VLDB 2026 Research / reviewers in the wild / expert
Patrick Bas
dblp:77/1713
· DBLP profile ↗
65ranked-venue papers
11as first author
22since 2021 · last 2026
0000-0003-0873-5872ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 42 · 2 first-author · 21 since 2021Graphics, computer vision, multimedia, augmented reality and games · 17 · 8 first-author · 1 since 2021Artificial intelligence and machine learning · 5 · 1 first-authorTheory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tackle CSM in JPEG Steganalysis with Data AdaptationabstractSteganalysis models excel on benchmark datasets but struggle in the wild when analyzed images are produced by a processing pipeline unseen during training. This problem known as Cover Source Mismatch (CSM) is particularly hard in realistic settings where practitioners (1) have access to only a small, unlabeled dataset, (2) are unsure of the processing techniques applied to these images, and (3) lack information on the proportion of covers and stegos in that set. To answer this challenge, we introduce TADA (Target Alignment through Data Adaptation), a framework learning to emulate the unknown processing pipeline from a small unlabeled target set. This architecture is trained with a loss combining residual covariance alignment, residual distribution matching, and a ℓ2 loss constraining the emulator to produce realistic images. Across toy and operational targets, TADA yields substantial gains in robustness to CSM and improves operational generalization compared to strong holistic and atomistic baselines. Additional resources are available at this link: https://github.com/RonyAbecidan/TADA. Rony Abecidan, Vincent Itier, Jérémie Boulanger, Patrick Bas, Tomás Pevný |
IH&MMSec | 4 |
| 2026 | Better Inversion of Diffusion Models for Generative SteganographyabstractTraditional inversion algorithms attempt to directly invert the diffusion sampling equation. In this work, built on Latent Diffusion Models (LDMs), we propose a family of algorithms with varying time complexities that perform the search of an antecedent within the latent space and/or the Variational Autoencoder (VAE) decoder. Aurélien Noirault, Tomás Pevný, Jan Butora, Vincent Itier, Patrick Bas |
IH&MMSec | 5 |
| 2025 | Effect of Acquisition Noise Outliers on SteganalysisabstractUnderstanding the mechanisms that lead to false alarms (erroneously detecting cover images as containing secrets) in steganalysis is a topic of utmost importance for practical applications.In this paper, we present evidence that a relatively small number of pixel outliers introduced by the image acquisition process can skew the soft output of a data driven detector to produce a strong false alarm.To verify this hypothesis, for a cover image we estimate a statistical model of the acquisition noise in the developed domain and identify pixels that contribute the most to the associated likelihood ratio test (LRT) for steganography.We call such cover elements LIEs (Locally Influential Elements).The effect of LIEs on the output of a data-driven detector is demonstrated by turning a strong false alarm into a correctly classified cover by introducing a relatively small number of "de-embedding" changes at LIEs.Similarly, we show that it is possible to introduce a small number of LIEs into a strong cover to make a data driven detector classify it as stego.Our findings are supported by experiments on two datasets with three steganographic algorithms and four types of data driven detectors. Edgar Kaziakhmedov, Jessica J. Fridrich, Patrick Bas |
IH&MMSec | 3 |
| 2024 | The Adobe Hidden Feature and its Impact on Sensor AttributionabstractIf the extraction of sensor fingerprints represents nowadays an important forensic tool for sensor attribution, it has been shown recently in [2,3,12] that images coming from several sensors were more prone to generate False Positives (FP) by presenting a common "leak". In this paper, we investigate the possible cause of this leak and after inspecting the EXIF metadata of the sources causing FP, we found out that they were related to the Adobe Lightroom or Camera Raw software. The cross-correlation between residuals on images presenting FP reveals periodic peaks showing the presence of a periodic pattern. By developing our own images with Adobe Lightroom we are able to show that all developments from raw images (or 16 bits per channel coded) to 8 bits-coded images also embed a periodic 128x128 pattern very similar to a watermark. However, we also show that the watermark depends on both the content and the architecture used to develop the image. The rest of the paper presents two different ways of removing this watermark, one by removing it from the image noise component, and the other by removing it in the pixel domain. We show that for a camera presenting FP in [12], we were able to prevent the False Positives. A discussion with Adobe representatives informed us that the company decided to add this pattern in order to induce dithering. Jan Butora, Patrick Bas |
IH&MMSec | 2 |
| 2024 | Statistical Correlation as a Forensic Feature to Mitigate the Cover-Source MismatchabstractThe present paper deals with the cover-source mismatch (CSM) problem in operational steganalysis. It first investigates the distribution of the noise in natural images, and shows how this property can be used to build a fingerprint of the cover- source, to address the issue of source identification from a single image. In particular, fingerprints from different noise extraction techniques are studied. Results show that these fingerprints can be complementary. The method proposed in the present paper aggregates them in a unique forensic feature to build a more accurate source identification algorithm than when using steganalysis features, such as the discrete cosine transform residual (DCTR). Last, the paper exploits the proposed forensic tool to mitigate CSM via "atomistic steganalysis". Used together with steganalysis methods, experimental results highlight the superiority of our approach, as compared to other atomistic mitigation strategies. The relevancy of these results is further studied on out- of-camera images coming from Flickr and the ALASKA dataset. We show that for some devices, our approach gives results superior to the omniscient scenario. Antoine Mallet, Patrick Bas, Rémi Cogranne |
IH&MMSec | 2 |
| 2024 | Linking Intrinsic Difficulty and Regret to Properties of Multivariate Gaussians in Image SteganalysisabstractThis paper deals with the Cover-Source Mismatch (CSM) problem faced in operational steganalysis. Based on a multivariate Gaussian model of the distribution of the noise contained in natural images, it provides proxies for the two important empirical measures of CSM: intrinsic difficulty and regret. The former can be modeled with the determinant of the covariance matrix of the noise present in an image. The latter can be predicted with a modified Kullback-Leibler divergence between the distribution of the noises of images coming from different cover-sources. We first recall the reasoning behind the multivariate Gaussian model of the noise, and detail how to compute the statistic of the distribution of the noise. Then, our proposed models are compared to empirical data with a specifically designed cover-source generation process. For both quantities, very high correlation coefficients between the model and the observations are obtained. Finally, realistic cover-sources are used to further illustrate the relevance of our model. Antoine Mallet, Rémi Cogranne, Patrick Bas |
IH&MMSec | 3 |
