论文标题

重新修理基于感知的散列客户侧扫描以进行身体监视

Re-purposing Perceptual Hashing based Client Side Scanning for Physical Surveillance

论文作者

Hooda, Ashish, Labunets, Andrey, Kohno, Tadayoshi, Fernandes, Earlence

论文摘要

内容扫描系统采用感知散列算法来扫描用户内容以获取非法材料,例如儿童色情或恐怖招募传单。感知散列算法有助于确定两个图像在保留输入图像的隐私时是否在视觉上相似。行业和学术界的几项努力建议在智能手机等客户设备上进行内容扫描,因为即将推出端到端加密,这将使服务器端内容扫描变得困难。但是,这些建议受到了强烈的批评,因为该技术有可能被滥用和重新使用。我们的工作通过实验表征一种滥用的潜力来为这次对话提供信息 - 攻击者操纵内容扫描系统以在目标位置进行物理监视。我们的贡献是三重的:(1)我们在客户端图像扫描系统的背景下提供了物理监视的定义; (2)我们通过实验表征了这种风险,并创建了一种监视算法,该算法通过中毒感知性哈希数据库的5%来实现> 40%的物理监视率; (3)我们通过实验研究客户端图像扫描系统的鲁棒性与监视之间的权衡,表明对非法材料的更强大的检测会增加物理监视的潜力。

Content scanning systems employ perceptual hashing algorithms to scan user content for illegal material, such as child pornography or terrorist recruitment flyers. Perceptual hashing algorithms help determine whether two images are visually similar while preserving the privacy of the input images. Several efforts from industry and academia propose to conduct content scanning on client devices such as smartphones due to the impending roll out of end-to-end encryption that will make server-side content scanning difficult. However, these proposals have met with strong criticism because of the potential for the technology to be misused and re-purposed. Our work informs this conversation by experimentally characterizing the potential for one type of misuse -- attackers manipulating the content scanning system to perform physical surveillance on target locations. Our contributions are threefold: (1) we offer a definition of physical surveillance in the context of client-side image scanning systems; (2) we experimentally characterize this risk and create a surveillance algorithm that achieves physical surveillance rates of >40% by poisoning 5% of the perceptual hash database; (3) we experimentally study the trade-off between the robustness of client-side image scanning systems and surveillance, showing that more robust detection of illegal material leads to increased potential for physical surveillance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源