VLDB 2026 Research / reviewers in the wild / expert
Niklas Bunzel
dblp:271/4888
· DBLP profile ↗
7ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0002-8921-1562ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Adversarial Attack Challenge for Secure Face Recognition 2025abstractAdversarial attacks pose a significant threat to the reliability of biometric systems, particularly in security-critical applications such as identity verification and access control. Ensuring robustness against such attacks is essential for the safe deployment of face recognition technologies in real-world scenarios. To advance this goal, the 2025 Adversarial Attack Challenge for Secure Face Recognition was organized as part of the International Joint Conference on Biometrics (IJCB) 2025.The competition focused on two main tracks: Detection, where the objective was to determine whether a given face image is clean or adversarial, and Resilience, which aimed to evaluate recognition systems under adversarial perturbations. Participants were provided with a standardized dataset derived from CelebA and LFW, encompassing both clean samples and adversarial images crafted using ten diverse attack methods targeting evasion and impersonation scenarios. To ensure fairness and reproducibility, all models were trained solely on the data provided, with support from a custom open source adversarial attack package tailored for face recognition.In addition to benchmarking adversarial robustness, the challenge contributes to the research community by releasing the data set and the extensible attack package, allowing further investigation of secure and reliable face recognition systems. João Tremoço, Iurii Medvedev, Nuno R. Freitas, Andreia M. Costa, Diogo Nunes, Niklas Bunzel, Lukas Graner, Nicholas Göller, Lorenzo Pellegrini, Nicolò Di Domenico, Guido Borghi, Monson Verghese, Shruti Bhilare, Avik Hati, Miguel Lourenço, Nuno Gonçalves 0001 |
IJCB | 6 |
| 2025 | Team RoMa @ AADD-2025: On the Generation of Transferable and Visually Imperceptible Adversarial Attacks Against Deepfake DetectorsabstractThe rapid development of generative AI and in particular deepfake technology enables the seamless creation and manipulation of visual content. As the resulting syntheses are often indistinguishable from authentic images, they threaten the integrity of visual evidence. While forensic detectors can be used to detect syntheses, they can become targets of adversarial attacks. In the ''Adversarial Attacks on Deepfake Detectors'' challenge, competitors were tasked with perturbing a dataset of AI-synthesized images so that four classifiers would mistakenly accept them as authentic. In this paper, we introduce our solution, a white-box adversarial framework that injects globally distributed, data-driven noise perturbations optimized via additional surrogate Vision Transformer and EfficientNet classifiers. Empirical comparisons to both conventional post-processing transforms and localized adversarial patches demonstrate that our approach based on globally distributed noise achieves the highest attack success rates across all public detectors while preserving superior SSIM, confirming its efficacy and visual imperceptibility. In the final evaluation of the challenge, our proposed approach placed third with a final score of 2679. Nicolas Göller, Lukas Graner, Raphael Antonius Frick, Niklas Bunzel |
ACM Multimedia | 4 |
| 2025 | Evasion Attacks in Continual LearningabstractContinual learning (CL) enables machine learning models to adapt to evolving tasks while addressing challenges such as catastrophic forgetting. However, it inherits vulnerabilities from conventional settings, notably evasion attacks where adversarial perturbations degrade model performance. This study investigates the impact of evasion attacks, specifically Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD), in a class incremental continual learning scenario using the CIFAR-10 dataset. Results show that adversarial examples generated during training largely retain their effectiveness across CL steps, demonstrating transferability over time. Their success varies depending on the similarity between newly introduced and previously learned classes, sometimes increasing or decreasing accordingly. Adversarial training, adapted for the CL setting, is also evaluated. While it improves robustness against specific attacks (mean gain ~30%), it introduces trade-offs such as reduced accuracy on benign inputs and potential overfitting to adversarial examples. These findings highlight the challenge of balancing robustness, generalization, and efficiency, and emphasize the importance of understanding how adversarial examples transfer across tasks in continual learning. Niklas Bunzel, Aino Schwarte |
TrustCom | 1 |
| 2025 | Exploring the Relationship Between Network Similarity and Transferability of Adversarial AttacksabstractNeural networks are vulnerable to adversarial attacks, and several defenses have been proposed. Designing a robust network is a challenging task given the wide range of attacks that have been developed. Therefore, we aim to provide insight into the influence of network similarity on the success rate of transferred adversarial attacks. Network designers can then compare their new network with existing ones to estimate its vulnerability. To achieve this, we investigate the complex relationship between network similarity and the success rate of transferred adversarial attacks. We applied the Centered Kernel Alignment (CKA) network similarity score and used various methods to find a correlation between a large number of Convolutional Neural Networks (CNNs) and adversarial attacks. Network similarity was found to be moderate across different CNN architectures, with more complex models such as DenseNet showing lower similarity scores due to their architectural complexity. Layer similarity was highest for consistent, basic layers, while specialized layers showed greater variability. Adversarial attack success rates were generally consistent for non-transferred attacks, but varied significantly for some transferred attacks, with complex networks being more vulnerable. We found that a DecisionTreeRegressor can predict the success rate of transferred attacks for all black-box and Carlini & Wagner attacks with an accuracy of over 90%, suggesting that predictive models may be viable under certain conditions. However, the variability of results across different data subsets underscores the complexity of these relationships and suggests that further research is needed to generalize these findings across different attack scenarios and network architectures. Gerrit Klause, Niklas Bunzel |
TrustCom | 2 |
| 2024 | Analyzing the Effectiveness of Image Preprocessing Defenses Under Runtime Constraintsabstract994 Niklas Bunzel, Gerrit Klause |
TrustCom | 1 |
| 2022 | Using Telegram as a carrier for image steganography: Analysing Telegrams API limitsabstractTelegram is a messaging platform with millions of users per month. For this reason, it is a possible vector for steganographic messages. We investigate the feasibility of using Telegram as a messenger service for images with steganographic content, specifically we use F5 as a proof of concept. We evaluate the optimal resolution and quality settings to achieve the highest possible payload size. In order to support longer message transfers over Telegram, we design a cover channel with a regular schedule of images to have a high bandwidth. We found that the optimal resolution for message transfers is 2560x2560 at JPEG quality settings of 82. And that this configuration allows us to send an average of 81 kilobytes of data per image. Niklas Bunzel, Tobias Chen, Martin Steinebach |
ARES | 1 |
| 2020 | Non-blind steganalysisabstractThe increasing digitization offers new ways, possibilities and needs for a secure transmission of information. Steganography and its analysis constitute an essential part of IT-Security. In this work we show how methods of blind-steganalysis can be improved to work in non-blind scenarios. The main objective was to examine how to take advantage of the knowledge of reference images to maximize the accuracy-rate of the analysis. Niklas Bunzel, Martin Steinebach, Huajian Liu |
ARES | 1 |