Sunday, 30 June 2024

(A)ML: is it worth it?

I worked in banks for a while, as an employee and as a consultant, and one thing the banks make sure you are aware of is Money Laundering. Money Laundering is something all banking employees are tested and reminded of.

But for what?

A little piece of interesting news, most of the people involved in the multi-million money laundering case in Singapore surrendered 95.5% of their assets and got sentences of under 2 years in Singapore jails (1), no financial penalty (assuming assets were ‘illegally obtained’), short jail term. So, it doesn’t seem it’s a big deal, right?

What actually is the problem with money laundering?

First, let’s take a step back. This blogpost was motivated by the recent multi billion money laundering case in Singapore.

A recent article entitled “the banks that hold most money in Singapore’s largest Money Laundering Scandal“ (2) shows the extent that banks in Singapore, not only the big 3 local banks (UOB, DBS, OCBC) manage bank accounts of the people found guilty of money laundering (49.6M, 29M, 22.4M), but also large international banks such as Credit Suisse, CitiGroup, (79.6M, 79.3M).

Credit Suisse is not a stranger to money laundering (3), the case of Bulgarian cocaine with the judge commenting that “the company could have prevented the infringement if it had fulfilled its organizational obligations” and yes, Credit Suisse is now owned by UBS, but UBS is not that vigilant regarding money laundering either (4). As for CitiGroup, this again would not be the first time (5).

The local banks were involved in the 1MDB and wirecard scandals (6)(7).

So, banks have been involved in Money Laundering, again and again.

Millions are spent by banks yearly to buy, maintain, upgrade their Anti Money Laundering (AML) systems. It is a very very lucrative market to be in. Free Money once you get in, since in most cases, banks are forced to show their AML capabilities to regulators, and having a shiny AML system is something most regulators would not question.


The Singapore case

The first thing that came to my mind when I read about the case was, how on earth did the great AML systems not pick these as possible money laundering cases. Do you see a pattern among the cases? And more importantly, even before knowing some of these people are involved in “interesting” activities, don’t you find it a bit weird and worth a second look? One early article focused on this aspect “”(8)

Ten people of Cypriot, Turkish, Chinese, Cambodian and Ni-Vanuatu nationalities were charged on Wednesday (Aug 16) night after police conducted simultaneous raids across Singapore as part of a probe into money laundering and forgery offences.”

And to add to this, another piece of news from Singapore about someone also belonging to the same very specific demographic group, this time about someone who created malware that infected many computers and caused large losses (9)

“The DOJ said that Wang, who also holds a St Kitts and Nevis citizenship, allegedly received US$99 million from cyber criminals who tapped his network from 2018 to July 2022.”

Now you can say that the world is now so open, having multiple nationalities, even for Chinese citizens is not a big deal, but is it?

China does not recognise dual nationality, according to the Nationality Law of the People’s Republic of China (10) which clearly states:

Article 3: The People’s Republic of China does not recognize dual nationality for any Chinese national

Everyone in Singapore knows of rich Chinese nationals who took up Singaporean nationality such as the bosses of Hai Di Lao (11), TsingShan Holdings (12), SEA holdings (Shopee is a subsidiary) (13) and their families. However, with all due respect, having Singapore as Nationality and say Vanuatu (14) are 2 very different things.

Why don’t sophisticated AML models used by these large banks fail to flag rich Chinese nationals having multi million dollars in assets but with ‘exotic’ passports.

Even if this may be a relatively recent phenomenon, and AML models, being trained on past data may take a while to pick up this characteristic (ahum…), you would have thought humans would take a deeper look into the sources of income of these people during the Know Your Customer (KYC) that is compulsory when accepting new customers, and their transactions. But, in the case of the Singapore based money launderers, they were allowed to purchase many properties easily, avoiding all AML models and human oversight (if any).

AML Models as a shield

And that’s the second thing, do banks use AML models as a shield? so they only get into minor trouble when money laundering is discovered? “Hey, check out my shiny AML model Regulator, it cost me millions, I am doing what I can in terms of AML”. After all, these money launderers must have paid hefty fees to banks while moving their millions, and buying their properties.

As far as I have seen, the only person who got into trouble related to transactions of the Money Launderers are the property agents, with one fined $4000 (15) which is likely a minor portion of what that agent earned on these cases. But there is noise about the rot going further into private banking sector, although no action has been taken yet (16). The only agent who faced the law seriously, was found to have behaved above board in the real estate transaction although her issues were unrelated (17).

To reiterate, getting involved in Money Laundering is no biggie, jail terms and financial wise

So, not only do the perpetrators of money laundering get minor jail sentences, for reference, 4 Vietnamese nationals who shoplifted items of 60,000 times less value, including a pregnant woman, were jailed more than 20 months each (more than the longest jail term for the money laundering) (18), and I am pretty sure the clothes shoplifted were restituted since these foreigners were caught while still in Singapore.

Should you be surprised?

No. Actually I didn’t think about it before, but money laundering is not something that serious, as the sentences showed.

I will go further… My brother told me “you think like a criminal” when I told him this, but, it is a risk worth taking. Imagine, even 1pct of SGD3b is still SGD30m... if I have this stashed somewhere, I will go there and enjoy cold sakes in summer and warm sakes in winter until my sunset.

To add to this, please note that at least 1 of the men sentenced went to Japan after release from jail in Singapore(19), it is highly unlikely they are wanted for anything in Japan.

Think about it.

Who were the victims of the money laundering?

-        The previous owners of the properties/assets purchased got to keep their funds from laundered money

-        Real estate and other agents who facilitated transactions usually got small fines (for reference a real estate agent may be charges 2% commission; for a SGD4,000 fine that would break even at a property worth SGD200,000.

-        Banks get to sell the assets mortgaged and recoup their loans and do not have to return their transaction fees

-        Bankers keep their bonuses

-        Even the government made via duties, fees, and taxes (whether directly or indirectly)

I don’t see anyone in Singapore worse off.

