In Other News: RSA Encryption Attack, Meta AI Privacy, ShinyHunters Hacker Guilty Plea

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:  

Cybercriminals targeting hotels, booking sites and travel agents

Cybercriminals are deploying infostealer malware on the systems of hotels, booking sites and travel agents, and then use the access they have obtained to reach out to their customers through legitimate communication channels. The goal is to trick the targeted company’s customers to hand over payment card information, Akamai reported

Diplomatic phishing operations of Russia’s APT29 

Advertisement. Scroll to continue reading.

Mandiant has published a technical report describing the diplomatic phishing operations of Russia’s APT29 cyberespionage group since the start of the war in Ukraine. The cybersecurity firm has seen significant changes in the threat actor’s tooling and tradecraft. 

Spanish aerospace company targeted by North Korean hackers

A Spanish aerospace company has been targeted by the North Korean hacker group Lazarus with a previously unknown backdoor named LightlessCan. The attackers gained initial access to the company’s systems after posing as a recruiter for Meta, ESET reported.

ShadowSyndicate working with various ransomware groups

Group-IB has analyzed the activities of a threat actor named ShadowSyndicate, which has worked with various ransomware groups and affiliates since July 2022. There is evidence that the group was involved in Quantum, Nokoyawa, ALPHV, Royal, Cl0p, Cactus, and Play ransomware operations.

APT and financial attacks on industrial organizations 

Kaspersky has published a report summarizing the state-sponsored and financially motivated attacks launched against industrial organizations in the first half of 2023. 

Fort Lauderdale loses $1.2 million in BEC attack

The city of Fort Lauderdale in Florida has lost $1.2 million in a BEC attack that involved the attackers posing as a construction company the city has been working with, CNN reported. The cybercriminals provided documents that made their request for the money seem legitimate. 

French hacker pleads guilty in the US

Sebastien Raoult, aka Sezyo Kaizen, a French citizen and member of the notorious ShinyHunters cybercrime group, has pleaded guilty in a US court to fraud and identity theft charges. He was arrested last year in Morocco and extradited to the US in January. Authorities say Raoult and his accomplices stole hundreds of millions of user records and caused losses of over $6 million.

US sanctions Russian and Chinese firms over national security risks

The US has sanctioned companies in China, Russia and other countries, citing national security risks. 

Marvin attack on RSA encryption

A researcher has disclosed the details of Marvin, a new attack method against RSA encryption that demonstrates Bleichenbacher-style attacks work against many software implementations of the PKCS#1 v1.5 padding scheme for RSA key exchange that were until now believed to be safe. 

Meta describes privacy safeguards in new generative AI features

Meta has described the privacy safeguards implemented in its new generative AI features in an effort to protect users’ information. The new features include a conversational assistant, AI stickers, as well as 28 more AIs with unique personalities and interests. 

Related: In Other News: New Analysis of Snowden Files, Yubico Goes Public, Election Hacking

Related: In Other News: China Blames NSA for Hack, AI Jailbreaks, Netography Spin-Off

https://www.securityweek.com/in-other-news-rsa-encryption-attack-meta-ai-privacy-shinyhunters-hacker-guilty-plea/




Researchers Extract Sounds From Still Images on Smartphone Cameras

A group of academic researchers has devised a technique to extract sounds from still images captured using smartphone cameras with rolling shutter and movable lens structures.

The movement of camera hardware, such as the Complementary Metal-oxide–Semiconductor (CMOS) rolling shutters and the moving lenses used for Optical Image Stabilization (OIS) and Auto Focus (AF), create sounds that are modulated into images as imperceptible distortions.

These types of smartphone cameras, the researchers explain in a research paper (PDF), create a “point-of-view (POV) optical-acoustic side channel for acoustic eavesdropping” that requires no line of sight, nor the presence of an object within the camera’s field of view.

Focusing on the limitations of this side channel – which relies on a “suitable mechanical path from the sound source to the smartphone” to support sound propagation, the researchers extract and analyze the leaked acoustic information identifying with high accuracy different speakers, genders, and spoken digits.

The academics relied on machine learning to recover information from human speech broadcast by speakers, in the context of an attacker that has a malicious application running on the smartphone but does not have access to the device’s microphone.

However, the threat model assumes that the attacker can captures a video with the victim’s camera and that they can acquire speech samples of the target individuals beforehand, to use them as part of the learning process.

Using a dataset of 10,000 samples of signal-digit utterances, the researchers performed three classification tasks (gender, identity, and digit recognition) and trained their model for each task. They used Google Pixel, Samsung Galaxy, and Apple iPhone devices for the experiments.

Advertisement. Scroll to continue reading.

“Our evaluation with 10 smartphones on a spoken digit dataset reports 80.66%, 91.28%, and 99.67% accuracies on recognizing 10 spoken digits, 20 speakers, and 2 genders respectively,” the academics say.

