Live data from Hacker News

Attacks against machine learning – an overview

elie.net

31–40 of 66 posts

Re: Attacks against machine learning – an overview

#31
post #18

Earlier quoted context omitted.

I suggested this to an EFF lawyer at Defcon and they hated the idea. Perhaps I worded it wrong, it makes sense to me. Signal to noise ratio. You should have a legal right to submit false information if you feel a service might harm you at some point.

Interesting, what did they hate about it?

Not OP but if I had to guess, once you have a 'legal right' to submit false information it paves the way for a lot of unwanted behavior and would help the spread of disinformation. If a service is harming you and you're thinking about ways to legally address the issue, why not just go after the service itself and come up with legal repercussions / regulations for their actions?

Your question led me to this NPR article that briefly talks about the legality of lying on the Internet that's worth mentioning (https://www.npr.org/sections/thetwo-way/2011/11/15/142356399...). It seems that when you agree to the Terms of Service with services like Facebook, you agree to not spread misinformation or misrepresent yourself (https://www.facebook.com/communitystandards/integrity_authen...).

Re: Attacks against machine learning – an overview

#32
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

Ask Apple.

https://www.digitaltrends.com/apple/apple-gets-privacy-prote...

Re: Attacks against machine learning – an overview

#33
post #18
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

I suggested this to an EFF lawyer at Defcon and they hated the idea. Perhaps I worded it wrong, it makes sense to me. Signal to noise ratio. You should have a legal right to submit false information if you feel a service might harm you at some point.

Apple could file a patent infringement suit if you tried to automate it.

https://www.digitaltrends.com/apple/apple-gets-privacy-prote...

Re: Attacks against machine learning – an overview

#34
post #6
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

I actually had the strategy on fb to just like very random stuff like movies, groups etc. I’m not sure whether it has helped but it makes me feel better

> I actually had the strategy on fb to just like very random stuff like movies, groups etc. I’m not sure whether it has helped but it makes me feel better

I've done similar, and afterwards nearly all advertising categorizations of me eventually dropped off my profile (after a period where they were schizophrenic and contradictory). I can't be certain I caused that, because this was contemporaneous with Zuck's congressional testimony and the run up to the GDPR (both of which probably motivated many changes).

But it would make sense that mountains of bad data would make it hard for them to confidently place me in advertising demographic and interest categories, do to all the contradictions.

Re: Attacks against machine learning – an overview

#35

Earlier quoted context omitted.

Could you just give fake info? Or else use multiple fake profiles? I don't know how you an deceive Facebook without also deceiving your friends and contacts though.

Does the api support creating old posts and back dating them? FB is really good at hiding old activity and being utterly worthless at searching your feed, so if you can just put all the fake stuff in the past you'd be fine with your real friends.

> Does the api support creating old posts and back dating them?

> FB is really good at hiding old activity and being utterly worthless at searching your feed, so if you can just put all the fake stuff in the past you'd be fine with your real friends.

They allow you to back date, but if you're goal is to avoid annoying your friends, you could use the privacy settings for a similar effect. Just post your garbage as visible to "only me," let it age for a week or two until the algorithm will ignore it, then make it "public," "friends only," or whatever you want.

Re: Attacks against machine learning – an overview

#36
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

       COMPOSITE HACKS
Are you Seeking for the Best Legit Professional Hackers online?? Congratulations Your search ends right here with us.

COMPOSITE HACKS is a vibrant squad of dedicated online hackers maintaining the highest standards and unparalleled professionalism in every aspect. We Are One Of The Leading Hack Teams in The United States🇺🇸🇺🇸 With So many Accolades From The IT Companies. In this online world there is no Electronic Device we cannot hack. Having years of experience in serving Clients with Professional Hacking services, we have mastered them all. You might get scammed for wrong hacking services or by fake hackers on the Internet. Don't get fooled by scamers that are advertising false professional hacking services via False Testimonies, and sort of Fake Write Ups.

