VLDB 2026 Research / reviewers in the wild / expert
Teddy Furon
dblp:00/3862
· DBLP profile ↗
83ranked-venue papers
10as first author
30since 2021 · last 2026
0000-0002-1565-765XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 43 · 5 first-author · 15 since 2021Security and privacy · 24 · 5 first-author · 7 since 2021Artificial intelligence and machine learning · 20 · 12 since 2021Databases, data management, data science and information retrieval · 9Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ROSE: Extended Evaluation of RObust and SEcure Black-Box DNN WatermarkingabstractDeep neural networks (DNNs) are valuable industrial assets requiring reliable intellectual-property protection. This paper extends ROSE [1], a black-box watermarking protocol for MLaaS settings that quantifies ownership through statistical rarity (expressed as R = −log2(p), in bits) and adversarial computational work. ROSE binds trigger-label pairs to a secret key through a hash-based mechanism, limiting a posteriori forgery and supporting formal reasoning about verification strength. We present an expanded theoretical analysis together with an extensive empirical evaluation across multiple image-classification datasets and architectures, including CNNs, ResNets, and Vision Transformers. Experiments show that ROSE preserves primary task accuracy at low trigger fractions, achieves high watermark recovery, and yields rarity values reaching several hundred bits. The method is evaluated under a broad range of model and input-level perturbations, including fine-tuning, pruning, quantization, image transformations, and sanitizers such as Neural Cleanse and Neural Laundering. In double-watermarking settings, overwriting attempts introduce ambiguity only at the cost of substantial accuracy loss, thereby preserving the practical verifiability of the original claim. Efficiency measurements indicate low overhead: embedding remains comparable to standard training and verification incurs minimal latency. More precisely, the verification cost scales primarily with the number of trigger evaluations rather than directly with model size. While this suggests favorable protocol-level scalability, the present empirical study is restricted to the image-classification architectures evaluated in this paper. Overall, ROSE provides a practical black box watermarking framework that combines strong ownership verifiability, empirical robustness, and low verification overhead in the studied setting. Kassem Kallas, Teddy Furon |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Evaluating the security of public surrogate watermark detectorsabstractThe omnipresence of generated content has led to an increasing need of multimedia content traceability. Water-marking techniques have been proven to provide both detection guarantees and robustness. However, widespread use of such methods would require disclosing the watermark detector to the public. Such access breaches the watermark security: end-users with unlimited access to the detector could easily craft adversarial examples, through white-box and black-box attacks. To circumvent this issue, we suggest providing to the public a surrogate, less accurate detector. Calls to the private detector would be reserved for important or anomalous cases. This paper studies the potential leakage of information from the surrogate detector. We first create a wide panel of images adversarial to the surrogate detector. The efficiency of the private detector is then assessed on this data. This allows us to introduce a metric of the transferability of these attacks from the surrogate to the private detector. Through this metric, we evaluate the security of different designs of surrogate detectors. Chloé Imadache, Eva Giboulot, Teddy Furon |
ICASSP | 3 |
| 2025 | Multi-modal Identity Extraction
Ryan Webster, Teddy Furon |
ICCV | 2 |
| 2025 | BAIT: A New DNN Backdoor Attack Using Inpainted TriggersabstractBackdoor attacks compromise deep neural networks by injecting them with covert, malicious behaviors during training. A backdoor can then be activated at test-time using a trigger pattern. As backdoors become more sophisticated, defenses struggle to catch up. This paper introduces a simple yet effective input-specific Backdoor Attack using Inpainted Triggers, dubbed BAIT. Its trigger relies on a randomly-drawn polygonal patch, filled via inpainting with an off-the-shelf generative adversarial network. We show with BAIT that several defenses, including common test-time input purification methods, can be bypassed by patch-based backdoors. To counter this new attack, we propose four defense recommendations. Quentin Le Roux, Yannick Teglia, Eric Bourbao, Philippe Loubet-Moundi, Teddy Furon |
ICIP | 5 |
| 2025 | Watermark Anything With Localized MessagesabstractImage watermarking methods are not tailored to handle small watermarked areas.
This restricts applications in real-world scenarios where parts of the image may come from different sources or have been edited.
We introduce a deep-learning model for localized image watermarking, dubbed the Watermark Anything Model (WAM).
The WAM embedder imperceptibly modifies the input image, while the extractor segments the received image into watermarked and non-watermarked areas and recovers one or several hidden messages from the areas found to be watermarked.
The models are jointly trained at low resolution and without perceptual constraints, then post-trained for imperceptibility and multiple watermarks.
Experiments show that WAM is competitive with state-of-the art methods in terms of imperceptibility and robustness, especially against inpainting and splicing, even on high-resolution images.
Moreover, it offers new capabilities: WAM can locate watermarked areas in spliced images and extract distinct 32-bit messages with less than 1 bit error from multiple small regions -- no larger than 10\% of the image surface -- even for small $256\times 256$ images.
Training and inference code and model weights are available at https://github.com/facebookresearch/watermark-anything. Tom Sander, Pierre Fernandez, Alain Durmus, Teddy Furon, Matthijs Douze |
ICLR | 4 |
| 2025 | AggNet: Learning to aggregate faces for group membership verification
Marzieh Gheisari, Javad Amirian, Teddy Furon, Laurent Amsaleg |
Signal Process. Image Commun. | 3 |
| 2025 | On the Vulnerability of Retrieval in High Intrinsic Dimensionality NeighborhoodabstractThis article investigates the vulnerability of the nearest neighbors search, which is a pivotal tool in pattern analysis and data science. The vulnerability is gauged as the relative amount of perturbation that an attacker needs to add to a dataset point in order to modify its proximity to a given query. The statistical distribution of the relative amount of perturbation is derived from simple assumptions, outlining the key factor that drives its typical values: The higher the intrinsic dimensionality, the more vulnerable is the nearest neighbors search. Experiments on six large-scale datasets validate this model up to some outliers, which are explained as violations of the assumptions. Teddy Furon |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Functional Invariants To Watermark Large TransformersabstractThe rapid growth of transformer-based models increases the concerns about their integrity and ownership insurance. Watermarking addresses this issue by embedding a unique identifier into the model, while preserving its performance. However, most existing approaches require to optimize the weights to imprint the watermark signal, which is not suitable at scale due to the computational cost. This paper explores watermarks with virtually no computational cost, applicable to a non-blind white-box setting (assuming access to both the original and watermarked networks). They generate functionally equivalent copies by leveraging the models’ invariance, via operations like dimension permutations or scaling/unscaling. This enables to watermark models without any change in their outputs and remains stealthy. Experiments demonstrate the effectiveness of the approach and its robustness against various model transformations (fine-tuning, quantization, pruning), making it a practical solution to protect the integrity of large models. Pierre Fernandez, Guillaume Couairon, Teddy Furon, Matthijs Douze |
ICASSP | 3 |
| 2024 | Proactive Detection of Voice Cloning with Localized WatermarkingabstractIn the rapidly evolving field of speech generative models, there is a pressing need to ensure audio authenticity against the risks of voice cloning. We present AudioSeal, the first audio watermarking technique designed specifically for localized detection of AI-generated speech. AudioSeal employs a generator / detector architecture trained jointly with a localization loss to enable localized watermark detection up to the sample level, and a novel perceptual loss inspired by auditory masking, that enables AudioSeal to achieve better imperceptibility. AudioSeal achieves state-of-the-art performance in terms of robustness to real life audio manipulations and imperceptibility based on automatic and human evaluation metrics. Additionally, AudioSeal is designed with a fast, single-pass detector, that significantly surpasses existing models in speed, achieving detection up to two orders of magnitude faster, making it ideal for large-scale and real-time applications.Code is available at https://github.com/facebookresearch/audioseal Robin San-Roman, Pierre Fernandez, Hady ElSahar, Alexandre Défossez, Teddy Furon |
ICML | 5 |
| 2024 | WaterMax: breaking the LLM watermark detectability-robustness-quality trade-offabstractWatermarking is a technical means to dissuade malfeasant usage of Large Language Models.
