I don't see how it can work any other way.
I don't see how it can work any other way.
If cops can get a warrant on mere hunches, then I agree we have real problems. But a separate problem.
Mission critical ML systems (G/FB ads, crime forensics, medical decision support, financial algorithms) do not work like this.
The designers know exactly which features are causing responses/predictions in the model, their respective perturbation sensitivities, and have clear bounds regarding adversarial inputs/outliers.
“Not knowing how the model works” is definitely true for deep learning, though.
First of all, deep learning absolutely is used in mission critical systems: https://www.techrepublic.com/article/intel-and-ge-healthcare...
Second, simply because designers use systems that are formally interpretable, that doesn't mean that designers know exactly what causes a given response in the model. Formal interpretability means you know what function the model is approximating -- there's a long way from that to a human-readable interpretation.
Finally, even if the designers can tell you what features cause a certain response in the model, they can only tell you that for features that are encoded in the data! There are plenty of features that aren't encoded in your data that can nevertheless affect the outcome of a model!
I don't know much about ML. Are you saying that we don't know how to interpret any ML models at all?
Regarding your final point, isn't that true with or without ML? Any mission-critical design process should scrutinize the solution to see if it's complete enough and correct enough.
Deep learning models are black box models, which means they are not formally interpretable. You can still sometimes get interpretations out of these models using various methods, but they are fairly underdeveloped, and without actual theories of neural network behavior I don't see that improving anytime soon.
You're right, it's true with or without ML. In fact, it's true with human-run systems, too. Consider a police officer who is more likely to pull people over in a certain neighborhood, and that neighborhood was 95% AfAm. IF they were asked why they pulled over more people in that neighborhood, they could say they were discriminating against the neighborhood, which, in and of itself is not racial discrimination. Of course, further inspection of that police officer's records could show that they are biased towards neighborhoods with a high AfAm population, which would be racial discrimination.
The same scenario can easily arise in an ML context, but interrogating a machine is a very different context from interrogating a human. First of all, people believe that computers are innately 'unbiased' because they are computers, so making the case that an algorithm is biased is already more difficult. Second, going back to the point I made before -- interpreting a model is not the same as providing a human-readable explanation. Asking a question about racial bias in a model which doesn't even encode for race (as many do, in an ill-conceived attempt to be 'neutral') requires skilled people to understand how to ask the question and how to interpret the answer. There's no plug and play process that one can follow to "scrutinize the solution to see if it's complete enough and correct enough".
This is how it functions at first.
Fast forward a few decades and you'll have doctors saying "The computer model flagged this spot as a concern. Our human review can't find anything, but we know that studies show the computer model has a 95% confidence in locating problems so we recommend surgery anyway. Surgery is lower risk than assuming the model is wrong."
Tool dependency changes over time.
Judges cannot just sign off on warrants and sentencing just because "the computer says so", for all we know the computer may be programmed to say "poor and non-comformist = guilty" or some other nonsense, and/or reprogrammed after every election. We need to be able to trust this stuff.
Is there any source that confirms the belief about judges deciding based on computer output in the past or in the future - relevant cases, law, etc?
First the Sheriff’s Office generates lists of people it considers likely to break the law, based on arrest histories, unspecified intelligence and arbitrary decisions by police analysts.
Then it sends deputies to find and interrogate anyone whose name appears, often without probable cause, a search warrant or evidence of a specific crime.
They swarm homes in the middle of the night, waking families and embarrassing people in front of their neighbors. They write tickets for missing mailbox numbers and overgrown grass, saddling residents with court dates and fines. They come again and again, making arrests for any reason they can.
One former deputy described the directive like this: “Make their lives miserable until they move or sue.”
It seems that police departments are happy to buy tools for stuff like this, and private companies are happy to make a buck. But are these systems vetted by anyone on behalf of the public? Some like sting rays and breathalyzers have been hidden behind non-disclosure agreements, kept out of open court, etc.
Other than the above I've also heard of computer systems in NJ advising judges whether a suspect is a risk of not appearing in court (as they are reforming the bail system). I wondered if the criteria is published, how it reviewed and modified, etc.
I'm just concerned about the increasing influence of hidden algorithms on our society, and very concerned in general that the government is going to hook all of its databases together and do more of this, a la Chinese social scores, etc.
[0] https://www.techdirt.com/articles/20200907/12212945257/flori...
Are you speaking from experience or from intuition?
We are not talking about black box models here. "Phones that pinged near the Capitol" is a very specific query. They want to identify those who trespassed and those who aided the trespassers. I believe it's pretty fair.
Getting a list of suspects is rarely a problem for law enforcement; the difficulty is in winnowing it down to the actual culprits. When a body is found, for example, family and acquaintances are all initially suspects, and experience has shown that summarily dismissing any of them, merely on intuitive grounds, will eliminate some fraction of actual culprits.
If a system did start suspecting the actual culprits with a significantly higher success rate than people achieve, there would be much reason to reverse-engineer the process in order to figure out how this was accomplished, as doing so would provide clues (and, ultimately, evidence) that otherwise could only be found by an independent process.
This assumes that due process exists, such that unsupported accusations are not taken as evidence, but if due process has been abandoned, we would have a much greater problem than that posited here.
No. They will come up with some fancy sounding term to describe these situations. Some experts will agree this is a sound method and it will be used to get warrants.
They will just put the cause as "suspect by unattended abnormalities" (aka phone not used during crime)
Everybody will smile. Warrants will be made. Life's turned up side down. And likely false arrest and convictions.
Even if we program rules into th3 AI to avoid this there is a real chance that the AI could work around and add people to thr list that it suspects is involved in one crime but could not list thr suspect do to rules, but a new crime opened a way for it to allow a suspect of crime one to br listed on crime 2.
Law enforcement doesn't want a system that incorrectly flags hundreds of people, unlike what some people seem to think. They want systems that reliably flag potential suspects, because that reduces work in stead of increasing it.
However, there is a long history of wrongful convictions and police and prosecutors using bad data to get them. Check out the Central Park Five for a big name one.
Precision data gives them convictions and convictions give them promotions. As they say, any metric that becomes a target... This is why giving the police invasive surveillance tech is a terrible idea, they will only focus on the data that fits their narrative and discard the rest. The defense doesn't even need to know that any other data exists.
If your system produces data points with 8 significant digits of wrong data, we have two problems: the system and whoever approved the purchase.
Any convictions will have to be corroborated by other evidence.