VLDB 2026 Research / reviewers in the wild / expert
Dengpan Ye
dblp:39/9365
· DBLP profile ↗
69ranked-venue papers
4as first author
47since 2021 · last 2026
0000-0003-2510-9523ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 32 · 2 first-author · 24 since 2021Security and privacy · 17 · 1 first-author · 11 since 2021Artificial intelligence and machine learning · 11 · 2 first-author · 8 since 2021Computer networks · 11 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Time Shuffle: A Transferability-Booster for Multiple Audio Adversarial TasksabstractExisting audio adversarial attack methods suffer from poor transferability, primarily due to insufficient exploration of model decision mechanisms and overreliance on heuristic-driven algorithm design. This paper aims to alleviate this gap. Specifically, through observations across three mainstream audio tasks (Automatic Speech Recognition, Speaker Verification, and Keyword Spotting), we reveal that these models primarily rely on local temporal features—inputs with time shuffled retain 83.7% of original accuracy. The SHAP-based visualization further validated that time shuffle leads to a significant shift in the salient regions of the model, but the samples can still be correctly identified, indicating the presence of redundant features that can affect decision-making. Inspired by these findings, we propose Time-Shuffle (TS) adversarial attack (including segments-based TS and phoneme-level-based TS-p). This method divides audio or phonemes into segments, randomly shuffles them, and computes gradients on the shuffled structure. By forcing perturbations to exploit transferable local temporal features and reduce overfitting to source-specific patterns, TS/TS-p inherently enhances transferability. As a model-agnostic framework, TS/TS-p can seamlessly integrate with existing attack methods. Comprehensive experiments demonstrate that TS-p achieved SOTA and boosts transferability by about 23%/14.7%/6.3% on ASR/ASV/KWS. Jiacheng Deng 0001, Dengpan Ye, Zhaolin Wei, Ziyi Liu 0009 |
AAAI | 2 |
| 2026 | SHARP: Self-adaptive Harmful Category-aware Prompt Generation for Black-box JailbreakingabstractLarge Language Models (LLMs) have been widely applied in various domains such as education and healthcare, making safety assurance crucial.Jailbreak attacks, a method used in red-teaming, can help evaluate and improve the defensive strategies of LLMs.However, existing jailbreak methods often overlook the semantic differences across categories of harmful questions, leading to inconsistent success rates and reduced overall attack effectiveness.We propose the first category-aware jailbreak framework, SHARP, which incorporates the semantic category of harmful questions into prompt generation.Trained on a verified jailbreak dataset, SHARP enables the model to learn category-specific semantic features and adaptively generate prompts that bypass safety mechanisms.The method combines two-stage LoRA fine-tuning, and DPO-based reinforcement learning to optimize both attack success and category alignment.Experiments show that SHARP significantly improves attack success rates and achieves better cross-category robustness compared to the state-of-the-art (SOTA) baselines, providing an efficient and scalable tool for evaluating LLM safety. Yingjie Xue, Xingyou Xia, Yunbo Cao, Dengpan Ye, Guotong Geng |
ACL (1) | 5 |
| 2026 | Omni-I2C: A Holistic Benchmark for High-Fidelity Image-to-Code GenerationabstractJiawei Zhou, Chi Zhang, Xiang Feng, Qiming Zhang, Haibo Qiu, Lihuo He, Dengpan Ye, Xinbo Gao, Jing Zhang. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Chi Zhang 0080, Qiming Zhang 0001, Haibo Qiu, Lihuo He, Dengpan Ye, Xinbo Gao 0001, Jing Zhang 0037 |
ACL (1) | 7 |
| 2026 | Universal Transferable Dual Attack on Anti-Spoofing and Recognition in Facial Security Systems
Sirun Chen, Sipeng Shen, Ziyi Liu 0009, Yueyun Shang, Dengpan Ye |
ICIC (16) | 6 |
| 2026 | Perceptual V-Cloak: Generating Trainable and Unintelligible Speech Dataset
Dengpan Ye, Jiacheng Deng 0001, Zhaolin Wei, Ziyi Liu 0009 |
ICIC (2) | 2 |
| 2026 | MSFT-Net: Mixture Semantic-Agnostic Manipulation Trace Enhanced Architecture for Robust Image Manipulation LocalizationabstractSince the proliferation of image manipulation methods, effective image manipulation localization (IML) in scenarios with post-processing operations gradually becomes a core challenge. For a long time, IML either relies on strongly semantically related features, resulting in semantic relevance bias in the localization results, or only uses a single semantic-agnostic space feature, which is unable to maintain effective localization capabilities after image post-processing operations. Inspired by this, we propose a novel mixture semantic-agnostic manipulation trace robust localization network (MSFT-Net), which specifically utilizes mixture semantic-agnostic information to achieve effective and robust IML. The MSFT-Net introduces two new modules, the mixture shared manipulation trace enhancement module (MISE) and the Multiscale Feature Association Module (FAM). MISE dynamically links multiple semantic-agnostic feature extractors using a sparsity-enhanced mixture of shared experts, enabling the extraction of diverse manipulation features for accurate localization. Furthermore, keeping the high resolution of the localization features is very important in the mask prediction stage. Therefore, FAM outputs high-resolution fused manipulation features by using the correlation of features at the same level and the spatial context information from different levels. This further improves the effectiveness of IML in post-processing scenarios. Comprehensive experiments on five datasets demonstrate that our model significantly improves both in localization accuracy (average F1 score and IoU increasing by over 9.9% and 4.0%) and robustness. The codes will be made available. Dengpan Ye, Yunming Zhang, Jiacheng Deng 0001, Ziyi Liu 0009, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2026 | Take Fake as Real: Realistic-Like Robust Black-Box Adversarial Attack to Evade AIGC DetectionabstractThe security of AI-generated content (AIGC) detection is crucial for ensuring multimedia content credibility. To enhance detector security, research on adversarial attacks has become essential. However, most existing adversarial attacks focus only on GAN-generated facial images detection, struggle to be effective on multi-class natural images and diffusion-based detectors, and exhibit poor invisibility. To fill this gap, we first conduct an in-depth analysis of the vulnerability of AIGC detectors and discover the feature that detectors vary in vulnerability to different post-processing. Then, considering that the detector is agnostic in real-world scenarios and given this discovery, we propose a Realistic-like Robust Black-box Adversarial attack (R2BA) with post-processing fusion optimization. Unlike typical perturbations, R2BA uses real-world post-processing, i.e., Gaussian blur, JPEG compression, Gaussian noise and light spot to generate adversarial examples. Specifically, we use a stochastic particle swarm algorithm with inertia decay to optimize post-processing fusion intensity and explore the detector’s decision boundary. Guided by the detector’s fake probability, R2BA enhances/weakens the detector-vulnerable/detector-robust post-processing intensity to strike a balance between adversariality and invisibility. Extensive experiments on popular/commercial AIGC detectors and datasets demonstrate that R2BA exhibits impressive anti-detection performance, excellent invisibility, and strong robustness in GAN-based and diffusion-based cases. Compared to state-of-the-art white-box and black-box attacks, R2BA shows significant improvements of 15%–72% and 21%–47% in anti-detection performance under the original and robust scenario respectively, offering valuable insights for the security of AIGC detection in real-world applications. Caiyun Xie, Dengpan Ye, Yunming Zhang, Yueyun Shang, Yunna Lv, Jiacheng Deng 0001, Jiawei Song |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2026 | DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial WatermarkabstractThe wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted authorizers, exacerbating the potential threat of identity impersonation. To address this, we propose the first double identity protection scheme based on traceable adversarial watermarking, termed DIP-Watermark. DIP-Watermark employs a one-time watermark embedding to deceive unauthorized FR models and allows authorizers to perform identity verification by extracting the watermark. Specifically, we propose an information-guided adversarial attack against FR models. The encoder embeds an identity-specific watermark into the deep feature space of the carrier, guiding recognizable features of the image to deviate from the source identity. We further adopt a collaborative meta-optimization strategy compatible with sub-tasks, which regularizes the joint optimization direction of the encoder and decoder. This strategy enhances the representation of universal carrier features, mitigating multi-objective optimization conflicts in watermarking. Extensive experiments on two large-scale facial datasets demonstrate that DIP-Watermark achieves significant attack success rates and traceability accuracy on state-of-the-art FR models and commercial APIs. It also exhibits superior robustness against a wide range of real-world simulated distortions, outperforming existing privacy protection methods based on adversarial attacks, deep watermarking, or their simple combination. Our work potentially opens up new insights into proactive protection for FR privacy. Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen, Ziyi Liu 0009, Jiacheng Deng 0001, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition ModelsabstractWhile face recognition (FR) models have brought remarkable convenience in face verification and identification, they also pose substantial privacy risks to the public. Existing facial privacy protection schemes usually adopt adversarial examples to disrupt face verification of FR models. However, these schemes often suffer from weak transferability against black-box FR models and permanently damage the identifiable information that cannot fulfill the requirements of authorized operations such as forensics and authentication. To address these limitations, we proposeErasableMask, a robust and erasable privacy protection scheme against black-box FR models. Specifically, via rethinking the inherent relationship between surrogate FR models, ErasableMask introduces a novel meta-auxiliary attack, which boosts black-box transferability by learning more general features in a stable and balancing optimization strategy. It also offers a perturbation erasion mechanism that supports the erasion of semantic perturbations in protected face without degrading image quality. To further improve performance, ErasableMask employs a curriculum learning strategy to mitigate optimization conflicts between adversarial attack and perturbation erasion. Extensive experiments on the CelebA-HQ and FFHQ datasets demonstrate that ErasableMask achieves the state-of-the-art performance in transferability, achieving over72%mean confidence in commercial FR systems. Moreover, ErasableMask also exhibits outstanding perturbation erasion performance, achieving over90%erasion success rate. Sipeng Shen, Yunming Zhang, Dengpan Ye, Xiuwen Shi, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Multim. | 3 |
