Skip to main content
QUICK REVIEW

[论文解读] Outside Looking In: Approaches to Content Moderation in End-to-End Encrypted Systems

Seny Kamara, Mallory Knodel|arXiv (Cornell University)|Feb 9, 2022
Internet Traffic Analysis and Secure E-voting被引用 10
一句话总结

本文评估了在端到端加密(E2EE)系统中内容审核的技术方法,结论是用户举报和元数据分析最能兼顾用户隐私与安全。研究发现,客户端扫描等技术会破坏E2EE的保障,而用户举报和元数据分析则能在不损害加密安全的前提下,有效检测儿童性虐待材料(CSAM)、垃圾信息和虚假信息等有害内容。

ABSTRACT

In this paper, we assess existing technical proposals for content moderation in End-to-End Encryption (E2EE) services. First, we explain the various tools in the content moderation toolbox, how they are used, and the different phases of the moderation cycle, including detection of unwanted content. We then lay out a definition of encryption and E2EE, which includes privacy and security guarantees for end-users, before assessing current technical proposals for the detection of unwanted content in E2EE services against those guarantees. We find that technical approaches for user-reporting and meta-data analysis are the most likely to preserve privacy and security guarantees for end-users. Both provide effective tools that can detect significant amounts of different types of problematic content on E2EE services, including abusive and harassing messages, spam, mis- and disinformation, and CSAM, although more research is required to improve these tools and better measure their effectiveness. Conversely, we find that other techniques that purport to facilitate content detection in E2EE systems have the effect of undermining key security guarantees of E2EE systems.

研究动机与目标

  • 评估不同内容审核技术对端到端加密(E2EE)隐私与安全保证的影响。
  • 识别在E2EE系统中检测不良内容的技术方法中,哪些与强加密特性相兼容。
  • 评估不同内容审核策略在E2EE环境下的有效性与隐私权衡。
  • 为平台设计者和政策制定者提供指导,推动在保障用户安全的同时实现有效审核的解决方案。

提出的方法

  • 将内容审核工具按审核生命周期的各个阶段进行分类,包括检测、审查和处理。
  • 定义E2EE及其核心隐私与安全保证,如机密性和完整性。
  • 将提出的各项技术方案(如客户端扫描、客户端过滤和密码学技术)与E2EE安全属性进行对比分析。
  • 评估用户举报和元数据分析作为维持端到端安全性的可行替代方案。
  • 评估每种方法在检测各类内容(如CSAM、垃圾信息和虚假信息)方面的可行性与局限性。
  • 使用威胁建模方法,判断哪些技术会削弱或维持E2EE保证。

实验结果

研究问题

  • RQ1在E2EE系统中,哪些内容审核技术能够维持端到端加密的机密性和完整性保证?
  • RQ2用户举报和元数据分析在E2EE系统中检测有害内容(如CSAM、垃圾信息和虚假信息)方面的有效性如何?
  • RQ3客户端扫描和过滤机制在多大程度上会破坏E2EE的安全属性?
  • RQ4不同技术方法在E2EE环境中进行内容审核时,其隐私与安全权衡关系如何?
  • RQ5是否可以在不损害端到端安全模型的前提下,实现可扩展且保护隐私的审核?

主要发现

  • 用户举报和元数据分析是E2EE系统中内容审核最可行的方案,因其能有效维持端到端安全保证。
  • 客户端扫描和过滤技术会破坏E2EE,因其引入了解密点,损害了机密性和完整性。
  • 用户举报和元数据分析可有效检测多种问题内容,包括儿童性虐待材料(CSAM)、垃圾信息和虚假信息。
  • 用户举报和元数据分析的有效性足够高,可实际应用,但需进一步研究以提升检测准确率和可扩展性。
  • 声称可在不破坏加密的前提下实现E2EE中内容检测的技术,往往无法维持核心安全属性,实际中并不安全。
  • 目前尚无任何技术方案能在不带来显著隐私或安全权衡的前提下,实现E2EE中的完整内容检测,这进一步凸显了采用替代方案的必要性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。