Live data from Hacker News

A catalog of naturally occurring images whose Apple NeuralHash is identical

github.com

41–50 of 304 posts

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#41
post #18
post #8

> a catalog Can two collisions really be called a catalog?

A catalog of a thousand pages begins with the first entry.

And a story may start with the first word, but if I present the word "Octopus" and say check out my story, you're going to be well within bounds to question me on it.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#42

"This is a false-positive rate of 2 in 2 trillion image pairs (1,431,168^2)" That is not bad. As a tool to filter down what apple human reviewers need to look at this is pretty good. Ultimately these images will make it to a human reviewer who can make a call as they would in any flagging system. Could a backend server side system do a more precise hash (96 bits is not a ton) prior to human review?

2 collisions out of a million images. I'm not sure how big the CSAM database is but if it's a tens of thousands and there are millions of photos uploaded a day then Apple could have a problem on their hands. This is all extrapolating from a study that doesn't use photos representative of what people actually upload. I would suspect when most photos being uploaded are of humans the actual collision rate will be much higher.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#43

I’m glad that people are trying to figure out any technical flaws in the system as best they can, but if I’m being honest I do trust Apple’s engineers to have built something that is solid from a technical stand point. Am I correct in that the primary reason folks are so upset is that the system could (probably) be easily modified such that -any- content could invoke legal action? That the main problem is really the…

It might be solid from a technical standpoint. Once you built it, governments will be coming and asking for more. Are you aware that the Chinese government already has been granted access to the infrastructure holding the keys to iCloud in China?

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#44

Earlier quoted context omitted.

Discussing the preimage attack on NeuralHash is not technical ignorance. Dismissing the preimage attack as irrelevant is. 0. Most importantly: the existence of a preimage attack makes Apple's system completely useless for its original purpose. The NeuralHash collider allows the producers and distributors of CSAM material to ensure that nearly all of the next generation of CSAM will suffer from hash collisions with pe…

That's a lot of words to say that you could sufficiently mangle an image that it could pass through all of Apple's algorithmic hurdles while not actually being CSAM. Of that I have no doubt. You could definitely generate a mangled image that fools multiple perceptual hash algorithms. Let's set aside the questions of where you got all these hashes to generate collisions with, how you got 30 of these mangled images int…

I think you missed the point of the first paragraph. The point is that you can now hide child porn by making its hash collide with innocent images. They won't ever make it to manual review. Ergo, NeuralHash is now useless.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#45

"This is a false-positive rate of 2 in 2 trillion image pairs (1,431,168^2)" That is not bad. As a tool to filter down what apple human reviewers need to look at this is pretty good. Ultimately these images will make it to a human reviewer who can make a call as they would in any flagging system. Could a backend server side system do a more precise hash (96 bits is not a ton) prior to human review?

I wouldn't be surprised if 1,431,168 photo uploads is what iCloud sees in an hour.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#46
post #33

Apple has yet to make a valid reason for implementing client side CSAM scanning. According to Apple only images that will be uploaded to iCloud will be scanned. If this is the case there is zero reason to scan locally and you can just scan the uploaded image once it is on the server. Apple has not implemented E2E nor has it released a statement indicating this will be implemented in the future.

Presumably, it’s done this way so they can say computers other than your personal device do not scan photos and “look” at decrypted and potentially innocent photos. And technically the original image is never decrypted in iCloud by Apple - if 30 images are flagged they are then able to decrypt the CSAM scan meta data which contains resized thumbnails, for confirmation.

In summary, I’m guessing they tried to invent a way where their server software never has to decrypt and analyze original photos, so they stay encrypted at rest.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#47
post #44

Earlier quoted context omitted.

That's a lot of words to say that you could sufficiently mangle an image that it could pass through all of Apple's algorithmic hurdles while not actually being CSAM. Of that I have no doubt. You could definitely generate a mangled image that fools multiple perceptual hash algorithms. Let's set aside the questions of where you got all these hashes to generate collisions with, how you got 30 of these mangled images int…

I think you missed the point of the first paragraph. The point is that you can now hide child porn by making its hash collide with innocent images. They won't ever make it to manual review. Ergo, NeuralHash is now useless.

Why would anyone go to the effort of technical concealment[1] of CSAM when they could just resist the urge to import child porn in their phone's photo library in the first place? I've managed to resist the urge to import regular porn into my photo library, and being caught with regular porn is (at most) embarrassing. It's not potentially life-destroying.

It's inconceivable that anyone could desire possession of NCMEC-catalogued CSAM images without being aware that they're risking serious consequences if they're caught. Who wants their deepest, darkest, potentially life-ruining secrets just milling about with photos of the dog and last night's dinner?

[1] ...which is all but impossible for an average user to prove was effective; it's not like the Photos app has a "Not Child Porn!" checkmark.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#48

"This is a false-positive rate of 2 in 2 trillion image pairs (1,431,168^2)" That is not bad. As a tool to filter down what apple human reviewers need to look at this is pretty good. Ultimately these images will make it to a human reviewer who can make a call as they would in any flagging system. Could a backend server side system do a more precise hash (96 bits is not a ton) prior to human review?

2 collisions out of a million images. I'm not sure how big the CSAM database is but if it's a tens of thousands and there are millions of photos uploaded a day then Apple could have a problem on their hands. This is all extrapolating from a study that doesn't use photos representative of what people actually upload. I would suspect when most photos being uploaded are of humans the actual collision rate will be much h…

They don’t take any action unless you have 30 matches in the database, which will not happen by chance.

Re: A catalog of naturally occurring images whose Apple NeuralHash is identical

#49

Please help me understand. Isn't this the reason why the process involved a final manual review? If so, isn't the point of having identical hashes moot? Or is the point that having more identical hashes means reviewing more personal pictures manually, leading to a privacy issue?

I don't think I would trust a huge corporation with this. Plus, leaving the review to some internal classified process where some poor faceless guy needs to reach an unrealistically high quota of reviewed images per day to get his bonus, might be a bit of a risk.
Post reply on HN