A Forensically Sound Method of Identifying Downloaders and Uploaders in Freenet
Brian Neil Levine, Marc Liberatore, Brian Lynn, Matthew Wright
Abstract
The creation and distribution of child sexual abuse materials (CSAM) involves a continuing violation of the victims? privacy beyond the original harms they document. A large volume of these materials is distributed via the Freenet anonymity network: in our observations, nearly one third of requests on Freenet were for known CSAM. In this paper, we propose and evaluate a novel approach for investigating these violations of exploited childrens' privacy. Our forensic method distinguishes whether or not a neighboring peer is the actual uploader or downloader of a file or merely a relayer. Our method requires analysis of the traffic sent to a single, passive node only. We evaluate our method extensively. Our in situ measurements of actual CSAM requests show an FPR of 0.002 ± 0.003 for identifying downloaders. And we show an FPR of 0.009 ± 0.018, a precision of 1.00 ± 0.01, and a TPR of 0.44 ± 0.01 for identifying uploaders based on in situ tests. Further, we derive expressions for the FPR and Power of our hypothesis test; perform simulations of single and concurrent downloaders; and characterize the Freenet network to inform parameter selection. We were participants in several United States Federal Court cases in which the use of our method was uniformly upheld.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c81f1335-2f7d-4b62-ba3f-c54b741a9585Cited by top-tier papers2
- Trauma-Informed Social Media: Towards Solutions for Reducing and Healing Online HarmCarol F. Scott, Gabriela Marcu, Riana Elyse Anderson, Mark W. Newman et al.CHI 2023 · 91 citations
- A De-anonymization Attack against Downloaders in FreenetYonghuan Xu, Ming Yang, Zhen Ling, Zixia Liu et al.INFOCOM 2024 · 7 citations
Related papers
- Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in FreenetYonghuan Xu, Ming Yang, Shan Wang, Xiaodan Gu et al.INFOCOM 2026
- Mental Models, Expectations and Implications of Client-Side Scanning: An Interview Study with ExpertsDivyanshu Bhardwaj, Carolyn Guthoff, Adrian Dabrowski, Sascha Fahl et al.CHI 2024 · 5 citations
- Gold Standard or Gold-Plated? Human Practices of Triple Verification in CSAM TakedownMelissa Rottier, Michel van Eeten, Savvas ZannettouCHI 2026 · 1 citation
- "Not the Right Question?" A Study on Attitudes Toward Client-Side Scanning with Security and Privacy Researchers and a U.S. Population SampleLisa Geierhaas, Florin Martius, Arthi Arumugam, Matthew SmithS&P 2025
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 50 citations
