Client-Side Vector Recommendations
Local Model
Reading habits adjust local taste weights.
Vector Query
Sends purely numerical embedding. No user ID.
Cosine Match
Returns relevant content, discards query.
On-device models generate preference vectors that are sent anonymously. The content API matches recommendations without tracking user identities.
NOON Cryptographic Blind Voting Protocol
Hash & Blind
Multiplies hash with secret factor r
m' = (m · re) mod n Blind Signature
Signs without seeing payload m
s' = (m')d mod n Unblind
Removes blinding factor r
s = (s' · r-1) mod n Anonymous Proof
Verifies without user linkage
m ≡ se mod n ✓ David Chaum blind signatures allow users to cast verified votes and likes without revealing their identity or choices to the server.
Building a social discovery platform that protects personal privacy while delivering relevant content requires rethinking foundational software design. Standard platforms gather massive behavioral logs to power backend recommendation models. Cryptographic engineering offers an alternative: client-side vector preference embeddings combined with blind signatures for anonymous engagement.
Client-Side Recommendation Algorithms with Vector Embeddings
Traditional recommendation engines rely on comprehensive server-side telemetry: tracking every dwell time, scroll velocity, click, and interaction to build persistent profiles. While technically effective, this creates an enormous honeypot of personal habits vulnerable to data brokers, government subpoenas, and security compromises.
Client-side recommendations invert this architecture. Instead of transmitting behavioral traces to an external server, preference calculations run on the user's hardware. Modern lightweight models compute an abstract preference embedding stored securely in local browser storage:
- Local Signal Processing: When an article or topic is read, local heuristics adjust the floating-point vector representing user interests without logging raw metadata to a remote database.
- Stateless Search Queries: To retrieve fresh content, the client sends this anonymous vector to a public query API. The server computes cosine similarity against published content embeddings and returns the closest matches.
- Zero Tracking: The server never receives an account ID, device fingerprint, or interaction history. From the infrastructure's perspective, each query is an isolated mathematical comparison.
- Portability and Control: Users can inspect, reset, or export their preference vectors at any time, eliminating vendor lock-in.
Blind Signatures for Anonymous Likes and Interactions
Engagement metrics like vote tallies and upvotes are central to social curation, but conventional implementations tie every vote to a specific user account. Over time, this creates an extensive map of individual beliefs, affiliations, and interests.
Blind signatures, first introduced by David Chaum, provide a mathematical solution. They enable a server to validate that an interaction was submitted by a genuine, authorized user without discovering which post that user interacted with or which option they selected.
The Two-Phase Anonymous Interaction Flow
- Credential Issuance: Upon account creation, the user receives a fixed quota of unblinded interaction tokens signed by the server's master key.
- Local Blinding: When interacting with a post, the client blinds the vote payload using a secret random multiplier $r$.
- Server Signing: The server signs the blinded hash without knowledge of the underlying target, registering that the user has consumed one token from their allotment.
- Unblinding & Submission: The client strips the blinding factor $r$ and submits the clean signature alongside the target post ID over an unauthenticated network request.
To implement this in production, Lupyd utilizes NOON, an open-source Rust library implementing David Chaum's blind signature scheme with cryptographic verification primitives designed for real-time applications.
- ✓ Centralized recommendation engines rely on pervasive behavioral tracking to profile users for monetization.
- ✓ Client-side vector embeddings keep interaction histories on physical devices, querying servers anonymously.
- ✓ Blind signature cryptography decouples identity from engagement, enabling verifiable likes and dislikes without surveillance.
- ✓ Pre-issued anonymous credentials prevent double-voting without tracking individual accounts.
- ✓ Open-source cryptographic primitives like NOON make zero-knowledge engagement practical for production systems.