Berkeley security expert Dawn Song explains how attackers fool AI systems, steal training data, and why humans are the weakest link.

Dawn Song: Dawn Song is a professor of computer science at UC Berkeley specializing in computer security, adversarial machine learning, and privacy. She is also founder of the startup Oasis Labs.
Lex Fridman talks with UC Berkeley professor Dawn Song about the intersection of computer security and machine learning. They cover formally verified systems, how attackers fool neural networks with adversarial examples in both the digital and physical world (including stop signs and facial recognition), and how training data can be poisoned or extracted. The conversation expands into data privacy, differential privacy, data ownership as an economic right, blockchain security, and program synthesis. It closes with a reflective discussion of Song's journey from physics in China to computer science in the US and the meaning of life.
“my students and collaborators has shown some very effective attacks on real-world systems for example Google Translate and translation api's”— Dawn Song
Tesla
“in the context of autonomous vehicles that use like Tesla autopilot for example they uses vision as a primary sensor for perceiving the world”— Lex Fridman
Alexey Pajitnov
“the other one actually programmed the game that's like a 3d Tetris it was a to not to be a super hard game to play”— Dawn Song