Breaking Widely Deployed Perceptual Hash Functions: Black-Box Collisions in Apple NeuralHash and Microsoft PhotoDNA
Diane Leblanc-Albarel, Bart Preneel
摘要
Perceptual hash functions have been designed to detect multimedia copyright violations and illegal content. To achieve their purpose, they map inputs that are perceived as similar to close outputs. For many widely deployed schemes, however, both the design strategy and detailed specifications remain proprietary. Governments are now considering their extension to Client-Side Scanning (CSS) for end-to-end encrypted services, verifying content against illegal material before encryption. In 2021, Apple presented a detailed proposal for CSS based on the NeuralHash perceptual hash function. After strong criticism over privacy and security concerns, Apple withdrew the proposal, but NeuralHash remains deployed on all devices, with its current purpose undisclosed. In theory, brute-force collisions for NeuralHash (96-bit hash value) require 2 48 evaluations. Shortly after the NeuralHash release, researchers showed it is easy to craft perceptually dissimilar collisions, to incriminate any user by sending an innocent image sharing the same hash value as illegal content. This work shows a more serious weakness: when inputs are restricted to human faces, we found several collisions between perceptually different images after only 2 16 hash function evaluations. Unlike targeted attacks, our black-box approach requires no knowledge of the hash function design. We also demonstrate a high false negative rate (images that should share the same hash but do not). We further confirm the generality of our approach by studying PhotoDNA, Microsoft's widely deployed 1152-bit perceptual hash function. In the case of PhotoDNA, we found near-collisions at thresholds significantly lower than previously reported, appearing after between 2 14.6 and 2 17 evaluations depending on the threshold used. This is the first work to demonstrate exact collisions in NeuralHash and to identify near-collisions in PhotoDNA at such low thresholds. These results cast serious doubts on the suitability of these designs for large-scale client scanning, as they produce high false positive and false negative rates, and highlight the need to reassess their security and feasibility, particularly for large-scale applications where privacy risks and false positives have serious consequences.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 被引用 597 次
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 被引用 50 次
- It's Not What It Looks Like: Manipulating Perceptual Hashing based ApplicationsQingying Hao, Licheng Luo, Steve T. K. Jan, Gang WangCCS 2021 · 被引用 36 次
- End-to-End Secure Messaging with Traceability Only for Illegal ContentJames Bartusek, Sanjam Garg, Abhishek Jain, Guru-Vamsi PolicharlaEUROCRYPT 2023 · 被引用 20 次
相关 Paper
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine LearningJonathan Prokos, Neil Fendley, Matthew Green, Roei Schuster 等USENIX Security 2023
- Deep perceptual hashing algorithms with hidden dual purpose: when client-side scanning does facial recognitionShubham Jain, Ana-Maria Cretu, Antoine Cully, Yves-Alexandre de MontjoyeS&P 2023
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- CertPHash: Towards Certified Perceptual Hashing via Robust TrainingYuchen Yang, Qichang Liu, Christopher Brix, Huan Zhang 等USENIX Security 2025
- Atkscopes: Multiresolution Adversarial Perturbation as a Unified Attack on Perceptual Hashing and BeyondYushu Zhang, Yuanyuan Sun, Shuren Qi, Zhongyun Hua 等USENIX Security 2025
