How AI + Hardware can Transforming Point-of-Care Workflows
PamirAI (co-founder · PamirAI)
DEF CON 33 · Day 1 · Main Stage
Overview
This talk, presented by a co-founder of PamirAI, delves into the transformative potential of integrating Artificial Intelligence (AI) with hardware to revolutionize various workflows, particularly in point-of-care and embedded systems. PamirAI, a San Francisco-based startup, specializes in bridging the gap between advanced AI models and resource-constrained hardware, enabling innovative applications that were previously confined to powerful data centers. The presentation highlights how recent advancements in open-source Large Language Models (LLMs) have made it possible to deploy increasingly sophisticated AI capabilities on compact, low-power devices like the Raspberry Pi.

Key moments
- 0:00 Introduction to PamirAI and talk's focus
- 2:00 Challenge: Running AI on embedded systems like Raspberry Pi
- 2:30 Open-source models enabling AI on embedded systems
- 4:00 DEF CON badge: Raspberry Pi 5 controlling sensors
- 5:45 Med-Gemma model for clinical reasoning and medical knowledge
- 7:00 Vision: Large AI models as agents for full hardware control
- 8:00 Examples: AI programming Flipper Zero, Arduino, thermal printer
How AI + Hardware can Transforming Point-of-Care Workflows
Speakers: PamirAI (co-founder, PamirAI)
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=-5bArYeJ3sU
Overview
This talk, presented by a co-founder of PamirAI, delves into the transformative potential of integrating Artificial Intelligence (AI) with hardware to revolutionize various workflows, particularly in point-of-care and embedded systems. PamirAI, a San Francisco-based startup, specializes in bridging the gap between advanced AI models and resource-constrained hardware, enabling innovative applications that were previously confined to powerful data centers. The presentation highlights how recent advancements in open-source Large Language Models (LLMs) have made it possible to deploy increasingly sophisticated AI capabilities on compact, low-power devices like the Raspberry Pi.
The speaker showcases practical applications developed in collaboration with the Biohacking Village at DEF CON, demonstrating how miniaturized AI inference engines can control real-world sensors, perform basic medical QA, and even act as autonomous agents to program and manage diverse hardware. This paradigm shift promises to democratize access to powerful AI tools, moving computation closer to the edge and fostering a new era of intelligent, self-configuring embedded systems. The talk underscores the critical importance of local AI execution for privacy, especially concerning sensitive medical and biometric data, envisioning a future where AI agents operate robustly and autonomously without relying on cloud infrastructure.
Background
▶ Watch: Introduction to PamirAI and talk's focus (0:00)
The landscape of AI model deployment has historically been stratified by computational demands. Enormous models, such as those powering popular platforms like ChatGPT (often exceeding 70 billion parameters), necessitate substantial GPU clusters for inference, placing them out of reach for individual users or edge devices. Mid-range models, typically ranging from 13 billion to 30 billion parameters, can be comfortably run on high-end consumer hardware like a Mac Studio. Smaller models, in the 0.5 billion to 7 billion parameter range, are increasingly viable on modern smartphones, offering decent but not always cutting-edge performance.
However, a significant void existed for truly embedded systems – devices like Raspberry Pi, Arduino, or ESP32, which are characterized by extreme resource constraints in terms of processing power, memory, and energy. For a long time, deploying anything beyond rudimentary machine learning models on these platforms was impractical. This began to change dramatically in the past half-year, thanks to a surge in open-source community contributions. Models like Qwen, Llama (with new 1-billion to 3-billion parameter variants), Smollm (3-billion to 4-billion parameter), and Google's Gemma series (including MatGemma) have emerged, specifically designed for efficiency and smaller footprints while retaining remarkable capabilities. These innovations have made it feasible to "squeeze" powerful language models into the limited resources of embedded systems, paving the way for local AI inference in a vast array of new applications.
Key Findings
▶ Watch: Open-source models enabling AI on embedded systems (2:30)
The central finding of this talk is the profound capability of suitably optimized Large Language Models (LLMs) to transform embedded systems from static, pre-programmed devices into dynamic, intelligent, and self-configuring agents. The speaker demonstrates that even relatively small open-source models, when deployed on hardware like a Raspberry Pi 5, can perform surprisingly sophisticated tasks, particularly in the realm of medical knowledge and hardware control.
