Showing posts with label behavior. Show all posts
Showing posts with label behavior. Show all posts

Friday, April 25, 2014

Video of gait analysis in action

This Security Solution Says It Can Figure Out If You Are Safe Or Dangerous By Scanning Your Skeleton (Business Insider - Australia)
They’re using a standard 2D surveillance camera to analyse a person’s motions and create a “skeletal map,” which shows the distance between joints and how they move. By comparing this map with future scans, Extreme Reality can detect any differences in movements that might indicate signs of stress and red flags. The system uses complex algorithms to detect these differences, and according to Extreme Reality, it is more than 90% accurate.

See for yourself...


Monday, April 8, 2013

I'm thinking of a number...

Affordable brainwave sensors could make typed passwords obsolete (The Verge)
The last hurdle involved determining what specific mental tasks would be best-suited to this type of authentication — the team wanted the interaction to be as user-friendly as possible. To find the most suitable tasks, the team the brainwaves of test subjects performing seven different mental activities to authenticate their identify. Researched showed that the best tasks for this setup were ones that users didn't mind repeating on a daily basis — the tasks need to be easy, but not too boring.
Interesting sort of behavioral biometric of the brain.

Wednesday, August 15, 2012

UPDATE II: Remotely-Staffed US-Mexico Border Crossings

FEB. 9, 2012: Self-service U.S.-Mexican border crossing could be replicated (NextGov)
Under the agency's plan, people carrying passports or other citizenship documents embedded with computer chips will approach kiosks to enter the United States. The kiosks will be mounted with digital scanners connected to a staffed entry point in El Paso, Texas, where CBP officers will see them through one-way video cameras and check their IDs. When near the scanner, the microchip, a radio frequency identification transmitter, signals a remote database to draw up biographical records and a photo of the document-holder. Officers then can confirm that the person in the database is the person on the camera.

AUG. 6, 2012
UPDATE: It looks like they're installing something along these lines in Nogales, Arizona.

Avatar Officer Installed at Arizona-Mexico Border Station (Yahoo)
[Customs and Border Protection] CBP is actually installing an updated version of the University of Arizona's kiosk—the original was tested at the station from December to March—to determine its ability to help enroll applicants in its Trusted Traveler programs at the Mexican border. The programs, also available for airline passengers, were created after 9/11 at various ports of entry into the U.S. to expedite preapproved, low-risk travelers through dedicated lanes and kiosks. All Trusted Traveler applicants must voluntarily undergo a background check against criminal, law-enforcement, customs, immigration, agriculture and terrorist databases. The process also includes biometric fingerprint checks and an interview with a CBP officer.

In Nogales, human CBP officers monitor the avatar-administered pilot-test interviews, which provide them with automated feedback uploaded wirelessly to an iPad tablet that these officers can use to conduct follow-up interviews.
AUG. 15, 2012
UPDATE II:
This robot border officer knows when you lie (Channel 3000)
Applicants for the program must undergo an interview and biometric fingerprinting to be eligible for the program -- both of which can be performed by the AVATAR kiosk.

Derrick said the kiosk could process travelers in five minutes.

Travelers simply stand in front of the unit -- which "looks like an ATM on steroids," according to Derrick -- and respond to yes/no questions asked in Spanish or English. "You speak to it like you speak to a person," he said.

Their answers are monitored, with any unusual physiological responses passed on to "a human field agent" who then subjects them to "a more careful interview process," said CBP spokesman Bill Brooks.

Unusual responses were not a sure sign of a lie, said Derrick. "There might be valid reasons for it beyond deception."

The computer uses three sensors to assess physiological responses: a microphone, which monitors vocal quality, pitch and frequency; an infrared camera, which looks at pupil dilation and where the eyes focus; and a high-definition camera recording facial expressions.
Much more at the link.

It looks like this is much more than a tele-presence or biometric document authentication app. If this article is accurate, U.S. Customs and Border Protection is actually piloting an automated deception detector in the field and has settled upon voice as the most important thing to measure.

