跳到主内容
@wquguru
精选70Hacker News Best(web_list)行业动态

AI可穿戴设备监控泛滥,反制技术如何应对

AI可穿戴设备全面监控,如何反制?

原文
发到 X

Listen−1.0x+

收听 1.0x+

Seek

快进

0:0010:02

0:0010:02

Anthony “Bingy” Arillotta waited years to become a made man in the Genovese crime family, and when at last the call came in August 2003, he followed directions to the letter. According to sworn testimony, Arillotta was summoned to a steak house in the Bronx, where he was made to hand over his cellphone, beeper, and jewelry before being driven to an apartment building. When he got there, he was taken to a small bathroom and strip-searched for electronic devices. For his big meeting with the boss, he was given a bathrobe to wear.

安东尼·“宾吉”·阿利洛塔等待多年,才成为杰诺维塞犯罪家族的一名正式成员。当2003年8月那个电话终于打来时,他严格遵照指示行事。根据宣誓证词,阿利洛塔被召到布朗克斯区的一家牛排馆,在那里他被迫交出了手机、寻呼机和珠宝,然后被开车送到一栋公寓楼。到达后,他被带进一个小浴室,并被脱衣搜查电子设备。为了与老板的重要会面,他得到了一件浴袍穿。

Until recently, only spies and criminals had to worry this obsessively about their private statements being picked up by electronic equipment. But soon, the average person might need to deploy surveillance countermeasures. The next time you conduct a delicate bit of office diplomacy or share a romantic or financial secret with a friend over drinks, a sensor built into someone’s glasses, necklace, or lapel pin might be watching you and listening.

直到最近,只有间谍和罪犯才需要如此过度担心他们的私人言论被电子设备窃听。但很快,普通人可能也需要部署反监控措施。下次你进行微妙的办公室外交,或与朋友在喝酒时分享浪漫或财务秘密时,某人眼镜、项链或领带夹上内置的传感器可能正在看着你、听着你。

In March, the tech start-up Deveillance announced the development of Spectre I, a hockey-puck-shaped device that purports to prevent others from recording you (no strip search required). The company was founded by Aida Baradari, a recent college graduate who was worried by the surge in people wearing AI-enabled recorders. These wearables can be used as a silent notetaker, a personal assistant, or even a therapist of sorts. That technology isn’t yet mainstream, but it may be soon. Apple—the company with the largest personal-tech ecosystem in the world—is rumored to be developing an AI pin or pendant that would serve as an iPhone’s constant eyes and ears; many other products of this type are on the way. AI accessories could one day be as widespread as AirPods.

今年3月,科技初创公司Deveillance宣布开发了Spectre I,一种冰球形状的设备,声称可以防止他人录制你(无需脱衣搜查)。该公司由艾达·巴拉达里创立,她是一位刚毕业的大学生,对佩戴AI录音设备的人数激增感到担忧。这些可穿戴设备可以用作无声的记事本、个人助理,甚至某种心理治疗师。这项技术尚未成为主流,但可能很快就会。苹果——拥有全球最大个人科技生态系统的公司——据传正在开发一种AI别针或挂件,作为iPhone的持续眼睛和耳朵;许多其他此类产品也即将问世。AI配件有一天可能会像AirPods一样普及。

New surveillance technologies tend to breed new countermeasures, which lead, in turn, to more sophisticated surveillance. During the Second World War, after Germany operationalized radar, the Royal Air Force began dropping thin strips of metallized paper cut to a specific size that resonated with the radar, swamping German screens with phantom echoes that were indistinguishable from real aircraft. Some historians have argued that the ensuing radar arms race was more consequential to the war’s outcome than the Manhattan Project.

新的监控技术往往会催生新的反制措施,进而又导致更复杂的监控。第二次世界大战期间,在德国将雷达投入实战后,英国皇家空军开始投放切成特定尺寸的金属化纸条,这些纸条与雷达产生共振,用与真实飞机无法区分的幻影回波淹没了德国雷达屏幕。一些历史学家认为,随后的雷达军备竞赛对战争结果的影响比曼哈顿计划更为重大。

For decades, crude jammers have been sold to people who hope to avoid being recorded. Early versions blasted loud, unpleasant white noise to conceal voices. More recently, companies have made models that emit a steady stream of ultrasonic sound at inaudible frequencies, exploiting a quirk of microphone hardware that converts those high frequencies into noise. In 2020, a team at the University of Chicago led by Yuxin Chen reported that it had mounted 23 ultrasonic transducers on a single bracelet, such that jamming signals could be sent in all directions instead of being focused on a single target.

