VLDB 2026 Research / reviewers in the wild / expert
Eva Giboulot
dblp:244/5025 · also Quentin Giboulot
· DBLP profile ↗
13ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0002-0277-5999ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Do Modern Post-Hoc Watermarking Methods Beat Broken-Arrows?abstractWith the rapid proliferation of generative models, such as diffusion models, digital watermarking has emerged as a crucial solution for identifying AI-generated images. Modern post-hoc watermarking schemes use neural networks to achieve an extremely low false-alarm rate while remaining robust to common image transformations. However, there is a lack of comparison between these modern methods and classic ones, particularly in real-world scenarios where robustness and security take precedence over achieving an extremely low false-alarm probability. In this paper, we propose a fair comparison of robustness and security between modern and classic post-hoc watermarking across various types of classic augmentations and recent sophisticated attacks. Our experiments show that, in a realistic scenario, classic watermarking outperforms modern techniques in terms of security while maintaining robustness. Enoal Gesny, Eva Giboulot |
IH&MMSec | 2 |
| 2025 | Evaluating the security of public surrogate watermark detectorsabstractThe omnipresence of generated content has led to an increasing need of multimedia content traceability. Water-marking techniques have been proven to provide both detection guarantees and robustness. However, widespread use of such methods would require disclosing the watermark detector to the public. Such access breaches the watermark security: end-users with unlimited access to the detector could easily craft adversarial examples, through white-box and black-box attacks. To circumvent this issue, we suggest providing to the public a surrogate, less accurate detector. Calls to the private detector would be reserved for important or anomalous cases. This paper studies the potential leakage of information from the surrogate detector. We first create a wide panel of images adversarial to the surrogate detector. The efficiency of the private detector is then assessed on this data. This allows us to introduce a metric of the transferability of these attacks from the surrogate to the private detector. Through this metric, we evaluate the security of different designs of surrogate detectors. Chloé Imadache, Eva Giboulot, Teddy Furon |
ICASSP | 2 |
| 2024 | WaterMax: breaking the LLM watermark detectability-robustness-quality trade-offabstractWatermarking is a technical means to dissuade malfeasant usage of Large Language Models.
This paper proposes a novel watermarking scheme, so-called WaterMax, that enjoys high detectability while sustaining the quality of the generated text of the original LLM.
Its new design leaves the LLM untouched (no modification of the weights, logits or temperature).
WaterMax balances robustness and computational complexity contrary to the watermarking techniques of the literature inherently provoking a trade-off between quality and robustness.
Its performance is both theoretically proven and experimentally validated.
It outperforms all the SotA techniques under the most complete benchmark suite. Eva Giboulot, Teddy Furon |
NeurIPS | 1 |
| 2023 | The Non-Zero-Sum Game of Steganography in Heterogeneous EnvironmentsabstractThe highly heterogeneous nature of images found in real-world environments, such as online sharing platforms, has been one of the long-standing obstacles to the transition of steganalysis techniques outside the laboratory. Recent advances in identifying the properties of images relevant to steganalysis as well as the effectiveness of deep neural networks on highly heterogeneous datasets have laid some groundwork for resolving this problem. Despite this progress, we argue that the way the game played between the steganographer and the steganalyst is currently modeled lacks some important features expected in a real-world environment: 1) the steganographer can adapt her cover source choice to the environment and/or to the steganalyst’s classifier, 2) the distribution of cover sources in the environment impacts the optimal threshold for a given classifier, and 3) the steganalyst and steganographer have different goals, hence different utilities. We propose to take these facts into account using a two-player non-zero-sum game constrained by an environment composed of multiple cover sources. We then show how to convert this non-zero-sum game into an equivalent zero-sum game, allowing us to propose two methods to find Nash equilibria for this game: a standard method using the double oracle algorithm and a minimum regret method based on approximating a set of atomistic classifiers. Applying these methods to contemporary steganography and steganalysis in a realistic environment, we show that classifiers which do not adapt to the environment severely underperform when the steganographer is allowed to select into which cover source to embed. Eva Giboulot, Tomás Pevný, Andrew D. Ker |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Efficient Steganography in JPEG Images by Minimizing Performance of Optimal DetectorabstractSince the introduction of adaptive steganography, most of the recent research works seek at designing cost functions that are evaluated against steganalysis methods. While those approaches have been successful, they rely on intuitive principles and ad-hoc costs associated with each pixel or Discrete Cosine Transform (DCT) coefficient. Beyond the empirical assessments, the insights one can get from such approaches are very limited. On the opposite, this paper presents an original method for steganography in JPEG images that exploits a statistical model of the DCT coefficients. Within the framework of hypothesis testing theory, we use a statistical model of covers to derive the analytical expression of the most powerful detector. The objective of the steganographer is to minimize the statistical performance of this “omniscient detector” which represents a “worst-case” scenario for security. This paper shows how this method allows designing effective steganography, in terms of both security and computational complexity, in the two main use cases: when having only one single JPEG image and when the uncompressed image is available, case also known as Side-Informed (SI). A wide range of numerical comparisons shows that the proposed method outperforms the current state-of-the-art especially against the latest and most accurate steganalysis approaches based on Deep Learning. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Multivariate Side-Informed Gaussian Embedding Minimizing Statistical DetectabilityabstractSteganography schemes based on a deflection criterion for embedding posses a clear advantage against schemes based on heuristics as they provide a direct link between theoretical detectability and empirical performance. However, this advantage depends on the accuracy of the cover and stego model underlying the embedding scheme. In this work we propose an original steganography scheme based on a realistic model of sensor noise, taking into account the camera model, the ISO setting and the processing pipeline. Exploiting this statistical model allows us to take correlations between DCT coefficients into account. Several types of dependency models are presented, including a very general lattice model which accurately models dependencies introduced by a large class of processing pipelines of interest. We show in particular that the stego signal which minimizes the KL divergence under this model has a covariance proportional to the cover noise covariance. The resulting embedding scheme achieves state-of-the-art performances which go well beyond the current standards in side-informed JPEG steganography. Eva Giboulot, Patrick Bas, Rémi Cogranne |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Detectability-Based JPEG Steganography Modeling the Processing Pipeline: The Noise-Content Trade-offabstractThe current art of steganography shows that schemes using a deflection criterion (such as MiPOD) for JPEG steganography are usually subpar with respect to distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. However, this statistically-based method provides a better assessment of the detectability of hidden data as well as theoretical guarantees under a given model. In this paper, we propose a method to obtain better estimates of the variances of DCT coefficients by taking into account the dependencies introduced by development pipeline on pixels. A second method, which is a side-informed extension of Gaussian Embedding in the JPEG domain using quantization error as side-information, is also formulated and shown to achieve state-of-the-art performances. Eventually, the trade-off between noise and content complexity in steganography is thoroughly analyzed through the lenses of these two new methods using a wide range of numerical experiments. Eva Giboulot, Rémi Cogranne, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | JPEG Steganography with Side Information from the Processing PipelineabstractThe current art in schemes using deflection criterion such as Mi-POD for JPEG steganography is either under-performing or on par with distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. In this paper, we propose a method to better estimate the variances of DCT coefficients by taking into account the dependencies between pixels that come from the development pipeline. Using this estimate, we are able to extend statistically-informed steganographic schemes to the JPEG domain while significantly outperforming the current state-of-the-art JPEG steganography. An extension of Gaussian Embedding in the JPEG domain using quantization error as side-information is also formulated and shown to attain state-of-the-art performances. Eva Giboulot, Rémi Cogranne, Patrick Bas |
ICASSP | 1 |
| 2020 | Steganography by Minimizing Statistical Detectability: The cases of JPEG and Color ImagesabstractThis short paper presents a novel method for steganography in JPEG-compressed images, extended the so-called MiPOD scheme based on minimizing the detection accuracy of the most-powerful test using a Gaussian model of independent DCT coefficients. This method is also applied to address the problem of embedding into color JPEG images. The main issue in such case is that color channels are not processed in the same way and, hence, a statistically based approach is expected to bring significant improvements when one needs to consider heterogeneous channels together. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IH&MMSec | 2 |
| 2020 | Effects and solutions of Cover-Source Mismatch in image steganalysis
Eva Giboulot, Rémi Cogranne, Dirk Borghys, Patrick Bas |
Signal Process. Image Commun. | 1 |
| 2019 | The ALASKA Steganalysis Challenge: A First Step Towards SteganalysisabstractThis paper presents ins and outs of the ALASKA challenge, a steganalysis challenge built to reflect the constraints of a forensic steganalyst. We motivate and explain the main differences w.r.t. the BOSS challenge (2010), specifically the use of a ranking metric prescribing high false positive rates, the analysis of a large diversity of different image sources and the use of a collection of steganographic schemes adapted to handle color JPEGs. The core of the challenge is also described, this includes the RAW image data-set, the implementations used to generate cover images and the specificities of the embedding schemes. The very first outcomes of the challenge are then presented, and the impacts of different parameters such as demosaicking, filtering, image size, JPEG quality factors and cover-source mismatch are analyzed. Eventually, conclusions are presented, highlighting positive and negative points together with future directions for the next challenges in practical steganalysis. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IH&MMSec | 2 |
| 2019 | Breaking ALASKA: Color Separation for Steganalysis in JPEG DomainabstractThis paper describes the architecture and training of detectors developed for the ALASKA steganalysis challenge. For each quality factor in the range 60-98, several multi-class tile detectors implemented as SRNets were trained on various combinations of three input channels: luminance and two chrominance channels. To accept images of arbitrary size, the detector for each quality factor was a multi-class multi-layered perceptron trained on features extracted by the tile detectors. For quality 99 and 100, a new "reverse JPEG compatibility attack" was developed and also implemented using the SRNet via the tile detector. Throughout the paper, we explain various improvements we discovered during the course of the competition and discuss the challenges we encountered and trade offs that had to be adopted in order to build a detector capable of detecting steganographic content in a stego source of great diversity. Yassine Yousfi, Jan Butora, Jessica J. Fridrich, Eva Giboulot |
IH&MMSec | 4 |
| 2019 | Payload Scaling for Adaptive Steganography: An Empirical StudyabstractPayload-scaling laws of imperfect steganography inform the steganographer about how the size of secret payload should grow with cover size for constant statistical detectability. In this letter, we carry out an empirical study for the case when the steganographer and the steganalyst operate at a game-theoretic equilibrium. We first explore the possibility to leverage a generalization of the square root law to content-adaptive steganography due to Ker. Since this result does not appear to be tight enough for realistic cover sizes, we instead work with a detectability limited sender in image sources with a forced model as well as real images in both spatial and JPEG domain. The scaling is observed in practice when the images are carefully cropped to preserve the distribution of costs across scales. Eva Giboulot, Jessica J. Fridrich |
IEEE Signal Process. Lett. | 1 |