This paper proposes a novel watermarking scheme, so-called WaterMax, that enjoys high detectability while sustaining the quality of the generated text of the original LLM.
Its new design leaves the LLM untouched (no modification of the weights, logits or temperature).
WaterMax balances robustness and computational complexity contrary to the watermarking techniques of the literature inherently provoking a trade-off between quality and robustness.
Its performance is both theoretically proven and experimentally validated.
It outperforms all the SotA techniques under the most complete benchmark suite. Eva Giboulot, Teddy Furon |
NeurIPS | 2 |
| 2024 | Watermarking Makes Language Models RadioactiveabstractWe investigate the radioactivity of text generated by large language models (LLM), \ie whether it is possible to detect that such synthetic input was used to train a subsequent LLM.
Current methods like membership inference or active IP protection either work only in settings where the suspected text is known or do not provide reliable statistical guarantees.
We discover that, on the contrary, it is possible to reliably determine if a language model was trained on synthetic data if that data is output by a watermarked LLM.
Our new methods, specialized for radioactivity, detects with a provable confidence weak residuals of the watermark signal in the fine-tuned LLM.
We link the radioactivity contamination level to the following properties: the watermark robustness, its proportion in the training set, and the fine-tuning process.
For instance, if the suspect model is open-weight, we demonstrate that training on watermarked instructions can be detected with high confidence ($p$-value $< 10^{-5}$) even when as little as $5\%$ of training text is watermarked. Tom Sander, Pierre Fernandez, Alain Durmus, Matthijs Douze, Teddy Furon |
NeurIPS | 5 |
| 2024 | Fast Reliability Estimation for Neural Networks with Adversarial Attack-Driven Importance SamplingabstractThis paper introduces a novel approach to evaluate the reliability of Neural Networks (NNs) by integrating adversarial attacks with Importance Sampling (IS), enhancing the assessment’s precision and efficiency. Leveraging adversarial attacks to guide IS, our method efficiently identifies vulnerable input regions, offering a more directed alternative to traditional Monte Carlo methods. While comparing our approach with classical reliability techniques like FORM and SORM, and with classical rare event simulation methods such as Cross-Entropy IS, we acknowledge its reliance on the effectiveness of adversarial attacks and its inability to handle very high-dimensional data such as ImageNet. Despite these challenges, our comprehensive empirical validations on the datasets the MNIST and CIFAR10 demonstrate the method’s capability to accurately estimate NN reliability for a variety of models. Our research not only presents an innovative strategy for reliability assessment in NNs but also sets the stage for further work exploiting the connection between adversarial robustness and the field of statistical reliability engineering. Karim Tit, Teddy Furon |
UAI | 2 |
| 2024 | Strategic safeguarding: A game theoretic approach for analyzing attacker-defender behavior in DNN backdoorsabstractDeep neural networks (DNNs) are fundamental to modern applications like face recognition and autonomous driving. However, their security is a significant concern due to various integrity risks, such as backdoor attacks. In these attacks, compromised training data introduce malicious behaviors into the DNN, which can be exploited during inference or deployment. This paper presents a novel game-theoretic approach to model the interactions between an attacker and a defender in the context of a DNN backdoor attack. The contribution of this approach is multifaceted. First, it models the interaction between the attacker and the defender using a game-theoretic framework. Second, it designs a utility function that captures the objectives of both parties, integrating clean data accuracy and attack success rate. Third, it reduces the game model to a two-player zero-sum game, allowing for the identification of Nash equilibrium points through linear programming and a thorough analysis of equilibrium strategies. Additionally, the framework provides varying levels of flexibility regarding the control afforded to each player, thereby representing a range of real-world scenarios. Through extensive numerical simulations, the paper demonstrates the validity of the proposed framework and identifies insightful equilibrium points that guide both players in following their optimal strategies under different assumptions. The results indicate that fully using attack or defense capabilities is not always the optimal strategy for either party. Instead, attackers must balance inducing errors and minimizing the information conveyed to the defender, while defenders should focus on minimizing attack risks while preserving benign sample performance. These findings underscore the effectiveness and versatility of the proposed approach, showcasing optimal strategies across different game scenarios and highlighting its potential to enhance DNN security against backdoor attacks. Kassem Kallas, Quentin Le Roux, Wassim Hamidouche, Teddy Furon |
EURASIP J. Inf. Secur. | 4 |
| 2023 | Gradient-Informed Neural Network Statistical Robustness EstimationabstractDeep neural networks are robust against random corruptions of the inputs to some extent. This global sense of safety is not sufficient in critical applications where probabilities of failure must be assessed with accuracy. Some previous works applied known statistical methods from the field of rare event analysis to classification. Yet, they use classifiers as black-box models without taking into account gradient information, readily available for deep learning models via auto-differentiation. We propose a new and highly efficient estimator of probabilities of failure dedicated to neural networks as it leverages the fast computation of gradients of the model through back-propagation. Karim Tit, Teddy Furon, Mathias Rousset |
AISTATS | 2 |
| 2023 | Mixer: DNN Watermarking using Image MixupabstractIt is crucial to protect the intellectual property rights of DNN models prior to their deployment. The DNN should perform two main tasks: its primary task and watermarking task. This paper proposes a lightweight, reliable, and secure DNN watermarking that attempts to establish strong ties between these two tasks. The samples triggering the watermarking task are generated using image Mixup either from training or testing samples. This means that there is an infinity of triggers not limited to the samples used to embed the watermark in the model at training. The extensive experiments on image classification models for different datasets as well as exposing them to a variety of attacks, show that the proposed watermarking provides protection with an adequate level of security and robustness. Kassem Kallas, Teddy Furon |
ICASSP | 2 |
| 2023 | Model Fingerprinting with Benign InputsabstractRecent advances in the fingerprinting of deep neural networks are able to detect specific instances of models, placed in a black-box interaction scheme. Inputs used by the fingerprinting protocols are specifically crafted for each precise model to be checked for. While efficient in such a scenario, this nevertheless results in a lack of guarantee after a mere modification of a model (e.g. finetuning, quantization of the parameters).In this paper we propose fingerprinting scheme (coined FBI) that are resilient to significant modifications of the models. These modifications are viewed and modeled as variants. We demonstrate that benign inputs, that are unmodified images, are sufficient material for efficient fingerprinting. We leverage an information-theoretic approach to achieve a success rate of 95.2%. It is experimentally validated over an unprecedented set of more than 1,000 neural networks, while demonstrating performance improvements over a state-of-the-art fingerprinting method.1 Thibault Maho, Teddy Furon, Erwan Le Merrer |
ICASSP | 2 |
| 2023 | The Stable Signature: Rooting Watermarks in Latent Diffusion ModelsabstractGenerative image modeling enables a wide range of applications but raises ethical concerns about responsible deployment. We introduce an active content tracing method combining image watermarking and Latent Diffusion Models. The goal is for all generated images to conceal an invisible watermark allowing for future detection and/or identification. The method quickly fine-tunes the latent decoder of the image generator, conditioned on a binary signature. A pre-trained watermark extractor recovers the hidden signature from any generated image and a statistical test then determines whether it comes from the generative model. We evaluate the invisibility and robustness of the watermarks on a variety of generation tasks, showing that the Stable Signature is robust to image modifications. For instance, it detects the origin of an image generated from a text prompt, then cropped to keep 10% of the content, with 90+% accuracy at a false positive rate below 10−6. Pierre Fernandez, Guillaume Couairon, Hervé Jégou, Matthijs Douze, Teddy Furon |
