VLDB 2026 Research / reviewers in the wild / expert
Pascal Schöttle
dblp:120/8189
· DBLP profile ↗
14ranked-venue papers
2as first author
5since 2021 · last 2024
0000-0001-8710-9188ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Incremental Whole Plate ALPR Under Data Availability Constraints
Markus Russold, Martin Nocker, Pascal Schöttle |
ICPRAM | 3 |
| 2024 | On the Economics of Adversarial Machine LearningabstractGiven the widespread deployment of machine learning algorithms, the security of these algorithms and thus, the field of adversarial machine learning gained popularity in the research community. In this article, we loosen several unrealistic restrictions found in prior art and bring economical-inspired adversarial machine learning one step closer to being applicable in the real world. First, we extend our own game-theoretical framework such that it allows any arbitrary number of actions for both actors, and analytically determine equilibrium strategies and conditions where mixed strategies are expected for the specific case in which both actors choose from any two arbitrary actions. Then, we pay special attention to an adversary’s knowledge about the attacked system by modeling them as a white-, gray-, or black-box adversary. We conduct extensive experiments for three architectures, two training procedures, and four adversarial attacks in different variations as direct and transfer attacks, resulting in 300 data points consisting of the respective accuracy and robustness values and the computational costs for both actors. We then instantiate our model with this data and explore the structure of the game for a wide range of each game parameter, overcoming the complexity by applying algorithmic game theory. We discover surprising properties in the actors’ strategies, such as the feasibility of cheap attacks that have been dismissed as practically irrelevant so far - examples include universal adversarial perturbations or (transfer) attacks utilizing only few optimization steps. For the defender, we find that given recent attacks and countermeasures, a rational defender would try to hide as much as possible from their infrastructure. Florian Merkle, Maximilian Samsinger, Pascal Schöttle, Tomás Pevný |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Pruning for Power: Optimizing Energy Efficiency in IoT with Neural Network Pruning
Thomas Widmann, Florian Merkle, Martin Nocker, Pascal Schöttle |
EANN | 4 |
| 2022 | Machine unlearning: linear filtration for logit-based classifiersabstractAbstract Recently enacted legislation grants individuals certain rights to decide in what fashion their personal data may be used and in particular a “right to be forgotten”. This poses a challenge to machine learning: how to proceed when an individual retracts permission to use data which has been part of the training process of a model? From this question emerges the field of machine unlearning , which could be broadly described as the investigation of how to “delete training data from models”. Our work complements this direction of research for the specific setting of class-wide deletion requests for classification models (e.g. deep neural networks). As a first step, we propose linear filtration as an intuitive, computationally efficient sanitization method. Our experiments demonstrate benefits in an adversarial setting over naive deletion schemes. Thomas Baumhauer, Pascal Schöttle, Matthias Zeppelzauer |
Mach. Learn. | 2 |
| 2021 | Adversarial Examples Against a BERT ABSA Model - Fooling Bert With L33T, Misspellign, and Punctuation, abstractThe BERT model is de facto state-of-the-art for aspect-based sentiment analysis (ABSA), an important task in natural language processing. Similar to every other model based on deep learning, BERT is vulnerable to so-called adversarial examples: strategically modified inputs that cause a change in the model’s prediction of the underlying input. In this paper we propose three new methods to create character-level adversarial examples against BERT and evaluate their effectiveness on the ABSA task. Specifically, our attack methods mimic human behavior and use leetspeak, common misspellings, or misplaced commas. By concentrating these changes on important words, we are able to maximize misclassification rates with minimal changes. To the best of our knowledge, we are the first to look into adversarial examples for the ABSA task and the first to propose these attacks. Nora Hofer, Pascal Schöttle, Alexander Rietzler, Sebastian Stabinger |
ARES | 2 |
| 2017 | Decoy Password Vaults: At Least as Hard as Steganography?
