REVIEW 2 cited by
Exploiting and Defending Against the Approximate Linearity of Apple's NeuralHash
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
abstract
Perceptual hashes map images with identical semantic content to the same $n$-bit hash value, while mapping semantically-different images to different hashes. These algorithms carry important applications in cybersecurity such as copyright infringement detection, content fingerprinting, and surveillance. Apple's NeuralHash is one such system that aims to detect the presence of illegal content on users' devices without compromising consumer privacy. We make the surprising discovery that NeuralHash is approximately linear, which inspires the development of novel black-box attacks that can (i) evade detection of "illegal" images, (ii) generate near-collisions, and (iii) leak information about hashed images, all without access to model parameters. These vulnerabilities pose serious threats to NeuralHash's security goals; to address them, we propose a simple fix using classical cryptographic standards.
Forward citations
Cited by 2 Pith papers
-
Double Down on Defense: Strengthening Deep Perceptual Hashes against Evasion Attacks without Retraining
A plug-in defense that hardens reference images and smooths match decisions reduces evasion attack success on eight deep perceptual hashes and provides a certified l2 robustness radius near 0.3.
-
Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools
A Pix2Pix GAN trained on 1000 celebrity photos can reconstruct recognizable faces from perceptual hash values of aHash, PDQ, NeuralHash, and PhotoDNA, including the first reported inversion attacks on PDQ and NeuralHash.
Discussion (0). Continue with ORCID to comment.