Live data from Hacker News

The Problem with Perceptual Hashes

rentafounder.com

401–410 of 440 posts

Re: The Problem with Perceptual Hashes

#401

Regarding false positives re:Apple, the Ars Technica article claims > Apple offers technical details, claims 1-in-1 trillion chance of false positives. There are two ways to read this, but I'm assuming it means, for each scan, there is a 1-in-1 trillion chance of a false positive. Apple has over 1 billion devices. Assuming ten scans per device per day, you would reach one trillion scans in ~100 days. Okay, but not al…

> Apple has over 1 billion devices. Assuming ten scans per device per day, you would reach one trillion scans in ~100 days. People like to complain about the energy wasted mining cryptocurrencies - I wonder how this works out in terms of energy waste? How many people will be caught and arrested by this? Hundreds or thousands? Does it make economic sense for the rest of us to pay an electric tax in the name of scannin…

> I wonder how this works out in terms of energy waste?

Cryptocurrency waste is vastly greater. It doesn't compare at all. Crypto wastes as much electricity as a whole country. This will lead to a few more people being employed by Apple to verify flagged images, that's it.

Re: The Problem with Perceptual Hashes

#402
post #171

Regarding false positives re:Apple, the Ars Technica article claims > Apple offers technical details, claims 1-in-1 trillion chance of false positives. There are two ways to read this, but I'm assuming it means, for each scan, there is a 1-in-1 trillion chance of a false positive. Apple has over 1 billion devices. Assuming ten scans per device per day, you would reach one trillion scans in ~100 days. Okay, but not al…

Eh...I don't think of it as one in a trillion scans...but one in a trillion chance per image. I have something like 2000 pics. My wife, at least 5x that number. If we split the difference, and assume the average device has 5000 pics, that's already hitting false positives multiple times. Feel sorry for the first 5 to get their account banned on day 1 because their pic of an odd piece of toast was reported to the govt…

[deleted]

Re: The Problem with Perceptual Hashes

#403

I've also implemented perceptual hashing algorithms for use in the real world. Article is correct, there really is no way to eliminate false positives while still catching minor changes (say, resizing, cropping, or watermarking). I'm sure I'm not the only person with naked pictures of my wife. Do you really want a false positive to result in your intimate moments getting shared around some outsourced boiler room for…

I, too, have worked on similar detection technology using state of the art neural networks. There is no way there won't be false positives, I suspect many, many more than true positives. It is very likely that as a result of this, thousands of innocent people will have their most private of images viewed by unaccountable strangers, will be wrongly suspected or even tried and sentenced. This includes children, teenage…

> thousands of innocent people will have their most private of images viewed by unaccountable strangers, will be wrongly suspected or even tried and sentenced

Apple says: "The threshold is set to provide an extremely high level of accuracy and ensures less than a one in one trillion chance per year of incorrectly flagging a given account."

What evidence do you have against that statement?

Next, flagged accounts are reviewed by humans. So, yes, there is a minuscule chance a human might see a derivative of some wrongly flagged images. But there is no reason to believe that they "will be wrongly suspected or even tried and sentenced".

Re: The Problem with Perceptual Hashes

#404
post #403

Earlier quoted context omitted.

I, too, have worked on similar detection technology using state of the art neural networks. There is no way there won't be false positives, I suspect many, many more than true positives. It is very likely that as a result of this, thousands of innocent people will have their most private of images viewed by unaccountable strangers, will be wrongly suspected or even tried and sentenced. This includes children, teenage…

> thousands of innocent people will have their most private of images viewed by unaccountable strangers, will be wrongly suspected or even tried and sentenced Apple says: "The threshold is set to provide an extremely high level of accuracy and ensures less than a one in one trillion chance per year of incorrectly flagging a given account." What evidence do you have against that statement? Next, flagged accounts are r…

> Apple says: "The threshold is set to provide an extremely high level of accuracy and ensures less than a one in one trillion chance per year of incorrectly flagging a given account."

I'd rather have evidence for that statement first, since these are just funny numbers. I couldn't find false-positive rates for PhotoDNA either. How many people have been legally affected by false positives so far, how many had their images viewed? The thing is, how exactly the system works has to be kept secret, because it can otherwise be circumvented. So these technical numbers will be unverifiable. The outcomes will not, and this might be a nice reason for a FOIA request.

But who knows, it might not matter, since it's a closed source, effectively uncontrollable program running soon on millions of devices against the interest of their owners and no one is really accountable so false positives can be treated as 'collateral damage'.

Re: The Problem with Perceptual Hashes

#405

> At my company, we use “perceptual hashes” to find copies of an image where each copy has been slightly altered. Kind of off topic, does anyone happen to know of some good software for doing this on a local collection of images? A common sequence of events at my company: 1. We're designing a website for some client. They send us a collection of a zillion photos to pull from. For the page about elephants, we select t…

https://pypi.org/project/ImageHash/

Thank you!

Re: The Problem with Perceptual Hashes

#406
post #401

Earlier quoted context omitted.

> Apple has over 1 billion devices. Assuming ten scans per device per day, you would reach one trillion scans in ~100 days. People like to complain about the energy wasted mining cryptocurrencies - I wonder how this works out in terms of energy waste? How many people will be caught and arrested by this? Hundreds or thousands? Does it make economic sense for the rest of us to pay an electric tax in the name of scannin…

> I wonder how this works out in terms of energy waste? Cryptocurrency waste is vastly greater. It doesn't compare at all. Crypto wastes as much electricity as a whole country. This will lead to a few more people being employed by Apple to verify flagged images, that's it.

