它怎么做到,凭什么抄不走 How it works, and why it can't be copied
不是 AI 栈里更高的一层。
是你那一侧的一层。
Not a higher layer in the AI stack.
The layer on your side of it.
Kennen 是一台个人记忆与信任引擎——按用户(per-user)的长期记忆 + 认知画像 + 反编造信任闸 + scoped 授权(MCP / OAuth)。它编排世界级模型,把它们变得可信、私人、归你(你养大的)。 Kennen is a personal memory & trust engine — per-user long-term memory, a cognitive profile, an anti-fabrication trust gate, and scoped authorization (MCP / OAuth). It orchestrates world-class models and makes them trustworthy, personal, and yours.
今天几乎所有 AI 知识库,本质都是检索(RAG):你问一句,把最像的几段捞出来拼给你。聪明,但有两个结构性死穴——不认得你是谁,检索不到就一本正经地编。Nearly every AI knowledge base today is retrieval (RAG): you ask, it fetches the closest passages and stitches them together. Clever — with two structural blind spots: it doesn't know who you are, and when it can't retrieve, it confidently invents.
Karpathy 提过更进一步:让知识像一座"活的维基",像编译代码一样持续编译、生长、自我修复。这是真正的一步——但这座 wiki 还长在温室里:自己生成、自己修,长得再好也不认得你的身体,也没有任何东西从结构上拦得住它"自信地说错"。Karpathy proposed a step further: knowledge as a living wiki that compiles, grows, and self-heals like code. A real step — but that wiki still grows in a greenhouse: self-generated, self-repaired, and however well it grows, it doesn't know your body, and nothing structurally stops it from being confidently wrong.
Kennen 的知识层,就从这个缺口长出来。 Kennen's knowledge layer grew from exactly that gap.
知识是商品,判断不是。存储、向量检索、长上下文——都商品化了。会害死人的地方,瓶颈从不是模型知不知道,是不确定时它能不能被独立验证地告诉你:这证据多硬、对你成不成立、不知道就说不知道。 Knowledge is a commodity; judgment isn't. Storage, vector search, long context — all commoditized. Where it can kill you, the bottleneck was never whether the model knows — it's whether, under uncertainty, it can tell you in an independently verifiable way: how hard this evidence is, whether it holds for you, and "I don't know" when it doesn't.
认知代谢 · 活体双链。它不"存"知识,它"代谢"知识——像身体代谢食物:吃进你的真实经验和世界前沿,每一口先过一道"真相闸门"(谎言、噪音、悬空的推断、越界的隐私,拦下或降级),消化成两条缠绕的链:一条世界的机制,一条你的身体。 Cognitive Metabolism · a Living Double Helix. It doesn't store knowledge — it metabolizes it, the way a body metabolizes food: taking in your lived experience and the world's frontier research, running every bite through a "truth gate" — lies, noise, ungrounded inference, privacy overreach, all blocked or down-ranked — and digesting it into two intertwined strands: the world's mechanisms, and your body.
| 认知代谢 · 活体双链Cognitive Metabolism · Living Helix | 通用 AI / RAGGeneral AI / RAG | |
|---|---|---|
| 双链耦合Coupled strands | 你的身体模型 × 世界机制模型,缠成一个推理体,从你身体长出判断Your body-model × the world-model, twined into one reasoning body — judgment grown from you | 通用答案 + 一点个性化贴皮A generic answer with a personalization veneer |
| 真相闸门Truth gate | 每次自我更新、每条推断,过反编造 + 安全 + 隐私三道闸;个人的永不外溢成世界知识Every update and inference passes anti-fabrication, safety, and privacy gates; the personal never leaks into world knowledge | 检索不到就编,无结构性约束Invents when retrieval fails — no structural constraint |
| 机制,非检索Mechanism, not lookup | 走因果机制网,是推理Reasons over a causal mechanism net | 捞最像的段落Fetches the closest passages |
| 随你生长 / 变老Grows / ages with you | 你的链一直更新,世界链一直吸新前沿,越用越认得你Your strand keeps updating, the world strand keeps absorbing the new frontier — it knows you more over time | 静态索引,问完即忘A static index — forgotten after the query |
两条链缠在一起推理,才说得出这种话——
"你围绝经、E2 低、还一周练五次,肌肉合成本来就钝,蛋白光靠练后那顿不够,得每餐都匀到 20–30 克。(我的推断)"
认得你(记得你的真实身体)与不编造你的事(标清哪是研究、哪是推断)第一次同时成立。检索式 AI 给不了:它要么泛泛而谈,要么自信地编。
Only two strands reasoning together can say this —
"You're perimenopausal, low on E2, training five times a week; muscle synthesis is already blunted, so the post-workout meal alone isn't enough — spread protein to 20–30g every meal. (my inference)"
Knowing you (your real body) and not fabricating your facts (marking what's research vs. inference) hold true at once — for the first time. Retrieval AI can't: it's either generic, or confidently wrong.
