LLM-Guided Program Evolution for Targeted Black-Box Attacks on Perceptual Hash Algorithms
This work addresses the lack of provable robustness in perceptual hashing algorithms under adversarial perturbations by introducing GigaEvo/OpenEvolve, a large language model (LLM)-guided program evolution framework. For the first time, LLM-driven program synthesis is applied to black-box attacks on perceptual hashing, circumventing the need for internal algorithm access and effectively handling the discrete and non-differentiable nature of hash outputs. By optimizing a composite scoring metric, the method achieves high-efficiency attacks with minimal perturbation. Experimental results demonstrate that the approach significantly outperforms existing black-box attacks on pHash, PDQ, PhotoDNA, and NeuralHash, requiring fewer queries, achieving lower L2 distortion, and reducing the composite attack score by up to 41.2%, thereby exposing previously undisclosed security vulnerabilities in mainstream content moderation systems.