CSAI Match and the Content Safety API: The Systems That Flagged You.
CSAI Match and the Content Safety API: The Systems That Flagged
You Most investigations that we handle begin with a referral from the National Center for Missing & Exploited Children’s CyberTipline (the “CyberTipline”). But, despite their importance, these referrals are investigative leads rather than conclusive proof of any crime. Most often, these leads come into the Department of Justice and the FBI because of one of several automated detection systems. The most common of these systems is known as “hash matching.” A hash is a unique digital fingerprint created by scanning the content of a file with a hash function. A hash value is different for every unique file, which means that the specific hash of a file can only have one identity. In the context of hash matching, this means that when any platform’s automated system scans a user’s files, it compares them to a database of known child sexual abuse material (CSAM). CSAM refers to visual depictions of sexually explicit conduct in which a person is depicted as a child. When the platform’s scanning program finds a match between a user’s hash and the database of known CSAM, it triggers a referral to the CyberTipline. If the law enforcement authorities then decide that there is cause to open an investigation into you, they will request your information from the platform. There are a few non-automated ways to get a CSAM investigation started, though. For example, sometimes computer repair shops will discover CSAM during normal computer repairs, which could lead them to make a police report that triggers a CyberTipline referral. Schools and members of the community can originate reports, as well. In some cases, investigators may use cryptocurrency tracing to uncover evidence, again leading to a federal child exploitation investigation. In each of these scenarios, though, the evidence of a match does not prove that you had the CSAM with the intent to have it.
What are CSAI Match and Google Content Safety API?
Google describes CSAI Match as one of the tools it uses to “match known child sexual abuse content,” and it refers to the tool as its “Child Sexual Abuse Imagery Match” technology. While the specific technical details of CSAI Match are a trade secret, it can still be inferred that this tool will function very similarly to Microsoft PhotoDNA. However, that does not mean that the two are identical; instead, it means that while both technologies rely on similar principles, they still have distinct implementations. CSAI Match is not ordinary text scanning or account-risk scoring either, and it is important to understand what it is and what it is not when defending against a federal child abuse investigation. Most notably, a match produced by the CSAI Match system (or by PhotoDNA) does not prove that a user knowingly possess or view an illicit image or video. Rather, a match only determines that the file in question is identical to one of the files in the CSAM database. The match proves identity, not intent, and proving a match alone is insufficient for a criminal conviction.
Google Content Safety API The Google Content Safety API
is not exactly like CSAI Match. While CSAI Match is a video fingerprint-matching tool that YouTube makes available to partners in industry and NGOs, the Content Safety API is a developer-facing classification tool. The Content Safety API is designed to analyze submitted content, and it uses artificial intelligence to provide outputs regarding “safety review signals.” These outputs are not judicial determinations, but rather signals which give an indication that content should be subject to human review. A key difference between the Content Safety API and a known-hash match system like CSAI Match is the nature of the output. With the Content Safety API, the output from its machine-learning classifiers is not “positive” or “negative,” but rather a score. This score is a probability, the output that results from the software’s confidence that the content depicts prohibited material. A fingerprint match like those produced by the CSAI Match system, conversely, shows that the user’s video contains a segment that is a full or near-duplicate of a known child abuse imagery video. In other words, CSAI Match determines the identity of the file, while Content Safety API generates a probability score that the content depicts illegal material. Both are useful for detection, but neither can, by itself, prove that a user possesses such material with the requisite intent in order to merit a conviction in federal court.
What does a content safety match actually prove?
When a company’s content safety system produces a “match,” what does that match prove? While the answer depends on the underlying technology at hand, here are some key examples of what a content safety “match” can prove. - An Exact Cryptographic Match.