So we are back full circle.

What is the problem with money laundering?

Referring to the Singapore multi billion dollar case, presumably, the issue is the source of the funds these people brought into Singapore. The people somehow made Singaporean entities believe (ahum…) these were from legitimate means, but they were not.

Money Laundering is a possible symptom of non legal activities having taken place. A possible tail-end part of a chain of transactions, one of which was possibly illegal.

The real problem is the presumably illegal transaction that generated the money to be laundered. Money laundering basically means taking money that is not registered in the legal economy and making it legally registered so that it can be used. The trick is that the amounts are huge; we could easily launder a few thousand dollars by living our normal life in a year, but if it was a million it would be harder, hence the need for large transactions, property, investments…

But the fact is, the laundering itself, doesn’t seem to harm many. It is the failure to detect and stop the illegal transaction themselves (that possibly cause harm such as adulterated drug dealing, scamming( Around 45,000 Singapore scam victims lost $600m last year(20)), gun and weapons dealing (ahum…interestingly Singapore has managed to cut trade of weapons to Myanmar (banned) by 90% recently (21))) that are the issue. The failure to stop these demonises money laundry, it is an easy way out.

What to do regarding money laundering then?

Radically, allow all transactions 😊, then there will be no need to launder, all transactions can be taxed appropriately (ahum… there really seems to be something lodged in my throat…) and nobody worse off. However, this is quite impractical.

The key is to first decide whether money laundering is really such a big deal.

From the example above, it seems that money laundering is not as bad as shoplifting. If that is the case, then there should be less focus in banks and financial institutions around money laundering, and money should be spent elsewhere. Since many banks getting involved in money laundering, and even more than once and/or over a period of time, and their business does not seem to suffer much, there is no incentive for them to do something about it, and spending on ‘state of the art’ AML systems is just a waste of money, especially when humans are kept out of the loop, whether willfully or not.

If money laundering is seen as worse than shoplifting, then the whole penalty set should be increased accordingly for people who actively launder money, and people and organisations that enable them such as real estate companies, private banks… A slap on the wrist of the people on the ground is obviously not sufficient.

A few days ago, the Monetary Authority of Singapore updated AML guidelines (22). Personally, sorry for being cynical, I do not think that this incentivises financial institutions to really do something, it is more of an advisory nature, neither carrot, and especially not a stick to change behaviour. At most there are more areas for AML software companies to sell their wares.

As a rough guide, in 12 months of 2022-23, Singapore financial institutions spent more than SGD7.5B 'to fight crime and meet regulatory obligations' (23)

Update:

The people found guilty of the SGD3B money laundering case used Family Offices (Offices that basically only manage a family's financial affairs, these do not fall under financial regulator (MAS) purview), and they even got tax breaks. (24) These tax breaks will not be clawed back.


  1. https://straitstimes.com/singapore/courts-crime/3b-money-laundering-case-su-jianfeng-sentenced-to-17-months-last-of-10-to-be-sent-to-jail
  2. https://sg.finance.yahoo.com/news/the-banks-that-hold-most-money-in-singapore-largest-laundering-scandal-220006461.html
  3. https://www.morningstar.hk/hk/news/233221/credit-suisses-demise-a-timeline-of-scandal-and-failures.aspx
  4. https://www.finews.com/news/english-news/62808-ubs-money-laundering-edf-mros-yemen-ali-abdullah-saleh
  5. https://www.nytimes.com/2017/05/22/business/dealbook/citigroup-settlement-banamex-usa-inquiry.html
  6. https://www.mas.gov.sg/-/media/MAS/News-and-Publications/Press-Releases/Summary-of-1MDB-Related-Court-and-Regulatory-Actions_as-at-30May17.pdf
  7. https://www.reuters.com/business/finance/singapore-fines-dbs-citibank-ocbc-swiss-life-inadequate-money-laundering-2023-06-21/
  8. https://www.channelnewsasia.com/singapore/money-laundering-suspects-police-probe-raids-gcb-condo-prime-areas-seized-3703491
  9. https://www.straitstimes.com/singapore/chinese-national-arrested-in-s-pore-for-creating-malware-that-allowed-criminals-to-steal-billions
  10. https://cn.ambafrance.org/IMG/pdf/loi_nationalite_chine.pdf
  11. https://www.straitstimes.com/business/property/haidilao-co-founder-shi-yonghong-buys-dr-lee-wei-lings-cluny-hill-gcb-for-50-million
  12. https://mothership.sg/2024/04/tsingshan-founder-daughter-84-million-gcb/
  13. https://theindependent.sg/sea-ceo-forrest-lis-wife-to-buy-gcb-on-gallop-road-for-s42-5m/
  14. https://www.dailypost.vu/news/citizenship-office-wont-decide-on-wanted-citizen-until-court-conviction-kapapa/article_17d821fa-6ce6-5f6b-a484-638dc9c15897.html
  15. https://www.businesstimes.com.sg/singapore/economy-policy/2-property-agents-found-guilty-failing-carry-out-anti-money-laundering
  16. https://www.singaporelawwatch.sg/Headlines/agents-gave-kickbacks-bankers-took-cuts-ethics-flew-out-the-window-in-money-launderers-deals
  17. https://mothership.sg/2024/01/rochelle-chow-shuting-license-not-renewed/
  18. https://asiatimes.com/2018/12/four-jailed-for-singapore-shoplifting-spree/
  19. https://www.channelnewsasia.com/Singapore/3-deported-japan-cambodia-billion-dollar-money-laundering-case-4380856
  20. https://www.straitstimes.com/singapore/courts-crime/scam-victims-in-s-pore-lost-6518m-in-2023-with-record-high-of-over-46000-cases-reported Stopping scams, or at least quickly catching scam centres is something that Analytics/ML/AI can help do relatively easily with the right data. The way exists, but the will is weak.
  21. https://www.channelnewsasia.com/singapore/weapons-arms-flow-singapore-myanmar-junta-dropped-dramatically-united-nations-envoy-tom-andrews-4439181
  22. https://www.mas.gov.sg/news/media-releases/2024/singapore-publishes-updated-money-laundering-national-risk-assessment
  23. https://www.straitstimes.com/business/singapore-financial-firms-spent-more-fighting-crime-and-meeting-regulatory-demands
  24. https://sg.news.yahoo.com/6-family-office-funds-tied-to-singapore-launder-case-got-tax-breaks-075431904.html

