VLDB 2026 Research / reviewers in the wild / expert
Juan Ramón Troncoso-Pastoriza
dblp:33/5866
· DBLP profile ↗
33ranked-venue papers
10as first author
11since 2021 · last 2023
0000-0001-8764-5570ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 5 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Scalable and Privacy-Preserving Federated Principal Component AnalysisabstractPrincipal component analysis (PCA) is an essential algorithm for dimensionality reduction in many data science domains. We address the problem of performing a federated PCA on private data distributed among multiple data providers while ensuring data confidentiality. Our solution, SF-PCA, is an end-to-end secure system that preserves the confidentiality of both the original data and all intermediate results in a passive-adversary model with up to all-but-one colluding parties. SF-PCA jointly leverages multiparty homomorphic encryption, interactive protocols, and edge computing to efficiently interleave computations on local cleartext data with operations on collectively encrypted data. SF-PCA obtains results as accurate as non-secure centralized solutions, independently of the data distribution among the parties. It scales linearly or better with the dataset dimensions and with the number of data providers. SF-PCA is more precise than existing approaches that approximate the solution by combining local analysis results, and between 3x and 250x faster than privacy-preserving alternatives based solely on secure multiparty computation or homomorphic encryption. Our work demonstrates the practical applicability of secure and federated PCA on private distributed datasets. David Froelicher, Hyunghoon Cho, Manaswitha Edupalli, João Sá Sousa, Jean-Philippe Bossuat, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Bonnie Berger, Jean-Pierre Hubaux |
SP | 7 |
| 2022 | Bootstrapping for Approximate Homomorphic Encryption with Negligible Failure-Probability by Using Sparse-Secret Encapsulation
Jean-Philippe Bossuat, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux |
ACNS | 2 |
| 2022 | Efficient protocols for oblivious linear function evaluation from ring-LWEabstractAn oblivious linear function evaluation protocol, or OLE, is a two-party protocol for the function f ( x ) = a x + b, where a sender inputs the field elements a, b, and a receiver inputs x and learns f ( x ). OLE can be used to build secret-shared multiplication, and is an essential component of many secure computation applications including general-purpose multi-party computation, private set intersection and more. In this work, we present several efficient OLE protocols from the ring learning with errors (RLWE) assumption. Technically, we build two new passively secure protocols, which build upon recent advances in homomorphic secret sharing from (R)LWE (Boyle et al. in: EUROCRYPT 2019, Part II (2019) 3–33 Springer), with optimizations tailored to the setting of OLE. We upgrade these to active security using efficient amortized zero-knowledge techniques for lattice relations (Baum et al. in: CRYPTO 2018, Part II (2018) 669–699 Springer), and design new variants of zero-knowledge arguments that are necessary for some of our constructions. Our protocols offer several advantages over existing constructions. Firstly, they have the lowest communication complexity amongst previous, practical protocols from RLWE and other assumptions; secondly, they are conceptually very simple, and have just one round of interaction for the case of OLE where b is randomly chosen. We demonstrate this with an implementation of one of our passively secure protocols, which can perform more than 1 million OLEs per second over the ring Z m , for a 120-bit modulus m, on standard hardware. Carsten Baum, Daniel Escudero 0001, Alberto Pedrouzo-Ulloa, Peter Scholl, Juan Ramón Troncoso-Pastoriza |
J. Comput. Secur. | 5 |
| 2022 | Privacy-Preserving and Efficient Verification of the Outcome in Genome-Wide Association StudiesabstractProviding provenance in scientific workflows is essential for reproducibility and auditability purposes. In this work, we propose a framework that verifies the correctness of the aggregate statistics obtained as a result of a genome-wide association study (GWAS) conducted by a researcher while protecting individuals' privacy in the researcher's dataset. In GWAS, the goal of the researcher is to identify highly associated point mutations (variants) with a given phenotype. The researcher publishes the workflow of the conducted study, its output, and associated metadata. They keep the research dataset private while providing, as part of the metadata, a partial noisy dataset (that achieves local differential privacy). To check the correctness of the workflow output, a verifier makes use of the workflow, its metadata, and results of another GWAS (conducted using publicly available datasets) to distinguish between correct statistics and incorrect ones. For evaluation, we use real genomic data and show that the correctness of the workflow output can be verified with high accuracy even when the aggregate statistics of a small number of variants are provided. We also quantify the privacy leakage due to the provided workflow and its associated metadata and show that the additional privacy risk due to the provided metadata does not increase the existing privacy risk due to sharing of the research results. Thus, our results show that the workflow output (i.e., research results) can be verified with high confidence in a privacy-preserving way. We believe that this work will be a valuable step towards providing provenance in a privacy-preserving way while providing guarantees to the users about the correctness of the results. Anisa Halimi, Leonard Dervishi, Erman Ayday, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux, Xiaoqian Jiang, Jaideep Vaidya |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Efficient Bootstrapping for Approximate Homomorphic Encryption with Non-sparse Keys