Lower quality cameras, the researchers say, would limit the potential information leakage associated with this type of attack. Keeping smartphones away from speakers and adding vibration-isolation dampening materials between the phone and the transmitting surface should also help.

Smartphone makers can mitigate the attack through higher rolling shutter frequencies, random-code rolling shutters, tougher lens suspension springs, and lens locking mechanisms.

“We believe the high classification accuracies obtained in our evaluation and the related work using motion sensors suggest this optical-acoustic side channel can support more diverse malicious applications by incorporating speech reconstruction functionality in the signal processing pipeline,” the researchers added.

Related: Researchers Demo Electromagnetic Fault Injection Attacks on Drones

Related: Open Source Tool For Hunting Node.js Security Flaws

Related: New Speculative Execution Attack Against Apple M1 Chips

https://www.securityweek.com/researchers-extract-sounds-from-still-images-on-smartphone-cameras/




A Key US Government Surveillance Tool Should Face New Limits, a Divided Privacy Oversight Board Says

Federal spy agencies should be required to get court approval before reviewing the communications of U.S. citizens collected through a secretive foreign surveillance program, a sharply divided privacy oversight board recommended on Thursday.

The recommendation came in a report from a three-member Democratic majority of the Privacy and Civil Liberties Oversight Board, an independent agency within the executive branch, and was made despite the opposition of Biden administration officials who warn that such a requirement could snarl fast-moving terrorism and espionage investigations and weaken national security as a result.

The report comes as a White House push to secure the reauthorization of the program known as Section 702 of the Foreign Intelligence Surveillance Act is encountering major bipartisan opposition in Congress and during a spate of revelations that FBI employees have periodically mishandled access to a repository of intelligence gathered under the law, violations that have spurred outrage from civil liberties advocates.

Section 702 permits allow spy agencies without a warrant to collect swaths of emails and other communications from foreigners located abroad, even when those foreigners are in touch with people in the United States.

Officials in President Joe Biden’s administration have said the program is essential for disrupting foreign terror attacks, espionage operations from Russia and China and cyberattacks against critical infrastructure. But many Democratic and Republican lawmakers say they won’t vote to renew Section 702 when it expires at the end of the year without major changes targeting how the FBI uses foreign surveillance data to investigate Americans.

The privacy board recommended that the program be renewed despite being divided about what reforms were needed.

The opposition to reauthorization has united unusual bedfellows, bringing together civil liberties-minded Democrats who have long supported limits on government surveillance powers with Republicans still angry over what they see as abuses during the investigation into ties between Russia and Donald Trump’s 2016 presidential campaign.

Advertisement. Scroll to continue reading.

A central point of contention is analysts’ use of the foreign intelligence database to search for information about people, businesses or phone numbers located in the U.S. Those queries are permissible if there’s reason to believe they will retrieve foreign intelligence information. The FBI can also search the database if it believes it will turn up evidence of a crime, though a court order is required to review the results of those queries.

A succession of unsealed court opinions in recent months have revealed FBI violations in how those queries have been done, including improper searches of Section 702 databases for information related to the Jan. 6, 2021, riot at the U.S. Capitol and the 2020 protests following the police killing of George Floyd. FBI officials say significant safeguards have since been imposed.

In a recommendation Thursday that critics say would impose a significant hurdle and mark a dramatic break from the status quo, three members of the board said executive branch agencies, with limited exceptions, should have to get permission from the secretive Foreign Intelligence Surveillance Court to read the results of their database queries on U.S. citizens.

“The scale of U.S. person queries, the number of compliance issues surrounding U.S. person queries, and the failure of current law and procedures to protect U.S. persons compels the Board to recommend a new approach,” the report said.

Underscoring the blurred political lines of the debate, the two Republican members of the board joined the White House in objecting to the proposal as unduly burdensome. Those two members refused to sign on to the report issued by their colleagues and instead issued their own document lambasting some of the conclusions.

“Eliminating U.S. person queries, or making it bureaucratically infeasible to conduct them — as the Majority recommends — would effectively destroy the crucial portion of the program that enables the U.S. government to prevent, among other things, terrorist attacks on our soil,” they wrote.

Separately, the White House said that seeking a judge’s permission to read through intelligence that’s already been lawfully collected was legally unnecessary and would interminably slow national security investigations that require fast action.

“That is operationally unworkable and would blind us to information already in our holdings that, often, must be acted upon in time-sensitive ways in order to prevent lethal plotting on U.S. soil, the recruitment of spies by hostile actors, the hacking of U.S. companies, and more,” a National Security Council spokesperson said in a statement.

“We urge Congress to continue to work with us on alternative reforms that can strengthen Section 702 this reauthorization cycle without causing the type of detrimental effects to U.S. national security that this recommendation would generate,” the statement added.

Speaking Thursday at a luncheon at the National Press Club, Gen. Paul Nakasone, the director of the National Security Agency, said the U.S. must balance national security needs with civil liberties and privacy.