* COMPOSITE HACKS is the Answers to your prayers. We Can help you to recover the password of your email, Facebook or any other accounts, Facebook Hack, Phone Hack (Which enables you to monitor your kids/wife/husband/boyfriend/girlfriend, by gaining access to everything they are doing on their phone without their notice), You Wanna Hack A Website or Database? You wanna Clear your Criminal Records?? Our Team accepts all types of hacking orders and delivers assured results to alleviate your agonies and anxieties. Our main areas of expertise include but is never confined to:

Website hacking ,Facebook and social media hacking, Database hacking, Email hacking⌨️, Phone and Gadget Hacking,Clearing Of Criminal Records Location Tracking Credit Card Loading and many More

We have a trained team of seasoned professionals under various skillsets when it comes to online hacking services. Our company in fact houses a separate group of specialists who are productively focussed and established authorities in different platforms. They hail from a proven track record and have cracked even the toughest of barriers to intrude and capture or recapture all relevant data needed by our Clients.

COMPOSITE HACKS understands your requirements to hire a professional hacker and can perceive what actually threatens you and risk your business️, relationships or even life. We are 100% trusted professional hacking Organization and keep your deal entirely confidential. We are aware of the hazards involved. Our team under no circumstances disclose information to any third party. The core values adhered by our firm is based on trust and faith. Our expert hacking online Organization supports you on time and reply to any query related to the unique services we offer.

COMPOSITE HACKS is available for customer care 24/7, all day and night. We understand that your request might be urgent, so we have a separate team of allocated hackers who interact with our Clients round the clock⏰. You are with the right people so just get started.

CONTACT US TODAY VIA: compositehacks@gmail.com

Re: Attacks against machine learning – an overview

#37
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

Not a happy answer but such a service would raise the noise floor but would otherwise not have much of an effect unless it was massively adopted to the point that the original signal was insignificant compared to the noise.

Even then it’s questionable if it would be effective. Over time even a faint behavioral signature will become transparent, because things that deviate from the true behavioral signature do so in random ways, which could essentially “cancel” out if your model for quantifying behavioral characteristics is well-specified. Meanwhile the “true” behaviors would “add” over time.

It would become like any other signal jamming arms race, whether it’s radar or social behaviors, and your model of generating random noise has to get more sophisticated as the other party’s anti-jamming techniques get more sophisticated.

I took a class with Scott Aaronson once where he mentioned the idea that the natural enemy of machine learning is cryptography.

So if you know the anti-jammers are using ever greater machine learning techniques, rather than trying to one-up them with adversarial learning, I suspect the best jamming would be cryptography.

Like, extensions to Facebook that essential encode text with PGP or something, send via Messenger, and allow decoding on the other side.

Then an interesting idea for machine learning would be how to make an autoencoder that accepts encrypted text, transforms it into human understandable text that would fool a machine learning algorithm designed to flag encrypted text, and can decode from natural language back to the encrypted data on the other end.

Re: Attacks against machine learning – an overview

#38
> Model stealing techniques, which are used to “steal” (i.e., duplicate) models or recover training data membership via blackbox probing. This can be used, for example, to steal stock market prediction models

I would like to hear stories about such attacks on stock market models.

Re: Attacks against machine learning – an overview

#39
post #21
post #3

It'd be great if there was a service that you could sign up for, which would "deceive" Facebook, Twitter, and other social media websites by producing false information about you. For example, if I don't want FB to know what movies I'm interested in, how about liking "random" movie pages on FB? If I don't want FB to know about my political orientations, how about run with the hare and hunt with the hounds?

This is very much the same foundation of disinformation campaigns like strongarm regime propaganda or what is currently termed “fake news”. By attacking credibility itself, anything and nothing are equally valid. The problem with poisoning the well of your own personal data is that it also makes it easier to indict you on false pretenses.

I guess if enough number of people do it, it removes the ability to indict anyone.

Re: Attacks against machine learning – an overview

#40

Earlier quoted context omitted.

How about you don’t sign up for Facebook if you don’t want them to know anything about you? I don’t really see the point of this deception.

Because facebook tracks you, even if you do not have a facebook account. https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

Because the word "tracking" can include request monitoring for DDoS mitigation and scraping detection, or storing information purposefully uploaded by other people (e.g. photos and contact list), saying anything about "tracking" isn't very meaningful.

Think of how many people are being involuntarily "tracked" by Dropbox because others are backing up photos in which they appear, or emails they sent, without their consent. For better headlines, we could call this information "Dropbox Shadow Dossiers".

Post reply on HN