Rémi Cogranne

dblp:68/10087 · DBLP profile ↗
← Back
53ranked-venue papers
16as first author
13since 2021 · last 2026
0000-0002-4205-4694ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 6 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 22 · 8 first-author · 2 since 2021Computer networks · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Deep learning-based sequential detection of attacks on low-Latency network services
abstract
This paper addresses the problem of monitoring network traffic metrics for the detection of attacks in computer networks. More precisely, we consider attacks on emerging low-latency services, which typically require a specific traffic management system. These new services are subject to novel types of attacks, including traffic that does not respond normally to Explicit Congestion Notification (ECN) as this behaviour can prevent normal operation of the low-latency management system. Therefore, novel methods are required to detect novel types of attacks on novel types of services. We present a simple yet very efficient hybrid method that takes advantage of both autoencoder and transformer models for early detection of the unresponsive ECN attack, a novel type of attack targeting low-latency services. The original method is compared with the current state-of-the-art on a large real-life dataset of network traffic to show the relevance of the proposed approach is evident, achieving more than a 10% reduction in detection error rate, particularly at low false-positive rates, where the proposed detection method reaches over 90% true-positive detection for a false-alarm rate below 10 − 4 . The issue of quickest detection is also considered empirically and a trade-off between reliable detection and fast response is proposed on numerical evaluation. An ablation analysis shows that the efficiency of the method relies on the combination of the two methods jointly used in our hybrid model.
Rémi Cogranne, Marius Letourneau, Guillaume Doyen
J. Inf. Secur. Appl.1
2025 Forensics Analysis of Residual Noise Texture in digital Images for Detection of Deepfake
abstract
This paper proposes an original approach for the automatic detection of AI-generated images, using features derived from noise residuals artefacts. Contrary to most current research that leverages sophisticated deep learning models to further improve performance, this study highlights the distinct noise residual characteristics in deepfakes, facilitating the identification of AI-generative images. Our findings highlight some limitations of image models, which can be used for forensic analysis and for future AI-based text-to-image generative models. Broad numerical results on a large and diverse dataset show the interest of the identified features as well as the relevance of the present method.
Arthur Méreur, Antoine Mallet, Rémi Cogranne, Minoru Kuribayashi
ICASSP3
2024 Are Deepfakes a Game-changer in Digital Images Steganography Leveraging the Cover-Source-Mismatch?
abstract
This work explores the potential of synthetic media generated by the means of Artificial Intelligence (AI), sometimes referred to as Deepfakes, as a source of cover-objects for steganography. Deepfakes offer a vast and diverse pool of media, potentially improving steganographic security by leveraging cover-source mismatch, a challenge in steganalysis where training and testing data come from different sources. The present paper proposes an initial study on Deepfakes’ effectiveness in the field of steganography. More precisely, we propose an initial investigation to assess the impact of Deepfakes on image steganalysis performance in an operational environment. Using a wide range of image generation models and state-of-the-art methods in steganography and steganalysis, we show that Deepfakes can significantly exploit the cover-source mismatch problem but that mitigation solutions also exist. The empirical findings can inform future research on steganographic techniques that exploit cover-source mismatch for enhanced security.
Arthur Méreur, Antoine Mallet, Rémi Cogranne
ARES3
2024 Detectability of Defects in the Presence of Linear Nuisance Parameters and Images Signal-Dependent Noise
abstract
This paper addresses two general problems of imaging systems used for visual inspection and defect detection. On the one hand, the inspected object should be carefully removed in order to detect a potential defect or an anomaly. On the other hand, one of the features of imaging systems is that the noise level depends on the image intensity and so does the detectability of defects. In addition, due to the aging of the acquisition system (LEDs, Reflector), the intensity of the illumination decreases gradually over time. The present paper addresses jointly the impact of aging imaging systems and its ensuing impact on the detectability of a defect in the presence of linear nuisance parameters and signal-dependent noise.
Rémi Cogranne
ICIP1
2024 Statistical Correlation as a Forensic Feature to Mitigate the Cover-Source Mismatch
abstract
The present paper deals with the cover-source mismatch (CSM) problem in operational steganalysis. It first investigates the distribution of the noise in natural images, and shows how this property can be used to build a fingerprint of the cover- source, to address the issue of source identification from a single image. In particular, fingerprints from different noise extraction techniques are studied. Results show that these fingerprints can be complementary. The method proposed in the present paper aggregates them in a unique forensic feature to build a more accurate source identification algorithm than when using steganalysis features, such as the discrete cosine transform residual (DCTR). Last, the paper exploits the proposed forensic tool to mitigate CSM via "atomistic steganalysis". Used together with steganalysis methods, experimental results highlight the superiority of our approach, as compared to other atomistic mitigation strategies. The relevancy of these results is further studied on out- of-camera images coming from Flickr and the ALASKA dataset. We show that for some devices, our approach gives results superior to the omniscient scenario.
Antoine Mallet, Patrick Bas, Rémi Cogranne
IH&MMSec3
2024 Linking Intrinsic Difficulty and Regret to Properties of Multivariate Gaussians in Image Steganalysis
abstract
This paper deals with the Cover-Source Mismatch (CSM) problem faced in operational steganalysis. Based on a multivariate Gaussian model of the distribution of the noise contained in natural images, it provides proxies for the two important empirical measures of CSM: intrinsic difficulty and regret. The former can be modeled with the determinant of the covariance matrix of the noise present in an image. The latter can be predicted with a modified Kullback-Leibler divergence between the distribution of the noises of images coming from different cover-sources. We first recall the reasoning behind the multivariate Gaussian model of the noise, and detail how to compute the statistic of the distribution of the noise. Then, our proposed models are compared to empirical data with a specifically designed cover-source generation process. For both quantities, very high correlation coefficients between the model and the observations are obtained. Finally, realistic cover-sources are used to further illustrate the relevance of our model.
