Live data from Hacker News

ImageNet contains naturally occurring Apple NeuralHash collisions

blog.roboflow.com

421–430 of 530 posts

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#422

Earlier quoted context omitted.

> But more philosophically, it's your own device being turned against you to check you for criminal behavior. That's very different from somebody else checking up on you after you willingly interact with them. This literally only works once you willing send photos to iCloud.

For now. There is no technical hurdle preventing them from scanning everything locally and reporting back.

I mean, that has always been the case. I'm not sure why there is so much paranoia over this hypothetical situation when this hypothetical has actually existed since the first iPhone shipped in 2007.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#423

Keep in mind that Apple's claimed false positive rate (one in a trillion chance of an account being flagged innocently), and the collision rate determined by Dwyer in the article, are both derived without any adversarial assumptions. Given that NeuralHash collider and similar tools already exist, the false positive rate is expected to be much much higher. Imagine that you play a game of craps against an online casino…

> one in a trillion chance of an account being flagged innocently

To be clear - Apple claims that there is a one in a trillion chance of there being ~30 false matches in a single account.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#424

Earlier quoted context omitted.

> "The end result is that some peon at Apple has to look at the images and mark them as not CSAM. You've cost someone a bit of privacy, but that's it." This can be abused to spam Apple's manual review process, grinding it down to a halt. You've cost Apple time and money by making them review each such fake report.

> You've cost Apple time and money by making them review each such fake report. Ok, but… how do I profit? If I wanted to waste Apple employee time, I could surely find a way to do it, but why would I? The functioning of society relies on the fact that people generally have better things to do than waste each others time.

You have justified the review of an "innocent" image that may be of interest. To justify investigations and whatever else. It's pretty easy to understand... Big tech bad mmmkay!?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#425

Here's one concern -- Neural Hash is finding false positives with images that look very similar. What if an underage girl takes a selfie (or over-age girl) and the pose or background features are similar enough to trigger a false collision. Then Apple is going to a manual step where they are able to look at a low-res version of somebody's private photos as I understand it. In my opinion that last step is not okay. I…

> I want to purchase from a company that offers me the peace of mind not to even have to think about such concerns, price isn't an obstacle.

Since this only affects people using iCloud Photos, have you considered not doing that, or using an alternative that you believe isn't doing this?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#426

There's been a lot of focus on the likelihood of collisions and whether someone could upload eg; an image with a matching hash to your device to "set you up", etc. But what's still extremely concerning is that there is still no guarantee that the hash list used can't be coopted for another purpose (eg; politically insensitive content).

On top of that, what happens if a court/government orders them to give them all the current data about people with matches, regardless of the 30 matches. They can't say if it is or not a match so they have to go after the individuals. Is that enough evidence for a warrant? Someone in the court thinks it's true and can't prosecute?, oh, it got leaked . -- Not every country has the same protections about innocent until…

My understanding is that these "safety vouchers" are uploaded regardless of a match. Only when there is about 30 matches are those safety vouches able to be decrypted to determine there there was a match.

So Apple claims your threat model is not technically possible.

Besides, Govt. can just order Apple to hand over the photos themselves from iCloud Photos because those are not end-to-end encrypted.

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#427

Keep in mind that Apple's claimed false positive rate (one in a trillion chance of an account being flagged innocently), and the collision rate determined by Dwyer in the article, are both derived without any adversarial assumptions. Given that NeuralHash collider and similar tools already exist, the false positive rate is expected to be much much higher. Imagine that you play a game of craps against an online casino…

> one in a trillion chance of an account being flagged innocently To be clear - Apple claims that there is a one in a trillion chance of there being ~30 false matches in a single account.

Is that number just for the private set intersection step?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#428

Earlier quoted context omitted.

On top of that, what happens if a court/government orders them to give them all the current data about people with matches, regardless of the 30 matches. They can't say if it is or not a match so they have to go after the individuals. Is that enough evidence for a warrant? Someone in the court thinks it's true and can't prosecute?, oh, it got leaked . -- Not every country has the same protections about innocent until…

More broadly speaking, every part of this scheme that is currently an arbitrary Apple decision (and not a technological limitation), can easily become an arbitrary government decision. And yes, it's true that the governments could always mandate such scanning before. The difference is that it'll be much harder politically for Apple to push back against tweaks to the scheme (such as lowering the bar for manual review…

What your saying is that the government can compel Apple to develop software and include it in iOS?

Haven’t they always been able to do that?

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#429
post #173

I have a suggestion for Apple. Maybe they could use this technique in a way that benefits all their customers by finally solving the problem of duplicate image imports in Photos.app. I have a couple of hundred duplicate images in my Library because of problems during local import from my iPhone into Photos.

PhotoSweeper[1] is great for dealing with this. (Not affiliated, just a happy customer trying to manage 100K photos.)

[1] https://overmacs.com/

Re: ImageNet contains naturally occurring Apple NeuralHash collisions

#430

Earlier quoted context omitted.

Dont worry, ill fix all this by creating a unique javascript framework that will change the world.

Maybe we could make this framework future-proof by using blockchains? Somehow? Maybe it can use blockchains, or it can be stored on a blockchain, or maybe both at the same time. Surely that will help society in some nonspecific, ambiguous manner.

Remember the people who, decades after the invention of the Internet, kept on insisting that it was useless and only for porn addicts?

Remember the people who, after the invention of the phone, insisted that it was a nice trick but probably only useful for a few businessmen with dictation needs?

Yeah, they all had to change their tone at some point, under the shame of having been wrong for so long.

Post reply on HN