Specifically, the key findings include:
- Viability of Small LLMs on Embedded Hardware: Models in the 1-billion to 4-billion parameter range (e.g., Llama 1B-3B, Smollm 3B-4B, MatGemma 4B) can now run effectively on single-board computers like the Raspberry Pi, enabling local AI inference with practical utility. A 1-billion parameter model can facilitate "okayish communication," akin to talking to a 10-year-old. At 2 billion parameters, models become capable of generating JSON-type requests, making them "useful" for structured data interaction. By 3-4 billion parameters, they can "very reliably" call Python functions, signaling a significant leap in programmatic control.
- Medical QA Capabilities at the Edge: The integration of a 4-billion parameter MatGemma model on a Raspberry Pi 5 badge demonstrated a surprising ability to answer medical questions, such as appropriate antibiotic dosages for a 2-year-old. While not hyper-accurate, the answers were within a "correct range," exceeding the speaker's own knowledge. Google's research on MatGemma for clinical reasoning and chest X-ray report generation further validates this potential for point-of-care diagnostics and information retrieval, even hinting at "doomsday device" utility.
- AI as an Autonomous Hardware Agent: Perhaps the most groundbreaking finding is the potential for large, cloud-based LLMs (like Anthropic models) to act as AI agents with full control over a Linux system connected to diverse hardware. These agents can interpret natural language commands, dynamically generate and load drivers, log data, build user interfaces, and even implement error retry mechanisms—all without a human writing a single line of code. This capability was demonstrated by controlling various devices, from Flipper Zeros and Arduinos to thermal printers and even Roomba vacuum cleaners.
- Future of Local, Privacy-Preserving AI Agents: The talk emphasizes the critical need and emerging feasibility of running these advanced AI agents entirely locally. Citing research like the "multi-step planning and reasoning improves acting RM agent" (or pre-act paper), the speaker suggests that fine-tuning larger models (e.g., 70 billion parameters) on specific planning and reasoning datasets could soon enable cloud-level AI performance on consumer hardware like MacBooks or Mac Studios. This local execution is deemed "very important" for applications involving sensitive biometric or medical data, ensuring privacy and reducing reliance on external cloud services.
These findings collectively point to a future where AI is not just a cloud service but an integrated, intelligent component of everyday hardware, capable of autonomous operation and personalized interaction, especially in critical sectors like healthcare.
Technical Deep Dive
▶ Watch: DEF CON badge: Raspberry Pi 5 controlling sensors (4:00)
The technical core of PamirAI's approach lies in its ability to bridge the gap between sophisticated AI models and the inherent limitations of embedded hardware. This is achieved through a combination of leveraging optimized open-source LLMs and developing frameworks that allow these models to interact with and control physical systems.
Model Miniaturization and Performance Tiers:
The talk meticulously outlines a hierarchy of LLM performance relative to their parameter count and the hardware they can run on:
- 70 Billion+ Parameters: Exclusively on GPU clusters (e.g., large-scale cloud AI).
- 13 Billion - 30 Billion Parameters: Runnable on high-end consumer hardware like a MacBook or Mac Studio.
- 0.5 Billion - 7 Billion Parameters: Achievable on modern smartphones, offering "decent results."
- Embedded Systems (Raspberry Pi, Arduino, ESP32): This is PamirAI's target domain. The speaker highlights recent breakthroughs in open-source models:
- Qwen (qwen): A model known for its efficiency.
- Llama 1B-3B: Smaller variants of Meta's Llama series, specifically optimized for smaller footprints.
- Smollm (S M O L L M): From Hugging Face, offering 3-billion to 4-billion parameter models with good performance.
- Google's Gemma: A family of models, including specialized versions.
- MatGemma (me Gemma): A Google-developed open-source model specifically trained for clinical reasoning and general medical knowledge answering.
The speaker provides a practical progression of capabilities observed with these smaller models on a Raspberry Pi:
- 1 Billion Parameters: Offers "okayish communication," described as "talking to a 10-year-old," capable of telling stories.