Jean-Philippe Bossuat, Christian Mouchet, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux |
EUROCRYPT (1) | 3 |
| 2021 | POSEIDON: Privacy-Preserving Federated Neural Network Learning
Sinem Sav, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, David Froelicher, Jean-Philippe Bossuat, João Sá Sousa, Jean-Pierre Hubaux |
NDSS | 3 |
| 2021 | Privacy and Integrity Preserving Computations with CRISP
Sylvain Chatel, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux |
USENIX Security Symposium | 3 |
| 2021 | Crypt4GH: a file format standard enabling native access to encrypted dataabstractMOTIVATION: The majority of genome analysis tools and pipelines require data to be decrypted for access. This potentially leaves sensitive genetic data exposed, either because the unencrypted data is not removed after analysis, or because the data leaves traces on the permanent storage medium. RESULTS: : We defined a file container specification enabling direct byte-level compatible random access to encrypted genetic data stored in community standards such as SAM/BAM/CRAM/VCF/BCF. By standardizing this format, we show how it can be added as a native file format to genomic libraries, enabling direct analysis of encrypted data without the need to create a decrypted copy. AVAILABILITY AND IMPLEMENTATION: The Crypt4GH specification can be found at: http://samtools.github.io/hts-specs/crypt4gh.pdf. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Alexander Senf, Robert Davies, Frédéric Haziza, John Marshall, Juan Ramón Troncoso-Pastoriza, Oliver Hofmann 0001, Thomas M. Keane |
Bioinform. | 5 |
| 2021 | SoK: Privacy-Preserving Collaborative Tree-based Model LearningabstractAbstract Tree-based models are among the most efficient machine learning techniques for data mining nowadays due to their accuracy, interpretability, and simplicity. The recent orthogonal needs for more data and privacy protection call for collaborative privacy-preserving solutions. In this work, we survey the literature on distributed and privacy-preserving training of tree-based models and we systematize its knowledge based on four axes: the learning algorithm, the collaborative model, the protection mechanism, and the threat model. We use this to identify the strengths and limitations of these works and provide for the first time a framework analyzing the information leakage occurring in distributed tree-based model learning. Sylvain Chatel, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Scalable Privacy-Preserving Distributed LearningabstractAbstract In this paper, we address the problem of privacy-preserving distributed learning and the evaluation of machine-learning models by analyzing it in the widespread MapReduce abstraction that we extend with privacy constraints. We designspindle(Scalable Privacy-preservINg Distributed LEarning), the first distributed and privacy-preserving system that covers the complete ML workflow by enabling the execution of a cooperative gradient-descent and the evaluation of the obtained model and by preserving data and model confidentiality in a passive-adversary model with up to N −1 colluding parties.spindleuses multiparty homomorphic encryption to execute parallel high-depth computations on encrypted data without significant overhead. We instantiatespindlefor the training and evaluation of generalized linear models on distributed datasets and show that it is able to accurately (on par with non-secure centrally-trained models) and efficiently (due to a multi-level parallelization of the computations) train models that require a high number of iterations on large input data with thousands of features, distributed among hundreds of data providers. For instance, it trains a logistic-regression model on a dataset of one million samples with 32 features distributed among 160 data providers in less than three minutes. David Froelicher, Juan Ramón Troncoso-Pastoriza, Apostolos Pyrgelis, Sinem Sav, João Sá Sousa, Jean-Philippe Bossuat, Jean-Pierre Hubaux |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Multiparty Homomorphic Encryption from Ring-Learning-with-ErrorsabstractAbstract We propose and evaluate a secure-multiparty-computation (MPC) solution in the semi-honest model with dishonest majority that is based on multiparty homomorphic encryption (MHE). To support our solution, we introduce a multiparty version of the Brakerski-Fan-Vercauteren homomorphic cryptosystem and implement it in an open-source library. MHE-based MPC