Remix.run Logo
bayindirh 6 hours ago

> It proved that it was technically feasible, and was "privacy preserving".

Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?

If not, I'll happily stand corrected, but please share sources.

Addenda:

- Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...

- Paper breaking the hash: https://arxiv.org/abs/2111.06628

Edit: The second one is the wrong paper. I’ll find and link the correct one tomorrow. Keeping the link for transparency.

comex 5 hours ago | parent | next [-]

The paper you linked doesn’t reveal blurred versions of the images being hashed. It does train a classifier to determine which of 1,000 ImageNet classes an image belongs to, which “achieved a top-1 test accuracy of 4.34%”.

bayindirh 4 hours ago | parent [-]

Then, that’s the wrong paper. I’ll find it and link it as a reply to this comment. Probably tomorrow morning.

yogorenapan 5 hours ago | parent | prev [-]

> to reveal blurred version of the images being hashed

Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.

So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.

I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have

soulofmischief 4 hours ago | parent [-]

It starts at a broad understanding and ends with people permanently giving up their right and ability to keep rogue corporate governments in check.