Media
To Transfer or Not to Transfer: Misclassification Attacks Against Transfer Learned Text Classifiers
Transfer learning --- transferring learned knowledge --- has brought a paradigm shift in the way models are trained. The lucrative benefits of improved accuracy and reduced training time have shown promise in training models with constrained computational resources and fewer training samples. Specifically, publicly available text-based models such as GloVe and BERT that are trained on large corpus of datasets have seen ubiquitous adoption in practice. In this paper, we ask, "can transfer learning in text prediction models be exploited to perform misclassification attacks?" As our main contribution, we present novel attack techniques that utilize unintended features learnt in the teacher (public) model to generate adversarial examples for student (downstream) models. To the best of our knowledge, ours is the first work to show that transfer learning from state-of-the-art word-based and sentence-based teacher models increase the susceptibility of student models to misclassification attacks. First, we propose a novel word-score based attack algorithm for generating adversarial examples against student models trained using context-free word-level embedding model. On binary classification tasks trained using the GloVe teacher model, we achieve an average attack accuracy of 97% for the IMDB Movie Reviews and 80% for the Fake News Detection. For multi-class tasks, we divide the Newsgroup dataset into 6 and 20 classes and achieve an average attack accuracy of 75% and 41% respectively. Next, we present length-based and sentence-based misclassification attacks for the Fake News Detection task trained using a context-aware BERT model and achieve 78% and 39% attack accuracy respectively. Thus, our results motivate the need for designing training techniques that are robust to unintended feature learning, specifically for transfer learned models.
Facebook's new policy bans deepfakes from the platform
See, the new rules don't cover videos manipulated for parody or satire or those edited "solely to omit or change the order of words." The Post says it also won't lead to the removal of edited videos using "lesser forms of manipulation" -- the altered Nancy Pelosi video, for instance, was tweaked using a simple video-editing software. That said, Facebook says it could still fact check these "shallowfakes" (as disinformation researchers call them) and limit their spread in the News Feed or remove them completely if they're being run as ads. The social network explains that the approach it's taking is critical to its strategy. "If we simply removed all manipulated videos flagged by fact-checkers as false, the videos would still be available elsewhere on the internet or social media ecosystem. By leaving them up and labelling them as false, we're providing people with important information and context," its announcement reads.
r/MachineLearning - [R] Destruction of Image Steganography using Generative Adversarial Networks
Abstract: Digital image steganalysis, or the detection of image steganography, has been studied in depth for years and is driven by Advanced Persistent Threat (APT) groups', such as APT37 Reaper, utilization of steganographic techniques to transmit additional malware to perform further post-exploitation activity on a compromised host. However, many steganalysis algorithms are constrained to work with only a subset of all possible images in the wild or are known to produce a high false positive rate. This results in blocking any suspected image being an unreasonable policy. A more feasible policy is to filter suspicious images prior to reception by the host machine. However, how does one optimally filter specifically to obfuscate or remove image steganography while avoiding degradation of visual image quality in the case that detection of the image was a false positive?
AI, cloud, blockchain and beyond: Changing the financial world individually and in tandem
AI has been talked about since the very early days of computing and has attained mainstream use in recent years with the likes of Amazon's Alexa and Apple's Siri. "Just as in the last 40 years, computation has enabled us to change the way we do business and create new products, AI will help us to make better decisions," Carlos Kuchovsky, chief of technology and R&D at BBVA, tells Finextra. "We are now looking at the ways in which it can help us change the way we operate and bring value." The Bank of England has recently reported that machine learning tools are in use at two thirds of UK financial firms, with the average company using it two business areas, which is expected to double in the next three years. It may be through interoperation with cloud and blockchain technology that AI's capabilities will be fully harnessed. AI Utilisation of machine learning and artificial intelligence has become commonplace in everyday life, whether it be in search engines, music streaming services or internet shopping.