CAREER: Resisting Automated Algorithmic Surveillance with Human-centered Adversarial Machine Learning
CAREER: Resisting Automated Algorithmic Surveillance with Human-centered Adversarial Machine Learning
批准号:
2316287
负责人:
Sauvik Das
金额:
$59.39万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-11-01 至 2027-02-28
中文摘要
该项目研究对抗性机器学习技术,这些技术将抵制面部识别和其他形式的自动推断人们在线共享的图像中的个人身份信息。这种方法包括以人眼难以或不可能检测到的方式修改图像的方法,但这些方法可靠地降低了机器学习分类器的准确性。目前的对抗性机器学习技术确实允许最终用户干扰他们打算在线共享的图像,但迄今为止,这些技术是从以技术为中心的角度而不是以人为中心的角度开发和评估的。目前还不清楚消费者是否认为这些技术有用和实用。该项目重新设计这些技术,以提高消费者的接受度。该项目引入了以人为本的方法来设计和评估对抗性机器学习反监控技术。 与倡导组织合作,帮助那些因在线共享图像的自动监控而承受特别高风险的人群,增强拟议工作的教育和研究影响。拟议的具体活动包括创建一套标准化的措施,通过这些措施,以人为中心的对抗性机器学习的开发人员要求人类评估人员评估扰动图像的质量和可接受性。当创建标准化措施时,将创建对抗性机器学习反监视技术的人类质量评估公共存储库,并对现有系统进行评估。该项目还涉及创建一个微分损失项,以捕捉受干扰图像的美学质量。微分损失项可以用来帮助生成人类用户认为高质量的对抗性示例。对于至少一个流行的机器学习库来说,这种新的损失术语的开源实现将使其他研究人员更容易使用和建立这项工作,以创建针对自动监控的新型以人为中心的对抗性攻击。该项目还涉及使用共同设计流程来开发一种新的以人为中心的对抗性机器学习应用程序,该应用程序将允许最终用户以一种既美观又有助于规避面部识别和其他形式的自动推理的方式来修改他们选择在线共享的图像。拟议的工作还包括教育活动,如向公众开放的网络研讨会和视频讲座,并与宣传组织合作,为自动监控风险较高的人群组织,提高公众对如何保护在线共享的图像免受自动监控的认识和知识。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值进行评估,被认为值得支持和更广泛的影响审查标准。
英文摘要
This project studies adversarial machine learning technologies that will resist facial recognition and other forms of automated inferencing of personally-identifiable information in images that people share online. This approach includes methods to modify images in a manner that is difficult or impossible to detect with the human eye but that reliably reduce the accuracy of machine learning classifiers. Current adversarial machine learning techniques do allow end-users to perturb images that they intend to share online but these technologies have, to date, been developed and evaluated from a technology-centered perspective, rather than a human-centered perspective. It remains unclear whether consumers find the developed technologies useful and practical. This project re-designs these technologies to improve consumer acceptance. The project introduces a human-centered approach to designing and evaluating adversarial machine learning anti-surveillance technologies. Collaboration with advocacy organizations for populations that bear especially high risks from automated surveillance of images shared online enhance the educational and research impacts of the proposed work.The specific activities proposed involves the creation of a standardized set of measures through which developers of human-centered adversarial machine learning ask human evaluators to assess the quality and acceptability of perturbed images. When a standardized measure is created, a public repository of human quality assessments of adversarial machine learning anti-surveillance technologies will be created and seeded with evaluations of extant systems. The project also involves the creation of a differentiable-loss term that captures the aesthetic quality of adversarially perturbed images. The differentiable-loss term can be used to help generate adversarial examples that human users perceive to be high quality. An open-source implementation of this novel loss term for at least one popular machine learning library will make it easier for other researchers to use and build on this work in the creation of novel human-centered adversarial attacks against automated surveillance. The project also involves the use of co-design processes to develop a new and novel human-centered adversarial machine learning application that will allow end-users to touch-up images they choose to share online in a manner that is both aesthetically pleasing and that helps evade facial recognition and other forms of automated inferencing of personally-identifiable information. The proposed work also entails educational activities such as webinars and video lectures open to the public and organized in concert with advocacy organizations for populations at higher risk of automated surveillance, to improve public literacy and knowledge of how to protect images shared online from automated surveillance.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
The Subversive AI Acceptance Scale (SAIA-8): A Scale to Measure User Acceptance of AI-Generated, Privacy-Enhancing Image Modifications
颠覆性人工智能接受量表 (SAIA-8):衡量用户对人工智能生成的、增强隐私的图像修改的接受程度的量表
DOI:
--
发表时间:
2024
期刊:
Computer supported cooperative work CSCW
影响因子:
--
作者:
[Logas, Jacob, Garg, Poojita, Arriaga, Rosa I., Das, Sauvik]
通讯作者:
Das, Sauvik
SaTC: CORE: Small: Corporeal Cybersecurity: Improving End-User Security and Privacy with Physicalized Computing Interface
-
批准号:2316294
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2022
-
负责人:Sauvik Das
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Privacy Through Design: A Design Methodology to Promote the Creation of Privacy-Conscious Consumer AI
-
批准号:2316768
-
项目类别:Standard Grant
-
资助金额:$66.92万
-
财政年份:2022
-
负责人:Sauvik Das
-
依托单位:
CAREER: Resisting Automated Algorithmic Surveillance with Human-centered Adversarial Machine Learning
-
批准号:2144988
-
项目类别:Continuing Grant
-
资助金额:$59.39万
-
财政年份:2022
-
负责人:Sauvik Das
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Privacy Through Design: A Design Methodology to Promote the Creation of Privacy-Conscious Consumer AI
-
批准号:2126058
-
项目类别:Standard Grant
-
资助金额:$66.92万
-
财政年份:2021
-
负责人:Sauvik Das
-
依托单位:
SaTC: CORE: Small: Corporeal Cybersecurity: Improving End-User Security and Privacy with Physicalized Computing Interface
-
批准号:2029519
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2020
-
负责人:Sauvik Das
-
依托单位:
CRII: SaTC: Systems That Facilitate Cooperation and Stewardship to Improve End-User Security Behaviors
-
批准号:1755625
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2018
-
负责人:Sauvik Das
-
依托单位:
EAPSI: A Cross-Cultural Exploration and Evaluation of Group-Centric Authentication
-
批准号:1614200
-
项目类别:Fellowship Award
-
资助金额:$0.54万
-
财政年份:2016
-
负责人:Sauvik Das
-
依托单位:
海外基金