This presentation summarizes research conducted as part of the Master of Science in Digital Forensics and Cybersecurity program at John Jay College of Criminal Justice, City University of New York. Perceptual hashing systems are widely used in content moderation, image similarity detection, digital forensics, and image authenticity and verification workflows. Despite their operational importance, prior adversarial evaluations have been fragmented across algorithms, datasets, and experimental protocols, making direct comparison difficult. This work introduces a unified adversarial evaluation framework that evaluates six perceptual hashing algorithms (pHash, PDQ, pHash-256, NeuralHash, SmartHash-WI, SmartHash-OV) under identical conditions using three attack objectives: evasion, near-collision, and exact collision. The study further introduces near-collision analysis as an operationally grounded security metric aligned with how deployed systems trigger alerts in practice. Key findings include: Successful evasion attacks against all evaluated algorithms under the tested conditions. Significant differences between exact-collision and near-collision security assessments. Evidence that prior exact-collision-focused evaluations may underestimate real-world false-positive risk. The first adversarial evaluation of SmartHash, revealing a distinctive asymmetric robustness profile. A controlled architectural comparison between PDQ and an extended 256-bit pHash variant. The presentation was delivered at the 2026 Graduate Student Research Symposium (GSRS) and summarizes the principal findings, methodology, and implications of the broader thesis research project. Author: Avijit RoyAdvisor: Prof. Shweta Jain, Ph.D.Affiliation: John Jay College of Criminal Justice, City University of New York Keywords: Perceptual Hashing, Adversarial Machine Learning, Near-Collision Attacks, Digital Forensics, Content Moderation, Computer Vision Security, Image Similarity Detection
Avijit Roy (Mon,) studied this question.