Antoine Mallet, Rémi Cogranne, Patrick Bas
IH&MMSec2
2024 Cover-source mismatch in steganalysis: systematic review
abstract
Operational steganalysis contends with a major problem referred to as the cover-source mismatch (CSM), which is essentially a difference in distribution caused by different parameters and settings over training and test data. Despite it being of fundamental importance in an operational context, the CSM problem is often overlooked in the literature. With the goal to increase the visibility of this problem and attract the interest of the community, the present paper proposes a systematic review of the literature. It summarizes gathered knowledge and major open questions over the last 20 years of active research on CSM: terminology, methods of measurement, known causes, and mitigation strategies. Over 100 papers exploring, mitigating, assessing, or discussing steganalysis under train-test mismatch were collected by sampling scholar databases, and tracing references, cited and generated. For image steganalysis, the literature provided enough evidence to quantify the impact of causes, and the effectiveness of mitigation strategies.
Antoine Mallet, Martin Benes 0001, Rémi Cogranne
EURASIP J. Inf. Secur.3
2023 Analysis and Mitigation of the False Alarms of the Reverse JPEG Compatibility Attack
abstract
The Reverse JPEG Compatibility Attack can be used for steganalysis of JPEG images compressed with Quality Factor 100 by detecting increased variance of decompression rounding errors. In this work, we point out the dangers associated with this attack by showing that in an uncontrolled environment, the variance can be elevated simply by using a different JPEG compressor. If not careful, the steganalyst can wrongly misclassify cover images. In order to deal with the diversity associated to the devices or softwares generating JPEGs, we propose in this paper to build a deep learning detector trained on a huge dataset of downloaded images. Experimental evaluation shows that such a detector can provide operational false alarms as small as 10-4, while still correctly classifying 90% of stego images. Furthermore, it is shown that this performance is directly applicable to other image datasets. As a side product, we indicate that the attack is not applicable to images developed with a specific JPEG compressor based on the trunc quantization function.
Jan Butora, Patrick Bas, Rémi Cogranne
IH&MMSec3
2022 UNCOVER: Development of an efficient steganalysis framework for uncovering hidden data in digital media
abstract
This paper presents the general goals of Horizon 2020 project UNCOVER, whose overall purpose is to close the gap between academic work and operational needs in the fields of data-hiding. While digital data-hiding is a relatively new area of research, our motivation in this project has been rooted in the growing gap between the academic community and the operational needs of a ”real-life” scenario of object inspection in order to UNCOVER the presence of data secretly hidden.
Vaila Leask, Rémi Cogranne, Dirk Borghys, Helena Bruyninckx
ARES2
2022 Efficient Steganography in JPEG Images by Minimizing Performance of Optimal Detector
abstract
Since the introduction of adaptive steganography, most of the recent research works seek at designing cost functions that are evaluated against steganalysis methods. While those approaches have been successful, they rely on intuitive principles and ad-hoc costs associated with each pixel or Discrete Cosine Transform (DCT) coefficient. Beyond the empirical assessments, the insights one can get from such approaches are very limited. On the opposite, this paper presents an original method for steganography in JPEG images that exploits a statistical model of the DCT coefficients. Within the framework of hypothesis testing theory, we use a statistical model of covers to derive the analytical expression of the most powerful detector. The objective of the steganographer is to minimize the statistical performance of this “omniscient detector” which represents a “worst-case” scenario for security. This paper shows how this method allows designing effective steganography, in terms of both security and computational complexity, in the two main use cases: when having only one single JPEG image and when the uncompressed image is available, case also known as Side-Informed (SI). A wide range of numerical comparisons shows that the proposed method outperforms the current state-of-the-art especially against the latest and most accurate steganalysis approaches based on Deep Learning.
Rémi Cogranne, Eva Giboulot, Patrick Bas
IEEE Trans. Inf. Forensics Secur.1
2022 Multivariate Side-Informed Gaussian Embedding Minimizing Statistical Detectability
abstract
Steganography schemes based on a deflection criterion for embedding posses a clear advantage against schemes based on heuristics as they provide a direct link between theoretical detectability and empirical performance. However, this advantage depends on the accuracy of the cover and stego model underlying the embedding scheme. In this work we propose an original steganography scheme based on a realistic model of sensor noise, taking into account the camera model, the ISO setting and the processing pipeline. Exploiting this statistical model allows us to take correlations between DCT coefficients into account. Several types of dependency models are presented, including a very general lattice model which accurately models dependencies introduced by a large class of processing pipelines of interest. We show in particular that the stego signal which minimizes the KL divergence under this model has a covariance proportional to the cover noise covariance. The resulting embedding scheme achieves state-of-the-art performances which go well beyond the current standards in side-informed JPEG steganography.