There are several different types of cryptographic hash functions. When a match is produced by one of these functions, it can be assumed that the file which produced the match is identical to a known hash value in a database of child abuse material. This means a cryptographic match identifies an identical file rather than a visually similar file. - Perceptual Match
A perceptual hash, conversely, is created with the goal of generating the same hash for different but perceptually similar images. This means that even if a file is altered by re-encoding or adding a border or overlay, the perceptual hash will match. When a content safety match is produced by a perceptual hash, it indicates that the user’s file is perceptually similar to a known-hash value, rather than identical. - A Video Frame Match
Similar to PhotoDNA, video matching involves the creation of frame-level fingerprints rather than whole-file hashes. While some video matching tools will rely on a single-frame fingerprint (i.e., one frame of the video that match a known-hash of a known-CSAM image), others will compare a sequence of fingerprints in order to produce a match. - Classifier Match
When a content safety match comes from a machine-learning classifier, the “match” is a signal based on a threshold for the output produced by the classifier. In other words, an output from a content safety match system like the Content Safety API, will include a probability that the content depicts illegal material. When that probability is above a certain threshold, the match is then reported as a “positive” result.
Why is This Significant?
A content safety match is significant because it is how most CSAM cases are initiated today. In fact, without content safety systems, many of these cases would never make it to court. The process of a content safety match involves identifying content that has been flagged as being child sexual abuse material and then transmitting the user’s account information to the U.S. government. However, it is important to remember that a content safety match does not prove that a user intentionally stored or viewed material in violation of federal law. There are numerous ways to experience false positives with content safety systems, and our defense team handle matters in arguing for exclusion based on false content safety matches. - Cryptographic Hash Collision
- Perceptual Matching Errors
- Transcoding
- Screenshots and Thumbnails
How does a platform flag become a federal investigation?
Under 18 U.S.C. § 2258A, electronic service providers are required to report suspected child abuse materials to the National Center for Missing & Exploited Children. Under the statute, providers are not required to proactively search for such materials; however, when they identify suspected material, they must file a report with NCMEC. The National Center for Missing & Exploited Children (NCMEC) operates the CyberTipline, which allows electronic service providers to fulfill their reporting obligations under 18 U.S.C. § 2258A. Once a provider files a report via the CyberTipline, NCMEC then forwards that report to the appropriate law enforcement agency. Along with other identifiers, providers typically include information such as:
- User account identifiers, email addresses, IP addresses, and timestamps;
- Filenames, file hashes, and other relevant data. While the process of submitting a report to the CyberTipline typically begins with an automated identification from a platform’s content safety system, it is not required to start with a detection by an automated system. As discussed, content safety matches can result from various sources and detection methods. While providers can and do review the material prior to submission to the CyberTipline, the statute does not require them to confirm the nature of the material. After a report is submitted to the CyberTipline, the report is then reviewed by NCMEC. If the report is deemed sufficiently credible, NCMEC will refer the report to law enforcement authorities. If the receiving agency decides it is in the best interest to investigate further, then a federal investigation into the suspected material is opened. Once an investigation is opened, federal agents will use the logs provided by the relevant platform to identify an account or device associated with the suspected material, which then often leads to a search warrant being issued to seize the devices or accounts involved.
Does a flagged cloud account prove I knew?
Courts have recognized that an exact cryptographic match only proves the fact that two files have the same content; this, alone, does not establish that a user knew what it contained or that he had control over the file’s storage on a service provider’s servers. From a technical perspective, cloud storage works just as Google explains, by creating additional copies of files that are stored on a device. Because this creates additional copies of a file automatically, the simple fact that a file exists in a cloud account does not prove that the user knew that the file existed or that the user possessed the file with the intent that is necessary for a federal CSAM conviction.
How to Prove Knowing Possession and Use of CSAM Proving
that a user knowingly possessed or accessed CSAM requires proving both the user’s knowledge of the material and their ability to access or control it. In United States v. Moreland, 665 F.3d 137 (5th Cir. 2011), the Fifth Circuit explained that “courts have refused to find that a defendant constructively possessed child pornography located on his computer simply because the defendant exclusively possessed that computer, without additional evidence of the defendant’s knowledge and dominion or control of the images.” In federal child exploitation cases, this is the primary challenge for prosecutors. A content safety match proves that an account contains child abuse material, but it does not prove the user’s knowledge or access. The second step for federal authorities is to establish a connection between the defendant and the cloud account. Determining this connection involves analyzing several factors. In most cases, the following factors are important when connecting a defendant to a flagged account: - Login and Access History. If a flagged account was accessed through various devices using the same login credentials, this could be used to establish a connection to the account.
- Device Tokens and OAuth Sessions.
- Other Forms of Cloud Attribution.
