Showing posts with label David Mindell. Show all posts
Showing posts with label David Mindell. Show all posts

Thursday, March 30, 2017

Open systems meet closed automation

Let me start with this rather intriguing story (via Bruce Schneier).



"Prior to World War II, Abraham Wald was a rising mathematician in Europe. Unable to obtain an academic research position in Austria due to his Jewish heritage, Wald eventually made his way to the U.S. to become one of the most important statisticians of the 20th century.

"One of Wald’s most prominent works was produced for the U.S. government’s World War II-era Statistical Resource Group. The project examined aircraft that had returned from their combat missions and the locations of armor on the planes. Placement was, of course, no trivial matter. Misplaced armor would result in a negatively balanced, heavier and less maneuverable plane, not to mention a waste of precious wartime resources.

"Tasked with the overall goal of minimizing Allied aircraft losses by placing additional armor in strategic locations on the plane, Wald challenged the natural instincts of military commanders. Conventional wisdom suggested that the planes’ survival rates might benefit from additional armor placed in the areas that suffered the highest volume of direct hits. But Wald found that was not the case.

"Leveraging data stemming from his examinations of planes returning from combat, Wald made a critical recommendation based on the observation of what was not actually visible: He claimed it was more important to place armor on the areas of the plane without combat damage (e.g., bullet holes) than to place armor on the damaged areas. Any combat damage on returning planes, Wald contended, represented areas of the plane that could withstand damage, since the plane had returned to base.

"Wald reasoned that those planes that were actually hit in the undamaged areas he observed would not have been able to return. Hence, those undamaged areas constituted key areas to protect. A plane damaged in said areas would not have survived and thus would not have even been observed in the sample. Therefore, it would be logical to place armor around the cockpit and engines, areas observed as sustaining less damage than a bullet-riddled fuselage.

"The complex statistical research involved in these and Wald’s related findings led to untold numbers of airplane crews being saved, not only in World War II, but in future conflicts as well."
---

As designers we always have a theory of our proposed artefact in its intended environment. Sometimes we capture the theory in a formal specification, sometimes it's implicit in the examples we feed to some artificial neural net, frequently it's some fuzzy understanding we incorporate into a plain-language requirements document plus some test data.

In any event, the final engineered artefact embodies a theory - the theory of the environment in which it works correctly. That environment is often the real world and here we hit a problem: the real world is not a precisely-specified closed system*. Inevitably the artefact will encounter an event which is out of the envelope of its design - and then it will fail.

A good example of this is driving. Here, you are the artefact. Initially you learn in structured lessons how to control the car and tactics to safely navigate the streets.

As you gain experience, you statistically encounter fewer, rarer anomalous events. If you are lucky, your consequential mistakes will not be too serious. You update your protocol and become a better driver. But you will never be perfect.

Driving is an open system. There are (porous) boundaries around the theory of driving but as all experienced drivers know, that theory incorporates a great deal of real-world social knowledge - it's more than seeing the white lines in the rain. **

---

When we classify a human social role as routine, we're saying that the wider system into which the role is enrolled is effectively closed and can be pre-specified. No real systems are truly closed so we always provide an escalation route to a competent (ie more informed) authority. For truly routine roles, we don't expect that escalation to occur too frequently, or to be problematic when it does.

Bruce Schneier's excellent article is about countering cyber-attacks. This is far from routine. The adversary is using intelligence, novel tools and unfixed vulnerabilities to get you. That's pretty much the definition of an open system. Schneier describes the problem like this:
"You can only automate what you're certain about, and [...] when an uncertain process is automated, the results can be dangerous."
The right answer is to use automated systems within manageably closed subsystems (like antivirus routines) within the broader oversight of a computer-augmented human response team.

Perhaps one day we will have human-socialised AIs which have the intuitions, general knowledge and motivational insights which humans possess, and then we can hand things over to those said AIs, confident they will make no more mistakes than we would in those incredibly challenging not-sufficiently-closed systems.

---

*   Arguably it is from the point of view of modern physics - but that doesn't buy you anything.

** Here's a review about the implications for driverless cars.

Saturday, January 02, 2016

'Our Robots, Ourselves' by David Mindell: a review

Link to Amazon page here

David Mindell trained as an electronics engineer, where he worked on deep-water submersibles, and as a social scientist where his ethnomethodological studies have looked in detail at how people construct and rework social relationships to integrate new technologies. If there’s one take-home message here, it’s that people create artefacts – technologies – to solve problems, and that all such tools, even those with substantial AI in the control loop, have to operate successfully embedded within a matrix of human processes.