In net terms, you're probably right. But at least the energy used for cryptocurrency is being used toward something that might benefit many (commerce, hoarding, what-have-you), vs against something that might result in the arrest of few.

The economics I'm thinking of are along the lines of cryptocurrency energy usage per participant, vs image scanning energy per caught perpetrator. The number of caught perpetrators via this method over time will approach zero, but we'll keep using energy to enforce it forever.

All this does is remove technology from the problem of child abuse, it doesn't stop child abuse.

Re: The Problem with Perceptual Hashes

#407
post #126

Earlier quoted context omitted.

It's used to emphasize the concept that if anyone would have nudes of my wife, it would be me, her husband. Here's another example of "even" used as an emphasizing word. >I don't know how to answer that. >Even I don't know how to answer that. Hope that helps you with your ESL tests!

The parallel to the construction you used before would be "I don't even know how to answer that" which means something quite different from "Even I don't know how to answer that".

English is a pragmatic language, meaning word order is flexible. In my first sentence, the 'even' can go in both places while retaining the same meaning. Good luck with your ESL tests as well.

Re: The Problem with Perceptual Hashes

#408
post #393

Earlier quoted context omitted.

Apple already use the same algorithm on photos in email, because email is unencrypted. Last year Apple reported 265 cases according to the NYT. Facebook reported 20.3 million. Devolving the job to the phone is a step to making things more private, not less. Apple don’t need to look at the photos on the server (and all cloud companies in the US are required to inspect photos for CSAM) if it can be done on the phone, r…

> all cloud companies in the US are required to inspect photos for CSAM) This is extremely disingenuous. If their devices uploaded content with end to end encryption there would be no matches for CSAM. If they were required to search your materials generally, then they would be effectively deputized-- acting on behalf of the government-- and your forth amendment protection against unlawful search would be would exten…

This is not disingenuous - it's a statement of the reality within which we live. You can claim all you like that there is no coercion taking place, and that e2e would solve all ills, but it doesn't change the facts that:

- All cloud providers scan for it. Facebook, Google, Amazon, Apple, Imgur ... There's a list of 144 companies at NCMEC. There must be a damn good reason for that consensus...

- Because they scan for it, they are obliged (coerced, if you will) to report anything they find. By law.

- Facebook (to pull an example out of the air) reported 20.3 million times last year. Google [1] are on for 365,319 for July->Dec and are coming up on 3 million reports. Apple reported 265 cases last year.

- Using e2e doesn't remove the tarnish of CSAM being on your service. All it does is give some hand-wavy deniability "oh, we didn't know". Yes, but you chose to not know by enforcing e2e. That choice was the act, and kiddy-porn providers flocking to your service was the consequence. Once the wheels of justice turn a few times, and there becomes a trend of insert your e2e service being where all the kiddy-porn is stored, there's no coming back.

The problem here is that there's no easy technical answer to a problem outside the technical sphere. It's not the technology that's the problem, it's the users, and you don't solve that by technological means. You take a stand and you defend it. To some, that will be your solution ("It's all e2e, we don't know or take any ownership, it's all bits to us"). To others, it'll be more like Apple's stance ("we will try our damndest not to let this shit propagate or get on our service"). Neither side will easily compromise too much towards the other, because both of them have valid points.

You pays your money and you takes your choice. My gut feeling is that the people bemoaning this as if the end-times were here will still all (for reasonable definitions of "all") be using iCloud in a few months time, and having their photos scanned (just like they have been for ages, but this time on upload to iCloud rather than on receipt by iCloud).

[1] https://transparencyreport.google.com/child-sexual-abuse-mat...

Re: The Problem with Perceptual Hashes

#409
post #126

Earlier quoted context omitted.

The parallel to the construction you used before would be "I don't even know how to answer that" which means something quite different from "Even I don't know how to answer that".

English is a pragmatic language, meaning word order is flexible. In my first sentence, the 'even' can go in both places while retaining the same meaning. Good luck with your ESL tests as well.

> In my first sentence, the 'even' can go in both places while retaining the same meaning.

I really don't think it can. Looking through examples of people using that construction [1] they are all being used to emphasize the speaker's lack of something, without any implication that if someone were to have one it would be the speaker. Do you see any examples of someone using it your way?

> Good luck with your ESL tests as well.

I don't know if it's apparent to you how condescending that sounds? But, for what it's worth, I'm a native speaker of English and have a degree in linguistics.

[1] https://www.google.com/search?q=%22i+don%27t+even+have%22

Re: The Problem with Perceptual Hashes

#410
post #291

I'm not insane in thinking this stuff has to be super vulnerable to adversarial attacks, right? And it's not like adversarial attacks are a solved problem or anything.

Wouldn't you need a way to determine if an image you generate has a match in Apple's database? The way it's set up, that's not possible: "Given a user image, the general idea in PSI is to apply the same set of transformations on the image NeuralHash as in the database setup above and do a simple lookup against the blinded known CSAM database. However, the blinding step using the server-side secret is not possible on…

I was thinking something along the lines of applying small transformations to all images before uploading, or even just images that are known to be problematic. Seems like something that people who traffic cp would be willing to do
Post reply on HN