Live data from Hacker News

ImageNet contains naturally occurring Apple NeuralHash collisions

blog.roboflow.com

81–90 of 530 posts

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#81

> By taking advantage of the birthday paradox, and a collision search algorithm that let me search in n(log n) time instead of the naive n^2 Someone got more details on that? How does the birthday paradox come into play here?

He means that even though the chance of two random images colliding is ~ 1/ 2 trillion, once you get up to a set of order sqrt(2 trillion) you have a good chance of having a collision amongst all pairs.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#82
I’m much more worried about adversarial attacks rather than accidental false positives.

For example, a year ago I was trying to track down how some unscrupulous photos ended up in my photo library. I finally realized that Telegram had, without my knowing permission, been adding all photos I had received in a crypto discussion group to my Apple photo library.

There seem many ripe opportunities for targeting.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#83

Earlier quoted context omitted.

That’s the same as what Apple is going to do - scan right before sending to iCloud

The same as what Apple is saying it's going to do , there's a difference.

If you don't trust Apple then they could've already done what you're concerned about before they announced this. I don't really get it. Either you trusted Apple before this and you continue to, or you didn't before, and continue not to. If it's the later, then you shouldn't be using Apple services.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#85

Earlier quoted context omitted.

That is literally the status quo with every cloud service. Apple, unlike the others, has said that they will evaluate you on the basis of what’s included in the associated data of your safety voucher, and you can inspect those contents because they’re shipped in the client. Facebook, for all I know, might be calculating a child predator likelihood score on my account based on how often I look up my middle school ex-g…

I don't think we can just appeal to the status quo here and assume it's acceptable. There's a couple reasons. First, how many people really understood this previously? Did society at large actually knowingly accept the current state of things, or did it just happen without most people realizing it? Even here on HN where we'd expect to find people way more knowledgeable about it than in general I'm not sure how well k…

> But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them.

This literally only works once you willing send photos to iCloud.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#86

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

Presumably Apple would be afraid that, say, the EU becomes suspicious, issues a court order to obtain the hashes, notices they cannot audit the CCP hashes, pointedly asks "what is this", becomes absolutely livid that their citizens are spied on by a country that is not them, fines Apple out the wazoo, then extradites whoever is responsible and puts them in prison. I mean, China's not the only player in this. Putting…

Seems pretty trivial to have different servers sides per country, and put there a different db.

EU, China, Iran, US: everyone gets to spy on their own children and forbid whatever they want.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#87

Earlier quoted context omitted.

This is already possible with PhotoDNA. When has it happened?

Your browser cache is not being synced to iCloud; Apple doesn't see it. So no, it is not currently possible.

I'm not talking about Apple, I'm saying in general technology has already been deployed to make what you're describing possible. So where's the evidence of abuse?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#88
post #25

Earlier quoted context omitted.

The OP mentions that two countries have to agree to add a file to the list, but your concern is definitely valid: > Perhaps the most concerning part of the whole scheme is the database itself. Since the original images are (understandably) not available for inspection, it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights adv…

What if those two countries can be Poland and Hungary? These two countries have been passing lots of laws to ostracize and criminalize pro-LGBT content and are friendly to each other.

Fortunately, Hungary and Poland, even combined, are quite small a fish for Apple to just tell them to go pound sand in some form or other. They can even ban iPhone sales, people will just buy them in Czechia.

It's not like China, or India, who not only have huge markets, but could easily hold a chunk of Apple's supply chain hostage.

It's very easy to uphold human rights if it doesn't actually cost you anything.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#89

It doesn’t matter if there are collisions if the two images don’t actually look the same. Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America? PhotoDNA has existed for over a decade doing the same thing with no instances that I have heard of. If some corrupt government wants to get you they don’t need this. They can just unilaterally say you’…

At least part of the concern is that a hash collision is basically "cause" for Apple to then dump and begin manually (like, with humans) reviewing the contents of your device, all of which will be happening behind the closed doors of a private corporation, outside of any of the usual oversight or innocent-presumption mechanisms that come from it happening through the courts. That, combined with a (pretty reasonable)…

[deleted]

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#90
post #62
post #52

Earlier quoted context omitted.

I would expect Apple to say the same thing if the CCP proposed a system of scanning devices last month. I fail to see how this system changes the calculus for how Apple will deal with authoritarian governments. If Apple could stand up to them before this system, why can't they stand up to them with this system?

Apple doesn't stand up to authoritarian governments. They give direct access of their systems to the US and Chinese governments already.

This. We've known Apple is backdoored since at least 2013 with Snowden revelations. Why are people still debating this nearly a decade later? Apple products ARE NOT PRIVATE.
Post reply on HN