| 2026 | Take Attention as Gate: An Associative Recurrent Network-Based Intrusion Detection Method for Industrial Control NetworkabstractThe Industrial Control Network (ICN), which is characterized by real-time responsiveness and reliability, plays a key role in increasing production speed, ensuring efficient processing, and managing industrial processes. Despite tremendous advantages, ICN inevitably struggles with some challenges, such as malicious user intrusion and hacker attacks. To detect malicious intrusions in ICN, Intrusion Detection Systems (IDS) have been deployed. However, network traffic in ICN often exhibits significant temporal periodicity, and computational resources are limited on edge nodes and infrastructure gateway devices. These characteristics pose significant challenges to the design and performance of IDS. To properly solve these problems, we design a new intrusion detection method for ICN. Specifically, we first design a novel neural network model called Associative Recurrent Network (ARN), which can properly handle the relationship between previous hidden state and current input. Then, we construct a novel intrusion detection method based on the ARN, which avoids gating conflicts in traditional Recurrent Neural Network (RNN), effectively captures the temporal characteristics of ICN traffic, and maintains slightly higher computational overhead than GRU, thus demonstrating good adaptability to industrial control networks. Subsequently, through theoretical analysis of computational complexity, we demonstrate that the proposed method achieves high computational efficiency, comparable to mainstream RNN methods and superior to Transformer methods. Finally, we implement a prototype system to evaluate detection accuracy. Experimental results show that our method achieves state-of-the-art performance on the industrial control systems datasets (ICS-ADD and SWaT) and the conventional network dataset (UNSW-NB15), with average accuracies of 98.93%, 95.57%, and 98.27%, respectively. Ziyi Liu 0009, Dengpan Ye, Yong Ding 0005, Yueling Liu, Chuanxi Chen |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Generalize Audio Deepfake Algorithm Recognition via Attribution EnhancementabstractThe development of voice cloning techniques has made forgery audios indistinguishable, posing an urgency to trace their sources. Many existing works focus on improving identification accuracy for audio deepfake algorithm recognition. However, most methods ignore the impact of complex information in audio signals on attribution. In this paper, we propose an audio deepfake attribution enhancement (ADAE) strategy, which aims to magnify the fingerprints of generation styles by removing the speaker information. This is achieved through an information disentangle block with an extra speaker encoder. In addition, we propose the FakeSource dataset, a novel audio deepfake algorithm recognition dataset that contains 25 different voice cloning algorithms, to address the constraint of data scarcity. Experiments on the FakeSource dataset demonstrate that ADAE improves the performance of unseen algorithm detection. We also assess ADAE on a more challenging training-free task which shows competitive performance. Dengpan Ye, Jiacheng Deng 0001 |
ICASSP | 2 |
| 2025 | From Voices to Beats: Enhancing Music Deepfake Detection by Identifying Forgeries in BackgroundabstractMusic deepfake detection is aimed at identifying whether songs are generated by AI. Current methods usually separate vocals from background music for detection, but this could leave residual forgery information in the background. Our study demonstrates for the first time that incorporating background forgery information with vocals can improve detection accuracy. Furthermore, our findings show that using background features can reduce EER by an average of about 2% on existing frameworks. Based on this observation, we propose a novel Hybrid Frontend that captures generalized features from both vocal and background music. The Hybrid Frontend comprises two branches: vocal and background music part. Specifically, the vocal part uses the Sinconv encoder as a deeply embedded feature extractor. The latter captures background variation by fine-tuning the pre-trained model with adapters. Experimental results demonstrate that our method outperforms the vocal-only detection on WildSVDD dataset, achieving an EER of 8.53%, which is 1.3% lower. Zhaolin Wei, Dengpan Ye, Jiacheng Deng 0001 |
ICASSP | 2 |
| 2025 | Relational Graph Attention Network Combined with Burst Position Encoding for Traffic ClassificationabstractNetwork traffic classification has become an essential technology for information service providers. While existing methods predominantly focus on packet-level features such as port numbers and payload content, they fundamentally overlook the dynamic interaction patterns revealed by traffic burst sequences and the inherent relational characteristics between consecutive traffic bursts. To overcome the limitation of existing methods, we design a new burst position relational graph attention network (BP-RGAT) for traffic classification. We introduce the Heterogeneous Traffic Burst Graph (HTBG) to obtain more traffic interaction information. We also incorporate Relative Traffic Burst Position Encoding (RBPE) to capture sequence information between bursts. To evaluate the performance of BPRGAT, we conduct experiments with ISCX-VPN and USTC-TFC datasets. The results show that BP-RGAT achieves the highest F1 score compared to existing baseline methods (e.g. NetMamba, ET-BERT, BehavSniffer, TFE-GNN). Siji Chen, Xi Xiao 0001, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan, Dengpan Ye |
IWQoS | 8 |
| 2025 | PhonoFence: A Cross-Task Defense Framework for DeepFake via Phoneme-Level Adversarial Perturbations
Zhaolin Wei, Xiuwen Shi, Dengpan Ye, Jiacheng Deng 0001, Ziyi Liu 0009 |
ACM Multimedia | 3 |
| 2025 | BALANCE: A Fairness-Aware Framework for Privacy-Preserving Synthetic Clinical Text GenerationabstractElectronic health-record narratives enable valuable data-driven clinical applications but raise acute risks of privacy leakage and demographic bias. We present Balance, the Bias-Aware, Leakage-avoidant ANonymized Clinical Engine, a fairness-aware clinical text synthesis framework that integrates group-aware entity auditing, fairness-aware k-anonymization, and few-shot LLM generation. On the MIMIC-III discharge-summary corpus, Balance reduces attacker re-identification accuracy, halves coverage gaps between sex and age cohorts, and preserves comparable semantic fidelity. Downstream models trained on Balance-generated corpora maintain or improve performance on clinical NER, readmission prediction, ICD-10 coding, and phenotyping. These results demonstrate that strong privacy protection and equitable representation can be achieved without compromising utility. Dengpan Ye |
MMAsia | 2 |
| 2025 | AdvLUT: Cloaking Geographic Location With Semantic-Based Adversarial 3-D Lookup TablesabstractThe proliferation of Internet of Things (IoT) devices equipped with cameras, such as those in electric vehicles, has increased the collection of personal image data. However, the potential misuse of cross-view geo-localization (CVGL) models, which can infer precise locations from ground view images, has been overlooked and seriously threatens individual location privacy. In this article, we introduce AdvLUT, a novel semantic-based adversarial 3-D lookup tables (3DLUTs) privacy protection framework designed to safeguard geographic location privacy against CVGL models. The AdvLUT employs a geographic feature encoder to extract semantic features rich in geographic information from the ground view input. These features then guide a specialized adversarial 3DLUT generator in producing a 3DLUT that alters the color properties of the input image, thereby obstructing accurate location inference. Furthermore, AdvLUT is designed with a generative architecture that enables rapid image processing within milliseconds, eliminating the need for the corresponding satellite image or CVGL model. Experimental results on multiple benchmark datasets and CVGL models demonstrate that our method achieves up to a 65.48% reduction in R@1 localization accuracy, with performance further improving to 69.25% after JPEG compression. Yiheng He, Dengpan Ye, Ziyi Liu 0009, Chuanxi Chen |
IEEE Internet Things J. | 2 |
| 2025 | Trinity Detector: Text-Assisted and Attention Mechanisms Based Spectral Fusion for Diffusion Generation Image DetectionabstractArtificial Intelligence Generated Content (AIGC) techniques, represented by text-to-image generation, have led to a malicious use of deep forgeries, raising concerns about the trustworthiness of multimedia content. Experimental results demonstrate that traditional forgery detection methods perform poorly in adapting to diffusion model-generated scenarios, while existing diffusion-specific techniques lack robustness against post-processed images. In response, we propose the Trinity Detector, which integrates coarse-grained text features from a Contrastive Language-Image Pretraining (CLIP) encoder with fine-grained artifacts in the pixel domain to achieve semantic-level image detection, significantly enhancing model robustness. To enhance sensitivity to diffusion-generated image features, a Multi-spectral Channel Attention Fusion Unit (MCAF) is designed. It adaptively fuses multiple preset frequency bands, dynamically adjusting the weight of each band, and then integrates the fused frequency-domain information with the spatial co-occurrence of the two modalities. Extensive experiments validate that our Trinity Detector improves transfer detection performance across black-box datasets by an average of 14.3% compared to previous diffusion detection models and demonstrating superior performance on post-processed image datasets. Jiawei Song, Dengpan Ye, Yunming Zhang |
IEEE Signal Process. Lett. | 2 |
