Lukas Graner

dblp:152/2498 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
5since 2021 · last 2025
0000-0002-0453-1146ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Adversarial Attack Challenge for Secure Face Recognition 2025
abstract
Adversarial attacks pose a significant threat to the reliability of biometric systems, particularly in security-critical applications such as identity verification and access control. Ensuring robustness against such attacks is essential for the safe deployment of face recognition technologies in real-world scenarios. To advance this goal, the 2025 Adversarial Attack Challenge for Secure Face Recognition was organized as part of the International Joint Conference on Biometrics (IJCB) 2025.The competition focused on two main tracks: Detection, where the objective was to determine whether a given face image is clean or adversarial, and Resilience, which aimed to evaluate recognition systems under adversarial perturbations. Participants were provided with a standardized dataset derived from CelebA and LFW, encompassing both clean samples and adversarial images crafted using ten diverse attack methods targeting evasion and impersonation scenarios. To ensure fairness and reproducibility, all models were trained solely on the data provided, with support from a custom open source adversarial attack package tailored for face recognition.In addition to benchmarking adversarial robustness, the challenge contributes to the research community by releasing the data set and the extensible attack package, allowing further investigation of secure and reliable face recognition systems.
João Tremoço, Iurii Medvedev, Nuno R. Freitas, Andreia M. Costa, Diogo Nunes, Niklas Bunzel, Lukas Graner, Nicholas Göller, Lorenzo Pellegrini, Nicolò Di Domenico, Guido Borghi, Monson Verghese, Shruti Bhilare, Avik Hati, Miguel Lourenço, Nuno Gonçalves 0001
IJCB7
2025 Team RoMa @ AADD-2025: On the Generation of Transferable and Visually Imperceptible Adversarial Attacks Against Deepfake Detectors
abstract
The rapid development of generative AI and in particular deepfake technology enables the seamless creation and manipulation of visual content. As the resulting syntheses are often indistinguishable from authentic images, they threaten the integrity of visual evidence. While forensic detectors can be used to detect syntheses, they can become targets of adversarial attacks. In the ''Adversarial Attacks on Deepfake Detectors'' challenge, competitors were tasked with perturbing a dataset of AI-synthesized images so that four classifiers would mistakenly accept them as authentic. In this paper, we introduce our solution, a white-box adversarial framework that injects globally distributed, data-driven noise perturbations optimized via additional surrogate Vision Transformer and EfficientNet classifiers. Empirical comparisons to both conventional post-processing transforms and localized adversarial patches demonstrate that our approach based on globally distributed noise achieves the highest attack success rates across all public detectors while preserving superior SSIM, confirming its efficacy and visual imperceptibility. In the final evaluation of the challenge, our proposed approach placed third with a final score of 2679.
Nicolas Göller, Lukas Graner, Raphael Antonius Frick, Niklas Bunzel
ACM Multimedia2
2024 Unveiling the Darkness: Analysing Organised Crime on the Wall Street Market Darknet Marketplace using PGP Public Keys
abstract
Darknet marketplaces (DNMs) are digital platforms for e-commerce that are primarily used to trade illegal and illicit products. They incorporate technological advantages for privacy protection and contribute to the growth of cybercriminal activities. In the past, researchers have explored methods to investigate multiple identities of vendors covering different DNMs. Leaving aside phenomena such as malicious forgery of identities or Sybil attacks, usernames and their corresponding PGP public keys are used to build brands around users and are considered a trusted method of vendor authentication across DNMs.
Shiying Fan, Paul Moritz Ranly, Lukas Graner, Inna Vogel, Martin Steinebach
ARES3
2024 Deepfakes: A New Kind of Adversarial Attacks Against Face Recognition Systems?
abstract
Neural networks have become essential to modern applications, excelling in various tasks such as image recognition, language translation, and predictive analytics. In security, they are, among other things, widely used as part of identity verification that often combines automatic recognition with human verification. However, automatized methods are facing challenges from adversarial attacks, where malicious modifications to an input can deceive networks, thus compromising their reliability. With defenses evolving to detect and reverse such attempts, as well as attacked samples not passing manual verification by a human, it raises the question, whether deepfakes such as face swapping and facial reenactment can serve as a new kind of adversarial attacks. In this paper, we explore if deepfakes can deceive neural networks and humans, by analyzing state-of-the-art methods and introducing a novel one-shot face swapping technique that blends reenactment and swapping for high-quality results and improved attack success rates of up to 11% in comparison to current state-of-the-art face swapping techniques.
Raphael Antonius Frick, Lukas Graner
TrustCom2
2021 POSNoise: An Effective Countermeasure Against Topic Biases in Authorship Analysis
abstract
Authorship verification (AV) is a fundamental research task in digital text forensics, which addresses the problem of whether two texts were written by the same person. In recent years, a variety of AV methods have been proposed that focus on this problem and can be divided into two categories: The first category refers to such methods that are based on explicitly defined features, where one has full control over which features are considered and what they actually represent. The second category, on the other hand, relates to such AV methods that are based on implicitly defined features, where no control mechanism is involved, so that any character sequence in a text can serve as a potential feature. However, AV methods belonging to the second category bear the risk that the topic of the texts may bias their classification predictions, which in turn may lead to misleading conclusions regarding their results. To tackle this problem, we propose a preprocessing technique called POSNoise, which effectively masks topic-related content in a given text. In this way, AV methods are forced to focus on such text units that are more related to the writing style. Our empirical evaluation based on six AV methods (falling into the second category) and seven corpora shows that POSNoise leads to better results compared to a well-known topic masking approach in 34 out of 42 cases, with an increase in accuracy of up to 10%.
