Getting started
How it works
Three steps between your words and the answer: split, route, measure.
Every private run goes through three steps.
- 01
Split
Your words never travel whole. The model's activations are cut into two secret shares. Each node computes on its own share and never holds the real tensor. - 02
Route
Contributed GPUs are pooled into swarms that serve open models. Each node runs a block of layers and passes its share on to the next. - 03
Measure
One node's view is scored for how much of the prompt it can recover. A run only counts as private if that number sits at chance.
What a request looks like
A prompt enters the network at an entry node, passes through a chain of nodes that each run a contiguous block of layers, and leaves through an exit node that produces the answer. In the reference setup, four nodes each run 16 layers of a 64-layer model.
Request path
prompt → Entry (layers 0–15) → Node 2 (16–31) → Node 3 (32–47) → Exit (48–63) → answerWithout protection, every hop sees real activations. With PRINET, each hop holds one share, and alone a share is noise. See Secret-shared activations for the details.