ICCV | 5 |
| 2023 | How to choose your best allies for a transferable attack?abstractThe transferability of adversarial examples is a key issue in the security of deep neural networks. The possibility of an adversarial example crafted for a source model fooling another targeted model makes the threat of adversarial attacks more realistic. Measuring transferability is a crucial problem, but the Attack Success Rate alone does not provide a sound evaluation. This paper proposes a new methodology for evaluating transferability by putting distortion in a central position. This new tool shows that transferable attacks may perform far worse than a black box attack if the attacker randomly picks the source model. To address this issue, we propose a new selection mechanism, called FiT, which aims at choosing the best source model with only a few preliminary queries to the target. Our experimental results show that FiT is highly effective at selecting the best source model for multiple scenarios such as single-model attacks, ensemble-model attacks and multiple attacks. Thibault Maho, Seyed-Mohsen Moosavi-Dezfooli, Teddy Furon |
ICCV | 3 |
| 2023 | Active Image Indexing
Pierre Fernandez, Matthijs Douze, Hervé Jégou, Teddy Furon |
ICLR | 4 |
| 2023 | Fingerprinting Classifiers With Benign InputsabstractRecent advances in the fingerprinting of deep neural networks are able to detect specific instances of models, placed in a black-box interaction scheme. Inputs used by the fingerprinting protocols are specifically crafted for each precise model to be checked for. While efficient in such a scenario, this nevertheless results in a lack of guarantee after a mere modification of a model (e.g. finetuning, quantization of the parameters). This article generalizes fingerprinting to the notion of model families and their variants and extends the task-encompassing scenarios where one wants to fingerprint not only a precise model (previously referred to as a detection task) but also to identify which model or family is in the black-box (identification task). The main contribution is the proposal of fingerprinting schemes that are resilient to significant modifications of the models. We achieve these goals by demonstrating that benign inputs, that are unmodified images, are sufficient material for both tasks. We leverage an information-theoretic scheme for the identification task. We devise a greedy discrimination algorithm for the detection task. Both approaches are experimentally validated over an unprecedented set of more than 1,000 networks. Thibault Maho, Teddy Furon, Erwan Le Merrer |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Watermarking Images in Self-Supervised Latent SpacesabstractWe revisit watermarking techniques based on pre-trained deep networks, in the light of self-supervised approaches. We present a way to embed both marks and binary messages into their latent spaces, leveraging data augmentation at marking time. Our method can operate at any resolution and creates watermarks robust to a broad range of transformations (rotations, crops, JPEG, contrast, etc). It significantly outperforms the previous zero-bit methods, and its performance on multi-bit watermarking is on par with state-of-the-art encoder-decoder architectures trained end-to-end for watermarking. The code is available at github.com/facebookresearch/ssl_watermarking. Pierre Fernandez, Alexandre Sablayrolles, Teddy Furon, Hervé Jégou, Matthijs Douze |
ICASSP | 3 |
| 2022 | Randomized Smoothing Under Attack: How Good is it in Practice?abstractRandomized smoothing is a recent and celebrated solution to certify the robustness of any classifier. While it indeed provides a theoretical robustness against adversarial attacks, the dimensionality of current classifiers necessarily imposes Monte Carlo approaches for its application in practice.This paper questions the effectiveness of randomized smoothing as a defense, against state of the art black-box attacks. This is a novel perspective, as previous research works considered the certification as an unquestionable guarantee. We first formally highlight the mismatch between a theoretical certification and the practice of attacks on classifiers. We then perform attacks on randomized smoothing as a defense. Our main observation is that there is a major mismatch in the settings of the RS for obtaining high certified robustness or when defeating black box attacks while preserving the classifier accuracy. Thibault Maho, Teddy Furon, Erwan Le Merrer |
ICASSP | 2 |
| 2022 | Impact of Downscaling on Adversarial ImagesabstractMost works on adversarial attacks consider that small images whose size already fits the model but downscaling is a necessary first step to adapt the size of the image to the model, and it can reform the adversarial signal. This paper explores attacking large images on classifiers with different input sizes and compares theoretical results with practical ones. The possibility of forging adversarial images using different interpolation methods and different deep learning structures are investigated. The distortion of the adversarial signal and the transferability over other downscaling methods are also studied. An ensemble model gathering different resizing interpolations is also proposed to increase the transferability of the attack against a set of downscaling kernels. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
ICIP | 2 |
| 2022 | Generating Adversarial Images in Quantized DomainsabstractMany adversarial attacks produce floating-point tensors which are no longer adversarial when converted to raster or JPEG images due to rounding. This paper proposes a method dedicated to quantize adversarial perturbations. This “smart” quantization is conveniently implemented as versatile post-processing. It can be used on top of any white-box attack targeting any model. Its principle is tantamount to a constrained optimization problem aiming to minimize the quantization error while keeping the image adversarial after quantization. A Lagrangian formulation is proposed and an appropriate search of the Lagrangian multiplier enables to increase the success rate. We also add a control mechanism of the$\ell _\infty $-distortion. Our method operates in both spatial and JPEG domains with little complexity. This study shows that forging adversarialimagesis not a hard constraint: our quantization does not introduce any extra distortion. Moreover, adversarial images quantized as JPEG also challenge defenses relying on the robustness of neural networks against JPEG compression. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | SurFree: A Fast Surrogate-Free Black-Box AttackabstractMachine learning classifiers are critically prone to evasion attacks. Adversarial examples are slightly modified inputs that are then misclassified, while remaining perceptively close to their originals. Last couple of years have witnessed a striking decrease in the amount of queries a black box attack submits to the target classifier, in order to forge adversarials. This particularly concerns the black box score-based setup, where the attacker has access to top predicted probabilites: the amount of queries went from to millions of to less than a thousand.This paper presents SurFree, a geometrical approach that achieves a drastic reduction in the amount of queries in the hardest setup: black box decision-based attacks (only the top-1 label is available). We first highlight that the most recent attacks in that setup, HSJA [3], QEBA [14] and GeoDA [23] all perform costly gradient surrogate estimations. SurFree proposes to bypass these, by instead focusing on careful trials along diverse directions, guided by precise indications of geometrical properties of the classifier decision boundaries. We motivate this geometric approach before performing a head-to-head comparison with previous attacks with the amount of queries as a first class citizen. We exhibit a faster distortion decay under low query amounts (few hundreds to a thousand), while remaining competitive at higher query budgets.1 Thibault Maho, Teddy Furon, Erwan Le Merrer |
CVPR | 2 |
| 2021 | RoBIC: A Benchmark Suite For Assessing Classifiers RobustnessabstractMany defenses have emerged with the development of adversarial attacks. Models must be objectively evaluated accordingly. This paper systematically tackles this concern by proposing a new parameter-free benchmark we coin ROBIC. ROBIC fairly evaluates the robustness of image classifiers using a new half-distortion measure. It gauges the robustness of the network against white and black box attacks, independently of its accuracy. ROBIC is faster than the other available benchmarks. We present the significant differences in the robustness of 16 recent models as assessed by ROBIC.We make this benchmark publicly available for use and contribution at https://gitlab.inria.fr/t;maho/robustness_benchmark. Thibault Maho, Benoît Bonnet 0001, Teddy Furon, Erwan Le Merrer |
