Goto

Collaborating Authors

 spoof


Spoof Diarization: "What Spoofed When" in Partially Spoofed Audio

arXiv.org Artificial Intelligence

This paper defines Spoof Diarization as a novel task in the Partial Spoof (PS) scenario. It aims to determine what spoofed when, which includes not only locating spoof regions but also clustering them according to different spoofing methods. As a pioneering study in spoof diarization, we focus on defining the task, establishing evaluation metrics, and proposing a benchmark model, namely the Countermeasure-Condition Clustering (3C) model. Utilizing this model, we first explore how to effectively train countermeasures to support spoof diarization using three labeling schemes. We then utilize spoof localization predictions to enhance the diarization performance. This first study reveals the high complexity of the task, even in restricted scenarios where only a single speaker per audio file and an oracle number of spoofing methods are considered. Our code is available at https://github.com/nii-yamagishilab/PartialSpoof.


Adversarial Robustness Guarantees for Quantum Classifiers

arXiv.org Artificial Intelligence

Despite their ever more widespread deployment throughout society, machine learning algorithms remain critically vulnerable to being spoofed by subtle adversarial tampering with their input data. The prospect of near-term quantum computers being capable of running {quantum machine learning} (QML) algorithms has therefore generated intense interest in their adversarial vulnerability. Here we show that quantum properties of QML algorithms can confer fundamental protections against such attacks, in certain scenarios guaranteeing robustness against classically-armed adversaries. We leverage tools from many-body physics to identify the quantum sources of this protection. Our results offer a theoretical underpinning of recent evidence which suggest quantum advantages in the search for adversarial robustness. In particular, we prove that quantum classifiers are: (i) protected against weak perturbations of data drawn from the trained distribution, (ii) protected against local attacks if they are insufficiently scrambling, and (iii) protected against universal adversarial attacks if they are sufficiently quantum chaotic. Our analytic results are supported by numerical evidence demonstrating the applicability of our theorems and the resulting robustness of a quantum classifier in practice. This line of inquiry constitutes a concrete pathway to advantage in QML, orthogonal to the usually sought improvements in model speed or accuracy.


Enhancing Fingerprint Image Synthesis with GANs, Diffusion Models, and Style Transfer Techniques

arXiv.org Artificial Intelligence

We present novel approaches involving generative adversarial networks and diffusion models in order to synthesize high quality, live and spoof fingerprint images while preserving features such as uniqueness and diversity. We generate live fingerprints from noise with a variety of methods, and we use image translation techniques to translate live fingerprint images to spoof. To generate different types of spoof images based on limited training data we incorporate style transfer techniques through a cycle autoencoder equipped with a Wasserstein metric along with Gradient Penalty (CycleWGAN-GP) in order to avoid mode collapse and instability. We find that when the spoof training data includes distinct spoof characteristics, it leads to improved live-to-spoof translation. We assess the diversity and realism of the generated live fingerprint images mainly through the Fr\'echet Inception Distance (FID) and the False Acceptance Rate (FAR). Our best diffusion model achieved a FID of 15.78. The comparable WGAN-GP model achieved slightly higher FID while performing better in the uniqueness assessment due to a slightly lower FAR when matched against the training data, indicating better creativity. Moreover, we give example images showing that a DDPM model clearly can generate realistic fingerprint images.


t-EER: Parameter-Free Tandem Evaluation of Countermeasures and Biometric Comparators

arXiv.org Artificial Intelligence

Presentation attack (spoofing) detection (PAD) typically operates alongside biometric verification to improve reliablity in the face of spoofing attacks. Even though the two sub-systems operate in tandem to solve the single task of reliable biometric verification, they address different detection tasks and are hence typically evaluated separately. Evidence shows that this approach is suboptimal. We introduce a new metric for the joint evaluation of PAD solutions operating in situ with biometric verification. In contrast to the tandem detection cost function proposed recently, the new tandem equal error rate (t-EER) is parameter free. The combination of two classifiers nonetheless leads to a \emph{set} of operating points at which false alarm and miss rates are equal and also dependent upon the prevalence of attacks. We therefore introduce the \emph{concurrent} t-EER, a unique operating point which is invariable to the prevalence of attacks. Using both modality (and even application) agnostic simulated scores, as well as real scores for a voice biometrics application, we demonstrate application of the t-EER to a wide range of biometric system evaluations under attack. The proposed approach is a strong candidate metric for the tandem evaluation of PAD systems and biometric comparators.


The weirdest studies of the year are revealed in the spoof 'Ig Nobel' awards - from research into the sex lives of ANCHOVIES to an experiment to explore whether there is an equal number of hairs in each nostril

Daily Mail - Science & tech

Keeping count of nostril hairs and investigating the promiscuity of anchovies may seem completely unrelated. But these studies are among 10 others to win this year's spoof'Ig Nobels', thanks to their ability to make scientists chuckle. Traditionally hosted at Harvard University, this ceremony is the 33rd of its kind, and sees genuine Nobel laureates handing out awards to lucky academics. The prize is ten trillion Zimbabwean dollars, which might sound like a huge amount, but is actually only the equivalent of 30p in the UK (40 cents in the US). MailOnline spoke with some of the wackiest prize winners of 2023.