“It can’t be out of balance,” he said. “That’s my concern and just being able to balance that equation. And that’s something we always work towards.”

Jamil Jaffer, founder and executive director of the National Security Institute at George Mason University’s law school and a senior Justice Department official at the time the law was created, was more pointed. He said in a statement that the position of the board’s majority would create a “wall” between law enforcement and intelligence and “represent a drastic break from the consistent view of all four presidents to have served” since the Sept. 11, 2001 attacks.

The Privacy and Civil Liberties Oversight Board was formed in 2007 following a recommendation from the Sept. 11 commission, intended as a way to create checks and balances on the government’s expanding spy powers. The five members are nominated by the president and receive Senate approval.

https://www.securityweek.com/a-key-us-government-surveillance-tool-should-face-new-limits-a-divided-privacy-oversight-board-says/




UK’s New Online Safety Law Adds to Crackdown on Big Tech Companies

British lawmakers have approved an ambitious but controversial new internet safety law with wide-ranging powers to crack down on digital and social media companies like TikTok, Google, and Facebook and Instagram parent Meta.

The government says the online safety bill passed this week will make Britain the safest place in the world to be online. But digital rights groups say it threatens online privacy and freedom of speech.

The new law is the U.K.’s contribution to efforts in Europe and elsewhere to clamp down on the freewheeling tech industry dominated by U.S. companies. The European Union has its Digital Services Act, which took effect last month with similar provisions aimed at cleaning up social media for users in the 27-nation bloc.

Here’s a closer look at Britain’s law:

What is the Online Safety Law?

The sprawling piece of legislation has been in the works since 2021.

The new law requires social media platforms to take down illegal content, including child sexual abuse, hate speech and terrorism, revenge porn and posts promoting self-harm. They also will have to stop such content from appearing in the first place and give users more controls, including blocking anonymous trolls.

Advertisement. Scroll to continue reading.

The government says the law takes a “zero tolerance” approach to protecting kids by making platforms legally responsible for their online safety. Platforms will be required to stop children from accessing content that, while not illegal, could be harmful or not age-appropriate, including porn, bullying or, for example, glorifying eating disorders or providing instructions for suicide.

Social media platforms will be legally required to verify that users are old enough, typically 13, and porn websites will have to make sure users are 18.

The bill criminalizes some online activity, such as cyberflashing, which is sending someone unwanted explicit images.

What if Big Tech Doesn’t Comply?

The law applies to any internet company, no matter where it’s based as long as a U.K. user can access its services. Companies that don’t fall in line face fines of up to 18 million pounds ($22 million) or 10% of annual global sales, whichever is greater.

Senior managers at tech companies also face criminal prosecution and prison time if they fail to answer information requests from U.K. regulators. They’ll also be held criminally liable if their company fails to comply with regulators’ notices about child sex abuse and exploitation.

Ofcom, the U.K. communications regulator, will enforce the law. It will focus first on illegal content as the government takes a “phased approach” to bring it into force.

Beyond that, it’s unclear how the law will be enforced because details haven’t been provided.

What do Critics Say?

The U.K.-based Open Rights Group and the Electronic Frontier Foundation in the U.S. said that if tech companies have to ensure content is not harmful for children, they could end up being forced to choose between sanitizing their platforms or making users verify their ages by uploading official ID or using privacy-intrusive face scans to estimate how old they are.

The law also sets up a clash between the British government and tech companies over encryption technology. It gives regulators the power to require encrypted messaging services to install “accredited technology” to scan encrypted messages for terrorist or child sex abuse content.

Experts say that would provide a backdoor for private communications that ends up making everyone less safe.

Meta said last month that it plans to start adding end-to-end encryption to all Messenger chats by default by the end of year. But the U.K. government called on the company not to do so without measures to protect children from sex abuse and exploitation.

https://www.securityweek.com/uks-new-online-safety-law-adds-to-crackdown-on-big-tech-companies/




California Law Restricting Companies’ Use of Information From Kids Online Is Halted by Federal Judge

A federal judge has halted implementation of a California law intended to restrict companies’ use of information gathered from young internet users in order to protect the privacy of minors.

U.S. District Judge Beth Labson Freeman on Monday granted a preliminary injunction, saying the legislation interferes with firms’ use of the internet in ways the state has failed to justify.

The law would require businesses to report to the state on any product or service they offer on the internet that is likely to be accessed by those under 18, and provide plans to reduce any harms minors might suffer. It would also prohibit businesses from collecting most types of personal information about young internet users, including their physical locations.

“The State has no right to enforce obligations that would essentially press private companies into service as government censors,” Freeman wrote.

The judge wrote that while she is “keenly aware of the myriad harms that may befall children on the internet,” the law singles out for-profit businesses for restrictions that do not apply to other users, such as government agencies or nonprofits.

The law by Assembly Member Buffy Wicks, a Democrat from Oakland, passed both state legislative houses unanimously last year and was due to take effect in July 2024.