ICIP | 3 |
| 2021 | Trustworthy AI'21: 1st International Workshop on Trustworthy AI for Multimedia ComputingabstractIn this workshop, we are addressing the trustworthy AI issues for Multimedia Computing. We aim to bring together researchers in the trustworthy aspects of Multimedia Computing and facilitate discussions in injecting trusts into multimedia to develop trustworthy AI techniques that are reliable and acceptable to multimedia researchers and practitioners. Our scope is at the conjunction of multimedia, computer vision and trustworthy AI, including Explainability, Robustness and Safety, Data Privacy, Accountability and Transparency, and Fairness. Teddy Furon, Jingen Liu, Yogesh S. Rawat, Wei Zhang 0031, Qi Zhao 0001 |
ACM Multimedia | 1 |
| 2021 | Efficient Statistical Assessment of Neural Network Corruption RobustnessabstractWe quantify the robustness of a trained network to input uncertainties with a stochastic simulation inspired by the field of Statistical Reliability Engineering. The robustness assessment is cast as a statistical hypothesis test: the network is deemed as locally robust if the estimated probability of failure is lower than a critical level.The procedure is based on an Importance Splitting simulation generating samples of rare events. We derive theoretical guarantees that are non-asymptotic w.r.t. sample size. Experiments tackling large scale networks outline the efficiency of our method making a low number of calls to the network function. Karim Tit, Teddy Furon, Mathias Rousset |
NeurIPS | 2 |
| 2021 | High Intrinsic Dimensionality Facilitates Adversarial Attack: Theoretical EvidenceabstractMachine learning systems are vulnerable to adversarial attack. By applying to the input object a small, carefully-designed perturbation, a classifier can be tricked into making an incorrect prediction. This phenomenon has drawn wide interest, with many attempts made to explain it. However, a complete understanding is yet to emerge. In this paper we adopt a slightly different perspective, still relevant to classification. We consider retrieval, where the output is a set of objects most similar to a user-supplied query object, corresponding to the set of k-nearest neighbors. We investigate the effect of adversarial perturbation on the ranking of objects with respect to a query. Through theoretical analysis, supported by experiments, we demonstrate that as the intrinsic dimensionality of the data domain rises, the amount of perturbation required to subvert neighborhood rankings diminishes, and the vulnerability to adversarial attack rises. We examine two modes of perturbation of the query: either `closer' to the target point, or `farther' from it. We also consider two perspectives: `query-centric', examining the effect of perturbation on the query's own neighborhood ranking, and `target-centric', considering the ranking of the query point in the target's neighborhood set. All four cases correspond to practical scenarios involving classification and retrieval. Laurent Amsaleg, James Bailey 0001, Amélie Barbe, Sarah M. Erfani, Teddy Furon, Michael E. Houle, Milos Radovanovic 0001, Xuan Vinh Nguyen |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Walking on the Edge: Fast, Low-Distortion Adversarial ExamplesabstractAdversarial examples of deep neural networks are receiving ever increasing attention because they help in understanding and reducing the sensitivity to their input. This is natural given the increasing applications of deep neural networks in our everyday lives. When white-box attacks are almost always successful, it is typically only the distortion of the perturbations that matters in their evaluation. In this work, we argue that speed is important as well, especially when considering that fast attacks are required by adversarial training. Given more time, iterative methods can always find better solutions. We investigate this speed-distortion trade-off in some depth and introduce a new attack called boundary projection (BP) that improves upon existing methods by a large margin. Our key idea is that the classification boundary is a manifold in the image space: we therefore quickly reach the boundary and then optimize distortion on this manifold. Hanwei Zhang 0001, Yannis Avrithis, Teddy Furon, Laurent Amsaleg |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Joint Learning of Assignment and Representation for Biometric Group MembershipabstractThis paper proposes a framework for group membership protocols preventing the curious but honest server from reconstructing the enrolled biometric signatures and inferring the identity of querying clients. This framework learns the embedding parameters, group representations and assignments simultaneously. Experiments show the trade-off between security/privacy and verification/identification performances. Marzieh Gheisari, Teddy Furon, Laurent Amsaleg |
ICASSP | 2 |
| 2020 | What if Adversarial Samples were Digital Images?abstractAlthough adversarial sampling is a trendy topic in computer vision, very few works consider the integral constraint: The result of the attack is a digital image whose pixel values are integers. This is not an issue at first sight since applying a rounding after forging an adversarial sample trivially does the job. Yet, this paper shows theoretically and experimentally that this operation has a big impact. The adversarial perturbations are fragile signals whose quantization destroys its ability to delude an image classifier. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
IH&MMSec | 2 |
| 2020 | Defending Adversarial Examples via DNN Bottleneck ReinforcementabstractThis paper presents a DNN bottleneck reinforcement scheme to alleviate the vulnerability of Deep Neural Networks (DNN) against adversarial attacks. Typical DNN classifiers encode the input image into a compressed latent representation more suitable for inference.This information bottleneck makes a trade-off between the image-specific structure and class-specific information in an image. By reinforcing the former while maintaining the latter, any redundant information, be it adversarial or not, should be removed from the latent representation. Hence, this paper proposes to jointly train an auto-encoder (AE) sharing the same encoding weights with the visual classifier. In order to reinforce the information bottleneck,we introduce the multi-scale low-pass objective and multi-scale high-frequency communication for better frequency steering in the network. Unlike existing approaches, our scheme is the first reforming defense per se which keeps the classifier structure untouched without appending any pre-processing head and is trained with clean images only. Extensive experiments on MNIST, CIFAR-10 and ImageNet demonstrate the strong defense of our method againstvarious adversarial attacks. Wenqing Liu, Miaojing Shi, Teddy Furon, Li Li 0008 |
ACM Multimedia | 3 |
| 2020 | Smooth adversarial examplesabstractAbstract This paper investigates the visual quality of the adversarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artifacts. In this work, smoothing has a different meaning as it perceptually shapes the perturbation according to the visual content of the image to be attacked. The perturbation becomes locally smooth on the flat areas of the input image, but it may be noisy on its textured areas and sharp across its edges.This operation relies on Laplacian smoothing, well-known in graph signal processing, which we integrate in the attack pipeline. We benchmark several attacks with and without smoothing under a white box scenario and evaluate their transferability. Despite the additional constraint of smoothness, our attack has the same probability of success at lower distortion. Hanwei Zhang 0001, Yannis Avrithis, Teddy Furon, Laurent Amsaleg |
EURASIP J. Inf. Secur. | 3 |
| 2019 | Aggregation and Embedding for Group Membership VerificationabstractThis paper proposes a group membership verification protocol preventing the curious but honest server from reconstructing the enrolled signatures and inferring the identity of querying clients. The protocol quantizes the signatures into discrete embeddings, making reconstruction difficult. It also aggregates multiple embeddings into representative values, impeding identification. Theoretical and experimental results show the trade-off between the security and the error rates. Marzieh Gheisari, Teddy Furon, Laurent Amsaleg, Behrooz Razeghi, Sviatoslav Voloshynovskiy |
ICASSP | 2 |