Thursday, 13 June 2024

Data Culture: why NCS servers being accessed by fired employee multiple times over 3 months is scary

If you had a place where you kept your barang-barang/bric-a-brac/bits-n-pieces, even detached, would you keep it unlocked/unlatched while latching and locking the rest of your home?

I was actually planning a blog on the multi-billion-dollar money laundering case in Singapore, when this piece of news came out in the open, the case of the disgruntled NCS employee. Laundry can wait.



Some facts as they have been released (1)

Background

1 NCS (2) is owned by Singtel group

2 NCS focuses on applications, cybersecurity, infrastructure and engineering

3 NCS serves corporates, Telco (since is owned by Singtel) and more pertinently Government. In fact, up to 66% of NCS $2.7B revenue was from government (3) and as recently as this year NCS was still focused on government (4)

4 Singtel is also a major player in GXS bank, together with Grab.

Mr Nagaraju

5 Mr Nagaraju was employed by NCS from November 2021

6 Mr Nagaraju was fired by NCS in October 2022, with an effective last day of Nov 16 2022.

7 Mr Nagaraju went back to India

8 Between Jan 6 2023 and Jan 17 2023, Mr Nagaraju accessed NCS servers using Administrator privileges 6 times.

9 Mr Nagaraju found a new job in Singapore in February 2023 and came back to Singapore, living with an ex NCS colleague

10 He used the “wifi” and accessed NCS systems again in February 2023

11 In March 2023, a full 3 months after he had been fired, Mr Nagaraju accessed the NCS systems 13 times and deleted some virtual servers.

12 Mr Nagaraju was arrested in April 2023

13 He was sentenced to 2 years and 8 months jail

14 NCS apparently made a loss of SGD918,000.


The press reaction

Mainstream media is portraying this case as a disgruntled ex-employee causing almost SGD1m damage to the ex-employer. This misses the point.

Assuming 66% of NCS revenue came from government, that’s $1.7B that the government has paid NCS in 2023 for services. Hence a lot of data that pertains to Singapore residents, likely including Personally Identifiable Information, is kept in systems possibly built (infrastructure and engineering), managed (applications) and secured (cybersecurity) by NCS. This should be the story.

I am sure some people will argue that the systems that Mr Nagaraju had access to were not government systems but systems internal to NCS. Yes, but so what? If you cannot keep your own house in order, how can you help keep someone else’s? What type of governance does NCS have on it systems?


Think about it:

1 Mr Nagaraju accessed systems after he was fired, the HR system is likely not to be properly integrated with the other systems. Also note, he was fired, he did not resign voluntarily. This is really weird because in a previous project I was involved in, we did have to integrate with an HR system to control accesses systematically.

2 He accessed systems from India even. Hence there is no geographical restriction as to who can access NCS systems. While this is a good thing to allow employees to work from home or take care of emergencies, there should be some monitoring taking place, not a half-yearly review after the horses have bolted.

3 It is not mentioned whether he used an NCS device or his own personal device from India to access the systems; personal devices can be secured and 3 months is past most cases for reviewing accessed for personal devices. If he had an NCS laptop, again, the processes to secure the devices failed, and the device access was not cut.

4 He had admin powers and admin credentials. Either, again, his ID’s access to systems was not terminated, not something new. You would have thought lessons would have been learnt. Or it was a shared ID and password, a major no-no in the IT world. Basically NCS controls and governance on IDs and passwords and accesses were severely lacking. Not that I am saying NCS was the IT vendor, but even in 2017 the AG reviewed 2 critical government services (Ministry of Defence MINDEF, and Ministry of Manpower MOM, and Singapore Customs) and found similar lapses in IDs (5)

In brief, this case shows how bad the controls of NCS were. And I think it is legitimate to ask how likely this culture has affected the projects for which they earned around SGD1.7B in 2023 from the government.

I am sure nobody in SG has forgotten about the IHIS/SingHealth issues where even the then PM’s data was searched (6).

To me, focusing on close to SGD1M ‘losses’ to NCS is a red herring. And I would like to ask, isn’t NCS aware of back-ups? Apparently NCS only discovered the servers missing when someone tried to log into one of them the day after Mr Nagaraju deleted it. SGD1M worth of damage, I would find it hard to believe unless there are no back-ups. That would be another horror story on how NCS managed its servers.

Conclusion

I think it is important to understand that the real story is not the SGD1M NCS supposedly lost, but the fact that their governance, processes and security practices leave much to be desired.

It's all about culture: is securing your company's assets in your blood?

Data is crucial, especially when more and more government services are moving online. We trust certain organisations to keep our data safe, and they choose vendors who, we hope, will do so. Personally, when I see a major vendor for these government organisations having a loose data culture, I fear for my data.


  1. https://www.channelnewsasia.com/singapore/former-employee-hack-ncs-delete-virtual-servers-quality-testing-4402141
  2. https://en.wikipedia.org/wiki/NCS_Group
  3. https://www.singtel.com/about-us/investor-relations/annual-report-fy2023/ncs-ceo-review
  4. https://www.zdnet.com/article/ncs-looks-beyond-government-singapore-for-transformation-growth/
  5. https://tnp.straitstimes.com/news/singapore/government-audit-finds-lapses-it-controls-unchecked-vendors
  6. https://www.straitstimes.com/singapore/personal-info-of-15m-singhealth-patients-including-pm-lee-stolen-in-singapores-most

Sunday, 9 June 2024

Thinking Analytically: the case of Mr Shariff Uddin

I mentioned to someone recently that I believed analytics is an application using tools of a way of thinking. To think analytically is something that can be learnt/taught, and once you have that, tools don’t matter that much; hey you still need to know what questions to ask GenAI, no?

