Skip to main content

AdvHash: Adversarial collision attacks on perceptual hashing functions

CircleCI codecov.io PyPI Version Python Version License: GPL v3

Summary

AdvHash is a Python package that provides a simple to use interface for performing adversarial collision attacks on perceptual hashing functions.

PyTorch is used to re-create the target hashing functions and generating adversarial examples. AdvHash supports both CPU and GPU computations. Install the CUDA enabled version of PyTorch to use a GPU with AdvHash and specify device='cuda' when instantiating an attack or hash.

Adversarial collision attacks on image hashing functions

Adversarial cat Currently AdvHash supports collision attacks on hashing functions from the popular imagehash package using methods described in Adversarial collision attacks on image hashing functions.

Components

AdvHash is divided into multiple granular components:

Component Description
advhash a PyTorch based library for performing adversarial attacks
advhash.attack adversarial attack methods
advhash.hash perceptual hashing functions
advhash.utils utility functions for performing common resizing, conversion, and comparison operations

Getting Started

Installation

pip install advhash

*Install a CUDA enabled version of PyTorch to use a GPU with AdvHash.

Example Usage

This example shows how the L2Attack can be used to perform an adversarial collision attack on dHash using the resize method as the target split point.

import torch
import numpy as np
from PIL import Image
from advhash.attack.l2 import L2Attack

target_img = Image.open('forest.jpg')
source_img = Image.open('cat.jpg')

target = torch.tensor((np.array(target_img).astype('float32')))
source = torch.tensor((np.array(source_img).astype('float32')))

l2 = L2Attack(hash_fn='dhash', split_point='resize')

im_adv = l2.attack(target, source)

Attacks

Collision Attacks for Image Hashing

  • advhash.attack.l2.L2Attack
  • advhash.attack.hinge.HingeAttack

The above attacks accept a source image, target image, and hashing function as an input. The source image will be perturbed to create an adversarial image that has the same hash as the target image when hashed by the selected hashing function. Some attacks require additional configuration.

Hashing Functions

Future Development

Hashing Functions

  • pHash
  • aHash
  • pqd

Attack Methods

  • TBD

Defense Methods

  • TBD

Contributing

Contributions are welcome! If you plan to contribute new features, methods, or enhancements, please open an issue to discuss the addition further, or comment on an existing issue.

Metadata

Release files for advhash 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for advhash 0.1.1
File Size Uploaded
advhash-0.1.1.tar.gz 23.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for advhash 0.1.1
File Interpreter ABI Platform
advhash-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 49.1 kB

Release files / advhash-0.1.1.tar.gz

Download URL advhash-0.1.1.tar.gz
Size 23.3 kB
Tags Source
SHA-256 checksum
How to use checksums
c1ac49ff6935b003f81a74861b2a315f57dd007e006eb99044b5e45d08600b02
BLAKE2b-256 checksum
How to use checksums
67db14b0f743c600629045fe83723ea800f5b8750ecf323ad1fcb4c0f2987731
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.2 importlib_metadata/4.6.3 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.0 CPython/3.6.4

Release files / advhash-0.1.1-py3-none-any.whl

Download URL advhash-0.1.1-py3-none-any.whl
Size 25.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
03d9e81bdbea0e3463adfa490cec7ce26db4cf432960bd7c35facfb00cff6e9f
BLAKE2b-256 checksum
How to use checksums
e733eda33c0c05ec3c9bda58de4ebc0d30d2484162145812527dc35e2eeb2454
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.4.2 importlib_metadata/4.6.3 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.0 CPython/3.6.4

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page