/* ---- Google Analytics Code Below */
Showing posts with label CACM. Show all posts
Showing posts with label CACM. Show all posts

Wednesday, June 21, 2023

Keeping Hackers Off the Electrical Grid

Biggest issue.

Keeping Hackers Off the Electrical Grid

By R. Colin Johnson

Commissioned by CACM Staff, June 20, 2023

ORNL researchers showed how to encode grid operating data into a unique color pattern hidden inside a single video frame, which can be transmitted to a grid control center computer using a Fibonacci sequence to encode/decode each sensor reading.

Credit: Oak Ridge National Laboratory

As attacks on grid substations increase—by 70% in 2022 alone, according to the Department of Energy's Oak Ridge National Laboratory (ORNL)—engineers there are anticipating new attack vectors and taking measures to protect from hackers using them.

"As researchers, we try to stay ahead of cyber threats, not just react to them after they occur," said ORNL's Peter Fuhr, who heads its Grid Communications and Security group. Fuhr's group recently demonstrated a new method of using a rotating color wheel to encode grid sensor data subliminally into a video feed, and using a novel Fibonacci sequence decoding key that rotates the color-wheel so each sensor reading uses a unique color code.

"ORNL has invented a compelling method to protect our critical grid infrastructure that builds upon known encryption technology," said Sterling Rooke, chief executive officer (CEO) of Brixon Inc. (Baltimore) , a company that manufactures electrical power monitoring instruments. "With the right application, there will be a need for this novel implementation—a kind of steganography that conceals critical information within the existing live video feeds from the grid substations themselves."

The technique, Fuhr says, translates the encrypted character codes utilities use today to a color-code hidden in video feeds from cameras that already monitor substation activity. EPB (formerly the Electric Power Board, Chattanooga, TN) successfully tested the technique for six months using a virtual local area network (VLAN) link between the central-EPB grid control center and its substations. "We proved the concept in the lab at ORNL, then extended the testing to a nearby substation, and eventually installed the color encoding/decoding equipment at both the EPB substation and its central-control computer," said Fuhr. "It's the real deal—tested and proven."

According to Fuhr, EPB and most industrial process control architectures in the U.S. follow the National Institute of Standards and Technology (NIST) SP800-82 guidelines for all industrial process control (IPC) systems—including factories, manufacturing, and automated testing, as well as the grid. His color encoding/decoding technique will work not only for grid communications from a grid central control computer to its substations, but for any operational technology (OT). In fact, several private companies have already shown interest in licensing his color-coding architecture, according to Fuhr.

Historically, Internet connections have offered an entry point for sophisticated hackers to insert malware into substations, which are almost universally run by SCADA (supervisory control and data acquisition) networks, which date back to the 1950s, when cybersecurity wasn't even a word. Even today, SCADA networks typically do not require any authentication to remotely execute commands on a control device. To solve most vulnerabilities, the NIST guidelines forbid the central control computer—which is typically connected to corporate IT—to extend Internet availability to the SCADA control system. NIST-compliant SCADA architectures are isolated from the Internet by firewalls that instead run a multi-channel virtual local area network (VLAN) to substations connected to its central control computers. Likewise, communicating data from sensors and to actuators run on different channels of the VLAN. Most operations are programmable, but run autonomously at unmanned substations; human operators can also use a graphical user interface (GUI) for high-level configuration and supervision of remote machines and processes.

Over the years as cybersecurity has become an increasingly important issue, many hacker-resilient modifications have been added to SCADA architectures. These security measures, however, have not been universally applied. The result has been numerous attacks dating back to 2000, when a disgruntled former employee took control of the Maroochy Shire sewage OT system in Queensland, Australia, using a single computer and a radio transmitter. Since the commercialization of the Internet, many hackers have attacked process control systems, including utilities, forcing new (and retrofit) SCADA industrial protocols to segment their networks with gateways, routers, one-way-only data-diodes, and white-listing that only passes traffic of a single type down each VLAN channel. In addition, VLAN channels are only bi-directional when they need to be, are segmented so they can only communicate with devices with which they were meant to communicate, and are not allowed to connect to the central corporate network without at least a firewall (for maximum security, with two firewalls on each side of a DMZ (demilitarized zone) server that securely forwards communications).  ... ' 

Saturday, April 16, 2022

Quantum Datacenter Intranet Advances

 More global advances:

Quantum Datacenter Intranet Advances

By R. Colin Johnson, Commissioned by CACM Staff, April 14, 2022

U.S., European Union, and Japanese researchers recently made advances that they say are necessary for future quantum datacenters, where millions of qubits will be interconnected with a quantum intranet (the private communications grid among separate quantum computers).

In particular, this year U.S. national lab-sponsored researchers have announced the capability to preserve the coherence of quantum superposition states for five seconds, "more than 500 times longer than last year's record," according to David Awschalom, principal investigator and senior scientist at Argonne National Laboratory, director of the U.S. Department of Energy's Q-NEXT next-generation quantum research and science project, and Liew Family Professor in Molecular Engineering and Physics at the University of Chicago. During that five-second interval, as many as 100 million quantum operations and their intermediate results could be communicated over a quantum intranet, according to Awschalom.

Also this year, researchers at QuTech, a collaboration between Delft University of Technology in the Netherlands and TNO, the Netherlands Organization for applied scientific research, demonstrated quantum gates with greater than 99.5% fidelity—the benchmark accuracy needed for quantum error correction, according to Lieven Vandersypen in the QuTech lab (the achievement was confirmed independently at the Riken Center for Emergent Matter Science in Saitama, Japan). "High-fidelity control of quantum bits is paramount for the reliable execution of quantum algorithms and for achieving fault tolerance," said Vandersypen. "Having surpassed the 99% barrier for two-qubit gate fidelity, semiconductor qubits are well positioned on the path to fault tolerance."