It was challenged by NetChoice, a commercial association whose members include Google, Amazon, Meta and TikTok. In a statement to the San Francisco Chronicle, NetChoice attorney Chris Marchese praised the judge’s decision “to prevent regulators from violating the free speech and online privacy rights of Californians, their families and their businesses as our case proceeds.”

Advertisement. Scroll to continue reading.

Attorney General Rob Bonta’s office said it was disappointed by the ruling and declined to comment further. The state could appeal the injunction to the Ninth U.S. Circuit Court of Appeals in San Francisco, the Chronicle said.

Related: Apple, Civil Liberty Groups Condemn UK Online Safety Bill

Related: Ransomware Criminals Are Dumping Kids’ Private Files Online After School Hacks

Related: Microsoft Will Pay $20M to Settle US Charges of Illegally Collecting Children’s Data

https://www.securityweek.com/california-law-restricting-companies-use-of-information-from-kids-online-is-halted-by-federal-judge/




TikTok Is Hit With $368 Million Fine Under Europe’s Strict Data Privacy Rules

European regulators slapped TikTok with a $368 million fine on Friday for failing to protect children’s privacy, the first time that the popular short video-sharing app has been punished for breaching Europe’s strict data privacy rules.

Ireland’s Data Protection Commission, the lead privacy regulator for Big Tech companies whose European headquarters are largely in Dublin, said it was fining TikTok 345 million euros and reprimanding the platform for the violations dating to the second half of 2020.

The investigation found that the sign-up process for teen users resulted in settings that made their accounts public by default, allowing anyone to view and comment on their videos. Those default settings also posed a risk to children under 13 who gained access to the platform even though they’re not allowed.

Also, a “family pairing” feature designed for parents to manage settings wasn’t strict enough, allowing adults to turn on direct messaging for users aged 16 and 17 without their consent. And it nudged teen users into more “privacy intrusive” options when signing up and posting videos, the watchdog said.

TikTok said in a statement that it disagrees with the decision, “particularly the level of the fine imposed.”

The company pointed out that the regulator’s criticisms focused on features and settings dating back three years. TikTok said it had made changes well before the investigation began in September 2021, including making all accounts for teens under 16 private by default and disabling direct messaging for 13- to 15-year-olds.

“Most of the decision’s criticisms are no longer relevant as a result of measures we introduced at the start of 2021 — several months before the investigation began,” TikTok’s head of privacy for Europe, Elaine Fox, wrote in a blog post.

Advertisement. Scroll to continue reading.

The Irish regulator has been criticized for not moving fast enough in its investigations into Big Tech companies since EU privacy laws took effect in 2018. For TikTok, German and Italian regulators disagreed with parts of a draft decision issued a year ago, delaying it further.

To avoid new bottlenecks, the Brussels headquarters of the 27-nation bloc has been given the job of enforcing new regulations to foster digital competition and clean up social media content — rules aimed at maintaining its position as a global leader in tech regulation.

In response to initial German objections, Europe’s top panel of data regulators said TikTok nudged teen users with pop-up notices that failed to lay out their choices in a neutral and objective way.

“Social media companies have a responsibility to avoid presenting choices to users, especially children, in an unfair manner — particularly if that presentation can nudge people into making decisions that violate their privacy interests,” said Anu Talus, chair of the European Data Protection Board.

The Irish watchdog, meanwhile, also had examined TikTok’s measures to verify whether users are at least 13 but found they didn’t break any rules.

The regulator is still carrying out a second investigation into whether TikTok complied with the EU’s General Data Protection Regulation when it transferred users’ personal information to China, where its owner, ByteDance, is based.

TikTok has faced accusations it poses a security risk over fears that users’ sensitive information could end up in China. It has embarked on a project to localize European user data to address those concerns: opening a data center in Dublin this month, which will be the first of three on the continent.

Data privacy regulators in Britain, which left the EU in January 2020, fined TikTok 12.7 million pounds ($15.7 million) in April for misusing children’s data and violating other protections for young users’ personal information.

Instagram, WhatsApp and their owner Meta are among other tech giants that have been hit with big fines by the Irish regulator over the past year.

Related: TikTok fined €750,000 for Violating Children’s Privacy

Related: Executive Fired From TikTok’s Chinese Owner Says Beijing Had Access to App Data in Termination Suit

Related: TikTok’s Trials and Tribulations Continue With UK Data Protection Fine

https://www.securityweek.com/tiktok-is-hit-with-368-million-fine-under-europes-strict-data-privacy-rules/




Imagine Making Shadowy Data Brokers Erase Your Personal Info. Californians May Soon Live the Dream

You may not know it, but thousands of often shadowy companies routinely traffic in personal data you probably never agreed to share — everything from your real-time location information to private financial details. Even if you could identify these data brokers, there isn’t much you can do about their activities, including in California, which has some of the strongest digital privacy laws in the U.S.