To give an example, I look at the case of Mr Shariff Uddin, a Bangladeshi author who was living and working in Singapore and recently left Singapore under less than clear circumstances.

Who is Mr Shariff Uddin?

Did you know that someone on a work permit authored (1) a book about his experiences as a work permit holder in Singapore, and won the prize for non-fiction in Singapore (2)

A fascinating, challenging and truly important book. Not only do we now at long last have access to the most sustained and authentic narrative and record of life and work as a Bengali migrant in 21st century Singapore, but also a genuine work of art in its own right. Sharif is an unprecedented and crucial voice in Singapore writing: perceptive, joyful, critical, constructive. With his characteristic modesty, he has something of moment to tell us and he does so from the heart beautifully.

– Richard Angus Whitehead, Lecturer, English Language and Literature Department, National Institute of Education

Mr Uddin has left Singapore. The aim of this blog is to explore his case using data-driven lens, and see what you think is the issue.

 


Background on the case

Things started falling apart early this year while Mr Uddin has been working in Singapore for 16 years. His employer started receiving threats from loansharks alleging Mr Uddin had borrowed money from them and failed to repay the debts.

From threats at the work place, things escalated to informing the other tenants of the work place, and eventually also to the home of the business owner and even to the business owner’s sister. (3)

There have been a few controversies in this case. The most interesting one was that Mr Uddin argued that the police and/or the Ministry of Manpower advised his employer to terminate his employment, as stated in his termination letter

“under police and MOM officer advice ... because of the troublesome bring along from your loan shark issue for us”(4)

Something the authorities vigorously denied (4). It turned out, something that is not contested, that the police officer whom the business owners talked to at Geylang Police Post as per this official Facebook post (5) “The officer, out of concern for her family’s and her well-being, also advised her generally that harassment would usually stop after the work pass of a foreign worker being harassed had been cancelled, and the worker no longer worked for the employer.”.

There has been some confusion whether the lady involved was the sister or daughter of the business owner was the person involved, as you can see the MoM refers to daughter (5) but the business owner says sister (3).

And importantly, the Police investigation found no evidence that Mr Uddin borrowed anything from loan sharks, hence the harassment was totally unfounded as Mr Uddin had been saying all along - Investigations eventually concluded with the authorities finding no evidence that Mr Sharif had borrowed money from unlicensed lenders. -(3)

I am not a social crusader so what does this case have to do with data?


What data?

Data does not mean just things on a spreadsheet, but pieces of information

  1. Mr Uddin’s details (presumably including his work permit number and employer) were used to obtain a loan from a loanshark
  2. the loan shark decided, as per usual practice, to harass the debtor where he/she can be damaged, here the place of employment
  3. they went further by informing other tenants
  4. they went even further and obtained information on where the sister of the employer lives, and caused harassment there. This is important, it is not the employer’s home but the sister’s.
  5. Mr Uddin was terminated by his employer
  6. Mr Uddin found a new employer who also received threats and as per the reports (3) only the first employer and MoM were aware of this new job offer
  7. Mr Uddin found no other suitable alternative employment
  8. At the expiry of his extended pass, he left Singapore.

 

Who dunnit?

This is kind of the information we have, so now the question is what is likely to be the most likely interpretation?

  • Mr Uddin took a loan from a loanshark and fed the him/her information, he is responsible
  • Mr Uddin took a loan from a loanshark with long arms and was hell bent chasing Mr Uddin out.
  • One or more people with access to government systems leaked information
  • Mr Uddin’s employer wanted Mr Uddin to leave Singapore

 

Actually…

Actually, I have no idea which is the correct interpretation, but I have a fairly good idea how this can be resolved. Since it is common for loansharks to obtain photocopies of NRIC/FIN/WP in order to give a loan, all parties have some reason to have access to the data.

The keys are

-        Address of the sister of the employer; the employer claims it is via her car plate number (LTA system)

-        Details of new employer of Mr Uddin

I have no clue who has access to what data in the government systems. In a nutshell:

  • MoM databases should hold data related to employees and people on various passes in Singapore, and data on the change in the passes.
  • ACRA should have access to directorships, including directors’ addresses, but not family members details.
  • LTA should have access to car owners’ data, and that includes vehicles owned by both individuals and corporations and as such some information on company directorships, but not comprehensively.
  • The Police force database should have access to multiple databases, or even copies of their data such as ICA who controls identity of everyone in Singapore

I assume that information is siloed, but even if it is not, access to information should be on need to now basis. And since this is considered PII, should fall under PDPA (although the government if exempted (6)), and at the very least all data requests for PII information should be logged and thus traceable.

Hence, to resolve the issue and find some justice for Mr Uddin, all that is required is the logs for say April onwards for the agencies above and understand who made requests for

  • New employer of Mr Uddin
  • Address of the sister of Mr Uddin’s previous employer

These 2 pieces of information should suffice in resolving the issues.

It is not rocket science, it is basic analysis.

 

Conclusion

There are 2 conclusions:

The case is closed, but to me some grey areas remain. They may not be of help to Mr Uddin, but intrinsically I believe it would be important to know what data in the various agencies has not been misused without detection.

It’s not very difficult to think of simple things analytically, is it?



