A plug-in defense that hardens reference images and smooths match decisions reduces evasion attack success on eight deep perceptual hashes and provides a certified l2 robustness radius near 0.3.
Robustness of Practical Perceptual Hashing Algorithms to Hash-Evasion and Hash-Inversion Attacks
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Perceptual hashing algorithms (PHAs) are widely used for identifying illegal online content and are thus integral to various sensitive applications. However, due to their hasty deployment in real-world scenarios, their adversarial security has not been thoroughly evaluated. This paper assesses the security of three widely utilized PHAs - PhotoDNA, PDQ, and NeuralHash - against hash-evasion and hash-inversion attacks. Contrary to existing literature, our findings indicate that these PHAs demonstrate significant robustness against such attacks. We provide an explanation for these differing results, highlighting that the inherent robustness is partially due to the random hash variations characteristic of PHAs. Additionally, we propose a defense method that enhances security by intentionally introducing perturbations into the hashes.
fields
cs.CV 1years
2026 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Double Down on Defense: Strengthening Deep Perceptual Hashes against Evasion Attacks without Retraining
A plug-in defense that hardens reference images and smooths match decisions reduces evasion attack success on eight deep perceptual hashes and provides a certified l2 robustness radius near 0.3.