In addition, at the end of last year, IBM announced its 127-qubit Eagle quantum computer, to be followed by its 433-qubit Osprey model later this year, and next year by a 1,121-qubit Condor model, according to IBM senior vice president Dario Gil. "Eagle, Osprey, and Condor will truly let us explore uncharted computational territory. …By 2030, we predict that our quantum computer users will be running a trillion quantum circuits per day, each of which will be solving problems that cannot be solved today on traditional digital computers."   .....  ' 

Wednesday, March 02, 2022

Will No-Code Win?

 Great piece,  continuing to consider 

Will No-Code Crack the Code?

By Samuel Greengard, Commissioned by CACM Staff, March 1, 2022

The history of computing is rife with advances that have made things easier for the common user. Graphical user interfaces (GUIs), the computer mouse, drag-and-drop functionality, and Web browsers are just a few examples of how complex processes have been simplified. Yet for decades, software development has remained largely outside the mainstream. Because most people lack the knowledge and ability to write computer code in C++, Python, Java, or other languages, they typically find themselves locked out—or they must hire someone to create the desired functionality.

That is beginning to change. No-code platforms are on the rise, including in areas such as automation and artificial intelligence (AI). The appeal is not difficult to understand. "No-code democratizes software development. It provides value in many areas where custom code is too expensive, slow to develop, and hard to maintain," says Isaac Sacolick, author of Driving Digital and CEO of business consulting firm Star CIO.

Behind the Lines

The idea of using visual elements to generate code is not particularly new. In 2003, WordPress introduced a drag-and-drop interface for building Websites. Not surprisingly, the concept has continued to evolve and expand. Today, no-code platforms such as Google's AppSheet make it possible to build Web and mobile apps in hours or days without any prior coding knowledge. Of course, coding continues to take place, though the process happens in an automated way behind the scenes. While the need to understand data structures and how to generate a useful app have not gone away, there is no longer a need to wear a data scientist hat. No-code platforms can grab data, classify and encode data, and use machine learning to spot relationships.

"No-code changes the game. With the popularity of smartphones and the Internet, there is a need to develop mobile apps and Websites quickly," says Ruben Martins, an assistant research professor at Carnegie Mellon University. "No-code frameworks aid individuals, but also help businesses build applications that can increase customer satisfaction and lower the cost of development."

Today, people are turning to these platforms to manage a wide array of tasks, including scheduling, claims and paperwork, tracking deliveries, viewing sales prospects, and checking job boards. No-code applications can handle text classification from unstructured data and scan financial transactions for fraud. In addition, "No-0code can do things like data cleaning and data transformation," Martins says.

Saturday, December 04, 2021

The Future is Big Graphs

Like the thought.    But how do we define big here? Complete?

The Future Is Big Graphs: A Community View on Graph Processing Systems

By Sherif Sakr, Angela Bonifati, Hannes Voigt, Alexandru Iosup, Khaled Ammar, Renzo Angles, Walid Aref, Marcelo Arenas, Maciej Besta, Peter A. Boncz, Khuzaima Daudjee, Emanuele Della Valle, Stefania Dumbrava, Olaf Hartig, Bernhard Haslhofer, Tim Hegeman, Jan Hidders, Katja Hose, Adriana Iamnitchi, Vasiliki Kalavri, Hugo Kapp, Wim Martens, M. Tamer Özsu, Eric Peukert, Stefan Plantikow, Mohamed Ragab, Matei R. Ripeanu, Semih Salihoglu, Christian Schulz, Petra Selmer, Juan F. Sequeda, Joshua Shinavier

Communications of the ACM, September 2021, Vol. 64 No. 9, Pages 62-71    10.1145/3434642

Graphs are, by nature, 'unifying abstractions' that can leverage interconnectedness to represent, explore, predict, and explain real- and digital-world phenomena. Although real users and consumers of graph instances and graph workloads understand these abstractions, future problems will require new abstractions and systems. What needs to happen in the next decade for big graph processing to continue to succeed?

We are witnessing an unprecedented growth of interconnected data, which underscores the vital role of graph processing in our society. Instead of a single, exemplary ("killer") application, we see big graph processing systems underpinning many emerging but already complex and diverse data management ecosystems, in many areas of societal interest.a

To name only a few recent, remarkable examples, the importance of this field for practitioners is evidenced by the large number (more than 60,000) of people registeredb to download the Neo4j book Graph Algorithmsc in just over one-and-a-half years, and by the enormous interest in the use of graph processing in the artificial intelligence (AI) and machine learning (ML) fields.d Furthermore, the timely Graphs 4 COVID-19 initiativee is evidence of the importance of big graph analytics in alleviating the pandemic.

Academics, start-ups, and even big tech companies such as Google, Facebook, and Microsoft have introduced various systems for managing and processing the growing presence of big graphs. Google's PageRank (late 1990s) showcased the power of Web-scale graph processing and motivated the development of the MapReduce programming model, which was originally used to simplify the construction of the data structures used to handle searches, but has since been used extensively outside of Google to implement algorithms for large-scale graph processing.

Motivated by scalability, the 2010 Google Pregel "think-like-a-vertex" model enabled distributed PageRank computation, while Facebook, Apache Giraph, and ecosystem extensions support more elaborate computational models (such as task-based and not always distributed) and data models (such as diverse, possibly streamed, possibly wide-area data sources) useful for social network data. At the same time, an increasing number of use cases revealed RDBMS performance problems in managing highly connected data, motivating various startups and innovative products, such as Neo4j, Sparksee, and the current Amazon Neptune. Microsoft Trinity and later Azure SQL DB provided an early distributed database-oriented approach to big graph management.   ... ' 

Friday, November 26, 2021

Can a Free Internet Survive?