| 2025 | Toward a Universal, Transferable, and Robust Adversarial Perturbation Framework Against Deep Hashing-Based Facial Image RetrievalabstractDeep Hashing (DH) based image retrieval is commonly used in facial recognition systems for its precision and effectiveness. However, this convenience is accompanied by a mounting threat to privacy. The DH model possesses vulnerability to adversarial attacks, which can be leveraged to prevent the retrieval of private images. Current adversarial attacks on DH models commonly focus on individual images or specific categories, lacking universal perturbations for the entire hashing dataset. This paper introduces the UTAP series, the first universal, transferable, and robust adversarial perturbation against DH facial image retrieval, safeguarding all images with a single perturbation. We explore the relationships between clusters learned by different DH models and define the optimization goal for optimizing UTAP series as moving away from the voted overall hashcenter. To alleviate the challenges of single-objective optimization, we randomly vote for sub-cluster centers and propose sub-task-based meta-learning to aid global optimization. Furthermore, we dissect the functional roles of key components in DH models and introduce UTAP++, a feature-hashing two-stage attack that is readily adaptable to cross-model and cross-scheme ensemble adversarial attacks. Extensive experiments conducted on renowned face datasets and DH models under varied complex scenarios, encompassing cross-image, cross-model, cross-bit, cross-algorithm, model ensemble, algorithm ensemble, and image compression, reveal that the UTAP series demonstrate remarkable universality, transferability, and robustness in preventing facial image retrieval. Compared to existing state-of-the-art methods, the UTAP series excel in white-box settings and exhibits significant transferability improvements of$10\%-70\%$in all black-box settings, with 20% and 55% average robustness improvements in white-box and black-box settings, respectively. These findings underscore the practical value of the UTAP series in real-world, presenting novel effective defense strategies against unauthorized facial image retrieval. Yunna Lv, Dengpan Ye, Yiheng He, Ziyi Liu 0009, Caiyun Xie |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2025 | Three-in-One: Robust Enhanced Universal Transferable Anti-Facial Retrieval in Online Social NetworksabstractDeep hash-based retrieval techniques are widely used in facial retrieval systems to improve the efficiency of facial matching. However, it also carries the danger of exposing private information. Deep hash models are easily influenced by adversarial examples, which can be leveraged to protect private images from malicious retrieval. The existing adversarial example methods against deep hash models focus on universality and transferability, lacking the research on its robustness in online social networks (OSNs), which leads to their failure in anti-retrieval after post-processing. Therefore, we provide the first in-depth discussion on robustness in universal transferable anti-facial retrieval and propose Three-in-One Adversarial Perturbation (TOAP). Specifically, we construct a local and global Compression Generator (CG) to simulate complex post-processing scenarios, which can be used to mitigate perturbation. Then, we propose robust optimization objectives based on the discovery of the variation patterns of model’s distribution after post-processing, and generate adversarial examples using these objectives and meta-learning. Finally, we iteratively optimize perturbation by alternately generating adversarial examples and fine-tuning the CG, balancing the performance of perturbation while enhancing CG’s ability to mitigate them. Numerous experiments demonstrate that, in addition to its advantages in universality and transferability, TOAP significantly outperforms current state-of-the-art methods in multiple robustness metrics. It further improves universality and transferability by 5% to 28%, and achieves up to about 33% significant improvement in several simulated post-processing scenarios as well as mainstream OSNs, demonstrating that TOAP can effectively protect private images from malicious retrieval in real-world scenarios. Yunna Lv, Dengpan Ye, Caiyun Xie, Jiacheng Deng 0001, Yiheng He, Sipeng Shen |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | StyleMark: Robust Style Watermarking for Artworks Against Black-Box Zero-Shot Style TransferabstractZero-shot style transfer(ZSST) enables the rendering of real-world natural images into the painting styles of arbitrary artworks without requiring fine-tuning on unseen artistic styles. This low-cost and efficient approach to artistic recreation promotes the dissemination and communication of art. However, misuse of unauthorized artistic style images for ZSST may infringe on the copyrights of artists. One countermeasure is robust watermarking, which tracks image propagation by embedding copyright watermarks into carriers. Unfortunately, the stylized image generated by ZSST lose the structural and semantic information of the original style image, hindering end-to-end robust tracking by watermarks. To fill this gap, we propose StyleMark, the first robust watermarking method for black-box ZSST, which can be seamlessly applied to artistic style images achieving precise attribution of artistic styles after ZSST, without compromising the social usability of artworks. Specifically, we propose a new style watermark network that adjusts the mean activations of style features through multi-scale watermark embedding, thereby planting watermark traces into the shared style feature space of style images. Furthermore, we design a distribution squeeze loss, which constrain content statistical feature distortion, forcing the reconstruction network to focus on integrating style features with watermarks, thus optimizing the intrinsic watermark distribution. Finally, based on solid end-to-end training, StyleMark mitigates the optimization conflict between robustness and watermark invisibility through decoder fine-tuning under random noise. Experimental results demonstrate that StyleMark exhibits significant robustness against black-box ZSST and common pixel-level distortions, maintains high watermark decoding accuracy under complex multi-stage processing scenarios, and securely defending against malicious adaptive attacks. Yunming Zhang, Dengpan Ye, Sipeng Shen, Caiyun Xie |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Towards Invisible Decision-Based Adversarial Attacks Against Visual Object TrackingabstractAdversarial attacks have become a critical focus in visual object tracking (VOT) research. Small, carefully crafted adversarial perturbations to video frames can easily disrupt the visual object tracker, leading to tracking failure. Therefore, studying adversarial attacks contributes to the development of more robust and reliable trackers. Considering that trackers are agnostic in real-world scenarios, research on decision-based black-box attacks is straightforward and practical. However, existing decision-based black-box attacks neither comprehensively analyze the unique characteristics of object tracking nor sufficiently consider the imperceptibility of adversarial perturbations. In this paper, we propose invisible local attack (ILA), a novel decision-based adversarial attack specifically for VOT with imperceptible perturbations. We assume that a significant number of pixels in a frame, irrelevant to the tracked object, do not substantially contribute to the functioning mechanism of a deep tracker. Based on this consideration, we propose a search algorithm to identify the pixel set focused on by the tracker during object tracking. The adversarial noise is then confined to these pixels and iteratively optimized through a heuristic algorithm of ILA. By perturbing only the key pixels, ILA significantly enhances both the attack performance and imperceptibility when it is applied to visual object trackers. Extensive experiments demonstrate that our ILA method achieves a 121% increase in the robustness metric and a 137% improvement in the structural similarity index measure (SSIM) across multiple datasets for various trackers compared with the state-of-the-art (SOTA) method. Ziyi Liu 0009, Caiyun Xie, Wenbing Ding, Dengpan Ye, Qian Wang 0002 |
IEEE Trans. Multim. | 4 |
| 2025 | The Interpretable and Transferable Adversarial Attack against Synthetic Speech DetectorsabstractExisting work finds it challenging for adversarial examples to transfer among different synthetic speech detectors because of cross-feature and cross-model. To enhance the transferability of adversarial examples, we propose a spectral saliency analysis method and gain insight into the underlying detection mechanisms of existing detectors for the first time. These insights offer an interpretable basis for why adversarial examples are challenging to transfer between synthetic speech detection models. Then we further propose a two-stage adversarial attack framework. Specifically, the first stage leverages insights into the model detection mechanism to design a random time-frequency masking module, the random offset module, and 1D convolution to generate transferable and robust adversarial examples. In the second stage, to mitigate the problem of obvious noise in the low-energy frames of the carrier in existing adversarial attacks, we perform secondary optimization on frames below the Signal-Noise-Rate threshold to enhance its auditory quality. Extensive experimental results demonstrate that the proposed method significantly enhances the transferability and robustness of adversarial examples, while simultaneously preserving the acoustic quality compared to typical approaches. Jiacheng Deng 0001, Dengpan Ye, Jizhi Li, Ziyi Liu 0009, Yunming Zhang |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2025 | Feature Extraction Matters More: An Effective and Efficient Universal Deepfake DisruptorabstractFace manipulation can modify a victim’s facial attributes (e.g., age or hair color) in an image, which is an important component of deepfakes. Adversarial examples are an emerging approach to combat the threat of visual misinformation to society. To efficiently protect facial images from being forged, designing a universal face anti-manipulation disruptor is essential. However, existing works treat deepfake disruption as an end-to-end process, ignoring the functional difference between feature extraction and image reconstruction. In this work, we propose FOUND , a novel F eature- O utput ensemble UN iversal D isruptor against face manipulation networks, which explores a new opinion considering attacking feature-extraction (encoding) modules as the critical task in deepfake disruption. We conduct an effective two-stage disruption process. We first perform ensemble disruption on multi-model encoders, maximizing the Wasserstein distance between features before and after the adversarial attack. Then we develop a Gradient-Ensemble strategy to enhance the disruption effect by simplifying the complex optimization problem of disrupting ensemble end-to-end models. Extensive experiments indicate that one FOUND generated with a few facial images can successfully disrupt multiple face manipulation models on cross-attribute and cross-face images, surpassing state-of-the-art universal disruptors in both success rate and efficiency. Dengpan Ye, Zhenhao Lu, Yunming Zhang, Chuanxi Chen |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2024 | Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalabstractDeep Hashing (DH)-based image retrieval has been widely applied to face-matching systems due to its accuracy and efficiency. However, this convenience comes with an increased risk of privacy leakage. DH models inherit the vulnerability to adversarial attacks, which can be used to prevent the retrieval of private images. Existing adversarial attacks against DH typically target a single image or a specific class of images, lacking universal adversarial perturbation for the entire hash dataset. In this paper, we propose the first universal transferable adversarial perturbation against DH-based facial image retrieval, a single perturbation can protect all images. Specifically, we explore the relationship between clusters learned by different DH models and define the optimization objective of universal perturbation as leaving from the overall hash center. To mitigate the challenge of single-objective optimization, we randomly obtain sub-cluster centers and further propose sub-task-based meta-learning to aid in overall optimization. We test our method with popular facial datasets and DH models, indicating impressive cross-image, -identity, -model, and -scheme universal anti-retrieval performance. Compared to state-of-the-art methods, our performance is competitive in white-box settings and exhibits significant improvements of 10%-70% in transferability in all black-box settings. Dengpan Ye, Yunna Lv, Chuanxi Chen, Yunming Zhang |
AAAI | 2 |
