5 ms·
How does something like this get through IRB - I always felt IRB was over the top - and then they approve something like this? UMN looks pretty shoddy - the re
by random5634 5y ago
How does something like this get through IRB - I always felt IRB was over the top - and then they approve something like this?
UMN looks pretty shoddy - the response from the researcher saying these were automated by a tool looks like a potential lie.
- deleted 5y ago[deleted]
- thaeli 5y agoThey obtained an "IRB-exempt letter" because their IRB found that this was not human research. It's quite likely that the IRB made this finding based on a misrepresentation of the research during that initial stage; once they had an exemption letter the IRB wouldn't be looking any closer.
- lbarrow 5y agoMy understanding is that it's pretty common for CS departments to get IRB exemption even when human participants are tangentially involved in studies.
- lmkg 5y agoI've seen from a distance one CS department struggle with IRB to get approval for using Amazon Mechanical Turk to label pictures for computer vision datasets. I believe the resolution was creating a specialized approval process for that family of tasks.
- waheoo 5y agoThat sounds like a disconnect from reality.
- WORLD_ENDS_SOON 5y agoI think it is because many labs in CS departments do very little research involving human subjects (e.g. a machine learning lab or a theory lab), so within those labs there isn't really an expectation that everything goes through IRB. Many CS graduate students likely never have to interact with IRB at all, so they probably don't even know when it is necessary to involve IRB. The rules for what requires IRB involvement are also somewhat open to interpretation. For example, surveys are often exempt depending on what the survey is asking about.
- waheoo 5y agoMachine learning automatically being exempt is a huge red flag for me. There are immense repercussions for the world on every comp sci topic. It's just less direct, and often "digital" which seems separate but it's not.
- corty 5y agoIt is also quite easy to pull the wool over an IRBs eyes. An IRB is usually staffed with a few people from the medicine, biology, psychology and maybe (for the good ethical looks) philosophy and theology departments. Usually they aren't really qualified to know what a computer scientist is talking about describing their research. And also, given that the stakes are higher e.g. in medicine, and the bar is lower in biology, one often gets a pass: "You don't want to poke anyone with needles, no LSD and no cages? Why are you asking us then?" Or something to that effect. The IRBs are just not used to such "harmless" things not being justified by the research objective.
- avs733 5y agosee my other comment to the GP. pulling the wool suggests agency and intentionality that isn't necessarily present when you have disciplinary differences like you describe. Simple miscommunication, e.g., using totally normal field terminology that does not translate well, is different.
- corty 5y agoIt is your job as a researcher to make the committee fully understand all the implications of what you are doing. If you fail in that, you failed in your duties. The committee will also tell you this, as well as any ethical guideline. Given that level of responsibility, it isn't easy to ascribe this to negligence on the part of the researchers, intent is far more likely.
- avs733 5y agoIt is absolutely my job, but I don’t necessarily have actionable information that I created a misunderstanding. I submit unclear thing Thing is approved Thing must have been clear right?
- davidkuhta 5y ago'Not ignorance, but ignorance of ignorance is the death of knowledge.' - Alfred North Whitehead
- devmor 5y agoThat's what it seemed like to me as well. Based on their research paper, they did not mention the individuals they interacted with at all. They also lied in the paper about their methodology - claiming that once their code was accepted, they told the maintainers it should not be included. In reality, several of their bad commits made it into the stable branch.
- rocqua 5y ago> In reality, several of their bad commits made it into the stable branch. Is it known whether these commits were indeed bad? It is certainly worth removing them just in case, but is there any confirmation?
- Koliakis 5y agohttps://lore.kernel.org/lkml/78ac6ee8-8e7c-bd4c-a3a7-5a90c7ccb399@roeck-us.net/ https://lore.kernel.org/lkml/78ac6ee8-8e7c-bd4c-a3a7-5a90c7c...
- devmor 5y agoI don't think we know if they contain bugs, but from what I gathered reading the mailing list, we do know that they added nothing of value.