| 2024 | Errorless Robust JPEG Steganography Using Outputs of JPEG CodersabstractRobust steganography is a technique of hiding secret messages in images so that the message can be recovered after additional image processing. One of the most popular processing operations is JPEG recompression. Unfortunately, most of today's steganographic methods addressing this issue only provide a probabilistic guarantee of recovering the secret and are consequently not errorless. That is unacceptable since even a single unexpected change can make the whole message unreadable if it is encrypted. We propose to create a robust set of DCT coefficients by inspecting their behavior during recompression, which requires access to the targeted JPEG compressor. This is done by dividing the DCT coefficients into 64 non-overlapping lattices because one embedding change can potentially affect many other coefficients from the same DCT block during recompression. The robustness is then combined with standard steganographic costs creating a lattice embedding scheme robust against JPEG recompression. Through experiments, we show that the size of the robust set and the scheme's security depends on the ordering of lattices during embedding. We verify the validity of the proposed method with three typical JPEG compressors and theSlackinstant messaging application. We benchmark its security for various embedding payloads, three different ways of ordering the lattices, and a range of Quality Factors. Finally, this method is errorless by construction, meaning the embedded message will always be readable. Jan Butora, Pauline Puteaux, Patrick Bas |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Size-Independent Reliable CNN for RJCA SteganalysisabstractDetection of image steganography is principally implemented with supervised machine learning detectors. There are two main drawbacks to this approach: the detectors are overly specific to a given image source, and the performance guarantees are only empirical. In this work, we further study a previously proposed deep learning detector that exploits natural image structure imposed by JPEG compression with high quality. We show in a controlled environment that for a fixed JPEG compressor, the soft outputs of a deep learning classifier - the logits - follow a Gaussian distribution. We prove a scaling law stating that the variance of this distribution scales linearly with the image size. By disabling padding in the convolutional neural network, we demonstrate that the mean of the logit distribution does not change, allowing us to directly analyze images of different sizes. Focusing on the logits, we show that we can prescribe a threshold with a theoretical false positive rate for a wide range of image sizes, which is then closely satisfied on real cover images, even for small probabilities such as 10-4. Moreover, the detection power on steganographic images still generalizes to non-adaptive and content-adaptive steganography. Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Finding Incompatible Blocks for Reliable JPEG SteganalysisabstractThis article presents a refined notion of incompatible JPEG images for a quality factor of 100. It can detect the presence of steganographic schemes embedding in DCT coefficients. We show that, within the JPEG pipeline, the combination of the DCT transform with the quantization function can map several blocks in the pixel domain to the same block in the DCT domain. However, not every DCT block can be obtained: we call those blocks incompatible. In particular, incompatibility can happen when DCT coefficients are manually modified to embed a message. We show that the problem of distinguishing compatible blocks from incompatible ones is an inverse problem with or without solution and we propose two different methods to solve it. The first one is heuristic-based, fast to find a solution if it exists. The second is formulated as an Integer Linear Programming problem and can detect incompatible blocks only for a specific DCT transform in a reasonable amount of time. We show that the probability for a block to become incompatible only relies on the number of modifications. Finally, using the heuristic algorithm we can derive a Likelihood Ratio Test depending on the number of compatible blocks per image to perform steganalysis. We simulate the result of this test and show that it outperforms a deep learning detector e-SRNet for every payload between 0.001 and 0.01 bpp by using only 10% of the blocks from$\bf 256\times 256$images. A Selection-Channel-Aware version of the test is even more powerful and outperforms e-SRNet while using only 1% of the blocks. Etienne Levecque, Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Analysis and Mitigation of the False Alarms of the Reverse JPEG Compatibility AttackabstractThe Reverse JPEG Compatibility Attack can be used for steganalysis of JPEG images compressed with Quality Factor 100 by detecting increased variance of decompression rounding errors. In this work, we point out the dangers associated with this attack by showing that in an uncontrolled environment, the variance can be elevated simply by using a different JPEG compressor. If not careful, the steganalyst can wrongly misclassify cover images. In order to deal with the diversity associated to the devices or softwares generating JPEGs, we propose in this paper to build a deep learning detector trained on a huge dataset of downloaded images. Experimental evaluation shows that such a detector can provide operational false alarms as small as 10-4, while still correctly classifying 90% of stego images. Furthermore, it is shown that this performance is directly applicable to other image datasets. As a side product, we indicate that the attack is not applicable to images developed with a specific JPEG compressor based on the trunc quantization function. Jan Butora, Patrick Bas, Rémi Cogranne |
IH&MMSec | 2 |
| 2023 | Compatibility and Timing Attacks for JPEG SteganalysisabstractThis paper introduces a novel compatibility attack to detect a steganographic message embedded in the DCT domain of a JPEG image at high-quality factors (close to 100). Because the JPEG compression is not a surjective function, i.e. not every DCT blocks can be mapped from a pixel block, embedding a message in the DCT domain can create incompatible blocks. We propose a method to find such a block, which directly proves that a block has been modified during the embedding. This theoretical method provides many advantages such as being completely independent to Cover Source Mismatch, having good detection power, and perfect reliability since false alarms are impossible as soon as incompatible blocks are found. We show that finding an incompatible block is equivalent to proving the infeasibility of an Integer Linear Programming problem. However, solving such a problem requires considerable computational power and has not been reached for 8x8 blocks. Instead, a timing attack approach is presented to perform steganalysis without potentially any false alarms for large computing power. Etienne Levecque, Patrick Bas, Jan Butora |
IH&MMSec | 2 |
| 2023 | Side-Informed Steganography for JPEG Images by Modeling Decompressed ImagesabstractSide-informed steganography has always been among the most secure approaches in the field. However, a majority of existing methods for JPEG images use the side information, here the rounding error, in a heuristic way. For the first time, we show that the usefulness of the rounding error comes from its covariance with the embedding changes. Unfortunately, this covariance between continuous and discrete variables is not analytically available. An estimate of the covariance is proposed, which allows to model steganography as a change in the variance of DCT coefficients. Since steganalysis today is best performed in the spatial domain, we derive a likelihood ratio test to preserve a model of a decompressed JPEG image. The proposed method then bounds the power of this test by minimizing the Kullback-Leibler divergence between the cover and stego distributions. We experimentally demonstrate in two popular datasets that it achieves state-of-the-art performance against deep learning detectors. Moreover, by considering a different pixel variance estimator for images compressed with Quality Factor 100, even greater improvements are obtained. Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Impact of Downscaling on Adversarial ImagesabstractMost works on adversarial attacks consider that small images whose size already fits the model but downscaling is a necessary first step to adapt the size of the image to the model, and it can reform the adversarial signal. This paper explores attacking large images on classifiers with different input sizes and compares theoretical results with practical ones. The possibility of forging adversarial images using different interpolation methods and different deep learning structures are investigated. The distortion of the adversarial signal and the transferability over other downscaling methods are also studied. An ensemble model gathering different resizing interpolations is also proposed to increase the transferability of the attack against a set of downscaling kernels. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