Cecilia Pasquini, Pascal Schöttle, Rainer Böhme |
SEC | 2 |
| 2016 | Forensics of High Quality and Nearly Identical JPEG Image RecompressionabstractWe address the known problem of detecting a previous compression in JPEG images, focusing on the challenging case of high and very high quality factors (>= 90) as well as repeated compression with identical or nearly identical quality factors. We first revisit the approaches based on Benford--Fourier analysis in the DCT domain and block convergence analysis in the spatial domain. Both were originally conceived for specific scenarios. Leveraging decision tree theory, we design a combined approach complementing the discriminatory capabilities. We obtain a set of novel detectors targeted to high quality grayscale JPEG images. Cecilia Pasquini, Pascal Schöttle, Rainer Böhme, Giulia Boato, Fernando Pérez-González |
IH&MMSec | 2 |
| 2016 | Game Theory and Adaptive SteganographyabstractAccording to conventional wisdom, content-adaptive embedding offers more steganographic security than random uniform embedding. We scrutinize this view and note that it is barely substantiated in the literature as only recently adaptive steganographic systems are tested against an attacker who anticipates the adaptivity and incorporates this knowledge into the detection strategy. For a better theoretical understanding of strategical embedding and detection, we propose a game-theoretic framework to study adaptive steganography while taking the knowledge of the steganalyst into account. We instantiate the framework with a stylized cover model and study both parties' optimal strategies. The model has a unique equilibrium in mixed strategies, which depends on the heterogeneity of the cover source. We add realism by introducing imperfect recoverability of the adaptivity criterion and prove that naïve adaptive embedding-the strategy implemented in many practical schemes-is only optimal if perfect steganography is possible or if the adaptivity criterion is not recoverable at all. In practice, where steganography is imperfect and adaptivity criteria are partially recoverable, the optimal embedding strategy is between naïve adaptive and random uniform embedding. Pascal Schöttle, Rainer Böhme |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Predictable rain?: steganalysis of public-key steganography using wet paper codesabstractSymmetric steganographic communication requires a secret stego-key pre-shared between the communicating parties. Public-key steganography (PKS) overcomes this inconvenience. In this case, the steganographic security is based solely on the underlying asymmetric encryption function. This implies that the embedding positions are either public or hidden by clever coding, for instance using Wet Paper Codes (WPC), but with public code parameters. We show that using WPC with efficient encoding algorithms may leak information which can facilitate an attack. The public parameters allow an attacker to predict among the possible embedding positions the ones most likely used for embedding. This approach is independent of the embedding operation. We demonstrate it for the case of least significant bit (LSB) replacement and present two new variants of Weighted Stego-Image (WS) steganalysis specifically tailored to detect PKS using efficient WPC. Experiments show that our WS variants can detect PKS with higher accuracy than known methods, especially for low embedding rates. The attack is applicable even if a hybrid stegosystem is constructed and public-key cryptography is only used to encapsulate a secret stego-key. Matthias Carnein, Pascal Schöttle, Rainer Böhme |
IH&MMSec | 2 |
| 2014 | On the combination of randomized thresholds and non-parametric boundaries to protect digital watermarks against sensitivity attacksabstractWith unlimited access to a watermark detector, an attacker can use sensitivity attacks to remove the watermark of a digital medium. Randomized detectors and non-parametric decision boundaries are two ways of defending the watermark against these attacks. However, both approaches have their vulnerabilities when used individually. The first enables working with the randomized region boundary. The second still provides reliable information. This paper presents a combination of these two approaches to overcome their shortcomings. We develop a detector that has a randomized region with non-parametric outer boundaries. To empirically evaluate our combination, we apply two attack algorithms: Kalker's attack and Blind Newton Sensitivity Attack. The combination is more effective than the non-parametric boundary alone and comparable with using only the randomized threshold. In addition, we increase security by preventing attacks against the outer boundaries. Erwin Quiring, Pascal Schöttle |
IH&MMSec | 2 |
| 2014 | Secure Team Composition to Thwart Insider Threats and Cyber-EspionageabstractWe develop a formal nondeterministic game model for secure team composition to counter cyber-espionage and to protect organizational secrets against an attacker who tries to sidestep technical security mechanisms by offering a bribe to a project team member. The game captures the adversarial interaction between the attacker and the project manager who has a secret she wants to protect but must share with a team of individuals selected from within her organization. Our interdisciplinary work is important in the face of the multipronged approaches utilized by well-motivated attackers to circumvent the fortifications of otherwise well-defended targets. Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme |
ACM Trans. Internet Techn. | 3 |
| 2013 | Managing the Weakest Link - A Game-Theoretic Approach for the Mitigation of Insider Threats
Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme |
ESORICS | 3 |
| 2013 | Bitspotting: Detecting Optimal Adaptive Steganography
Benjamin Johnson 0001, Pascal Schöttle, Aron Laszka, Jens Grossklags, Rainer Böhme |
IWDW | 2 |
| 2008 | On the application of anomaly detection in Reliable Server Pooling systems for improved robustness against denial of service attacksabstractThe Reliable Server Pooling (RSerPool) architecture is the IETFpsilas upcoming standard of a lightweight server redundancy and session failover framework for availability-critical applications. RSerPool combines the ideas from different research areas into a single, resource-efficient and unified architecture. Although there have already been a number of research papers on the pool management, load distribution and failover handling performance of RSerPool, the robustness against intentional attacks has not been intensively addressed yet. Therefore, the first goal of this paper is to provide a robustness analysis in order to outline the attack bandwidth necessary for a significant impact on RSerPool-based services. After that, we present our anomaly detection approach that has been designed to protect RSerPool systems against attacks. We also show the effectiveness of this approach by simulations. Pascal Schöttle, Thomas Dreibholz, Erwin P. Rathgeb |
LCN | 1 |