End-to-end encryption (E2EE) provides strong technical protections to individuals from interferences. Governments and law enforcement agencies around the world have however raised concerns that E2EE also allows illegal content to be shared undetected. Client-side scanning (CSS), using perceptual hashing (PH) to detect known illegal content before it is shared, is seen as a promising solution to prevent the diffusion of illegal content while preserving encryption. While these proposals raise strong privacy concerns, proponents of the solutions have argued that the risk is limited as the technology has a limited scope: detecting known illegal content. In this paper, we show that modern perceptual hashing algorithms are actually fairly flexible pieces of technology and that this flexibility could be used by an adversary to add a secondary hidden feature to a client-side scanning system. More specifically, we show that an adversary providing the PH algorithm can ``hide" a secondary purpose of face recognition of a target individual alongside its primary purpose of image copy detection. We first propose a procedure to train a dual-purpose deep perceptual hashing model by jointly optimizing for both the image copy detection and the targeted facial recognition task. Second, we extensively evaluate our dual-purpose model and show it to be able to reliably identify a target individual 67% of the time while not impacting its performance at detecting illegal content. We also show that our model is neither a general face detection nor a facial recognition model, allowing its secondary purpose to be hidden. Finally, we show that the secondary purpose can be enabled by adding a single illegal looking image to the database. Taken together, our results raise concerns that a deep perceptual hashing-based CSS system could turn billions of user devices into tools to locate targeted individuals.
翻译:端到端加密(E2EE)为个人提供强大的技术保护以防止干扰。然而,世界各地的政府和执法机构担心E2EE也允许非法内容在未被检测到的情况下被共享。客户端扫描(CSS)利用感知哈希(PH)在共享前检测已知非法内容,被视为既能防止非法内容扩散又能保留加密的有前景解决方案。尽管这些提案引发了强烈的隐私担忧,但支持者认为风险有限,因为该技术的范围有限:仅检测已知非法内容。在本文中,我们展示了现代感知哈希算法实际上是相当灵活的技术,且这种灵活性可能被对手利用,为客户端扫描系统添加隐藏的次要功能。具体而言,我们证明提供PH算法的对手可以“隐藏”一个次要目的——对目标个体进行人脸识别——与其主要目的(图像副本检测)并存。首先,我们提出了一种训练双重目的深度感知哈希模型的流程,通过联合优化图像副本检测和目标人脸识别任务来实现。其次,我们广泛评估了双重目的模型,并证明它能够在67%的情况下可靠识别目标个体,同时不影响其检测非法内容的性能。我们还表明,我们的模型既不是通用人脸检测模型也不是人脸识别模型,从而使其次要目的得以隐藏。最后,我们证明,只需在数据库中添加一张看似非法的图像即可启用次要目的。综合而言,我们的研究结果引发担忧:基于深度感知哈希的CSS系统可能将数十亿用户设备转变为定位目标个体的工具。