{"id":35929,"date":"2022-02-18T11:41:18","date_gmt":"2022-02-18T16:41:18","guid":{"rendered":"https:\/\/www.bu.edu\/cise\/?p=35929"},"modified":"2022-02-21T23:31:56","modified_gmt":"2022-02-22T04:31:56","slug":"irs-stares-technological-advancement-issues-in-the-face","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/cise\/irs-stares-technological-advancement-issues-in-the-face\/","title":{"rendered":"IRS Stares Technological Advancement Issues in the Face"},"content":{"rendered":"<p><img loading=\"lazy\" src=\"\/cise\/files\/2022\/02\/SeekPng.com_face-icon-png_2037143.png\" alt=\"\" width=\"426\" height=\"461\" class=\"alignnone wp-image-35930 aligncenter\" \/><\/p>\n<p><span>Almost every American is used to sharing information with the Internal Revenue Service (IRS), but people were about to become eerily intimate with the agency after they announced the launch of a new website requirement:\u00a0 live video identity verification. The agency partnered with the third-party company ID.me to prevent scammers from benefiting off of the chaos of the pandemic. Although this new security measure was meant to protect citizens, it can end up doing more harm than good.<\/span><\/p>\n<p><span>The government has dealt with a higher than average number of con artists since the start of the pandemic. In late 2020, intelligence agencies revealed that<\/span><a href=\"https:\/\/www.npr.org\/2020\/12\/15\/946776718\/u-s-scrambles-to-understand-major-computer-hack-but-says-little\"><span>\u00a0Russian hackers had been successfully infiltrating<\/span><\/a><span>\u00a0U.S government agencies and placing malware for six months. The IRS was not one of the agencies affected, but it uses a lot of the same security infrastructure.\u00a0<\/span><span>\u00a0<\/span><\/p>\n<p><span>There are also cases in other countries where personal information is gained by \u201cmission creep\u201d.\u00a0 Data from government projects like COVID-19 contact tracing were seized by police and used for unrelated purposes.\u00a0<\/span><a href=\"https:\/\/www.washingtonpost.com\/world\/2022\/01\/13\/german-covid-contact-tracing-app-luca\/\"><span>German police<\/span><\/a><span>\u00a0used COVID tracking data to investigate a restaurant death, and\u00a0<\/span><a href=\"https:\/\/theconversation.com\/police-debacle-leaves-the-mcgowan-government-battling-to-rebuild-public-trust-in-the-safewa-app-162850\"><span>Australian police<\/span><\/a><span>\u00a0officials used it to investigate murders without public knowledge or consent.\u00a0<\/span><\/p>\n<p><span>The IRS\u2019s solution to protecting private information: capture live footage of everyone trying to access certain tax services, like their personal profile, on the government website. This impromptu image would then be cross referenced with the photo ID already on file and confirmed. <strong>Ari Trachtenberg<\/strong>, CISE faculty affiliate and a researcher in the Center for Reliable Information Systems and Cyber Security at the Hariri Institute, had concerns about the project. \u201c<\/span><span>The downside of such a system is that both the government and third parties have a terrible track record of maintaining the privacy of sensitive information,\u201d Trachtenberg said.\u00a0<\/span><\/p>\n<p><span>Not only did the plan itself have some flaws, but the tools being used have also been criticized.\u00a0<\/span><span>Facial recognition systems actually use a combination of two different technologies. Both digital processing and artificial intelligence (AI) are used to measure a person\u2019s facial features, and then find a matching image in a database. \u201c<\/span><span>These technologies typically have very high accuracy, in part because these biometric features tend to be fairly stable over a person\u2019s lifetime,\u201d Trachtenberg stated.\u00a0 \u201cAt the same time, they have also had spectacular and very public failures.\u201d\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span>Some of these failures center around larger systemic issues with photo databases.\u00a0<\/span><a href=\"https:\/\/www.aclu.org\/news\/privacy-technology\/how-artificial-intelligence-can-deepen-racial-and-economic-inequities\/\"><span>Studies<\/span><\/a><span>\u00a0suggest that certain algorithms have trouble identifying specific minority groups. AI systems are trained using a database of faces, and because most of these faces belong to white people, the technology may be less likely to\u00a0<\/span><a href=\"https:\/\/www.cnn.com\/2021\/04\/29\/tech\/nijeer-parks-facial-recognition-police-arrest\/index.html\"><span>correctly identify people of color<\/span><\/a><span>.\u00a0 Using these technologies can result in an additional barrier for certain groups and companies can be liable, regardless of intent, in a civil lawsuit.\u00a0<\/span><\/p>\n<p><span>The systemic flaws in facial recognition software design and implementation become a nation-wide problem if this technology is used in government processes. Andrew Sellars, a clinical associate professor of law at Boston University, believes that technologies should have a rigorous vetting process before any decisions are made. \u201c<\/span><span>It puts a spotlight on the growing recognition that there needs to be more of an impact assessment,\u201d said Sellars.\u00a0 \u201cWhat biases could be involved, who is accountable, and do we understand the machine learning process that got us this technology?\u201d<\/span><\/p>\n<p><span><a href=\"https:\/\/apnews.com\/article\/technology-business-data-privacy-ron-wyden-f955f9f3ad074f0263018ef2ae38ea01\">The IRS recently dropped the facial recognition project, just a few weeks after announcing it, following much criticism<\/a>.\u00a0 The agency announced that it will use different security measures that do not involve facial recognition.\u00a0<\/span><\/p>\n<p><span>Trying to balance security, privacy, and equity may seem like a riddle with no answer at times, but Trachtenberg offers some insight to potential fixes. \u201c<\/span><span>I don\u2019t think that there is a foolproof solution, but one approach that has worked reasonably well in the security community is to allow as much transparency as possible.\u201d This means publishing photo identification system methods and opening them for public comment, or allowing third parties to test the systems and publish their findings.<\/span><\/p>\n<p><span>Sellars advocates for a better screening process before any new systems are actually implemented.\u00a0\u00a0<\/span><span>\u00a0\u201cIt calls for human impact to be a larger part of the discussion when adopting technology,\u201d he said.\u00a0 \u201cOnce something has already been created, it\u2019s very hard to take that thing away.\u201d\u00a0<\/span><\/p>\n<p><span>Lawyers and cybersecurity experts are having serious discussions about the existence of facial recognition technology, and if it should be used at all.\u00a0 They argue that there are major faults, and that we don\u2019t understand machine learning enough to ethically implement it into our lives like this.\u00a0 Whatever future decisions are made about facial recognition, it seems that the issue is making its way to the forefront of both tech talk and research.\u00a0\u00a0<\/span><\/p>\n<p><span>\u201cI think that the IRS reached the right result,\u201d Sellars ends.\u00a0 \u201cThe best choice would be not to do this right now.\u201d\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Almost every American is used to sharing information with the Internal Revenue Service (IRS), but people were about to become eerily intimate with the agency after they announced the launch of a new website requirement:\u00a0 live video identity verification. The agency partnered with the third-party company ID.me to prevent scammers from benefiting off of the [&hellip;]<\/p>\n","protected":false},"author":19737,"featured_media":35930,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[127],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/35929"}],"collection":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/users\/19737"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/comments?post=35929"}],"version-history":[{"count":5,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/35929\/revisions"}],"predecessor-version":[{"id":35992,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/35929\/revisions\/35992"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media\/35930"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media?parent=35929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/categories?post=35929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/tags?post=35929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}