ICIP | 3 |
| 2022 | Fighting the Reverse JPEG Compatibility Attack: Pick your SideabstractIn this work we aim to design a steganographic scheme undetectable by the Reverse JPEG Compatibility Attack (RJCA). The RJCA, while only effective for JPEG images compressed with quality factors 99 and 100, was shown to work mainly due to change in variance of the rounding errors after decompression of the DCT coefficients, which is induced by embedding changes incompatible with the JPEG format. One remedy to preserve the aforementioned format is utilizing during the embedding the rounding errors created during the JPEG compression, but no steganographic method is known to be resilient to RJCA without this knowledge. Inspecting the effect of embedding changes on variance and also mean of decompression rounding errors, we propose a steganographic method allowing resistance against RJCA without any side-information. To resist RJCA, we propose a distortion metric making all embedding changes within a DCT block dependent, resulting in a lattice-based embedding. Then it turns out it is enough to cleverly pick the side of the (binary) embedding changes through inspection of their effect on the variance of decompression rounding errors and simply use uniform costs in order to enforce their sparsity across DCT blocks. To increase security against detectors in the spatial (pixel) domain, we show an easy way of combining the proposed methodology with steganography designed for spatial domain security, further improving the undetectability for quality factor 99. The improvements over existing non-informed steganography are up to 40% in terms of detector's accuracy. Jan Butora, Patrick Bas |
IH&MMSec | 2 |
| 2022 | Backpack: A Backpropagable Adversarial Embedding SchemeabstractA min max protocol offers a general method to automatically optimize steganographic algorithm against a wide class of steganalytic detectors. The quality of the resulting steganograhic algorithm depends on the ability to find an “adversarial” stego image undetectable by a set of detectors while communicating a given message. Despite min max protocol instantiated with ADV-EMB scheme leading to unexpectedly good results, we show it suffers a significant flaw and we present a theoretically sound solution called Backpack. Extensive experimental verification of min max protocol with Backpack shows superior performance to ADV-EMB, the generality of the tool by targeting a new JPEG QF100 compatibility attack and further improves the security of steganographic algorithms. Solène Bernard, Patrick Bas, John Klein, Tomás Pevný |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Generating Adversarial Images in Quantized DomainsabstractMany adversarial attacks produce floating-point tensors which are no longer adversarial when converted to raster or JPEG images due to rounding. This paper proposes a method dedicated to quantize adversarial perturbations. This “smart” quantization is conveniently implemented as versatile post-processing. It can be used on top of any white-box attack targeting any model. Its principle is tantamount to a constrained optimization problem aiming to minimize the quantization error while keeping the image adversarial after quantization. A Lagrangian formulation is proposed and an appropriate search of the Lagrangian multiplier enables to increase the success rate. We also add a control mechanism of the$\ell _\infty $-distortion. Our method operates in both spatial and JPEG domains with little complexity. This study shows that forging adversarialimagesis not a hard constraint: our quantization does not introduce any extra distortion. Moreover, adversarial images quantized as JPEG also challenge defenses relying on the robustness of neural networks against JPEG compression. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Efficient Steganography in JPEG Images by Minimizing Performance of Optimal DetectorabstractSince the introduction of adaptive steganography, most of the recent research works seek at designing cost functions that are evaluated against steganalysis methods. While those approaches have been successful, they rely on intuitive principles and ad-hoc costs associated with each pixel or Discrete Cosine Transform (DCT) coefficient. Beyond the empirical assessments, the insights one can get from such approaches are very limited. On the opposite, this paper presents an original method for steganography in JPEG images that exploits a statistical model of the DCT coefficients. Within the framework of hypothesis testing theory, we use a statistical model of covers to derive the analytical expression of the most powerful detector. The objective of the steganographer is to minimize the statistical performance of this “omniscient detector” which represents a “worst-case” scenario for security. This paper shows how this method allows designing effective steganography, in terms of both security and computational complexity, in the two main use cases: when having only one single JPEG image and when the uncompressed image is available, case also known as Side-Informed (SI). A wide range of numerical comparisons shows that the proposed method outperforms the current state-of-the-art especially against the latest and most accurate steganalysis approaches based on Deep Learning. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Multivariate Side-Informed Gaussian Embedding Minimizing Statistical DetectabilityabstractSteganography schemes based on a deflection criterion for embedding posses a clear advantage against schemes based on heuristics as they provide a direct link between theoretical detectability and empirical performance. However, this advantage depends on the accuracy of the cover and stego model underlying the embedding scheme. In this work we propose an original steganography scheme based on a realistic model of sensor noise, taking into account the camera model, the ISO setting and the processing pipeline. Exploiting this statistical model allows us to take correlations between DCT coefficients into account. Several types of dependency models are presented, including a very general lattice model which accurately models dependencies introduced by a large class of processing pipelines of interest. We show in particular that the stego signal which minimizes the KL divergence under this model has a covariance proportional to the cover noise covariance. The resulting embedding scheme achieves state-of-the-art performances which go well beyond the current standards in side-informed JPEG steganography. Eva Giboulot, Patrick Bas, Rémi Cogranne |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Optimizing Additive Approximations of Non-additive Distortion FunctionsabstractThe progress in steganography is hampered by a gap between non-additive distortion functions, which capture well complex dependencies in natural images, and their additive counterparts, which are efficient for data embedding. This paper proposes a theoretically justified method to approximate the former by the latter. The proposed method, called Backpack (for BACKPropagable AttaCK), combines new results in the approximation of gradients of discrete distributions with a gradient of implicit functions in order to derive a gradient w.r.t. the distortion of each JPEG coefficient. Backpack combined with the min max iterative protocol leads to a very secure steganographic algorithm. For example, the error rate of XuNet on 512 X 512 JPEG images, compressed with quality factor 100 and a payload of 0.4 bits per non-zero AC coefficient is 37.3% with Backpack, compared to a 26.5% error rate using ADV-EMB with minmax (considered state of the art in this work) and a 16.9% error rate with J-UNIWARD. Solène Bernard, Patrick Bas, Tomás Pevný, John Klein |
IH&MMSec | 2 |