That’s on the verge of changing. Both houses of the California state Legislature have passed the Delete Act, which would establish a “one stop shop” where individuals could order hundreds of data brokers registered in the state to delete their personal data — and to cease acquiring and selling it in the future — with a single request.

The Delete Act isn’t law yet. Democratic Gov. Gavin Newsom still has to decide whether to sign the measure, whose impact could potentially extend well beyond state lines given California’s history of setting similar trends.

Here’s what you need to know.

What the Bill Does

While California law already gives individuals the right to request data deletion, doing so currently require making separate requests to hundreds of data brokers registered in the state, many with their own unique requirements for drafting and handling such requests. Even then, nothing stops these companies from simply reacquiring the data after they delete it.

The Delete Act would require the state’s new privacy office, the California Privacy Protection Agency, to set up a website where consumers can verify their identity and then make a single request to delete their personal data held by data brokers and to opt out of future tracking. Proponents call it a “do not track” signal similar to the “do not call” list for telemarketers maintained by the Federal Trade Commission.

Advertisement. Scroll to continue reading.

California already regulates data brokers, but the Delete Act would strengthen those provisions by requiring the companies to disclose more information about the data they collect on consumers and beefing up the state’s enforcement mechanisms.

Meet the Data Brokers

The Electronic Privacy Information Center, a Washington, D.C., nonprofit focused on bolstering the right to privacy, defines data brokers as companies that collect and categorize personal information, usually to build profiles on millions of Americans that the companies can then rent, sell or use to provide services.

The data they collect, per EPIC, can include: “names, addresses, telephone numbers, email addresses, gender, age, marital status, children, education, profession, income, political preferences, and cars and real estate owned.”

That is in addition to “information on an individual’s purchases, where they shop, and how they pay for their purchases,” plus “health information, the sites we visit online, and the advertisements we click on. And thanks to the proliferation of smartphones and wearables, data brokers collect and sell real-time location data.”

Privacy advocates have warned for years that location and seemingly non-specific personal data — often collected by advertisers and amassed and sold by brokers — can be used to identify individuals. They also charge that the data often isn’t well secured and that the brokers aren’t covered by laws that require the clear consent of the person being tracked. They have argued for both legal and technical protections so consumers can push back.

Are Data Brokers That Bad?

Data brokers say they get a bad rap for serving a vital need.

Dan Smith, president of the Consumer Data Industry Association, which describes itself as “the voice of the consumer reporting industry,” called the Delete Act “severely flawed” and warned in a Wednesday release that the change could lead to unintended consequences by undermining consumer fraud protections, hurting the competitiveness of small businesses and entrenching big platforms such as Facebook and Google that collect vast amounts of consumer data but don’t sell it.

Smith also argued that the heart of the bill — the one-stop data deletion program — could potentially allow malicious outsiders to impersonate consumers and delete their data without permission. The organization also argues that the cost of the legislation will be much greater than California regulators currently suggest.

What Abuse of Data Broker Information Looks Like

In other respects, though, the information collected by these companies can be startlingly easy to abuse. The general lack of U.S. restrictions on what brokers can do with the vast amount of data they collect means there’s aren’t many legal protections to prevent outsiders from spying on politicians, celebrities and just about anyone who is a target of idle curiosity, or malice.

In mid-2021, for instance, the U.S. Conference of Catholic Bishops announced the resignation of its top administrative official, Monsignor Jeffrey Burrill, ahead of a report by the Catholic news outlet The Pillar probing his private romantic life. The Pillar said it obtained “commercially available” location data from an unnamed vendor that was “correlated” to Burrill’s phone to determine he had visited gay bars and private residences while using Grindr, a dating app popular with gay people.

The Pillar alleged “serial sexual misconduct” by Burrill, as homosexual activity is considered sinful under Catholic doctrine and priests are expected to remain celibate. Following an extended leave, Burrill resumed his ministry in the small town of West Salem, Wisconsin, according to the Catholic News Service.

https://www.securityweek.com/imagine-making-shadowy-data-brokers-erase-your-personal-info-californians-may-soon-live-the-dream/




California Settles With Google Over Location Privacy Practices for $93 Million

Search giant Google agreed to a $93 million settlement with the state of California on Thursday over its location-privacy practices.

The settlement follows a $391.5 million settlement with 40 states, reached in November 2022, to resolve an investigation into how the company tracked users’ locations.

The states’ investigation was sparked by a 2018 Associated Press story, which found that Google continued to track people’s location data even after they opted out of such tracking by disabling a feature the company called “location history.”

“Our investigation revealed that Google was telling its users one thing — that it would no longer track their location once they opted out — but doing the opposite and continuing to track its users’ movements for its own commercial gain. That’s unacceptable, and we’re holding Google accountable with today’s settlement,” Attorney General Rob Bonta said in a statement.

As part of the settlement, in which Google admitted no wrongdoing, the company also agreed to a number of restrictions, including providing more transparency about location tracking, disclosing to users that their location information may be used for ad personalization, and showing additional information to users when enabling location-related account settings.

