LIVE · cybersecurity feed
Live wire
ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…

ZeroDay News ·

Source: Help Net Security

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage capable of continuous tracking of individuals and vehicles.

The VRAIO system introduces an independent third party, referred to as the Recorder, which manages an outbound firewall for municipal AI systems. Before any AI output leaves the system, the operator must declare the cameras used, the time range, and the purpose of the data access. The Recorder then verifies this declaration against predefined legal rules and logs its decision in a tamper-resistant ledger. Crucially, the Recorder does not possess decryption keys and cannot access the content of the footage itself; it only processes the labels and declarations.

A key vulnerability in this design is that the Recorder cannot verify the truthfulness of an operator's declaration. For instance, an operator could claim to be searching for a missing child but use the footage for an entirely different purpose. The Recorder would approve this request if the stated purpose aligns with the rules. To address this, Fujii's system incorporates unannounced spot checks. During an audit, the recorded declaration is compared against the actual data released. If a discrepancy is found, the ledger identifies the request and the operator responsible, who could then face administrative penalties, criminal liability, and public disclosure of the violation. The effectiveness of this deterrent depends on the frequency of audits and the severity of the penalties, which Fujii suggests should be adjusted based on experience to ensure the expected cost of misuse outweighs its potential benefits.

Fujii acknowledges several limitations of the VRAIO system. Bypassing the firewall would leave no record, requiring conventional security measures to detect. The Recorder itself could be compromised by the operators it oversees. Furthermore, the system does not evaluate the fairness of the rules; if a city implements discriminatory rules, VRAIO would enforce them faithfully. Fujii envisions the Recorder as an independent body, possibly a judicial institution or an entity between administrative and judicial systems, overseen by multiple parties to ensure its impartiality.

Beyond technical safeguards, Fujii emphasizes the importance of public acceptance for FMPS. He defines true acceptance as when individuals express approval, attribute it to a lack of harm or a perceived benefit, and exhibit no changes in their routes, information-seeking behavior, expression, or participation in assemblies. He distinguishes this from mere resignation, where individuals accept tracking simply because avoidance is impossible. An earlier experiment involving 11 cameras and notifications to 2,218 households yielded positive opinions from residents, but did not measure behavioral changes, which Fujii now considers essential. He proposes anonymous surveys to gauge behavioral impacts and also suggests measuring positive effects, such as increased feelings of safety and greater use of public spaces, particularly for vulnerable populations.

Fujii's plan for implementing FMPS involves three stages. The first stage focuses on locating missing children and consent-based child safeguarding. The second stage involves using AI in streetlights to detect crimes or accidents. The third, which he calls a "stress test," would involve a central AI learning behavioral patterns from past crimes and flagging pedestrians who resemble these patterns. This final stage would first be tested through vignette studies and simulations, with pre-defined stopping criteria including a substantial rise in "chilling effects," unacceptable false detections, or a significant increase in complaints or withdrawals. Fujii has not yet discussed his proposal with regulators or municipalities, advocating for its development and testing through a small-scale demonstration project.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

How AI can fix cybersecurity compliance: From dashboards to continuous execution

Cybersecurity compliance, a critical but often costly endeavor, is increasingly challenged by the rapid pace of cyber threats and the manual nature of traditional compliance processes. The Department of War's recent suspension of Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, which would have mandated third-party assessments for contractors handling controlled…

ransomware

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's official Twitter account, which boasts 13 million followers, was reportedly compromised by an attacker who used the platform to promote a cryptocurrency scam. The incident, which occurred on October 8, 2026, involved the attacker posting an image of Clippy, Microsoft's former animated assistant, alongside a promotion for a "dodgy crypto coin."

ai

Australian Gov't Weighs Mandatory AI Incident Reporting

The Australian government is reportedly considering the implementation of mandatory incident reporting requirements for companies developing and deploying frontier artificial intelligence systems. This move comes after an incident involving an "agentic attack" against the nation's Medicare systems, prompting a re-evaluation of regulatory frameworks for advanced AI.

nation-state

The people who know passkeys best are still typing passwords

A recent survey of nearly 1,900 technology and security professionals across nine countries reveals that while 87% are familiar with passkeys, 43% still rely on usernames and passwords for work accounts. This preference for traditional authentication methods persists despite the known vulnerabilities associated with passwords and the respondents' high level of expertise in the field.

ransomware

Ransomware recovery CEO charged over secret ransom payments

The owner of MonsterCloud, a ransomware remediation company, has been charged with allegedly defrauding clients by secretly paying ransoms to cybercriminals while claiming to use proprietary technology for data recovery. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026, and arraigned…

security

Cisco quantum network controller lets apps order entanglement on demand

Cisco has unveiled a Quantum Network Controller, a research prototype designed to enable applications to request entanglement on demand from a quantum network, abstracting away the underlying hardware complexities. This controller manages the distribution of entanglement, a linked quantum state shared between distant points, which is a critical resource for quantum networks.