  1. https://www.landmarkbooks.sg/md-sharif-uddin
  2. https://www.landmarkbooks.sg/store/p/stranger-to-myself
  3. https://www.channelnewsasia.com/singapore/uddin-sharif-loanshark-hiap-seng-piling-construction-4385606
  4. https://www.channelnewsasia.com/singapore/migrant-worker-fired-loan-sharks-bangladeshi-sharif-md-uddin-4247646
  5. https://www.facebook.com/sgministryofmanpower/posts/784330097132347
  6. https://www.straitstimes.com/politics/parliament-public-agencies-not-governed-by-pdpa-because-of-fundamental-differences-in-how


Sunday, 28 April 2024

Songs about AI: Have we been listening or mindlessly humming/headbanging...?

Many people still believe AI is a21st Century thing. It is not, it has been around since the 1950s (1), but current advances in storage and compute have given it new breath and started democratizing it.

Therefore it should come as no surprise that 20th Century troubadour-philosophers have been informing us about what such technology could mean for us.



Have we been listening? These troubadour-philosophers do not communicate to us like the works of Plato/Aristotle that are unfortunately being pushed into colder storage to save costs. I came across one of these works on the radio recently, and got inspired to write this blog post. How many of you are familiar with these philosophical pieces?



Every Breath you take (Synchronicity) – The Police (1983)

Let’s start by something easy, and a song that many of us have heard, hummed, or even sung at a karaoke…

Oh, can't you see
You belong to me?
How my poor heart aches
With every step you take

The chorus of the song is probably what makes many people believe this is a love song, the singer is heart broken.

However, it is worth looking at the lyrics in more detail.

Every breath you take
And every move you make
Every bond you break
Every step you take
I'll be watching you

The first verse shows watching basically every waking moment.

Every single day
And every word you say
Every game you play
Every night you stay
I'll be watching you

And the second verse shows it goes on day and night.

There is no escape.

Nowadays it’s not so difficult to achieve this given the digital traces we leave everywhere, and the scary thing is that this has been happening, even in Singapore; true to the song someone searched his girlfriend in the police databases (2) However this is not an isolated incident, for example searching for details of his mistress (well the song could be about a mistress too, right?)(3) and there are many other, less romantic reasons for searching databases for individuals’ data (4)(5).

You will notice that these issues have occurred in different years.

I am not picking on the SPF, it’s just that

The cases regarding the Singapore Police Force on jealousy, surveillance, even ownership causing abuse of powers regarding data are

  • Not limited to the police force, it’s ironical (or prescient) because of the name of the band (6)(7)
  • not the only ones that have occurred, just a sample of those that made it to court and mainstream papers

My main point is that our data exists in so many places that the lyrics of the song can be taken literally.

Another thing to bear in mind is that in all these cases, the people who accessed the data actually had the privilege to do so, and they abused that privilege.

As a side not, I always tend to ask for all identifying information to be stripped off or the data anonymised before I work on any analysis/model. I think it is good practice.

The real question is whether enough is being done to prevent such abuses. And given that they keep occurring, the answer is no.

As more and more data is being captured about us, with more and more cameras being placed all over and technologies like facial recognition make it easy to identify and track individuals.

The singer, Sting in 1983 mentioned “I think it’s a nasty little song, really rather evil. It’s about jealousy and surveillance and ownership,”(8).

I wonder what he’d say nowadays. He did warn us about surveillance and ownership.

While The Police warned about what can happen at an individual level, someone else was already singing about a system designed to work at a larger scale.


Eye in the Sky (Eye in the Sky) – The Alan Parsons Project (1982)

This is another song many of us have hummed, “Eye in the sky, looking at you, I can read your mind…”

Casinos were some of the 1st people to really look into analytics and human behaviour, going as far as designing the whole outlay of casinos, not only with FengShui (9) but also human minds in place. And that was what Alan Parsons project had written about.

But it is worth going into more details of the lyrics.

Many of us are familiar with the chorus (10) that starts:
I am the eye in the sky
Looking at you
I can read your mind

The idea is that surveillance is not just watching but has a predictive element “I can read your mind”. That was in 1982. And it goes even deeper:

I am the maker of rules
Dealing with fools
I can cheat you blind

Those who conduct the surveillance and the predictive analysis also make rules we have to obey, as fools. And since they are in control, they can cheat us if they choose to, so we better behave accordingly.

And the third part of the chorus:

And I don't need to see any more to know that
I can read your mind (looking at you)
I can read your mind (looking at you)
I can read your mind (looking at you)
I can read your mind

The information gathered is sufficient to predict what we do, what we are…

And they make it very clear in the 3rd verse that the system is not something you can easily beat, it is futile to resist:

Don't leave false illusions behind

Cause I ain't gonna live anymore believing
Some of the lies while all of the signs are deceiving

Although the song goes quite dark, it also, earlier tried to use the carrot rather than the stick:

Don't say words you're gonna regret
Don't let the fire rush to your head
I've heard the accusation before
And I ain't gonna take any more
Believe me
The sun in your eyes
Made some of the lies worth believing

This is very true today where whatever we publish (this included) is captured ‘forever’ and can come to bite you in your behind, “Don’t say words you’re gonna regret”. But the ending of this verse is an encouragement to believe the lie “The sun on your eyes made some of the lies worth believing”, if we choose to, we can live contentedly.

Recently I was at a neighbourhood shop queuing for soya bean curd. A boy came in with his father and was looking around the shop. He was pointing out the cameras and counting them. I will ashamedly admit I had not paid attention.

Quick question, which city do you think has the most cctv cameras per sq km?

If you guessed Beijing or any city in China, you’d be wrong.

Chennai in India has the highest number of cctv cameras per sqkm, 657 (11), more than twice that of Beijing.

Anyway, back to the song… I feel that the song is a warning about surveillance and all that goes with it. That applies ot the whole album. Don’t take my word for it, their website says so too (12)

The concept behind this album was related to belief systems, whether they be religious beliefs, political beliefs or belief in luck (as in gambling). Generally the concept is related to the universal idea that there is someone looking down on us all. The expression is also used in military and surveillance contexts.