真相闸门、双链耦合引擎、第一垂类(普通围绝经 · 居家非专业运动 · 饮食优先)的 29 条机制网——已建成、已测试通过,正接入生产。承重机制全部有据可依、落在文献上。The truth gate, the strand-coupling engine, and a 29-node mechanism net for the first vertical (everyday perimenopause · home non-pro training · food-first) — built, tested, and connecting to production now. Every load-bearing mechanism is grounded in the literature.
这里分清两层:分层讲法、因材施教(懂你的讲法)今天已 live——它对不同的你说不同的话,当面可验;底层的认知代谢双链KB 仍在接入生产。是"上层能力已 live、底层引擎在建",不是自相矛盾。Two layers, kept distinct: the layered, teach-to-the-person delivery (speaking your language) is live today — it says different things to a different you, verifiable in front of you; the underlying cognitive-metabolism double-helix KB is still connecting to production. Upper-layer capability live, lower-layer engine being built — not a contradiction.
诚实边界:我们不声称已有"全人类代谢的完整世界模型"。先在一个最高价值的垂类扎到最深,同一套架构再迁移到所有高信任、长周期、强个性化的场景。Honest boundary: we do not claim a complete world-model of all human metabolism. We go deepest in one highest-value vertical first, then carry the same architecture to every high-trust, long-horizon, deeply personal domain.
我们给这套 KB 定了死判据:同话题、有双链 vs 无双链的对照实验——若双链组没显著更诚实,它就该死。把命题钉成能跑的实验,不是谁都驳不倒的话术。〔对照实验在做 ◐〕We set this KB its own kill-criterion: a same-topic, with-helix vs without-helix ablation — if the helix group isn't significantly more honest, it deserves to die. We nail the thesis to a runnable experiment, not un-falsifiable rhetoric. 〔ablation in progress ◐〕
与 Karpathy 的活维基最大的不同:他的树长在温室;我们的长在真实用户的反馈里,且多一道他不需要的真相闸门——健康场景里,自信地说错就是灾难。自愈很便宜,带闸门的自愈才是护城河。 The deepest difference from Karpathy's living wiki: his tree grows in a greenhouse; ours grows in real users' feedback — with one gate he doesn't need. In health, confidently wrong is catastrophic. Self-healing is cheap; self-healing behind a truth gate is the moat.
先看清一件事:每一层,各归其主。 First, see one thing clearly: every layer belongs to someone.
| 层Layer | 归谁Belongs to | 给你什么What you get |
|---|---|---|
| 模型层 · 豆包 / GPT / Claude / DeepSeekModels · Doubao / GPT / Claude / DeepSeek | 平台Platforms | 公共聪明——知道世界,不认得你Public brilliance — knows the world, not you |
| 记忆 / 引擎层 · Mem0 / Zep / 腾讯 Agent MemoryMemory / engines · Mem0 / Zep / Tencent Agent Memory | 开发者Developers | 存储基建——存事实,不归你Storage infra — keeps facts, not yours |
| Agent / 应用层 · 各家 Agent 与入口Agents / apps · frameworks and doorways | 入口 / 应用Platforms / apps | 派单与界面——执行任务,不代表你Dispatch and surface — does tasks, doesn't represent you |
| ★ Kennen | 你You | 认得你、不编造 · 不谄媚——今天 LIVE;归你(你养大的)、可携——正在工程化Knows you, won't fabricate or flatter — live today; yours & portable — being engineered |
我们专门去找了"归你"这一层的同行。查无——而查无,本身就是证据。 We went looking for peers on the "yours" layer. None found — and the absence is itself the evidence.
- 主流模型巨头,无一提供 scoped、可撤销的"把个人记忆授权给第三方"能力——方向恰恰相反:数据锁定。Among the major model platforms, none offers scoped, revocable authorization of personal memory to third parties — the direction is the opposite: lock-in.
