Live data from Hacker News

Hash collision in Apple NeuralHash model

github.com

711–720 of 725 posts

Re: Hash collision in Apple NeuralHash model

#711
post #18

How can you use it for targeted attacks? This is what would need to happen: 1. Attacker generates images that collide with known CSAM material in the database (the NeuralHashes of which, unless I'm mistaken, are not available) 2. Attacker sends that to innocent person 3. Innocent person accepts and stores the picture 4. Actually, need to run step 1-3 at least 30 times 5. Innocent person has iCloud syncing enabled 6.…

I don't know why you'd even go through this trouble. At least few years ago finding actual CP on TOR was trivial, not sure if the situation has changed or not. If you're going to blackmail someone, just send actual illegal data, not something that might trigger detection scanners. >> What has changed wrt targeted attacks against innocent people? Anecdote: every single iphone user I know has iCloud sync enabled by def…

> Anecdote: every single iphone user I know has iCloud sync enabled by default.

Yeah, but a lot of them have long ago maxed out their 5 GB iCloud account.

Re: Hash collision in Apple NeuralHash model

#712

Second preimage attacks are trivial because of how the algorithm works. The image goes through a neural network (one to which everyone has access), the output vector is put through a linear transformation, and that vector is binarized, then cryptographically hashed. It's trivial to perturb any image you might wish so as to be close to the original output vector. This will result in it having the same binarization, he…

Wouldn’t it also just be possible to turn a jailbroken iDevice into a CSAM cleaner/hider? You could take actual CSAM, check if it matches the hashes and keep modifying the material until it doesn’t (adding borders, watermarking, changing dimensions etc.). Then just save it as usual without any risk.

I can’t tell what would prevent a jailbroken device from pairing an illegal CSAM image with the safety voucher from a known-innocuous image, since the whole system depends on the trustworthiness of the safety voucher and that it truly represents the image in question. If the device is compromised I would think all bets would be off. To me, one potential flaw of this system may be that Apple inherently trusts the device. The existence of a jailbreak seems like a massive risk to the system.

In fact, Apple themselves generate fake/meaningless safety vouchers a certain percentage of the time (see synthetic safety vouchers.) If a jailbroken phone could trigger that code path for all images in the pipeline, apple’s system would be completely broken.

On the other hand, this may be just the excuse apple needs to lock down the phone further, to “protect the integrity of the CSAM detection system.” Perhaps they could persuade congress to make jailbreaking a federal crime. Perhaps they’re more clever than I ever imagined. Or perhaps they can fend off alternate App Store talk for sake of protecting the integrity of the system. Or perhaps staying up too late makes me excessively conspiratorial.

Re: Hash collision in Apple NeuralHash model

#713

Earlier quoted context omitted.

>And there’s nothing to stop them from scanning all images on a device. All images on your device have been scanned for years by ML models to detect things all sorts of things and make your photo library searchable regardless of whether you use an Android or Apple device. That's how you can go and search "dog", "revolver", "wife", etc and get relevant photos popping up.

I don't think this is accurate. I don't use the Google Photos cloud service, and searching in the Photos app on my Android phone returns zero results for any search term.

My impression was Google had been doing it for ages.

Ex. This article from 2013 where they talk about searching for [my photos of flowers] https://search.googleblog.com/2013/05/finding-your-photos-mo...

I'm an iOS guy, and don't have an Android device to confirm it. I've got a few photos visible on photos.google.com and they're able to detect "beard", at least. Which, to be fair, it's just a few selfies.

iOS does this pretty well. I searched my phone and it was able to recognize and classify a gun as a revolver from a meme I'd saved years ago. That's not this CSAM technology, just something they've been doing for years with ML.

Re: Hash collision in Apple NeuralHash model

#714

Earlier quoted context omitted.

What part of "they already totally fucked up how their own process is supposed to work" don't you understand?

What part of it is fucked up? They never promised that their hashing algorithm was uncollidable. The process is specifically designed to be tolerant of hash collisions (and in fact wouldn't work otherwise, because the system needs to ignore small differences between copies of the illegal images, like one-pixel edits or color temperature differences or photocopies). There are multiple stages of human review in the pro…

"Apple said that there is a one in one trillion chance of a false positive"

https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni...