Learning Not to Spoof

arXiv.org Artificial Intelligence

As intelligent trading agents based on reinforcement learning (RL) gain prevalence, it becomes more important to ensure that RL agents obey laws, regulations, and human behavioral expectations. There is substantial literature concerning the aversion of obvious catastrophes like crashing a helicopter or bankrupting a trading account, but little around the avoidance of subtle non-normative behavior for which there are examples, but no programmable definition. Such behavior may violate legal or regulatory, rather than physical or monetary, constraints. In this article, I consider a series of experiments in which an intelligent stock trading agent maximizes profit but may also inadvertently learn to spoof the market in which it participates. I first inject a hand-coded spoofing agent to a multi-agent market simulation and learn to recognize spoofing activity sequences. Then I replace the hand-coded spoofing trader with a simple profit-maximizing RL agent and observe that it independently discovers spoofing as the optimal strategy. Finally, I introduce a method to incorporate the recognizer as normative guide, shaping the agent's perceived rewards and altering its selected actions. The agent remains profitable while avoiding spoofing behaviors that would result in even higher profit. After presenting the empirical results, I conclude with some recommendations. The method should generalize to the reduction of any unwanted behavior for which a recognizer can be learned.


Proof-of-Learning is Currently More Broken Than You Think

arXiv.org Artificial Intelligence

Proof-of-Learning (PoL) proposes that a model owner logs training checkpoints to establish a proof of having expended the computation necessary for training. The authors of PoL forego cryptographic approaches and trade rigorous security guarantees for scalability to deep learning. They empirically argued the benefit of this approach by showing how spoofing--computing a proof for a stolen model--is as expensive as obtaining the proof honestly by training the model. However, recent work has provided a counter-example and thus has invalidated this observation. In this work we demonstrate, first, that while it is true that current PoL verification is not robust to adversaries, recent work has largely underestimated this lack of robustness. This is because existing spoofing strategies are either unreproducible or target weakened instantiations of PoL--meaning they are easily thwarted by changing hyperparameters of the verification. Instead, we introduce the first spoofing strategies that can be reproduced across different configurations of the PoL verification and can be done for a fraction of the cost of previous spoofing strategies. This is possible because we identify key vulnerabilities of PoL and systematically analyze the underlying assumptions needed for robust verification of a proof. On the theoretical side, we show how realizing these assumptions reduces to open problems in learning theory.We conclude that one cannot develop a provably robust PoL verification mechanism without further understanding of optimization in deep learning.


Never-Ending AI-Generated 'Seinfeld' Spoof Has Nearly 171,000 Followers On Twitch

#artificialintelligence

A never-ending spoof of Seinfeld generated by AI has attracted nearly 171,000 followers on Twitch. The stream, which first aired on December 14, has been playing non-stop ever since and is almost entirely generated by algorithms. It's titled Nothing, Forever, a reference to the '90s sitcom being the so-called "show about nothing." Created by Skyler Hartle and Brian Habersberger, the show uses a combination of machine learning, generative algorithms and cloud services to create a Seinfeld parody, using OpenAI's GPT-3 language model. Nothing, Forever features animated versions of the main Seinfeld cast, including Jerry, Elaine, George and Kramer, but with dialogue that often doesn't make sense, characters who wander off aimlessly, and a badly-timed laugh track. Speaking about the project to Vice, Hartle said: "The actual impetus for this was it originally started its life as this weird, very, off-center kind of nonsensical, surreal art project.


'Nothing, Forever,' an AI 'Seinfeld' spoof, is the next 'Twitch Plays Pokรฉmon' โ€ข TechCrunch

#artificialintelligence

"So, I was at the store the other day, and as I'm checking out, the cashier asks me if I have any coupons, and I say, 'No coupon problem!'" recalls a pixelated, barely three-dimensional figure that vaguely resembles Jerry Seinfeld. "So I'm walking down the street, and this guy comes up to me and says, 'Hey, how's it going?' and I say, 'It's going coupon!'" An automated laugh track plays, but the joke doesn't make sense. Then again, it doesn't have to make sense. "Nothing, Forever" is a never-ending, AI-generated spoof of "Seinfeld," the show about nothing.


AI can spot biometric spoofing attacks with ease - Help Net Security

#artificialintelligence

Humans have far greater difficulty identifying images of biometric spoofing attacks compared to computers performing the same task, according to research released by ID R&D. The research report finds that computers are more adept than people at accurately and quickly determining whether a photo is of an actual, live person versus a presentation attack. Fraudsters attempt to imitate real customers during processes such as creating a new bank account or logging into an existing account. Liveness detection instantly validates whether a photo, taken in real time, is of a live person. The study tested humans and machines by presenting them with the most common spoofing techniques: printed photos, videos, digital images, and 2D or 3D masks.