As you pointed out, since this is an adversarial use case, a robust cryptographic hash function is the way to go. [For a non-cryptographic Hash function, SeaHash [1] would be the best choice, which is violently fast!]
BLAKE2b would have been the perfect choice given the adversarial nature, as it much secure and faster than MD5. [2]
MD5 is so broken, it's really poor choice for any use case - cryptographic (fundamentally broken) or not (fundamentally slow).
[1] http://ticki.github.io/blog/seahash-explained/
[2] https://leastauthority.com/blog/BLAKE2-harder-better-faster-...