Atkscopes: Multiresolution Adversarial Perturbation as a Unified Attack on Perceptual Hashing and Beyond
Yushu Zhang, Yuanyuan Sun, Shuren Qi, Zhongyun Hua, Wenying Wen, Yuming Fang
摘要
Privacy and regulation are a long-lasting conflict in modern instant messaging, where the security community attempts to bridge this gap from a technological perspective. End-to-end encryption (E2EE) is a mathematically guaranteed privacy policy that has been widely built into commercial instant messaging applications. On the other hand, regulatory designs compatible with E2EE privacy are severely restricted, i.e., content auditing is (almost) impossible on ciphertext. For this reason, the community develops perceptual hash matching (PHM) as a regulation policy, where content-aware hash codes for media are computed prior to E2EE and matched against known criminal media, e.g., child pornography images, on the server side. In this paper, we systematically reveal a range of adversarial threats to such E2EE-PHM systems, leading to regulatory failures. Unlike previous case studies, our attack is a more realistic threat -uniformly fooling the famous pHash, Facebook PDQ, Microsoft PhotoDNA, and Apple NeuralHash, even with higher success rates and less training rounds. Here, we validate the above proposition in both scenarios of escaping and triggering regulation. Our main contribution is a new idea of multiresolution perturbation, where each perturbation element can affect image regions of adjustable scales. With this new idea and its wellformalized design, our attack encapsulates previous attacks as special cases -in some scenarios, it exhibits a huge leap in convergence efficiency compared to previous ones. Based on the above technical insights, we also discuss possible countermeasures and recommendations for social good.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 被引用 172 次
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen 等CCS 2017 · 被引用 166 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
- Surveylance: Automatically Detecting Online Survey ScamsAmin Kharraz, William K. Robertson, Engin KirdaS&P 2018 · 被引用 73 次
- It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming ServicesM. Zubair Rafique, Tom van Goethem, Wouter Joosen, Christophe Huygens 等NDSS 2016 · 被引用 60 次
相关 Paper
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine LearningJonathan Prokos, Neil Fendley, Matthew Green, Roei Schuster 等USENIX Security 2023
- CertPHash: Towards Certified Perceptual Hashing via Robust TrainingYuchen Yang, Qichang Liu, Christopher Brix, Huan Zhang 等USENIX Security 2025
- Public Verification for Private Hash MatchingSarah Scheffler, Anunay Kulshrestha, Jonathan R. MayerS&P 2023
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 被引用 50 次