| 2019 | Watermarking Error Exponents in the Presence of Noise: The Case of the Dual Hypercone DetectorabstractThe study of the error exponents of zero-bit watermarking is addressed in the article by Comesana, Merhav, and Barni, under the assumption that the detector relies solely on second order joint empirical statistics of the received signal and the watermark. This restriction leads to the well-known dual hypercone detector, whose score function is the absolute value of the normalized correlation. They derive the false negative error exponent and the optimum embedding rule. However, they only focus on high SNR regime, i.e. the noiseless scenario. Teddy Furon |
IH&MMSec | 1 |
| 2018 | Hybrid Diffusion: Spectral-Temporal Graph Filtering for Manifold Ranking
Ahmet Iscen, Yannis Avrithis, Giorgos Tolias, Teddy Furon, Ondrej Chum |
ACCV (2) | 4 |
| 2018 | Fast Spectral Ranking for Similarity SearchabstractDespite the success of deep learning on representing images for particular object retrieval, recent studies show that the learned representations still lie on manifolds in a high dimensional space. This makes the Euclidean nearest neighbor search biased for this task. Exploring the manifolds online remains expensive even if a nearest neighbor graph has been computed offline. This work introduces an explicit embedding reducing manifold search to Euclidean search followed by dot product similarity search. This is equivalent to linear graph filtering of a sparse signal in the frequency domain. To speed up online search, we compute an approximate Fourier basis of the graph offline. We improve the state of art on particular object retrieval datasets including the challenging Instre dataset containing small objects. At a scale of 105 images, the offline cost is only a few hours, while query time is comparable to standard similarity search. Ahmet Iscen, Yannis Avrithis, Giorgos Tolias, Teddy Furon, Ondrej Chum |
CVPR | 4 |
| 2018 | Extreme-value-theoretic estimation of local intrinsic dimensionality
Laurent Amsaleg, Oussama Chelly, Teddy Furon, Stéphane Girard, Michael E. Houle, Ken-ichi Kawarabayashi, Michael Nett |
Data Min. Knowl. Discov. | 3 |
| 2018 | Memory Vectors for Similarity Search in High-Dimensional SpacesabstractWe study an indexing architecture to store and search in a database of high-dimensional vectors from the perspective of statistical signal processing and decision theory. This architecture is composed of several memory units, each of which summarizes a fraction of the database by a single representative vector. The potential similarity of the query to one of the vectors stored in the memory unit is gauged by a simple correlation with the memory unit's representative vector. This representative optimizes the test of the following hypothesis: the query is independent from any vector in the memory unit versus the query is a simple perturbation of one of the stored vectors. Compared to exhaustive search, our approach finds the most similar database vectors significantly faster without a noticeable reduction in search quality. Interestingly, the reduction of complexity is provably better in high-dimensional spaces. We empirically demonstrate its practical interest in a large-scale image search scenario with off-the-shelf state-of-the-art descriptors. Ahmet Iscen, Teddy Furon, Vincent Gripon, Michael G. Rabbat, Hervé Jégou |
IEEE Trans. Big Data | 2 |
| 2017 | Efficient Diffusion on Region Manifolds: Recovering Small Objects with Compact CNN RepresentationsabstractQuery expansion is a popular method to improve the quality of image retrieval with both conventional and CNN representations. It has been so far limited to global image similarity. This work focuses on diffusion, a mechanism that captures the image manifold in the feature space. An efficient off-line stage allows optional reduction in the number of stored regions. In the on-line stage, the proposed handling of unseen queries in the indexing stage removes additional computation to adjust the precomputed data. We perform diffusion through a sparse linear system solver, yielding practical query times well below one second. Experimentally, we observe a significant boost in performance of image retrieval with compact CNN descriptors on standard benchmarks, especially when the query object covers only a small part of the image. Small objects have been a common failure case of CNN-based retrieval. Ahmet Iscen, Giorgos Tolias, Yannis Avrithis, Teddy Furon, Ondrej Chum |
CVPR | 4 |
| 2017 | About zero bitwatermarking error exponentsabstractThis paper aims to motivate more research works on the design of zero-bit watermarking schemes by showing an upper bound of the performances that known solutions failed to reach. To this end, an upper bound of error exponent characteristic is derived by translating Costa's rationale to zerobit watermarking with side information. Three schemes are then considered: the dual-cone detection region originally proposed by Cox et al. and improved in Merhav et al. papers, ISS (Improved Spread Spectrum), and ZATT (Zero Attraction). It turns out that in certain conditions the latter performs better than the first one, which questions the optimality claimed Merhav et al. Nevertheless, the main conclusion is that these schemes are in general far away from the upper bound in the region of practical interest. Teddy Furon |
ICASSP | 1 |
| 2017 | Complex Document Classification and Localization Application on Identity Document ImagesabstractThis paper studies the problem of document image classification. More specifically, we address the classification of documents composed of few textual information and complex background (such as identity documents). Unlike most existing systems, the proposed approach simultaneously locates the document and recognizes its class. The latter is defined by the document nature (passport, ID, etc.), emission country, version, and the visible side (main or back). This task is very challenging due to unconstrained capturing conditions, sparse textual information, and varying components that are irrelevant to the classification, e.g. photo, names, address, etc. First, a base of document models is created from reference images. We show that training images are not necessary and only one reference image is enough to create a document model. Then, the query image is matched against all models in the base. Unknown documents are rejected using an estimated quality based on the extracted document. The matching process is optimized to guarantee an execution time independent from the number of document models. Once the document model is found, a more accurate matching is performed to locate the document and facilitate information extraction. Our system is evaluated on several datasets with up to 3042 real documents (representing 64 classes) achieving an accuracy of 96.6%. Ahmad Montaser Awal, Nabil Ghanmi, Ronan Sicre, Teddy Furon |
ICDAR | 4 |
| 2017 | Panorama to Panorama Matching for Location RecognitionabstractInternational audience Ahmet Iscen, Giorgos Tolias, Yannis Avrithis, Teddy Furon, Ondrej Chum |
ICMR | 4 |
| 2016 | Efficient Large-Scale Similarity Search Using Matrix FactorizationabstractWe consider the image retrieval problem of finding the images in a dataset that are most similar to a query image. Our goal is to reduce the number of vector operations and memory for performing a search without sacrificing accuracy of the returned images. We adopt a group testing formulation and design the decoding architecture using either dictionary learning or eigendecomposition. The latter is a plausible option for small-to-medium sized problems with high-dimensional global image descriptors, whereas dictionary learning is applicable in large-scale scenarios. We evaluate our approach for global descriptors obtained from both SIFT and CNN features. Experiments with standard image search benchmarks, including the Yahoo100M dataset comprising 100 million images, show that our method gives comparable (and sometimes superior) accuracy compared to exhaustive search while requiring only 10% of the vector operations and memory. Moreover, for the same search complexity, our method gives significantly better accuracy compared to approaches based on dimensionality reduction or locality sensitive hashing. Ahmet Iscen, Michael G. Rabbat, Teddy Furon |
CVPR | 3 |
| 2016 | Sketching Techniques for Very Large Matrix Factorization
Raghavendran Balu, Teddy Furon, Laurent Amsaleg |
ECIR | 2 |
| 2016 | Differentially Private Matrix Factorization using Sketching TechniquesabstractCollaborative filtering is a popular technique for recommendation system due to its domain independence and reliance on user behavior data alone. But the possibility of identification of users based on these personal data raise privacy concerns. Differential privacy aims to minimize these identification risks by adding controlled noise with known characteristics. The addition of noise impacts the utility of the system and does not add any other value to the system other than enhanced privacy. We propose using sketching techniques to implicitly provide the differential privacy guarantees by taking advantage of the inherent randomness of the data structure. In particular, we use count sketch as a storage model for matrix factorization, one of the successful collaborative filtering techniques. Our model is also compact and scales well with data, making it well suitable for large scale applications. Raghavendran Balu, Teddy Furon |