| 2024 | Reputation Defender: Local Black-Box Adversarial Attack against Image-Translation-Based DeepFakeabstractDeepFakes technologies possess powerful capabilities to convincingly modify the expressions, appearances, and identities of targets in photos and videos. This capability has enabled various forms of misuse, e.g., blackmail, nonconsensual pornography, and political disinformation, that severely harm the reputation of people. To mitigate this issue, a leading defensive approach is to add adversarial perturbations to the original images or videos, causing the core components of image-translation-based DeepFake systems to fail. However, we found that existing perturbation techniques for image-translation-based DeepFake systems are mostly implemented in white-box settings, making them hard to apply in realistic scenarios. Moreover, these techniques indiscriminately alter the entire image, often failing to protect the most critical facial regions. In this paper, we propose a novel adversarial perturbation generation framework called ReDef in the black-box setting, which narrowly focuses on perturbing facial regions to fool image-translation-based DeepFake systems. By diversifying the output and using the prior knowledge to guide the direction of optimizing the adversarial perturbations, ReDef exhibits better query efficiency and attack success rates. Compared to the state-of-the-art works, ReDef can improve the ASR by 37.8%, and reduce the query count by 41.3%. Lingchen Zhao, Dengpan Ye |
ICME | 3 |
| 2024 | Improving Adversarial Robustness With Adversarial AugmentationsabstractDeep neural network (DNN)-based applications are extensively being researched and applied in the Internet of Things (IoT) devices in daily lives due to impressive performance. Recently, adversarial attacks pose a significant threat to the security of deep neural networks (DNNs), adversarial training has emerged as a promising and effective defense approach for defending against such attacks. However, existing adversarial training methods have shown limited success in defending against attacks unseen during training, thereby undermining their effectiveness. Besides, generating adversarial perturbations for adversarial training requires massive expensive labeled data, which is a critical obstacle in the robust DNNs-based IoT applications. In this article, we first explore the effective data augmentations by implementing adversarial attacks with self-supervised in latent space. Then, we propose new loss metric functions that can avoid collapse phenomenon of contrastive learning (CL) by measuring the distances between adversarial augmented pairs. Based on the extracted adversarial features in self-supervised CL, we propose a novel adversarial robust learning (ARL) method, which implements adversarial training without any labels and obtains more general robust encoder network. Our approach is validated on commonly used benchmark data sets and models, where it achieves comparable adversarial robustness against different adversarial attacks when compared to supervised adversarial training methods. Additionally, ARL outperforms state-of-the-art self-supervised adversarial learning techniques in terms of achieving higher robustness and clean prediction accuracy for the downstream classification task. Chuanxi Chen, Dengpan Ye, Yiheng He |
IEEE Internet Things J. | 2 |
| 2024 | Perceptual Video Hashing With Secure Anti-Noise Model for Social Video RetrievalabstractIn real scenarios, videos are usually corrupted by multiple types of noise, which brings great challenges to retrieving social videos. However, most of the current video hashing methods for video retrieval consider the attack of a single noise model, and rarely discuss when dealing with complex noise models, which is not conducive to solving the above difficulties. Thus, we describe a novel video hashing with secure anti-noise model (SANM). To improve the robustness of noise attacks, the input video is reconstructed into a SANM by low-rank representation (LRR) and random subspace partition (RSP). LRR is useful technique for capturing the global structure of data. It focuses on recovering the underlying subspace in noisy environment and helps to make the proposed model robust to multiple noises. In addition, using chaotic mapping to control the generation of RSP can ensure the security of proposed model. Then, a new subspace decomposition descriptor (SDD) is proposed. SDD is obtained by calculating the invariant distances of the factor matrices obtained by tucker decomposition, and is used to decompose SANM to derive a compact hash. Various experiments demonstrate that the SANM hashing performs better than several state-of-the-art algorithms in terms of good robustness and discrimination, and it can accurately retrieve social videos. Lv Chen, Dengpan Ye, Yueyun Shang |
IEEE Internet Things J. | 2 |
| 2024 | AVT$^{2}$-DWF: Improving Deepfake Detection With Audio-Visual Fusion and Dynamic Weighting StrategiesabstractWith the continuous improvements of deepfake methods, forgery messages have transitioned from single-modality to multi-modal fusion, posing new challenges for existing forgery detection algorithms. In this letter, we proposeAVT$^{2}$-DWF, theAudio-Visual dualTransformers grounded inDynamicWeightFusion, which aims to amplify both intra- and cross-modal forgery cues, thereby enhancing detection capabilities. AVT$^{2}$-DWF adopts a dual-stage approach to capture both spatial characteristics and temporal dynamics of facial expressions. This is achieved through a face transformer with an$n$-frame-wise tokenization strategy encoder and an audio transformer encoder. Subsequently, it uses multi-modal conversion with dynamic weight fusion to address the challenge of heterogeneous information fusion between audio and visual modalities. Experiments on DeepfakeTIMIT, FakeAVCeleb, and DFDC datasets indicate that AVT$^{2}$-DWF achieves state-of-the-art performance intra- and cross-dataset Deepfake detection. Rui Wang 0141, Dengpan Ye, Yunming Zhang, Jiacheng Deng 0001 |
IEEE Signal Process. Lett. | 2 |
| 2024 | Dual Defense: Adversarial, Traceable, and Invisible Robust Watermarking Against Face SwappingabstractMalicious applications of deep face swapping technology pose security threats such as misinformation dissemination and identity fraud. Some research propose the utilization of robust watermarking methods to track the copyright of facial images, facilitating post-forgery identity attribution. However, these methods cannot fundamentally prevent or eliminate the adverse impacts of face swapping. To address this issue, we present Dual Defense, an innovative framework based on robust adversarial watermarking. It simultaneously tracks image copyrights and disrupts the face swapping model by one-time embedding the robust adversarial watermark. Specifically, we propose an Original-domain Feature Emulation Attack (OFEA) method, which makes the traceable watermark adversarial through specially designed original domain adversarial loss. Additionally, we conduct a wavelet domain image structural information compensation loss, combined with a channel attention mechanism, to jointly balance watermark invisibility, adversariality, and traceability. Furthermore, we design a more comprehensive and rational evaluation method to thoroughly assess the effectiveness of adversarial attacks against face swapping models. Extensive experiments demonstrate that Dual Defense exhibits exceptional cross-task generality and dataset generalization. It maintains impressive adversariality and traceability in both original and robust settings, surpassing current forgery defense methods that possess only one of these capabilities. Yunming Zhang, Dengpan Ye, Caiyun Xie, Xin Liao 0001, Ziyi Liu 0009, Chuanxi Chen, Jiacheng Deng 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Tiny WFP: Lightweight and Effective Website Fingerprinting via Wavelet Multi-Resolution Analysis
Dengpan Ye, Chuanxi Chen |
ACNS (1) | 2 |
| 2023 | Implicit Identity Driven Deepfake Face Swapping DetectionabstractIn this paper, we consider the face swapping detection from the perspective of face identity. Face swapping aims to replace the target face with the source face and generate the fake face that the human cannot distinguish between real and fake. We argue that the fake face contains the explicit identity and implicit identity, which respectively corresponds to the identity of the source face and target face during face swapping. Note that the explicit identities of faces can be extracted by regular face recognizers. Particularly, the implicit identity of real face is consistent with the its explicit identity. Thus the difference between explicit and implicit identity of face facilitates face swapping detection. Following this idea, we propose a novel implicit identity driven framework for face swapping detection. Specifically, we design an explicit identity contrast (EIC) loss and an implicit identity exploration (IIE) loss, which supervises a CNN backbone to embed face images into the implicit identity space. Under the guidance of EIC, real samples are pulled closer to their explicit identities, while fake samples are pushed away from their explicit identities. More-over, IIE is derived from the margin-based classification loss function, which encourages the fake faces with known target identities to enjoy intra-class compactness and inter-class diversity. Extensive experiments and visualizations on several datasets demonstrate the generalization of our method against the state-of-the-art counterparts. Baojin Huang, Zhongyuan Wang 0001, Jifan Yang, Jiaxin Ai, Qin Zou 0001, Qian Wang 0002, Dengpan Ye |
CVPR | 7 |
| 2023 | Detecting Backdoors During the Inference Stage Based on Corruption Robustness ConsistencyabstractDeep neural networks are proven to be vulnerable to backdoor attacks. Detecting the trigger samples during the inference stage, i.e., the test-time trigger sample detection, can prevent the backdoor from being triggered. However, existing detection methods often require the defenders to have high accessibility to victim models, extra clean data, or knowledge about the appearance of backdoor triggers, limiting their practicality. In this paper, we propose the test-time corruption robustness consistency evaluation (TeCo)11https://github.com/CGCL-codes/TeCo, a novel test-time trigger sample detection method that only needs the hard-label outputs of the victim models without any extra information. Our journey begins with the intriguing observation that the backdoor-infected models have similar performance across different image corruptions for the clean images, but perform discrepantly for the trigger samples. Based on this phenomenon, we design TeCo to evaluate test-time robustness consistency by calculating the deviation of severity that leads to predictions' transition across different corruptions. Extensive experiments demonstrate that compared with state-of-the-art defenses, which even require either certain information about the trigger types or accessibility of clean data, TeCo outperforms them on different backdoor attacks, datasets, and model architectures, enjoying a higher AUROC by 10% and 5 times of stability. Xiaogeng Liu, Shengshan Hu, Dengpan Ye, Hai Jin 0001, Chaowei Xiao |
CVPR | 5 |
| 2023 | Robust Anti-forensics on Audio Forensics System
Dengpan Ye |
ICIC (5) | 2 |