The Alan Parsons Project was direct about surveillance and hinted at how we probably could live an easier life if we complied to the rules.

But in true metal fantasy fashion, Ronnie James Dio sang about not bowing to the system while describing it very aptly, in 1992.


Computer God (Dehumanizer) – Black Sabbath (1992)

In 1992, Black Sabbath came up with the album dehumanizer, and the most relevant song for today’s theme is “Computer God”(13). You can find the full lyrics here (14).

The first verse itself contains the lyrics:

Waiting for the revolution
New clear vision - genocide
Computerize god - it's the new religion
Program the brain - not the heartbeat

The first verse, in a nutshell warns about the unstoppable march of technology. We have seen how technology is being used today (2024) to choose targets and ‘help’ decide their fate (15). The song eventually pushes to the risk of genocide of the human race.

Black Sabbath foresaw the unstoppable influence of technology, almost becoming a religion, and plead that the computers should help the brain, not the heart, because the heart is what makes us human. Perfect fit for the theme ‘Dehumanizer’.

The bridge (by the way illustrates the amazing talent of RJD) seems to hint at our addiction to social media and the effects it can have on us:

Midnight confessions
Never heal the soul
What you believe is fantasy

Many of us are attached to our devices at midnight, but is what is portrayed on social media real or fantasy? Is is just a way to learn about us to control us? Social media behaviour is also being used to identify people with certain traits and action is being taken (16)

Your past is your future
Left behind
Lost in time
Will you surrender

The next 4 lines hint at prediction, where your actions in the past, all of them, including those on social media (midnight confessions and the fantasy) are used to control your future since everything is calculated. Planned, and you just follow the recommendations that are fed to you while on social media (literally what your feed is calculated to be) or the ads, recommendations based on your profile that are shown to you. The question is “will you surrender”?

I, of course, am guilty of helping people surrender. When a ‘data scientist’, or ‘AI’ decides what offer to make you, and you pick it up, it counts as a success and reinforces the machine and directs what you will see next, you are being learned, your brain is being ‘programmed’ in a way. Are you being helped, or controlled? There is a thin line there, has it been crossed? Remember, this warning came more than 30 years ago.

The song ends on a grim note, warning us to think about what it is that makes us human (again, the album’s theme), and whether this is at risk:

Virtual existence
With a superhuman mind
The ultimate creation
Destroyer of mankind

It sounds a lot like “The Matrix” trilogy (17) but preceded it by 7 years.

Would you prefer the blue pill or the red pill?


Conclusion

The nice thing is that people have been thinking of and anticipating changes that advancing technology could bring to our society and the way we live. We are at a stage where the works of these people are all around us, we have been exposed to them. Have we been listening or just hearing?

Like many things in life, it is up to each individual to decide. Hopefully each of us first of all is aware of the choice, and at some point makes it.


  1. https://sitn.hms.harvard.edu/flash/2017/history-artificial-intelligence/
  2. https://www.straitstimes.com/singapore/courts-crime/policeman-jailed-for-using-official-portal-to-conduct-illegal-search-on
  3. https://www.straitstimes.com/singapore/courts-crime/cop-fined-4k-for-illegally-accessing-police-computer-system-to-check-on
  4. https://www.straitstimes.com/singapore/courts-crime/police-nsf-illegally-accessed-man-s-files-snapped-photo-of-him-being-handcuffed-and-shared-it-with-chat-group
  5. https://www.todayonline.com/singapore/police-officer-checked-confidential-spf-database-friend-who-turned-out-be-criminal-gets-jail-2204876
  6. https://www.channelnewsasia.com/singapore/mom-officer-asked-ex-dbs-colleague-access-salary-information-3770021
  7. https://www.straitstimes.com/singapore/courts-crime/man-gets-2-weeks-jail-for-abetting-bank-employee-in-making-unlawful-search-on-its-computer-system
  8. https://ig.ft.com/life-of-a-song/every-breath-you-take.html
  9. https://singaporegeomancy.wordpress.com/rws/
  10. https://www.azlyrics.com/lyrics/alanparsonsproject/eyeinthesky.html
  11. https://surfshark.com/surveillance-cities
  12. https://www.the-alan-parsons-project.com/eye-in-the-sky
  13. You can enjoy the studio version (https://www.youtube.com/watch?v=T8bvi1gewB8) or the live version when the singer was 67 a few months before his departure to Metal Heaven due to cancer (2009)( https://www.youtube.com/watch?v=j9syt-i5ju0 )
  14. https://www.azlyrics.com/lyrics/blacksabbath/computergod.html
  15. https://www.theverge.com/2024/4/4/24120352/israel-lavender-artificial-intelligence-gaza-ai
  16. https://www.arabnews.com/node/2495816/media
  17. https://en.wikipedia.org/wiki/The_Matrix

 

 


Wednesday, 17 April 2024

ML/(Gen)AI: get the basics right, unless all you want to do is brag or punish

Recently we have seen a few walk-backs, tail-between legs moments in the field of applications of ML/AI; the most interesting one from my point of view is Amazon stopping its ‘just walk out’ from its grocery stores (1). The reason I find it interesting is that behind all the tech, there were a thousand people checking the purchases (2). Hands up if you thought that it was all done by machines…

However, I will give credit where it is due, the ability to just walk out of a store after shopping, knowing that your purchases have been accurately tracked and the correct amount deducted from your accounts is a pretty useful feature. (3) It saves the consumer an appreciable amount of time and effort, and presumable at low to no cost especially if was truly automated)

And to me, analytics/ML/AI ‘s main aim should be to make people’s lives easier. Saving time and low to no cost while shopping is a good thing.

With this as context, I am sure you will understand my exasperation at HDB and ST Engineering(*).