Oren Halvani, Lukas Graner
ARES2
2020 TAVeer: an interpretable topic-agnostic authorship verification method
abstract
A central problem that has been researched for many years in the field of digital text forensics is the question whether two documents were written by the same author. Authorship verification (AV) is a research branch in this field that deals with this question. Over the years, research activities in the context of AV have steadily increased, which has led to a variety of approaches trying to solve this problem. Many of these approaches, however, make use of features that are related to or influenced by the topic of the documents. Therefore, it may accidentally happen that their verification results are based not on the writing style (the actual focus of AV), but on the topic of the documents. To address this problem, we propose an alternative AV approach that considers only topic-agnostic features in its classification decision. In addition, we present a post-hoc interpretation method that allows to understand which particular features have contributed to the prediction of the proposed AV method. To evaluate the performance of our AV method, we compared it with eight competing baselines (including the current state of the art) on four challenging data sets. The results show that our approach outperforms all baselines in two cases (with a maximum accuracy of 84%), while in the other two cases it performs as well as the strongest baseline.
Oren Halvani, Lukas Graner, Roey Regev
ARES2
2019 Assessing the Applicability of Authorship Verification Methods
abstract
Authorship verification (AV) is a research subject in the field of digital text forensics that concerns itself with the question, whether two documents have been written by the same person. During the past two decades, an increasing number of proposed AV approaches can be observed. However, a closer look at the respective studies reveals that the underlying characteristics of these methods are rarely addressed, which raises doubts regarding their applicability in real forensic settings. The objective of this paper is to fill this gap by proposing clear criteria and properties that aim to improve the characterization of existing and future AV approaches. Based on these properties, we conduct three experiments using 12 existing AV approaches, including the current state of the art. The examined methods were trained, optimized and evaluated on three self-compiled corpora, where each corpus focuses on a different aspect of applicability. Our results indicate that part of the methods are able to cope with very challenging verification cases such as 250 characters long informal chat conversations (72.7% accuracy) or cases in which two scientific documents were written at different times with an average difference of 15.6 years (> 75% accuracy). However, we also identified that all involved methods are prone to cross-topic verification cases
Oren Halvani, Christian Winter 0001, Lukas Graner
ARES3
2018 Authorship Verification in the Absence of Explicit Features and Thresholds
Oren Halvani, Lukas Graner, Inna Vogel
ECIR2
2017 On the Usefulness of Compression Models for Authorship Verification
abstract
Compression models represent an interesting approach for different classification tasks and have been used widely across many research fields. We adapt compression models to the field of authorship verification (AV), a branch of digital text forensics. The task in AV is to verify if a questioned document and a reference document of a known author are written by the same person. We propose an intrinsic AV method, which yields competitive results compared to a number of current state-of-the-art approaches, based on support vector machines or neural networks. However, in contrast to these approaches our method does not make use of machine learning algorithms, natural language processing techniques, feature engineering, hyperparameter optimization or external documents (a common strategy to transform AV from a one-class to a multi-class classification problem). Instead, the only three key components of our method are a compressing algorithm, a dissimilarity measure and a threshold, needed to accept or reject the authorship of the questioned document. Due to its compactness, our method performs very fast and can be reimplemented with minimal effort. In addition, the method can handle complicated AV cases where both, the questioned and the reference document, are not related to each other in terms of topic or genre. We evaluated our approach against publicly available datasets, which were used in three international AV competitions. Furthermore, we constructed our own corpora, where we evaluated our method against state-of-the-art approaches and achieved, in both cases, promising results.
Oren Halvani, Christian Winter 0001, Lukas Graner
ARES3
2017 Towards Imperceptible Natural Language Watermarking for German
abstract
Watermarking natural language is still a challenge in the domain of digital watermarking. Here, only the textual information must be used as a cover. No format changes or modified illustrations are accepted. Still, natural language watermarking (NLW) has some important applications, especially in leakage tracking, where a small set of individually marked copies of a confidently text is distributed. Properties of watermarking schemes such as imperceptibility, blindness or adaptability to non-English languages are of importance here. In order to address these three simultaneously, we present a blind NLW scheme, consisting of four independent embedding methods, which operate on the phonetical, morphological, lexical and syntactical layer of German texts. An evaluation based on 1,645 assessments provided by 131 test persons reveals promising results.
Oren Halvani, Martin Steinebach, Lukas Graner
IH&MMSec3
2014 Data Corpora for Digital Forensics Education and Research
York Yannikos, Lukas Graner, Martin Steinebach, Christian Winter 0001
IFIP Int. Conf. Digital Forensics2