| 2023 | Voice Guard: Protecting Voice Privacy with Strong and Imperceptible Adversarial Perturbation in the Time DomainabstractAdversarial example is a rising tool for voice privacy protection. By adding imperceptible noise to public audio, it prevents tampers from using zero-shot Voice Conversion (VC) to synthesize high quality speech with target speaker identity. However, many existing studies ignore the human perception characteristics of audio data, and it is challenging to generate strong and imperceptible adversarial audio. In this paper, we propose the Voice Guard defense method, which uses a novel method to advance the adversarial perturbation to the time domain to avoid the loss caused by cross-domain conversion. And the psychoacoustic model is introduced into the defense of VC for the first time, which greatly improves the disruption ability and concealment of adversarial audio. We also standardize the evaluation metrics of adversarial audio for the first time, combining multi-dimensional metrics to define the criteria for defense. We evaluate Voice Guard on several state-of-the-art zero-shot VC models. The experimental results show that our method can ensure the perceptual quality of adversarial audio while having a strong defense capability, and is far superior to previous works in terms of disruption ability and concealment. Dengpan Ye, Chuanxi Chen, Shengshan Hu |
IJCAI | 2 |
| 2023 | Universal Defensive Underpainting Patch: Making Your Text Invisible to Optical Character RecognitionabstractOptical Character Recognition (OCR) enables automatic text extraction from scanned or digitized text images, but it also makes it easy to pirate valuable or sensitive text from these images. Previous methods to prevent OCR piracy by distorting characters in text images are impractical in real-world scenarios, as pirates can capture arbitrary portions of the text images, rendering the defenses ineffective. In this work, we propose a novel and effective defense mechanism termed the Universal Defensive Underpainting Patch (UDUP) that modifies the underpainting of text images instead of the characters. UDUP is created through an iterative optimization process to craft a small, fixed-size defensive patch that can generate non-overlapping underpainting for text images of any size. Experimental results show that UDUP effectively defends against unauthorized OCR under the setting of any screenshot range or complex image background. It is agnostic to the content, size, colors, and languages of characters, and is robust to typical image operations such as scaling and compressing. In addition, the transferability of UDUP is demonstrated by evading several off-the-shelf OCRs. The code is available at https://github.com/QRICKDD/UDUP. Jiacheng Deng 0001, Li Dong 0006, Diqun Yan, Rangding Wang, Dengpan Ye, Lingchen Zhao, Jinyu Tian 0001 |
ACM Multimedia | 6 |
| 2023 | RTIM Hashing: Robust and Compact Video Hashing With a Rotation- and Translation-Invariant ModelabstractAbstract Video hashing is a popular research topic in the fields of multimedia information and security because its fast matching and low-cost storage characteristics are widely used in many applications (video copy detection, video retrieval, video authentication, etc.). This paper describes a compact video hashing method with a rotation- and translation-invariant model (RTIM). The key contribution of this approach is that it innovatively reconstructs an input video into a 3D RTIM by combining ring partition and a pipeline histogram; this is a first in video hashing and helps make video hashes resistant to rotation and translation. Then, the proposed model is decomposed via Tucker decomposition, and the generated core tensor is used to produce a compact hash. As the core tensor is a compressed version of the original tensor, hash construction with the core tensor makes RTIM hashing compact and achieves desirable discrimination ability. Different from existing video hashing algorithms, RTIM hashing can not only resist many commonly used digital operations, especially video rotation and cyclic frame shifting, but also achieve good discrimination ability. Various experiments demonstrate the effectiveness of our algorithm. Receiver operating characteristic curve comparisons show that compared with the state-of-the-art video hashing algorithms, RTIM hashing is more robust and compact. Lv Chen, Dengpan Ye, Yueyun Shang |
Comput. J. | 2 |
| 2022 | Robust Video Hashing Based on Local Fluctuation Preserving for Tracking Deep Fake VideosabstractWith the rapid development of deepfake techniques, massive face manipulation videos appeared on social networks. These deepfake videos not only violated the original video of the author’s privacy, but also seriously threatened the security of the video database. Robust video hashing can map videos with similar visual content into similar hash codes, which is beneficial for tracking fake video material in social networks. In this paper, a robust video hashing algorithm based on local fluctuation preserving is proposed. The algorithm uses a shot segmentation model and local statistical descriptors, which is robust to many commonly-used digital operations and can accurately track the original version of these fake videos from a huge video database. An essential contribution is a shot segmentation model reconstruction from input video with image hashing and discrete wavelet transform, reaching initial data compression and against noise attack. In addition, as local statistical descriptors are content-based and local preserving features, the hash generated by local statistical descriptors can achieve good discrimination and ensure that the proposed hash has good tracking ability to fake videos from original videos. Lv Chen, Dengpan Ye, Yueyun Shang, Jiaqing Huang |
ICASSP | 2 |
| 2022 | Towards Adversarial Robustness with Multidimensional Perturbations via Contrastive LearningabstractRecent works have demonstrated that neural networks are vulnerable to adversarial attacks, while adversarial training is promising for improving robustness of deep networks. However, these models still remain vulnerable to new types of attacks not seen due to representative general samples may not be provided during training. Moreover, substantially larger datasets are necessary in adversarial robust models than those required for standard training where labeled data is expensive. In this work, we propose a novel approach to adversarial robustness, which establishes on the insights from min-max optimization that more powerful adversarial perturbations lead to more robust defense. Our algorithm is called Adversarial Training with Multidimensional Perturbations (ATMP), aims at guiding networks learn strong representations through minimizing the distance between differently augmented views via adopting an innovative contrastive learning objective function in the latent space. By perturbing the representations corresponding to key robust features, more powerful adversarial perturbations could be obtained in self-supervised form during adversarial training. Besides, we can avoid label leaking to some extent because no label information is required in generating adversarial examples. Extensive experimental results on common benchmarks show that our method can achieve high robustness against various of representative adversarial attacks. We also compare it with the existing state-of-the-art techniques, and the experiments indicate that our method is superior. Chuanxi Chen, Dengpan Ye, Hao Wang 0134 |
TrustCom | 2 |
| 2022 | Detection defense against adversarial attacks with saliency mapabstractIt is well established that neural networks are vulnerable to adversarial examples, which are almost imperceptible on human vision and can cause the deep models misbehave. Such phenomenon may lead to severely inestimable consequences in the safety and security critical applications. Existing defenses are trend to harden the robustness of models against adversarial attacks, for example, adversarial training technology. However, these are usually intractable to implement due to the high cost of retraining and the cumbersome operations of altering the model architecture or parameters. In this paper, we discuss the saliency map method from the view of enhancing model interpretability, it is similar to introducing the mechanism of the attention to the model, so as to comprehend the progress of object identification by the deep networks. We then propose a novel method combined with additional noises and utilize the inconsistency strategy to detect adversarial examples. Our experimental results of some representative adversarial attacks on common data sets including ImageNet and popular models show that our method can detect all the attacks with high detection success rate effectively. We compare it with the existing state-of-the-art technique, and the experiments indicate that our method is more general. Dengpan Ye, Chuanxi Chen, Changrui Liu, Hao Wang 0134, Shunzhi Jiang |
Int. J. Intell. Syst. | 1 |
| 2022 | Black-Box Adversarial Attacks against Audio Forensics ModelsabstractSpeech synthesis technology has made great progress in recent years and is widely used in the Internet of things, but it also brings the risk of being abused by criminals. Therefore, a series of researches on audio forensics models have arisen to reduce or eliminate these negative effects. In this paper, we propose a black-box adversarial attack method that only relies on output scores of audio forensics models. To improve the transferability of adversarial attacks, we utilize the ensemble-model method. A defense method is also designed against our proposed attack method under the view of the huge threat of adversarial examples to audio forensics models. Our experimental results on 4 forensics models trained on the LA part of the ASVspoof 2019 dataset show that our attacks can get a 99 % attack success rate on score-only black-box models, which is competitive to the best of white-box attacks, and 60 % attack success rate on decision-only black-box models. Finally, our defense method reduces the attack success rate to 16 % and guarantees 98 % detection accuracy of forensics models. Dengpan Ye |
Secur. Commun. Networks | 2 |
| 2021 | Ground-to-Aerial Image Geo-Localization with Cross-View Image Synthesis
Jiaqing Huang, Dengpan Ye |
ICIG (3) | 2 |
| 2021 | Protecting Encrypted Video Stream Against Information Leak Using Adversarial Traces
Dengpan Ye |
ICIG (3) | 2 |
| 2021 | Metric Learning for Anti-Compression Facial Forgery DetectionabstractDetecting facial forgery images and videos is an increasingly important topic in multimedia forensics. As forgery images and videos are usually compressed into different formats such as JPEG and H264 when circulating on the Internet, existing forgery-detection methods trained on uncompressed data often suffer from significant performance degradation in identifying them. To solve this problem, we propose a novel anti-compression facial forgery detection framework, which learns a compression-insensitive embedding feature space utilizing both original and compressed forgeries. Specifically, our approach consists of three ideas: (i) extracting compression-insensitive features from both uncompressed and compressed forgeries using an adversarial learning strategy; (ii) learning a robust partition by constructing a metric loss that can reduce the distance of the paired original and compressed images in the embedding space; (iii) improving the accuracy of tampered localization with an attention-transfer module. Experimental results demonstrate that, the proposed method is highly effective in handling both compressed and uncompressed facial forgery images. Shenhao Cao, Qin Zou 0001, Xiuqing Mao, Dengpan Ye, Zhongyuan Wang 0001 |
ACM Multimedia | 4 |
