Pith. sign in

REVIEW 2 cited by

Adversarial collision attacks on image hashing functions

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2011.09473 v1 pith:WB6WTXIK submitted 2020-11-18 cs.CV

classification cs.CV
keywords imagehashhashingadversarialattacksacrossalgorithmcollision
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Hashing images with a perceptual algorithm is a common approach to solving duplicate image detection problems. However, perceptual image hashing algorithms are differentiable, and are thus vulnerable to gradient-based adversarial attacks. We demonstrate that not only is it possible to modify an image to produce an unrelated hash, but an exact image hash collision between a source and target image can be produced via minuscule adversarial perturbations. In a white box setting, these collisions can be replicated across nearly every image pair and hash type (including both deep and non-learned hashes). Furthermore, by attacking points other than the output of a hashing function, an attacker can avoid having to know the details of a particular algorithm, resulting in collisions that transfer across different hash sizes or model architectures. Using these techniques, an adversary can poison the image lookup table of a duplicate image detection service, resulting in undefined or unwanted behavior. Finally, we offer several potential mitigations to gradient-based image hash attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Evolved attack programs cut a composite success–query–distortion score by 8–41% versus best optimized seeds on pHash, PDQ, PhotoDNA, and NeuralHash under a graded black-box oracle.

  2. Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools

    cs.CR 2024-12 conditional novelty 6.0 of 10

    A Pix2Pix GAN trained on 1000 celebrity photos can reconstruct recognizable faces from perceptual hash values of aHash, PDQ, NeuralHash, and PhotoDNA, including the first reported inversion attacks on PDQ and NeuralHash.

Pith tools