News: 1653217273

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Deepfake attacks can easily trick live facial recognition systems online

(2022/05/22)


In brief Miscreants can easily steal someone else's identity by tricking live facial recognition software using deepfakes, according to a new report.

Sensity AI, a startup focused on tackling identity fraud, carried out [1]a series of pretend attacks . Engineers scanned the image of someone from an ID card, and mapped their likeness onto another person's face. Sensity then tested whether they could breach live facial recognition systems by tricking them into believing the pretend attacker is a real user.

So-called "liveness tests" try to authenticate identities in real-time, relying on images or video streams from cameras like face recognition used to unlock mobile phones, for example. Nine out of ten vendors failed Sensity's live deepfake attacks.

[2]

Sensity did not name the companies susceptible to the deepfake attacks. "We told them 'look you're vulnerable to this kind of attack,' and they said 'we do not care,'" Francesco Cavalli, Sensity's chief operating officer, [3]told The Verge. "We decided to publish it because we think, at a corporate level and in general, the public should be aware of these threats."

[4]

[5]

Liveness tests are risky, especially if banks or [6]the American tax authorities , for example, use them for automated biometric authentication. These attacks, however, aren't always easy to carry out. Sensity mentioned needing a specialized phone to hijack mobile cameras and injecting pre-made deepfake models in its report.

PyTorch developers can train AI models on their own Apple laptops soon

Newer versions of Apple's computers contain custom-made GPUs, but PyTorch developers haven't been able to utilize the hardware's power when training machine learning models.

That will change, however, with the upcoming PyTorch v1.12 release. "In collaboration with the Metal engineering team at Apple, we are excited to announce support for GPU-accelerated PyTorch training on Mac," the PyTorch community [7]announced in a blog post this week.

"Until now, PyTorch training on Mac only leveraged the CPU, but with the upcoming PyTorch v1.12 release, developers and researchers can take advantage of Apple silicon GPUs for significantly faster model training." The new release means Mac users will be able to train neural networks on their own devices without having to fork out to rent computational resources via cloud computing services.

[8]

The newest PyTorch v1.12 is expected to be released "sometime in the second half of June," a spokesperson told The Register .

Apple's GPUs are more optimized for training machine learning models than its CPUs, making it easier to train larger models more quickly.

Fake data for medical models

US health insurance provider Anthem is working with Google Cloud to build a synthetic data pipeline for machine learning models.

Up to to two petabytes of fake data, mimicking medical records and healthcare claims, will be generated by folks over at the Chocolate Factory. These synthetic datasets will be used to train AI algorithms that can better detect cases of fraud, and pose less of a security risk than collecting real data from patients.

[9]US cops kick back against facial recognition bans

[10]OpenAI's DALL·E 2 generates AI images that are sometimes biased or NSFW

[11]AI helps scientists design novel plastic-eating enzyme

[12]Google Docs' AI-powered inclusive writing auto-correct now under fire

The models will eventually analyze real data, and could, for example, look out for fraudulent claims filed by people by automatically checking their health records. "More and more… synthetic data is going to overtake and be the way people do AI in the future," Anil Bhatt, Anthem's chief information officer, [13]told the Wall Street Journal .

Using fake data avoids privacy issues and could reduce bias too. But these artificial samples don't always work in every machine learning application, experts [14]previously told The Register.

"Synthetic data models, in our opinion, will ultimately fuel the promise of what big data can deliver," said Chris Sakalosky, managing director, US Healthcare & Life Science at Google Cloud. "We think that's actually what will set this industry forward."

Ex-Apple AI director leaves for DeepMind

A former director of machine learning at Apple, who reportedly resigned over the company's return-to-work policy, is moving to work at DeepMind.

Ian Goodfellow led the iGiant's secretive "Special Projects Group," helping to develop its self-driving car software. It was [15]previously reported he left after Apple asked employees to return to the office three days a week starting May 23. The policy has now been delayed due to a rise in COVID cases.

[16]

He will go on to join DeepMind, [17]according to Bloomberg. Interestingly, Goodfellow will reportedly be employed as an "individual contributor" by the UK-headquartered research lab. He is best known for inventing generative adversarial networks, a type of neural network often used to produce AI-generated images, and for helping write the popular Deep Learning textbook published in 2015.

Goodfellow was a director at Apple for over three years, and previously held positions as an AI researcher at Google and OpenAI. ®

Get our [18]Tech Resources



[1] https://sensity.ai/blog/deepfake-detection/deepfakes-vs-kyc-biometric-verification/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YopeI824-7PobwXKlRcS6QAAAMI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theverge.com/2022/5/18/23092964/deepfake-attack-facial-recognition-liveness-test-banks-sensity-report

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YopeI824-7PobwXKlRcS6QAAAMI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YopeI824-7PobwXKlRcS6QAAAMI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/02/23/irs_facial_deletion/

[7] https://pytorch.org/blog/introducing-accelerated-pytorch-training-on-mac/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YopeI824-7PobwXKlRcS6QAAAMI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/05/16/in_brief_ai/

[10] https://www.theregister.com/2022/05/08/in_brief_ai/

[11] https://www.theregister.com/2022/05/02/ai_in_brief/

[12] https://www.theregister.com/2022/04/25/the_latest_automated_ai_writing/

[13] https://www.wsj.com/articles/anthem-looks-to-fuel-ai-efforts-with-petabytes-of-synthetic-data-11652781602

[14] https://www.theregister.com/2022/04/18/fake_ai_data/

[15] https://www.theregister.com/2022/05/16/in_brief_ai/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YopeI824-7PobwXKlRcS6QAAAMI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.bloomberg.com/news/articles/2022-05-17/ian-goodfellow-former-apple-director-of-machine-learning-to-join-deepmind

[18] https://whitepapers.theregister.com/



Artificial Mimickry

cyberdemon

Honestly I think the term "AI" should be banned. It misleads the public into thinking that there is some kind of intelligence in the machine.