| 2021 | Countering Spoof: Towards Detecting Deepfake with Multidimensional Biological SignalsabstractThe deepfake technology is conveniently abused with the low technology threshold, which may bring the huge social security risks. As GAN-based synthesis technology is becoming stronger, various methods are difficult to classify the fake content effectively. However, although the fake content generated by GANs can deceive the human eyes, it ignores the biological signals hidden in the face video. In this paper, we proposed a novel video forensics method with multidimensional biological signals, which extracting the difference of the biological signal between real and fake videos from three dimensions. The experimental results show that our method achieves 98% accuracy on the main public dataset. Compared with other technologies, the proposed method only extracts fake video information and is not limited to a specific generation method, so it is not affected by synthetic methods and has good adaptability. Xinlei Jin, Dengpan Ye, Chuanxi Chen |
Secur. Commun. Networks | 2 |
| 2021 | Augmenting Encrypted Search: A Decentralized Service Realization with Enforced ExecutionabstractSearchable symmetric encryption (SSE) allows the data owner to outsource an encrypted database to a remote server in a private manner while maintaining the ability for selectively search. So far, most existing solutions focus on an honest-but-curious server, while security designs against a malicious server have not drawn enough attention. A few recent works have attempted to construct verifiable SSE that enables the data owner to verify the integrity of search results. Nevertheless, these verification mechanisms are highly dependent on specific SSE schemes, and fail to support complex queries. A general verification mechanism is desired that can be applied to all SSE schemes. In this work, instead of concentrating on a central server, we explore the potential of the smart contract, an emerging blockchain-based decentralized technology, and construct decentralized SSE schemes where the data owner can receive correct search results with assurance without worrying about potential wrongdoings of a malicious server. We study both public and private blockchain environments and propose two designs with a trade-off between security and efficiency. To better support practical applications, the multi-user setting of SSE is further investigated where the data owner allows authenticated users to search keywords in shared documents. We implement prototypes of our two designs and present experiments and evaluations to demonstrate the practicability of our decentralized SSE schemes. Shengshan Hu, Chengjun Cai, Qian Wang 0002, Cong Wang 0001, Zhibo Wang 0001, Dengpan Ye |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | Detection of Electric Network Frequency in Audio Recordings-From Theory to Practical DetectorsabstractRecently, it has been discovered that the electric network frequency (ENF) could be captured by digital audio, video, or even image files, and could further be exploited in forensic investigations. However, the existence of the ENF in multimedia content is not a sure thing, and if the ENF is not present, ENF-based forensic analysis would become useless or even misleading. In this paper, we address the problem of ENF detection in digital audio recordings, which is modeled as the detection of a weak (ENF) signal contaminated by unknown colored wide-sense stationary (WSS) Gaussian noise, while the signal also contains multiple unknown random parameters. We first derive three Neyman-Pearson (NP) detectors, i.e., general matched filter (GMF), matched filter (MF)-like detector, and the asymptotic approximation of the GMF, and choose the MF-like detector as the clairvoyant detector. For practical detectors, we show that the generalized likelihood ratio test (GLRT) could not be efficiently obtained due to the unknown noise and large matrix inversion. Alternatively, we propose two least-squares (LS)-based time domain detectors termed as LS-likelihood ratio test (LRT) and naive-LRT. Further, we propose a time-frequency (TF) domain detector, termed as TF detector, which exploits the a priori knowledge of the ENF. The performances of the derived detectors are extensively analyzed in terms of test statistic distributions, threshold selection, and computational complexity. The naive-LRT detector is found to be only effective for very short recordings. As the data recording length increases, both LS-LRT and TF detectors yield effective detection results, while the latter is approximately a constant false alarm rate (CFAR) detector. Practical experiments using real audio recordings justify the effectiveness of the proposed detectors and our analysis. Guang Hua 0001, Han Liao, Dengpan Ye |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | Robust ENF Estimation Based on Harmonic Enhancement and Maximum Weight CliqueabstractThe electric network frequency (ENF) is an important and extensively researched forensic criterion to authenticate digital recordings, but currently it is still challenging to extract reliable ENF traces from recordings in uncontrollable environments. In this paper, we present a framework for robust ENF extraction from real-world audio recordings, featuring multi-tone harmonic ENF enhancement and graph-based harmonic selection. We first extend the recently developed single-tone robust filtering algorithm (RFA) to the multi-tone scenario and propose a harmonic robust filtering algorithm (HRFA). It can enhance each harmonic component without cross-component interference, thus alleviating the effects of unwanted noise and audio content. In addition, considering the fact that some harmonic components could still be severely corrupted after the HRFA, interfering rather than facilitating ENF estimation, we propose a graph-based harmonic selection algorithm (GHSA), which finds a subset of harmonic components having the overall highest mutual cross-correlation. Noticeably, the harmonic selection problem is found to be equivalent to the maximum weight clique problem in graph theory, and the Bron-Kerbosch algorithm is adopted in the GHSA. With the enhanced and carefully selected harmonic components, both the existing maximum likelihood estimator (MLE) and weighted MLE are incorporated to yield the final ENF estimation results. The proposed framework is evaluated using both synthetic signals and the ENF-WHU dataset consisting of 130 real-world audio recordings, demonstrating its advantages over both the existing single- and multi-tone competitors. This work further improves the applicability of the ENF as a forensic criterion in real-world situations. Guang Hua 0001, Han Liao, Dengpan Ye, Jiayi Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | High Accuracy Perceptual Video Hashing via Low-Rank Decomposition and DWT
Lv Chen, Dengpan Ye, Shunzhi Jiang |
MMM (1) | 2 |
| 2020 | Adaptive Machine learning: A Framework for Active Malware DetectionabstractApplications of Machine Learning (ML) algorithms in cybersecurity provide significant performance enhancement over traditional rule-based algorithms. These intelligent cyber-security solutions demand careful integration of the learning algorithms to develop a significant cyber incident detection system to formulate security analysts' industrial level. The development of advanced malware programs poses a critical threat to cybersecurity systems. Hence, an efficient, robust, and scalable malware recognition module is essential for every cybersecurity product. Conventional Signature-based methods struggle in terms of robustness and effectiveness during malware detection, specifically in the case of zero-day and polymorphic viruses attacks. In this paper, we design an adaptive Machine Learning based active malware detection framework which provides a cybersecurity solution against phishing attacks. The proposed framework utilize ML algorithms in a multilayered feed-forwarding approach to successfully detect the malware by examining the static features of the web pages. The proposed framework successfully extracts the features from the web pages and performs a successful detection process for the phishing attack. In the multilayered feed-forwarding framework, the first layer utilizes Random Forest (RF), Support Vector Machine (SVN), and K-Nearest Neighbor (K-NN) classifiers to build a model for detecting malware from the real-time input. The output of the first layer passes to the Ensemble Voting (EV) algorithm, which accumulates earlier classifiers' performance. At the third layer, adaptive frameworks investigate second layer input data and formulate the phishing detection model. We analyze the proposed framework's performance on three different phishing datasets and validate the higher accuracy rate. Muhammad Aslam 0004, Dengpan Ye, Muhammad Asad 0002 |
MSN | 2 |
| 2020 | NEXT: a neural network framework for next POI recommendation
Zhiqian Zhang, Chenliang Li 0005, Zhiyong Wu 0003, Aixin Sun, Dengpan Ye, Xiangyang Luo 0001 |
Frontiers Comput. Sci. | 5 |
| 2020 | SmartSteganogaphy: Light-weight generative audio steganography model for smart embedding application
Shunzhi Jiang, Dengpan Ye, Jiaqing Huang, Yueyun Shang, Zhuoyuan Zheng |
J. Netw. Comput. Appl. | 2 |
| 2020 | Anti-steganalysis for image on convolutional neural networks
Dengpan Ye, Shunzhi Jiang, Changrui Liu, Xiaoguang Niu, Xiangyang Luo 0001 |
Multim. Tools Appl. | 2 |
| 2019 | Multi-view coupled dictionary learning for person re-identification
Fei Ma 0004, Xiaoke Zhu, Qinglong Liu, Chengfang Song, Xiaoyuan Jing, Dengpan Ye |
Neurocomputing | 6 |
| 2019 | EveDroid: Event-Aware Android Malware Detection Against Model Degrading for IoT DevicesabstractWith the proliferation of the smart Internet of Things (IoT) devices based on Android system, malicious Android applications targeting for IoT devices have received more and more attention due to the concern of privacy leakage and property loss. However, existing malware detection approaches based on static or dynamic analysis are not scalable to the evolvement of malware and cannot extract enough valid semantics in application programming interface (API) level, failing to detect new malware. In this paper, we propose EveDroid, a scalable and event-aware Android malware detection system, which exploits the behavioral patterns in different events to effectively detect new malware based on the insight that events can reflect apps' possible running activities. Unlike existing approaches using API calls as features directly, we propose to use event group to describe apps' behaviors in event level, which can capture higher level of semantics than in API level. In event group, we adopt function clusters to represent behaviors in each event so that behaviors hidden in events can still be captured as time goes on, which enables EveDroid to detect new malware in the event level. The function clusters can generalize API calls into vectors based on their API composition to capture new API calls, which makes EveDroid scalable to malware evolving. Moreover, a neural network is specifically designed to aggregate the multiple events and automatically mine the semantic relationship among them. We train the system and evaluate its F1-measure on a dataset of 14 956 benign and 28 848 malicious Android apps released in different years. The experimental results show that EveDroid outperforms other malware detection systems. Tao Lei 0005, Zhan Qin, Zhibo Wang 0001, Qi Li 0002, Dengpan Ye |
IEEE Internet Things J. | 5 |