HDB is using AI to detect power failures (4) – as if these occur frequently in Singapore…. ST Engineering even wants to sell its AI capabilities, even actionable intelligence (5)

However, to me, the basic functions the organisations are hired to do have to be done properly first, it’s like the Maslow hierarchy of needs (6), start by getting the basic needs right first. And this does not only mean the snazzy jazzy AI stuff, but the whole implementation process.

One of the HDB carparks we use very often is near a Sheng Siong Supermarket  Coffee Shop + sundry shop… a very well utilized area within a block of HDB flats. The carpark of this area is managed by ST Engineering.

And the car park system has been erratic for a long while, at least 6 months now. You can tell who is a regular user of the car park because they give the car near the gantry enough space to reverse, reposition a few times to try and get the sensors to detect the vehicle (7). My question is, how is it possible that with their tools at their disposal, ST Engineering has not detected issues with this gantry? I am not even talking preventive maintenance, I am talking about usage being affected… That’s even more basic.

To add to this, I have a very specific incident.

It was raining very heavily when we were trying to exit the carpark, and the barriers simply wouldn’t go up. I exited the vehicle to press for attention from a human (ST Engineering, I assume has a number of people who can deal with the situation). The moment connection was made, it was cut-off; basically the human hung up. Twice. While I was getting drenched.

I called the helpline once we managed to get out of the car park (thank you to the people queuing for their patience, and the closest vehicle knowing to leave large room for maneuvering.) All I got was basically the communication is spoilt, we will fix it. I asked for written feedback, gave my email address, and noting came from ST Engineering. To me sounds like the case was not even lodged and there may have been covering for a colleague.

The point is, with simple use of Analytics,

  1. the faulty gantry should have been detected earlier, rather than wait for complaints
  2. there should be an automated system to ensure cases and raised and closed with SLAs, and this should be tracked automatically. Again, this is simple using today’s tools.

To me ST Engineering has failed in analytics and process, and in customer care.

How about HDB you ask?

Well, HDB outsourced the management of the carpark to ST engineering. Do they have customer satisfaction reports from ST Engineering, or do they not care? They must be happy with ST Engineering reports and performance – although I doubt the contract involves more than $. But also the design of the car park is bad. I got drenched attempting to communicate with the human managing gantry issues. A couple of metres from the gantry is a nicely covered walkway. I would think that extending the coverage to the gantry would not have costed that much. But hey, who cares?

What I am saying is very simple, before you start talking of GenAI, make sure you have the basic right, take care of Maslow’s hygiene and safety issues before you go for you own self-actualisation. After all, while HDB has a virtual monopoly on parking, customers should matter, don’t you think?

Conclusion

Build useful analytics, useful to the your users, make sure your KPIs reflect that, and build them into contracts. On the contractor side, track and analyse your true performance continuously. It is not rocket science, but still so many organisations fail at making lives of their stakeholders easier. Although, it would seem HDB/contractors are focused on maximizing revenue, investing in punishing rather than delivering good service (8)(9).


  1. https://www.theverge.com/2024/4/2/24119199/amazon-just-walk-out-cashierless-checkout-ending-dash-carts
  2. https://www.bloomberg.com/opinion/articles/2024-04-03/the-humans-behind-amazon-s-just-walk-out-technology-are-all-over-ai
  3. this is a very different experience from NTUC supermarket self-checkout, but hat’s for another day
  4. https://sbr.com.sg/telecom-internet/news/hdb-eyes-ai-powered-energy-system-in-tengah
  5. https://www.stengg.com/en/digital-tech/data-science-analytics-and-ai/
  6. https://www.simplypsychology.org/maslow.html
  7. Each vehicle in SG has an IU (In-vehicle Unit) and when you get into a car park, the IU number is read, the gantry opens, and upon exit the IU number is read, the time and relevant fee calculated and deducted from your cashcard within the IU, and the gantry opens.
  8. https://blackdotresearch.sg/secret-devices-installed-in-hdb-car-park-gantries-to-catch-tailgaters/
  9. https://tnp.straitstimes.com/news/singapore/hdb-crack-down-carpark-fee-evaders

* HDB is the Housing Development Board, a government agency responsible for public housing in Singapore, around 77% of residents live in HDB flats. ST Engineering is a government linked entity specialising in aerospace, electronics, land systems and marine sectors.

Sunday, 10 December 2023

NTUC fairprice shines a new path in AI

Recently, I was having a discussion on the potential effects of large scale adoption of LLMs (and AI in general), and one of the risks was a move towards uniformity/homogeneity, or a loss of randomness in the human experience. (1)

Basically, if algorithms are designed to give you ‘the most likely’ or ‘the best’ answer (this may not always have to be the case (2)), then everyone would get similar answers and be driven to same things.

Add to this the fact that as more people use LLMs, more and more content on the internet will be LLM generated, and therefore the training data used for LLMs will include a higher percentage of LLM created data as opposed to human created data. 

Fear not!

A data scientist at NTUC fairprice in Singapore has managed to build a machine (apply an algo) that gives very interesting answers:


The AI built by NTUC understands that, after a meal, you can use 2 similar products, similar in the sense that you, as a human, have a choice to do 1 of 2 things:

  1. do the dishes using the sponge, or
  2. have a piece of chocolate

There still is hope!

Or despair“mummy/daddy, it’s not me! It’s the machine who told me I could do either one since they are similar”


  1. https://www.linkedin.com/feed/update/urn:li:activity:7134835884893290497/
  2. https://www.linkedin.com/feed/update/urn:li:activity:7124551149268963328/


Sunday, 19 November 2023

You are overpaying for your vehicle insurance. It doesn't have to be this way.

I am sure you have been making this complaint over the years, but didn’t have much choice since prices are around the same and policies are designed to be sticky or not so advantageous to get out of (that’s for another day).


Singapore General Insurance Association says so too!