solutions have several advantages: Their transcript is public, their o~ine phase is compact, and their circuit-evaluation procedure is noninteractive. By exploiting these properties, the communication complexity of MPC tasks is reduced from quadratic to linear in the number of parties, thus enabling secure computation among potentially thousands of parties and in a broad variety of computing paradigms, from the traditional peer-to-peer setting to cloud-outsourcing and smart-contract technologies. MHE-based approaches can also outperform the state-of-the-art solutions, even for a small number of parties. We demonstrate this for three circuits: private input selection with application to private-information retrieval, component-wise vector multiplication with application to private-set intersection, and Beaver multiplication triples generation. For the first circuit, privately selecting one input among eight thousand parties’ (of 32 KB each) requires only 1.31 MB of communication per party and completes in 61.7 seconds. For the second circuit with eight parties, our approach is 8.6 times faster and requires 39.3 times less communication than the current methods. For the third circuit and ten parties, our approach generates 20 times more triples per second while requiring 136 times less communication per-triple than an approach based on oblivious transfer. We implemented our scheme in the Lattigo library and open-sourced the code at github.com/ldsec/lattigo. Christian Mouchet, Juan Ramón Troncoso-Pastoriza, Jean-Philippe Bossuat, Jean-Pierre Hubaux |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | GenoShare: Supporting Privacy-Informed Decisions for Sharing Individual-Level Genetic Data
Jean Louis Raisaro, Juan Ramón Troncoso-Pastoriza, Yamane El-Zein, Mathias Humbert, Jacques Fellay, Carmela Troncoso, Jean-Pierre Hubaux |
AMIA | 2 |
| 2020 | SCOR: A secure international informatics infrastructure to investigate COVID-19abstractGlobal pandemics call for large and diverse healthcare data to study various risk factors, treatment options, and disease progression patterns. Despite the enormous efforts of many large data consortium initiatives, scientific community still lacks a secure and privacy-preserving infrastructure to support auditable data sharing and facilitate automated and legally compliant federated analysis on an international scale. Existing health informatics systems do not incorporate the latest progress in modern security and federated machine learning algorithms, which are poised to offer solutions. An international group of passionate researchers came together with a joint mission to solve the problem with our finest models and tools. The SCOR Consortium has developed a ready-to-deploy secure infrastructure using world-class privacy and security technologies to reconcile the privacy/utility conflicts. We hope our effort will make a change and accelerate research in future pandemics with broad and diverse samples on an international scale. Jean Louis Raisaro, Juan Ramón Troncoso-Pastoriza, Raphaelle Beau-Lejdstrom, Riccardo Bellazzi, Robert Murphy, Elmer V. Bernstam, Henry Wang, Mauro Bucalo, Yong Chen 0016, Assaf Gottlieb, Arif Ozgun Harmanci, Miran Kim, Yejin Kim 0001, Jeffrey G. Klann, Catherine Klersy, Bradley A. Malin, Marie Méan, Fabian Prasser, Luigia Scudeller, Ali Torkamani, Julien Vaucher, Mamta Puppala, Stephen T. C. Wong, Milana Frenkel-Morgenstern, Hua Xu 0001, Baba Maiyaki Musa, Abdulrazaq G. Habib, Trevor Cohen, Adam B. Wilcox, Hamisu M. Salihu, Heidi Sofia, Xiaoqian Jiang, Jean-Pierre Hubaux |
J. Am. Medical Informatics Assoc. | 3 |
| 2020 | Drynx: Decentralized, Secure, Verifiable System for Statistical Queries and Machine Learning on Distributed DatasetsabstractData sharing has become of primary importance in many domains such as big-data analytics, economics and medical research, but remains difficult to achieve when the data are sensitive. In fact, sharing personal information requires individuals’ unconditional consent or is often simply forbidden for privacy and security reasons. In this paper, we propose Drynx, a decentralized system for privacy-conscious statistical analysis on distributed datasets. Drynx relies on a set of computing nodes to enable the computation of statistics such as standard deviation or extrema, and the training and evaluation of machine-learning models on sensitive and distributed data. To ensure data confidentiality and the privacy of the data providers, Drynx combines interactive protocols, homomorphic encryption, zero-knowledge proofs of correctness, and differential privacy. It enables an efficient and decentralized verification of the input data and of all the system’s computations thus provides auditability in a strong adversarial model in which no entity has to be individually trusted. Drynx is highly modular, dynamic and parallelizable. Our evaluation shows that it enables the training of a logistic regression model on a dataset (12 features and 600,000 records) distributed among 12 data providers in less than 2 seconds. The computations are distributed among 6 computing nodes, and Drynx enables the verification of the query execution’s correctness in less than 22 seconds. David Froelicher, Juan Ramón