August 13-14, 2018
In association with the 2018 Naval Applications of Machine Learning Workshop,
San Diego International Airport Authority Administrative Offices
3225 North Harbor Dr, San Diego, CA
Workshop is being organized by technical staff at SPAWAR Systems Center Pacific.
Participation is open to all interested parties.
The intent of this 2-day workshop is to assess current and future issues relating to safety and privacy in a world with pervasive sensors and autonomous systems. When we depend on artificial intelligence, autonomy, and machine learning technologies to protect public and personal safety, how can we protect these systems from being misled and used against us while still maintaining positive control of our information and privacy from those that would abuse it or use it to undermine our safety and security? In other words: "My toaster is always watching me and apparently tells the internet when I'm making toast, but at least it promises not to ever set my house on fire when I'm gone."
Monday Keynote - Tony Cole, CTO, Attivo Networks - Deception in Cyberspace
Tuesday Keynote - Jamie Lukos, SSC Pacific - Building Trust in Unmanned Systems
Today’s online environments build enormous data sets using sophisticated software-based tracking systems and leverage machine learning and artificial intelligence to understand individual preferences and trends and to de-anonymize and track our activities, putting individuals and communities at risk. Current and emerging techniques skirt privacy laws and protections, violating our privacy in profiteering and criminal ways. Advertisers surreptitiously watch online activities and sell our browsing histories and online identities to others. Criminals track our activities in order to steal credentials, impersonate us, hold our data for ransom, and make us unwittingly complicit in large-scale cyber attacks. How do we protect privacy, security, and identity in a world saturated with sensors and systems which can see, track, know, and, sometimes, harm us? Can we fool these systems? Can we prevent widespread misuse of information collected about us through the world and through the information environment? How will privacy and privacy protections evolve over the next decade? Should/will active obfuscation and defensive deception become normal when protecting our privacy and our personal information? What are the implications of the use of deception technologies to protect our personal information? Can we also use these techniques to protect our information systems and our computer networks?
We have become increasingly dependent on autonomous systems, both as a society and personally. We depend on the proper functioning of automated and autonomous systems to perform everyday tasks from the mundane to the sophisticated. We task simple autonomous systems via our mobile phones to search through traffic and topological data to provide us with efficient directions to our next destination. We also depend upon sophisticated vision recognition and control systems to keep our cars on the road, driving between the lines, and saving us from catastrophic collisions. Today, there are an almost unlimited number of effective strategies and methods that a malicious actor might use to defeat, disable, or destroy an autonomous system or its ability to function properly. Small commercially-available autonomous drones can be easily jammed and caused to fall from the sky. Home automation and remotely accessible security systems may suffer from cyber attacks or be used by criminals to learn of our whereabouts. We often give these systems carte blanche access to our most private information and living spaces, trusting them implicitly. Billions of dollars are being spent in creating autonomy for automobiles, but these sensor systems and machine learning algorithms are still easily confused. Something as seemingly innocuous such as conspicuously-placed white electrical tape might prevent an autonomous platform from recognizing a stop sign. High power LEDs strobing at the right frequency may disrupt the LiDAR sensors causing a car to lose track of the "world". A vehicle operator might even intentionally deceive their own vehicle, falsely indicating ‘attentiveness’ by attaching strips of metal to hand-placement sensors on a steering wheel or painting wide-open eyes over their closed and sleeping eyelids. How do we protect our autonomous systems from malicious interference and manipulation? How can we detect and adapt in the face of autonomous system failures? How do we differentiate ‘normal’ failures from intentional attacks? Finally, if we are ever to be able to fully trust these systems how will we prevent them from being thwarted by the very techniques and technologies that we might use to protect ourselves?
During the workshop, participants will explore the problem and technical solutions to the privacy and personal security implications of pervasive sensor systems and ubiquitous computing. In particular, participants will be asked to consider defensive deception and misdirection as a general approach to protecting privacy and personal security. Simultaneously, participants will explore methods for protecting autonomous systems and sensor systems from being misdirected or misused.
The workshop will consist of two full days consisting of short talks by invited speakers, open discussions, and brainstorming sessions with peers from related industries and research groups. The final session of the workshop will provide short out-briefs by workshop participants and the sharing of workshop artifacts between attendees. Participation will include experts and technologists from industry and academia in the fields of artificial intelligence, autonomy, machine learning, privacy, security, behavioral psychology, and the sciences of deception and trust. The problems explored and solutions proposed will be used as inspiration to guide similar approaches to protecting military and defense systems from misdirection and exploitation.
We invite interested individuals to submit succinct 1-2 page blinded proposals in the form of an extended abstract citing recent research in the field. Proposals should inform readers of the recent topical research while bringing to light outstanding gaps in our current reasoning and identifying opportunities for new research endeavors. Proposals may focus on technical, cultural, or policy aspects of autonomy, privacy, security, trust, and deception.
Workshop registration will require submission and acceptance of a proposal. However, proposals will be accepted from all interested individuals regardless of whether they are able to attend the first workshop. With author permission, proposals and key cited literature will be collected, curated, and published. Please review submission instructions and details of the review process.