Pith. sign in

REVIEW 2 cited by

Robustness of Practical Perceptual Hashing Algorithms to Hash-Evasion and Hash-Inversion Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.00918 v2 pith:CQTSSPOT submitted 2024-06-03 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords phasattacksrobustnesssecurityalgorithmshash-evasionhash-inversionhashing
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Perceptual hashing algorithms (PHAs) are widely used for identifying illegal online content and are thus integral to various sensitive applications. However, due to their hasty deployment in real-world scenarios, their adversarial security has not been thoroughly evaluated. This paper assesses the security of three widely utilized PHAs - PhotoDNA, PDQ, and NeuralHash - against hash-evasion and hash-inversion attacks. Contrary to existing literature, our findings indicate that these PHAs demonstrate significant robustness against such attacks. We provide an explanation for these differing results, highlighting that the inherent robustness is partially due to the random hash variations characteristic of PHAs. Additionally, we propose a defense method that enhances security by intentionally introducing perturbations into the hashes.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Double Down on Defense: Strengthening Deep Perceptual Hashes against Evasion Attacks without Retraining

    cs.CV 2026-08 conditional novelty 6.0 of 10

    A plug-in defense that hardens reference images and smooths match decisions reduces evasion attack success on eight deep perceptual hashes and provides a certified l2 robustness radius near 0.3.

  2. LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Evolved attack programs cut a composite success–query–distortion score by 8–41% versus best optimized seeds on pHash, PDQ, PhotoDNA, and NeuralHash under a graded black-box oracle.

Pith tools