Eva Giboulot, Patrick Bas, Rémi Cogranne
IEEE Trans. Inf. Forensics Secur.3
2021 Assessing the Threats Targeting Low Latency Traffic: the Case of L4S
abstract
New types of services with low-latency requirements have become a major challenge for the future Internet. Many optimizations, all targeting the latency reduction have been proposed. Among them, jointly re-architecting congestion control and active queue management has been particularly considered. In this effort, the L4S (Low Latency, Low Loss and Scalable Throughput) proposal aims at allowing both classic and low-latency traffic to cohabit within a single node architecture. Although this architecture sounds promising for latency improvement, it can be exploited by an attacker to perform malicious actions whose purposes are to defeat its low-latency feature and consequently make their supported applications unusable. In this paper, we analyze a set of weaknesses of L4S architecture and show that application-layer protocols such as QUIC can easily be hacked in order to exploit the over-sensitivity of those new services to network variations. By implementing undesirable flows in a real testbed and evaluating how they impact the proper delivery of low-latency flows, we demonstrate their reality and relevance for future deployments.
Marius Letourneau, Kouame Boris N'Djore, Guillaume Doyen, Bertrand Mathieu, Rémi Cogranne, Huu Nghia Nguyen
CNSM5
2021 Detectability-Based JPEG Steganography Modeling the Processing Pipeline: The Noise-Content Trade-off
abstract
The current art of steganography shows that schemes using a deflection criterion (such as MiPOD) for JPEG steganography are usually subpar with respect to distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. However, this statistically-based method provides a better assessment of the detectability of hidden data as well as theoretical guarantees under a given model. In this paper, we propose a method to obtain better estimates of the variances of DCT coefficients by taking into account the dependencies introduced by development pipeline on pixels. A second method, which is a side-informed extension of Gaussian Embedding in the JPEG domain using quantization error as side-information, is also formulated and shown to achieve state-of-the-art performances. Eventually, the trade-off between noise and content complexity in steganography is thoroughly analyzed through the lenses of these two new methods using a wide range of numerical experiments.
Eva Giboulot, Rémi Cogranne, Patrick Bas
IEEE Trans. Inf. Forensics Secur.2
2020 Selection-Channel-Aware Reverse JPEG Compatibility for Highly Reliable Steganalysis of JPEG Images
abstract
This paper deeply studies the principle of the recent reverse JPEG compatibility attack [1]. This analysis allows us to cast the problem of hidden data detection in DCT coefficients within hypothesis testing theory. The optimal LR test, thought efficient, is rather computationally expensive. Therefore, mild assumptions are used to simplify the detection problem dramatically and design a test that is simple yet extremely efficient and reliable. It is shown that the proposed detector is way more efficient than the original statistical test [1], and allows highly reliable detection of data hidden within JPEG images.
Rémi Cogranne
ICASSP1
2020 JPEG Steganography with Side Information from the Processing Pipeline
abstract
The current art in schemes using deflection criterion such as Mi-POD for JPEG steganography is either under-performing or on par with distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. In this paper, we propose a method to better estimate the variances of DCT coefficients by taking into account the dependencies between pixels that come from the development pipeline. Using this estimate, we are able to extend statistically-informed steganographic schemes to the JPEG domain while significantly outperforming the current state-of-the-art JPEG steganography. An extension of Gaussian Embedding in the JPEG domain using quantization error as side-information is also formulated and shown to attain state-of-the-art performances.
Eva Giboulot, Rémi Cogranne, Patrick Bas
ICASSP2
2020 Steganography by Minimizing Statistical Detectability: The cases of JPEG and Color Images
abstract
This short paper presents a novel method for steganography in JPEG-compressed images, extended the so-called MiPOD scheme based on minimizing the detection accuracy of the most-powerful test using a Gaussian model of independent DCT coefficients. This method is also applied to address the problem of embedding into color JPEG images. The main issue in such case is that color channels are not processed in the same way and, hence, a statistically based approach is expected to bring significant improvements when one needs to consider heterogeneous channels together.
Rémi Cogranne, Eva Giboulot, Patrick Bas
IH&MMSec1
2020 JPEG Steganography and Synchronization of DCT Coefficients for a Given Development Pipeline
abstract
This paper proposes to use the statistical analysis of the correlation between DCT coefficients to design a new synchronization strategy that can be used for cost-based steganographic schemes in the JPEG domain. First, an analysis is performed on the covariance matrix of DCT coefficients of neighboring blocks after a development pipeline similar to the one used to generate BossBase, and applied on a photonic noise. This analysis exhibits (i) a decomposition into 8 disjoint sets of uncorrelated coefficients (4 sets per block used by 2 disjoint lattices) and (ii) the fact that each DCT coefficient is correlated with 38 other coefficients belonging either to the same block or to connected blocks. Using the uncorrelated groups, an embedding scheme can be designed using only 8 disjoint lattices. The proposed embedding scheme relies on ingredients. Firstly, we convert the empirical costs associated to one each coefficient into a Gaussian distribution whose variance is directly computed from the embedding costs. Secondly we derive conditional Gaussian distributions from a multivariate distribution considering only the correlated coefficients which have been already modified by the embedding scheme. This covariance matrix takes into account both the correlations exhibited by the analysis of the covariance matrix and the variance derived from the costs. This synchronization scheme enables to obtain a gain of $P_E$ of at least $7%$ at $QF95$ for an embedding rate close to 0.3 bnzac coefficient using DCTR feature sets for both UERD and JUniward.