| 2021 | Explicit Optimization of min max Steganographic GameabstractThis article proposes an algorithm which allows Alice to simulate the game played between her and Eve. Under the condition that the set of detectors that Alice assumes Eve to have is sufficiently rich (e.g. CNNs), and that she has an algorithm enabling to avoid detection by a single classifier (e.g adversarial embedding, gibbs sampler, dynamic STCs), the proposed algorithm converges to an efficient steganographic algorithm. This is possible by using a min max strategy which consists at each iteration in selecting the least detectable stego image for the best classifier among the set of Eve's learned classifiers. The algorithm is extensively evaluated and compared to prior arts and results show the potential to increase the practical security of classical steganographic methods. For example the error probability Perr of XU-Net on detecting stego images with payload of 0.4 bpnzAC embedded by J-Uniward and QF 75 starts at 7.1% and is increased by +13.6% to reach 20.7% after eight iterations. For the same embedding rate and for QF 95, undetectability by XU-Net with J-Uniward embedding is 23.4%, and it jumps by +25.8% to reach 49.2% at iteration 3. Solène Bernard, Patrick Bas, John Klein, Tomás Pevný |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Detectability-Based JPEG Steganography Modeling the Processing Pipeline: The Noise-Content Trade-offabstractThe current art of steganography shows that schemes using a deflection criterion (such as MiPOD) for JPEG steganography are usually subpar with respect to distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. However, this statistically-based method provides a better assessment of the detectability of hidden data as well as theoretical guarantees under a given model. In this paper, we propose a method to obtain better estimates of the variances of DCT coefficients by taking into account the dependencies introduced by development pipeline on pixels. A second method, which is a side-informed extension of Gaussian Embedding in the JPEG domain using quantization error as side-information, is also formulated and shown to achieve state-of-the-art performances. Eventually, the trade-off between noise and content complexity in steganography is thoroughly analyzed through the lenses of these two new methods using a wide range of numerical experiments. Eva Giboulot, Rémi Cogranne, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Natural Steganography in JPEG Domain With a Linear Development PipelineabstractIn order to achieve high practical security, Natural Steganography (NS) uses cover images captured at ISO sensitivity ISO1and generates stego images mimicking ISO sensitivity ISO2> ISO1. This is achieved by adding a stego signal to the cover that mimics the sensor photonic noise. This paper proposes an embedding mechanism to perform NS in the JPEG domain after linear developments by explicitly computing the correlations between DCT coefficients before quantization. In order to compute the covariance matrix of the photonic noise in the DCT domain, we first develop the matrix representation of demosaicking, luminance averaging, pixel section, and 2D-DCT. A detailed analysis of the resulting covariance matrix is done in order to explain the origins of the correlations between the coefficients of 3 × 3 DCT blocks. An embedding scheme is then presented that takes into account all the correlations. It employs 4 sub-lattices and 64 lattices per sub-lattices. The modification probabilities of each DCT coefficient are then derived by computing conditional probabilities computed from a multivariate Gaussian distribution using the Cholesky decomposition of the covariance matrix. This derivation is also used to compute the embedding capacity of each image. Using a specific database called E1Base, we show that in the JPEG domain NS (J-Cov-NS) enables to achieve high capacity (more than 2 bits per non-zero AC DCT) and with high practical security (PE 40% using DCTR and PE 32% using SRNet) from QF 75 to QF 100). Théo Taburet, Patrick Bas, Wadih Sawaya, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | JPEG Steganography with Side Information from the Processing PipelineabstractThe current art in schemes using deflection criterion such as Mi-POD for JPEG steganography is either under-performing or on par with distortion-based schemes. We link this lack of performance to a poor estimation of the variance of the model of the noise on the cover image. In this paper, we propose a method to better estimate the variances of DCT coefficients by taking into account the dependencies between pixels that come from the development pipeline. Using this estimate, we are able to extend statistically-informed steganographic schemes to the JPEG domain while significantly outperforming the current state-of-the-art JPEG steganography. An extension of Gaussian Embedding in the JPEG domain using quantization error as side-information is also formulated and shown to attain state-of-the-art performances. Eva Giboulot, Rémi Cogranne, Patrick Bas |
ICASSP | 3 |
| 2020 | What if Adversarial Samples were Digital Images?abstractAlthough adversarial sampling is a trendy topic in computer vision, very few works consider the integral constraint: The result of the attack is a digital image whose pixel values are integers. This is not an issue at first sight since applying a rounding after forging an adversarial sample trivially does the job. Yet, this paper shows theoretically and experimentally that this operation has a big impact. The adversarial perturbations are fragile signals whose quantization destroys its ability to delude an image classifier. Benoît Bonnet 0001, Teddy Furon, Patrick Bas |
IH&MMSec | 3 |
| 2020 | Steganography by Minimizing Statistical Detectability: The cases of JPEG and Color ImagesabstractThis short paper presents a novel method for steganography in JPEG-compressed images, extended the so-called MiPOD scheme based on minimizing the detection accuracy of the most-powerful test using a Gaussian model of independent DCT coefficients. This method is also applied to address the problem of embedding into color JPEG images. The main issue in such case is that color channels are not processed in the same way and, hence, a statistically based approach is expected to bring significant improvements when one needs to consider heterogeneous channels together. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IH&MMSec | 3 |
| 2020 | JPEG Steganography and Synchronization of DCT Coefficients for a Given Development PipelineabstractThis paper proposes to use the statistical analysis of the correlation between DCT coefficients to design a new synchronization strategy that can be used for cost-based steganographic schemes in the JPEG domain. First, an analysis is performed on the covariance matrix of DCT coefficients of neighboring blocks after a development pipeline similar to the one used to generate BossBase, and applied on a photonic noise. This analysis exhibits (i) a decomposition into 8 disjoint sets of uncorrelated coefficients (4 sets per block used by 2 disjoint lattices) and (ii) the fact that each DCT coefficient is correlated with 38 other coefficients belonging either to the same block or to connected blocks. Using the uncorrelated groups, an embedding scheme can be designed using only 8 disjoint lattices. The proposed embedding scheme relies on ingredients. Firstly, we convert the empirical costs associated to one each coefficient into a Gaussian distribution whose variance is directly computed from the embedding costs. Secondly we derive conditional Gaussian distributions from a multivariate distribution considering only the correlated coefficients which have been already modified by the embedding scheme. This covariance matrix takes into account both the correlations exhibited by the analysis of the covariance matrix and the variance derived from the costs. This synchronization scheme enables to obtain a gain of $P_E$ of at least $7%$ at $QF95$ for an embedding rate close to 0.3 bnzac coefficient using DCTR feature sets for both UERD and JUniward. Théo Taburet, Patrick Bas, Wadih Sawaya, Rémi Cogranne |
IH&MMSec | 2 |