Troncoso-Pastoriza, João Sá Sousa, Jean-Pierre Hubaux |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Revisiting Multivariate Lattices for Encrypted Signal ProcessingabstractMultimedia contents are inherently sensitive signals that must be protected when processed in untrusted environments. The field of Secure Signal Processing addresses this challenge by developing methods which enable operating with sensitive signals in a privacy-conscious way. Recently, we introduced a hard lattice problem called m-RLWE (multivariate Ring Learning with Errors) which gives support to efficient encrypted processing of multidimensional signals. Afterwards, Bootland et al. presented an attack to m-RLWE that reduces the security of the underlying scheme from a lattice with dimension \prod_in_i to \max\n_i\ _i . Our work introduces a new pre-/post-coding block that addresses this attack and achieves the efficient results of our initial approach while basing its security directly on RLWE with dimension \prod_in_i, hence preserving the security and efficiency originally claimed. Additionally, this work provides a detailed comparison between a conventional use of RLWE, m-RLWE and our new pre-/post-coding procedure, which we denote "packed''-RLWE. Finally, we discuss a set of encrypted signal processing applications which clearly benefit from the proposed framework, either alone or in a combination of baseline RLWE, m-RLWE and "packed''-RLWE. Alberto Pedrouzo-Ulloa, Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
IH&MMSec | 2 |
| 2019 | MedCo: Enabling Secure and Privacy-Preserving Exploration of Distributed Clinical and Genomic DataabstractThe increasing number of health-data breaches is creating a complicated environment for medical-data sharing and, consequently, for medical progress. Therefore, the development of new solutions that can reassure clinical sites by enabling privacy-preserving sharing of sensitive medical data in compliance with stringent regulations (e.g., HIPAA, GDPR) is now more urgent than ever. In this work, we introduce MedCo, the first operational system that enables a group of clinical sites to federate and collectively protect their data in order to share them with external investigators without worrying about security and privacy concerns. MedCo uses (a) collective homomorphic encryption to provide trust decentralization and end-to-end confidentiality protection, and (b) obfuscation techniques to achieve formal notions of privacy, such as differential privacy. A critical feature of MedCo is that it is fully integrated within the i2b2 (Informatics for Integrating Biology and the Bedside) framework, currently used in more than 300 hospitals worldwide. Therefore, it is easily adoptable by clinical sites. We demonstrate MedCo's practicality by testing it on data from The Cancer Genome Atlas in a simulated network of three institutions. Its performance is comparable to the ones of SHRINE (networked i2b2), which, in contrast, does not provide any data protection guarantee. Jean Louis Raisaro, Juan Ramón Troncoso-Pastoriza, Mickaël Misbach, João Sá Sousa, Sylvain Pradervand, Edoardo Missiaglia, Olivier Michielin, Bryan Ford, Jean-Pierre Hubaux |
IEEE ACM Trans. Comput. Biol. Bioinform. | 2 |
| 2018 | On Enforcing the Digital Immunity of a Large Humanitarian OrganizationabstractHumanitarian action, the process of aiding individuals in situations of crises, poses unique information-security challenges due to natural or manmade disasters, the adverse environments in which it takes place, and the scale and multi-disciplinary nature of the problems. Despite these challenges, humanitarian organizations are transitioning towards a strong reliance on the digitization of collected data and digital tools, which improves their effectiveness but also exposes them to computer security threats. In this paper, we conduct a qualitative analysis of the computer-security challenges of the International Committee of the Red Cross (ICRC), a large humanitarian organization with over sixteen thousand employees, an international legal personality, which involves privileges and immunities, and over 150 years of experience with armed conflicts and other situations of violence worldwide. To investigate the computer security needs and practices of the ICRC from an operational, technical, legal, and managerial standpoint by considering individual, organizational, and governmental levels, we interviewed 27 field workers, IT staff, lawyers, and managers. Our results provide a first look at the unique security and privacy challenges that humanitarian organizations face when collecting, processing, transferring, and sharing data to enable humanitarian action for a multitude of sensitive activities. These results highlight, among other challenges, the trade offs between operational security and requirements stemming from all stakeholders, the legal barriers for data sharing among jurisdictions; especially, the need to complement privileges and immunities with robust technological safeguards in order to avoid any leakages that might hinder access and potentially compromise the neutrality, impartiality, and independence of humanitarian action. Stevens Le Blond, Alejandro Cuevas, Juan Ramón Troncoso-Pastoriza, Philipp Jovanovic, Bryan Ford, Jean-Pierre Hubaux |