Théo Taburet, Patrick Bas, Wadih Sawaya, Rémi Cogranne
IH&MMSec4
2020 Effects and solutions of Cover-Source Mismatch in image steganalysis
Eva Giboulot, Rémi Cogranne, Dirk Borghys, Patrick Bas
Signal Process. Image Commun.2
2019 The ALASKA Steganalysis Challenge: A First Step Towards Steganalysis
abstract
This paper presents ins and outs of the ALASKA challenge, a steganalysis challenge built to reflect the constraints of a forensic steganalyst. We motivate and explain the main differences w.r.t. the BOSS challenge (2010), specifically the use of a ranking metric prescribing high false positive rates, the analysis of a large diversity of different image sources and the use of a collection of steganographic schemes adapted to handle color JPEGs. The core of the challenge is also described, this includes the RAW image data-set, the implementations used to generate cover images and the specificities of the embedding schemes. The very first outcomes of the challenge are then presented, and the impacts of different parameters such as demosaicking, filtering, image size, JPEG quality factors and cover-source mismatch are analyzed. Eventually, conclusions are presented, highlighting positive and negative points together with future directions for the next challenges in practical steganalysis.
Rémi Cogranne, Eva Giboulot, Patrick Bas
IH&MMSec1
2019 Modelling Interactions in Rescue Operations
abstract
In rescue operations, situation awareness is very critical to decision-makers and responders in order to reduce the bad consequences. Furthermore, a good collaboration between services and organizations is vital to achieve successful operations. Therefore, a good communication and information exchange between actors is crucial to meet these requirements. This work aims to enhance situation awareness in rescue operations by supporting communication and interaction between participating actors. To do that, we start by studying interactions, communication, and information flow. After that, we look forward to design and implement a communication system that will be used by rescuers and first responders. In this paper, we show our preliminary results in which we model the interactions.
Samer Chehade, Matta Nada, Jean-Baptiste Pothin, Rémi Cogranne
SMC4
2019 Reliable Detection of Interest Flooding Attack in Real Deployment of Named Data Networking
abstract
Named data networking (NDN) is a disruptive yet promising architecture for the future Internet, in which the content diffusion mechanisms are shifted from the conventional host-centric to content-centric ones so that the data delivery can be significantly improved. After a decade of research and development, NDN and the related NDN forwarding daemon implementations are now mature enough to enable stakeholders, such as telcos, to consider them for a real deployment. Consequently, NDN and IP will likely cohabit, and the future Internet may be formed of isolated administrative domains, each deploying one of these two network paradigms. The security question of the resulting architecture naturally arises. In this paper, we consider the case of denial of service. Even though the interest flooding attack (IFA) has been largely studied and mitigated through NACK packets in pure NDN networks, we demonstrate in this paper through experimental assessments that there are still some ways to mount such an attack, and especially in the context of coupling NDN with IP, which can hardly be addressed by current solutions. Subsequently, we leverage the hypothesis testing theory to develop a generalized likelihood ratio test adapted to evolve IFA attacks. Simulations show the relevance of the proposed model for guaranteeing the prescribed probability of false alarm and highlight the trade-off between detection power and delay. Finally, we consider a real deployment scenario where NDN is coupled with IP to carry HTTP traffic. We show that the model of IFA attacks is not very accurate in practice and further develops a sequential detector to keep a high detection accuracy. By considering data from the testbed, we show the efficiency of the overall detection method.
Tan N. Nguyen, Hoang Long Mai, Rémi Cogranne, Guillaume Doyen, Wissam Mallouli, Luong Nguyen, Moustapha El Aoun, Edgardo Montes de Oca, Olivier Festor
IEEE Trans. Inf. Forensics Secur.3
2018 Data Interpretation Support in Rescue Operations: Application for French Firefighters
abstract
This work aims at developing a system that supports French firefighters in data interpretation during rescue operations. An application ontology is proposed based on existing crisis management ones and operational expertise collection. After that, a knowledge-based system will be developed and integrated in firefighters' environment. Our first studies are shown in this paper.
Samer Chehade, Matta Nada, Jean-Baptiste Pothin, Rémi Cogranne
AICCSA4
2018 Towards a security monitoring plane for named data networking and its application against content poisoning attack
abstract
Named Data Networking (NDN) is the most mature proposal of the Information Centric Networking paradigm, a clean-slate approach for the Future Internet. Although NDN was designed to tackle security issues inherent to IP networks natively, newly introduced security attacks in its transitional phase threaten NDN's practical deployment. Therefore, a security monitoring plane for NDN is indispensable before any potential deployment of this novel architecture in an operating context by any provider. We propose an approach for the monitoring and anomaly detection in NDN nodes leveraging Bayesian Network techniques. A list of monitored metrics is introduced as a quantitative measure to feature the behavior of an NDN node. By leveraging the hypothesis testing theory, a micro detector is developed to detect whenever the metric significantly changes from its normal behavior. A Bayesian network structure that correlates alarms from micro detectors is designed based on the expert knowledge of the NDN specification and the NFD implementation. The relevance and performance of our security monitoring approach are demonstrated by considering the Content Poisoning Attack (CPA), one of the most critical attacks in NDN, through numerous experiment data collected from a real NDN deployment.