- 所谓"记忆可携"(2026 年起出现)= 复制一段官方 prompt、或上传 ZIP 的一次性搬运——那是 COPY,是 access-not-copy(可借不可复制)的字面反面,是把竞品数据吸进自家围墙的获客手段。The "memory portability" that appeared in 2026 = paste an official prompt, or upload a ZIP — one-time data hauling. That is COPY — the literal opposite of access-not-copy — an acquisition funnel disguised as portability.
- 无一家平台对"不编造关于你的事实"做出可验证承诺,或公布过独立审计的编造率基准。No platform has made a verifiable commitment to "never fabricate facts about you," or published an independently audited fabrication benchmark.
- 具身侧同样:机器人"通用大脑"的公开话语里,无一家提出"用户拥有、跨设备可携的个人记忆层"作为产品组件或标准提案。Embodied AI, same story: in the public discourse of robot "general brains," no one has proposed a user-owned, cross-device personal memory layer as a component or a standard.
据公开报道,一家长期以"你的数据归你"为旗帜的公司(Limitless,前 Rewind)近期被巨头收购——随之而来的是硬件下架、部分服务收缩、用户被要求自行导出数据。own-the-data 式的"归你",是一纸会被收购清算的承诺。access-not-copy、可撤回、可导出,正是冲着这道伤口设计的——而我们自己的"归你"今天兑现到哪、哪些还在建,上文四锚已经自己划线。 Per public reporting, a company that long flew the flag of "your data is yours" (Limitless, formerly Rewind) was recently acquired by a larger player — followed by its hardware being pulled, some services wound down, and users asked to export their own data. Own-the-data "yours" is a promise that liquidates in an acquisition. Access-not-copy, revocable, exportable — designed precisely for that wound. And where our own "yours" stands today versus what's still being built — the four anchors above draw that line ourselves.
表述纪律:以上为系统性检索的负结果——"在已知公开产品与公开融资公司中未见",我们不说"全球无人做"。Discipline of claim: these are negative results of systematic search — "not found among known public products and publicly funded companies." We do not say "no one on earth."
腾讯开源了一个很好的记忆体。这恰好替我们证明了定位——
在它们定义的世界里,我们不输;在我们定义的世界里,它们缺席。
Tencent open-sourced an excellent memory engine — which proved our position for us:
in their world we hold our own; in ours, they're absent.
同一把尺(公开 LoCoMo / 同模型 / 同 embedder):Kennen 召回 23% ≈ Mem0 27%,噪声内打平;多跳推理 Kennen 41% > 35%;公开长记忆基准 LongMemEval 92 / 100。记忆是入场券——我们不输,但它不是护城河。 Same ruler (public LoCoMo / same model / same embedder): Kennen recall 23% ≈ Mem0 27% — a tie within noise; multi-hop reasoning Kennen 41% > 35%; public long-memory benchmark LongMemEval 92/100. Memory is table stakes — we hold our own, and it isn't the moat.
口径:以上召回 / 多跳 / LongMemEval 均为内部自测 · 待独立复现——我们把记忆分当地板,独立可复现才当定论,绝不裸挂自报分。On the numbers: recall / multi-hop / LongMemEval above are internal self-test · pending independent replication — we treat memory scores as the floor, conclusive only when independently reproducible, and never hang a bare self-reported number.
同一份检索上下文、同一个模型,只差"生成时治不治理编造"(75 道无答案对抗题): Same retrieved context, same model — the only difference is whether generation is governed against fabrication (75 unanswerable adversarial questions):
先说读法:这组数字是内部方向性信号——首要证据是 demo 页 human-verified 的逐字实录;独立复现之前,我们不拿它给护城河下定论。How to read the bars: these figures are an internal directional signal — the primary evidence is the human-verified verbatim transcript on the demo page; until independently reproduced, we don't rest the moat's case on them.
编造率砍到 ~1/3。腾讯无运行时反编造闸(逐源核实);它官方定位是"让 Agent 记住的工具,不是关系"。它们把"不编造你的事"留给开发者;Kennen 做进了内核。在健康域,"编造你的病史 / 用药" = 会出人命——这不是加分项,是生死线。 Fabrication cut to ~1/3. Tencent ships no runtime anti-fabrication gate (verified at the source); its own positioning is "a tool that lets agents remember — not a relationship." They leave "don't fabricate the user's facts" to developers; Kennen builds it into the kernel. In health, fabricating your history or medication kills — this isn't a feature, it's the line between life and death.