Monday, July 2, 2012

A Visionary's Perspective

The Chartered Institute for IT has published a wide ranging interview, Getting a facial, with Professor Maja Pantic, from Imperial College, London.

Prof. Pantic has been working on automatic facial behaviour analysis. This type of research, if successful, could lead to a revolution in the way humans interact with technologies devoted to security, entertainment, health and the control of local physical environments in homes and offices.

The interview is long, wide-ranging, and worth reading in it's entirety.

I would, however, like to point out two passages that have great bearing on some of the themes we discuss regularly here.

Why computer science?
But with computers, it was something completely new; we just couldn’t predict where it would go. And we still don’t really know where it will go! At the time I started studying it was 1988 - it was the time before the internet - but I did like to play computer games and that was one of the reasons, for sure, that I looked into it. [ed. Emphasis added]

You never know where a new technology will lead, and those who fixate on a technology, as a thing in itself are missing something important. Technology only has meaning in what people do with it. The people who created the internet weren't trying to kill the record labels, revolutionize the banking industry, globalize the world market for fraud, or destroy the Mom & Pop retail sector while passing the savings on to you. The internet, much less its creators, didn't do it. The people it empowered did. 


Technologies empower people. Successful technologies tend to empower people to improve things. If a technology doesn't lead to improvement, in the vast majority of cases it will fail to catch on and/or fall into disuse. In the slim minority of remaining cases (a successful "bad" technology) people tend to agree not to produce them or place extreme conditions on their production and or use i.e. chem-bio weapons, or CFC's. There really aren't many "bad" technologies that people actually have to worry about. 


It makes far more sense to worry about people using technologies that are, on balance, "good" to do bad things — a lesson the anti-biometrics crowd should internalize. Moreover, you don't need high technology to do terrible things. The most terrible things that people have ever done to other people didn't require a whole lot of technology. They just required people who wanted to do them.


The interview also contains this passage on the working relationship between people and IT...

The detection software allows us to try to predict how atypical the behaviour is of a particular person. This may be due to nervousness or it may be due to an attempt to cover something up.

It’s very pretentious to say we will have vision-based deception detection software, but what we can show are the first signs of atypical or nervous behaviour. The human observer who is monitoring a person can see their scores and review their case. It’s more of an aid to the human observer rather than a clear-cut deception detector. That’s the whole security part.

There’s a lot of human / computer interaction involved.
It's not the tech; it's the people. 


Technology like biometrics or behavioral analysis isn't a robot overlord created to boss around people like security staff. It's a tool designed to help inform their trained human judgement. This informs issues like planning for exceptions to the security rule: lost ID's, missing biometrics, etc. Technology can't be held responsible for anything. It can help people become more efficient, and inform their judgement, but it can't do a job by itself.


Back to Three Sides of the Same Coin

Thursday, January 19, 2012

Biometrics and Biostatistics Revisited

[UPDATE: An uptick in recent articles like this one made me want to revisit this post. A quote from the article:
Ford showed off a prototype of this future health system, developed by BlueMetal Architects, at CES. The system will be able to capture biometric data from devices such as pacemakers and glucose monitors, and will also be able to accept voice input from the driver [emph. mine].
Maybe the term "biometrics" has a marketing cachet that "biostatistics" lacks; maybe for reasons of economy, journalists prefer to save ink, pixels, space and keystrokes. Whatever the reason, "biometrics" is a term that gets applied to every new application where technology is used to monitor or measure some aspect of the human body, its condition, motion or position. In being used to describe so many different things, "biometrics" has lost a great deal of precision of meaning.

DARPA has come up with another set of applications that some will be tempted to call biometrics (though DARPA doesn't call them that). DARPA is interested in collecting behavior metrics they call “cognitive fingerprints” or “human secrets” in order to develop an identity assurance model that relies on constant monitoring of an individual's unique behaviors while interacting with computer hardware.

Since...

Acta exteriora indicant interiora secreta; External actions indicate internal secrets

...maybe "actametrics" is a decent term for what DARPA's up to.