| 2020 | Pixels-off: Data-augmentation Complementary Solution for Deep-learning SteganalysisabstractAfter 2015, CNN-based steganalysis approaches have started replacing the two-step machine-learning-based steganalysis approaches (feature extraction and classification), mainly due to the fact that they offer better performance. Mehdi Yedroudj, Marc Chaumont, Frédéric Comby, Ahmed Oulad Amara, Patrick Bas |
IH&MMSec | 5 |
| 2020 | Effects and solutions of Cover-Source Mismatch in image steganalysis
Eva Giboulot, Rémi Cogranne, Dirk Borghys, Patrick Bas |
Signal Process. Image Commun. | 4 |
| 2019 | Exploiting Adversarial Embeddings for Better SteganographyabstractThis work proposes a protocol to iteratively build a distortion function for adaptive steganography while increasing its practical security after each iteration. It relies on prior art on targeted attacks and iterative design of steganalysis schemes. It combines targeted attacks on a given detector with a \min\max strategy, which dynamically selects the most difficult stego content associated with the best classifier at each iteration. We theoretically prove the convergence, which is confirmed by the practical results. Applied on J-Uniward this new protocol increases \perr from 7% to 20% estimated by Xu-Net, and from 10% to 23% for a non-targeted steganalysis by a linear classifier with GFR features. Solène Bernard, Tomás Pevný, Patrick Bas, John Klein |
IH&MMSec | 3 |
| 2019 | The ALASKA Steganalysis Challenge: A First Step Towards SteganalysisabstractThis paper presents ins and outs of the ALASKA challenge, a steganalysis challenge built to reflect the constraints of a forensic steganalyst. We motivate and explain the main differences w.r.t. the BOSS challenge (2010), specifically the use of a ranking metric prescribing high false positive rates, the analysis of a large diversity of different image sources and the use of a collection of steganographic schemes adapted to handle color JPEGs. The core of the challenge is also described, this includes the RAW image data-set, the implementations used to generate cover images and the specificities of the embedding schemes. The very first outcomes of the challenge are then presented, and the impacts of different parameters such as demosaicking, filtering, image size, JPEG quality factors and cover-source mismatch are analyzed. Eventually, conclusions are presented, highlighting positive and negative points together with future directions for the next challenges in practical steganalysis. Rémi Cogranne, Eva Giboulot, Patrick Bas |
IH&MMSec | 3 |
| 2019 | Computing Dependencies between DCT Coefficients for Natural Steganography in JPEG DomainabstractThis short paper is an extension of a family of embedding schemes called Natural Steganography, which embeds a message by mimicking heteroscedastic sensor noise in the JPEG domain. Under the assumption that the development from RAW uses linear de- mosaicking, we derive a closed-form for the covariance matrix of DCT coefficients from 3 × 3 JPEG blocks. This computation relies on a matrix formulation of all steps involved in the development pipeline, which includes demosaicking, conversion to luminance, DCT transform, and reordering. This matrix is then used for pseudo-embedding in the JPEG domain on four lattices of 8 × 8 DCT blocks. The results obtained with the computed covariance matrix are contrasted with the results previously obtained with the covariance matrix estimated using Monte Carlo sampling and scaling. The empirical security using DCTR features at JPEG quality 100 increased from PE = 14% using covariance estimation and scaling to PE = 43% using the newly derived analytic form. Théo Taburet, Patrick Bas, Jessica J. Fridrich, Wadih Sawaya |
IH&MMSec | 2 |
| 2018 | Facing the Cover-Source Mismatch on JPHide using Training-Set DesignabstractThis short paper investigates the influence of the image processing pipeline (IPP) on the cover-source mismatch (CSM) for the popular JPHide steganographic scheme. We propose to deal with CSM by combining a forensics and a steganalysis approach. A multi-classifier is first trained to identify the IPP, and secondly a specific training set is designed to train a targeted classifier for steganalysis purposes. We show that the forensic step is immune to the steganographic embedding. The proposed IPP-informed steganalysis outperforms classical strategies based on training on a mixture of sources and we show that it can provide results close to a detector specifically trained on the appropriate source. Dirk Borghys, Patrick Bas, Helena Bruyninckx |
IH&MMSec | 2 |
| 2018 | An Empirical Study of Steganography and Steganalysis of Color Images in the JPEG Domain
Théo Taburet, Louis Filstroff, Patrick Bas, Wadih Sawaya |
IWDW | 3 |
| 2017 | An embedding mechanism for natural steganography after down-samplingabstractNatural Steganography (NS) uses the concept of cover-source switching to provide good undetectability performances [1]. The sensor noise of the source (camera) for a given ISO sensitivity ISO1is first modeled as an independent Gaussian distribution for each photo-site, then the embedding mimics a switch to another sensitivity ISO2(> ISO1). Because the embedding has to be performed on developed images, we investigate in this paper how to generate a stego-signal once the image is down-sampled. By studying different down-sampling mechanisms (sub-sampling, box down-sampling, tent down-sampling) applied on RAW images generated from a monochrome sensor, we show that the use of a convolution kernel with overlapping boundaries implies a synchronization mechanism similar to the one used by the CMD and Synch embedding schemes, but motivated here by statistical foundations. For each mechanism and scaling factor, we also compute the associated embedding rates and show that our results are in-line with experimental results previously highlighted for other steganographic schemes. Patrick Bas |
ICASSP | 1 |
| 2016 | Physical object authentication: Detection-theoretic comparison of natural and artificial randomnessabstractIn this paper, we compare two methods that can be used by the anti-counterfeiting industry to protect physical objects, which are either based on an object's natural randomness or on artificial randomness embedded on the object. We show that the considered verification architectures rely either on a comparison between an enrolled fingerprint and an extracted one or between a tag and a fingerprint. We compare these setups from detection-theoretic perspectives for both types of architectures. Authentication performance using false and miss error probabilities of the two systems are analysed and then compared using two practical setups. We highlight the advantages and limitations of each architecture. These theoretical results derived for binary fingerprints are useful to construct and optimise practical methods and to help select the appropriate architecture. Sviatoslav Voloshynovskiy, Taras Holotyak, Patrick Bas |
ICASSP | 3 |
| 2016 | Rethinking Optimal EmbeddingabstractAt present, almost all leading steganographic techniques for still images use a distortion minimization paradigm, where each potential change is assigned a cost ci and the change probabilities πi chosen to minimize the average total cost ∑iπici. However, some detectors have exploited knowledge of this adaptivity and the embedding cannot be considered optimal. In this work we prove a theoretical result suggesting that, against a knowing attacker, the embedder should simply minimize ∑iπ2ici instead, for the same costs ci, which is the minimax and equilibrium strategy. This aligns with some special case results that have appeared in recent literature. We then test some simple steganographic methods in theoretical and real settings, showing that naive (average cost) adaptivity is exploitable, but the equilibrium probabilities cannot be exploited. However, it is essential to determine statistically well-founded costs ci. Andrew D. Ker, Tomás Pevný, Patrick Bas |
IH&MMSec | 3 |
| 2016 | Rare event probability estimation using information projection
Anh Thu Phan Ho, Wadih Sawaya, Patrick Bas |
ISITA | 3 |