| 2019 | Situation-Aware Authenticated Video Broadcasting Over Train-Trackside WiFi NetworksabstractLive video programs can bring in better travel experience for subway passengers and earn abundant advertisement revenue for subway operators. However, because the train-trackside channels for video dissemination are easily accessible to anyone, the video traffic are vulnerable to attacks, which may cause deadly tragedies. This paper presents a situation-aware authenticated video broadcasting scheme in the railway network, which consists of train, on-board sensor, trackside global system for mobile communications-railway (GSM-R) device, WiFi access point (AP), and train control center. Specifically, the scheme has four modules: 1) a train uses its on-board sensors to obtain its speed, location, and received signal strength indicator of train-trackside WiFi channel; 2) the train reports these real-time measurements to the railway control center with the legacy GSM-R networks; 3) according to the measurements, the control center or its WiFi AP adaptively customizes the protected codestream bitrate and AP-train handover time; and 4) the train renders the received codestream, which passes the authenticity verification process. As shown in the performance analysis, the present scheme ensures the codestream authenticity and provides high quality of service in the lossy subway WiFi environment. Yongdong Wu, Dengpan Ye, Zhuo Wei, Qian Wang 0002, William Tan, Robert H. Deng |
IEEE Internet Things J. | 2 |
| 2019 | Study on the interaction between the cover source mismatch and texture complexity in steganalysis
Donghui Hu, Zhongjin Ma, Yuqi Fan 0001, Shuli Zheng, Dengpan Ye, Lina Wang 0001 |
Multim. Tools Appl. | 5 |
| 2018 | Big Data Analytics for Information Security
Krzysztof Szczypiorski, Xiangyang Luo 0001, Dengpan Ye |
Secur. Commun. Networks | 4 |
| 2017 | The Concept Drift Problem in Android Malware Detection and Its SolutionabstractCurrently, the Android platform is the most popular mobile platform in the world and holds a dominant share in the mobile device market. With the popularization of the Android platform, large numbers of Android malware programs have begun to emerge on the Internet, and the sophistication of these programs is developing rapidly. While many studies have already investigated Android malware detection through machine learning and have achieved good results, most of these are based on static data sources and fail to consider the concept drift problem resulting from the rapid growth in the number of Android malware programs and normal Android applications, as well as rapid technological advancement in the Android environment. To address this problem, this work proposes a solution based on an ensemble classifier. This ensemble classifier is based on a streaming data-based Naive Bayes classifier. Android malware has identifiable feature utilization tendencies. On this basis, feature selection algorithm is introduced into the ensemble classifier, and a sliding window is maintained inside the ensemble classifier. Based on the performance of the subclassifiers inside the sliding window, the ensemble classifier makes dynamic adjustments to address the concept drift problem in Android malware detection. The experimental results from the proposed method demonstrate that it can effectively address the concept drift problem in Android malware detection in a streaming data environment. Donghui Hu, Zhongjin Ma, Pei-Pei Li 0001, Dengpan Ye, Baohong Ling |
Secur. Commun. Networks | 5 |
| 2016 | A novel image hashing scheme with perceptual robustness using block truncation coding
Chuan Qin 0001, Xueqin Chen 0003, Dengpan Ye, Xingming Sun |
Inf. Sci. | 3 |
| 2016 | Guest Editorial: Information Hiding and Forensics for Multimedia Security
Chuan Qin 0001, Dengpan Ye, Xiangyang Luo 0001 |
Multim. Tools Appl. | 2 |
| 2016 | Detection of double MP3 compression Based on Difference of Calibration Histogram
Yanzhen Ren, Mengdi Fan, Dengpan Ye, Lina Wang 0001 |
Multim. Tools Appl. | 3 |
| 2016 | Mobile crowd-sensing context aware based fine-grained access control mode
Dengpan Ye, Yueyun Shang, Jixiang Zhu, Kun Ouyang |
Multim. Tools Appl. | 1 |
| 2016 | Lossless data hiding algorithm for encrypted images with high capacity
Shuli Zheng, Donghui Hu, Dengpan Ye, Lina Wang 0001 |
Multim. Tools Appl. | 4 |
| 2016 | Cyber CrimeabstractToday's world's societies are becoming more and more dependent on open networks such as the Internet – where commercial activities, business transactions, and government services are realized. This has led to the fast development of new cyber threats and numerous information security issues which are exploited by cyber criminals. The inability to provide trusted secure services in contemporary computer network technologies has a tremendous socio-economic impact on global enterprises as well as individuals. Moreover, the frequently occurring international frauds impose the necessity to conduct the investigation of facts spanning across multiple international borders. Such examination is often subject to different jurisdictions and legal systems. A good illustration of the previously mentioned is the Internet, which has made it easier to perpetrate traditional crimes. It has acted as an alternate avenue for the criminals to conduct their activities, and launch attacks with relative anonymity. The increased complexity of the communications and the networking infrastructure is making investigation of the crimes difficult. Traces of illegal digital activities are often buried in large volumes of data, which are hard to inspect with the aim of detecting offenses and collecting evidence. Nowadays, the digital crime scene functions like any other network, with dedicated administrators functioning as the first responders. This poses new challenges for law enforcement policies and forces the computer societies to utilize digital forensics to combat the increasing number of cybercrimes. Forensic professionals must be fully prepared in order to be able to provide court admissible evidence. To make these goals achievable, forensic techniques should keep pace with new technologies. In this special issue, we are delighted to present a selection of 14 papers, which, in our opinion, will contribute to the enhancement of knowledge in cyber crime. The collection of high-quality research papers provides a view on the latest research advances and results in the field of digital forensics and to present the development of tools and techniques which assist the investigation process of potentially illegal cyber activity. In the first paper, Cyberterrorism targeting the general public through social media, Nicholas Ayres and Leandros A. Maglaras investigate whether a mimetic malware could be a viable method of attack against a population with respect to cyberterrorism. The presented research shows that although people are, in general, aware of cyberterrorism on their current level of fear of being a potential target of attack is relatively low. However, when presented with such a threat, their level of fear increased. The obtained results prove that a targeted mimetic virus can indeed have an effect on a population and is a potential attack method for cyberterrorism. The paper emphasizes also the importance of social media as a vessel of propagation of such threat. Next, in the paper entitled Effectiveness of File-Based Deduplication in Digital Forensics Sebastian Neuner, Martin Schmiedecker, and Edgar Weippl focus on introducing improvements to the standardized forensic process to reduce the amount of storage requirement for forensic investigations by using file whitelisting and cross-device deduplication. Authors approach is shown to be particularly useful in cases where investigation relies on referenced files in the file system. In the exemplary use case authors prove that file deduplication and file whitelisting can be successfully utilized to achieve 78% size reduction compared to the full data set which means saving about 700 gigabytes of storage capacity. Jawwad Shamsi, Sherali Zeadally, Fareha Sheikh, and Angelyn Flowers in Attribution in Cyberspace: Techniques and Legal Implications argue that only a few known cybercrimes have been successfully attributed to the actual attacker. To improve this situation authors propose three-level attribution framework to indicate various attributes and guidelines through which attribution can be instigated. The proposed framework is an initial step and in order to be successful it requires strong cooperation between different stake holders, government sponsored active cyber unit, existence of cyber laws, and cooperation among international community members. Next, two papers are focused on anomaly detection. In Evolutionary-based Packets Classification for Anomaly Detection in Web Layer, Rafał Kozik, Michał Choraś, and Witold Hołubowicz propose a novel detection method for modern web applications. First, authors observe that the majority of the state of the art solutions make an assumption about the packets' content, or how the data inside the payload is serialized. Then they propose an evolutionary-based approach to unsupervised and automated packets segmentation. On the top of their approach, authors apply several variants of machine-learned classifiers and statistics to prove that the proposed algorithm can improve the effectiveness of many well-known anomaly detection methods. In the second paper entitled DWT-based Anomaly Detection Method for Cyber Security of Wireless Sensor Networks Łukasz Saganowski, Tomasz Andrysiak, Rafał Kozik, and Michał Choraś introduce a discrete wavelet transformation-based anomaly detection approach for wireless sensor networks which is especially suited for deployment in critical infrastructures for measuring and/or monitoring purposes. The main authors' contribution is that the proposed anomaly detection is integrated with an effective SNORT-based pre-processor. Then DWT-based solution is applied to 25 network traffic parameters measured in a realistic testbed and most suitable parameters are indicated. It is worth noting that several papers from this special issue are devoted to information hiding techniques, which utilization is currently a raising trend among cybercriminals. Papers focus on both: proposing new methods and detection approaches. In the first paper entitled Pitch-based steganography for Speex voice codec, Artur Janicki devises an improved version of the HideF0 steganographic algorithm which is especially suitable for IP telephony. The proposed approach relies on approximation of the pitch-related parameter (F0) in speech signal regions where the pitch is monotonic enough to be linearly approximated with a low error. It also utilizes unused fields in the headers of the voice packets. Experiments conducted on all narrowband Speex codec modes show that an improvement in quality when compared with the originally proposed algorithm has been observed. The resulting steganographic bandwidths of HideF0 turns out to be around 200 bps at the expense of a steganographic cost of between 0.5 and 0.7 MOS, depending on the Speex mode. Hui Tian, Yanpeng Wu, Chin-Chen Chang, Yongfeng Huang, Jin Liu, Tian Wang, Yonghong Chen, and Yiqiao Cai in Steganalysis of Analysis-by-synthesis Speech Exploiting Pulse-position Distribution Characteristics introduce a Support Vector Machine-based detection of low bit-rate speech which utilizes statistic characteristics of pulse positions, that is, the probability distribution of pulse positions as a long-time distribution feature, Markov transition