Earlier quoted context omitted.
The false positive rate reported in the blogpost for imagenet was 1 in a trillion, and the author concludes that this algorithm is better than they expected.
"After running the hashes against 100 million non-CSAM images, Apple found three false positives" So closer to 1/10M. The reporting threshold is made artificially higher by requiring more than one positive. But anyway, that's beside the point. A perceptual hash is not uniformly distributed; it's not a random number. Likewise for photos taken in a specific setting; they do not approach the randomness of a set of rando…
They don't say what kind/distribution of non-CSAM images. Landscapes? Parent pix of kids in the bathtub? Cat memes? Porn of young adults? Photos from real estate listings?
I suspect some pools of image types would have a much higher hit rate.
Edit: And, well "hot dog / not hot dog" is impressive on a set of random landscapes too.