IH&MMSec | 2 |
| 2016 | Group Testing for Identification with PrivacyabstractThis paper describes an approach where group testing helps in enforcing security and privacy in identification. We detail a particular scheme based on embedding and group testing. We add a second layer of defense, group vectors, where each group vector represents a set of dataset vectors. Whereas the selected embedding poorly protects the data when used alone, the group testing approach makes it much harder to reconstruct the data when combined with the embedding. Even when curious server and user collude to disclose the secret parameters, they cannot accurately recover the data. Another byproduct of our approach is that it reduces the complexity of the search and the required storage space. We show the interest of our work in a benchmark biometrics dataset, where we verify our theoretical analysis with real data. Ahmet Iscen, Teddy Furon |
IH&MMSec | 2 |
| 2016 | Scaling Group Testing Similarity SearchabstractThe large dimensionality of modern image feature vectors, up to thousands of dimensions, is challenging the high dimensional indexing techniques. Traditional approaches fail at returning good quality results within a response time that is usable in practice. However, similarity search techniques inspired by the group testing framework have recently been proposed in an attempt to specifically defeat the curse of dimensionality. Yet, group testing does not scale and fails at indexing very large collections of images because its internal procedures analyze an excessively large fraction of the indexed data collection. This paper identifies these difficulties and proposes extensions to the group testing framework for similarity searches that allow to handle larger collections of feature vectors. We demonstrate that it can return high quality results much faster compared to state-of-the-art group testing strategies when indexing truly high-dimensional features that are indeed hardly indexable with traditional indexing approaches. Ahmet Iscen, Laurent Amsaleg, Teddy Furon |
ICMR | 3 |
| 2016 | Privacy-Preserving Outsourced Media SearchabstractThis work proposes a privacy-protection framework for an important application called outsourced media search. This scenario involves a data owner, a client, and an untrusted server, where the owner outsources a search service to the server. Due to lack of trust, the privacy of the client and the owner should be protected. The framework relies on multimedia hashing and symmetric encryption. It requires involved parties to participate in a privacy-enhancing protocol. Additional processing steps are carried out by the owner and the client: (i) before outsourcing low-level media features to the server, the owner has to one-way hash them, and partially encrypt each hash-value; (ii) the client completes the similarity search by re-ranking the most similar candidates received from the server. One-way hashing and encryption add ambiguity to data and make it difficult for the server to infer contents from database items and queries, so the privacy of both the owner and the client is enforced. The proposed framework realizes trade-offs among strength of privacy enforcement, quality of search, and complexity, because the information loss can be tuned during hashing and encryption. Extensive experiments demonstrate the effectiveness and the flexibility of the framework. Li Weng, Laurent Amsaleg, Teddy Furon |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2015 | Estimating Local Intrinsic DimensionalityabstractThis paper is concerned with the estimation of a local measure of intrinsic dimensionality (ID) recently proposed by Houle. The local model can be regarded as an extension of Karger and Ruhl's expansion dimension to a statistical setting in which the distribution of distances to a query point is modeled in terms of a continuous random variable. This form of intrinsic dimensionality can be particularly useful in search, classification, outlier detection, and other contexts in machine learning, databases, and data mining, as it has been shown to be equivalent to a measure of the discriminative power of similarity functions. Several estimators of local ID are proposed and analyzed based on extreme value theory, using maximum likelihood estimation (MLE), the method of moments (MoM), probability weighted moments (PWM), and regularly varying functions (RV). An experimental evaluation is also provided, using both real and artificial data. Laurent Amsaleg, Oussama Chelly, Teddy Furon, Stéphane Girard, Michael E. Houle, Ken-ichi Kawarabayashi, Michael Nett |
KDD | 3 |
| 2015 | Rotation and translation covariant match kernels for image retrieval
Giorgos Tolias, Andrei Bursuc, Teddy Furon, Hervé Jégou |
Comput. Vis. Image Underst. | 3 |
| 2014 | Orientation Covariant Aggregation of Local Descriptors with Embeddings
Giorgos Tolias, Teddy Furon, Hervé Jégou |
ECCV (6) | 2 |
| 2014 | Challenging Differential Privacy: The Case of Non-interactive Mechanisms
Raghavendran Balu, Teddy Furon, Sébastien Gambs |
ESORICS (2) | 2 |
| 2014 | Beyond "project and sign" for cosine estimation with binary codesabstractMany nearest neighbor search algorithms rely on encoding real vectors into binary vectors. The most common strategy projects the vectors onto random directions and takes the sign to produce so-called sketches. This paper discusses the sub-optimality of this choice, and proposes a better encoding strategy based on the quantization and reconstruction points of view. Our second contribution is a novel asymmetric estimator for the cosine similarity. Similar to previous asymmetric schemes, the query is not quantized and the similarity is computed in the compressed domain. Both our contribution leads to improve the quality of nearest neighbor search with binary codes. Its efficiency compares favorably against a recent encoding technique. Raghavendran Balu, Teddy Furon, Hervé Jégou |
ICASSP | 2 |
| 2014 | Instance classification with prototype selectionabstractWe address the problem of instance classification: our goal is to annotate images with tags corresponding to objects classes which exhibit small intra-class variations such as logos, products or landmarks. We propose a novel algorithm for the selection of class-specific prototypes which are used in a voting-based classification scheme. We show significant improvements over two state-of-the-art methods, namely the Fisher vector and Hamming Embedding, on two challenging methods of logos and vehicles. Josip Krapac, Florent Perronnin, Teddy Furon, Hervé Jégou |
ICMR | 3 |
| 2014 | A Group Testing Framework for Similarity Search in High-dimensional SpacesabstractThis paper introduces a group testing framework for detecting large similarities between high-dimensional vectors, such as descriptors used in state-of-the-art description of multimedia documents.At the crossroad of multimedia information retrieval and signal processing, we produce a set of group representations that jointly encode several vectors into a single one, in the spirit of group testing approaches. By comparing a query vector to several of these intermediate representations, we screen the large values taken by the similarities between the query and all the vectors, at a fraction of the cost of exhaustive similarity calculation. Unlike concurrent indexing methods that suffer from the curse of dimensionality, our method exploits the properties of high-dimensional spaces. It therefore complements other strategies for approximate nearest neighbor search. Our preliminary experiments demonstrate the potential of group testing for searching large databases of multimedia objects represented by vectors. We obtain a large improvement in terms of the theoretical complexity, at the cost of a small or negligible decrease of accuracy.We hope that this preliminary work will pave the way to subsequent works for multimedia retrieval with limited resources. Miaojing Shi, Teddy Furon, Hervé Jégou |
ACM Multimedia | 2 |
| 2013 | Secure and efficient approximate nearest neighbors searchabstractThis paper presents a moderately secure but very efficient approximate nearest neighbors search. After detailing the threats pertaining to the `honest but curious' model, our approach starts from a state-of-the-art algorithm in the domain of approximate nearest neighbors search. We gradually develop mechanisms partially blocking the attacks threatening the original algorithm. Benjamin Mathon, Teddy Furon, Laurent Amsaleg, Julien Bringer |
IH&MMSec | 2 |
