What happened
It was reported that on 15 March 2019, a gunman attacked two mosques in Christchurch, New Zealand, and livestreamed the first attack on Facebook. The broadcast ran for around 17 minutes.
Facebook reportedly said the live video was watched by fewer than 200 people while it was happening, and by around 4,000 people in total before it was removed. No user reported the stream during the live broadcast, and the first user report came about 12 minutes after the stream had already ended. Facebook said it removed roughly 1.5 million copies of the video worldwide in the first 24 hours, with about 1.2 million of those blocked at the point of upload.
Facebook also said its automated systems did not flag the video while it ran. The platform leaned on the people watching to report it, and no one did while it was live. What spread afterwards was not one video but a flood of reuploaded copies that the same systems then had to chase.
Facebook later said it worked with law enforcement, including on firearms training footage, to help its systems better recognise this kind of first person attack video in future.
What an auditable version would have shown
An auditable version of this system would show, in a record you could inspect afterwards, what the automated classifiers actually saw during those 17 minutes, what confidence they returned, and why the footage did not cross a threshold for human review. It would show whether live video was being scanned with the same rigour as uploaded video, and whether any escalation path existed that did not wait on a member of the public to press report. Without that record, the failure can only be argued about from press statements rather than traced.
Where the gap was
The gap was in detection, not in review. Reporting at the time indicated the systems had little training data for that kind of first person, weapon forward footage, so the classifiers did not flag it as the atrocity it was. The design leaned heavily on users to report live content, and the people watching this stream were not the people who would report it.
What governance should have looked like
Live video is not the same problem as an uploaded clip, and it should not have been left to the same tools. When a stream sets off a serious warning sign, it needs to reach a person while it is still running, not after someone in the audience decides to report it. That is what a verification gate is for. And there should have been a plain record of what the detection systems saw during those 17 minutes, so afterwards the story could be told from the logs instead of a press statement. That is what a conduct record keeps.
The reference implementation of VerificationGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.
Sources
- Facebook scrambles to remove New Zealand mosque attacker’s livestreamed video (Fortune)
- Facebook says original Christchurch shooting video had 200 live views and 4,000 total views (Fast Company)
- No one reported gunman’s live stream until 12 minutes after it ended (Yahoo News)