IEEE Symposium on Security and Privacy | 3 |
| 2017 | Secure genomic susceptibility testing based on lattice encryptionabstractRecent advances in Next Generation Sequencing have increased the availability of genomic data for more accurate analyses, like testing for the genetic susceptibility to a disease. Current laboratories' facilities cannot cope with this data growth, and genomic processing needs to be outsourced, comprising serious privacy risks. This work proposes an encrypted genomic susceptibility test protocol based on lattice homomorphic cryptosystems, and introduces optimizations like data packing and transformed processing to achieve considerable gains in performance, bandwidth and storage needs. Juan Ramón Troncoso-Pastoriza, Alberto Pedrouzo-Ulloa, Fernando Pérez-González |
ICASSP | 1 |
| 2017 | ORide: A Privacy-Preserving yet Accountable Ride-Hailing Service
Anh Pham, Italo Dacosta, Guillaume Endignoux, Juan Ramón Troncoso-Pastoriza, Kévin Huguenin, Jean-Pierre Hubaux |
USENIX Security Symposium | 4 |
| 2017 | Number Theoretic Transforms for Secure Signal ProcessingabstractMultimedia contents are inherently sensitive signals that must be protected whenever they are outsourced to an untrusted environment. This problem becomes a challenge when the untrusted environment must perform some processing on the sensitive signals; a paradigmatic example is Cloud-based signal processing services. Approaches based on Secure Signal Processing (SSP) address this challenge by proposing novel mechanisms for signal processing in the encrypted domain and interactive secure protocols to achieve the goal of protecting signals without disclosing the sensitive information they convey. This paper presents a novel and comprehensive set of approaches and primitives to efficiently process signals in an encrypted form, by using Number Theoretic Transforms (NTTs) in innovative ways. This usage of NTTs paired with appropriate signal pre-and post-coding enables a whole range of easily composable signal processing operations comprising, among others, filtering, generalized convolutions, matrix-based processing or error correcting codes. Our main focus is on unattended processing, in which no interaction from the client is needed; for implementation purposes, efficient lattice-based somewhat homomorphic cryptosystems are used. We exemplify these approaches and evaluate their performance and accuracy, proving that the proposed framework opens up a wide variety of new applications for secured outsourced-processing of multimedia contents. Alberto Pedrouzo-Ulloa, Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Co-creating Security-and-Privacy-by-Design SystemsabstractThe elicitation and the analysis of security and privacy requirements are generally intended as being mainly performed by field experts. In this paper we show how it is possible to integrate practical Co-Creation processes into Security-and-Privacy-by-Design methodologies. In addition, we present some guidelines showing how it is possible to translate the high-level requirements obtained from the end-user engaging into verifiable low-level requirements and technological requirements. The paper demonstrates as well the feasibility of our approach by applying it in two realistic scenarios where the outsourcing of personal and sensitive data requires high-level of security and privacy. Sauro Vicini, Francesco Alberti, Nicolás Notario, Alberto Crespo, Juan Ramón Troncoso-Pastoriza, Alberto Sanna |
ARES | 5 |
| 2016 | Dynamic Privacy-Preserving Genomic Susceptibility TestingabstractThe field of genomic research has considerably grown in the recent years due to the unprecedented advances brought about by Next Generation Sequencing (NGS) and the need and increasing widespread use of outsourced processing. But this rapid increase also poses severe privacy risks due to the inherently sensitive nature of genomic information. In this work, we address privacy-preserving genetic susceptibility tests outsourced to an untrustworthy party, enhancing previous approaches in terms of computation and communication efficiency by leveraging the use of somewhat homomorphic lattice encryption and relinearization operations to achieve more efficient constructions. Additionally, we also propose a more general construction which deals with several different medical units (such as pharmaceutical companies or hospitals), managing patients' consent to the disclosure of test results for each of these units, which may dynamically join the system. Our scheme features an attribute-based homomorphic cryptosystem which enables enforcing the patient's access policy referred to the different medical units. Mina Namazi, Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
IH&MMSec | 2 |
| 2015 | Multivariate lattices for encrypted image processingabstractImages are inherently sensitive signals that require privacy-preserving solutions when processed in an untrusted environment, but their efficient encrypted processing is particularly challenging due to their structure and size. This work introduces a new cryptographic hard problem called m-RLWE (multivariate Ring Learning with Errors) extending RLWE. It gives support to lattice cryptosystems that allow for encrypted processing of multidimensional signals. We show an example cryptosystem and prove that it outperforms its RLWE counterpart in terms of security against basis-reduction attacks, efficiency and cipher expansion for encrypted image processing. Alberto Pedrouzo-Ulloa, Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