Hoang Long Mai, Tan N. Nguyen, Guillaume Doyen, Rémi Cogranne, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor
NOMS4
2018 Multimedia Security: Novel Steganography and Privacy Preserving
abstract
International audience
Zhenxing Qian, Kim-Kwang Raymond Choo, Rémi Cogranne, Xinpeng Zhang 0001
Secur. Commun. Networks3
2018 Statistical decision methods in the presence of linear nuisance parameters and despite imaging system heteroscedastic noise: Application to wheel surface inspection
Karim Tout, Rémi Cogranne, Florent Retraint
Signal Process.2
2018 Detecting Botclouds at Large Scale: A Decentralized and Robust Detection Method for Multi-Tenant Virtualized Environments
abstract
Cloud computing has gained an important role in providing high quality and cost-effective IT services by outsourcing part of their operations to dedicated cloud providers. If intrinsic security issues of this architecture have been extensively studied, it has recently been considered as a ready-to-use platform able to perform malicious activities, thus offering new targets for indirect threats. However, its large scale, the heterogeneous and dynamic nature of the activities it executes, as well as multi-tenancy and privacy-related issues, make the security operation complex. Consequently, cloud providers can hardly detect and mitigate malicious activities they unknowingly host. Leveraging the autonomic paradigm represents a promising solution to face such a complexity, but it requires efficient grounded monitoring and analysis functions to efficiently detect malicious activities hidden within the large number of legitimate ones. In this effort, this paper presents a robust and cost-effective solution to detect malicious activities in a public virtualized environment. Its contribution is twofold: 1) a scalable and robust workload estimation of the virtual host activities in a cloud and 2) a detection algorithm able to discriminate infected hosts with low malicious activities hidden within their legitimate workload and potentially scattered across several tenants. For both of these contributions, we establish their theoretical performance, which demonstrates their optimality, and we evaluate their efficiency on a dataset made of real data collected on PlanetLab. Finally, we study the scalability on a large dataset that consists of simulated data resulting from the real dataset modeling. This demonstrates to what extent the proposal exhibits an excellent sharpness and a reasonable cost, even at a very large scale.
Rémi Cogranne, Guillaume Doyen, Nisrine Ghadban, Badis Hammi
IEEE Trans. Netw. Serv. Manag.1
2017 Practical strategies for content-adaptive batch steganography and pooled steganalysis
abstract
This paper investigates practical strategies for distributing payload across images with content-adaptive steganography and for pooling outputs of a single-image detector for steganalysis. Adopting a statistical model for the detector's output, the steganographer minimizes the power of the most powerful detector of an omniscient Warden, while the Warden, informed by the payload spreading strategy, detects with the likelihood ratio test in the form of a matched filter. Experimental results with state-of-the-art content-adaptive additive embedding schemes and rich models are included to show the relevance of the results.
Rémi Cogranne, Vahid Sedighi, Jessica J. Fridrich
ICASSP1
2017 A decentralized approach for adaptive workload estimation in virtualized environments
abstract
Cloud computing is gaining an important role in providing high quality IT services. However, the heterogeneous and dynamic nature of the activities it hosts makes the related management operations, serving performance or security purposes, complexes. Leveraging the autonomic paradigm, represents a promising solution but it requires efficient grounded monitoring and analysis functions which can in turn implement advanced control algorithms. In this effort, this paper presents a robust and cost effective solution to monitor and estimate the workload in a virtualized environment. It consists in a decentralized algorithm leveraging an incremental Principal Component Analysis (PCA) featuring the system activity of multi-tenants execution environments. To evaluate the relevance of our proposal in terms of both performance and cost, we consider real execution traces of more than one thousand PlanetLab containers hosted on more than forty servers belonging to more than one hundred tenants.
Nisrine Ghadban, Rémi Cogranne, Guillaume Doyen
IM2
2017 Content Poisoning in Named Data Networking: Comprehensive characterization of real deployment
abstract
Information Centric Networking (ICN) is seen as a promising solution to re-conciliate the Internet usage with its core architecture. However, to be considered as a realistic alternative to IP, ICN must evolve from a pure academic proposition deployed in test environments to an operational solution in which security is assessed from the protocol design to its running implementation. Among ICN solutions, Named Data Networking (NDN), together with its reference implementation NDN Forwarding Daemon (NFD), acts as the most mature proposal but its vulnerability against the Content Poisoning Attack (CPA) is considered as a critical threat that can jeopardize this architecture. So far, existing works in that area have fallen into the pit of coupling a biased and partial phenomenon analysis with a proposed solution, hence lacking a comprehensive understanding of the attack's feasibility and impact in a real network. In this paper, we demonstrate through an experimental measurement campaign that CPA can easily and widely affect NDN. Our contribution is threefold: (1) we propose three realistic attack scenarios relying on both protocol design and implementation weaknesses; (2) we present their implementation and evaluation in a testbed based on the latest NFD version; and (3) we analyze their impact on the different ICN nodes (clients, access and core routers, content provider) composing a realistic topology.
Tan N. Nguyen, Xavier Marchal, Guillaume Doyen, Thibault Cholez, Rémi Cogranne
IM5
2017 Individual camera device identification from JPEG images
Florent Retraint, Rémi Cogranne, Thanh Hai Thai
Signal Process. Image Commun.3
2017 JPEG Quantization Step Estimation and Its Applications to Digital Image Forensics
abstract
The goal of this paper is to propose an accurate method for estimating quantization steps from an image that has been previously JPEG-compressed and stored in lossless format. The method is based on the combination of the quantization effect and the statistics of discrete cosine transform (DCT) coefficient characterized by the statistical model that has been proposed in our previous works. The analysis of quantization effect is performed within a mathematical framework, which justifies the relation of local maxima of the number of integer quantized forward coefficients with the true quantization step. From the candidate set of the true quantization step given by the previous analysis, the statistical model of DCT coefficients is used to provide the optimal quantization step candidate. The proposed method can also be exploited to estimate the secondary quantization table in a double-JPEG compressed image stored in lossless format and detect the presence of JPEG compression. Numerical experiments on large image databases with different image sizes and quality factors highlight the high accuracy of the proposed method.