| 2014 | Image model and printed document authentication: A theoretical analysisabstractThis paper combines the principles of statistical estimation and hypothesis testing to analyze the impact of parameter estimation on an authentication system based on graphical codes. The studied authentication system uses the fact that a code, once printed, undergoes a stochastic and non invertible alteration. A statistical test applies a likelihood ratio between the model of the authentic printed and scanned image and the model of the reproduced one, with the particularity here that the later model is unknown. The proposed solution consists in using an optimal estimation of the image model coming from observed fake codes in order to perform the likelihood test. Using a second order expansion, we derive a linear relation between the quadratic error of the estimated parameters and the probability of type II error. We are then able to formulate analytically and practically the error spread region of the Receiver Operating Characteristic (ROC) curves, and to compute the average authentication performance when the receiver has to estimate the opponent print and scan channel. Bao An Mai Hoang, Wadih Sawaya, Patrick Bas |
ICIP | 3 |
| 2014 | Document authentication using graphical codes: reliable performance analysis and channel optimizationabstractThis paper proposes to investigate the impact of the channel model for authentication systems based on codes that are corrupted by a physically unclonable noise such as the one emitted by a printing process.The core of such a system for the receiver is to perform a statistical test in order to recognize and accept an original code corrupted by noise and reject any illegal copy or a counterfeit.This study highlights the fact that the probability of type I and type II errors can be better approximated, by several orders of magnitude, when using the Cramér-Chernoff theorem instead of a Gaussian approximation.The practical computation of these error probabilities is also possible using Monte Carlo simulations combined with the importance sampling method.By deriving the optimal test within a Neyman-Pearson setup, a first theoretical analysis shows that a thresholding of the received code induces a loss of performance.A second analysis proposes to find the best parameters of the channels involved in the model in order to maximize the authentication performance.This is possible not only when the opponent's channel is identical to the legitimate channel but also when the opponent's channel is different, leading this time to a min-max game between the two players.Finally, we evaluate the impact of an uncertainty for the receiver on the opponent channel, and we show that the authentication is still possible whenever the receiver can observe forged codes and uses them to estimate the parameters of the model. Anh Thu Phan Ho, Bao An Mai Hoang, Wadih Sawaya, Patrick Bas |
EURASIP J. Inf. Secur. | 4 |
| 2014 | Optimal Transport for Secure Spread-Spectrum Watermarking of Still ImagesabstractThis paper studies the impact of secure watermark embedding in digital images by proposing a practical implementation of secure spread-spectrum watermarking using distortion optimization. Because strong security properties (key-security and subspace-security) can be achieved using natural watermarking (NW) since this particular embedding lets the distribution of the host and watermarked signals unchanged, we use elements of transportation theory to minimize the global distortion. Next, we apply this new modulation, called transportation NW (TNW), to design a secure watermarking scheme for grayscale images. The TNW uses a multiresolution image decomposition combined with a multiplicative embedding which is taken into account at the distribution level. We show that the distortion solely relies on the variance of the wavelet subbands used during the embedding. In order to maximize a target robustness after JPEG compression, we select different combinations of subbands offering the lowest Bit Error Rates for a target PSNR ranging from 35 to 55 dB and we propose an algorithm to select them. The use of transportation theory also provides an average PSNR gain of 3.6 dB on PSNR with respect to the previous embedding for a set of 2000 images. Benjamin Mathon, François Cayre, Patrick Bas, Benoît Macq |
IEEE Trans. Image Process. | 3 |
| 2013 | Document authentication using graphical codes: impacts of the channel modelabstractThis paper proposes to investigate the impact of the channel model for authentication systems based on codes that are corrupted by a physically unclonable noise such as the one emitted by a printing process. The core of such a system is the comparison for the receiver between an original binary code, an original corrupted code and a copy of the original code. We analyze two strategies, depending on whether or not the receiver use a binary version of its observation to perform its authentication test. By deriving the optimal test within a Neyman-Pearson setup, a theoretical analysis shows that a thresholding of the code induces a loss of performance. This study also highlights the fact that the probability of the type I and type II errors can be better approximated, by several orders of magnitude, computing Chernoff bounds instead of the Gaussian approximation. Finally we evaluate the impact of an uncertainty for the receiver on the opponent channel and show that the authentication is still possible whenever the receiver can observe forged codes and uses them to estimate the parameters of the model. Anh Thu Phan Ho, Bao An Mai Hoang, Wadih Sawaya, Patrick Bas |
IH&MMSec | 4 |
| 2013 | Moving steganography and steganalysis from the laboratory into the real worldabstractThere has been an explosion of academic literature on steganography and steganalysis in the past two decades. With a few exceptions, such papers address abstractions of the hiding and detection problems, which arguably have become disconnected from the real world. Most published results, including by the authors of this paper, apply "in laboratory conditions" and some are heavily hedged by assumptions and caveats; significant challenges remain unsolved in order to implement good steganography and steganalysis in practice. This position paper sets out some of the important questions which have been left unanswered, as well as highlighting some that have already been addressed successfully, for steganography and steganalysis to be used in the real world. Andrew D. Ker, Patrick Bas, Rainer Böhme, Rémi Cogranne, Scott Craver, Tomás Filler, Jessica J. Fridrich, Tomás Pevný |
IH&MMSec | 2 |
| 2013 | A New Measure of Watermarking Security: The Effective Key LengthabstractWhereas the embedding distortion, the payload, and the robustness of digital watermarking schemes are well understood, the notion of security is still not completely well defined. The approach proposed in the last five years is too theoretical and solely considers the embedding process, which is half of the watermarking scheme. This paper proposes a new measure of watermarking security, called the effective key length, which captures the difficulty for the adversary to get access to the watermarking channel. This new methodology is applied here to additive spread spectrum schemes where theoretical and practical computations of the effective key length are proposed. Experimental protocols using either Monte Carlo simulations, region approximation, or rare event probability estimator allow good evaluation of this quantity. For improved spread spectrum (ISS), our analysis exhibits setups where 1) the robustness and the security of the scheme are superior to spread spectrum and 2) estimating the secret keys from the observations only is not the best way to break the scheme. Moreover, a comparison with correlation aware spread spectrum (CASS) shows that ISS offers a better security than CASS for a given robustness. Patrick Bas, Teddy Furon |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Impacts of Watermarking Security on Tardos-Based FingerprintingabstractThis paper presents a study of the embedding of Tardos binary fingerprinting codes with watermarking techniques. By taking into account the security of the embedding scheme, we present a new approach for colluding strategies which relies on the possible estimation error rate of the code symbols (denoted$\epsilon$). We derive a new attack strategy called “$\epsilon$-Worst Case Attack” and show its efficiency using the computation of achievable rates for simple decoding. Then we consider