VLDB 2026 Research / reviewers in the wild / expert
Edgar Kaziakhmedov
dblp:250/9371
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0006-3608-5175ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Effect of Acquisition Noise Outliers on SteganalysisabstractUnderstanding the mechanisms that lead to false alarms (erroneously detecting cover images as containing secrets) in steganalysis is a topic of utmost importance for practical applications.In this paper, we present evidence that a relatively small number of pixel outliers introduced by the image acquisition process can skew the soft output of a data driven detector to produce a strong false alarm.To verify this hypothesis, for a cover image we estimate a statistical model of the acquisition noise in the developed domain and identify pixels that contribute the most to the associated likelihood ratio test (LRT) for steganography.We call such cover elements LIEs (Locally Influential Elements).The effect of LIEs on the output of a data-driven detector is demonstrated by turning a strong false alarm into a correctly classified cover by introducing a relatively small number of "de-embedding" changes at LIEs.Similarly, we show that it is possible to introduce a small number of LIEs into a strong cover to make a data driven detector classify it as stego.Our findings are supported by experiments on two datasets with three steganographic algorithms and four types of data driven detectors. Edgar Kaziakhmedov, Jessica J. Fridrich, Patrick Bas |
IH&MMSec | 1 |
| 2024 | Improving Steganographic Security with Source BiasingabstractBy selecting covers in which steganographic embedding is harder to detect, the steganographer can decrease the chances of being caught by the Warden. On the other hand, sampling from the cover source with a bias is detectable on its own. In this paper, we study this trade-off theoretically within a simple source model. Our analysis predicts the existence of "bias security gain" when the sender selects the sampling bias optimally. Sampling with a bias initially morphs the ROC of Warden's detector to be asymmetrical, lowering the true positive rate for small false alarm rates. We provide a theorem, analogous to the square root law, for the joint critical rates of sampling bias and payload that achieve asymptotically constant detectability. Our analysis is verified experimentally. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2023 | On Comparing Ad Hoc Detectors with Statistical Hypothesis TestsabstractThis paper addresses how to fairly compare ROCs of ad hoc (or data driven) detectors with tests derived from statistical models of digital media. We argue that the ways ROCs are typically drawn for each detector type correspond to different hypothesis testing problems with different optimality criteria, making the ROCs uncomparable. To understand the problem and why it occurs, we model a source of natural images as a mixture of scene oracles and derive optimal detectors for the task of image steganalysis. Our goal is to guarantee that, when the data follows the statistical model adopted for the hypothesis test, the ROC of the optimal detector bounds the ROC of the ad hoc detector. While the results are applicable beyond the field of image steganalysis, we use this setup to point out possible inconsistencies when comparing both types of detectors and explain guidelines for their proper comparison. Experiments on an artificial cover source with a known model with real steganographic algorithms and deep learning detectors are used to confirm our claims. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2023 | Advancing the JPEG Compatibility Attack: Theory, Performance, Robustness, and PracticeabstractThe JPEG compatibility attack is a steganalysis method for detecting messages embedded in the spatial representation of an image under the assumption that the cover image was a decompressed JPEG. This paper addresses a number of open problems in previous art, namely the lack of theoretical insight into how and why the attack works, low detection accuracy for high JPEG qualities, robustness to the JPEG compressor and DCT coefficient quantizer, and real-life performance evaluation. To explain the main mechanism responsible for detection and to understand the trends exhibited by heuristic detectors, we adopt a model of quantization errors of DCT coefficients in the recompressed image, and within a simplified setup, we analyze the behavior of the most powerful detector. Empowered by our analysis, we resolve the performance deficiencies using an SRNet trained on a two-channel input consisting of the image and its SQ error. This detector is compared with previous state of the art on four content-adaptive stego methods and for a wide range of payloads and quality factors. The last sections of this paper are devoted to studying robustness of this detector with respect to JPEG compressors, quantizers, and errors in estimating the JPEG quantization table. Finally, to demonstrate practical usability of this attack, we test our detector on stego images outputted by real steganographic tools available on the Internet. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2023 | Limits of Data Driven Steganography DetectorsabstractWhile deep learning has revolutionized image steganalysis in terms of performance, little is known about how much modern data driven detectors can still be improved. In this paper, we approach this difficult and currently wide open question by working with artificial but realistic looking images with a known statistical model that allows us to compute the detectability of modern content-adaptive algorithms with respect to the most powerful detectors. Multiple artificial image datasets are crafted with different levels of content complexity and noise power to assess their influence on the gap between both types of detectors. Experiments with SRNet as the heuristic detector indicate that independent noise contributes less to the performance gap than content of the same MSE. While this loss is rather small for smooth images, it can be quite large for textured images. A network trained on many realizations of a fixed textured scene will, however, recuperate most of the loss, suggesting that networks have the capacity to approximately learn the parameters of a cover source narrowed to a fixed scene. Edgar Kaziakhmedov, Eli Dworetzky, Jessica J. Fridrich |
IH&MMSec | 1 |