Ben Zhao

speaker
105 appearances 2 recordings 2 series first heard Jan 2025 last heard Mar 2025

Ben Zhao’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
Tariffs only raise prices.
Sound check, technical check.
About two hours ago, Bybit experienced a hack. As far as we know, this could be the largest hack in the history of our industry.
They take decades to hone their skill. So when that's taken against their will, that is sort of identity theft.
There is an exceptional level of hype. That bubble is in many ways in the middle of bursting right now.
We call it the SAN Lab. Which stands for? Security, algorithms, networking, and data. Most of the work that we do has been to use technology for good, to limit the harms of abuses and attacks and protect human beings and their values, whether it's personal privacy or security or data or your identity.
It's really quite anticlimactic. We've had some TV crews come by and they're always expecting some sort of secret lair. And then they walk in, it's a bunch of cubicles. Our students all have standing desks. The only wrinkle is that I'm at one of the standing desks in the room. I don't usually sit in my office. I sit next to them a couple of cubicles over so that they don't
get paranoid about me watching their screen.
Well, there's only a handful of students in my lab to begin with. So all hands on deck is like, what, seven or eight PhD students plus us. Typically speaking, the projects are a little bit smaller just because we've got multiple projects going on. And so people are partitioning their attention and work energy at different things.
Adversarial machine learning is a shorthand for this interesting research area at the intersection of computer security and machine learning. anything to do with attacks, defenses, privacy concerns, surveillance, all these subtopics as related to machine learning and AI. That's what I've been working on mostly for the last decade.
For more than two years, we've been focused on how the misuse and abuse of these AI tools can harm real people and trying to build research tools and technology tools to try to reduce some of that harm. To protect regular citizens and, in particular, human creatives like artists and writers.
So that's from my D&D days. It's a fun little project. We had done prior work in ultrasonics and modulation effects when you have different microphones and how they react to different frequencies of sound. One of the effects that people have been observing is that you can make microphones vibrate in a frequency that they don't want to.
We figured out that we could build a set of little transducers. You can imagine a fat bracelet, sort of like cyberpunk kind of thing with, I think, 24 or 12. I forget the exact number. Little transducers that are hooked onto the bracelet like gemstones.
Well, hey, you got to do what you got to do, and hopefully other people will make it much smaller, right? We're not in the production business. What it does is basically it radiates a carefully tuned pair of ultrasonic pulses in such a way that commodity microphones anywhere within reach will, against their will, begin to vibrate at a normal audible frequency.
They basically generate the sound that's necessary to jam themselves. When we first came out with this thing, a lot of people were very excited, privacy advocates, public figures who were very concerned, not necessarily about their own Alexa, but the fact that they had to walk in to public places all the time.
You're really trying to prevent that hidden microphone eavesdropping on a private conversation.
Fox is a fun one. In 2019, I was brainstorming about some dangers that we have in the future. And this is not even generative AI. This is just sort of classification and facial recognition. One of the things that we came up with was this idea that AI is going to be everywhere and therefore anyone can train any model and therefore people can basically train models of you.
At the time, it was not about deep fakes. It was about surveillance. And what would happen if people just went online, took your entire internet footprint, which of course today is massive, scrape all your photos from Facebook and Instagram and LinkedIn, and then build this incredibly accurate facial recognition model of you without your knowledge, much less permission.
And we built this tool that basically allows you to alter your selfies, your photos, in such a way that it made you look more like someone else than yourself.
Only in the version when it's being used to build a model against you. But the funny part was that we built this technology, we wrote the paper, and on the week of submission, this was 2020, we were getting ready to submit that paper. I remember it distinctly. That was when Cashmere Hill at the New York Times came out with her story on Clearview AI.
Showing 1–20 of 105 · page 1 of 6 Next →