the interplay between security and robustness regarding the accusation performances of the fingerprinting scheme and show that 1) for the same accusation rate secure schemes can afford to be less robust than insecure ones, and 2) that secure schemes enable to cast the Worst Case Attack into an interleaving attack. Additionally, we use the security analysis of the watermarking scheme to derive from$\epsilon$a security attack for a fingerprinting scheme based on Tardos codes and a new scheme called stochastic spread-spectrum watermarking. We compare a removal attack against an AWGN robustness attack and we show that for the same distortion, the combination of a fingerprinting attack and a security attack easily outperform classical attacks even with a small number of observations. Benjamin Mathon, Patrick Bas, François Cayre, Benoît Macq |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | Practical key length of watermarking systemsabstractThe paper proposes a new approach for evaluating the security levels of digital watermarking schemes, which is more in line with the formulation proposed in cryptography. We first exhibit the class of equivalent decoding keys. These are the keys allowing a reliable decoding of contents watermarked with the secret key. Then, we evaluate the probability that the adversary picks an equivalent key. The smaller this probability, the higher the key length. This concept is illustrated on two main families of watermarking schemes: DC-QIM (Distortion Compensation Quantization Index Modulation) and SS (Spread Spectrum). The trade-off robustness-security is again verified and gives some counter-intuitive results: For instance, the security of SS is a decreasing function of the length of the secret vector at a fixed Document to Watermark power ratio. Additionally, under the Known Message Attack, the practical key length of the watermarking scheme rapidly decreases to 0 bits per symbol. Patrick Bas, Teddy Furon, François Cayre |
ICASSP | 1 |
| 2011 | Informed secure watermarking using optimal transportabstractThis paper presents several watermarking methods preventing the estimation of the secret key by an adversary. The constraints for secure embedding using distribution matching, where the decoding regions rely implicitly on the distribution of the host signal, are first formulated. In order to perform informed coding, different decoding regions are associated with the same message using an appropriate partitioning function. The minimization of the embedding distortion is afterwards casted into an optimal transport problem. Three new secure embeddings are presented and the performances of the proposed embedding functions regarding the AWGN channel for different WCRs are evaluated. Depending on the embedding and noise distortions, informed secure coding can outperform classical secure coding or classical insecure coding such as ISS or SCS. Patrick Bas |
ICASSP | 1 |
| 2011 | TROP-ELM: A double-regularized ELM using LARS and Tikhonov regularization
Yoan Miché, Mark van Heeswijk, Patrick Bas, Olli Simula, Amaury Lendasse |
Neurocomputing | 3 |
| 2010 | Ensemble Modeling with a Constrained Linear System of Leave-One-Out Outputs
Yoan Miché, Emil Eirola, Patrick Bas, Olli Simula, Christian Jutten, Amaury Lendasse, Michel Verleysen |
ESANN | 3 |
| 2010 | Considering security and robustness constraints for watermark-based Tardos fingerprintingabstractThis article is a theoretical study on binary Tardos' fingerprinting codes embedded using watermarking schemes. Our approach is derived from and encompasses both security and robustness constraints. We assume here that the coalition has estimated the symbols of the fingerprinting code by the way of a security attack, the quality of the estimation relying on the security of the watermarking scheme. Taking into account the fact that the coalition can perform estimation errors, we update the Worst Case Attack, which minimises the mutual information between the sequence of one colluder and the pirated sequence forged by the coalition. After comparing the achievable rates of the previous and proposed Worst Case Attack according to the estimation error, we conclude this analysis by comparing the robustness of no-secure embedding schemes versus secure ones. We show that, for low probabilities of error during the decoding stage (e.g. highly robust watermarking schemes), security enables to increase the achievable rate of the fingerprinting scheme. Benjamin Mathon, Patrick Bas, François Cayre, Benoît Macq |
MMSP | 2 |
| 2010 | Steganalysis by subtractive pixel adjacency matrixabstractThis paper presents a method for detection of steganographic methods that embed in the spatial domain by adding a low-amplitude independent stego signal, an example of which is least significant bit (LSB) matching. First, arguments are provided for modeling the differences between adjacent pixels using first-order and second-order Markov chains. Subsets of sample transition probability matrices are then used as features for a steganalyzer implemented by support vector machines. The major part of experiments, performed on four diverse image databases, focuses on evaluation of detection of LSB matching. The comparison to prior art reveals that the presented feature set offers superior accuracy in detecting LSB matching. Even though the feature set was developed specifically for spatial domain steganalysis, by constructing steganalyzers for ten algorithms for JPEG images, it is demonstrated that the features detect steganography in the transform domain as well. Tomás Pevný, Patrick Bas, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | OP-ELM: optimally pruned extreme learning machineabstractIn this brief, the optimally pruned extreme learning machine (OP-ELM) methodology is presented. It is based on the original extreme learning machine (ELM) algorithm with additional steps to make it more robust and generic. The whole methodology is presented in detail and then applied to several regression and classification problems. Results for both computational time and accuracy (mean square error) are compared to the original ELM and to three other widely used methodologies: multilayer perceptron (MLP), support vector machine (SVM), and Gaussian process (GP). As the experiments for both regression and classification illustrate, the proposed OP-ELM methodology performs several orders of magnitude faster than the other algorithms used in this brief, except the original ELM. Despite the simplicity and fast performance, the OP-ELM is still able to maintain an accuracy that is comparable to the performance of the SVM. A toolbox for the OP-ELM is publicly available online. Yoan Miché, Antti Sorjamaa, Patrick Bas, Olli Simula, Christian Jutten, Amaury Lendasse |
IEEE Trans. Neural Networks | 3 |
| 2009 | Reliable Steganalysis Using a Minimum Set of Samples and FeaturesabstractInternational audience Yoan Miché, Patrick Bas, Amaury Lendasse, Christian Jutten, Olli Simula |
EURASIP J. Inf. Secur. | 2 |
| 2008 | A Methodology for Building Regression Models using Extreme Learning Machine: OP-ELM
Yoan Miché, Patrick Bas, Christian Jutten, Olli Simula, Amaury Lendasse |
ESANN | 2 |
| 2008 | Broken ArrowsabstractInternational audience Teddy Furon, Patrick Bas |
EURASIP J. Inf. Secur. | 2 |