What steps, what cost, what limits?

Can a Free Internet Survive?,  By Samuel Greengard, Commissioned by CACM Staff, November 23, 2021

In the beginning, Internet pioneers dreamed of creating an open framework for global communication and interaction. It would be a place where free thinking and information could flourish. Over the last half century, despite a few potholes and speedbumps, the Internet has largely lived up to that promise.

However, there's evidence that attitudes and values are shifting. Governments around the world are taking steps to limit access to information, or even shut it down using tactics like site blocking, URL throttling, restricting mobile data, and regulatory and legal threats.

"This is in the face of governments, business and industry, and popular movements responding to perceived threats to dominant institutions and traditional sources of information," observes William H. Dutton, Emeritus Professor at the University of Southern California and co-author of the UNESCO report   Freedom of Connection, Freedom of Expression.

Washington D.C.-based democracy advocacy group Freedom House reported in 2021 that Internet freedom declined for the fifth year in a row in the U.S. and the 11th consecutive year internationally. Officials in at least 20 countries suspended Internet access, and 20 regimes blocked access to social media platforms, the report noted.

Principles for Innovative Engineers

Very useful principles below at the link, we worked with Rosalind Picard long ago ... 

What Every Engineer and Computer Scientist Should Know: The Biggest Contributor to Happiness

By Rosalind Picard     in CACM

Communications of the ACM, December 2021, Vol. 64 No. 12, Pages 40-42    10.1145/3465999

My teams at MIT and our spin-out companies have worked for years to create technology that is both intelligent and able to improve people's lives. Through research drawing from psychiatry, neuroscience, psychology, and affective computing, I have learned some surprising things. In some cases, they are principles we have embedded into technology that interacts with people. Guess what? People like it. After one year of the COVID-19 pandemic, I realize that the principles we learned apply not only to making smart robots or software agents, but also to the people around us. They give us lessons for how to live happier lives, and happier engineers are better at solving creative problems and have more fun.

Researchers have studied what brings happiness in life, and what, at the end of life, people wish they had done. While many factors contribute, do you know the biggest one?

Almost never late in life do people say: "I wish I had invented a smarter or faster device," "I wish I had made more money," "I wish I had given more TED talks," "I wish I had climbed higher in my business," or "I wish I had authored more books." Even this pinnacle of achievement is not uttered: "I wish I had written an article for an ACM magazine." Instead, almost always, people wish that they had done a better job at building meaningful authentic human relationships, and spending time in those relationships.

This finding is a general one, whether studying human happiness or end-of-life reflections. They apply to hard-working, well-educated computer scientists or engineers and also to many kinds of people, different races and cultures, rich and poor, male and female, uneducated or over-educated.

All of the patents, publications, presentations, and personal technical achievements can be amazing: They can literally save lives and bring immense delight, win us world acclaim, fill our shelves with awards, tally up clicks online, and even make our resumes impressively long. However, they all pale in comparison to something that is even more joy-giving: Achieving deeply satisfying, personally-significant human relationships.

How do you engineer great relationships? Here are three helpful principles you can test in your own life and relationships. If you build AI that interacts directly with people, you can build these principles into those interactions too. I learned these principles while trying to engineer more intelligence in machines, specifically computers with skills of social-emotional intelligence. The skills derive from studies of human relationships and they apply not only when the interactions involve two people, but also when one is a computer (including chatbots, software agents, robots, and other things programmed to talk with us). The three principles below can help improve relationships, human or AI.   ..... ....

(Full principles below)

Wednesday, September 29, 2021

Beyond Seti, Can AI get us There?

 A number of good questions are asked. 

AI Calling ET: How Artificial Intelligence Supports the Search for Extraterrestrial Life

By Karen Emslie,  Commissioned by CACM Staff,  September 28, 2021

Back in 1977, astronomer Jerry Ehman circled an anomaly on a printout of narrowband radio signal data recorded by Ohio State University's Big Ear telescope as it swept the skies for signs of extraterrestrial life. Alongside, Ehman wrote one now-famous word "Wow!"

We are still scouring the heavens for evidence that may answer the enduring question: are we alone in the universe? We don't yet know, but artificial intelligence (AI) is now supporting our investigations.

A number of methods have been deployed in the search for extraterrestrial life. They include in situ observations, like sending a rover to Mars to search for evidence of current or historical life, as well as remote sensing, like probing distant planetary atmospheres using technologies such as the future James Webb Space Telescope (JWST), and searching for signs of extraterrestrial technologies and communications.

AI is being used to support each of these research avenues.

Looking for planets that have similar life-supporting conditions to Earth, such as the presence of liquid water, is a vital part of the search. Exoplanets, or planets that orbit stars beyond our solar system, are a primary target. Explains Greg Olmschenk, a machine learning specialist at the U.S. National Aeronautics and Space Administration (NASA)  Goddard Institute for Space Sciences, "Our best bet right now for finding life elsewhere is to look for life as we know it, because that's the only kind of life that we know."

NASA missions, such the Transiting Exoplanet Survey Satellite (TESS) and the now-retired Kepler space telescope, survey the skies looking for exoplanets. Tiny dips in a star's perceived brightness can reveal the presence of an exoplanet as it transits, or crosses in front of, the star. These dips can be detected in light curves, or measurements of a star's light over time. TESS data, for example, contains around 60 million such light curves, which helps to explain the incorporation of AI into the process.

