it. So, so like that I, I wanted to,

49:44
I realized how ignorant I was about what had actually happened in the past, about what scientific facts were actually true, about how scoped my knowledge was. And I started to ask what I know there's a longer answer than you wanted, but this is what led me to this, right? It's like I was like, you know, as a research scientist and you're a research scientist also. We're in the unusual position of being pre headline people. What I mean by that is like this was more true on the Twitter of like five years ago, but there's a fair number of, let's call them normie NPC type people who genuinely cannot believe something is true until it's appeared in the headline. That is to say, until NYT or the State Department or something

50:32
like that, their implicit epistemology was is a reputable source saying it. If so, then true, If not, then false. Now this was always bizarre to me because as a research scientist you're used to figure out if something is true on your own using logic and reason. And eventually I was able to figure out the difference between pre headline people and post headline people. A pre headline person, you have some scientific finding and you are going to publish it and you are actually the upstream source of that finding. Like the press release will be based on your paper, right? Or conversely, you have some VC investment round and you know something is true before the world knows it's true. So you're actually upstream. It's like a miner, you're mining truth before it's being sold at

51:19
the market. However, you realize that actually the guy who's a post headline person has some wisdom all his own because he implicitly, I'm not saying they're doing this explicitly, they kind of know that you can only be a pre headline person in so many areas. Like you, you can't be an expert on Turkish and Japanese and I don't know, Brazilian iron ore and so on and so forth. Much of what you're sensing is going to be essentially on some Web3 of trust, which is based on some information supply chain, right? Anyway, it was through thinking through things like this and how we build a higher standard of truth that got me to where we were. Let me pause here. Interesting. Yeah, I guess you've been thinking about this for a really long time. And then I think we've been

52:06
thinking about this for, honestly maybe the past three to six months as we saw the AI problem get worse and worse and there's this interesting asymmetry. I mean, our team is based on our software. There's so many smart people working on accelerating all this AI stuff, which is really good. There's obviously incredible positive externalities, but I think if there's a techno, if there's a technology that's genuinely so powerful, obviously it's going to have negative externalities. And I think there's very few people focused on combating these negative externalities. And I think in this domain with the pictures and images and fake audio and you know, that poses real problems. And I do think this is an area

52:51
where the combination of cryptographic hardware, cryptographic software, chain of trust, custody Ledger record, provable technology broadly as a category can actually like help some solve those negative externalities. So amazing. Yeah, that's how I got to it. But you got to it much earlier than all of us, which is like kind of your specialty, which is which is very cool. Well, thank you and but I but I appreciate you also grinding through all the details to actually build the SDK and so on, because obviously that's non trivial. So let's talk more about that. And Uma, thank you for coming on. Never see a podcast? Thank you for having me.