几十年来,粗糙的干扰器一直出售给那些希望避免被录音的人。早期版本会发出响亮、刺耳的白噪音来掩盖声音。最近,公司推出了能够以听不见的频率发出稳定超声波流的型号,利用麦克风硬件的一个怪癖,将这些高频转换为噪音。2020年,由陈昱鑫领导的芝加哥大学团队报告称,他们在一个手镯上安装了23个超声波换能器,使得干扰信号可以向所有方向发送,而不是聚焦于单个目标。

Read: The most reviled tech CEO in New York confronts his haters

阅读:纽约最受鄙视的科技CEO直面他的反对者

But even high-tech jammers have a hard time fending off today’s AI wearables. The most advanced pins, pendants, and glasses use speech-recovery algorithms to strip away unwanted noise, whether it originates from everyday sources—such as the clinking of glasses in a crowded bar—or from an ultrasonic jammer. This task the algorithms perform is quite difficult: In that crowded bar, a microphone on a person’s lapel will intercept sound vibrations from many different sources at once. It will pick up a bartender calling out a drink order, music emanating from a speaker, bursts of laughter coming from nearby tables—and all of these sounds ricochet off of walls and other objects, creating yet more noise. The human body solves this “cocktail party problem” without us noticing: Our ears serve as dual microphones, and our brain can use the timing and intensity differences between them, along with layered processing in the auditory cortex, to isolate the voice of a person who is sitting across from us.

但即使是高科技干扰器也难以抵御当今的AI可穿戴设备。最先进的别针、吊坠和眼镜使用语音恢复算法来去除不需要的噪音,无论这些噪音是来自日常来源(如拥挤酒吧中杯子的叮当声)还是来自超声波干扰器。这些算法执行的任务相当困难:在拥挤的酒吧里,人们翻领上的麦克风会同时拦截来自许多不同来源的声音振动。它会拾取调酒师喊出的饮品订单、扬声器播放的音乐、附近桌子传来的阵阵笑声——所有这些声音都会从墙壁和其他物体上反弹,产生更多噪音。人体无需我们注意就能解决这个“鸡尾酒会问题”:我们的耳朵充当双麦克风,我们的大脑可以利用它们之间的时间差和强度差,以及听觉皮层中的分层处理,来隔离坐在我们对面的那个人的声音。

DeLiang Wang, a computer scientist at Ohio State University, has spent decades training neural networks to accomplish that same goal, for the purpose of improving hearing aids. By feeding the networks hundreds of hours of recorded human voices, he has taught them to recognize the frequencies and rhythms of speech. The models build an internal representation of “speech-ness,” and when they encounter a noisy recording, they focus on the parts that match the patterns they have learned and then suppress everything else. The most advanced technologies can now infer missing syllables in the way that a reader fills in a redacted word from context, allowing them to reconstruct speech that wasn’t cleanly captured in the first place.

俄亥俄州立大学的计算机科学家王德良花了数十年时间训练神经网络来实现同样的目标,目的是改善助听器。通过向网络输入数百小时的录制人声,他教会了它们识别语音的频率和节奏。这些模型构建了“语音性”的内部表示,当它们遇到嘈杂的录音时,它们会专注于与所学模式匹配的部分,然后抑制其他一切。最先进的技术现在可以推断缺失的音节,就像读者根据上下文填补被涂黑的单词一样,从而重建最初未被清晰捕获的语音。

Big tech companies are trying to do this too. Microsoft has been running an annual Deep Noise Suppression Challenge since 2020 to advance the field. (Their in-house team is trying to make Teams meetings less excruciating.) Other companies are working on noise cancellation for cellphone calls and podcast software. This sort of research is meant to improve the lives of normal users of technology—assuming that we podcast listeners count as normal—but every advance in de-noising can also be used to help an AI assistant recover speech from a jammed recording.