"It's not practical to have an astrophysicist look at each one of those and so we trained a neural network to do that," Olmschenk said.

To accomplish that, Olmschenk collaborated with researchers from the Universities Space Research Association, the Catholic University of America, the University of Maryland, and Science Systems and Applications, Inc. in the U.S., and the Università degli Studi di Napoli Federico II in Italy. They developed a one-dimensional (1D) convolutional neural network (CNN) to identify planetary transit signals. Olmschneck explained that while 2D convolutional networks are more common, as most neural networks are looking at images, "In this case, what we're looking at is one-dimensional time data."

Olmschenk said the CNN was trained to dismiss false positives, dips caused by other types of signals, such as the eclipsing of binary stars. It has a stack of convolutional layers that process input data, with each layer looking for certain patterns, such as light curves going up or down.

"You'll start to get pieces of the neural network that are recognizing peaks and troughs in the light curve, and eventually when you get down to the lower layers, you start to recognize things like actual transit dips."

The process filtered millions of light curves down to a few thousand that looked most likely to be planets. Astrophysicists then carried out follow-up observations to produce a short list of exoplanet candidates.

Sophisticated techniques such as radial velocity measurement, which detects the tell-tale 'wobble' produced by the gravitational tug of a planet on a star, ultimately determine whether candidates are truly planets. At the time of writing, 183 such candidates are still being investigated.

Searching for Signs of Intelligence

At the SETI Institute in Mountain View, CA, researchers have been looking for evidence of life on other worlds since 1985. The non-profit research organization was born from earlier SETI (search for extraterrestrial intelligence) projects funded by NASA.

SETI Institute CEO Bill Diamond draws a distinction between 'life' and 'intelligent life' on other worlds. While there may be biological life elsewhere in our solar system, he says, "We're talking about intelligent and technological beings that might exist on planets outside of our own solar system."

The Institute has close links with the nearby NASA Ames Research Center, and its researchers developed AI for NASA'S Kepler and TESS missions.  ... ' 

Saturday, September 18, 2021

Biases in AI Systems

Excellent piece, broadly useful beyond AI applications.  

May 12, 2021, Volume 19, issue 2

Download PDF version of this article PDF  

Biases in AI Systems     

A survey for practitioners

Ramya Srinivasan and Ajay Chander   in CACM

A child wearing sunglasses is labeled as a "failure, loser, nonstarter, unsuccessful person." This is just one of the many systemic biases exposed by ImageNet Roulette, an art project that applies labels to user-submitted photos by sourcing its identification system from the original ImageNet database.7 ImageNet, which has been one of the instrumental datasets for advancing AI, has deleted more than half a million images from its "person" category since this instance was reported in late 2019.23 Earlier in 2019, researchers showed how Facebook's ad-serving algorithm for deciding who is shown a given ad exhibits discrimination based on race, gender, and religion of users.1 There have been reports of commercial facial-recognition software (notably Amazon's Rekognition, among others) being biased against darker-skinned women.6,22

These examples provide a glimpse into a rapidly growing body of work that is exposing the bias associated with AI systems, but biased algorithmic systems are not a new phenomenon. As just one example, in 1988 the UK Commission for Racial Equality found a British medical school guilty of discrimination because the algorithm used to shortlist interview candidates was biased against women and applicants with non-European names.17

With the rapid adoption of AI across a variety of sectors, including in areas such as justice and health care, technologists and policy makers have raised concerns about the lack of accountability and bias associated with AI-based decisions. From AI researchers and software engineers to product leaders and consumers, a variety of stakeholders are involved in the AI pipeline. The necessary expertise around AI, datasets, and the policy and rights landscape that collectively helps uncover bias is not uniformly available among these stakeholders. As a consequence, bias in AI systems can compound inconspicuously.

Consider, for example, the critical role of ML (machine learning) developers in this pipeline. They are asked to: preprocess the data appropriately, choose the right models from several available ones, tune parameters, and adapt model architectures to suit the requirements of an application. Suppose an ML developer was entrusted with developing an AI model to predict which loans will default. Unaware of bias in the training data, an engineer may inadvertently train models using only the validation accuracy. Suppose the training data contained too many young people who defaulted. In this case, the model is likely to make a similar prediction about young people defaulting when applied to test data. There is thus a need to educate ML developers about the various kinds of biases that can creep into the AI pipeline.

Defining, detecting, measuring, and mitigating bias in AI systems is not an easy task and is an active area of research.4 A number of efforts are being undertaken across governments, nonprofits, and industries, including enforcing regulations to address issues related to bias. As work proceeds toward recognizing and addressing bias in a variety of societal institutions and pathways, there is a growing and persistent effort to ensure that computational systems are designed to address these concerns.

The broad goal of this article is to educate nondomain experts and practitioners such as ML developers about various types of biases that can occur across the different stages of the AI pipeline and suggest checklists for mitigating bias. There is a vast body of literature related to the design of fair algorithms.4 As this article is directed at aiding ML developers, the focus is not on the design of fair AI algorithms but rather on practical aspects that can be followed to limit and test for bias during problem formulation, data creation, data analysis, and evaluation. Specifically, the contributions can be summarized as follows:

• Taxonomy of biases in the AI pipeline. A structural organization of the various types of bias that can creep into the AI pipeline is provided, anchored in the various phases from data creation and problem formulation to data preparation and analysis.

• Guidelines for bridging the gap between research and practice. Analyses that elucidate the challenges associated with implementing research ideas in the real world are listed, as well as suggested practices to fill this gap. Guidelines that can aid ML developers in testing for various kinds of biases are provided.

The goal of this work is to enhance awareness and practical skills around bias, toward the judicious use and adoption of AI systems......' 

