Matthew C. Stamm

dblp:77/4225 · also Matthew Christopher Stamm · DBLP profile ↗
← Back
55ranked-venue papers
11as first author
13since 2021 · last 2026
0000-0002-3986-4039ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 33 · 8 first-author · 7 since 2021Security and privacy · 18 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 Seeing the Unseen: Enhancing Synthetic Video Detector Transferability to New AI Video Generation Models via Virtual Generators
abstract
Synthetic video detectors often struggle to generalize to content generated by previously unseen models. While training on a diverse set of generators can improve transferability, this approach is inherently limited by the finite number of known generators. In this work, we address this challenge by introducing a novel technique to artificially boost training diversity through virtual generators - parametric models that synthesize forensic microstructures not associated with any real generator. We model these microstructures using a 2D autoregressive process and design AR parameters that simulate plausible yet unseen generative behaviors, informed by architectural patterns and learned transformations in modern video generators. Our results demonstrate that detectors trained with virtual generators significantly outperform those trained with traditional data augmentation and offer improved generalization to new generators.
Danial Samadi Vahdati, Tai D. Nguyen, Aref Azizpour, Hamed Ahangari, Matthew C. Stamm
IH&MMSec5
2025 Forensic Self-Descriptions Are All You Need for Zero-Shot Detection, Open-Set Source Attribution, and Clustering of AI-generated Images
abstract
The emergence of advanced AI-based tools to generate realistic images poses significant challenges for forensic detection and source attribution, especially as new generative techniques appear rapidly. Traditional methods often fail to generalize to unseen generators due to reliance on features specific to known sources during training. To address this problem, we propose a novel approach that explicitly models forensic microstructures—subtle, pixel-level patterns unique to the image creation process. Using only real images in a self-supervised manner, we learn a set of diverse predictive filters to extract residuals that capture different aspects of these microstructures. By jointly modeling these residuals across multiple scales, we obtain a compact model whose parameters constitute a unique forensic self-description for each image. This self-description enables us to perform zero-shot detection of synthetic images, open-set source attribution of images, and clustering based on source without prior knowledge. Extensive experiments demonstrate that our method achieves superior accuracy and adaptability compared to competing techniques, advancing the state of the art in synthetic media forensics.
Tai D. Nguyen, Aref Azizpour, Matthew C. Stamm
CVPR3
2025 SAFE: Synthetic Audio Forensics Evaluation Challenge
abstract
Figure 1: Synthetic Audio Forensics Evaluation Challenge Round 1 Results.Performance (circle markers) from top five teams and the detection vs. false alarm curves are shown for three tasks of increasing difficulty: detection of (1) synthetic voice audio, (2) synthetic voice audio post-processed with various compression and resampling and (3) laundered to evade detection.
Kirill Trapeznikov, Paul Cummer, Pranay Pherwani, Jai Aslam, Michael Davinroy, Peter Bautista, Laura Cassani, Matthew C. Stamm
IH&MMSec8
2025 Unmasking Puppeteers: Leveraging Biometric Leakage to Expose Impersonation in AI-Based Videoconferencing
abstract
AI-based talking-head videoconferencing systems reduce bandwidth by transmitting a latent representation of a speaker’s pose and expression, which is used to synthesize frames on the receiver's end. However, these systems are vulnerable to “puppeteering” attacks, where an adversary controls the identity of another person in real-time. Traditional deepfake detectors fail here, as all video content is synthetic. We propose a novel biometric defense that detects identity leakage in the transmitted latent representation. Our metric-learning approach disentangles identity cues from pose and expression, enabling detection of unauthorized swaps. Experiments across multiple talking-head models show that our method consistently outperforms prior defenses, operates in real time on consumer GPUs, and generalizes well to out-of-distribution data. By targeting the latent features shared during normal operation, our method offers a practical and robust safeguard against puppeteering.
