Earlier quoted context omitted.
Doing that would mean the NeuralHash would change though. And you'd have to not only get CLIP to identify CSAM in the generated image but also negate the parts of the generated image that are causing CLIP to label it as "generated" (while still colliding with the target NeuralHash). Unclear how hard this would actually be in practice (if I were going to attempt it, the first thing I'd try is to evolve a colliding ima…
Take 2 CSAM pictures, known. Combine into one image. Swing and a miss. Not in the CSAM dataset. Take two images. Encode alternating pixels. Decode to get the original image back. Convert to different encodings print to PDF or Postscript. Encode as base64 representations of the image file... Who are we trying to fool here? This is kiddie stuff. This is more about trying to implant scanning capabilities on client devic…
Did we think they didn't already have that ability?