4 ms·
I don't see how. They're hashing on feature space (so trivial cropping and such doesn't defeat this) but they have two totally separate methods of matching tho
by only_as_i_fall 5y ago
I don't see how.
They're hashing on feature space (so trivial cropping and such doesn't defeat this) but they have two totally separate methods of matching those hashes? Doesn't sound right to me...
- jchw 5y agoApparently the images in question would get sent to the server, and all calculation happens there. > In a call with reporters regarding the new findings, Apple said its CSAM-scanning system had been built with collisions in mind, given the known limitations of perceptual hashing algorithms. In particular, the company emphasized a secondary server-side hashing algorithm, separate from NeuralHash, the specifics of which are not public. If an image that produced a NeuralHash collision were flagged by the system, it would be checked against the secondary system and identified as an error before reaching human moderators. https://www.theverge.com/2021/8/18/22630439/apple-csam-neuralhash-collision-vulnerability-flaw-cryptography https://www.theverge.com/2021/8/18/22630439/apple-csam-neura... For one reason or another Apple really wants to create this precedent, so it’s only natural they’re doing every last thing to make the feature hard to defeat.
- ec109685 5y agoHard to exploit is better phrasing.