Public Verification for Private Hash Matching
Sarah Scheffler, Anunay Kulshrestha, Jonathan R. Mayer
Abstract
End-to-end encryption (E2EE) prevents online services from accessing user content. This important security property is also an obstacle for content moderation methods that involve content analysis. The tension between E2EE and efforts to combat child sexual abuse material (CSAM) has become a global flashpoint in encryption policy, because the predominant method of detecting harmful content—server-side perceptual hash matching on plaintext images—is unavailable.Recent applied cryptography advances enable private hash matching (PHM), where a service can match user content against a set of known CSAM images without revealing the hash set to users or nonmatching content to the service. These designs, especially a 2021 proposal for identifying CSAM in Apple’s iCloud Photos service, have attracted widespread criticism for creating risks to security, privacy, and free expression.In this work, we aim to advance scholarship and dialogue about PHM by contributing new cryptographic methods for system verification by the general public. We begin with motivation, describing the rationale for PHM to detect CSAM and the serious societal and technical issues with its deployment. Verification could partially address shortcomings of PHM, and we systematize critiques into two areas for auditing: trust in the hash set and trust in the implementation. We explain how, while these two issues cannot be fully resolved by technology alone, there are possible cryptographic trust improvements.The central contributions of this paper are novel cryptographic protocols that enable three types of public verification for PHM systems: (1) certification that external groups approve the hash set, (2) proof that particular lawful content is not in the hash set, and (3) eventual notification to users of false positive matches. The protocols that we describe are practical, efficient, and compatible with existing PHM constructions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aa9b2136-af02-4b32-a127-e0314199d763Cited by top-tier papers4
- PICS: Private Intersection over Committed (and reusable) SetsAarushi Goel, Peihan Miao, Phuoc Van Long Pham, Satvinder SinghUSENIX Security 2026 · 1 citation
- Experimental Analyses of the Physical Surveillance Risks in Client-Side Content ScanningAshish Hooda, Andrey Labunets, Tadayoshi Kohno, Earlence FernandesNDSS 2024
- Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging SystemsZhongming Wang, Tao Xiang, Xiaoguo Li, Guomin Yang et al.NDSS 2026
- Analyzing Cryptography in Context: A Cryptography-Native Approach to Threat ModelingRan Canetti, Julie Ha, Gabriel KaptchukUSENIX Security 2026
Builds on5
- Authenticated Garbling and Efficient Maliciously Secure Two-Party ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 212 citations
- PSI from PaXoS: Fast, Malicious Private Set IntersectionBenny Pinkas, Mike Rosulek, Ni Trieu, Avishay YanaiEUROCRYPT 2020 · 198 citations
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 50 citations
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- Estimating Incidental Collection in Foreign Intelligence Surveillance: Large-Scale Multiparty Private Set Intersection with Union and SumAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2022
Related papers
- Atkscopes: Multiresolution Adversarial Perturbation as a Unified Attack on Perceptual Hashing and BeyondYushu Zhang, Yuanyuan Sun, Shuren Qi, Zhongyun Hua et al.USENIX Security 2025
- End-to-End Secure Messaging with Traceability Only for Illegal ContentJames Bartusek, Sanjam Garg, Abhishek Jain, Guru-Vamsi PolicharlaEUROCRYPT 2023 · 20 citations
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine LearningJonathan Prokos, Neil Fendley, Matthew Green, Roei Schuster et al.USENIX Security 2023
- Deep perceptual hashing algorithms with hidden dual purpose: when client-side scanning does facial recognitionShubham Jain, Ana-Maria Cretu, Antoine Cully, Yves-Alexandre de MontjoyeS&P 2023
- Breaking Widely Deployed Perceptual Hash Functions: Black-Box Collisions in Apple NeuralHash and Microsoft PhotoDNADiane Leblanc-Albarel, Bart PreneelUSENIX Security 2026