| 2013 | A New Measure of Watermarking Security: The Effective Key LengthabstractWhereas the embedding distortion, the payload, and the robustness of digital watermarking schemes are well understood, the notion of security is still not completely well defined. The approach proposed in the last five years is too theoretical and solely considers the embedding process, which is half of the watermarking scheme. This paper proposes a new measure of watermarking security, called the effective key length, which captures the difficulty for the adversary to get access to the watermarking channel. This new methodology is applied here to additive spread spectrum schemes where theoretical and practical computations of the effective key length are proposed. Experimental protocols using either Monte Carlo simulations, region approximation, or rare event probability estimator allow good evaluation of this quantity. For improved spread spectrum (ISS), our analysis exhibits setups where 1) the robustness and the security of the scheme are superior to spread spectrum and 2) estimating the secret keys from the observations only is not the best way to break the scheme. Moreover, a comparison with correlation aware spread spectrum (CASS) shows that ISS offers a better security than CASS for a given robustness. Patrick Bas, Teddy Furon |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | Practical key length of watermarking systemsabstractThe paper proposes a new approach for evaluating the security levels of digital watermarking schemes, which is more in line with the formulation proposed in cryptography. We first exhibit the class of equivalent decoding keys. These are the keys allowing a reliable decoding of contents watermarked with the secret key. Then, we evaluate the probability that the adversary picks an equivalent key. The smaller this probability, the higher the key length. This concept is illustrated on two main families of watermarking schemes: DC-QIM (Distortion Compensation Quantization Index Modulation) and SS (Spread Spectrum). The trade-off robustness-security is again verified and gives some counter-intuitive results: For instance, the security of SS is a decreasing function of the length of the secret vector at a fixed Document to Watermark power ratio. Additionally, under the Known Message Attack, the practical key length of the watermarking scheme rapidly decreases to 0 bits per symbol. Patrick Bas, Teddy Furon, François Cayre |
ICASSP | 2 |
| 2012 | Enlarging hacker's toolbox: Deluding image recognition by attacking keypoint orientationsabstractContent-Based Image Retrieval Systems (CBIRS) used in forensics related contexts require very good image recognition capabilities. Whereas the robustness criterion has been extensively covered by Computer Vision or Multimedia literature, none of these communities explored the security of CBIRS. Recently, preliminary studies have shown real systems can be deluded by applying transformations to images that are very specific to the SIFT local description scheme commonly used for recognition. The work presented in this paper adds one strategy for attacking images, and somehow enlarges the box of tools hackers can use for deluding systems. This paper shows how the orientation of keypoints can be tweaked, which in turn lowers matches since this deeply changes the final SIFT feature vectors. The method learns what visual patch should be applied to change the orientation of keypoints thanks to an SVM-based process. Experiments with a database made of 100,000 real world images confirms the effectiveness of this keypoint-orientation attacking scheme. Thanh-Toan Do, Ewa Kijak, Laurent Amsaleg, Teddy Furon |
ICASSP | 4 |
| 2012 | Anti-sparse coding for approximate nearest neighbor searchabstractThis paper proposes a binarization scheme for vectors of high dimension based on the recent concept of anti-sparse coding, and shows its excellent performance for approximate nearest neighbor search. Unlike other binarization schemes, this framework allows, up to a scaling factor, the explicit reconstruction from the binary representation of the original vector. The paper also shows that random projections which are used in Locality Sensitive Hashing algorithms, are significantly outperformed by regular frames for both synthetic and real data if the number of bits exceeds the vector dimensionality, i.e., when high precision is required. Hervé Jégou, Teddy Furon, Jean-Jacques Fuchs |
ICASSP | 2 |
| 2012 | Security-oriented picture-in-picture visual modificationsabstractThe performance of Content-Based Image Retrieval Systems (CBIRS) is typically evaluated via benchmarking their capacity to match images despite various generic distortions such as crops, rescalings or Picture in Picture (PiP) attacks, which are the most challenging. Distortions are made in a very generic manner, by applying a set of transformations that are completely independent from the systems later performing recognition tasks. Recently, studies have shown that exploiting the finest details of the various techniques used in a CBIRS offers the opportunity to create distortions that dramatically reduce the recognition performance. Such a security perspective is taken in this paper. Instead of creating generic PiP distortions, it proposes a creation scheme able to delude the recognition capabilities of a CBIRS that is representative of state of the art techniques as it relies on SIFT, high-dimensional k-nearest neighbors searches and geometrical robustification steps. Experiments using 100,000 real-world images confirm the effectiveness of these security-oriented PiP visual modifications. Thanh-Toan Do, Ewa Kijak, Laurent Amsaleg, Teddy Furon |
ICMR | 4 |
| 2012 | Toward Practical Joint Decoding of Binary Tardos Fingerprinting CodesabstractThe class of joint decoder in fingerprinting codes is of utmost importance in theoretical papers to establish the concept of fingerprint capacity. However, no implementation supporting a large user base is known to date. This paper presents an iterative decoder which is the first attempt toward practical large-scale joint decoding. The discriminative feature of the scores benefits on one hand from the side-information of previously found users, and on the other hand, from recently introduced universal linear decoders for compound channels. Neither the code construction nor the decoder makes assumptions about the collusion size and strategy, provided it is a memoryless and fair attack. The extension to incorporate soft outputs from the watermarking layer is straightforward. An extensive experimental work benchmarks the very good performance and offers a clear comparison with previous state-of-the-art decoders. Peter Meerwald-Stadler, Teddy Furon |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | Group testing meets traitor tracingabstractThis paper links two a priori different topics, group testing and traitor tracing. Group testing, as an instantiation of a compressed sensing problem over binary data, is indeed easier than traitor tracing because the mixing model is far simpler. State-of-the-art algorithms for traitor tracing, including the celebrated probabilistic Tardos code, are applied to the group testing problem. They yield better than or competitive performance when compared to state-of-the-art algorithms. Peter Meerwald-Stadler, Teddy Furon |
ICASSP | 2 |
| 2011 | Iterative single tardos decoder with controlled probability of false positiveabstractWe propose a blind iterative single Tardos decoder for traitor tracing designed to catch as many colluders as possible while controlling the probability of accusing an innocent. The key idea is that users accused in the previous iterations are used as side-information to build a more discriminative test. A fast implementation supporting millions of users is presented and compared with two recent fingerprinting codes. Peter Meerwald-Stadler, Teddy Furon |
ICME | 2 |
| 2010 | Understanding the security and robustness of SIFTabstractMany content-based retrieval systems (CBIRS) describe images using the SIFT local features because of their very robust recognition capabilities. While SIFT features proved to cope with a wide spectrum of general purpose image distortions, its security has not fully been assessed yet. In one of their scenario, Hsu et al. in [2] show that very specific anti-SIFT attacks can jeopardize the keypoint detection. These attacks can delude systems using SIFT targeting application such as image authentication and (pirated) copy detection. Thanh-Toan Do, Ewa Kijak, Teddy Furon, Laurent Amsaleg |
ACM Multimedia | 3 |
| 2010 | Challenging the security of Content-Based Image Retrieval systemsabstractContent-Based Image Retrieval (CBIR) has been recently used as a filtering mechanism against the piracy of multimedia contents. Many publications in the last few years have proposed very robust schemes where pirated contents are detected despite severe modifications. As none of these systems have addressed the piracy problem from a security perspective, it is time to check whether they are secure: Can pirates mount violent attacks against CBIR systems by carefully studying the technology they use? This paper is an initial analysis of the security flaws of the typical technology blocks used in state-of-the-art CBIR systems. It is so far too early to draw any definitive conclusion about their inherent security, but it motivates and encourages further studies on this topic. Thanh-Toan Do, Ewa Kijak, Teddy Furon, Laurent Amsaleg |
