Live data from Hacker News

Attacks against machine learning – an overview

elie.net

21–30 of 66 posts

Re: Attacks against machine learning – an overview

#21
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

This is very much the same foundation of disinformation campaigns like strongarm regime propaganda or what is currently termed “fake news”. By attacking credibility itself, anything and nothing are equally valid. The problem with poisoning the well of your own personal data is that it also makes it easier to indict you on false pretenses.

Re: Attacks against machine learning – an overview

#22

I just watched a presentation about using deep learning to detect cheaters in CounterStrike: Go ( https://youtu.be/ObhK8lUfIlc ) and the question he didn't seem to have an answer for was data poisoning -- what if the cheaters all volunteer to be on the anti-cheater jury? Of course they are cross checking juror reliability ratings and stuff, but it's definitely a treadmill.

Whenever you're crowdsourcing, bad actors are a possibility. You'd usually track agreement to root out both the bad and incompetent actors, but what you're saying would essentially amount to a 51%-attack. That is, with enough bad actors working together, consensus stops being trustworthy.

I see two ways to address this (there are probably more, this is just me thinking out loud):

1. Increase the size of the pool of total reviewers so a 51%-attack becomes infeasible. Incentives can be offered to the rest of the community to get them to participate. (This is similar to what bitcoin tries to do, with the added obstacle of actor anonymity. In an anonymous system, 1 bad actor can trivially simulate an arbitrary number of actors. Bitcoin tries to solve this by increasing the operating cost for each perceived actor. Counter Strike can be seen as having a fixed lump operating cost: purchase price of the game + time investment to accrue enough XP to qualify for the cheater jury. )

2. Create an additional set of people you trust unconditionally. (These can be people you train and pay a wage.) This means you can spot-check anyone, and a consensus between bad actors is an investigative clue (to find more bad actors) rather than a hindrance.

Re: Attacks against machine learning – an overview

#23
post #11

Interesting post. Maybe to complete about adversarial examples in medicine https://medium.com/fitchain/attacking-deep-learning-models-3...

Is the thesis there that Big Pharma would pollute the data to sell more cancer cures to people with moles?

Re: Attacks against machine learning – an overview

#24
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

How about you don’t sign up for Facebook if you don’t want them to know anything about you? I don’t really see the point of this deception.

Re: Attacks against machine learning – an overview

#25
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

How about you don’t sign up for Facebook if you don’t want them to know anything about you? I don’t really see the point of this deception.

Because facebook tracks you, even if you do not have a facebook account.

https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

Re: Attacks against machine learning – an overview

#26
post #14

Earlier quoted context omitted.

AdNauseum[1] is that "service", but Google blocked it from the Chorome Add On Store for obvious reasons. [1]: https://adnauseam.io/

One of the many reasons I switched over to Firefox. Additionally, AdNauseum is an amazing product name.

*AdNauseam

Re: Attacks against machine learning – an overview

#27

Earlier quoted context omitted.

How about you don’t sign up for Facebook if you don’t want them to know anything about you? I don’t really see the point of this deception.

Because facebook tracks you, even if you do not have a facebook account. https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

The problem is laziness. “Call your Congressperson” is hard. Waxing lyrical about political distinction is easy. Imagining technical solutions to political problems is easier.

Re: Attacks against machine learning – an overview

#28

Earlier quoted context omitted.

Because facebook tracks you, even if you do not have a facebook account. https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

The problem is laziness. “Call your Congressperson” is hard. Waxing lyrical about political distinction is easy. Imagining technical solutions to political problems is easier.

I'd say that there are two related problems, one political and one technical, and that there is no reason not to address both issues.

* Political problem: It is legal and acceptable to track people on the internet to an extreme degree. Political solution: Call your Congressperson, donate to the EFF, reframe the issue as corporate stalking, etc.

* Technical problem: It is possible to track people on the internet to an extreme degree. Technical solution: Restrict ability to collect data by using adblock, poison existing databases with reasonable but false data.

Re: Attacks against machine learning – an overview

#29

Earlier quoted context omitted.

How about you don’t sign up for Facebook if you don’t want them to know anything about you? I don’t really see the point of this deception.

Because facebook tracks you, even if you do not have a facebook account. https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

is it possible to block facebook domain via hosts file or chrome extension?

Re: Attacks against machine learning – an overview

#30
post #14

Earlier quoted context omitted.

AdNauseum[1] is that "service", but Google blocked it from the Chorome Add On Store for obvious reasons. [1]: https://adnauseam.io/

One of the many reasons I switched over to Firefox. Additionally, AdNauseum is an amazing product name.

Another reason: Stylus (FF-only) vs. Stylish (which works on both FF and Chrome, but collects your data).
Post reply on HN