“Consistent with improvements we’ve made in recent years, we have settled this matter, which was based on outdated product policies that we changed years ago,” Google said in a statement.

Related: South Korea Fines Google, Meta Over Privacy Violations

Advertisement. Scroll to continue reading.

Related: Spotify Fined $5 Million for Breaching EU Data Rules

Related: Norway Threatens $100,000 Daily Fine on Meta Over Data

https://www.securityweek.com/california-settles-with-google-over-location-privacy-practices-for-93-million/




AI, Kurapati (Ceo di Clearbox AI): ‘Dati sintetici per aiutare le aziende’

Aiutare le aziende ad usare al meglio l’Intelligenza Artificiale, in modo semplice e corretto tramite i dati sintetici. Questa in sintesi la mission di Clearbox AI, una startup torinese specializzata in AI, la cui Ceo Shalini Kurapati è stata premiata dalla Commissione Ue come una delle principali ‘Lady Tech’ europee. Kurapati prenderà parte all’evento ‘State of Privacy ‘23’ organizzato dal Garante Privacy il 18 settembre a Roma, per parlare dell’impatto dell’AI sulla società.

Key4biz. Clearbox AI, start up di intelligenza artificiale, per fare cosa?

Shalini Kurapati. Clearbox AI è una startup tech italiana che aiuta le aziende a lanciare progetti di Intelligenza Artificiale attraverso l’utilizzo di Dati Sintetici. Nasciamo nel 2019 col supporto dell’Incubatore del Politecnico di Torino, abbiamo fondato la società con 4 co-fondatori, me compresa, che si sono uniti dopo una lunga esperienza di ricerca e professionale in molti paesi europei. La nostra missione: comprendere gli ostacoli che le aziende incontrano nello sviluppo di Intelligenza Artificiale.

Key4biz. Quali sono i principali ostacoli per le aziende?

Shalini Kurapati. Abbiamo scoperto che molto spesso queste sfide sono legate ai dati, quando questi sono sensibili e difficili da gestire a livello di privacy, la loro quantità non è sufficiente, o non sono abbastanza rappresentativi per tutte le fasce di popolazione per garantire risultati di successo.

Key4biz. E’ qui che entrano in gioco i Dati Sintetici?

Shalini Kurapati. Sì. I Dati Sintetici possono risolvere questi problemi. Sono generati artificialmente da algoritmi AI sulla base dei dati originali, dei quali mantengono le proprietà statistiche e il potere predittivo, risultando quindi realistici. Essendo simili ma non uguali ai dati reali, non contengono informazioni personali e possono essere condivisi rispettando i regolamenti di privacy, come il GDPR. Offriamo un prodotto/software basato sulla nostra tecnologia proprietaria che genera dati sintetici di alta qualità per le aziende che vogliono iniziare e accelerare il loro percorso di Intelligenza artificiale. Il nostro team ha una duplice anima: forti radici nel mondo R&D con lauree dalle migliori università tecnologiche in Europa, che vanno mano nella mano con un approccio ingegneristico e pratico nel risolvere i problemi dei clienti. Le strade professionali e personali dei componenti del gruppo hanno attraversato l’Europa per convergere a Torino, dove è nata la missione Clearbox AI: creare valore per le imprese attraverso le tecnologie IA, rispettandone i principi etici.

Key4biz. Ci può fare qualche esempio concreto di come i Dati Sintetici possono aiutare le aziende?

Shalini Kurapati. Oggi avere un modello di Intelligenza Artificiale è molto facile. Basta un download. Ma la sfida vera è avere dati giusti dal punto di vista dell’accesso privacy e della qualità. I dati sintetici sono una delle soluzioni a questo problema. Sono generati artificialmente tramite algoritmi. Noi produciamo dati sintetici per due motivi principali: la tutela della privacy e poi in molti casi i data set non sono rappresentativi per diversi motivi, il che può creare pregiudizi (bias) dell’algoritmo. Questo perché l’algoritmo pensa erroneamente che questo set di dati rappresenti la realtà, ma non è così. I dati sintetici possono aumentare questo data set sbilanciato in modo tale da far rappresentare la realtà.  

Key4biz. Ad esempio?

Shalini Kurapati. Ad esempio, sviluppiamo un algoritmo per riconoscere un tumore sulla pelle. L’algoritmo deve capire cosa vuol dire un algoritmo sulla pelle. Noi forniamo diversi esempi di tumori. Ma se forniamo soltanto esempi con carnagione bianca questo algoritmo non funziona per altre carnagioni di pelle. Quindi funziona soltanto per questo tipo di pelle. Un dato non rappresentativo può danneggiare altre persone se usiamo questo algoritmo senza testare tutti i tipi di persone.     

Key4biz. E ancora?