But you can see why (over)use of the term "biometrics" is so tempting. In this case, “cognitive fingerprint” and "human secret" is even more confusing than overusing "biometrics," and the folks at DARPA are geniuses that probably know their Latin scientific terms very well.

The original post, with minor edits, follows...]


We've danced around this topic a couple of times in the past (see links at the end of this post).

Biometrics and Biostatistics, the difference is subtle.

Biometric = body measure.
Biostatistic = body status, state, or condition.

[I'm no Latin scholar so I don't want to go to the mat for these definitions, but keeping them in mind helps me make sense of things when I read about all the uses for "biometrics" in health care and the health insurance industry. If there are any Latin (language) scholars out there who have interest and insight into this question, I'd love to hear from them.]

Biometrics for identity management concern facts about the physical human body that don't change (or don't change much) over time.

Biostatistics, on the other hand, are useful precisely because they change, sometimes radically over short or long time-frames.


Health care uses both biometrics and biostatistics. Health care providers use biometrics such as fingerprint and iris scanners for patient records management and logical and physical access control. They use biostatistics such as heart rate, weight, and EEG's, etc. for diagnostics, monitoring progress and assessing outcomes.

The Security sector is also seeking ways to use quantitative biostatistics to achieve better outcomes. I added the "quantitative" modifier because in many ways human beings have used non-quantified biostatistics (observations of behavior, for example) for security purposes since, well, forever. For example, we all know what someone means when they say that someone else was "acting suspiciously" or "looked guilty".

The computerized, measurement of biostatistics for security purposes, is at least as old as lie detectors. The novelty described by the article linked below is in bringing lie detectors out of the rigorously controlled laboratory environment and into more chaotic situations.

Face-reading lie detectors to be tested at UK airports (Airport-Technology.com)
The dual cameras in the system observe changes in facial expression and blood flow, with the first camera spotting signs of deceit such as lip-biting, nose-wrinkling, blinking and Freudian slips, and the second thermal imaging camera measuring flushing and blood-flow patterns around the eyes.


See also:
Behavioral Biometrics or Public Lie Detectors?
Mal-intent may be the future of security

Tuesday, November 8, 2011

Dishonesty detectors: Flawed technology?

We've been generally skeptical of applied behavioral biometrics (and biostatistics) in security applications. The author of the linked article, in the quoted text below nails the reason we're unlikely to see these technologies deployed for a very long time. It's a variation on the Return on Investment argument for adopting a given security solution.

Who knows what evil lurks in the hearts of men? (Smart Planet)
Even if we put aside reservations about self-reported scores on trials under unspecified conditions and grant that FAST is a technology in its infancy, that track record doesn’t inspire confidence. No one should be satisfied with a screening method that lets through more than one out of every five would-be plane bombers. Far more annoying, however, is that we don’t know exactly what the rates of false positives and false negatives were. A system that missed 20 percent of the terrorists in an airport would be bad but terrorists are rare, so disastrous mistakes would be few. But a system that snared 20 percent of innocent travelers as terrorist suspects would destroy air travel overnight.
Even while extending the author's benefit of the doubt, for airports especially the (negative) return on investment would be crippling.

In order to see how, let's imagine a system integrator's dream deployment and then see how that environment differs from an airport.

A system like this would detect all sorts of biostatistics and then compare them to some "normal" value, allow for a tolerance and then alert administrators if something is out of a certain range. If someone wanted to deploy a system like this and give it the best possible chance of success, it would make sense to seek out an environment where "normal" is a very narrow range, rather than a very wide range. The test designer would naturally gravitate toward a test environment where the test subjects make up a homogeneous group, a place where there is cultural uniformity, narrow age differences, low novelty, etc. If I'm the tester, I'm thinking prison first, then military base.

Now airports, by their very nature serve people of all ages from all over the world in various mental, physical and emotional states, not smooth sailing for testing sensitive equipment or training TSA staff to make judgments on small fluctuations of observed data. In airport use, either the error rates have to be very small, or the biostatistic examination would serve as only a small factor in security decision making.