Mindell’s case studies include underwater crewed and remotely-controlled vehicles; advanced aviation automation and military RPVs; space systems such as Mars rovers and the ISS, and finally innovative proposed systems such as driverless cars. I read one comment on his work which argued that there could be no issue in principle with fully autonomous systems: the fact that existing ‘autonomous’ systems always sit in a loop with human specialists is simply that it hasn’t yet proven cost-effective to automate said specialists. This is to spectacularly miss the point, that all such ‘autonomous’ systems are in fact embedded within human systems; all such artefacts are tasked, their operations monitored and their results delivered into wider human systems and contexts. You can never escape the issue of the human-machine interface.

And this issue has been around for a long time. A generation ago people worried about the inscrutability of expert systems, the bafflement humans felt when a  system veered off into some unexpected course of deduction or action. Was this intended or is it a glitch? In either case, how can we humans continue to engage with the ‘rogue’ system? Mindell has many examples of autonomous subsystems (autopilots and autolanders come to mind) where the automation fails inscrutably, throwing control back to the unprepared user/driver/pilot with consequent disaster. This is the stuff of newspaper headlines.

The automation which seems to work best is augmented reality. Here the automation systems map a high-complexity environment (eg engines and system status, outside terrain) into a visualisation which makes task performance easy (eg keep the craft icon on the guidance icon as you come onto target). Here the human stays in the loop with enhanced powers.

Autonomous systems work where environmental behaviour is largely predictable and there are few (and acceptable) negative consequences to unanticipated failure modes. In military affairs, guided missiles and mines come to mind, although unintended consequences in the latter case have proven controversial. Put a putative autonomous system into an open environment with a great deal of under-constrained human interaction and unpredictable environmental variation (snow, weather, building work, crashes, diversions) and no AI system currently foreseeable can cope. The system requirement would be emulation of the full common-sense and conversational capabilities of a socialised adult human. No, we are nowhere near that point.

These seem to be good reasons to be sceptical about prospects for fully-automated driverless cars, despite their great desirability and corresponding levels of hype.  David Mindell finishes his book with a well-researched assessment of prospects for the Google car and similar automotive innovations. I can summarise by saying, don’t hold your breath.

The author has written an excellent and thought-provoking book, a welcome attempt to see beyond the limitations of a pure systems engineering approach to advanced AI automation: essential reading.

Tuesday, December 29, 2015

The implacable state; Autonomous AI; 23andMe as a family investment

I was reduced to helpless, incandescent fury this morning by the unexpected arrival of a speeding ticket. I had been caught on camera on the way to my mother's funeral on Monday, Dec 21st 2015. I have applied for the driving awareness course option and will let you know in due course how it went, if accepted.


I visualise the Speed Enforcement Unit putting this together, chuckling as they did so.

Turns out I was doing 35 mph in a 30 mph section of the A-road at Westbury-on-Trym, Bristol. Once my head-banging, visceral anger had subsided (a trip to the gym helped considerably) I found the list above of more or less lame excuses (none of which work) quite amusing.

---

Robin Hanson has an interesting piece about a newish book, 'Our Robots, Ourselves: Robotics and the Myths of Autonomy' by Prof. David Mindell at MIT. The book argues:
"If robotics in extreme environments are any guide, Mindell says, self-driving cars should not be fully self-driving. That idea, he notes, is belied by decades of examples involving spacecraft, underwater exploration, air travel, and more. In each of those spheres, fully automated vehicles have frequently been promised, yet the most state-of-the-art products still have a driver or pilot somewhere in the network. This is one reason Mindell thinks cars are not on the road to complete automation.

“That’s just proven to be a loser of an approach in a lot of other domains,” Mindell says. “I’m not arguing this from first principles. There are 40 years’ worth of examples.”
As someone who is interested in AI and its impact on the automation of everyday tasks, I promptly bought the book (Kindle) and will let you know how compelling I think his arguments are. After my speeding ticket I am thinking wistfully - and defensively - about Google cars. How does anyone drive on a regular basis in the UK without collecting 12 points in short order and losing their licence?

---

In August 2014 I persuaded my mother to donate a spit sample to 23andMe. Eventually I was able to show her the report plus the much more detailed information from Promethease. My mother had no technical interests and in particular no background in genetics. Nevertheless she read all the material in the folder with close attention for half an hour and then took possession of it, refusing to allow its contents to be shared with anyone else, even close family.

I think there was a little bit of magical thinking here, as the information was in no way earth-shattering. However, the reason I signed her up was in anticipation of a future where 23andMe provide a full genome description and we actually know what it means. It's a family history gift to future generations. I might have mentioned to her that we could clone her from this data, bring her back memoryless, but I doubt she took it on board!

My father unfortunately died in 2009, before 23andMe got into business. I have some of his personal effects in storage anticipating future DNA profiling ... .

On an adjacent topic, it's interesting to see the latest genomic news on the ancestry of the Irish. Razib Khan has an in-depth discussion.