Shalini Kurapati. Storicamente le donne non erano tantissime nel mondo del lavoro. Quindi, se alleniamo un algoritmo soltanto con dati storici, se anche mettiamo in produzione con dati attuali, l’algoritmo pensa che i dati storici sono la realtà. Magari prende delle decisioni sulla base del fatto che 30 anni fa la percentuale di donne al lavoro erano meno e quindi prende decisioni in base a dati ormai superati. Qui vengono in soccorso i dati sintetici, che prendono sempre in considerazione la realtà.

Key4biz. Un altro esempio dal campo medico?

Shalini Kurapati. Per tanto tempo i dati della ricerca sono sempre stati presi su degli uomini. Per tante malattie i sintomi delle donne non sono presenti e sono troppo pochi. Per esempio, per un infarto i sintomi di un uomo sono male al cuore e al braccio. Per una donna, invece, può essere mal di schiena. Però, se alleniamo un modello è successo anche questo, che un’azienda che ha sviluppato un algoritmo di intelligenza artificiale per riconoscere una malattia dai sintomi, per un uomo ha detto di andare subito al pronto soccorso. Ma per una donna ha detto che era un attacco di panico, calmati! Invece era un infarto. Quando parliamo di responsabilità, un algoritmo soprattutto per una applicazione per prendere decisioni su un curriculum o prendere decisioni su un mutuo, o decisioni sulla salute, quindi un impatto grande, dobbiamo avere una metodologia per capire quali dati stiamo usando. Come possiamo migliorare questo. Lo stesso discorso vale anche per il riconoscimento di frodi per banche e assicurazioni. Qui il problema è che gli esempi di frodi non sono molto numerosi ed è quindi difficile per l’algoritmo riconoscerle. Grazie ai dati sintetici possiamo fornire all’algoritmo più esempi per riconoscere le frodi.

Key4biz. Quali sono le aree di competenza del team?

Shalini Kurapati. Le aree di competenza del team spaziano tra machine learning, data science, data privacy, uncertainty quantification, project management, innovazione e sviluppo software, e sono state fondamentali per creare una visione condivisa.

Key4biz. La Commissione Europea l’ha premiata come una delle 50 più geniali e innovative ‘Lady Tech’. Per questo motivo è entrata nel progetto pilota, voluto da Bruxelles, per supportare start up ad elevato contenuto tecnologico guidate da donne. Come considera l’approccio di Bruxelles sull’IA? (vedi AI ACT)

Shalini Kurapati. Sì, siamo molto contenti di essere stati selezionati tra i vincitori del progetto Women TechEU, finanziato dalla Commissione Europea. L’iniziativa ha come obiettivo il supporto alle startup deep-tech guidate da donne per valorizzare il talento e favorire un’innovazione più inclusiva nell’ecosistema tech europeo. In questo senso, i dati sintetici che produciamo giocano un ruolo fondamentale per gli obiettivi del bando, per i motivi di mitigazione bias che abbiamo raccontato. Anche la nostra missione aziendale è in linea con questi fini perché si colloca all’intersezione tra tecnologia ed etica dell’Intelligenza Artificiale. In particolare, utilizzeremo i finanziamenti della Commissione Europea per creare un modulo basato sui dati sintetici che punta a diminuire la presenza di bias nei progetti di Intelligenza Artificiale. Credo che a livello europeo si stiano facendo molti passi avanti nella promozione della conoscenza e creazione di framework legati all’AI. Uno su tutti è l’AI Act, apripista nell’istituzione di regole esaustive e realmente applicabili per garantire la sicurezza dell’IA e l’innovazione responsabile, attraverso un approccio basato sul rischio delle applicazioni IA. Nonostante alcuni limiti (se ne è parlato per anni e ci sono sempre discussioni in corso) e sebbene potrebbe richiedere da 2 a 3 anni per entrare in vigore, ci sono comunque molte ragioni per sostenerlo fortemente. Ha creato un punto di riferimento e un quadro per la cooperazione nella regolamentazione globale dell’IA. Ha attivato opportunità per adottare codici di condotta e patti sull’IA per iniziare a mettere in pratica i principi della regolamentazione mentre aspettiamo che entrino in vigore e per cominciare ad adattarsi all’evoluzione della tecnologia IA. A complicare il tentativo dell’Ue, però, è anche la portata di una norma che, per essere efficace, deve essere riconosciuta a livello globale. Altrimenti rischia di essere agevolmente aggirata. Infatti le principali società che sviluppano l’AI nel mondo sono oggi Microsoft/Open AI, Google, Meta, Tesla, solo per citarne alcune: un panorama che coinvolge gli Stati Uniti, ma che inizia a coinvolgere anche la Cina. E gli Stati Uniti, per il momento, non hanno alcuna intenzione di frenare la ricerca e lo sviluppo: per quanto l’amministrazione Biden sia consapevole dei rischi, dopo tanti discorsi tutto ciò che è stato fatto ad oggi – di fatto – sono una serie di misure non legislative che suggeriscono ai colossi dell’AI come dovrebbero comportarsi per auto-regolare la propria tecnologia. Dobbiamo tutti essere molto interessati e proattivi nell’implementare i requisiti dell’AI Act, non solo per essere conformi, ma per garantirci un futuro responsabile!