Removing our benefit of the doubt by hypothesizing that those most likely to want to bring harm to global commerce and air travel might undertake training to control their biostatistics and subvert the security they afford, I'm guessing that airports will be one of the last places to adopt such a system. It'll be too costly in all sorts of ways for too little return.

See also:
Security: Biometrics vs. Biostatistics (Sept. 15, 2011)
Behavioral Biometrics or Public Lie Detectors? (Sept. 23, 2010)
Mal-intent may be the future of security (June 1, 2010)

Thursday, September 15, 2011

Biometrics vs. Biostatistics

[UPDATE: An uptick in recent articles like this one made me want to revisit this post. A quote from the article:
Ford showed off a prototype of this future health system, developed by BlueMetal Architects, at CES. The system will be able to capture biometric data from devices such as pacemakers and glucose monitors, and will also be able to accept voice input from the driver [emph. mine].
Maybe the term "biometrics" has a marketing cachet that "biostatistics" lacks; maybe for reasons of economy, journalists preserve to save ink, pixels, space and keystrokes.

The original post follows...]


We've danced around this topic a couple of times in the past (see links at the end of this post).

Biometrics and Biostatistics, the difference is subtle.

Biometric = body measure.
Biostatistic = body status, state, or condition.

[I'm no Latin scholar so I don't want to go to the mat for these definitions, but keeping them in mind helps me make sense of things when I read about all the uses for "biometrics" in health care and the health insurance industry. If there are any Latin (language) scholars out there who have interest and insight into this question, I'd love to hear from them.]

Biometrics for identity management concern facts about the physical human body that don't change (or don't change much) over time.

Biostatistics, on the other hand, are useful precisely because they change, sometimes radically over short or long time-frames.


Health care uses both biometrics and biostatistics. Health care providers use biometrics such as fingerprint and iris scanners for patient records management and logical and physical access control. They use biostatistics such as heart rate, weight, and EEG's, etc. for diagnostics, monitoring progress and assessing outcomes.

The Security sector is also seeking ways to use quantitative biostatistics to achieve better outcomes. I added the "quantitative" modifier because in many ways human beings have used non-quantified biostatistics (observations of behavior, for example) for security purposes since, well, forever. We all know what someone means when they say that someone else was "acting suspiciously".

The computerized, measurement of biostatistics for security purposes, is at least as old as lie detectors. The novelty described by the article linked below is in bringing lie detectors out of the rigorously controlled laboratory environment and into more chaotic situations.

Face-reading lie detectors to be tested at UK airports (Airport-Technology.com)
The dual cameras in the system observe changes in facial expression and blood flow, with the first camera spotting signs of deceit such as lip-biting, nose-wrinkling, blinking and Freudian slips, and the second thermal imaging camera measuring flushing and blood-flow patterns around the eyes.


See also:
Behavioral Biometrics or Public Lie Detectors?
Mal-intent may be the future of security

Tuesday, June 1, 2010

Mal-intent may be the future of security

The Sacramento Bee
This isn't related to identity management or biometrics but it is related to security.

Biometrics are used to establish a person's identity with a high degree of confidence so that the entity making the identification can accomplish further goals.

Identifying mal-intent does not seek to identify an individual but rather it seeks to predict undesired behavior through the detection of other behaviors.

Interestingly, both types of system represent attempts to predict the future.

One system -- the biometric one -- attempts to predict the future based on the identification of trusted or untrusted individuals. The assumption is that if I know who you are, I can make an educated prediction about what you will do.

The behavioral system, attempts to predict the future based upon what someone is doing now. If I know that people who do what you are doing tend to progress to other sorts of behavior, I can predict that you will also progress to that behavior. Or can I?

That's what the scientists are trying to figure out. Can you automate the judgments made by highly trained human observers of human behavior? Do people like Dr. Lightman from 'Lie to Me' exist? If so, can what they do be automated?