Danial Samadi Vahdati, Tai D. Nguyen, Ekta Prashnani, Koki Nagano, David P. Luebke, Orazio Gallo, Matthew C. Stamm
NeurIPS7
2025 MVFNet: Multipurpose Video Forensics Network using Multiple Forms of Forensic Evidence
abstract
While videos can be falsified in many different ways, most existing forensic networks are specialized to detect only a single manipulation type (e.g. deepfake, inpainting). This poses a significant issue as the manipulation used to falsify a video is not known a priori. To address this problem, we propose MVFNet - a multipurpose video forensics network capable of detecting multiple types of manipulations including inpainting, deepfakes, splicing, and editing. Our network does this by extracting and jointly analyzing a broad set of forensic feature modalities that capture both spatial and temporal anomalies in falsified videos. To re-liably detect and localize fake content of all shapes and sizes, our network employs a novel Multi-Scale Hierarchi-cal Transformer module to identify forensic inconsistencies across multiple spatial scales. Experimental results show that our network obtains state-of-the-art performance in general scenarios where multiple different manipulations are possible, and rivals specialized detectors in targeted scenarios.
Tai D. Nguyen, Matthew C. Stamm
WACV2
2025 Generative Adversarial Attacks Against Deep- Learning-Based Camera Model Identification
abstract
Recently, deep learning techniques have gained popularity in multimedia forensics research designed to accomplish tasks such as camera model identification. However, despite the success of deep learning techniques, research has shown that they are vulnerable to adversarial perturbations. These adversarial perturbations can cause deep learning classifiers to misclassify images even though the perturbations are imperceptible to human eyes. To understand the vulnerabilities of deep-learning-based forensic algorithms, we propose a novel anti-forensic framework inspired by generative adversarial networks that is capable of falsifying an image’s source camera model. To accomplish this, we design a generator to anti-forensically falsify camera model traces in an image without introducing visually perceptible changes or artifacts. We propose two techniques to adversarially train this generator depending on the knowledge available to the attacker. In a white-box scenario when complete knowledge of an investigator’s camera model identification network is available to an attacker, we directly incorporate the network into our generator’s adversarial training strategy. In a black-box scenario when no internal details of the camera model classifier are available to the attacker, we construct a substitute network to mimic its decisions, then utilize this substitute network to adversarially train our generator. We conduct a series of experiments to evaluate the performance of our attack against several well-known CNNbased camera model classifiers. Experimental results show that our attack can successfully fool these CNNs in both white-box and black-box scenarios. Furthermore, our attack maintains high image quality and can be generalized to attack images from arbitrary source camera models.
Chen Chen 0059, Matthew C. Stamm
IEEE Trans. Inf. Forensics Secur.3
2024 VideoFACT: Detecting Video Forgeries Using Attention, Scene Context, and Forensic Traces
abstract
Fake videos represent an important misinformation threat. While existing forensic networks have demonstrated strong performance on image forgeries, recent results reported on the Adobe VideoSham dataset show that these networks fail to identify fake content in videos. In response, we propose VideoFACT - a new network that is able to detect and localize a wide variety of video forgeries and manipulations. To overcome challenges that existing networks face when analyzing videos, our network utilizes both forensic embeddings to capture traces left by manipulation, context embeddings to control for variation in forensic traces introduced by video coding, and a deep self-attention mechanism to estimate the quality and relative importance of local forensic embeddings. We create several new video forgery datasets and use these, along with publicly available data, to experimentally evaluate our network’s performance. These results show that our proposed network is able to identify a diverse set of video forgeries, including those not encountered during training. Furthermore, we show that our network can be fine-tuned to achieve even stronger performance on challenging AI-based manipulations. (Code is available at: https://github.com/ductai199x/videofact-wacv-2024)
Tai D. Nguyen, Shengbang Fang, Matthew C. Stamm
WACV3
2024 Attacking Image Splicing Detection and Localization Algorithms Using Synthetic Traces
abstract
Recent advances in deep learning have enabled forensics researchers to develop a new class of image splicing detection and localization algorithms. These algorithms identify spliced content by detecting localized inconsistencies in forensic traces using Siamese neural networks, either explicitly during analysis or implicitly during training. At the same time, deep learning has enabled new forms of anti-forensic attacks, such as adversarial examples and generative adversarial network (GAN) based attacks. Thus far, however, no anti-forensic attack has been demonstrated against image splicing detection and localization algorithms. In this paper, we propose a new GAN-based anti-forensic attack that is able to fool state-of-the-art splicing detection and localization algorithms such as EXIF-Net, Noiseprint, and Forensic Similarity Graphs. This attack operates by adversarially training an anti-forensic generator against a set of Siamese neural networks so that it is able to create synthetic forensic traces. Under analysis, these synthetic traces appear authentic and are self-consistent throughout an image. Through a series of experiments, we demonstrate that our attack is capable of fooling forensic splicing detection and localization algorithms without introducing visually detectable artifacts into an attacked image. Additionally, we demonstrate that our attack outperforms existing alternative attack approaches.
