Hacker News new | ask | show | jobs
by ec109685 1767 days ago
Not resembles. The adversarial image has to match a private perceptual hash function of the same CSAM image that the NeuralHash function matched before a human reviewer ever looks at it.
1 comments

Do you have any material on this private function?
Not beyond the documents Apple has shared. Presumably it will be kept that way given it prevents an adversarial attack against it.