| 2008 | Kerckhoffs-Based Embedding Security Classes for WOA Data HidingabstractAbstract — It has recently been discovered that using pseudorandom sequences as carriers in spread-spectrum techniques for data-hiding is not at all a sufficient condition for ensuring datahiding security. Using proper and realistic a priori hypothesis on the messages distribution, it is possible to accurately estimate the secret carriers by casting this estimation problem into a Blind Source Separation problem. After reviewing relevant works on spread-spectrum security for watermarking, we further develop on this topic to introduce the concept of security classes which broaden previous notions in watermarking security and fills the gap with steganography security as defined by Cachin. We define four security classes, namely, by order of creasing security: insecurity, key-security, subspace-security and stego-security. To illustrate these views, we present two new modulations for truly secure watermarking in the Watermark-Only-Attack (WOA) framework. The first one is called Natural Watermarking and can be made either stego-secure or subspace-secure. The second is called Circular Watermarking and is key-secure. We show that Circular Watermarking has robustness comparable to that of the insecure classical spread spectrum. We shall also propose information leakage measures to highlight the security level of our new spread-spectrum modulations. Index Terms — Spread spectrum watermarking, security. EDICS Category: WAT-SSPM François Cayre, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2005 | Airborne remote sensing of vineyards for the detection of dead vine treesabstractAbstract — Airborne remote sensing technology can be used to accurately monitor vineyards. In this paper we present a method to detect missing or dead trees. This is achieved by exploiting the periodic structure of a vineyard: equally spaced trees are planted in parallel rectilinear rows. This clearly appears on the spectrum which can be analyzed using the Radon transform. Simple morphological operators then enable the detection of unusal spaces within the plantation rows, corresponding to missing trees. I. Jocelyn Chanussot, Patrick Bas, Lionel Bombrun |
IGARSS | 2 |
| 2005 | Security of DM Quantization Watermarking Schemes: A Practical Study for Digital Images
Patrick Bas, Jarmo Hurri |
IWDW | 1 |
| 2004 | Enhanced audio data hiding synchronization using non linear filtersabstractThe paper addresses the problem of synchronization in the context of audio data hiding. For real time transmission purposes, the data decoding process has to deal with synchronization issues. The paper proposes an new synchronization scheme that optimizes the performances of systems which are based on spread spectrum synchronization by the use of mathematical morphological tools that present good performance for peak detection. A brief theoretical presentation of the top-hat filter is recalled and the enhanced system is derived from the analysis of the advantages and disadvantages. The final scheme provides a robust synchronization system and is compared with the classical solutions. Alejandro LoboGuerrero, Ferran Marqués, Patrick Bas, Joel Lienard |
ICASSP (2) | 3 |
| 2003 | Color image watermarking using quaternion Fourier transformabstractThe paper presents a digital color image watermarking scheme using a hypercomplex numbers representation and the quaternion Fourier transform (QFT). Previous color image watermarking methods are first presented and the quaternion representation is then described. In this framework, RGB pixel values are associated with a unique quaternion number having three imaginary parts. The QFT is presented; this transform depends on an arbitrary unit pure quaternion, /spl mu/. The value of /spl mu/ is selected to provide embedding spaces having robustness and/or perceptual properties. In our approach, /spl mu/ is a function of the mean color value of a block and a perceptual component. A watermarking scheme based on the QFT and the quantization index modulation scheme is then presented. This scheme is evaluated for different color image filtering processes (JPEG, blur). The fact that perceptive QFT embedding can offer robustness to luminance filtering techniques is outlined. Patrick Bas, Nicolas Le Bihan, Jean-Marc Chassery |
ICASSP (3) | 1 |
| 2002 | Image watermarking: an evolution to content based approaches
Patrick Bas, Jean-Marc Chassery, Benoît Macq |
Pattern Recognit. | 1 |
| 2002 | Geometrically invariant watermarking using feature pointsabstractThis paper presents a new approach for watermarking of digital images providing robustness to geometrical distortions. The weaknesses of classical watermarking methods to geometrical distortions are outlined first. Geometrical distortions can be decomposed into two classes: global transformations such as rotations and translations and local transformations such as the StirMark attack. An overview of existing self-synchronizing schemes is then presented. Theses schemes can use periodical properties of the mark, invariant properties of transforms, template insertion, or information provided by the original image to counter geometrical distortions. Thereafter, a new class of watermarking schemes using the image content is presented. We propose an embedding and detection scheme where the mark is bound with a content descriptor defined by salient points. Three different types of feature points are studied and their robustness to geometrical transformations is evaluated to develop an enhanced detector. The embedding of the signature is done by extracting feature points of the image and performing a Delaunay tessellation on the set of points. The mark is embedded using a classical additive scheme inside each triangle of the tessellation. The detection is done using correlation properties on the different triangles. The performance of the presented scheme is evaluated after JPEG compression, geometrical attack and transformations. Results show that the fact that the scheme is robust to these different manipulations. Finally, in our concluding remarks, we analyze the different perspectives of such content-based watermarking scheme. Patrick Bas, Jean-Marc Chassery, Benoît Macq |
IEEE Trans. Image Process. | 1 |
| 2001 | A new video-object watermarking scheme robust to object manipulationabstractThis paper presents a watermarking scheme for image or video objects. The watermarking of video objects implies different constraints from raw watermarking methods. The mark has to be detected after object manipulations such as rotations, translations and VOL modifications. To achieve these requirements, the embedding scheme exploits the shape of the object: a random sequence is transformed to fit the scale and the orientation of the object. The detection of the mark is performed applying an inverse transform and calculating a correlation between the random sequence and the warped object. Our results illustrate the fact that the presented method is robust to object manipulation. Patrick Bas, Benoît Macq |
ICIP (3) | 1 |
| 2001 | A new video-object watermarking scheme robust to object manipulationabstractThis paper presents a watermarking scheme for image or video objects. The watcamarking of video objects implies different constraints from raw watermarking methods. The mark has to be detected after object manipulations such as rotations, translations arid VOL modifications. To achieve these requirements, the embedding scheme exploits the shape of the object: a random sequence is transformed to fit the scale and the orientation of the object. The detection of the mark is performed applying an inverse transform and calculating a correlation between the random sequence and the warped object. Our results illustrate the fact that the presented method is robust to object manipulation. Patrick Bas, Benoît Macq |
ICIP (2) | 1 |
| 2001 | A new CDMA technique for digital image watermarking, enhancing capacity of insertion and robustnessabstractImage watermarking has today a growing success in the community of image processing. Many methods were already proposed making it possible to obtain increasingly more powerful algorithms. The multi-layer method that we propose aims at inserting a non binary message in an image. It is issued from techniques tested in communication, namely spread spectrum techniques and more specifically the CDMA (code division multiaccess). Applied to image watermarking, it makes it possible to insert a more significant payload in an image without degrading it. In addition this method is robust with all the typical image processing attacks : JPEG compression with a quality factor of 50%, collusion, histogram manipulations, average filters. Boris Vassaux, Patrick Bas, Jean-Marc Chassery |
ICIP (3) | 2 |
| 1998 | Using the Fractal Code to Watermark ImagesabstractOur paper presents a watermarking scheme based on an insertion of similarities. In the first part different watermarking techniques are presented and classed. In the second part our scheme is described in its spatial and frequential implantations. Finally the different results and perspectives of the work are outlined. Patrick Bas, Jean-Marc Chassery, Franck Davoine |
ICIP (1) | 1 |