Secure Minions: private collaboration between Ollama and frontier models
Ollama published details of Secure Minions, a security protocol built by Stanford's Hazy Research lab to enable encrypted communication between local Ollama models and frontier cloud models. The announcement is dated June 3, 2025.
The work extends Minions, an open-source research project introduced three months earlier at ICML 2025 that connects local Ollama models such as Google's gemma3:4b to cloud frontier models such as GPT-4o. In the original Minions protocol, raw context stays local and is accessible only to the local LLM, while the frontier model orchestrates local LLMs and aggregates their outputs. According to the announcement, sending fewer tokens to the cloud reduces cloud costs by 5x to 30x while achieving 98% of frontier model accuracy. Some information still went to the cloud in that design, and that information can be sensitive.
Avanika Narayan and Dan Biderman of Hazy Research asked whether an entire local-remote communication protocol could be encrypted end-to-end, even from the cloud provider. Their team built a security protocol around the confidential computing mode introduced with NVIDIA's Hopper H100 GPUs.
In the described flow, the local device and the H100 GPU exchange keys; the GPU proves it is genuine and running in secure mode via remote attestation; once verified, the H100 becomes a secure enclave where all memory and computation are encrypted and even root users cannot access plaintext. Local LLM messages are encrypted before being sent to the GPU enclave, decrypted and processed there by the cloud LLM, and outputs are encrypted again before returning to the local client. According to the announcement, no plaintext is exposed during transmission or remote inference, and overhead is less than 1% added latency even with prompts of roughly 8k tokens and large models such as Qwen-32B.
Ollama provided setup instructions, including cloning the HazyResearch/minions repository, installing the package, pulling gemma3:4b, running a Streamlit demo, and example Python code using SecureClient, OllamaClient, and the Minion protocol. Full technical details are in the Hazy Research blog post.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Secure Minions is a secure protocol built by Stanford's Hazy Research lab to allow encrypted local-remote communication.