probabilities of pulse positions according to the short-time invariance characteristic of speech signals, and finally joint probability matrices characterizing the pulse-to-pulse correlation. The proposed steganalysis method is evaluated for the G.729a speech codec and compared with the state-of-the-art methods. Obtained experimental results reveal that the proposed method's detection performance is superior when compared with the previous steganalysis algorithms. The paper, Color Images Stegananalysis Using RGB Channel Geometric Transformation Measures by Hasan Abdulrahman, Marc Chaumont, Philippe Montesinos, and Baptiste Magnier, introduces steganalysis method for color images that is based on color feature correlation and machine learning classification. This approach relies on fusing features with those obtained from color-rich models which results in improved detectability of hidden messages. Authors use two types of features, computed between color image channels – first that reflects local Euclidean transformations and second that reflects mirror transformations. They also demonstrate the efficiency of the proposed detection method on three state-of-the-art steganography algorithms. The paper, A framework of adaptive steganography resisting JPEG compression and detection by Yi Zhang, Xiangyang Luo, Chunfang Yang, Dengpan Ye, and Fenlin Liu, describes a framework of adaptive steganography resisting JPEG compression and detection which aims at solving the issue of information loss in the process of image compression while applying image steganography to mobile intelligent terminals. The proposed framework uses the relationship between discrete cosine transform coefficients to determine the domain of messages embedding. Based on this framework, authors devise an adaptive steganography algorithm and perform its evaluation. Obtained experimental results for different payloads and quality factors of JPEG compression prove that when an algorithm is based on the framework, it has both a strong JPEG compression resistant ability and detection resistant performance. In the next paper, Micro protocol engineering for unstructured carriers: On the embedding of steganographic control protocols into audio transmissions, Matthias Naumann, Steffen Wendzel, Wojciech Mazurczyk, and Jörg Keller present techniques to embed micro protocol, that is, covert channel control protocol into an unstructured carrier which is audio streaming over the network. Two types of implementing the micro protocol: static and dynamic have been demonstrated. This allowed comparing the resulting performance and to measure the impact of both designs on the overt audio signal. On the basis of obtained experimental results, a micro protocol engineering approach for unstructured carriers has been devised. Another paper that is focused on analysis of micro protocols has been authored by Jaspreet Kaur, Steffen Wendzel, Omar Eissa, Jernej Tonejc, and Michael Meier. In Covert Channel-internal Control Protocols: Attacks and Defense, an interesting analysis of micro protocols has been conducted. First authors demonstrate that some potential attacks scenarios on micro protocols exist, and that if successful, they are able to break even sophisticated covert communication. The described attacks are based on the attacker's intentional interaction with the micro protocol specifics. Then, authors propose several defense techniques to make micro protocols immune against such threats. In Perfect undetectability of network steganography, Wojciech Frączek and Krzysztof Szczypiorski introduce StegBlocks that is a general approach for constructing network steganography techniques which defines the way in which the methods work, and at the same time it allows for the creation of methods for various carriers (network protocols). The paper encloses also the definition of perfectly undetectable network steganography which is derived from a classic steganography definition, and it covers the specific features of network steganography. Using this definition, authors argue that it is possible to create a network steganography method that is undetectable for the adversary with unlimited computational power. In the next article, DAT Detectors – Uncovering TCP/IP Covert Channels by Descriptive Analytics, Felix Iglesias, Robert Annessi, and Tanja Zseby propose descriptive analytics of traffic (DAT) detectors that utilize descriptive analytics for the detection of covert channels in TCP/IP communication networks. DAT detectors are envisioned to be an extension for network intrusion detection system and are aimed to perform fast and lightweight analysis of numerous flows. They transform communication data into flexible feature vectors that represent traffic as a set of extracted calculations and estimations. The detection approach relies mostly on the combined application of autocorrelation calculations and multimodality measures built upon kernel density estimations and Pareto charts. In the last of the presented articles, An assessment of automatic speaker verification vulnerabilities to replay spoofing attacks, Artur Janicki, Federico Alegre, and Nicholas Evans compare at a high level the threat of replay attacks to those of speech synthesis and voice conversion. This comparison is performed using strictly controlled protocols and with six different Automatic Speaker Verification systems. Presented experimental results prove that low-effort replay attacks are indeed a threat to speech synthesis and voice conversion. Basing on these findings, authors also introduce and assess two replay attack countermeasures: the local binary pattern analysis of speech spectrograms and an approach based on the detection of far-fields recordings. To summarize, we believe that this Special Issue will contribute to enhancing knowledge in Information and Communication Technology security and in Cyber Crime in particular. In addition, we also hope that the presented results will stimulate further research in the important areas of information and network security. We also want to thank the Editors-in-Chief of the Security and Communication Networks journal, the researchers contributing to the special issue, and excellent reviewers for their great help and support that made this special issue possible. Wojciech Mazurczyk, Krzysztof Szczypiorski, Zoran Duric, Dengpan Ye |
Secur. Commun. Networks | 4 |
| 2016 | A framework of adaptive steganography resisting JPEG compression and detectionabstractAbstract Current typical adaptive steganography algorithms take the detection resistant capability into account adequately but usually cannot extract the embedded secret messages correctly when stego images suffer from compression attack. In order to solve this problem, a framework of adaptive steganography resisting JPEG compression and detection is proposed. Utilizing the relationship between Discrete Cosine Transformation (DCT) coefficients, the domain of messages embedding is determined; for the maximum of the JPEG compression resistant ability, the modifying magnitude of different DCT coefficients caused by messages embedding can be determined; in order to ensure the completely correct extraction of embedded messages after JPEG compression, error correct codes are used to encode the messages to be embedded; on the basis of the current distortion functions, the distortion value of DCT coefficients corresponding to the modifying magnitude in the embedding domain can be calculated; to improve the detection resistant ability of the stego images and realize the minimum distortion embedding, syndrome‐trellis codes are used to embed the encoded messages into the DCT coefficients that have a smaller distortion value. Based on the proposed framework, an adaptive steganography algorithm resisting JPEG compression and detection is designed, which utilizes the relationship between coefficients in a DCT block and the means of that in three adjacent DCT blocks. The experimental results that demonstrate the proposed algorithm not only has a good JPEG compression resistant ability but also has a strong detection resistant performance. Comparing with current J‐UNIWARD steganography under quality factor 85 of JPEG compression, the extraction error rates without pre‐compression decrease from about 50% to nearly 0, while the stego images remain a good detection resistant ability comparing with a typical robust watermarking algorithm, which shows the validity of the proposed framework. Copyright © 2016 John Wiley & Sons, Ltd. Yi Zhang 0026, Xiangyang Luo 0001, Chunfang Yang, Dengpan Ye, Fenlin Liu |
Secur. Commun. Networks | 4 |
| 2015 | A JPEG-Compression Resistant Adaptive Steganography Based on Relative Relationship between DCT CoefficientsabstractCurrent typical adaptive Steganography algorithms cannot extract the embedded secret messages correctly after compression. In order to solve this problem, a JPEG-compression resistant adaptive steganography algorithm is proposed. Utilizing the relationship between DCT coefficients, the domain of messages embedding is determined. The modifying magnitude of different DCT coefficients can be determined according to the quality factors of JPEG compression. To ensure the completely correct extraction of embedded messages after JPEG compression, the RS codes is used to encode the messages to be embedded. Besides, based on the current energy function in the PQe steganography and the distortion function in J-UNIWARD Steganography, the corresponding distortion value of DCT coefficients is calculated. With the help of that, STCs is used to embed the encoded messages into the DCT coefficients, which have a smaller distortion value. The experimental results under different quality factors of JPEG compression and different payloads demonstrate that the proposed algorithm not only has a high correct rate of extracted messages after JPEG compression, which increases from about 60% to nearly 100% comparing with J-UNIWARD steganography under quality factor 75 of JPEG compression, but also has a strong detection resistant performance. Yi Zhang 0026, Xiangyang Luo 0001, Chunfang Yang, Dengpan Ye, Fenlin Liu |
ARES | 4 |
| 2011 | Image authentication based on perceptual hash using Gabor filters
Lina Wang 0001, Xiaqiu Jiang, Shiguo Lian, Donghui Hu, Dengpan Ye |
Soft Comput. | 5 |
| 2004 | A fast motion segmentation based watermarking for MPEG-2 videoabstractTo achieve high robustness against collusion and geometric attacks, video watermarking schemes often employ local-content-based methods in which watermarks are embedded in several semantically independent regions that partitioned from video-segments. For these schemes, self-synchronization is also an important issue that needs to be taken into account in the design of watermark detectors. In this paper, a simple and fast object-based watermarking algorithm is proposed. It is based on the techniques of motion segmentation and block matching, which is consistent with MPEG-2 standard. In the proposed algorithm, a spread spectra watermark that similar to a CDMA signal is inserted into selected video blocks so that different video contents can be protected accordingly. Experimental results have demonstrated the advantage of the scheme over other exist local content-based ones in terms of computational complexity, resistance against attacks include cropping, pixel shift and recompression etc. Dengpan Ye, Yuewei Dai, Hongyu Lei |
ICARCV | 1 |
| 2004 | A Multi-feature Based Invertible Authentication Watermarking for JPEG Images
Dengpan Ye, Yaobin Mao, Yuewei Dai |
IWDW | 1 |