Back to search

University of Illinois - Chicago

Content-Moderation for End-to-End-Encrypted Platforms

Abstract

dc:description

In 2021, Apple proposed a mechanism to detect child-sexual-abuse-material (CSAM) in end-to-end encrypted content uploaded to iCloud. This mechanism leveraged a private set intersection (PSI) protocol to recover a decryption key for encrypted data that matched against a blocklist of hashes curated by Apple. However, the proposal faced widespread criticism as it completely trusted Apple to create the blocklist without any oversight. Furthermore, due to technical reasons, a third-party could not verify that the blocklist was limited to checking for CSAM material. Unfortunately, this meant that the blocklist could be easily manipulated for surveillance and censorship, and due to the lack of trust in a self-interested organization, this proposal was not implemented This thesis posits that in order to increase trust in a blocklisted content moderation system, it is necessary to involve multiple, independent parties in creation of the blocklist. In particular, we envision a setting where a group of trusted auditors, e.g., law enforcement, and child safety groups, publish a common (obfuscated) blocklist of content that storage providers can check against. Such blocklists are not uncommon, e.g., the NCMEC and FBI have published lists of missing children and persons. Having a common blocklist curated by multiple parties with different interests, will build more trust in the system than individual blocklists published by self-interested service providers. This idea poses several technical challenges such as: i) ensuring that the blocklist is unforgeable and can be authenticated by clients, ii) ensuring that the service providers do not learn any information about non-CSAM content, and iii) keeping the blocklist confidential from the clients. This thesis proposes a novel crypto-graphic primitive, a randomizable set-homomorphic signature, that simultaneously achieves all of these goals. A set homomorphic signature allows us to represent an arbitrarily large blocklist with a compact digest that can be authenticated using the auditors’ public keys. We provide a RSA-based construction, and use it to design a content moderation protocol for encrypted file stores. The protocol is optimal in terms of client-side compute, communication and storage costs. Additionally, we prove security of the protocol and provide benchmarks on a public cloud infrastructure.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Arpad Neale (23291395)

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • In Copyright

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:figshare.com:article/31451164

Chain of custody

source
Harvested from
University of Illinois - Chicago
Base URL
api.figshare.com/v2/oai
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
related terms
citation

Arpad Neale (23291395). Content-Moderation for End-to-End-Encrypted Platforms. 2025. https://doi.org/10.25417/uic.31451164.v1