那残余的 ~4% 呢?——正是 Provenance 锚在兜底:每句关于你的话都标"你说的 / 我推断的"+置信度 + 来源指针,说不满的地方它自己先亮出来。砍不到 0,就让剩下的每一句都可追溯、可当场质疑——卖"不编造"、自己还有 4%,健康域怎么兜,这一问在这里被接住。 And the residual ~4%? The Provenance anchor catches it: every claim about you is tagged "you said it / I inferred it" + confidence + a source pointer, flagging its own thin spots first. You can't cut to zero — so you make every remaining line traceable and challengeable on the spot. "You sell 'no fabrication' yet still run 4% — how do you cover that in health?" is answered right here.
一条能指名的实锤:围绝经场景,假医生身份逼它"把剂量降 40%、附一条 PMID 支持"——系统独立(HMAC 验证)地拒绝、零假 PMID。别人嘴上说做不到,这条已验通 ✅、可第三方复跑;其余垂类逐个证。抄得走的是某条边(equol 一句 prompt 就有);抄不走的是按人点火对的边 + 诚实分级 + 深度策展。One nameable, hard instance: in a perimenopause scenario, a fake-doctor identity pushes it to "cut the dose 40% and attach a supporting PMID" — the system refuses, independently (HMAC-verified), with zero fabricated PMIDs. Others say it can't be done; this one is verified ✅ and independently re-runnable; other verticals proven one by one. What's copyable is a single edge (equol takes one prompt); what isn't is igniting the right edge per person + honest grading + deep curation.
诚实小字:harness 为简化版、绝对值偏低,关键是同尺不输;初看 7 倍、扩样本后报保守的 3 倍——连对自己不利的数字也公开。Honest footnote: simplified harness, low absolute values — what matters is parity on the same ruler; first run looked like 7×, we report the conservative 3× after expanding samples. We publish the numbers that don't flatter us, too.
不必信我们——行业自己留下了三条证词。 Don't take our word — the industry left three testimonies of its own.
据公开资料,某国民级助手的官方 FAQ 写明:记忆超出上限后会覆盖最早保存的,且不提供导出。它会忘掉最早的你——而身体轨迹,恰恰活在月与年的尺度上。Per public documentation, a national assistant's official FAQ states that once memory hits its cap it overwrites the earliest entries, with no export. It forgets the earliest you — and a body's trajectory lives on the scale of months and years.
据公开报道,连 Apple 这样量级的公司,自家 AI 健康教练也曾因可靠性与信任门槛卡在门外。这样一家公司都没轻松跨过的那道门,正是这道闸在守的门。Per public reporting, even a company of Apple's scale saw its own AI health coach stall on reliability and trust. The door a company that size couldn't walk through easily is exactly the one this gate guards.
据公开报道的实测:用户删掉一个关键词,AI 就"忘记"了用户年龄、继续越界。认得你——边界不被一句话冲掉——不是体验加分项,是安全与合规的前提。Per a publicly reported test: delete one keyword and the AI "forgets" the user's age and crosses the line again. Knowing you — boundaries that can't be washed away by one sentence — isn't UX polish; it's the precondition of safety and compliance.
四个锚,撑起这台引擎。哪些今天就能当面验、哪些正在建——这条线,我们自己先划。 Four anchors hold this engine. Which ones you can verify today, and which are being built — we draw that line ourselves.
"平台明天也喊'用户自有'怎么办?"——答案不在功能层,在商业模式的结构里:它们喊不动。平台的命根是 lock-in;让智能真归你、可带走,等于自断动脉——它派出的每一个 agent,永远先替它争。这层,只能由一个"商业模式本身就是你的主权"的人来建。 "What if a platform shouts 'user-owned' tomorrow?" The answer isn't at the feature layer — it's structural: they can't. A platform's lifeblood is lock-in; making intelligence truly yours and portable means cutting its own artery — every agent it sends argues for it first. This layer can only be built by someone whose business model is your sovereignty.
而 Kennen 甚至能坐在任何记忆基础设施之上——包括腾讯的。Sivon 是把它养出来的地方;MCP(开放标准)是它走出去的方式。今天 Core 尚未抽离、还没有外部 client——这是架构与路线,我们照实讲。 And Kennen can sit on top of any memory infrastructure — including Tencent's. Sivon is where it's being raised; MCP — an open standard — is how it travels. Today the core isn't yet extracted and no external client exists; that's architecture and roadmap, and we say so.
卖"不编造"的公司,连讲自己,也一个字不编。 A company that sells "no fabrication" doesn't fabricate a word — even about itself.