Friday, August 06, 2021

Scaling up Chatbots

 Below just the introduction, much more at the link.

Scaling Up Chatbots for Corporate Service Delivery Systems  By Alistair Barros, Renuka Sindhgatta, Alireza Nili   Communications of the ACM, August 2021, Vol. 64 No. 8, Pages 88-97 10.1145/3446912

Conversational agents, or chatbots, providing question-answer assistance on smart devices, have proliferated in recent years and are poised to transform online customer services of corporate sectors.1,6 Implemented through dialogue management systems, chatbots converse through voice-based and textual dialogue, and harness natural language processing and artificial intelligence to recognize requests, provide responses, and predict user behavior.5,28 Market analysts concur on current adoption trends and the magnitude of growth and impact of chatbots anticipated in the next five years. According to a report by Grand View Research, for instance, already 45% of users prefer chatbots as the primary point of communications for customer service enquiries, translating into a global 'chatbot' market of $1.23 billion by 2025, at a compounded annual growth rate (CAGR) of 24.3%.9   .... '

Friday, May 14, 2021

Toshiba Simulations Beat Quantum Computing

Toshiba work of interest.  Linking to Microsoft Cloud.  Would you expect a simulation to beat out an actual implementation?  Depends.  But a simulation usually means it does not include all the physical constraints involved.  Note the mention of 'combinatorial' problems ....that is problems that have very large numbers of possible solutions, exactly what we posed very early on.

Commissioned by CACM Staff

Why wait for quantum computers to be perfected "someday," when you can use Toshiba's quasi-quantum optimization algorithm on Microsoft's Azure cloud in 2021? It outperforms today's fledgling quantum computer speeds through the use of that proprietary algorithm on conventional digital computers accelerated with cloud GPUs [graphic processing units].

Alternatively, the quasi-quantum algorithms can run on Toshiba's FPGA [field programmable gate array].

"It will take a very long time for quantum computers to achieve the high performance of our [GPU and FPGA-powered] optimization solutions for large-size problems," said Hayato Goto, chief research Scientist at Toshiba Corp. in Japan. In fact, Goto said, "So far, no one has even been able to prove that any future quantum computer will be able to solve combinatorial optimization problems faster, which leaves room for our classical machines to surpass quantum computers."

Too good to be true? Toshiba recently demonstrated a discrete version of its quasi-quantum algorithm in peer-reviewed benchmarks against a wide variety of current-day quantum computer hardware and quasi-quantum software simulators, and outperformed them all.... " 

Sunday, February 28, 2021

MFA as Security

 Good overview piece abut 2FA and beyond. 

Is MFA Needed to Improve Security?

By Keith Kirkpatrick   Commissioned by CACM Staff    February 25, 2021

Many corporate and consumer-based systems and applications deploy short message service (SMS)-based two-factor authentication technology to help protect users from being hacked. This method of two-factor authentication is fairly simple; a user will log onto an app or system using their username and password, and then a unique security code is generated by an algorithm within the app, which is then sent to the user's phone via a text message. If that code is correctly entered into the system when prompted, it theoretically will authenticate the person trying to log into the system.

However, SMS-based authentication is rife with security holes. Alex Weinert, Microsoft's director of identity security, published a blog post in early November highlighting the immense risk of continuing to use SMS-based codes to authenticate users, given the ability of hackers to either intercept the codes while they're being sent (basic SMS messages are unencrypted), or to simply carry out a scheme known as subscriber identity module (SIM)-card swapping, or SIMjacking.

SIMjacking is a technique through which a criminal will call a user's wireless company and use information gathered about the user (including personal data garnered via phishing schemes, guessing answers to challenge questions, and exploiting the empathetic nature of humans) to have a phone's SIM card transferred to their account, giving them access to the user's SMS messages, including authentication texts.

"SIM-based multi-factor authentication is probably one of the most popular MFA methods on the Internet, if not the most popular, meaning that almost every company you deal with uses these SMS-based MFA solutions, and you really don't have a choice," says Roger Grimes, author of Hacking Multifactor Authentication, and a Data-Driven Defense Evangelist at KnowBe4, a security awareness education company. "Not only is [SMS] a poor authenticator, it is fairly easy to hack, but many times you can't opt out of it."

That's why security professionals suggest the use of multi-factor authentication applications, which are designed to reside on each physical device and do not require the use of SMS-based authentication codes. Authentication applications, which have been released by both large companies (Google Authenticator, Microsoft Authenticator) and independent software vendors (Twilo Authy, LogMeIn LastPass Authenticator, and Duo Mobile) generally only require a data connection during the initial set-up process, which involves installing the application on a smartphone, then configuring it to work with each account to be protected. Each account provides a secret key that is shared over a secure data channel to the authenticator app, and is used for all future logins.

To log into such a site, the user will provide credentials (a username and password to the site); an algorithm then generates codes using the current time on the device and the shared secret key, in order to generate a one-time password, then asks the user to enter it. The user runs the Authenticator app, which independently computes and displays the same password, which the user types into the site, authenticating their identity.  ... " 

Saturday, February 27, 2021

Decline of Computers as a General Purpose Technology

Contributed article, excerpt below in the March 2021 CACM.

My first reaction was No!  But some very good points made ... '

The Decline of Computers as a General Purpose Technology   By Neil C. Thompson, Svenja Spanuth

Communications of the ACM, March 2021, Vol. 64 No. 3, Pages 64-72  10.1145/3430936

Perhaps in no other technology has there been so many decades of large year-over-year improvements as in computing. It is estimated that a third of all productivity increases in the U.S. since 1974 have come from information technology,a,4 making it one of the largest contributors to national prosperity.

