False 911 Calls Increase During Festival as iOS Mistakes Dancing for Car Crashes
gizmodo.com
gizmodo.com
The sensor fusion algorithms get confused by this, and the phone decides to call 911. It displays a notification for 10 seconds, then it starts a further 10 second countdown where it buzzes at maximum power and plays a siren noise at maximum volume. Under normal circumstances a reasonable person would notice these very loud alerts, and cancel the call. In a festival scenario where the users are deafened by other noises and possibly drunk/high, you might not notice. The phone then makes a call to 911.
How would you alternatively design a system that calls emergency services in a crash? Where would you personally choose to calibrate the false positive/false negative rate? These are hard design choices, and there will always be incorrect detections with any automated system like this.
I'd put it in the car. Make it use the same sensor as airbag deployment.
I'm pretty sure that this iPhone feature has and will save lives, and it may also risk them due to resource mismanagement.
I think this may be another job for Bayes. Apple's algorithm may be very accurate at detecting car crashes when there are car crashes, but most of the time there are not car crashes. As a result it may actually be super inaccurate at the 'population' level. So while it may have the reach, the incidence of false positives and the infrastructure misallocation may yield worse outcomes than not having the system in the first place.
Definitely. I think it is difficult to assess the scale of the issue here without any raw numbers. In terms of resource allocation, this quote in the article seems to suggest that they weren't so stretched thin that they had any issues.
>Our employees really stepped up, as first responders always do really step up in the line of duty and they did. And we didn’t have any situation where we couldn’t help someone because of the amount of calls.
A good individual idea not always turns out to be great when taken at a population level
"Apple will have to make the calculation actual lives saved vs. useless dispatches"
The personal phone is the best place to fit this feature because it already has cellular communications and can work in any mode of transportation.
Make a USB cigarette lighter charger which also has crash sensors that the phone can use.
(and/or put them in dashcams)
(or aftermarket stereo/infotainment systems)
https://en.wikipedia.org/wiki/ECall
And many modern cars have it as well in the USA. My BMW has it.
iPhones do have approximate location available at all times, via wi-fi scanning/databases and tower ~triangulation. This wouldn't be good enough to infer any sort of acute acceleration/deceleration.
All of that said, none of it helps if you were sitting at a red light for 3 minutes before being rear-ended.
This is, all told, a fairly useful feature that has historically been accomplished only with dedicated hardware.
Such that I'm surprised at all of the indignation here. I remember when the watch came out, that there were many stories on how it had helped folks. Seems a straight line from those to false positives. There are probably also false negatives, such that the feature has work to do in both directions.
Put another way; if an emergency team arrives late to another accident because they were tied up on a false positive from an iphone and that results in less effective care, what happens? Do we just front the bill for more emergency workers? Do we hold apple accountable for false positives? Do we hold the user accountable for false positives (I guarantee most people are gonna start turning it off then).
Seems like emergency response centers are a little mixed in how they feel about the feature. But this last point is especially important as to why false positives are pretty irresponsible.
"An automated call from Crash Detection could cost responders as much as $10,000, and they have a limited budget."
https://appleinsider.com/articles/23/01/09/apple-crash-detec...
Again, they should improve it. And reporting and asking for changes makes sense. The disdain on this post is baffling to me, though. You don't have to search hard to find cases of this feature providing tangible help to people.
If you have solid data showing that it is overwhelming places, that changes things. So far, it has not been reported to be doing that.
I know you mean well, but if this is that hard for you to understand then you aren't even trying to consider responders' wasted time or effort. Until the majority of automated calls are verifiable emergencies, this is adding more noise than signal. The handful of times it gets it right puts it a step above a broken clock in terms of usefulness. For what response costs in human capital, it needs to do better than occasionally getting it right. "If it saves one life..." isn't good enough when you're driving responders to apathy and exhaustion; others will suffer from their lack of attention.
Really, welfare checks borne from vaguely-substantiated malfunctions are a job for friends, not emergency services.
For one, you haven't established that the majority are not verifiable emergencies. You are asserting that it can't possibly be the case that this is providing real value, as it is.
You also have not established that it causes a substantial increase in costs for most municipalities. Again, quoting how much a search and rescue can cost up to, in a place with many ski resorts, does little to actually convince me of good faith discussions here.