- 2 Billion Parameters: Becomes "useful" by reliably generating JSON-type requests, enabling structured data interaction.
- 3-4 Billion Parameters: Achieves highly reliable execution of Python functions, marking a critical threshold for programmatic control and automation.
The Biohacking Village Badge:
A concrete example of this technology is the custom badge developed for the Biohacking Village at DEF CON. This badge integrates a Raspberry Pi 5 as its core processing unit, running a 4-billion parameter MatGemma model. The choice of MatGemma is significant due to its specialized training in medical knowledge. The badge was demonstrated to:
- Control RGB LEDs: Simple commands like "red," "green," "blue" were reliably processed to control the badge's four LEDs via a Python function. More complex color requests like "pink" or "purple" (requiring reasoning about RGB combinations) often failed, highlighting the current limitations of these smaller models in complex, multi-step reasoning.
- Perform Medical QA: The MatGemma model surprised attendees by providing a "correct range" answer to a query about antibiotic dosage for a 2-year-old. This showcases the potential for embedded AI to offer immediate, context-aware medical information at the point of need. The speaker also referenced Google's research on MatGemma for generating chest X-ray reports, further validating its clinical utility.
AI as an Autonomous Agent for Hardware Control:
Beyond static inference, the talk explores a more advanced paradigm: the AI agent. This involves a large, cloud-based LLM (like those from Anthropic) being given full control over a Linux system (specifically, a single-board computer housing a Raspberry Pi 5). This agent operates with an unprecedented degree of autonomy:
- Driver Generation and Loading: The AI can analyze connected hardware, identify its type, search for existing drivers or SDKs (even obscure command-line interfaces like the Arduino IDE CLI), and then automatically download and load them.
- Code Generation and Deployment: Given a high-level natural language prompt, the AI can generate the necessary code (e.g., a Flipper Zero screensaver, Arduino firmware) and deploy it to the target device.
- System Interaction: The agent can log data, build user interfaces, and even implement error retry mechanisms, creating a highly resilient and self-correcting system.
- Reverse Engineering and Custom Drivers: A notable achievement was the AI's ability to reverse-engineer the universal protocol of a generic thermal printer (designed only for shipping labels) and write a custom Linux driver for it, enabling the printing of arbitrary stickers. This demonstrates a sophisticated capability to adapt and extend hardware functionality beyond its original design.
- Complex Device Integration: The AI successfully integrated a Roomba vacuum cleaner via its USB port, found the appropriate driver, and enabled control using an Xbox controller.
The Path to Local AI Agents:
A critical future direction emphasized is the transition from cloud-dependent AI agents to fully local execution. The speaker points to the "multi-step planning and reasoning improves acting RM agent" paper (often referred to as the pre-act paper) as a key enabler. This research suggests that fine-tuning large models (e.g., 70 billion parameters) on specific datasets focused on "thinking, replanning" can allow them to achieve performance comparable to much larger cloud models. The speaker anticipates that such capabilities, enabling full AI agent functionality on devices like MacBooks or Mac Studios, could materialize within the next "two or three months." This move to local computation is deemed essential for data privacy, particularly for sensitive medical and biometric information, and for enabling robust automation in industries like medical device operation, where complex UIs could be simplified by AI agents interpreting manuals and SDKs.
Demo / Proof of Concept
▶ Watch: Vision: Large AI models as agents for full hardware control (7:00)
The talk presented several compelling demonstrations and proof-of-concept scenarios, illustrating the practical application of AI on embedded hardware and as an autonomous agent.
- Biohacking Village Badge (Raspberry Pi 5 with MatGemma):
- Hardware: A custom badge built around a Raspberry Pi 5.
- AI Model: A 4-billion parameter MatGemma model was deployed on the device.
- Sensor Control: The badge featured four RGB LEDs. The speaker demonstrated that the model could reliably interpret commands for primary colors ("red," "green," "blue") and translate them into Python function calls to illuminate the corresponding LEDs. However, when asked for complex colors like "pink" or "purple," which require reasoning about RGB combinations, the smaller model struggled, occasionally outputting incorrect colors. This highlighted both the capabilities and current limitations of embedded LLMs for complex, multi-step reasoning.
