It's Not What It Looks Like: Manipulating Perceptual Hashing based Applications

It's Not What It Looks Like: Manipulating Perceptual Hashing based Applications
复制标题

DOI:
10.1145/3460120.3484559
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Qingying Hao;Licheng Luo;Steve T. K. Jan;Gang Wang
Qingying Hao;Licheng Luo;Steve T. K. Jan;Gang Wang
中科院分区:
其他
文献类型:
--
作者:
Qingying Hao;Licheng Luo;Steve T. K. Jan;Gang Wang

文献摘要

相似文献

感知哈希广泛用于搜索或匹配类似图像,以进行数字取证和网络犯罪研究。不幸的是,感知哈希算法的鲁棒性在这些背景下还没有得到很好的理解。在本文中,我们通过实验和经验研究了感知哈希的稳健性及其相关的安全应用。我们首先开发了一系列攻击算法来颠覆基于感知哈希的图像搜索。这是通过生成攻击图像来完成的,这些图像有效地扩大了与原始图像的哈希距离,同时引入了最小的视觉变化。为了使攻击切实可行,我们在黑盒设置下设计了攻击算法,并通过新颖的设计(例如灰度初始化)进行了增强,以提高攻击效率和可转移性。然后,我们使用三个不同的数据集评估对标准 pHash 及其强大变体的攻击。在通过实验确认攻击有效性后,我们对现实世界的反向图像搜索引擎(包括 TinEye、Google、Microsoft Bing 和 Yandex)进行了实证测试。我们发现我们的攻击在 TinEye 和 Bing 上非常成功,在 Google 和 Yandex 上也取得了一定的成功。根据我们的发现,我们讨论可能的对策和建议。
Perceptual hashing is widely used to search or match similar images for digital forensics and cybercrime study. Unfortunately, the robustness of perceptual hashing algorithms is not well understood in these contexts. In this paper, we examine the robustness of perceptual hashing and its dependent security applications both experimentally and empirically. We first develop a series of attack algorithms to subvert perceptual hashing based image search. This is done by generating attack images that effectively enlarge the hash distance to the original image while introducing minimal visual changes. To make the attack practical, we design the attack algorithms under a black-box setting, augmented with novel designs (e.g., grayscale initialization) to improve the attack efficiency and transferability. We then evaluate our attack against the standard pHash as well as its robust variant using three different datasets. After confirming the attack effectiveness experimentally, we then empirically test against real-world reverse image search engines including TinEye, Google, Microsoft Bing, and Yandex. We find that our attack is highly successful on TinEye and Bing, and is moderately successful on Google and Yandex. Based on our findings, we discuss possible countermeasures and recommendations.