大型科技公司也在尝试这样做。微软自2020年以来每年举办深度噪声抑制挑战赛,以推动该领域的发展。(他们的内部团队正努力让Teams会议不那么令人痛苦。)其他公司正在研究手机通话和播客软件的降噪技术。这类研究旨在改善普通技术用户的生活——假设我们播客听众算作普通用户——但每一次降噪技术的进步也可以用来帮助AI助手从嘈杂的录音中恢复语音。

Defeating these algorithms may require a different countersurveillance approach altogether. Finn Brunton, a historian at UC Davis and the co-author of Obfuscation: A User’s Guide for Privacy and Protest, told me that one of the best ways is to identify the data that a device is trying to collect, and then supply it with a junk version. The Berlin-based artist Adam Harvey used this strategy when he developed makeup and clothing that frustrate facial-recognition algorithms. Daniel Howe and Helen Nissenbaum did something similar with a browser plug-in called TrackMeNot: Rather than concealing a user’s Google searches, the extension continually runs its own randomized decoy queries in the background, so that whatever a user actually searched for becomes lost in a sea of false leads.

击败这些算法可能需要一种完全不同的反监控方法。加州大学戴维斯分校的历史学家、也是《混淆:隐私与抗议的用户指南》一书的合著者芬恩·布伦顿告诉我,最好的方法之一是识别设备试图收集的数据,然后向它提供垃圾版本。柏林艺术家亚当·哈维在开发挫败面部识别算法的妆容和服装时使用了这一策略。丹尼尔·豪和海伦·尼森鲍姆用名为TrackMeNot的浏览器插件做了类似的事情:该扩展不是隐藏用户的谷歌搜索,而是在后台不断运行自己的随机诱饵查询,这样用户实际搜索的内容就会迷失在大量虚假线索中。

People have tried this technique in the realm of audio too. Woodrow Hartzog, a law professor at Boston University who studies privacy and surveillance, told me that early in his legal career, he worked with defense attorneys who worried that their jailhouse conversations with clients would be recorded. To fight back, they played “babble tapes”—audio files layered with 40 tracks of voices in different accents—in the background.

人们也曾在音频领域尝试过这种技术。波士顿大学研究隐私和监控的法律教授伍德罗·哈佐格告诉我,在他早期的法律职业生涯中,他曾与辩护律师合作,这些律师担心他们在监狱与客户的谈话会被录音。为了反击,他们在背景中播放“胡言乱语磁带”——一种叠加了40种不同口音语音的音频文件。

In 2023, a team led by Ming Gao, now a researcher at Nanjing University, used human voices to defeat speech-recovery algorithms in a different way. Its jammer, called MicFrozen, is worn by a speaker who doesn’t want to be recorded. It listens as they talk and then generates a real-time stream of ultrasonic “anti-speech” tuned to the speaker’s voice, much like the noise-cancellation technology in your headphones. The device then sends out another layer of counterfeit speech-shaped sound to mislead any algorithm that tries to reconstruct what was lost.

2023年,由南京大学研究员高鸣领导的一个团队以另一种方式使用人声来击败语音恢复算法。他们的干扰器名为MicFrozen,由不想被录音的说话者佩戴。它一边听他们说话,一边生成针对说话者声音的实时超声波“反语音”,就像耳机中的降噪技术一样。然后,该设备发出另一层伪装的语音形状的声音,以误导任何试图重建丢失内容的算法。

Baradari, whose company is working on the Spectre I device, wouldn’t tell me exactly how her jammer’s signals work, but she said that they, too, resemble speech. The launch video for Spectre I claims that the device will also be able to detect the presence of nearby microphones. When I asked Baradari how it will do that, she clarified that her team is still “working on that part right now.”

巴拉达里所在的公司正在研发Spectre I设备,她没有确切告诉我她的干扰器信号是如何工作的,但她说这些信号同样模拟语音。Spectre I的发布视频声称该设备还能探测到附近麦克风的存在。当我问巴拉达里它将如何实现这一点时,她澄清说她的团队目前仍在“研究这部分内容”。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近