Versus:

https://blog.roboflow.com/nerualhash-collision/

Along with:

https://github.com/anishathalye/neural-hash-collider

Demonstrates blatant incompetence on the part of Apple's design. At this point, trust is broken. That's the end of credibility regarding any other claim made about the security or base function of the system.

As for a simple example of one of many potential attack vectors (search HN for "neuralhash" and read the comments for countless examples), here is a basic attack:

As Apple's hash algorithm is entirely broken and useless, a malicious actor can easily craft a NSFW, but otherwise legal image, that has a hash matching one in the CSAM database, that is visually ambiguous in that context (for example, a close-up). Targeted attacks could be launched on unsuspecting victims as simply as sending them an image.

If their app is configured to auto-save to iCloud - as some are by default, and as many are configurable to be - the image will then get automatically flagged as a match, and may well potentially pass a human review - because the image may indeed look just like CP - and an innocent person, who may not even be aware of the presence of the image in their iCloud library at this point, may get visited by the police.

That in itself is bad enough.

However it gets worse - do bear in mind that "the police" is not an equivalent concept across nations, yet iPhones are ubiquitously used across the world. In certain countries, a "visit from the police" over such automatically-flagged content could well result in presumption of guilt to the point of immediately administered punishment and a destroyed innocent life.

In China for example, conviction rates are routinely 99.99% - being accused of a crime there is equivalent to being convicted, and that's just one major country containing well over 100 million iphone users.

Apple is demonstrating not only gross incompetence in this design of this "system", but vagrant disregard for human rights, along with utterly destroying their own long-cultivated pro-privacy stance.

It's a disaster for them and their customers in every possible way it could be.

Re: Hash collision in Apple NeuralHash model

#715

Earlier quoted context omitted.

>And there’s nothing to stop them from scanning all images on a device. All images on your device have been scanned for years by ML models to detect things all sorts of things and make your photo library searchable regardless of whether you use an Android or Apple device. That's how you can go and search "dog", "revolver", "wife", etc and get relevant photos popping up.

I don't think this is accurate. I don't use the Google Photos cloud service, and searching in the Photos app on my Android phone returns zero results for any search term.

I looked on our iphones. And its possible I am an edge case. With the restrictions I have on Siri, icloud (the only use for iCloud is some shared albums with family, in lieu of facebook, and find my) etc. My phone doesn't categorize photos by person or do those montages others routinely get within the photos app.

And the only reason I know about them is because my wife asked about them and why our iPhones dont do them.

But we don't put stuff on Facebook. Our photos are backed up to our NAS. Phones backup to a macmini only. Siri and search are basically disabled as much as possible (we have to somewhat enable it for carplay) but definitely no voice or anything.

Re: Hash collision in Apple NeuralHash model

#716

Earlier quoted context omitted.

I tried to look up [Antonio] Dickerson v. US, but I don't see any SCOTUS decision on it, only a certiorari petition. Do you have a reference for the decision?

Yep, sorry, Dickerson was an appellant that cited the relevant case law, which is New York v Ferber. Now, Dickerson rightfully lost and it's appropriate that SCOTUS rejected his case because he was involved in child porn production , not posession , so he can't rely on the Ferber precedent. He had the opportunity to ask the underage person in question their age, and chose not to, which would meet the reckless disrega…

I don't see any mention of the reckless disregard standard in the New York v. Ferber decision, either? So far as I can see, it just says that CSAM is outside of the scope of 1A, so long as it's "adequately defined by the applicable state law". Am I missing something in the opinion?

Re: Hash collision in Apple NeuralHash model

#717

Earlier quoted context omitted.

What part of it is fucked up? They never promised that their hashing algorithm was uncollidable. The process is specifically designed to be tolerant of hash collisions (and in fact wouldn't work otherwise, because the system needs to ignore small differences between copies of the illegal images, like one-pixel edits or color temperature differences or photocopies). There are multiple stages of human review in the pro…

"Apple said that there is a one in one trillion chance of a false positive" https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni... Versus: https://blog.roboflow.com/nerualhash-collision/ Along with: https://github.com/anishathalye/neural-hash-collider Demonstrates blatant incompetence on the part of Apple's design. At this point, trust is broken. That's the end of credibility regarding any other claim made a…

Apple was talking about the chance of accidental false positives.