For places that have a convention or festival, I can already assume that they will have an increase in everything because of that. Per this very story, they were emphatically not overwhelmed. It was an increase, and is notable such that it is best if it is addressed.
But I see very little ways of framing the doom and gloom posts here other than FUD.
The cost of a false negative could be a life.
Improved protocols and better algorithms from Apple will probably help tremendously with false positives.
Plus, there are pedestrians, cyclists, motorcyclists, etc., who can crash.
Most crashes have at least one car involved.
Was it common before to get in a serious accident but nobody calls 911?
If a call goes through when there was a legitimate accident, do the 911 operators even care, or do they assume all these automated calls are false positives?
I think it's likely that this feature does more harm than good by ddosing the 911 infrastructure.
You also don't have to search too hard to see that it has, in fact, been useful. First news search I found: https://9to5mac.com/2022/04/15/police-officer-apple-watch-fa... I see no reason to think there aren't others.
I don't have a confident answer for this at all, I think it's almost entirely subjective. There are folks who would confidently say that ANY amount of mass inconvenience is worth saving one life. There are others that would confidently say the opposite. Much more thoughtful people than I have spent a long time debating the topic on LessWrong, it's a pretty rich area of discussion.
First, there are the direct costs. If false auto-calls are clogging up 911 resources, then the taxpayers need to pay for more operators and infrastructure. This money could be used to "save lives" elsewhere.
Then there are second order effects such as lowering the signal/noise ratio of 911 calls. If operators get used to ignoring the automated calls, then the feature becomes a pure cost on society with little/no benefit.
My wife went out and bought a watch the next day.
To the point where I would actually consider suppressing this feature when used at car speeds at daytime in a city, since even when correct, the report would almost always be redundant, and thus provides a low value/noise ratio.
[1]https://europa.eu/youreurope/citizens/travel/security-and-em...
It is the part of the car in some... other countries. And it works, experienced it myself.
This would require AGPS rather than just the less power-hungry IMU, but maybe that's the price for not DDOSing 911 infrastructure.
I wouldn’t - it’s not clear to me this feature is saving lives. Why not incorporate it into the car?
And that'd sell more cars not more iPhones
But, I haven’t seen a good source on how frequently the false positive trigger versus real calls where the caller was unlikely to place it themselves. I could be totally wrong.
Seems a bit excessive to me. Especially since I’m not over 80 years or or whatever.
It's already done and mandated. Why design something new?
https://europa.eu/youreurope/citizens/travel/security-and-em...
If significant motion does not stop shortly after a candidate crash is identified then reject the candidate as a false positive.
Maybe also listen for voices. If you can detect people talking and they seem to be reasonably coherent that suggests that even if there was a crash there are people on site already who can take care of summoning emergency services if needed.
Or if the phone continually collects sensor data already for this feature, I’d just make sure the second preceding the supposed crash was consistent with traveling in a vehicle, not being in the same place. It won’t work when you are hit by something though in that case.
Maybe the feature should ask the user: where do you put the phone normally? handbag, pocket; where while driving? while riding a bike? and the software would use sound, light sensors, based on the answers, etc.
Otherwise simply stop this feature, since it is more trouble than it is worth it.
Worst case is real human calls start getting ignored or the response is delayed because of the noise of all these fake calls. This is a serious public safety issue, and it should not be up to a company to decide if they collapse it to sell more phones.
Pretty easy to filter all the car crashes coming from a grassy lawn somewhere.
If you want to prevent false positives—then, same as you’ve described, but only enable when either:
- phone is connected to Carplay via USB or bluetooth
- phone is connected to a bluetooth device known to be an auto (inferred by manufacturer ID, and configurable in bluetooth settings)
- GPS data for the last 5 minutes indicate you’re driving
And display an indicator on lockscreen that shows this feature is enabled.
Of course, consider that the downside of false positives don’t affect consumers or manufacturers—rather, they affect public utilities. Then, it’s easy to understand why this happens.
If it were g-forces alone that are confusing the phone there might be more stories about fall detection rather than just car crash detection. Even though the age cohort at festivals might be less likely to explicitly enable fall detection, I think it’s a default setting.
Really, this is effectively criminal under the statute iiuc
Keep state for a longer period of time.
Activate when you start driving and deactivate when parking.
Start could be triggered by gps detecting movement over longer period of time over roads.
That would avoid festival where you're stationary in a place where cars arent allowed.