How to Establish Account Attribution Determining
if an individual uploaded or downloaded a file manually, or if a file was uploaded to the cloud automatically, will require an analysis of app telemetry and other information that is associated with the devices or account that is under investigation. If an account is shared with family or workplaces, determining if the account belongs to one individual rather than another is also necessary. Finally, many devices will automatically cache images and other types of data from the web; this means that a screenshot or a thumbnail could be a local file or that a file was saved to a cloud account automatically, without any direct knowledge or action on the part of the user. This is also important to distinguish from a manual upload or a knowing acquisition of CSAM.
What should my lawyer request after an automated flag?
If an automated content safety system is why your case exists, then one of the first and most-important things to do is to make sure your lawyer requests the pertinent documentation from the provider. When these tools trigger an investigation, the provider’s own records can have a huge role in a successful defense. If your lawyer requests these documents during the investigation phase, it can help secure evidence that might not exist by the time the case gets to trial.
- Request a copy of the provider’s match logs if an automated system triggered the investigation.
- Request the API response and confidence score if a machine-learning classifier was used to flag the account or file.
- Request a copy of the moderation notes if a human reviewer made or overturned a match finding.
- Request the source or description of the hash database used to establish the match.
- Request a copy of the CyberTipline attachment and preservation request from the platform.
- Request the provider’s audit logs for the events that led to a match or the provider’s referral of the account.
What if I delete the files?
Deleting files does not, necessarily, remove the logs from the provider. Often, providers will take a snapshot of the relevant content before filing a referral to the CyberTipline. This snapshot and the logs will be sent to the investigators. The investigators will then have access to the snapshot and logs after your files have been deleted.
Similarly, deleting an account will not necessarily delete the preserved logs that are available to investigators. If the platform has preserved a copy of the data, that data will continue to exist regardless of what action the user takes. As with all forms of data preservation, the user’s intentional efforts to erase evidence will not be effective if a snapshot has been taken.
What if I am a victim of extortion or hacking?
When a content safety match system flags a suspect account, it does not necessarily reveal information about whether the content has been accessed or if it has been posted by a hacker or someone posing as the user. This is especially true in cases of extortion, as the user may have stored or posted CSAM as the result of being hacked. In these cases, a content safety match alone is not sufficient to prove guilt, but, as discussed above, it could lead to an investigation and, in some cases, a search warrant. Determining whether a user had control of a device at a certain point is a key element in a defense against a federal child exploitation charge.
Can the defense inspect the detection system?
Can the defense request copies of the files?
The defense can request copies of the files in question, and this is often something that is covered by a protective order. In some cases, there are legal issues with duplication of the files due to the contents. In one case, the court noted that “due to the nature of the material produced, the government will not provide the defense with duplicates of the contraband files, and the defense will not attempt to view or copy these files outside of the controlled environment in Government Laboratory 2 (Lab 2).”
How does this compare to request copies of the detection system?
While requests for copies of the files in question often involve a protective order and duplication concerns, requests for copies of the detection system and other records are different. For example, request copies of API documentation, not records, in a case that involves an alleged match from a detection system will not raise duplication issues because the documentation is not a record of illegal images and videos. In fact, while a provider may attempt to claim a trade secret in its proprietary detection system, this would not automatically exclude records or information in the defense’s possession in order to be able to provide a proper defense. Protective orders can, however, govern the use and retention of these records by the defense during discovery.
Is there any other reason for restricting access?
Contamination of the hash database is a common ground for challenging the reliability of automated matching systems, and the process by which the database is updated is also a pertinent issue to investigate in CSAM cases. The method by which a human reviewer confirms an automated match, the manner in which matches are processed by a government laboratory, and the means by which the materials are cataloged are all issues that can affect the reliability of the results obtained from automated matching systems. In Chiaradio, the court required that an expert explain “the nature, purpose and operation of the highly specialized P2P software that this computer examined to obtain the evidence it has produced, which is not evidence.” This request is consistent with the other steps outlined in this article.
Talk to Spodek Law Group
Every case turns on its own facts, and general information is no substitute for advice about yours. Todd Spodek, managing partner of Spodek Law Group, and the firm& #x27;s attorneys defend federal criminal and white collar matters nationwide. Reach the firm at 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196