- Medical QA: An attendee asked the badge about the appropriate antibiotic dosage for a 2-year-old. The MatGemma model provided an answer in "milligrams," which the speaker noted was within a "correct range," expressing surprise at its accuracy and medical knowledge. This served as a compelling real-world example of point-of-care medical information retrieval on a constrained device.
- AI Agent Controlling a Full Linux System (Cloud-based LLM):
This series of demonstrations showcased the power of a "very, very big cloud model" (implicitly Anthropic's) given full control over a single-board computer running Linux, effectively acting as an AI agent.
- Flipper Zero Screensaver: The speaker wanted a custom screensaver for a Flipper Zero but didn't know how to code one. The AI agent, connected to the Flipper Zero, identified a command-line driver/SDK for the device and proceeded to write and deploy a screensaver without human intervention.
- Arduino Programming: Similarly, an Arduino was connected, and the AI agent, upon identifying its type and product number, discovered the Arduino IDE CLI. It then used this command-line interface to program the Arduino with the desired functionality.
- Thermal Printer Driver Development: A standard thermal printer, designed only for shipping labels and lacking Linux drivers, was connected. The AI agent recognized it as a printer using a "universal protocol." It then reverse-engineered the protocol and wrote a complete custom Linux driver for the device, allowing it to print arbitrary content like stickers, extending its functionality beyond its manufacturer's intent.
- Roomba Control: A used Roomba with a USB port was connected. The AI agent successfully located and loaded the necessary driver, enabling control of the Roomba via an Xbox controller. This demonstrated the AI's ability to integrate and control complex, consumer-grade robotics.
These demonstrations collectively illustrate a future where AI agents can autonomously interact with, program, and even reverse-engineer hardware, significantly reducing the need for manual coding and specialized knowledge in hardware development and integration.
Defensive Implications
▶ Watch: Examples: AI programming Flipper Zero, Arduino, thermal printer (8:00)
The capabilities demonstrated in this talk, while primarily focused on enablement and automation, carry significant defensive implications for cybersecurity professionals and hardware manufacturers. The concept of an AI agent with autonomous control over embedded systems and the ability to generate code, download drivers, and even reverse-engineer protocols introduces a new frontier of potential risks and challenges.
- Automated Exploitation and Hacking: The speaker explicitly mentions, "if you have an AI in your pocket and can slightly hack stuff for me." This is a direct acknowledgement of the offensive potential. An AI agent, especially one with access to vast knowledge bases and system control, could potentially:
- Discover Vulnerabilities: Automate the process of identifying weaknesses in connected hardware or software configurations.
- Generate Exploits: Craft custom exploits for identified vulnerabilities, similar to how it generates drivers.
- Automate Post-Exploitation: Perform reconnaissance, privilege escalation, and data exfiltration steps autonomously.
- Supply Chain Attacks: If an AI agent is tasked with downloading and installing drivers or SDKs, it could inadvertently pull malicious code from compromised repositories or make poor security decisions in selecting sources.
- Increased Attack Surface for Embedded Systems: By making embedded systems more programmable and interconnected, AI agents inherently expand their attack surface. Devices previously considered "air-gapped" or too specialized to exploit could become targets if an AI agent gains initial access. The ability to automatically load drivers and reconfigure hardware presents new avenues for compromise.
- Lack of Human Oversight and Audit Trails: An AI agent operating autonomously, generating code, and performing actions without explicit human instruction or review could lead to unintended security flaws or actions that are difficult to trace. Debugging or auditing the decisions of a complex LLM acting as an agent poses a significant challenge.
- Data Privacy and Confidentiality Risks: While the speaker strongly advocates for local execution for privacy, the initial demonstrations often rely on large cloud models. Transmitting sensitive operational data, device specifics, or even medical queries to remote cloud services introduces data leakage risks and compliance challenges, especially in regulated environments like healthcare. Even with local models, ensuring the model itself hasn't been trained on or doesn't inadvertently leak sensitive information remains a concern.
