[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86237-en":3,"doc-seo-86237-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},86237,1374391974585,"Genevieve","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms","Perceptual hash algorithms (PHAs) enable detection of image forgery under benign transformations, but their resilience to adversarially chosen perturbations lacks both clear understanding and provable guarantees. An evolutionary framework is presented using GigaEvo and OpenEvolve for targeted second-image attacks on PHAs. Attack performance is measured with a composite score covering attack success rate, query count, and L2 distortion. Experiments on four deployed PHAs (pHash, PDQ, PhotoDNA, NeuralHash) show improved attack success with fewer queries and lower distortion, revealing vulnerabilities in content-moderation pipelines and motivating provably robust designs.","LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms  \nAleksei S. Krylov 1 ,2[0009−0009−7990−6895], Denis S. Rakhov2[0009−0005−2915−7225], Veronica Veselova3[0009−0003−9508−0698], Dmitry Bolokhov3[1111−2222−3333−4444], and Oleg Y. Rogov 1 ,3 ,4 ,5[2222−−3333−4444−5555]  \n1 MIPT  \n2 Sberbank  \n3 Central University  \n4 AIRI  \n5 MTUCI-Labs  \narXiv :2607 . 1 1472v 1 [ cs .CR] 13 Jul 2026  \nAbstract. Perceptual hash algorithms (PHAs) are widely deployed to detect image forgery under benign transformations, yet their robustness against adversarially chosen perturbations remains poorly understood and rarely comes with provable guarantees. We propose a novel evolutionary framework based on GigaEvo and OpenEvolve for targeted second-image attacks on perceptual hash algorithms. We assess attack performance using a composite score that jointly accounts for the fraction of adversarial images whose normalized Hamming distance to the target hash falls below threshold p (Attack Success Rate), the number of queries issued to the hash function, and the L2 distortion relative to the original image. Experiments on four deployed PHAs (pHash, PDQ, PhotoDNA, NeuralHash) across 30 ImageNet image pairs demonstrate that our evolutionary approach achieves comparable or better ASR than existing black-box baselines using substantially fewer queries to the hash function, while simultaneously producing adversarial images with lower L2 distortion relative to the originals. The best evolved programs reduce the pre-defined composite attack score relative to the best optimized seed by 41.2% for NeuralHash, 38.3% for PDQ, 34.0% for pHash, and 8. 1% for PhotoDNA. Unlike gradient-based methods, our framework requires no internal knowledge of PHA architectures and naturally handles the non-differentiable, discretized nature of hash outputs. These results reveal previously unreported vulnerabilities in widely deployed contentmoderation pipelines and motivate the development of provably robust perceptual hashing schemes.  \nKeywords: perceptual hash algorithms · perceptual hash functions · hashes · black-box attacks · targeted collision · program evolution · safety · large language models · adversarial robustness  \n2 A. Krylov et al.  \n1 Introduction  \nPerceptual hash algorithms (PHAs) map multimedia objects to short binary strings so that perceptually similar inputs yield nearby hashes under Hamming distance. This functionality makes PHAs attractive for large-scale near-duplicate search [12], copyright enforcement, and safety applications such as client- or server-side detection of known harmful imagery [9] . In contrast to cryptographic hashing-where a single-bit change should avalanche-perceptual hashing is intentionally stable under benign content-preserving transformations (e.g. , resizing, compression, mild blur), while remaining discriminative across distinct content. Popular deployed designs include DCT-based global hashes (pHash, PDQ) [17, 6], gradient aggregation schemes (PhotoDNA-like) [14, 4, 3], and neural embedding approaches (NeuralHash-like) [5] . This stability–discrimination tension isnot merely an engineering trade-off: it is a mathematical constraint that becomes security-critical when an adversary can choose inputs. A substantial empirical literature demonstrates that many PHAs are robust to common non-adversarial edits [27, 2] . However, recent work has also established that robustness under benign transformations does not imply robustness against adversarial perturbations, including gradient-based hash-evasion attacks in white-box settings [8, 25] and practical attacks spanning inversion and evasion regimes [20] . Moreover, for certain semantic classes (notably faces), the effective hash space can be far smaller than the nominal bit-length would suggest [18] . These results raise a foundational question: what can we prove about the robustness of a perceptual hash, and what instance-wise guarantees can a depl","cbCaijrTBdrHOarX","https://ap.wps.com/l/cbCaijrTBdrHOarX","pdf",413061,1,15,"English","en",105,"# Abstract\n# Introduction\n# Related Work\n## Perceptual Hash Algorithms","[{\"question\":\"What problem does the paper address about perceptual hash algorithms?\",\"answer\":\"It studies how PHAs can be attacked when the attacker can choose inputs, noting that robustness under benign edits does not guarantee resistance to adversarial perturbations.\"},{\"question\":\"How does the proposed method run targeted black-box attacks?\",\"answer\":\"It uses an evolutionary program search framework (GigaEvo and OpenEvolve) to evolve perturbations so the produced hash closely matches a designated target hash.\"},{\"question\":\"How is attack performance evaluated in the experiments?\",\"answer\":\"Performance is assessed with a composite metric that combines attack success rate (thresholded normalized Hamming distance), number of hash-function queries, and L2 distortion from the original image.\"}]",1784209716,38,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"llm-guided-program-evolution-for-targeted-black-box-attacks-on-perceptual-hash-algorithms","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/llm-guided-program-evolution-for-targeted-black-box-attacks-on-perceptual-hash-algorithms/86237/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address about perceptual hash algorithms?","Question",{"text":75,"@type":76},"It studies how PHAs can be attacked when the attacker can choose inputs, noting that robustness under benign edits does not guarantee resistance to adversarial perturbations.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed method run targeted black-box attacks?",{"text":80,"@type":76},"It uses an evolutionary program search framework (GigaEvo and OpenEvolve) to evolve perturbations so the produced hash closely matches a designated target hash.",{"name":82,"@type":73,"acceptedAnswer":83},"How is attack performance evaluated in the experiments?",{"text":84,"@type":76},"Performance is assessed with a composite metric that combines attack success rate (thresholded normalized Hamming distance), number of hash-function queries, and L2 distortion from the original image.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]