The FTC’s new enforcement weapon: “Algorithmic destruction”
protocol.com
protocol.com
I am not a data point, I do not want to be a data point, and I do not want products and services to interact with me as if I was. We humans are superior at curation, discovery, and anticipating our needs. Not AI.
Depends, I would prefer reco Algos be open source and I can plug in different ones.
Trying to make sense of the mass of data without a personalized recommendation engine is a fools errand.
<insert obligatory The Prisoner reference>
I am not a number! I am a free man!
I will not make any deals with you.
I've resigned.
I will not be pushed, filed, stamped, indexed,
briefed, debriefed, or numbered!
My life is my own!1. I think is far from established, and if anything the accumulating evidence shows the opposite (though I do hate the term AI when used like this)
2. The issue (for me, at least) is not "AI" replacing human equivalents (though in some parts of life, this is a huge issue), but rather the ease to which the AI's actual purpose and success metrics can be different from the claims made about it by its owner-operators.
It's not that this can't happen with human beings too - financial advisers who are actually lining their own pockets rather than providing you with the best advice for you. But it is much easier to hide nefarious intent inside an algorithm, and harder to discover it without access to source code (and non-trivial even then).
If nuclear weapons are superior to all weapons, no need to ban them!!
You speak as though advertising was for you.
The data being collected about you is used to sell you to advertisers, and your data to 3rd parties.
you see advertisements not because you are interested in a product, but because the seller of the product is interested in one of your characteristics (like your income, sex, weight, religious affiliation, price insensitivity, poor decision making skills, etc...)
I mean, what data is going to get extracted? Your favorite color? The app that came with mine is great and I can work the controls remotely.
Might be the wrong forum to be complaining that an app is too hard for you.
You're misconstruing the objection here. No one thinks an app is too hard. The problem I don't want my email to end up in some database because I wanted to dim my lights. I imagine it would also be able to collect info on what bluetooth devices I have in my kitchen, etc.
I have an aquarium and I use a water quality tester when I suspect something is wrong. Before it was a colour stripe you have to compare with a reference printed on a package. Now it uses a camera and matches the color better for a better analysis. However, that app calls home directly to JBL, so they are building a profile on how I abuse my fish because every time it logs, it logs a bad situation. It also leaks the usage to jquery, google and crashlytics without notifying me or asking my consent.
This is the first time I’ve read someone refer to loading jquery as a data leak.
Ideally they shouldn’t be using jquery, or just shipping it with the app/self-hosting. But for the general case, are you saying your ideal would be an app prompting you for permission before it loaded any external resource from any url? Even one as ubiquitous as jquery?
How is the fact that your IP address requested a copy of jquery, one of the most downloaded JavaScript libraries of all time, any kind of meaningful signal?
I’d be more worried about it as an attack vector than a privacy infringement.
Loading any framework script not hosted on the site the app originates is the same kind of leak as the facebook pixel. jquery gets my IP, access time and referrer. They can cross-site track me over all pages that load their scripts.
I also use frameworks scripts, only I host them locally to counter this kind of leakage.
I want to avoid the hassle because it affects me and my life. I might not be important to others, but I'm important to myself. Don't tell me to get over myself.
A dial on the wall also doesn't potentially open an IoT shaped hole in my network security.
Well probably that as well as information about every device on the same wifi network and a list of nearby bluetooth devices.
For instance, a log of every time I turn my lights on and off? Coupled with of course all kinds of fingerprinting info about my phone which is also tied to all my accounts. Others mentioned it could also scan the local network. Creepy.
So sick of apps being required for basic things. My ISP is trying to require one to admin my router...
That's an algorithm. It is not "statistical regression", even if that is the method that was used in its creation.
The whole its-just-statistics-shtick is what's getting out of hand. People are just mindlessly repeating the point because it seemed smart when it was first made. Hint: it no longer does, especially if you use it wrong.
2. Add three
3. Square the result
4. Take this result as your final number
There's an algorithm for f(x) = (7x + 3)^2. Similarly, any map from one space to another is an algorithm if it's describable on paper. Every mathematical proof is analogous to an algorithm in important ways. Math is not "equal to" algorithms, in the sense that two different algorithms can describe the same underlying math, but every description of any math essentially has to be an algorithm.
The only parts of math that would not fit would be anything non-constructible, but we know we are limited to exploring and describing only 0% of that world since our descriptions (algorithms) are countably infinite, and there are constructivists who believe non-constructible things don't exist in any meaningful sense. So, yes, most (or all) of the practice of mathematics is algorithms.
Why are we trying to gatekeep this word?
My word for algorithms that aren't closed-form functions, my life's work, is "repetigrams" because they involve repetition in the form of iteration or recursion.
Hence, math consists of things that correspond to implementations of algorithms.
I also question whether we are talking about algorithms, or the data set they are working with or the model created from that. I can forgive confusing an algorithm with its implementation (e.g. the source code), but this goes beyond that.
