USENIX Security2025Top-tier venue
Atkscopes: Multiresolution Adversarial Perturbation as a Unified Attack on Perceptual Hashing and Beyond
Yushu Zhang, Yuanyuan Sun, Shuren Qi, Zhongyun Hua, Wenying Wen, Yuming Fang
Abstract
Privacy and regulation are a long-lasting conflict in modern instant messaging, where the security community attempts to bridge this gap from a technological perspective. End-to-end encryption (E2EE) is a mathematically guaranteed privacy policy that has been widely built into commercial instant messaging applications. On the other hand, regulatory designs compatible with E2EE privacy are severely restricted, i.e., content auditing is (almost) impossible on ciphertext. For this reason, the community develops perceptual hash matching (PHM) as a regulation policy, where content-aware hash codes for media are computed prior to E2EE and matched against known criminal media, e.g., child pornography images, on the server side. In this paper, we systematically reveal a range of adversarial threats to such E2EE-PHM systems, leading to regulatory failures. Unlike previous case studies, our attack is a more realistic threat -uniformly fooling the famous pHash, Facebook PDQ, Microsoft PhotoDNA, and Apple NeuralHash, even with higher success rates and less training rounds. Here, we validate the above proposition in both scenarios of escaping and triggering regulation. Our main contribution is a new idea of multiresolution perturbation, where each perturbation element can affect image regions of adjustable scales. With this new idea and its wellformalized design, our attack encapsulates previous attacks as special cases -in some scenarios, it exhibits a huge leap in convergence efficiency compared to previous ones. Based on the above technical insights, we also discuss possible countermeasures and recommendations for social good.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Surveylance: Automatically Detecting Online Survey ScamsAmin Kharraz, William K. Robertson, Engin KirdaS&P 2018 · 73 citations
- It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming ServicesM. Zubair Rafique, Tom van Goethem, Wouter Joosen, Christophe Huygens et al.NDSS 2016 · 60 citations
Related papers
- Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine LearningJonathan Prokos, Neil Fendley, Matthew Green, Roei Schuster et al.USENIX Security 2023
- CertPHash: Towards Certified Perceptual Hashing via Robust TrainingYuchen Yang, Qichang Liu, Christopher Brix, Huan Zhang et al.USENIX Security 2025
- Public Verification for Private Hash MatchingSarah Scheffler, Anunay Kulshrestha, Jonathan R. MayerS&P 2023
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 50 citations