- bogwog 5y agoI don’t think that’s what’s happening here. The research paper you’re talking about was already published, and supposedly only consisted of 3 patches, not the 200 or so being reverted here. So it’s possible that this situation has nothing to do with that research, and is just another unethical thing that coincidentally comes from the same university. Or it really is a new study by the same people. Either way, I think we should get the facts straight before the wrong people are attacked.
- avs733 5y agoNot necessarily. And the conflation of IRB-exemption and not human subjects research is not exactly correct.[0] Each institution, and each IRB is made up of people and a set of policies. One does not have to meaningfully misrepresent things to IRBs for them to be misunderstood. Further, exempt from IRB review and 'not human subjects research' are not actually the same thing. I've run into this problem personally - IRB declines to review the research plan because it does not meet their definition of human subjects research, however the journal will not accept the article without IRB review. Catch-22. Further, research that involves deception is also considered a perfectly valid form of research in certain fields (e.g., Psychology). The IRB may not have responded simply because they see the complaint as invalid. Their mandate is protecting human beings from harm, not random individuals who email them from annoyance. They don't have in their framework protecting the linux kernel from harm any more than they have protecting a jet engine from harm (Sorry if that sounds callous). Someone not liking a study is not research misconduct and if the IRB determined within their processes that it isn't even human subjects research, there isn't a lot they can do here. I suspect that this is just one of those disconnects that happens when people talk across disciplines. no misrepresentation was needed, all that was needed was for someone reviewing this, who's background is medicine and not CS, to not understand the organizational and human processes behind submitting a software 'patch'. The follow up behavior...not great...but the start of this could be a serious of individually rational actions that combine into something problematic because they were not holistically evaluated in context. [0] https://oprs.usc.edu/irb-review/types-of-irb-review/ https://oprs.usc.edu/irb-review/types-of-irb-review/
- nightpool 5y agoMy understanding in this case is not that the IRB declined to review the study plan, but that (quoting the study authors) "The IRB of UMN reviewed the study and determined that this is not human research (a formal IRB exempt letter was obtained)." (more information here: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.pdf https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....) Do you think that the IRB was correct to make the determination they did? It does sound like a bit of a grey area
- 5y ago
- tarboreus 5y agoIRB is useless. They don't use much context, including if the speediness of IRB approval would save lives. You could make a reasonable argument that IRB has contributed to millions of preventable deaths at this point, with COV alone it's at least dozens of thousands if not far more.
- random5634 5y agoI don't disagree.
- angry_octet 5y agoThis is the unfortunate attitude that leads to bad research and reduces trust in science. If you think IRB has contributed to deaths you should make a case, because right now you sound like a blowhard.
- admax88q 5y agoBy COV do you mean Covid? It sounds like you're alluding to the argument that if they'd only let us test potential vaccines on humans right away then we would have had a vaccine faster. I disagree that that's a foregone conclusion, and you certainly need a strong argument or evidence to make such a claim.
- woodruffw 5y ago> the response from the researcher saying these were automated by a tool looks like a potential lie. To be clear, this is unethical research. But I read the paper, and these patches were probably automatically generated by a tool (or perhaps guided by a tool, and filled in concretely by a human): their analyses boil down to a very simple LLVM pass that just checks for pointer dereferences and inserts calls to functions that are identified as performing frees/deallocations before those dereferences. Page 9 and onwards of the paper[1] explains it in reasonable detail. [1]: https://github.com/QiushiWu/QiushiWu.github.io/blob/main/papers/OpenSourceInsecurity.pdf https://github.com/QiushiWu/QiushiWu.github.io/blob/main/pap...
- random5634 5y agoThanks for this, very helpful. Could they have submitted patches to fix the problems based on same tooling or was that not possible (I am not close to kernel development flow)?
- woodruffw 5y ago> Could they have submitted patches to fix the problems based on same tooling or was that not possible (I am not close to kernel development flow)? Depends on what you mean: they knew exactly what they were patching, so they could easily have submitted inverse patches. On the other hand, the obverse research problem (patching existing UAFs rather than inserting new ones) is currently unsolved in the general case.
- deleted 5y ago[deleted]
- psychometry 5y agoI have a feeling that methods of patching the Linux kernel is a concept most members of IRB boards wouldn't understand at all. It's pretty far outside their wheelhouse.