Shengbang Fang, Matthew C. Stamm
IEEE Trans. Inf. Forensics Secur.2
2023 Open Set Synthetic Image Source Attribution
Shengbang Fang, Tai D. Nguyen, Matthew C. Stamm
BMVC3
2023 Semantic Adversarial Attacks via Diffusion Models
Chenan Wang, Jinhao Duan, Chaowei Xiao, Edward Kim 0006, Matthew C. Stamm, Kaidi Xu
BMVC5
2023 Comprehensive Dataset of Synthetic and Manipulated Overhead Imagery for Development and Evaluation of Forensic Tools
abstract
We present a first of its kind dataset of overhead imagery for development and evaluation of forensic tools. Our dataset consists of real, fully synthetic and partially manipulated overhead imagery generated from a custom diffusion model trained on two sets of different zoom levels and on two sources of pristine data. We developed our model to support controllable generation of multiple manipulation categories including fully synthetic imagery conditioned on real and generated base maps, and location. We also support partial in-painted imagery with same conditioning options and with several types of manipulated content. The data consist of raw images and ground truth annotations describing the manipulation parameters. We also report benchmark performance on several tasks supported by our dataset including detection of fully and partially manipulated imagery, manipulation localization and classification.
Brandon B. May, Kirill Trapeznikov, Shengbang Fang, Matthew C. Stamm
IH&MMSec4
2022 Deepfake Speech Detection Through Emotion Recognition: A Semantic Approach
abstract
In recent years, audio and video deepfake technology has advanced relentlessly, severely impacting people’s reputation and reliability. Several factors have facilitated the growing deepfake threat. On the one hand, the hyper-connected society of social and mass media enables the spread of multimedia content worldwide in real-time, facilitating the dissemination of counterfeit material. On the other hand, neural network-based techniques have made deepfakes easier to produce and difficult to detect, showing that the analysis of low-level features is no longer sufficient for the task. This situation makes it crucial to design systems that allow detecting deepfakes at both video and audio levels. In this paper, we propose a new audio spoofing detection system leveraging emotional features. The rationale behind the proposed method is that audio deepfake techniques cannot correctly synthesize natural emotional behavior. Therefore, we feed our deepfake detector with high-level features obtained from a state-of-the-art Speech Emotion Recognition (SER) system. As the used descriptors capture semantic audio information, the proposed system proves robust in cross-dataset scenarios outperforming the considered baseline on multiple datasets.
Emanuele Conti, Davide Salvi, Clara Borrelli, Brian C. Hosler, Paolo Bestagini, Fabio Antonacci, Augusto Sarti, Matthew C. Stamm, Stefano Tubaro
ICASSP8
2021 Robust camera model identification using demosaicing residual features
Chen Chen 0059, Matthew C. Stamm
Multim. Tools Appl.2
2020 Open Set Video Camera Model Verification
abstract
We introduce a new open set video forensics problem called video camera model verification. The video camera model verification task is to determine if two query videos were captured by the same camera model. Importantly, verification must be reliable on videos from camera models unknown to the investigator, referred to the as the open set scenario. While researchers have considered other open set problems for digital images, video forensics introduces unique challenges. In this work we propose a new, video-specific system for open set verification of camera models. To do this, we design a deep-learning based system that 1) uses a CNN to extract expressive deep features from video patches, 2) compares pairs of these features using a similarity network, and 3) fuses multiple comparisons to produce a video-level verification decision. We experimentally show that this technique accurately verifies the source camera model of videos in open set scenarios.
