Supergroup
Superpowered personal messaging for the AI era
How do you add an AI to a group chat without spoiling it?
In most messaging apps a service provider sits in the middle, relaying each message from the sender to everyone else. With Encryption where only the sender and the intended recipients hold the keys to read a message., the message is encrypted on the sender's device so that no third party, the provider included, can decrypt it, and each recipient decrypts it on their own phone. WhatsApp, iMessage, Facebook Messenger and Signal all work this way for chat messages.
Groups make this harder. A common trick is to hand out "A key each group member uses to encrypt their messages to the whole group, shared privately with the other members." over existing one-to-one secure channels, so each member encrypts messages to the group with their own key. A newer IETF standard, An internet standard for end-to-end encrypted group messaging that scales to very large groups., is built for groups as large as 50,000 and for people who chat from several devices.
Further reading End-to-end encryption (Wikipedia)RFC 9420: The Messaging Layer Security (MLS) Protocol (IETF / RFC Editor)Messaging Layer Security (Wikipedia)
- i.
Keys for a crowd
Sender keys are efficient, but they heal badly. Recovering security after a key leaks takes a number of key update messages that grows with the square of the group's size, and an attacker holding a sender key can often listen in indefinitely. MLS takes a different route, arranging the group's keys in Arrangements of keys in a branching hierarchy, so an update only has to touch one branch. so the whole group can refresh its keys, even when members are offline.
- ii.
The model has to read
The big AI models run on servers, not phones, and that means the provider can see the requests. A cloud model needs unencrypted access to your request and the personal data that comes with it, which rules out end-to-end encryption. So every helpful thing an assistant does with your chat, like summarising it, pulls against the privacy people expect from a messaging app.
- iii.
Knowing when to talk
Most dialogue research studies conversations between two parties, and group chats aren't that. In a group a model has to decide when to talk, a skill that models trained on pairwise conversations appear to lack. It also has to work out who it is answering. Everyone knows the friend who replies to every single message. Nobody wants that friend to be software.
Further reading RFC 9420: The Messaging Layer Security (MLS) Protocol (IETF / RFC Editor)Building Private Processing for AI tools on WhatsApp (Engineering at Meta)Private Cloud Compute: A new frontier for AI privacy in the cloud (Apple Security Research)Multi-Party Chat: Conversational Agents in Group Settings with Humans and Models (arXiv)Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations (arXiv)
Supergroup is building "super-powered group chat for you & your friends": a place for making plans and shooting the breeze, with AI built into the conversation.
Further reading Supergroup (Supergroup)
- Step 1: An AI in the thread
The app includes AI features such as conversational replies, image generation and assisted web search. When someone uses them, the relevant message content goes to the AI provider serving the selected model, and the answer comes back into the conversation where it was asked.
- Step 2: Plans that become invites
A scheduler helps the people in a conversation find a time to meet. Connecting a calendar is optional. If someone does, the scheduler can read when they're busy, and a time the group agrees on becomes a real calendar invitation.
- Step 3: Answers everyone can see
An answer from the assistant is a message like any other, so if you ask about your schedule in a group chat, everyone in it sees the reply. For privacy, ask in a one-to-one conversation. Location is asked for only when a feature needs it, such as showing how far away a place is, and never collected in the background.
Further reading Supergroup Privacy Policy (Supergroup)
Can an AI read your messages without the company reading them?
WhatsApp's WhatsApp's system for running AI on messages inside a sealed server environment that the company cannot see into. sends AI requests to a confidential environment where, by design, no one, including Meta and WhatsApp, can access them. Apple's Private Cloud Compute makes a similar promise for its devices. Both rest on outside security researchers being able to check that the promises hold.
When should an assistant chime in?
Research systems built for group discussion split the problem into what to say, when to respond and whom to answer, and have shown they can chime in at sensible moments with small to medium groups. A recent survey argues that a working model of what each participant knows and wants, which researchers call The ability to model what other people know, believe and intend., is essential for doing it well.
Further reading Building Private Processing for AI tools on WhatsApp (Engineering at Meta)Private Cloud Compute: A new frontier for AI privacy in the cloud (Apple Security Research)Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations (arXiv)Multi-Party Conversational Agents: A Survey (arXiv)
Supergroup is building superpowered personal messaging for the AI era.
- end-to-end encryption
- Encryption where only the sender and the intended recipients hold the keys to read a message.
- sender keys
- A key each group member uses to encrypt their messages to the whole group, shared privately with the other members.
- Messaging Layer Security
- An internet standard for end-to-end encrypted group messaging that scales to very large groups.
- tree structures
- Arrangements of keys in a branching hierarchy, so an update only has to touch one branch.
- Private Processing
- WhatsApp's system for running AI on messages inside a sealed server environment that the company cannot see into.
- theory of mind
- The ability to model what other people know, believe and intend.
- 1End-to-end encryption · Wikipedia
- 2RFC 9420: The Messaging Layer Security (MLS) Protocol · IETF / RFC Editor
- 3Messaging Layer Security · Wikipedia
- 4Building Private Processing for AI tools on WhatsApp · Engineering at Meta
- 5Private Cloud Compute: A new frontier for AI privacy in the cloud · Apple Security Research
- 6Multi-Party Chat: Conversational Agents in Group Settings with Humans and Models · arXiv
- 7Multi-User Chat Assistant (MUCA): a Framework Using LLMs to Facilitate Group Conversations · arXiv
- 8Multi-Party Conversational Agents: A Survey · arXiv
- 9Supergroup · Supergroup
- 10Supergroup Privacy Policy · Supergroup