MMSP | 3 |
| 2008 | Experimental Assessment of the Reliability for Watermarking and Fingerprinting SchemesabstractInternational audience Frédéric Cérou, Teddy Furon, Arnaud Guyader |
EURASIP J. Inf. Secur. | 2 |
| 2008 | Broken ArrowsabstractInternational audience Teddy Furon, Patrick Bas |
EURASIP J. Inf. Secur. | 1 |
| 2007 | A Constructive and Unifying Framework for Zero-Bit WatermarkingabstractIn the watermark detection scenario, also known as zero-bit watermarking, a watermark, carrying no hidden message, is inserted in a piece of content. The watermark detector checks for the presence of this particular weak signal in received contents. The article looks at this problem from a classical detection theory point of view, but with side information enabled at the embedding side. This means that the watermark signal is a function of the host content. Our study is twofold. The first step is to design the best embedding function for a given detection function, and the best detection function for a given embedding function. This yields two conditions, which are mixed into one 'fundamental' partial differential equation. It appears that many famous watermarking schemes are indeed solution to this 'fundamental' equation. This study thus gives birth to a constructive framework unifying solutions, so far perceived as very different Teddy Furon |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | Watermarking Is Not Cryptography
Ingemar J. Cox, Gwenaël J. Doërr, Teddy Furon |
IWDW | 3 |
| 2006 | Security of Lattice-Based Data Hiding Against the Known Message AttackabstractSecurity of quantization index modulation (QIM) watermarking methods is usually sought through a pseudorandom dither signal which randomizes the codebook. This dither plays the role of the secret key (i.e., a parameter only shared by the watermarking embedder and decoder), which prevents unauthorized embedding and/or decoding. However, if the same dither signal is reused, the observation of several watermarked signals can provide sufficient information for an attacker to estimate the dither signal. This paper focuses on the cases when the embedded messages are either known or constant. In the first part of this paper, a theoretical security analysis of QIM data hiding measures the information leakage about the secret dither as the mutual information between the dither and the watermarked signals. In the second part, we show how set-membership estimation techniques successfully provide accurate estimates of the dither from observed watermarked signals. The conclusion of this twofold study is that current QIM watermarking schemes have a relative low security level against this scenario because a small number of observed watermarked signals yields a sufficiently accurate estimate of the secret dither. The analysis presented in this paper also serves as the basis for more involved scenarios Luis Pérez-Freire, Fernando Pérez-González, Teddy Furon, Pedro Comesaña Alfaro |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2005 | A theoretical study of watermarking securityabstractThis article proposes a theory of watermarking security based on a cryptanalysis point of view. The main idea is that information about the secret key leaks from the observations, for instance watermarked pieces of content, available to the opponent. Tools from information theory (Shannon's mutual information and Fisher's information matrix) can measure this leakage of information. The security level is then defined as the number of observations the attacker needs to successfully estimate the secret key. This theory is applied to two common watermarking methods: the substitutive scheme and the spread spectrum based techniques. Their security levels are calculated against three kinds of attack François Cayre, Caroline Fontaine, Teddy Furon |
ISIT | 3 |
| 2005 | A Survey of Watermarking Security
Teddy Furon |
IWDW | 1 |
| 2004 | Watermarking Attack: Security of WSS Techniques
François Cayre, Caroline Fontaine, Teddy Furon |
IWDW | 3 |
| 2004 | Towards digital rights and exemptions management systems
Thierry Maillard, Teddy Furon |
Comput. Law Secur. Rev. | 2 |
| 2003 | Application of side-informed embedding and polynomial detection to audio watermarkingabstractSpread spectrum watermarking proceeds by extracting a feature vector from the cover contents and embedding a pseudo-random watermark signal in that feature vector. To detect the presence of the watermark, a correlation of the feature vector with the pseudorandom signal is performed and the result compared to a threshold. This correlation detection function is a first-order function of the feature vector components. In recent work, we have proposed that higher-order polynomial detection functions, combined with a side-informed watermark embedding strategy, can be used to increase the efficiency of the watermarking system. We have demonstrated this through a statistical analysis. In this paper, we apply our new family of detection functions to the watermarking of real audio signals. The schemes are tested on a database of over 300 different audio signals and a robustness analysis is performed on the experimental results. Micheal Mullarkey, Neil J. Hurley, Guénolé C. M. Silvestre, Teddy Furon |
ICASSP (3) | 4 |
| 2003 | Application of side-informed embedding and polynomial detection to audio watermarkingabstractSpread spectrum watermarking proceeds by extracting a feature vector from the cover contents and embedding a pseudo-random watermark signal in that feature vector. To detect the presence of the watermark, a correlation of the feature vector with the pseudo-random signal is performed and the result compared to a threshold. This correlation detection function is a first-order function of the feature vector components. In recent work, we have proposed that higher-order polynomial detection functions, combined with a side-informed watermark embedding strategy, can be used to increase the efficiency of the watermarking system. We have demonstrated this through a statistical analysis. In this paper, we apply our new family of detection functions to the watermarking of real audio signals. The schemes are tested on a database of over 300 different audio signals and a robustness analysis is performed on the experimental results. Micheal Mullarkey, Neil J. Hurley, Guénolé C. M. Silvestre, Teddy Furon |
ICME | 4 |
| 2003 | A general framework for robust watermarking security
Mauro Barni, Franco Bartolini, Teddy Furon |
Signal Process. | 3 |
| 2002 | JANIS: Just Another n-order Side-Informed Watermarking SchemeabstractThis paper deals with some detection issues of watermark signals. We propose an easy way to implement an informed watermarking embedder whatever the detection function. This method shows that a linear detection function is not suitable for side information. This is the reason why we build a family of nonlinear functions named JANIS. Used with a side-informed embedder, its performance is much better than the classical spread spectrum method. Teddy Furon, Benoît Macq, Neil J. Hurley, Guénolé C. M. Silvestre |
ICIP (2) | 1 |
| 2000 | Audio public key watermarking techniqueabstractThis paper presents the application of the promising public key watermarking method to the audio domain. Its detection process does not need the original content nor the secret key used in the embedding process. It is the translation, in the watermarking domain, of a public key pair cryptosystem. We start to build the detector with some basic assumptions. This leads to a hypothesis test based on probability likelihood. But real audio signals do not satisfy the assumption of a Gaussian probability density function. Moreover, the use of an advanced human perception model to hide the watermark makes the detection issue a tough problem. Our works result in a new detection process offering a good test's power for a low probability of false alarm. Teddy Furon, Nicolas Moreau, Pierre Duhamel |
ICASSP | 1 |
| 2000 | Robustness of an Asymmetric Watermarking TechniqueabstractAsymmetric schemes belong to second generation of watermarking. Whereas their need and advantage are well understood, many doubts have been raised about their robustness. According to a method presented by Furon and Duhamel (see Proc. of the 3rd Int. Work. on Information Hiding, Dresden, 1999), a very robust symmetric technique is derived into an asymmetric scheme. Tests show that it is as robust as the symmetric version. Yet, asymmetric schemes undergo malicious attacks that confuse the detection process. Tests reveal that the quality loss due to these malicious attacks is too important for the signal to be used after the attack. Teddy Furon, Pierre Duhamel |
ICIP | 1 |