For anything public, it's anything varying from trivial to hard/annoying depending on your client settings, but never quite impossible. Even in the best-case scenario where you have DHT turned off and all the trackers in the torrent are using HTTPS, man-in-the-middle attacks are fairly doable for anything popular.
If it was me, I’d snoop the DNS requests and/or SNI headers. Flag on torrent index sites and trackers known to be used for pirate stuff. They don’t need to know exactly which paw patrol movie you’re downloading, just that you are getting something from thepiratebay.