ICASSP | 2 |
| 2013 | Fully Private Noninteractive Face VerificationabstractFace recognition is one of the foremost applications in computer vision, which often involves sensitive signals; privacy concerns have been raised lately and tackled by several recent privacy-preserving face recognition approaches. Those systems either take advantage of information derived from the database templates or require several interaction rounds between client and server, so they cannot address outsourced scenarios. We present a private face verification system that can be executed in the server without interaction, working with encrypted feature vectors for both the templates and the probe face. We achieve this by combining two significant contributions: 1) a novel feature model for Gabor coefficients' magnitude driving a Lloyd-Max quantizer, used for reducing plaintext cardinality with no impact on performance; 2) an extension of a quasi-fully homomorphic encryption able to compute, without interaction, the soft scores of an SVM operating on quantized and encrypted parameters, features and templates. We evaluate the private verification system in terms of time and communication complexity, and in verification accuracy in widely known face databases (XM2VTS, FERET, and LFW). These contributions open the door to completely private and noninteractive outsourcing of face verification. Juan Ramón Troncoso-Pastoriza, Daniel González-Jiménez, Fernando Pérez-González |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | Fully homomorphic facesabstractFace recognition is a prominent application of image processing. It is also a very sensitive application, and privacy concerns have been lately raised and tackled in several recent papers dealing with privacy-preserving face recognition systems. Nevertheless, the presented systems either use the knowledge of some information derived from the database templates in order to perform the recognition or require several interaction rounds between client and server. In this paper, we propose a private system that can cope with a simple verification algorithm executed in the server without interaction (using a quasi-fully homomorphic encryption and an efficient face features representation with Lloyd-Max quantized Gabor jets), in which both the templates and the queried face are encrypted; we show its performance in terms of time complexity and size of transferred encryptions, as well as in verification accuracy with respect to the non-private system. This opens the door to completely private and noninteractive outsourcing of face recognition. Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
ICIP | 1 |
| 2011 | Encrypted Domain Processing for Cloud Privacy - Concept and Practical Experience
Daniel A. Rodríguez-Silva, Francisco Javier González-Castaño, Lilian Adkinson-Orellana, A. Fernández-Cordeiro, Juan Ramón Troncoso-Pastoriza, David González-Martínez |
CLOSER | 5 |
| 2011 | Efficient protocols for secure adaptive filteringabstractThe field of Signal Processing in the Encrypted Domain (SPED) has emerged in order to provide efficient and secure solutions for pre serving privacy of signals that are processed by untrusted agents. In this work, we study the privacy problem of adaptive filtering, one of the most important and ubiquitous blocks in signal processing nowadays. We examine several use cases along with their privacy characteristics, constraints and requirements, that differ in several aspects from those of the already tackled linear filtering and classification problems. Due to the impossibility of using a strategy based solely on current homomorphic encryption systems, we pro pose novel secure protocols for a privacy-preserving execution of the BLMS (Block Least Mean Squares) algorithm, combining different SPED techniques, and paying special attention to the trade-off between computational complexity, bandwidth, and the error produced due to finite-precision implementations. Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
ICASSP | 1 |
| 2011 | Secure Adaptive FilteringabstractIn an increasingly connected world, the protection of digital data when it is processed by other parties has arisen as a major concern for the general public, and an important topic of research. The field of Signal Processing in the Encrypted Domain (SPED) has emerged in order to provide efficient and secure solutions for preserving privacy of signals that are processed by untrusted agents. In this work, we study the privacy problem of adaptive filtering, one of the most important and ubiquitous blocks in signal processing today. We present several use cases for adaptive signal processing, studying their privacy characteristics, constraints, and requirements, that differ in several aspects from those of the already tackled linear filtering and classification problems. We