Owen Mayer, Brian C. Hosler, Matthew C. Stamm
ICASSP3
2020 Forensic Similarity for Digital Images
abstract
In this paper, we introduce a new digital image forensics approach called forensic similarity, which determines whether two image patches contain the same forensic trace or different forensic traces. One benefit of this approach is that prior knowledge, e.g., training samples, of a forensic trace is not required to make a forensic similarity decision on it in the future. To do this, we propose a two-part deep-learning system composed of a convolutional neural network-based feature extractor and a three-layer neural network, called the similarity network. This system maps the pairs of image patches to a score indicating whether they contain the same or different forensic traces. We evaluated the system accuracy of determining whether two image patches were captured by the same or different camera model and manipulated by the same or a different editing operation and the same or a different manipulation parameter, given a particular editing operation. Experiments demonstrate applicability to a variety of forensic traces and importantly show efficacy on “unknown” forensic traces that were not used to train the system. Experiments also show that the proposed system significantly improves upon prior art, reducing error rates by more than half. Furthermore, we demonstrated the utility of the forensic similarity approach in two practical applications: forgery detection and localization, and database consistency verification.
Owen Mayer, Matthew C. Stamm
IEEE Trans. Inf. Forensics Secur.2
2019 Data Reduction, Compression, and Recovery for Online Performance Monitoring
abstract
The volume of data needed for effective monitoring of datacenters poses significant challenges in its collection, transmission, analysis, and storage. Considering a setting wherein data collected locally at a server is sent to a monitoring station for analysis, this paper develops computationally efficient methods for systematic reduction of this data during the transfer and its subsequent recovery at the monitoring station. Specifically, we develop a low-cost method of obtaining a sparse representation of the data collected at each individual server while preserving a specified fidelity with respect to the original signal. The sparsified representation obtained from the data-collection step is amenable to further compression prior to transmission to the monitoring station. Upon receipt of the compressed-data stream at the monitoring station, a method of sparse-signal recovery is utilized to reconstruct the original full-length signal for further analysis. The techniques are validated using workload traces collected from one of Google's production clusters. Experiments show that the achieved data reduction, which is a function of the specified fidelity, is significant: to reconstruct the signal with a fidelity between 90%-95%, the sample size that must be be transferred to the monitoring station is under 10% of the original. We also verify that the recovered signal tracks the target minimum fidelity requirements specified by the operator with high precision.
Salvador DeCelles, Matthew C. Stamm, Nagarajan Kandasamy
CLOUD2
2019 A Video Camera Model Identification System Using Deep Learning and Fusion
abstract
While significant work has been conducted to perform source camera model identification for images, little work has been done specifically for video camera model identification. This is problematic because different forensic traces may be left in digital images and videos captured by the same camera. As our experiments in this paper will show, a system trained to perform camera model identification for images yields unacceptably low performance when given video frames from the same cameras. To overcome this problem, new systems for identifying a videos source must be developed. In this paper, we propose a deep learning based system for determining the source camera model that captured a digital video. To do this, we use a convolutional neural network to produce camera model identification scores for small patches taken from video frames. These patches are chosen by a patch selection system that obtains patches from several appropriate frames temporally distributed throughout the video. Forensic information obtained by the CNN is provided to a fusion system, which combines it to produce a single, more accurate identification result. Through a series of experiments, we evaluate several system design choices and show that our system can achieve 95.9% video camera model identification accuracy.