Thanh Hai Thai, Rémi Cogranne, Florent Retraint, Thi-Ngoc-Canh Doan
IEEE Trans. Inf. Forensics Secur.2
2016 Content-Adaptive Steganography by Minimizing Statistical Detectability
abstract
Most current steganographic schemes embed the secret payload by minimizing a heuristically defined distortion. Similarly, their security is evaluated empirically using classifiers equipped with rich image models. In this paper, we pursue an alternative approach based on a locally estimated multivariate Gaussian cover image model that is sufficiently simple to derive a closed-form expression for the power of the most powerful detector of content-adaptive least significant bit matching but, at the same time, complex enough to capture the non-stationary character of natural images. We show that when the cover model estimator is properly chosen, the state-of-the-art performance can be obtained. The closed-form expression for detectability within the chosen model is used to obtain new fundamental insight regarding the performance limits of empirical steganalysis detectors built as classifiers. In particular, we consider a novel detectability limited sender and estimate the secure payload of individual images.
Vahid Sedighi, Rémi Cogranne, Jessica J. Fridrich
IEEE Trans. Inf. Forensics Secur.2
2015 Source camera device identification based on raw images
abstract
This paper investigates the problem of identifying the source imaging device of the same model for a natural raw image. The approach is based on the Poissonian-Gaussian noise model which can accurately describe the distribution of the given image. This model relies on two parameters considered as unique fingerprint to identify source cameras of the same model. The identification is cast in the framework of hypothesis testing theory. In an ideal context where all model parameters are perfectly known, the Likelihood Ratio Test (LRT) is presented and its performance is theoretically established. The statistical performance of LRT serves as an upper bound of the detection power. For a practice use, when the image parameters are unknown and camera parameters are known, a detector based on estimation of those parameters is designed. Numerical results on simulated data and real natural raw images highlight the relevance of our proposed approach.
Florent Retraint, Rémi Cogranne, Thanh Hai Thai
ICIP3
2015 An optimal statistical test for robust detection against interest flooding attacks in CCN
abstract
Confronting the changing demand of users, the current Internet is revealing its limitations. Information Centric Network (ICN) are Future Internet proposals which are based on named data objects. In order to actually replace its predecessor, ICN must be able to resist existent threats in the current Internet, especially the Denial of Service (DoS) attack. In this paper, we focus on Interest flooding - a new type of DoS attack in Content Centric Network (CCN). Several solutions for this threat have been introduced, but they do not solve the problem in a satisfying way because of some drawbacks in either their detection performance, scalability support or restricted scenario of usage. Our goal is to design a reliable, low resources-consuming detection method against Interest flooding attack in CCN. A detection scheme must be attended since a lot of resources consumed by unnecessarily continuous countermeasure can be saved by a dependable detector. Like no other detectors in proposed solutions, our detector is based on statistical hypotheses testing theory. The achieved result is a low resources-consuming detector that can be deployed globally on each CCN router. The false alarm probability of our detector can be controlled at will. Its statistical power can be theoretically established and evaluated precisely. To validate our contribution, numerical results show the relevance of the proposed approach and the sharpness of theoretical results.
Tan N. Nguyen, Rémi Cogranne, Guillaume Doyen
IM2
2015 Steganalysis of JSteg algorithm using hypothesis testing theory
abstract
This paper investigates the statistical detection of JSteg steganography. The approach is based on a statistical model of discrete cosine transformation (DCT) coefficients challenging the usual assumption that among a subband all the coefficients are independent and identically distributed (i. i. d.). The hidden information-detection problem is cast in the framework of hypothesis testing theory. In an ideal context where all model parameters are perfectly known, the likelihood ratio test (LRT) is presented, and its performances are theoretically established. The statistical performance of LRT serves as an upper bound for the detection power. For a practical use where the distribution parameters are unknown, by exploring a DCT channel selection, a detector based on estimation of those parameters is designed. The loss of power of the proposed detector compared with the optimal LRT is small, which shows the relevance of the proposed approach.
Florent Retraint, Rémi Cogranne, Cathel Zitzmann
EURASIP J. Inf. Secur.3
2015 Generalized signal-dependent noise model and parameter estimation for natural images
Thanh Hai Thai, Florent Retraint, Rémi Cogranne
Signal Process.3
2015 Modeling and Extending the Ensemble Classifier for Steganalysis of Digital Images Using Hypothesis Testing Theory
abstract
The machine learning paradigm currently predominantly used for steganalysis of digital images works on the principle of fusing the decisions of many weak base learners. In this paper, we employ a statistical model of such an ensemble and replace the majority voting rule with a likelihood ratio test. This allows us to train the ensemble to guarantee desired statistical properties, such as the false-alarm probability and the detection power, while preserving the high detection accuracy of original ensemble classifier. It also turns out the proposed test is linear. Moreover, by replacing the conventional total probability of error with an alternative criterion of optimality, the ensemble can be extended to detect messages of an unknown length to address composite hypotheses. Finally, the proposed well-founded statistical formulation allows us to extend the ensemble to multi-class classification with an appropriate criterion of optimality and an optimal associated decision rule. This is useful when a digital image is tested for the presence of secret data hidden by more than one steganographic method. Numerical results on real images show the sharpness of the theoretically established results and the relevance of the proposed methodology.