But now, ladies and gentlemen, we have the ultimate confirmation. This comes from the GIA the association that groups General Insurers in Singapore “About two in 10 motor insurance claims in Singapore are fraudulent, often involving exaggerated injuries and inflated vehicle damage”(1)

 

And the president of Budget Direct

The president of Budget Direct, who usually prides itself in competitive rates even admitted: “In the end, all motorists are victims of motor insurance fraud as we all end up paying higher premiums as a result

This is the key you see, the claims paid out in fraudulent cases simply get translated into increased premiums for ALL vehicle insurance customers. Irrespective of whether you commit fraud, are a scam victim, or are accident/claim-free, you are paying for the fraudsters’ bread butter and cake, and the insurers maintain their healthy margins and profits


The Insurers have no incentive to act on fraud

The thing is the GIA is saying, it is up to you, the customer to stop the fraud. And that I find laughable. Let’s see what are the main causes of fraud as per GIA …

  1. Beware of Phoney Helpers: After an accident, individuals may offer "help" and pressure victims to follow their directions, often leading them to unauthorized repair shops or overpriced towing services.
  2. Staged Accidents: Scammers stage accidents, causing victims to collide with their vehicles and then falsely accuse victims of causing the collision. They often fake injuries and make substantial claims for damage and injuries.
  3. Phoney Witnesses: Suspect convenient witnesses who support the other driver's account, often suggesting a staged accident.

1 Unauthorised repair shops:

Most vehicle owners are aware of the workshops that their insurer accepts, whether by own bad experience, by hearing from friends and family, or from the insurer. Plus, most of the time, unauthorized repair shops costs are not paid by the insurer, if they are, it is a bit rich on the part of insurers to honour the claim while complaining about it.

Plus it is not rocket science to detect highly inflated claims based on pictures and description that accompany the claims. I know because I worked in an insurance company in a much less developed country than Singapore, and I know for fact that they have the data needed to deal with this, the question is financials and will.

 

2 Staged Accident

And how is that the fault of the insured? The insured is getting scammed at the same time as the insurer, unless GIA is claiming that the insured is somehow going along with the scammers… more on this later

 

3 Phoney Witnesses

Again, how will someone who has just been in an accident be able to detect whether witnesses are phoney or not?

 

Unless Singapore is a nation of scammers (not scammed/scam victims (2)), it just doesn’t make sense to think that individual people involved in accidents are part of the scam. So should victims pay the price twice (once being scammed and second via higher premium, and probably loss of NCB)?.

 

So my arguments that follow assume that Singapore is not a nation of scammers (unlike (3)). Afterall Singapore is only beaten by Finland, New Zealand, and Denmark in terms of corruption perception. (4)

 

The fact that GIA mentions Staged Accidents, Phoney Witnesses seems to indicate syndicates are at play, or at best a group of people who are in the business of scamming accident vistims. In fact, it is likely that staged accidents and phoney witnesses occur together, rather than separately.

 

You can have a staged accident without phoney witnesses, but very unlikely to have phoney witnesses to a real accident.

So chances are, there are syndicates/gangs/groups of scammers at work. It is ridiculous for GIA to expect an individual consumer to be able to detect them, don’t you think so?

 

So what can be done?

The answer, in most of my blogs, is Analytics!

 

Inflated Claims

I briefly mentioned the solution to GIA issue 1, inflated claims. Analytical models can be built to detect inflated claims. The beauty of this is that it can be even employed to detect which workshops are cheating. 

But, from experience, there is little will power in senior management to do something that will rock the boat. It is important for analytics people to learn that not everything that can be done will be done, other factors come into play, obviously whether it is financially viable (in this case I am quite sure it pays for itself quite quickly, a couple of months of work to build, another month to finetune, and the low running costs for a basic solution), or politically (is it worth opening pandora’s box at your preferred workshops?). 

In sum, technically easy to solve and pays for itself, management wise depends on management.

It's even worse at the GIA level where, as people in SG know, some workshops are on the panel for multiple insurers.

 

Staged Accidents and Phoney Witnesses

Accidents, by their nature, are (most of the time) unexpected, hence being able to, by simply looking say at road and traffic conditions, location, it is not that straight forward estimate the probability of an accident and highlight the stranger ones; one of the reasons being that humans play a large role and it is not so easy to get data on all actors involved, not only all drivers involved and their data, but also drivers in the immediate vicinity.(5)

 

The easy way to detect staged accidents and phoney witnesses is to focus on the people, not the vehicles. The key assumption is that these are the work of groups of people. Hence they are likely to play different roles at different times. Let me put it this way, how likely is it that someone is a claimant, a witness of an accident, and at fault for a vehicular accident all within say a year?

 

The idea is that, chances are, a member of the group is likely to play different roles over time, sometimes even with different insurers to make the chances of detection lower. This is something very easy to pick up using social network analytics, especially at the GIA or police level.

 

Conclusion

Saying that 20% of claims are likely to be fraudulent and placing the onus on customers/insured in the case of vehicular insurance in Singapore is a joke.

1 The main causes as stated by GIA are unlikely to be caused by claimants

2 The GIA itself (or to a lesser degree large insurers) are the ones who have the data easily at hand to detect potential fraudulent cases effectively

3 however the insurers (and the GIA) have little incentive to do so since they can simply pass the costs to customers.

 

However, relatively simple analytics can, right now, help alleviate this problem and allow customers to pay lower premiums since the risk of fraud can be mitigated. It is just a question of will from the insurers’ point of view.

 

  1. https://insuranceasia.com/insurance/news/20-singapores-motor-insurance-claims-are-fraudulent-giaj
  2. https://www.straitstimes.com/world/14-trillion-lost-to-scams-globally-s-pore-victims-lost-the-most-on-average-study
  3. https://www.youtube.com/watch?v=q5PI5ZtJTSY
  4. https://www.transparency.org/en/cpi/2021
  5. That is not actually true anymore in Singapore, I will explain in a subsequent blog.