Brian C. Hosler, Owen Mayer, Belhassen Bayar, Chen Chen 0059, James A. Shackleford, Matthew C. Stamm
ICASSP7
2019 An Efficient Strategy for Online Performance Monitoring of Datacenters via Adaptive Sampling
abstract
Performance monitoring of datacenters provides vital information for dynamic resource provisioning, anomaly detection, and capacity planning decisions. Online monitoring, however, incurs a variety of costs: the very act of monitoring a system interferes with its performance, consuming network bandwidth and disk space. With the goal of reducing these costs, this paper develops and validates a strategy based on adaptive-rate compressive sampling. It exploits the fact that the signals of interest often can be sparsified under an appropriate representation basis and that the sampling rate can be tuned as a function of sparsity. We use the Trade6 application as our experimental platform and measure the signals of interest-in our case, signals pertaining to memory and disk I/O activity-using adaptive sampling. We then evaluate whether the reconstructed signals can be used for trend detection to track the gradual deterioration of system performance associated with software aging. Our experiments show that the signals recovered by our methods can be used to detect, with high confidence, the existence of trends within the original signal. We also evaluate the reconstructed signals for threshold-violation detection wherein the magnitude of the signal exceeds a preset value. Our experiments show that performance bottlenecks and anomalies that manifest themselves in portions of the signal where its magnitude exceeds a threshold value can also be detected using the reconstructed signals. Most importantly, detection of these anomalies is achieved using a substantially reduced sample size-a reduction of more than 70 percent when compared to the standard fixed-rate sampling method.
Tingshan Huang, Nagarajan Kandasamy, Harish Sethu, Matthew C. Stamm
IEEE Trans. Cloud Comput.4
2018 Towards Open Set Camera Model Identification Using a Deep Learning Framework
abstract
Existing forensic camera model identification algorithms can be trained to accurately distinguish between a set of known camera models. In reality, however, an investigator may be confronted with an image that was not captured by one of these known models. If this happens, existing algorithms will associate this image with one of the known camera models. This is known as the open set problem. In this paper, we propose two different approaches to address the open set problem for camera model identification. To do this, we use a CNN to learn a set of deep forensic features. Our first approach replaces the CNN's classifier with a confidence score mapping which it thresholds to detect unknown models. Our second approach uses a set of `known unknown' models to train a new classifier to identify unknown camera models. Experiments show that we can detect unknown camera models with a 97.74% accuracy.
Belhassen Bayar, Matthew C. Stamm
ICASSP2
2018 Learned Forensic Source Similarity for Unknown Camera Models
abstract
Information about an image's source camera model is important knowledge in many forensic investigations. In this paper we propose a system that compares two image patches to determine if they were captured by the same camera model. To do this, we first train a CNN based feature extractor to output generic, high level features which encode information about the source camera model of an image patch. Then, we learn a similarity measure that maps pairs of these features to a score indicating whether the two image patches were captured by the same or different camera models. We show that our proposed system accurately determines if two patches were captured by the same or different camera models, even when the camera models are unknown to the investigator. We also demonstrate the utility of this approach for image splicing detection and localization.
Owen Mayer, Matthew C. Stamm
ICASSP2
2018 Mislgan: An Anti-Forensic Camera Model Falsification Framework Using A Generative Adversarial Network
abstract
Deep learning techniques have become popular for performing camera model identification. To expose weaknesses in these methods, we propose a new anti-forensic framework that utilizes a generative adversarial network (GAN) to falsify an image's source camera model. Our proposed attack uses the generator trained in the GAN to produce an image that can fool a CNN-based camera model identification classifier. Moreover, our proposed attack will only introduce a minimal amount of distortion to the falsified image that is not perceptible to human eyes. By conducting experiments on a large amount of data, we show that the proposed attack can successfully fool a state-of-art camera model identification CNN classifier with 98% probability and maintain high image quality.
Chen Chen 0059, Matthew C. Stamm
ICIP3
2018 Learning Unified Deep-Features for Multiple Forensic Tasks
abstract
Recently, deep learning researchers have developed a technique known as deep features in which feature extractors for a task are learned by a CNN. These features are then provided to another classifier, or even used to perform a different classification task. Research in deep learning suggests that in some cases, deep features generalize to seemingly unrelated tasks. In this paper, we develop techniques for learning deep features that can be used across multiple forensic tasks, namely image manipulation detection and camera model identification. To do this, we develop two approaches for building deep forensic features: a transfer learning approach and a multitask learning approach. We experimentally evaluate the performance of both approaches in several scenarios and find that: 1) features learned for camera model identification generalize well to manipulation detection tasks but manipulation detection features do not generalize well to camera model identification, suggesting a task asymmetry, 2) deeper features are more task specific while shallower features generalize well across tasks, suggesting a feature hierarchy, and 3) a single, unified feature extractor can be learned that is highly discriminative for multiple forensic tasks. Furthermore, we find that when there is limited training data, a unified feature extractor can significantly outperform a targeted CNN.