Key4biz. Come governare i rischi dell’AI e come l’Italia, secondo lei, dovrebbe sostenere di più lo sviluppo dell’AI in Italia?

Shalini Kurapati. Spesso si parla dell’Italia come terra di cultura e di buon cibo, il che è assolutamente vero, ma dovremmo considerare che l’Italia ha già una lunga storia e saper-fare nell’industrializzazione e soprattutto nell’automazione industriale. In termini di robot density (un’importante indicatore dell’automazione industriale), l’Italia è davanti a Francia e Canada. Tuttavia, anche se non si può dire lo stesso dell’adozione delle applicazioni di IA e dell’innovazione guidata dai dati, l’Italia ha un grande potenziale. Abbiamo bisogno di una bella spinta nella giusta direzione in termini di creazione di maggiore consapevolezza e di cambiamento di mentalità. Ad oggi siamo molto felici di riscontrare sempre più interesse da parte delle aziende italiane nell’approfondire come si può implementare l’AI in maniera efficiente all’interno dei processi e, da parte nostra, cerchiamo da sempre di diffondere messaggi precisi per aiutarle a beneficiarne. Ad esempio, che l’AI non è appannaggio solo delle grandi aziende. Allo stesso tempo, però, bisogna avere una conoscenza precisa degli obiettivi per i quali si vuole usare l’AI, affidarsi a delle professionalità specifiche e ridimensionare le aspettative dell’AI come “panacea di tutti i mali”.

“State of Privacy ’23”, il 18 settembre l’evento del Garante. Scopri il programma

https://www.key4biz.it/ai-kurapati-ceo-di-clearbox-ai-dati-sintetici-per-aiutare-le-aziende/459453/




Rifiuti e videosorveglianza, multa di 45mila euro al Comune di Modica per violazione della privacy

Una multa di 45mila euro è stata comminata dal Garante Privacy al Comune di Modica per aver installato alcune telecamere per il controllo della raccolta differenziata dei rifiuti in violazione della disciplina che tutela i dati personali.

Il Comune, per contrastare il fenomeno diffuso dell’abbandono dei rifiuti, aveva incaricato due ditte, dell’acquisto, installazione e manutenzione di telecamere fisse, e della raccolta e analisi dei filmati relativi alle violazioni. Ma anche le società dunque operavano in modo illecito, ragion per cui entrambe sono state sanzionate anch’esse dal Garante, l’una per 10.000 euro, per non essere mai stata nominata responsabile del trattamento, e l’altra per 5.000 euro, per essere stata nominata responsabile in ritardo.

La denuncia di un cittadino e la violazione delle norme privacy

L’intervento dell’Autorità segue le segnalazioni di un cittadino che lamentava la ricezione di alcune multe per aver conferito i rifiuti indifferenziati in modo errato. Gli accertamenti della violazione sarebbero avvenuti più di un mese dopo la registrazione dei filmati, effettuata senza che i cittadini fossero stati adeguatamente informati della presenza delle telecamere e del trattamento dei dati. Il Comune infatti aveva apposto un cartello direttamente sul cassonetto, non facilmente visibile e per di più privo delle informazioni necessarie.

Il Municipio inoltre non aveva individuato i tempi di conservazione dei dati e non aveva nominato, prima dell’inizio del trattamento, le due aziende sopracitate quali responsabili del trattamento dati, come previsto dalla normativa privacy.

Il trattamento di dati personali mediante sistemi di videosorveglianza da parte di soggetti pubblici è generalmente ammesso se è necessario per adempiere un obbligo legale e la gestione dei rifiuti rientra tra le attività istituzionali affidate agli enti locali. Anche in presenza di una condizione di liceità il titolare del trattamento, ha ribadito il Garante, è in ogni caso tenuto a rispettare i principi in materia di protezione dei dati, fra i quali quelli di liceità, correttezza e trasparenza. In particolare, è necessario adottare misure appropriate per fornire all’interessato tutte le informazioni previste dal GDPR in forma concisa, trasparente, intelligibile e facilmente accessibile.

Ai fini dell’applicazione delle sanzioni il Garante ha tenuto conto del fatto che il trattamento ha riguardato potenzialmente i dati dei residenti del Comune (circa 53.000 interessati) e dei soggetti non residenti (il cui numero non è quantificabile).

Di contro, l’Autorità ha considerato il comportamento non doloso del Municipio e delle aziende, nonché l’assenza di precedenti violazioni a loro carico.

Per approfondire clicca qui.

https://www.key4biz.it/rifiuti-e-videosorveglianza-multa-di-45mila-euro-al-comune-di-modica-per-violazione-della-privacy/458936/