Its pretty clear cut tbh. An algorithm is a set of steps to follow to produce some output. A trained model is, 'hey do these matrix multiplications with these coefficients to get an output'. The fact that the exact coefficients were arrived at via backprop, doesn't make it not an algorithm.
Indeed it is - for one thing, it allows us to see that various useful theorems and results about algorithms and computability apply as much to large programs as to small ones, such as the fact that there's no fundamental impediment to porting them between computers with different instruction sets, or running them in virtual machines.
What's not so well or usefully defined here is your distinction between hard and soft computing.
> In other words, a statistical algorithm does not point to the same category as a deterministic algorithm and an algorithm refer to the later class by default.
You appear to be under the misapprehension that the set of statistical algorithms is disjoint from that of deterministic algorithms. I strongly suspect that all the algorithms covered by the article are both statistical in terms of what they compute and deterministic in terms of how they do it.
Machine learning is somewhat unique in the software world in that the actual useful artifacts are not necessarily strongly tied to the source code itself. You can have the identical source code running at two different companies, but by supplying them with two different training sets, you'll end up with very different outputs. That's what algorithmic destruction is targeted at--not even necessarily the source code or algorithm in the technical sense (you can't destroy "KMeans" or "convolution" as a concept, obviously), but both the data and the model weights that are produced through the use of that data that are used in perform a business action. Those weights are typically stored separately from the source code, and can be extremely expensive to re-create from scratch.
> The FTC’s new enforcement weapon spells death for algorithms
makes it sound like running quick-sort is a federal crime
If I have a bunch of drugs or chemicals I shouldn't have, I can give them the addresses and they can have government agents watch the destruction.
If I have an algorithm (that is just a bunch of computer files) how do I prove I destroyed it? Do they literally just watch someone run "rm banned_model.bin" and then decide it's gone? It's basically impossible to prove you don't have a copy of something. There could always be a backup at another location. There could always be an encrypted copy stored somewhere that is impossible to detect.
Any moderately well company has a service contract with a backup provider that acts an option of a last resort for restoring lost data. How do you get that provider to destroy their copy?
It's the same problem with saying "destroy that data", which is also difficult to enforce (and probably isn't), except that it's an additional level of difficulty in enforcing.
I'm not saying they don't have a point, I'm just saying I don't see how they will be able to enforce this, even with whistleblowers.
Whistleblower: "that ML model came from illegal data" Company: "No, it didn't." ...
It would help demonstrate what biases were introduced, the systems and processes that permitted/encouraged those to exist, and it would help prevent repeats of similar mistakes in future.
(it seems fair for the FTC to also be able to order companies to stop using a particular category of algorithms; that doesn't require or imply deletion, though)
[1] https://techcrunch.com/2021/03/01/facebook-illinois-class-ac...
These companies make billions off of harvesting data. They need to be shuttered entirely if they are found to be violating privacy rights.
The data they have gathered, and even possibly shared with allies also needs to be traced and deleted as well before I'd believe this isn't just fluffy optics.
These companies also regularly risk breaches of that data, which can be very very harmful when it lands in the wrong hands... It's really far beyond a time when serious moves should have been taken to eliminate this kind of behavior, and frankly I can't see any future where we can trust any company with any accurate information about us.
I've even got into the habit of filling inaccurate info into (non vital) data forms for companies that don't need to know my personal information.
We also have power to fight the private data gorge they drive...
By creating incorrect location tags, using pseudonyms and improper spellings on our names, by opting out of tracking and using additional personal privacy tools, not buying devices that serve tracking, and most of all, by not enrolling with or supporting companies that harvest personally identifiable information.
Facebook IS NOT a government entity, they never had the authority to make everyone switch over to their real names...
In order to protect our personal privacy, we need to wake up and start asserting our rights on our own, because consumer protection has been sleeping at the wheel, and even coddling these corrupt and deeply irresponsible private companies & industry control freak CEOs for way too long. Hold these companies accountable and legislate the end of this cycle of personal data abuse or it will get far far worse with every update.
Algorithms have an age old anti-enforcement weapon, called the white shoe law firm. https://www.debevoise.com/insights/publications/2020/10/thir...
Outside of that, the headline seems very accurate--algorithmic disgorgement is a very new approach (the Everalbum ruling was in early 2021), and with the Kurbo ruling, one it appears is going to be much more common moving forward. The whole area of regulating algorithmic use is pretty novel--the whole field is basically so new that agencies are still figuring out the way to go about.
I don't understand this label. Isn't this more about discovering how data is (ab)used by companies (what watchdogs are supposed to do), and less about destroying things with algorithms?
"...destroy the algorithms or AI models it built using personal information collected through its Kurbo healthy eating app from kids as young as 8 without parental permission."
and
"..forcing them to delete algorithmic systems built with ill-gotten data could become a more routine approach, one that modernizes FTC enforcement to directly affect how companies do business."
Those quotes are from the first 3 paragraphs.