But as anyone with a clue knows, these systems are nothing more than statistical regression. (multi-dimensional statistical regression yes, with lots of fancy optimisation over an enormous dataset to make it good)

But fundamentally, all they do is try to copy and extrapolate decisions made by actual intelligent beings (humans) based on a big pile of data that represents (what are assumed to be) correct decisions.

There is no logic behind them. So-called "AI" does not have the power to form IF/THEN/ELSE logical constructs, because it has no cognition . It is simply a guessing machine, and they should be called that: Guessing machines.

Sure, you could take ten thousand real humans and have them do a hundred thousand Turing Tests, 50% against each other, and 50% against deep-fakes, and try to make a turing tester machine.

It might (initially) perform very well. But it would still be a guessing machine. One of the humans might have said that she caught out the deep fake because it made some statement that wasn't logically consistent with her question. Even if she could input her insight into the analysis, how does an LSTM-RNN solve for that? All it can do is say that "this subject looks somewhat like some of the deepfakes" and it is dead-easy to make a new deepfake that fools it.

Re: Artificial Mimickry

cyberdemon

> and it is dead-easy to make a new deepfake that fools it.

And I will add: At that point it becomes just an endless arms race, where the only way to get ahead is to collect and analyse more and more data, from every human being on the planet, just to make better fakes and better fake-spotters, and better fakes...

Until the only way to prove that you are human is to authenticate with your cryptographically-secure Human ID issued to you at birth (which may be rescinded at any time for naughtiness, at which point you would be considered a fake by the machines).

And at that point we will have stepped into George Orwell's most famous dystopia.

Please authenticate as Human before you can watch your "Sky Glass" Telescreen. (It is still watching you and it already knows exactly who you are, but you must authenticate anyway, in case you have been replaced by a fake)

Oops, ID check failed. See you in Room 101

Re: Artificial Mimickry

Martin Gregorie

Correct. All "AI" means at present is 'Pattern Matcher': some device or program that can report a result as 'matches requirement', 'doesn't match requirement', or more rarely 'similar to required answer' and cannot explain how it arrived at the answer it provided.

As a result, the "AI" tag is essentially meaningless.

The 'Artificial Intelligence' designation should only be applied to systems that CAN give a meaningful explanation of why they came to a particular conclusion or recommended a procedure to be carried out,

However, fat chance of THAT ever happening thanks to the money being made by selling the current fallible pattern matching systems to the gullible as 'AI' or, worse, claiming them to be reliable ways to give definitive answers that affect people or control autonomous vehicles, factories, et al.

Re: Artificial Mimickry

Anonymous Coward

The 'Artificial Intelligence' designation should only be applied to systems that CAN give a meaningful explanation of why they came to a particular conclusion or recommended a procedure to be carried out.

Easy there, buddy. More than 70% of global population CAN'T give a meaningful explanation of why they came to a particular conclusion.

Re: Artificial Mimickry

ThatOne

> Honestly I think the term "AI" should be banned. It misleads the public into thinking that there is some kind of intelligence in the machine.

Agree, but in this specific case one should also ban "facial recognition" and other biometrics software from holding any important (much less critical) role.

Biometrics are not a secure way to determine it is you and nobody else. All right, it might spot that you were supposed to be a little old lady and not a young 7 foot bearded guy, but even then, if the guy puts a picture of you in front of his face he's in. Even if the rest of him is still pretty much "not you".

But well, it's a lost battle: Biometrics are "cool", extremely easy to use, very cheap to implement, and as the article states, "We told them 'look you're vulnerable to this kind of attack,' and they said 'we do not care,'". Sure, why would they? It's cool , man! The suckers love it , because it relieves them from making any effort, it's not like you can forget your face.

Now obviously someone will jump in to point out that what's the difference between using "123456" as a password or using your face? Well, the difference is that in the first case *I* can chose to use a more secure password, while in the second case I can't chose a more secure face. Simple.

Re: Artificial Mimickry

Tom 7

As someone who has had his face rearranged by a pavement after a few drinks and know a few people who have had facial injuries through car accidents and muggings I'd be disinclined to use facial recognition for anything more important than a piece of paper.

Re: Artificial Mimickry

cyberdemon

"AI" based authentication is also a great way to embed deniable backdoors in all kinds of software, as reported in an [1]earlier reg article

[1] https://www.google.com/amp/s/www.theregister.com/AMP/2021/05/05/ai_backdoors/

Re: Artificial Mimickry

Alumoi

Ever heard of plastic surgery?

Re: Artificial Mimickry

vtcodger

"Artificial Stupidity" might well be more accurate, but I guarantee you that the Artificial Stupidity label will never make it past the folks in marketing. At least not until they are replaced by AI agents.

The Shaman was Right

vtcodger

Those damn camera thingees can in fact steal -- if not your soul -- your wealth.

BTW, anyone remember the Mythbuster's successful attack on fingerprint scanners https://en.wikipedia.org/wiki/MythBusters_%282006_season%29#Fingerprint_Lock? My guess is that fooling facial recognition is going to be easier than fooling a fingerprint sensor. At least for the forseeable future.

And it's not like many, probably most, smartphone users haven't cleverly posted pictures of their face online.

Ah say, son, you're about as sharp as a bowlin' ball.