Problem here is solved.
But when you are famous, they just let you do it.
That is, be careful not to strawman this such that they can't have any false positives. Do keep on them to make it ever better, of course.
If dancing can make an iphone call 911, then Apple has not done their job. You cannot achieve g-forces dancing anywhere close to a serious crash. This is pathetic and unacceptable.
You absolutely can, remember, the phone is recording the accelerations of the phone, not the acceleration of your brain or car or anything heavy.
did you just make up that fact?
https://www.bernards.cz/news/irish-dancers-get-pilot-g-force...
A 30mph car crash into a solid obstacle spikes at 30G https://www.jrlawfirm.com/blog/auto-accidents/car-accident-g...
Race car drivers have walked away from g-force as high as 78G https://www.essentiallysports.com/f1-news-from-max-verstappe...
We’re talking an order of magnitude here. Algorithms should be able to tell the difference.
are we sure it's enough to excuse the failed crash detection described in the article (IE do we know the bouncing around generates multiple tens of Gs like an accident)?
without such a confirmation, the error is still inexcused
with it, the error seems like the feature is just poorly implemented or perhaps even poorly thought out
The alert said: “You had a hard fall and stopped moving. Press this button or we call help”
The “stopped moving” part seems like the perfect proxy here. People in a car crash experience a huge spike in G-force once. Then it stops. Or maybe it goes for a few seconds if you’re rolling down the highway.
Car crashes don’t go on for minutes upon minutes. This seems like something a machine learning algorithm could handle. At the cost of calling 911 3min after a crash instead of 3sec. That’s still much faster than how long it takes people to call for help.
https://www.researchgate.net/figure/Thresholds-g-forces-for-...
I believe 4.5gs would be like a 9-10mph crash.
There are wildly different G-forces involved.
https://www.researchgate.net/figure/Thresholds-g-forces-for-...
My assumption is that they want to trigger the alarm even for mild accidents.
Note that the Gs experienced by the dancers in my previously shared article approach the threshold for a mild accident. I wonder how they conducted the experiment, and if a phone held in a person's hand while they are dancing might experience even more Gs than the person's body.
edit: I think 4.5gs is equal to a 9-10mph crash.
"A concussion occurs at roughly 90 to 100 g-force, which equates to smashing your skull against a wall at 20 mph" - https://news.umich.edu/football-helmet-sensors-help-research...
These comments are making it quite clear why stuff like this makes it to production.
https://www.researchgate.net/figure/Thresholds-g-forces-for-...
90-100g is a pretty extreme amount of force.
And it isn't impossible to say how many were negatively affected, all told. It is hard in the moment, of course, but you can pull that signal out.
Again, they should work to fix this. But don't ignore the benefits of the feature, as well.
Edit: I also wouldn't be shocked to know that most of the dancing causing false reports were people dropping their phones. That will look a lot like a crash, for obvious reasons.
Edit2: For the "difficulty determining the impact," it is worth noting that they specifically callout that they were not overwhelmed, such that there is no reason to think this caused specific issues.
It leverages the GPS, microphone, barometer, Bluetooth, Carplay status, accelerometer, and gyroscope in a sensor fusion.
The actual setting for the apple watch calls it a "severe crash" and has triggered for people crashing bicycles and things. There's also a separate "fall detection" setting that will call after a hard fall if you're not moving.
I'm fine investigating. And reporting on a lot of this is fine, of course. But this very story says it did not overwhelm them, such that they were getting utilized. Probably net good for training, overall. As it let them practice runbooks that may not get a lot of use.
We have a piss-poor track record of holding 'job creators' accountable for direct harm to our communities, let alone two-steps removed indirect harm.
Where do you see that they rushed it?
It's crazy what large tech companies are allowed to do with public infrastructure. I bet you an app from a small developer would get cease and desisted within a month if it had false positives like these. At least put some of your own operators on the line first so you can verify that the emergency services are actually needed, and maybe don't even roll out the feature in areas that don't opt into receiving these automated alerts.
That feature is identical to iPhone's SOS call feature, but I think it has gotten recent coverage for false positives. I don't recall hearing that Apple's implementation has had the same level of false positives.
In this most recent situation it is crash detection, which I -think- Android also has, or at least Pixel phones do, but I don't know if they've had false positive problems.