- Physical World Impact of AI Control: The Roomba demonstration highlights the AI's ability to control physical devices. If an AI agent gains unauthorized control over critical infrastructure, medical devices, or industrial control systems, the consequences could extend beyond data breaches to physical damage or disruption of services.
Defensive Strategies and Mitigations:
- Secure by Design for AI Agents: Implement robust security principles in the development of AI agents, including sandboxing, least privilege access, and strict input/output validation.
- Trusted Execution Environments (TEEs) & Secure Boot: For embedded systems running AI, leveraging TEEs and secure boot mechanisms can help ensure the integrity of the AI model and its operating environment, preventing tampering.
- Rigorous Code Validation: For AI-generated code, implement automated and, where critical, manual code review processes to identify potential vulnerabilities before deployment.
- Source Verification and Supply Chain Security: Implement strict policies for verifying the authenticity and integrity of all drivers, SDKs, and software components downloaded or generated by AI agents.
- Granular Access Control: Ensure that AI agents only have the minimum necessary permissions to perform their tasks. Limit their ability to access or modify critical system components.
- Monitoring and Anomaly Detection: Implement continuous monitoring of AI-controlled systems for unusual behavior, unauthorized access attempts, or deviations from normal operational parameters.
- Privacy-Preserving AI: Prioritize the development and deployment of local, on-device AI models for sensitive applications, minimizing data transmission to external cloud services.
- Explainable AI (XAI): Research and integrate XAI techniques to better understand and audit the decisions made by AI agents, improving transparency and accountability.
The advent of AI-driven hardware control represents a powerful leap forward, but it mandates a proactive and comprehensive approach to security to harness its benefits responsibly.
Key Takeaways
- Small LLMs are Viable for Embedded Systems: Recent advancements in open-source models (1-4 billion parameters like Llama, Smollm, MatGemma) enable sophisticated AI inference directly on resource-constrained hardware such as Raspberry Pi 5.
- AI Enhances Point-of-Care & Medical Automation: Models like MatGemma deployed on embedded devices can provide surprisingly accurate medical QA and clinical reasoning, hinting at transformative potential for diagnostics and patient information at the edge.
- Autonomous AI Agents Revolutionize Hardware Control: Large, cloud-based LLMs can act as powerful AI agents, taking full control of Linux systems to automatically generate drivers, program devices (Flipper Zero, Arduino), reverse-engineer protocols, and integrate diverse hardware (thermal printers, Roomba) via natural language commands.
- Local Execution is Critical for Privacy and Security: The future of AI agents emphasizes running models entirely locally (e.g., 70B parameter models on Mac Studio) to protect sensitive biometric and medical data, ensuring privacy and reducing reliance on external cloud infrastructure.
- New Security Implications Emerge: The ability of AI to autonomously control, program, and "hack" hardware introduces significant defensive challenges, including potential for automated exploitation, supply chain risks, and the need for robust security-by-design principles for AI agents.
- Simplified Human-Machine Interaction: AI-driven interfaces can drastically simplify the operation of complex machinery, particularly medical devices, by allowing users to interact via natural language rather than navigating intricate UIs or SDKs.
About the Speaker(s)
The talk was delivered by a co-founder of PamirAI, a startup based in San Francisco. The speaker's background includes prior experience working at both Microsoft and Qualcomm. This professional history provides a strong foundation in both Artificial Intelligence development and hardware engineering, which are the core disciplines PamirAI leverages to bridge the gap between advanced AI models and embedded systems. Their expertise is evident in the detailed understanding of AI model architectures, their computational requirements, and the practical challenges of deploying them on diverse hardware platforms.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A product demo disguised as a research talk. PamirAI's co-founder spent a DEF CON slot showing their startup's integration layer for running small LLMs on Raspberry Pi hardware — interesting technology, zero original research. The 'findings' are a restatement of what Hugging Face blog posts and the llama.cpp README already tell you.
Heather Calloway (CISO) — PASS
A founder demo from a DEF CON adjacent stage showing edge AI inference on a Raspberry Pi. Outside my lane by design — there is no governance angle, no institutional risk framing, and no content for security leaders or defenders at any level that matters to this audience.