Skip to main content
QUICK REVIEW

[论文解读] Chat Control or Child Protection?

Ross Anderson|arXiv (Cornell University)|Oct 11, 2022
Homicide, Infanticide, and Child Abuse被引用 6
一句话总结

本文批判了英国和欧盟拟议的立法,这些立法将强制要求对加密消息实施客户端扫描,以检测儿童性虐待和恐怖主义诱导行为。罗斯·安德森指出,此类监控破坏了端到端加密,存在被滥用的风险,并分散了人们对基于人权和现实执法的、由本地主导的多利益相关方儿童保护方法的注意力。

ABSTRACT

Ian Levy and Crispin Robinson's position paper "Thoughts on child safety on commodity platforms" is to be welcomed for extending the scope of the debate about the extent to which child safety concerns justify legal limits to online privacy. Their paper's context is the laws proposed in both the UK and the EU to give the authorities the power to undermine end-to-end cryptography in online communications services, with a justification of preventing and detecting of child abuse and terrorist recruitment. Both jurisdictions plan to make it easier to get service firms to take down a range of illegal material from their servers; but they also propose to mandate client-side scanning - not just for known illegal images, but for text messages indicative of sexual grooming or terrorist recruitment. In this initial response, I raise technical issues about the capabilities of the technologies the authorities propose to mandate, and a deeper strategic issue: that we should view the child safety debate from the perspective of children at risk of violence, rather than from that of the security and intelligence agencies and the firms that sell surveillance software. The debate on terrorism similarly needs to be grounded in the context in which young people are radicalised. Both political violence and violence against children tend to be politicised and as a result are often poorly policed. Effective policing, particularly of crimes embedded in wicked social problems, must be locally led and involve multiple stakeholders; the idea of using 'artificial intelligence' to replace police officers, social workers and teachers is just the sort of magical thinking that leads to bad policy. The debate must also be conducted within the boundary conditions set by human rights and privacy law, and to be pragmatic must also consider reasonable police priorities.

研究动机与目标

  • 挑战拟议立法背后的技术与伦理假设,即强制对端到端加密消息实施客户端扫描以实现儿童保护。
  • 强调为国家和企业监控让位于儿童安全名义下的强加密体系可能带来的风险。
  • 将政策辩论的视角从情报机构和技术公司,转向遭受暴力侵害风险的儿童。
  • 反对以人工智能替代训练有素的警察、社工和教育工作者来应对复杂社会犯罪。
  • 强调有效的儿童保护必须由本地主导,多方参与,并受人权和隐私法的约束。

提出的方法

  • 分析在端到端加密消息中检测基于文本的诱导和恐怖主义招募的客户端扫描在技术上的可行性及其风险。
  • 研究英国和欧盟拟议立法的影响,这些立法将要求服务提供商在应用加密前扫描用户内容。
  • 结合现实世界中的儿童虐待和极端化案例,论证此类犯罪根植于复杂的社会问题,需要细致入微、以人为本的应对措施。
  • 批判认为自动化系统可替代专业判断来识别虐待或诱导行为的假设。
  • 强调隐私保护设计的重要性,以及后门机制(即使出于儿童安全目的)所蕴含的危险。
  • 强调政策必须尊重人权法,并与实际执法优先事项和能力保持一致。

实验结果

研究问题

  • RQ1强制在端到端加密消息平台实施客户端扫描,其技术和系统性风险是什么?
  • RQ2所提议的儿童保护监控模式与有效、本地主导、多方参与的应对方式相比,有何异同?
  • RQ3儿童虐待和恐怖主义问题的政治化如何削弱有效的执法和儿童保护工作?
  • RQ4在不侵犯隐私或产生误报的情况下,人工智能或自动化系统在多大程度上能可靠检测诱导或极端化行为?
  • RQ5如何将儿童保护政策从国家和企业监控重新导向真正符合受侵害风险儿童的实际需求?

主要发现

  • 对加密消息实施客户端扫描存在重大技术风险,包括被滥用、被对手利用,以及整体系统安全性的削弱。
  • 拟议的法律可能破坏端到端加密,而端到端加密对保护所有用户(而不仅仅是涉嫌违法者)的隐私与安全至关重要。
  • 自动化系统无法替代警察、社工和教师等训练有素的专业人员在识别和应对儿童虐待方面的细致判断。
  • 儿童保护是一项复杂且棘手的社会问题,需要由本地主导、多方参与的干预措施,而非自上而下的技术强制。
  • 辩论必须基于受侵害儿童的真实生活经验,而非情报机构或监控承包商的优先事项。
  • 任何政策都必须在人权法的框架内进行,并切实与实际执法优先事项和能力保持一致。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。