Safe Crime Prediction: Encrypted Deep Learning for Less Intrusive Surveillance
iamtrask.github.io
iamtrask.github.io
http://www.businessinsider.com/death-risk-statistics-terrori...
Terrorists have to kill literally hundreds of times more people per year for it to justify even the meagerest response. And one may argue about the economic impacts, but that's just a reflection of this underlying irrationality. If we had media focusing on "Keep Calm and Carry On" like Israel does now or Britain did in WWII it would have a much smaller economic impact - and terrorists would stop doing it, since it would be less effective at achieving the subgoal of "terror".
So this post is really begging the question IMO.
But you are certainly correct that statistically these events are more difficult to interpret, and raw averages are not a fair comparison.
"[...] the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country."
I'm a simple person. We have government, and we pay taxes so we can get services and have safety (that is what they tell us). So, terrorism is something we expect government to fix and resolve. Just like all the other things listed above that kill more people per year than terrorism. We can't just say "let's ignore it", and "we have to deal with X acts of terrorism per year for a N years before the terrorists lose interest". That is what some of these "anti-anti-terrorism" arguments logically lead to, and rightfully it's a tough pill to sell to the public.
Did it ever occur to you that terrorism could be aided by your or other government, using the taxes you and others pay? The US is arming rebel factions in Syria now. We'll see how that turns out. They armed the Taliban with Stinger missiles during the Russian war in Afghanistan. The Taliban took over the country and then harboured Osama Bin Laden and Al Queda. US ally Saudi Arabia is sponsoring ISIS and sunni rebel groups in Yemen. Turkey also bought oil from ISIS. There's a huge scandal in the Middle East now due to Quatar allegedly supporting the Muslim Brotherhood. Have tou ever heard the quote: state sponsored terrorism? All of this is done with taxpayer money.
Perhaps this post is most useful as a counter-argument to any "privacy vs safety" arguments that might be used to justify unrestricted access to consumer data.
There are other applications that such a system could be interesting for, though. What about determining interest rates on loans for people and small businesses? Small businesses could benefit greatly if lower-rate small loans enabled them to grow. Maybe insurance rates too? Etc.
And that's why there are no terrorist attacks in Israel.
But I'd like to raise another objection: Homomorphic encryption does not provide integrity over the ciphertext, which could open the door to active attacks against the systems that undermine its privacy goals.
https://news.ycombinator.com/item?id=14443191
https://paragonie.com/blog/2016/08/crypto-misnomers-zero-kno...
If you really need to build such a dangerous and needless system, would you want it to be built with such an error-prone cryptographic design? I'd say "No".
I'm still doubtful if the specificity of such pre-crime systems will be high enough that only a negligible number people will be wrongfully investigated. After all, the prevalence of terrorism is extremely low in any population. I guess if you trust law enforcement enough to escalate the investigation slowly and carefully (instead of putting a suspect on a no-fly list immediately) it can work.
Also, with regard to the audits by NGOs or government watchdogs: I suppose you would also need the auditors to cryptographically sign the version of the software they audited so that users can check that a trusted surveillance system was deployed.
How is public-key homomorphic encryption possible? Suppose I know the pub-key, and have some cipher text X. Can't I simply encrypt 0 and try, for all plausible values V, whether encrypt(V) - X = encrypt(0). Or is the encryption function not reversible, i.e. there are multiple 0s?
If not, it seems like you'd need quite a bit of true entropy in the plausible values. I don't see how you add something like a Nonce to artificially add entropy.
Heck, if you have nice integer under/over flow on division, that would give a crude implementation of comparison, bringing the search down by a logarithm.
It seems like the only reasonable situation is one where indeed multiple different values decrypt to 0.
Yep, there's padding.
That, combined with comparison based on integer division and underflow would still make decryption quite easy.
That is the scariest thing I've read. All we need is a black box to investigate people at anytime.
The real question is who owns them and are they audit-able? This blogpost is about making neural networks used for these purposes auditable by a third party without making them vulnerable to evasion by criminals.
For the SPAM example you provided, you used a Data Set available publicly with no consequences. But where will the training data for prediction of homicides will come from? Will it be accurate? Will it unfairly target minorities?
The predictor uses features in the data to predict the future. What features will the machine learning algorithm learn to predict homicide? location? age? gender? ethnicity? mannerism? income? I could see big problems with any features used to detect and potentially send law enforcement for "Investigations"
- Detectors
Capturing and sending users data to a warehouse is a privacy/security risk. But what is worse is installing a detector in their house, or in their computer. What happens when a citizen removes the SPAM detector from their computer? Well, the next logical step is to pass a law requiring all citizens to run a specific process on their computer and are not allowed to reverse engineer it or else...
For me, this is even worse than having my privacy violated. It would mean users would not have root access to their own computer. It would mean, many applications will be illegal and developers cannot write certain applications that enable people to send emails. If this is not impossible, it would be the worst outcome for everyone.
- Globalization
The SPAM detector, the fire detector and the sniffer dog are great localized examples. But todays problems are globalized. Attacks might be planned and coordinated from different country with different set of rules. And not all countries are considerate when it comes to privacy. How will global security surveillance deployment work when we can't even agree on matters of climate change?
That sad truth is that police bear no cost when they fail to prevent crime and, in fact, get more funding and power if crime goes up.
Someone will inevitably make this though, and it will inevitably be abused.
Plus what if I start switching search parameters from say, 'planning a terrorist attack' to, likely to to vote one way, believe on thing, or be of a certain religion.
We will trade all our privacy and the nefarious people will switch to a new method of comms...like they always do.
Keep in mind the extents governments and other private enterprise would go to get their hands on this.
You will have created a clean super-weapon.
Or 'the dark mark' for those biblical folk out there.
Can you imagine what that would do to your life as well? Even if you couldn't access the information.
Half the governments of the world would torture you just to double-check.
I think that's from Harry Potter, not the bible. Maybe you meant the mark of the beast?
Its just a smart way to comb through all the data you've extracted.
I ask this about the following contexts:
- government surveillance: does using a homomorphism remove the need for a search warrant?
- in-app analytics: does using homomorphisms allow a firm to consider data not disclaimed by the firm's privacy policy?
- research: when does a homomorphism eliminate the need for IRB approval?