Live data from Hacker News

ImageNet contains naturally occurring Apple NeuralHash collisions

blog.roboflow.com

131–140 of 530 posts

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#131

Earlier quoted context omitted.

I don't think we can just appeal to the status quo here and assume it's acceptable. There's a couple reasons. First, how many people really understood this previously? Did society at large actually knowingly accept the current state of things, or did it just happen without most people realizing it? Even here on HN where we'd expect to find people way more knowledgeable about it than in general I'm not sure how well k…

> But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them. This literally only works once you willing send photos to iCloud.

You can't buy a car in EU that doesn't have a sim card. All Tractors have a computer that locks out the machine if it doesn't like something and phones home. Almost every TV on sale is 'smart' and spies on what you are saying. Coffee machines, lights and toasters are now internet connected, and all of them send data to a server that will be scanning for the 'wrong' material. in 10 years there will be nowhere to hide.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#132

> it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse. If the CCP says "put these hashes in your database or we will halt all iPhone sales in…

Presumably Apple would be afraid that, say, the EU becomes suspicious, issues a court order to obtain the hashes, notices they cannot audit the CCP hashes, pointedly asks "what is this", becomes absolutely livid that their citizens are spied on by a country that is not them, fines Apple out the wazoo, then extradites whoever is responsible and puts them in prison. I mean, China's not the only player in this. Putting…

> extradites whoever is responsible and puts them in prison

If we lived in a world where the people who make these kind of decisions for companies were actually accountable in this way, life might be better in a lot of different ways. But sadly we do not.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#134
post #92
post #48

Earlier quoted context omitted.

>This is a false-positive rate of 2 in 2 trillion image pairs (1,431,168^2). Assuming the NCMEC database has more than 20,000 images, this represents a slightly higher rate than Apple had previously reported. But, assuming there are less than a million images in the dataset, it's probably in the right ballpark. Apple reported a pretty similar collision rate so maybe they did.

Their reported collision rate was against their CSAM hash database[1]. > In Apple’s tests against 100 million non-CSAM images, it encountered 3 false positives when compared against NCMEC’s database. In a separate test of 500,000 adult pornography images matched against NCMEC’s database, it found no false positives. [1] https://tidbits.com/2021/08/13/new-csam-detection-details-em...

I don't follow the point you are making here. The goal of the algorithm is to match images so I would expect similar collision rates regardless of what image was matched against what set of hashes. The exact rate of collision will obviously vary slightly.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#135

Earlier quoted context omitted.

They don’t matter because if two images don’t look the same, but collide - then human processes will absolve you. This isn’t some AI that sends you straight to prison lol

Imagine this scenario. - You receive some naughty (legal!) images of a naked young adult while flirting online and save them to your camera roll. - These images have been made to collide [1] with "well known" CSAM images obtained from the dark underbelly of the internet, on the assumption that their hashes will be contained in the encrypted database. - Apple's manual review kicks in because you have enough such image…

"- The human reviewer sees a bunch of thumbnails of naked people whose age is indeterminate but looks to be on the young side."

Given how most companies have barely paid, clueless and PTSD suffering human reviewers, a litany of mistakes is to be expected.

We should expect all the coherence of the twitter's nipple policy, except now it put you in jail or at least ruins your life with legal fees

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#136

It doesn’t matter if there are collisions if the two images don’t actually look the same. Do people honestly believe a single CSAM flag from an “innocent” image is going to result in someone going to prison in America? PhotoDNA has existed for over a decade doing the same thing with no instances that I have heard of. If some corrupt government wants to get you they don’t need this. They can just unilaterally say you’…

We are talking about how everyone who gave Apple money now has a potential probable cause vector that they didn't before. Everyone running the software is a suspect by default. Ask black Americans how they feel about setting the bar low for probable cause.

"Following the 2004 Madrid train bombings, fingerprints on a bag containing detonating devices were found by Spanish authorities. The Spanish National Police shared the fingerprints with the FBI through Interpol. Twenty possible matches for one of the fingerprints were found in the FBI database and one of the possible matches was Brandon Mayfield. His prints were in the FBI database as they were taken as part of standard procedure when he joined the military."

"The FBI described the fingerprint match as '100% verified'."

https://en.wikipedia.org/wiki/Brandon_Mayfield

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#137

Earlier quoted context omitted.

They don’t matter because if two images don’t look the same, but collide - then human processes will absolve you. This isn’t some AI that sends you straight to prison lol

Imagine this scenario. - You receive some naughty (legal!) images of a naked young adult while flirting online and save them to your camera roll. - These images have been made to collide [1] with "well known" CSAM images obtained from the dark underbelly of the internet, on the assumption that their hashes will be contained in the encrypted database. - Apple's manual review kicks in because you have enough such image…

Your scenario makes no sense. You can just skip all of the steps and skip to "the FBI, who now have cause to turn your life upside down." If the evidence doesn't matter, they could've just reported you to the FBI for having CP, regardless of whether you have it or not and your point remains the same.

Not to mention your scenario requires someone you trust trying to "get you." If that's true, then none of the other steps are necessary since you're already compromised.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#138

Earlier quoted context omitted.

At least part of the concern is that a hash collision is basically "cause" for Apple to then dump and begin manually (like, with humans) reviewing the contents of your device, all of which will be happening behind the closed doors of a private corporation, outside of any of the usual oversight or innocent-presumption mechanisms that come from it happening through the courts. That, combined with a (pretty reasonable)…

That is literally the status quo with every cloud service. Apple, unlike the others, has said that they will evaluate you on the basis of what’s included in the associated data of your safety voucher, and you can inspect those contents because they’re shipped in the client. Facebook, for all I know, might be calculating a child predator likelihood score on my account based on how often I look up my middle school ex-g…

I don't understand technie people on HN being okay with apple breaching the spirit of the 4th amendment and becoming the FBI agent in your phone. Scanning the stuff in the cloud is one thing but this is crossing a line. I am shedding all my apple hardware over it. If you want to trust them fine but one day it will bite you on the ass.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#139
If it's so easy to modify NeuralHashes, won't "CSAM networks" just rotate the hashes of their "collections"?

If you can make an innocent picture collide with a CSAM picture, presumably you can also edit a CSAM picture to have a random hash not in the database?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#140

Earlier quoted context omitted.

I don't think we can just appeal to the status quo here and assume it's acceptable. There's a couple reasons. First, how many people really understood this previously? Did society at large actually knowingly accept the current state of things, or did it just happen without most people realizing it? Even here on HN where we'd expect to find people way more knowledgeable about it than in general I'm not sure how well k…

> But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them. This literally only works once you willing send photos to iCloud.

For now. There is no technical hurdle preventing them from scanning everything locally and reporting back.
Post reply on HN