Rémi Cogranne, Jessica J. Fridrich
IEEE Trans. Inf. Forensics Secur.1
2014 Statistical detection of Jsteg steganography using hypothesis testing theory
abstract
This paper investigates the statistical detection of Jsteg steganography. The approach is based on the statistical model of Discrete Cosine Transformation (DCT) coefficients. The hidden information detection problem is cast in the framework of hypothesis testing theory. In an ideal context where all model parameters are perfectly known, the Likelihood Ratio Test (LRT) is presented and its performances are theoretically established. The statistical performance of LRT serves as an upper bound of the detection power. For a practical use, when the distribution parameters are unknown, a detector based on estimation of those parameters is designed. The loss of power of the proposed detector, compared with the optimal LRT is small, which shows the relevance of the proposed approach.
Cathel Zitzmann, Florent Retraint, Rémi Cogranne
ICIP4
2014 Detection of JSteg algorithm using hypothesis testing theory and a statistical model with nuisance parameters
abstract
This paper investigates the statistical detection of data hidden within DCT coefficients of JPEG images using a Laplacian distribution model. The main contributions is twofold. First, this paper proposes to model the DCT coefficients using a Laplacian distribution but challenges the usual assumption that among a sub-band all the coefficients follow are independent and identically distributed (i.i.d). In this paper it is assumed that the distribution parameters change from DCT coefficient to DCT coefficient. Second this paper applies this model to design a statistical test, based on hypothesis testing theory, which aims at detecting data hidden within DCT coefficient with the JSteg algorithm. The proposed optimal detector carefully takes into account the distribution parameters as nuisance parameters. Numerical results on simulated data as well as on numerical images database show the relevance of the proposed model and the good performance of the ensuing test.
Cathel Zitzmann, Rémi Cogranne, Florent Retraint
IH&MMSec3
2014 Optimal detector for camera model identification based on an accurate model of DCT coefficients
abstract
The goal of this paper is to design a statistical test for the camera model identification problem. The approach is based on the state-of-the-art model of Discret Cosine Transform (DCT) coefficients to capture their statistical difference, which jointly results from different sensor noises and in-camera processing algorithms. The noise model parameters are considered as camera fingerprint to identify camera models. The camera model identification problem is cast in the framework of hypothesis testing theory. In an ideal context where all model parameters are perfectly known, this paper studies the optimal detector given by the Likelihood Ratio Test (LRT) and analytically establishes its statistical performances. In practice, a Generalized LRT is designed to deal with the difficulty of unknown parameters such that it can meet a prescribed false alarm probability while ensuring a high detection performance. Numerical results on simulated database and natural JPEG images highlight the relevance of the proposed approach.
Thanh Hai Thai, Rémi Cogranne, Florent Retraint
MMSP2
2014 Statistical detection of defects in radiographic images using an adaptive parametric model
Rémi Cogranne, Florent Retraint
Signal Process.1
2014 A local adaptive model of natural images for almost optimal detection of hidden data
Rémi Cogranne, Cathel Zitzmann, Florent Retraint, Igor V. Nikiforov, Philippe Cornu, Lionel Fillatre
Signal Process.1
2014 Statistical detection of data hidden in least significant bits of clipped images
Thanh Hai Thai, Florent Retraint, Rémi Cogranne
Signal Process.3
2014 Camera Model Identification Based on the Heteroscedastic Noise Model
abstract
The goal of this paper is to design a statistical test for the camera model identification problem. The approach is based on the heteroscedastic noise model, which more accurately describes a natural raw image. This model is characterized by only two parameters, which are considered as unique fingerprint to identify camera models. The camera model identification problem is cast in the framework of hypothesis testing theory. In an ideal context where all model parameters are perfectly known, the likelihood ratio test (LRT) is presented and its performances are theoretically established. For a practical use, two generalized LRTs are designed to deal with unknown model parameters so that they can meet a prescribed false alarm probability while ensuring a high detection performance. Numerical results on simulated images and real natural raw images highlight the relevance of the proposed approach.
Thanh Hai Thai, Rémi Cogranne, Florent Retraint
IEEE Trans. Image Process.2
2014 Statistical Model of Quantized DCT Coefficients: Application in the Steganalysis of Jsteg Algorithm
abstract
The goal of this paper is to propose a statistical model of quantized discrete cosine transform (DCT) coefficients. It relies on a mathematical framework of studying the image processing pipeline of a typical digital camera instead of fitting empirical data with a variety of popular models proposed in this paper. To highlight the accuracy of the proposed model, this paper exploits it for the detection of hidden information in JPEG images. By formulating the hidden data detection as a hypothesis testing, this paper studies the most powerful likelihood ratio test for the steganalysis of Jsteg algorithm and establishes theoretically its statistical performance. Based on the proposed model of DCT coefficients, a maximum likelihood estimator for embedding rate is also designed. Numerical results on simulated and real images emphasize the accuracy of the proposed model and the performance of the proposed test.
