Interesting work. It seems like these lossy photo hashes are more obfuscation and resolution reduction than anything secure.
In the photo of the child, facial features aren't reconstructable. Is it possible that PhotoDNA hashes might be sufficiently potato to not infringe on privacy or meaningfully (if not legally) count as explicit/illicit content?
Are secure lossy photo hashes possible? I feel like it'd require indistinguishability obfuscation (iO), where distinguishing a hash from zillions of random noise preimages would be guaranteed intractable. But I'm not sure if you could guarantee all the preimages matching the hash aren't all still recognizable.
Maybe you could set up some kind of adversarial system using your work as the adversary? (e.g. Set of transformed input images --[hashing neural net]-->hashes, then hashes--[Ribosome]-->preimage, then penalize hashing neural net (and reward Ribosome) based on distance of input image and preimage, along with rewarding the hashing net for distance from its hashes of other images + closeness of its hashes of similar transformed images.)