Key Insights  ...  

- Moore's Law was driven by technical achievements and a "general purpose technology" (GPT) economic cycle where market growth and investments in technical progress reinforced each other.  These created strong economic incentives for users to standardize to fast-improving CPUs, rather than designing their own specialized processors.

- Today, the GPT cycle is unwinding, resulting in less market growth and slower technical progress. 

- As CPU improvement slows, economic incentives will push users toward specialized processors, which threatens to fragment computing. In such a computing landscape, some users willbe in the 'fast lane,' benefit ing from customized hardware, and others will be left in the 'slow lane,' stuck on CPUs whose progress fades. ... 

The rise of computers is due to technical successes, but also to the economics forces that financed them. Bresnahan and Trajtenberg3 coined the term general purpose technology (GPT) for products, like computers, that have broad technical applicability and where product improvement and market growth could fuel each other for many decades. But, they also predicted that GPTs could run into challenges at the end of their life cycle: as progress slows, other technologies can displace the GPT in particular niches and undermine this economically reinforcing cycle. We are observing such a transition today as improvements in central processing units (CPUs) slow, and so applications move to specialized processors, for example, graphics processing units (GPUs), which can do fewer things than traditional universal processors, but perform those functions better. Many high profile applications are already following this trend, including deep learning (a form of machine learning) and Bitcoin mining. ... 

With this background, we can now be more precise about our thesis: "The Decline of Computers as a General Purpose Technology." We do not mean that computers, taken together, will lose technical abilities and thus 'forget' how to do some calculations. We do mean that the economic cycle that has led to the usage of a common computing platform, underpinned by rapidly improving universal processors, is giving way to a fragmentary cycle, where economics push users toward divergent computing platforms driven by special purpose processors.

This fragmentation means that parts of computing will progress at different rates. This will be fine for applications that move in the 'fast lane,' where improvements continue to be rapid, but bad for applications that no longer get to benefit from field-leaders pushing computing forward, and are thus consigned to a 'slow lane' of computing improvements. This transition may also slow the overall pace of computer improvement, jeopardizing this important source of economic prosperity.    ...."

Wednesday, February 03, 2021

On Historical Robots

Not really directly useful, but I like thinking about history as it predicts the future.   Da Vinci is a good, and very early example.  

Superb Historical Robots

By Herbert Bruderer  in the CACM,  January 19, 2021

Robots of all kinds are in widespread use today. They are often humanoid machines. However, the definition of a robot is unclear, as is the distinction from automata. Already Heron of Alexandria (1st century) created such devices. Leonardo da Vinci (1452–1519) also designed a wealth of drawings of sophisticated objects, see Leonardo da Vinci's Robot Lion and Leonardo's Self-driving Car. There were also fake automatons, e.g. the chess-playing Turk by Wolfgang von Kempelen (1770).

In the 18th century, automaton figures experienced their heyday. Some of these creations are still fully functional and are regularly demonstrated. This development began primarily with Jacques Vaucanson. His three machines, duck, flute player, and drummer (1738), are unfortunately not preserved. In 1745, he had also manufactured an automatic tape controlled loom. Numerous automated figures were damaged or destroyed in fires, including the draughtsman-writer of Henri Maillardet (Franklin Institute, Philadelphia).

The three musical, drawing, and writing automata (see Figs. 1 and 2) in the Musée d'art et d'histoire, Neuchâtel (Switzerland, MahN) from 1774 are considered to be the most beautiful automaton figures in the world. Makers of these masterpieces are Pierre Jaquet-Droz, Henri-Louis Jaquet-Droz, and Jean-Frederic Leschot.   ... " 

Friday, November 20, 2020

Vint Cerf Talks Repairability

Below an intro, some good points.  

Repairability Redux  By Vinton G. Cerf

Communications of the ACM, December 2020, Vol. 63 No. 12, Page 5   10.1145/3429267

Google Vice President and Chief Internet Evangelist Vinton G. Cerf 

I wrote about repairability in the February 2020 issue of Communications (p. 7) and here I am at year's end harping on the same topic. My excuse is COVID-19. I have been at home for the past six months while my normal schedule would have had me on the road three weeks out of four. Of course, like many of you, I have been all over the world—virtually—since mid-March. There are days when I can visit Australia and Austria and be home in time for dinner. So, what does that have to do with stuff that breaks? Mostly, I am actually here when it does. Under more normal conditions, my wife would have to call a repair person to fix or replace a broken item. Now that I am home, I am sometimes the one who discovers the problem, or I am told about it before a repair service gets the call. I am an engineer of sorts, so broken things attract my attention. Engineers love problems to solve. "Fix me! Fix me! You can do it!" Of course, if you are like me, you go to the hardware store three times: first to get the stuff you need, second to get the stuff you forgot, and third to get the stuff you need to fix what you broke. My basic rant is that manufactured goods today do not seem to take into account the possibility of repair.   ... " 

Sunday, November 08, 2020

Drones use Darts to Create Networks

At first I thought the idea was to sense the state of forestry plantations.   But no, it was for setting up apparently temporary networks to share sensor data.   So the word 'attacks' is wrong in the sense that it is very misleading.   Bad science.   But the precision you can use for tagging trees is a useful learning. 

Dart-Shooting Drone Attacks Trees for Science  By IEEE Spectrum

Researchers in the Aerial Robotics Lab of Imperial College London in the U.K. are working on a method to increase the efficiency of setting up sensor networks by using a drone to launch laser-aimed, sensor-equipped darts.

Researchers in the Aerial Robotics Lab of Imperial College London in the U.K. are working on a method to increase the efficiency of setting up sensor networks by using a drone as a launching platform for laser-aimed, sensor-equipped darts.

