Live data from Hacker News

Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

github.com

261–270 of 363 posts

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#262

Earlier quoted context omitted.

I think you're underestimating the severity of child abuse by orders of magnitude. CSAM is a database of child rape, not child nudity.

idk what's in the database, whether it's rape or nudes or both. Although depictions of sexual acts versus simple nudity seems like a logical place to draw a line, all the lines on adult pornography are arbitrarily drawn based on "community standards", and we're only a few decades away from state-level bans on any nudes as "porn" in the US, including artistic photos. (Not to mention anti-sodomy laws). Even if what's i…

You would presumably have the 30+ images on your device or in iCloud to prove your innocence.

For you to get caught up in this dragnet, 30+ plus images have to match NeuralHash’s of known illegal images, thumbnails of those images have to also produce a hit when run through a private hash function that Apple only has, and two levels of reviewers have to confirm the match as well.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#263
post #251

Earlier quoted context omitted.

You store the photos you want to keep private in another app. I'm sure there are lots in the App Store. Still waiting on that citation.

If the default behavior is not to exclude photo rolls from this new feature, I'm not sure where the argument exists. Telling iOS users they should download some app to keep photos private is absurd.

If a photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't.

Still waiting on that citation.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#264

This is just getting wilder and wilder by the day, how spectacularly this move has backfired. As others have commented, at this point all you need is someone willing to sell you the CSAM hashes on the darknet, and this system is transparently broken. Until that day, just send known CSAM to any person you'd like to get in trouble (make sure they have icloud sync enabled), be it your neighbour or a political figure, an…

Imagine being a parent that made pictures of their own children that bathed naked in their own backyard. I don't know about you, but my parents certainly have lots of embarassing pictures of me in their photo album. There will be so many false positives in that system, it's ridiculous. It doesn't necessarily have to be a false colliding hash, but legitimate use cases that - by definition - are impossible to train neu…

In the digital age, I certainly wouldn't be taking such pictures, let alone uploading them to cloud storage. Not because of any concerns about neural hashing, but simply because I wouldn't want such pictures of my children getting leaked / stolen / hacked.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#265

Earlier quoted context omitted.

Not resembles. The adversarial image has to match a private perceptual hash function of the same CSAM image that the NeuralHash function matched before a human reviewer ever looks at it.

Do you have any material on this private function?

Not beyond the documents Apple has shared. Presumably it will be kept that way given it prevents an adversarial attack against it.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#266

Earlier quoted context omitted.

The adversarial images have to match both the NeuralHash output of CSAM, plus another private perceptual hash that points to the same image that only Apple has access to, plus a human reviewer needs to agree it is CSAM, and this has to happen for 30 images.

Do you think the reviewer will dismiss the alert if only 29 images look like CSAM and the last one looks like a Beagle? What if only 1 looks like CSAM and the other 29 are animal pictures? It's a safe bet that they will report your account for the 1 that looks like CSAM.

30 images are required to match known bad NeuralHash’s before Apple has any access to look at any of those 30 images.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#267
post #100
post #82

Really naive question. What's to stop apple from using two distinct and separate visual hashing algorithms? Wouldn't the collision likelihood decrease drastically in that scenario? Again, really naive but it seems like if you have two distinct multi-dimensional hashes it would be much harder to solve the gradient descent problem.

I'm fairly sure they do, actually. It was in one of the articles earlier today that Apple has a distinct, secret algorithm they perform on suspected CSAM server side after it gets flagged by the client side neural hash. Then only after 30 such images from a single user are identified as CSAM by both algorithms will they be sent to a human reviewer who will confirm their contents. Then, finally, law enforcement will b…

> It was in one of the articles earlier today that Apple has a distinct, secret algorithm they perform on suspected CSAM server side

But then they still need to upload the original image to the server, and what was the reason for doing the scanning client-side then when they still upload it?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#268
post #99

I don't see how this is fixable on their end. Several people have suggested simply layering several different perceptual hash systems, with the assumption that it's difficult to find a colliding image in all of them. This is pretty suspect - there's a reason we hold a decades-long competition to select secure hash functions. Basically, a function can't generally achieve cryptographic properties (like collision-resist…

> First, as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possibility that the match threshold was exceeded due to non-CSAM images that were adversarially perturbed to cause false NeuralHash matches against the on-device encrypted CSAM database. https://www.apple.com/chi…

Honestly missed this.

Is that security-through-obscurity? If the model and weights for the second hash function became public, then we could still construct a collision on both functions, right?

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#269
post #53

Why does matter? The photo looks nothing like the target? If someone looks at the two images wouldn’t they see they’re not the same and therefore the original image was mistakenly linked with the target

Apple's reviewers, by law, cannot look at the target. No one except NCMEC is allowed to possess the target (CSAM material). So Apple will be looking at a low-res grayscale image of whatever the collided image is, which could be legal adult pornography (let's say: a screengrab of legal "teen" 18+ porn), but the CSAM filter tells it that it's abuse material! What would you do as the Apple reviewer? (Hint: You only have…

But NCMEC will then review the reports and see that it doesn't match the target.

Re: Show HN: Neural-hash-collider – Find target hash collisions for NeuralHash

#270
post #251

Earlier quoted context omitted.

If the default behavior is not to exclude photo rolls from this new feature, I'm not sure where the argument exists. Telling iOS users they should download some app to keep photos private is absurd.

If a photo is about to be uploaded to iCloud Photo Library then it is scanned for CSAM. If it's not, it isn't. Still waiting on that citation.

Are we arguing the same thing? How does one opt-out a specific photo? It's not possible as far as I know.
Post reply on HN