5 ms·
Ok so now all we have to do is get a phone, load it with adversarial images that have hashes from the CSAM database and we wait and see what happens. Basically
by ryanmarsh 5y ago
Ok so now all we have to do is get a phone, load it with adversarial images that have hashes from the CSAM database and we wait and see what happens. Basically a honeypot. Get some top civil rights attorneys involved. Take the case to the Supreme Court. Get precedence set right.
Lawfare
- robertoandred 5y agoWhere would you get the CSAM hashes?
- dannyw 5y agoGive it a few days, and you'll probably find someone selling a list of CSAM neural hashes on darknet marketplaces.
- Dylan16807 5y agoOr tweeting out a bunch of them. They're just 12 byte numbers.
- copperx 5y agoI bet there's a list of hashes already up in Pastebin.
- arsome 5y agoThe client has to be able to check for them in some way - just run that algorithm against every image you can scrape from Tor/Freenet and I suspect you'll have results rather quickly. Or you can probably just wait a minute and pay an... enterprising individual to sell you such a list on a darknet market though, or perhaps even find one posted on the clearnet soon enough.
- robertoandred 5y agoNo, the client doesn’t have access to the CSAM hashes. And matches are verified on the server, not on the client.
- belltaco 5y agoThe poster meant the algorithm to compute the hash has to be on the local device. And it's already been found. https://old.reddit.com/r/MachineLearning/comments/p6hsoh/p_appleneuralhash2onnx_reverseengineered_apple/ https://old.reddit.com/r/MachineLearning/comments/p6hsoh/p_a...
- arsome 5y agoIndeed, if they're proposing to only decrypt select images the client needs to know pass/fail at some point. Whether that's before or after sending the hashes to Apple's server really doesn't matter as bulk checks will likely be a part of API anyways. We'll have to wait for further reverse engineering to get full details here though.
- ec109685 5y agoThe adversarial images have to match both the NeuralHash output of CSAM, plus another private perceptual hash that points to the same image that only Apple has access to, plus a human reviewer needs to agree it is CSAM, and this has to happen for 30 images.
- kuratkull 5y agoDo you think the reviewer will dismiss the alert if only 29 images look like CSAM and the last one looks like a Beagle? What if only 1 looks like CSAM and the other 29 are animal pictures? It's a safe bet that they will report your account for the 1 that looks like CSAM.
- ec109685 5y ago30 images are required to match known bad NeuralHash’s before Apple has any access to look at any of those 30 images.