In indoor tests using magnets, researchers found  the darts, fired from a spring-loaded launcher, hit its target and stuck 90% to 100% of the time,  at a distance of 1 to 4 meters away.

The drone was controlled manually in its initial outdoor tests, which also were successful, but the researchers plan to add vision state estimation and positioning, and a depth sensor to allow for autonomous drone flights.

From IEEE Spectrum

Wednesday, October 28, 2020

Five Nonobvious Remote Work Techniques

Very interesting piece in Queue and the Communications of the ACM, Nov 2020,  pp 108-110.  Take the problem beyond the technical and to the collaboratively social.    From experiences at Stack Overflow.  Well Worth the read.

Five Nonobvious Remote Work Techniques   001:10 .1145/3410627

Emulating the efficiency of in-person conversations   By Thomas A. Limoncelli   This article reveals five nonobvious techniques that make remote work successful at Stack Overflow.

Remote work has been part of the engineering culture at Stack Overflow since the company began. Eighty percent of the engineering department works remotely. This enables the company to hire top engineers from around the world, not just from the New York City area. (Forty percent of the company worked remotely prior to the COVID-19 lockdown; 100 percent during the lockdown.) Even employees who do not work remotely must work in ways that are remote-friendly.

For some companies, working remotely was a new thing when the COVID-19 pandemic lockdowns began. At first the problems were technical: IT departments had to ramp up VPN (virtual private network) capacity, human resources and infosec departments had to adjust policies, and everyone struggled with microphones, cameras, and videoconferencing software.

Once those technical issues are resolved, the social issues become more apparent. How do you strike up a conversation as you used to do in the office? How do you know when it is appropriate to reach out to someone? How do you prevent loneliness and isolation?

Here are my top five favorite techniques Stack Overflow uses to make remote work successful on a social level.

Tip #1: If Anyone is Remote, We're All Remote

Meetings should be either 100 percent in-person, or 100 percent remote; no mixed meetings.

Ever been in a conference room with a bunch of people plus one person participating by phone or videoconference? It never works. The one remote participant can't hear the conversation, can't see what everyone else is seeing, and so on. He or she can't authentically participate.

At Stack Overflow we recognized this years ago and adopted a rule: If one person is remote, we're all remote. This means everyone who is physically present leaves the conference room, goes back to their desks, and we conduct the meeting using desktop videoconferencing.

During the COVID-19 lockdown your entire company may be remote, but this is a good policy to adopt when you return to the office.

This may not be an option for companies with open floor plans, however, where participants videoconferencing from their desks may disturb their neighbors. How can you make mixed meetings work? Where I've observed them working well required two ingredients: First, the conference-room design was meticulously refined and adjusted over time (this is rarer—and more expensive—than you would think); second, and the biggest determinant, was the degree to which all those in the meeting were aware of the remote participants. It requires a learned skill of being vigilant for clues that someone is having difficulty in participating and then taking corrective action. Everyone, not just the facilitator, needs to be mindful of this. ... "

Thursday, October 15, 2020

AI and Seismology

 An area we consulted on early and continue to follow.   Some comment here on why current, otherwise excellent pattern recognition techniques do not predict earthquakes.  Good update by CACM

AI Shakes up Seismology World

Commissioned by CACM Staff    By Samuel Greengard  

Artificial intelligence is helping researchers to better understand seismic events and to develop early warning systems that can save lives and protect property.

Few events on our planet are as complex as earthquakes. How, when and why they occur remains mostly a mystery, even with today's sophisticated instruments, sensors, and machines continuously monitoring and measuring seismic activity. "The vast number of variables and data points produce an extraordinarily complex picture," says Men-Andrin Meier, associate staff seismologist in the Seismological Laboratory of the California Institute of Technology (CalTech).

For decades, scientists have attempted to understand earthquakes using everything from satellite imagery to computer simulations, which have yielded modest and mixed results. Now scientists are turning to a new ally: artificial intelligence (AI), which is helping researchers better understand seismic events and develop early warning systems that can save lives and protect property.

"Machine learning and other forms of AI have emerged as valuable tools. They are advancing the science in a significant way," says Zachary Ross, an assistant professor of geophysics in the Division of Geological and Planetary Sciences at CalTech.

Finding Faults

The science surrounding earthquakes is extraordinarily complex. Unlike weather forecasting, which uses real-time data from satellites, sensors, and earth stations to track conditions as they occur, seismologists must rely on signals after an event. This data streams in from digital seismometers and broadband sensors on the ground. Measuring stress beneath the Earth's surface is next to impossible, because researchers don't have access to sensors buried deeply enough to measure underground forces.

Seismologists had largely given up on the idea of predicting earthquakes; at least, for the foreseeable future. However, the field is enjoying a renaissance thanks to machine learning and deep learning. Using connected sensors and algorithms, researchers are gaining insights into earthquake behavior, including how smaller swarms of temblors may or may not lead to a larger event. The researchers also are developing early alert systems that can protect property and lives. Says Meier, "We have gotten to the point where we don't have to choose between quantity and quality of the data."  .... " 

Thursday, June 25, 2020

Getting Pay for Data

Another project with aim at paying users for their data.  Links to our long term data as an asset view.

Andrew Yang Is Pushing Big Tech to Pay Users for Data
By The Verge
June 22, 2020

Andrew Yang wants people to get paid for the data they create on big tech platforms like Facebook and Google, and with a new project launching on Monday, he believes he can make it happen. ...

Yang's Data Dividend Project is a new program tasked with establishing data-as-property rights under privacy laws like the California Consumer Privacy Act (CCPA) all across the country. The program hopes to mobilize over 1 million people by the end of the year, focusing primarily on Californians, and "pave the way for a future in which all Americans can claim their data as a property right and receive payment" if they choose to share their data with platforms.

