USENIX Security2026Top-tier venue
Breaking Widely Deployed Perceptual Hash Functions: Black-Box Collisions in Apple NeuralHash and Microsoft PhotoDNA
Diane Leblanc-Albarel, Bart Preneel
Abstract
Perceptual hash functions have been designed to detect multimedia copyright violations and illegal content. To achieve their purpose, they map inputs that are perceived as similar to close outputs. For many widely deployed schemes, however, both the design strategy and detailed specifications remain proprietary. Governments are now considering their extension to Client-Side Scanning (CSS) for end-to-end encrypted services, verifying content against illegal material before encryption. In 2021, Apple presented a detailed proposal for CSS based on the NeuralHash perceptual hash function. After strong criticism over privacy and security concerns, Apple withdrew the proposal, but NeuralHash remains deployed on all devices, with its current purpose undisclosed. In theory, brute-force collisions for NeuralHash (96-bit hash value) require 2 48 evaluations. Shortly after the NeuralHash release, researchers showed it is easy to craft perceptually dissimilar collisions, to incriminate any user by sending an innocent image sharing the same hash value as illegal content. This work shows a more serious weakness: when inputs are restricted to human faces, we found several collisions between perceptually different images after only 2 16 hash function evaluations. Unlike targeted attacks, our black-box approach requires no knowledge of the hash function design. We also demonstrate a high false negative rate (images that should share the same hash but do not). We further confirm the generality of our approach by studying PhotoDNA, Microsoft's widely deployed 1152-bit perceptual hash function. In the case of PhotoDNA, we found near-collisions at thresholds significantly lower than previously reported, appearing after between 2 14.6 and 2 17 evaluations depending on the threshold used. This is the first work to demonstrate exact collisions in NeuralHash and to identify near-collisions in PhotoDNA at such low thresholds. These results cast serious doubts on the suitability of these designs for large-scale client scanning, as they produce high false positive and false negative rates, and highlight the need to reassess their security and feasibility, particularly for large-scale applications where privacy risks and false positives have serious consequences.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 331254a0-ce3d-4d72-8be8-93e7bbec32c8Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 50 citations
- It's Not What It Looks Like: Manipulating Perceptual Hashing based ApplicationsQingying Hao, Licheng Luo, Steve T. K. Jan, Gang WangCCS 2021 · 36 citations
- End-to-End Secure Messaging with Traceability Only for Illegal ContentJames Bartusek, Sanjam Garg, Abhishek Jain, Guru-Vamsi PolicharlaEUROCRYPT 2023 · 20 citations
Related papers
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine LearningJonathan Prokos, Neil Fendley, Matthew Green, Roei Schuster et al.USENIX Security 2023
- Deep perceptual hashing algorithms with hidden dual purpose: when client-side scanning does facial recognitionShubham Jain, Ana-Maria Cretu, Antoine Cully, Yves-Alexandre de MontjoyeS&P 2023
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- CertPHash: Towards Certified Perceptual Hashing via Robust TrainingYuchen Yang, Qichang Liu, Christopher Brix, Huan Zhang et al.USENIX Security 2025
- Atkscopes: Multiresolution Adversarial Perturbation as a Unified Attack on Perceptual Hashing and BeyondYushu Zhang, Yuanyuan Sun, Shuren Qi, Zhongyun Hua et al.USENIX Security 2025
