A Pix2Pix GAN trained on 1000 celebrity photos can reconstruct recognizable faces from perceptual hash values of aHash, PDQ, NeuralHash, and PhotoDNA, including the first reported inversion attacks on PDQ and NeuralHash.
Exploiting and Defending Against the Approximate Linearity of Apple's NeuralHash
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Perceptual hashes map images with identical semantic content to the same $n$-bit hash value, while mapping semantically-different images to different hashes. These algorithms carry important applications in cybersecurity such as copyright infringement detection, content fingerprinting, and surveillance. Apple's NeuralHash is one such system that aims to detect the presence of illegal content on users' devices without compromising consumer privacy. We make the surprising discovery that NeuralHash is approximately linear, which inspires the development of novel black-box attacks that can (i) evade detection of "illegal" images, (ii) generate near-collisions, and (iii) leak information about hashed images, all without access to model parameters. These vulnerabilities pose serious threats to NeuralHash's security goals; to address them, we propose a simple fix using classical cryptographic standards.
fields
cs.CR 1years
2024 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools
A Pix2Pix GAN trained on 1000 celebrity photos can reconstruct recognizable faces from perceptual hash values of aHash, PDQ, NeuralHash, and PhotoDNA, including the first reported inversion attacks on PDQ and NeuralHash.