At the beginning of the year, the CCPA went into effect, granting consumers new control over their data online like the right to delete and opt out of the sale of their personal information. There's nothing in the law about tech companies paying for data (or, more specifically, paying them not to opt out), but Yang's new project is looking to show that the idea is popular with voters. The Data Dividend Project is betting on collective action as a means of changing the law and extending data property rights to users across the country. If this idea becomes law, Yang's team says it will work on behalf of users to help them get paid.

"We are completely outgunned by tech companies," Yang told The Verge. "We're just presented with these terms and conditions. No one ever reads them. You just click on them and hope for the best. And unfortunately, the best has not happened."  ... ' 


Saturday, May 30, 2020

Algorithm Selection, Design, as a Learning Problem

Good way to look at it.   Many good points, ultimately technical.

Technical Perspective: Algorithm Selection as a Learning Problem
By Avrim Blum
Communications of the ACM, June 2020, Vol. 63 No. 6, Page 86
10.1145/3394623

The following paper by Gupta and Roughgarden—"Data-Driven Algorithm Design"—addresses the issue that the best algorithm to use for many problems depends on what the input "looks like." Certain algorithms work better for certain types of inputs, whereas other algorithms work better for others. This is especially the case for NP-hard problems, where we do not expect to ever have algorithms that work well on all inputs: instead, we often have various heuristics that each work better in different settings. Moreover, heuristic strategies often have parameters or hyperparameters that must be set in some way.  ... " 

To view the accompanying paper, visit doi.acm.org/10.1145/3394625

Data-Driven Algorithm Design
By Rishi Gupta, Tim Roughgarden
Communications of the ACM, June 2020, Vol. 63 No. 6, Pages 87-94
10.1145/339462

The best algorithm for a computational problem generally depends on the "relevant inputs," a concept that depends on the application domain and often defies formal articulation. Although there is a large literature on empirical approaches to selecting the best algorithm for a given application domain, there has been surprisingly little theoretical analysis of the problem.

We model the problem of identifying a good algorithm from data as a statistical learning problem. Our framework captures several state-of-the-art empirical and theoretical approaches to the problem, and our results identify conditions under which these approaches are guaranteed to perform well. We interpret our results in the contexts of learning greedy heuristics, instance feature-based algorithm selection, and parameter tuning in machine learning.

Back to Top

1. Introduction
Rigorously comparing algorithms is hard. Two different algorithms for a computational problem generally have incomparable performance: one algorithm is better on some inputs but worse on the others. How can a theory advocate one of the algorithms over the other? The simplest and most common solution in the theoretical analysis of algorithms is to summarize the performance of an algorithm using a single number, such as its worst-case performance or its average-case performance with respect to an input distribution. This approach effectively advocates using the algorithm with the best summarizing value (e.g., the smallest worst-case running time).

Solving a problem "in practice" generally means identifying an algorithm that works well for most or all instances of interest. When the "instances of interest" are easy to specify formally in advance—say, planar graphs, the traditional analysis approaches often give accurate performance predictions and identify useful algorithms. However, the instances of interest commonly possess domain-specific features that defy formal articulation. Solving a problem in practice can require designing an algorithm that is optimized for the specific application domain, even though the special structure of its instances is not well understood. Although there is a large literature, spanning numerous communities, on empirical approaches to data-driven algorithm design (e.g., Fink11, Horvitz et al.14, Huang et al.15, Hutter et al.16, Kotthoff et al.18, Leyton-Brown et al.20), there has been surprisingly little theoretical analysis of the problem. One possible explanation is that worst-case analysis, which is the dominant algorithm analysis paradigm in theoretical computer science, is intentionally application agnostic.   ....  "

Monday, April 27, 2020

Critical Role of Human Performance in Software

Software is ultimately a collaboration between people and machines.  People still need to be adaptive in critical systems.     Which needs to lead to better designing of such systems.    Here quite a considerable look at the problem.

Revealing the Critical Role of Human Performance in Software
By David D. Woods, John Allspaw
Communications of the ACM, May 2020, Vol. 63 No. 5, Pages 64-67 10.1145/3380468

Four articles, published across the March through May issues of Communications, highlight how people are the unique source of the adaptive capacity essential to incident response in modern Internet-facing software systems. While it's reasonable for software engineering and operations communities to focus on the intricacies of technology, there is not much attention given to the intricacies of how people do their work. Ultimately, it is human performance that makes modern business-critical systems robust and resilient.

As business-critical software systems become more successful, they necessarily increase in complexity. Ironically, this complexity makes these systems inherently messy so that surprising incidents are part and parcel of the capability to provide services at larger scales and speeds.13 Studies in resilience engineering 2,12 reveal that people produce resilient performance in messy systems by doing the cognitive work of anomaly response; coordinating joint activity during events that threaten service outages; and revising their models of how the system actually works and malfunctions using lessons learned from incidents. People's resilient performance compensates for the messiness of systems, despite constant change.

Thus, incidents that threaten service outages are endemic as an emergent side effect of the increasing complexity of the interdependencies required to provide valuable services at scale. Incidents will continue to present challenges that require resilient performance, regardless of past reliability statistics. It is the cognitive work, coordination across roles, and adaptive capacity of people that resolve anomalies as they threaten to grow into service outages.4 To be more specific: modern business-critical systems work as well as they do because of the adaptive capabilities of people; and without the cognitive work that people engage in with each other, all software systems eventually fail (some with increasingly catastrophic impact, given the criticality of the services they provide). ... "