show the impossibility of using a strategy based solely on current homomorphic encryption systems, and we propose several novel secure protocols for a privacy-preserving execution of the least mean squares (LMS) algorithm, combining different SPED techniques, and paying special attention to the error analysis of the finite-precision implementations. We seek the best trade-offs in terms of error, computational complexity, and used bandwidth, showing a comparison among the different alternatives in these terms, and we provide the experimental results of a prototype implementation of the presented protocols, as a proof of concept that showcases the viability and efficiency of our novel solutions. The obtained results and the proposed solutions are straightforwardly extensible to other adaptive filtering algorithms, providing a basis and master guidelines for their privacy-preserving implementation. Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | A new model for Gabor coefficients' magnitude in face recognitionabstractGabor filters have demonstrated their effectiveness in automatic face recognition, which can greatly benefit from an accurate statistical model for Gabor-based face representations. Previous approaches have modeled real and imaginary parts independently as Generalized Gaussians (GG). Since most Gabor-based face recognition systems discard coefficients' phase, we propose a novel statistical model for the magnitude of Gabor coefficients that accounts for the dependence between real and imaginary parts, assuming they are circularly symmetric and marginally GG distributed. The quality of the fit for our model is assessed using the Kullback-Leibler divergence, and optimal quantization of Gabor coefficients is shown as one of its applications. Juan Ramón Troncoso-Pastoriza, Daniel González-Jiménez, Fernando Pérez-González |
ICASSP | 1 |
| 2009 | Videosurveillance and privacy: covering the two sides of the mirror with DRMabstractPrivacy and security have always been key concerns for individuals. They have also been closely related concepts: in order to increase their perception of security, people sacrifice a part of their privacy by accepting to be surveilled by others. The tradeoff between both is usually reasonable and commonly accepted; however, the case of videosurveillance systems has been particularly controversial since their inception, as their benefits are not perceived to compensate for the privacy loss in many cases. The situation has become even worse during the last years with the massive deployment of these systems, which often do not provide satisfactory guarantees for the citizens. This paper proposes a DRM-based framework for videosurveillance to achieve a better balance between both concepts: it protects privacy of the surveilled individuals, whilst giving support to efficient automated surveillance. Juan Ramón Troncoso-Pastoriza, Pedro Comesaña Alfaro, Luis Pérez-Freire, Fernando Pérez-González |
Digital Rights Management Workshop | 1 |
| 2009 | Skewed log-stable model for natural images pixel block-varianceabstractThis work presents a log-stable model for natural images block-variance. Exponential and halfnormal distributions have been previously used to model block-variance, but they were employed to fit images for which the assumption of constant intra-block variance does not hold. We show that when this assumption holds, the log-stable model yields a much better fit in an ML sense. We use a computationally efficient method for estimating the log-stable parameters through the empirical Kullback-Leibler divergence, which is asymptotically optimum in an ML sense, and show the validity of the lognormal distribution as an approximation with closed-form formulas for the ML parameter estimation. Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
ICIP | 1 |
| 2007 | Privacy preserving error resilient dna searching through oblivious automataabstractHuman Desoxyribo-Nucleic Acid (DNA) sequences offer a wealth of information that reveal, among others, predisposition to various diseases and paternity relations. The breadth and personalized nature of this information highlights the need for privacy-preserving protocols. In this paper, we present a new error-resilient privacy-preserving string searching protocol that is suitable for running private DNA queries. This protocol checks if a short template (e.g., a string that describes a mutation leading to a disease), known to one party, is present inside a DNA sequence owned by another party, accounting for possible errors and without disclosing to each party the other party's input. Each query is formulated as a regular expression over a finite alphabet and implemented as an automaton. As the main technical contribution, we provide a protocol that allows to execute any finite state machine in an oblivious manner, requiring a communication complexity which is linear both in the number of states and the length of the input string. Juan Ramón Troncoso-Pastoriza, Stefan Katzenbeisser 0001, Mehmet Utku Celik |
CCS | 1 |
| 2007 | Efficient Zero-Knowledge Watermark Detection with Improved Robustness to Sensitivity Attacks
Juan Ramón Troncoso-Pastoriza, Fernando Pérez-González |
EURASIP J. Inf. Secur. | 1 |