Menu
← Field notes
◇ ARCHIVEPAGE 10 / 10 · OLDEST → NEWEST

The field notes archive.

2026.09.11 VOICE

Speech deepfake detection is losing the arms race.

Anti-spoof detectors hit near-perfect scores in the lab and collapse in the open world. They memorize the artifacts of the attacks they were trained on, and every new synthesizer erases them. Detection has to be one layer — paired with liveness checks and out-of-band verification.

2026.09.11 STANDARDS

You can publish four machine-readable 'do not train on me' signals and still have no enforceable preference.

RSL, IETF AIPREF, W3C TDMRep, and IPTC all let you say 'do not train on me.' The tokens do not match, the attachment surfaces do not overlap, no rule says which wins when they disagree, and no major model developer has committed to honoring any of them.

2026.09.12 ZKML

You cannot check that someone trained a model by replaying their checkpoints.

Checkpoint-replay verification of a training run is not merely buggy: making it provably robust reduces to open problems in learning theory, and spoofing already forges valid logs cheaply. The only floor that does not rest on unsolved theory is a zero-knowledge proof of training.

2026.09.14 VOICE

You scrubbed the words from the audio and shipped the speaker's age, accent, and health anyway.

Redacting the transcript and anonymizing the speaker feels like the privacy work is done. It is not: the waveform is a biometric giving up age, accent, emotion, and clinical conditions from the signal — and it leaks hardest for the groups least seen in pretraining.

2026.09.15 OPINION

Regulators just mandated a robust watermark that a proof says cannot exist.

The EU AI Act requires AI output to be marked in a robust, reliable way. A formal impossibility theorem says strong watermarking cannot exist. Five words in the statute carry the collision.

2026.09.16 PRIVACY

Machine unlearning is suppression, not deletion.

Unlearning promises a model can forget specific data without a full retrain. What it delivers is output suppression: a small benign relearning set — or simply quantizing the model — brings the 'forgotten' knowledge back.

2026.09.16 PRIVACY

Your membership-inference 'proof' that they trained on your book is mostly a clock.

A membership-inference attack that separates your book from a held-out one is usually reading the calendar, not the weights. A successful attack is not a sound proof — and the null it would need to test against cannot be sampled.

NEW ENGAGEMENT · INTAKE

Tell us about it.

The more specific you are, the more useful our first reply.

SERVICE AREA
↩ ENCRYPTED IN TRANSIT
ASK THE FIELD NOTES BETA