There is a 1 in 4 billion chance that if I send a message to an IP address, it will be yours. The fact that I can know your IP address and send you a message intentionally does not make the previous statement false.

> As Apple's hash algorithm is entirely broken and useless, a malicious actor can easily craft a NSFW, but otherwise legal image, that has a hash matching one in the CSAM database, that is visually ambiguous in that context (for example, a close-up). Targeted attacks could be launched on unsuspecting victims as simply as sending them an image.

Everybody keeps talking about this scenario as if it is any different whatsoever from sending people actual regular old-fashioned CSAM, which A: already happens, B: requires less effort on the part of the attacker, and C: isn't reliant on the recipient uploading them to iCloud, triggering several layers of filtering and detection, which may or may not result in law enforcement interest depending on your forgery's ability to fool professional investigators at NCMEC who are comparing it alongside the original.

The attack you're describing is less effective and more difficult than existing ones.

Re: Hash collision in Apple NeuralHash model

#718
post #666

Earlier quoted context omitted.

You're assuming that there is a side-by-side comparison with a hash matching image. I think that is an extremely big assumption which assumes facts not in evidence at all. As far as what kind of image would be believed to be child porn without a side-by-side with the supposed match: ordinary porn. Without context plenty would be hard to distinguish, especially with the popularity of waxed smooth bodies and explicit c…

You still haven't explained how an image can be at the same time so benign that the user doesn't delete it from their phone and cloud service and the sender is in no legal danger, and yet so obviously pornographic that a jury will be convinced beyond any reasonable doubt that it's child porn. The entire point of this process is to catch only images from a known catalogue of existing images, of course there will be op…

I think I explained it adequately. An attacker gets some hashes likely to be in the database. The attacker modified legal pornography of young looking people, perhaps closeups of genitalia, to match the child porn hashes.

There are plenty of examples of US persons being charged for lawful pornography which a prosecutor accused of being child porn, I linked to one such example-- where the accused was rescued only by the testimony of the actress, and where the prosecution had expert witnessess testifying that the images of an adult were images of a child.

The attacker in this case would know the origin of the images and could point to them. The victim would have no idea where they came from.

I have searched the case law, and can find no case where the NCMEC provided an image for comparison. Are you aware of any?

You also seem to have continued to move the goalpost. Being merely accused of possessing child porn would be extremely damaging to a person. The fact that they might escape conviction by a jury after years of legal ordeal, incarceration, and having their reputation ruined, is not that much consolation.

> The idea that new images of nudity could be caught in it is because

This is an absurd claim. I have demonstrated (https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...) that it is possible to alter existing images to match an arbitrary neuralhash resulting in a perfectly normal looking image. This point is not a matter for dispute, anymore.

I could easily do so with a nude or pornographic image, I only chose to use SFW pictures out of good taste.

My interest in apple's scheme arouse out of their malicious use of cryptography to shield their actions from accountability. I didn't even hear about the imessage nudie scanner until some time after. You can be certain no such confusion applies here.

Re: Hash collision in Apple NeuralHash model

#719

Earlier quoted context omitted.

I don't think this is accurate. I don't use the Google Photos cloud service, and searching in the Photos app on my Android phone returns zero results for any search term.

My impression was Google had been doing it for ages. Ex. This article from 2013 where they talk about searching for [my photos of flowers] https://search.googleblog.com/2013/05/finding-your-photos-mo... I'm an iOS guy, and don't have an Android device to confirm it. I've got a few photos visible on photos.google.com and they're able to detect "beard", at least. Which, to be fair, it's just a few selfies. iOS does thi…

Right, the Google Photos service does this, but it's a cloud service, it's not on-device.

Re: Hash collision in Apple NeuralHash model

#720
post #532

Earlier quoted context omitted.

Imagine if WhatsApp and other apps added received photos to iPhone's iCloud Photos gallery by default.. wait, they do.

Imagine if Apps had to ask permission before they could save photos… Imagine if the local photo storage is not the same as iCloud Photo Library… Imagine if anyone who cared could simply switch off iCloud Photo Library…

Imagine if our cognitive capability wasn’t exploited.
Post reply on HN