Yes, Pixel launched the feature on 2019. I didn't really find articles about false positives, but that's not at all empirical.
The automatic speed and G force detection mechanism has completely different false positives from a button being pressed. Both can happen on accident, of course.
I don't really understand how the Android feature gets triggered by accident; my best guess is that the power button is resting against something and getting fake touches that would otherwise just launch the camera (the standard double power button tap on Android). The BBC article doesn't explain how this happens.
I mean realistically unless you have a clear visual of the crash it's going to be very hard to tell a car crash from a loud noise + movement alone.
Really they should be asking you if you want to enable "crash detection" before setting off and it should remain disabled at all other times. If you can already ensure the user is in a car and then the phone happens to sense something like a crash then chances are much greater that it's actually a crash.
The G-forces in a crash are much higher than dancing.
Other implementations are better.
I carry an iPhone when I go biking, and I have a Garmin GPS. The Garmin crash detection works far better. The Garmin is tuned well enough to go off on a real crash mountain biking but won't go off if you have an accident that's not a full fall.
I have had a very "real" crash and seen the Garmin correctly identify it and the iPhone does not.
Apple currently checks your location periodically, so it can fulfill location-based reminder requests, so I honestly figured a similar tech was used for the crash detection. I’m pretty surprised that that’s not the case.
GPS positioning at least used to be power-hungry, to the point it couldn't be run continuously. I'm not sure if that's still the case, but it could be a factor.
That excludes most human only activities. Of course roller-coasters and various other rides could still trigger it.
Security alarms require obtaining an alarm permit. Automated alarms notify the alarm company who call the customer. They ask if help is needed and what their security code is. If the customer says an actual emergency happened they then call 911. In my jurisdiction more than three false alarms results in a fine for the resident/business.
The police generally don't respond to an alarm signal unless a person on site calls it in. Although once in the 1990s someone at work didn't know the burglar alarm keypad code and the police did eventually respond with guns drawn. That was a hair raising experience.
This is much more like a fire alarm, which does trigger an automatic response.
In my view, we should be more lenient with false alarms when it could save someones life, compared to stopping theft.
If you've been standing in a field for the last 40 minutes, and haven't traveled more than 10 meters at a slow pace, and are surrounded by hundreds of other iphones that also have barely moved, you probably aren't suddenly in the middle of a car crash.
I would also think it's pretty easy to dismiss on the 911 operator side. Hey reported car crash. Oh wait, the location is in the middle of a dance club. Guess it's just another false positive.
Maybe a difference is that people in the pit are more likely to have phone in pocket, whereas dancers are more likely to be holding phone in hand (cuz generally more likely to want it at the ready for selfies, etc?). I imagine that a phone’s accelerometer, when at the end of a moment arm (or literal arm in this scenario), is going to have a wilder experience than when held closer to the center of mass.
I could see how "negative" g forces could lead to a false positive but I think the absolute forces are too low.
On the other hand I could see how during dancing the phone gets thrown around and that may be a similar pattern to a car crash.
I suppose that a regular crash but with a lucky ending can do a significant damage to phone in the pocket, because while the body is losing speed slowly, the phone and other things in pocket can hit the road hardly and ricochet with insane acceleration. I am a fan of downhill but I never carry my phone during that kind of ride when I am acknowledged about high chances of my crash. And in that risky kind of event I would rather go bombing the hill with a friend who can give me a proper help than rely on some computer.
This happened day 1 (Thursday) of a 4-day festival. Even though they declined to have Apple come out you know they still sent a couple engineers out to gather data regardless.
On top of that, being proactive once it started happening and getting messaging out to attendees helped cut down the calls by ~50%, which definitely helped.
All you can do is continually refine it once you deploy it. A bit damned if you do, damned if you don't.
you could also get it to work with fewer false positives before deploying it, so more like damned if you do rush to market without proper testing and not-damned if you're thoughtful and do minimal testing first (which would obviously include dancing)
or, alternatively, just don't deploy and keep deployed a feature which fails so often and for which failures have such a significant impact on people
I'm sure they did.
this means they either didn't get it to work with fewer false positives than it has, or they did, then they discarded those improvements, leading to the inadequate release we have now (in which, again, the amount of false positives is too many)
we can't define what "the amount it needs" is, and we don't know what Apple's definition of "the amount it needs" is. So this is ultimately a fruitless argument.
speak for yourself: perhaps you can't define it, if you want to admit so.