Thanh Hai Thai, Rémi Cogranne, Florent Retraint
IEEE Trans. Image Process.2
2013 A new tomography model for almost optimal detection of anomalies
abstract
In this paper a new methodology for detecting anomaly from few tomography projections is presented. This methodology exploits a statistical model adapted to the content of radiographs together with hypothesis testing theory. The main contributions are the following. First, using a generic model of the tomography acquisition pipeline, the whole non-destructive testing process is entirely automated. Second, by using testing theory the statistical properties of the proposed test are analytically established. This particularly permits the guaranteeing of a prescribed false-alarm probability and allows us to show that the proposed test is almost optimal. Experimental results show the sharpness of the established results and the relevance of the methodology.
Rémi Cogranne, Florent Retraint
ICIP1
2013 Asymptotically optimal detection of LSB matching data hiding
abstract
This paper proposes a novel method, based on hypothesis testing theory, to detect data hidden with the LSB matching. When all the image parameters, a test which asymptotically maximizes the detection power and guarantees a false-alarm probability, is presented and its statistical properties are analytically given in a closed-form. This provides an asymptotic upper-bound for the power of any detector for LSB matching. In practice the image parameters are unknown. A Generalized Likelihood Ratio Test (GLRT) is proposed and its statistical properties are also analytically established. Numerical results and comparisons with prior art detectors highlight the relevance of the proposed methodology.
Rémi Cogranne, Thanh Hai Thai, Florent Retraint
ICIP1
2013 Steganalysis of Jsteg algorithm based on a novel statistical model of quantized DCT coefficients
abstract
The goal of the paper is to propose an optimal statistical test for the steganalysis of Jsteg algorithm. The test is based on a state-of-the-art statistical model of quantized Discrete Cosine Transform (DCT) coefficients that allows us to reliably detect any small change in a cover image due to hidden information. By formulating the hidden information detection as a hypothesis testing problem, the paper designs the most powerful Likelihood Ratio Test (LRT) assuming that all model parameters are perfectly known. The statistical performance of the LRT is analytically provided. Numerical results and comparison with other detectors highlight the relevance of the proposed approach.
Thanh Hai Thai, Rémi Cogranne, Florent Retraint
ICIP2
2013 Moving steganography and steganalysis from the laboratory into the real world
abstract
There has been an explosion of academic literature on steganography and steganalysis in the past two decades. With a few exceptions, such papers address abstractions of the hiding and detection problems, which arguably have become disconnected from the real world. Most published results, including by the authors of this paper, apply "in laboratory conditions" and some are heavily hedged by assumptions and caveats; significant challenges remain unsolved in order to implement good steganography and steganalysis in practice. This position paper sets out some of the important questions which have been left unanswered, as well as highlighting some that have already been addressed successfully, for steganography and steganalysis to be used in the real world.
Andrew D. Ker, Patrick Bas, Rainer Böhme, Rémi Cogranne, Scott Craver, Tomás Filler, Jessica J. Fridrich, Tomás Pevný
IH&MMSec4
2013 Application of hypothesis testing theory for optimal detection of LSB matching data hiding
Rémi Cogranne, Florent Retraint
Signal Process.1
2013 An Asymptotically Uniformly Most Powerful Test for LSB Matching Detection
abstract
This paper investigates the detection of information hidden in digital media by the least significant bit (LSB) matching scheme. In a theoretical context of known medium parameters, two important results are presented. First, based on the likelihood ratio test, we present a test that asymptotically maximizes the detection power whatever the embedding rate might be. Second, the statistical properties of this test are analytically calculated; it is particularly shown that the decision threshold which warrants a given probability of false-alarm is independent of inspected medium parameters. This provides an asymptotic upper-bound for the detection power of any test that aims at detecting data hidden with the LSB matching method. In practice, when detecting LSB matching, the unknown medium parameters have to be estimated. Based on a local model of digital media, a generalized likelihood ratio test is presented by replacing the unknown parameters by their estimation. Numerical results on large databases highlight the relevance of the proposed methodology and comparison with state-of-the-art detectors shows that the proposed tests perform well.
Rémi Cogranne, Florent Retraint
IEEE Trans. Inf. Forensics Secur.1
2012 Hidden information detection based on quantized Laplacian distribution
abstract
The goal of this paper is to propose the optimal statistical test based on the modeling of discrete cosine transform (DCT) coefficients with a quantified Laplacian distribution. This paper focuses on the detection of hidden information embedded in bits of the DCT coefficients of a JPEG image. This problem is difficult, in terms of statistical decision, for two main reasons: first, the number of DCT coefficients used to conceal the hidden bits is random; second, the JPEG image compression induces a strong quantization of DCT coefficients. The proposed test explicitly takes into account the randomness of the number of DCT coefficients used. It maximizes the probability of hidden information detection by ensuring a prescribed level of false alarm.
Cathel Zitzmann, Rémi Cogranne, Lionel Fillatre, Igor V. Nikiforov, Florent Retraint, Philippe Cornu
ICASSP2
2011 Statistical decision by using quantized observations
abstract
In the last two decades substantial progress has been made in the detection of hidden information or hidden communication channels in media files or streams. Typically, it is necessary to reliably detect in a huge set of files (image, audio, and video) which of these files contain the hidden information. The goal of this paper is to study the problem of hypothesis testing based on quantized observations by using a parametric statistical model with nuisance parameters and to apply the obtained tests to the hidden information detection.
Rémi Cogranne, Cathel Zitzmann, Lionel Fillatre, Florent Retraint, Igor V. Nikiforov, Philippe Cornu
ISIT1