I can do so, easily: the amount it needs is an amount low enough to not prompt complaints from first responders.
In fact, that's the primary requirement. Doing fancy detection of whatever only comes when you know you aren't butt dialing paramedics and wasting their time.
Sorry, you can't push that negative externality onto society just for a neat slide at WWDC. Denied.
Great, you then deferred your meaning to another nebulous amount that is again, not defined. Maybe if you were willing to research and derive the current amount of false positives received, and if that threshold is acceptable as is, Id agree.
Otherwise: Maybe you consider mind reading as "easy" and I congratulate you on your talents. In the meantime I'll simply not assume what thresholds are what in the minds of operations that I'm not familiar with.
Alternatively you may be a 911 dispatcher with the power to define this. I hope you can communicate properly with apple becsuse your current estimate isn't really quantifiable.
Feels like these automated emergency things should go into a 2nd lower priority queue if they’re so low signal to noise ratio. Else it drowns out the higher quality sig/noise actual calls
Notable that not a single story that has been reported has mentioned places getting overwhelmed with calls from this.
trash
At this point I feel like the best course of action is to back out the feature. Adding a "are you sure" button to prevent a false dialing might as well just be turning it off. Making it less sensitive - effectively the same (maybe worse if you expect to rely on it). There really isn't a fundamental way to save this without yet-more-complexity. The user's intention will be betrayed from the perspective of their device in some percent of cases. You will never be able to solve this 100%.
Now the real question is, are we comfortable with some % error rate? Probably yes. A crank call to 911 isn't like an airbag going off unprovoked or your car deciding a plastic bag floating on the freeway is good cause to engage full emergency braking.
https://support.garmin.com/en-US/?faq=RfaXahBWkH8Q7pVFLsuUmA
I have a feeling this creates more problems than they solve. A computer should never reach out to emergency calls without the user pressing something.
From what I've heard, 911 operators regularly get people calling them for non-emergencies. The 911 operator's job is to judge whether the caller is actually reporting a legitimate emergency, and if so, route the report to the correct emergency personnel (fire/police/ambulance/etc) OR disregard the report as a non-emergency.
The end of the article seems to confirm the false positives didn't actually have any real negative impact. So legitimate emergencies were not drowned out by the accidental dialing.
> Thankfully, that wasn’t enough false 911 calls to overwhelm the local system and prevent responders from dealing with real emergencies that weekend, and with the help of festival organizers, the local authorities were able to locate the source of every false 911 call to determine that no actual emergencies were being reported.
Obviously eliminating false positives would be ideal. But if the false positives aren't overloading 911 operators, seems like maybe a non-issue? Especially if these things can be predicted, e.g. local emergency personell should be aware of a local festival anyway (and can be on alert for these false positives, assuming it's not so bad as to drown out actual emergencies).
Many people have an irrational fear of dialing 911. If you do it right now, someone will pickup the phone, and if you simply say "Sorry, I didn't mean to dial!" you won't get in trouble and the 911 operator will gladly let you off the line.
It's a massive nuisance unless someone gets on to say it was a mistake...and if someone didn't notice their phone buzzing before it made the call they aren't gonna pick up.
Ideally there’d be a better system for this where 999 can be notified in a machine readable format allowing them to filter out automated calls from known sites that are generating false positives, but it’s not like the operators don’t have information to work from.
It’s also possible operators could (maybe they already can) see which mobile cell the call came from, which would also help rule out false alerts because they’d be flagged as coming from the vicinity of a festival. Generally for large events 999 are going to contact the organisers and let them know they need to send out a first aid team anyway, they’re not going to automatically despatch an ambulance without someone having confirmed the need for one.
Just fine the person for negligent abuse of the system. The problem will get solved quickly enough if your badly configured phone calls 911 and you're not communicative, so they have to send an ambulance or whatever.
I don't see a good outcome of fining this. Either the person turns off the feature and now there's a bunch of situations where it could have saved lives lost, or you charge Apple and they turn off the feature, effectively doing the same.
Or worse, because as of now every smartphone has requirements to dial emergency services, regardless of sim cards or passwords or whatnot. If it's not completely dead it can contact 911.
People can be expected to behave responsibly.
"I was going so hard that my phone thought I was dying and called an ambulance"