Owen Mayer, Belhassen Bayar, Matthew C. Stamm
IH&MMSec3
2018 Constrained Convolutional Neural Networks: A New Approach Towards General Purpose Image Manipulation Detection
abstract
Identifying the authenticity and processing history of an image is an important task in multimedia forensics. By analyzing traces left by different image manipulations, researchers have been able to develop several algorithms capable of detecting targeted editing operations. While this approach has led to the development of several successful forensic algorithms, an important problem remains: creating forensic detectors for different image manipulations is a difficult and time consuming process. Furthermore, forensic analysts need general purpose forensic algorithms capable of detecting multiple different image manipulations. In this paper, we address both of these problems by proposing a new general purpose forensic approach using convolutional neural networks (CNNs). While CNNs are capable of learning classification features directly from data, in their existing form they tend to learn features representative of an image's content. To overcome this issue, we have developed a new type of CNN layer, called a constrained convolutional layer, that is able to jointly suppress an image's content and adaptively learn manipulation detection features. Through a series of experiments, we show that our proposed constrained CNN is able to learn manipulation detection features directly from data. Our experimental results demonstrate that our CNN can detect multiple different editing operations with up to 99.97% accuracy and outperform the existing state-of-the-art general purpose manipulation detector. Furthermore, our constrained CNN can still accurately detect image manipulations in realistic scenarios where there is a source camera model mismatch between the training and testing data.
Belhassen Bayar, Matthew C. Stamm
IEEE Trans. Inf. Forensics Secur.2
2018 Accurate and Efficient Image Forgery Detection Using Lateral Chromatic Aberration
abstract
In copy-and-paste image forgeries, where image content is copied from one image and pasted into another, inconsistencies in an imaging feature called lateral chromatic aberration (LCA) are intrinsically introduced. In this paper, we propose a new methodology to detect forged image regions that is based on detecting localized LCA inconsistencies. To do this, we propose a statistical model that captures the inconsistency between global and local estimates of LCA. We then use this model to pose forgery detection as a hypothesis testing problem and derive a detection statistic, which we show is optimal when certain conditions are met. To test its detection efficacy, we conduct a series of experiments that demonstrate our proposed methodology significantly outperforms prior art and addresses deficiencies of previous research. Additionally, we propose a new and efficient LCA estimation algorithm. To accomplish this we adapt a block matching algorithm, called diamond search, which efficiently measures the LCA in a localized region. We experimentally show that our proposed estimation algorithm reduces estimation time by two orders of magnitude without introducing additional estimation error.
Owen Mayer, Matthew C. Stamm
IEEE Trans. Inf. Forensics Secur.2
2017 On the robustness of constrained convolutional neural networks to JPEG post-compression for image resampling detection
abstract
Detecting image resampling in re-compressed images is a very challenging problem. Existing approaches to image resampling detection operate by building pre-selected model to locate periodicities in linear predictor residues. Additionally, if an image was JPEG compressed before resampling, existing techniques detect tampering using the artifacts left by the pre-compression. However, state-of-the-art approaches cannot detect resampling in re-compressed images initially compressed with high quality factor. In this paper, we propose a novel deep learning approach to adaptively learn resampling detection features directly from data. To accomplish this, we use our recently proposed constrained convolutional layer. Through a set of experiments we evaluate the effectiveness of our proposed constrained convolutional neural network (CNN) to detect resampling in re-compressed images. The results of these experiments show that our constrained CNN can accurately detect resampling in re-compressed images in scenarios that previous approaches are unable to detect.
Belhassen Bayar, Matthew C. Stamm
ICASSP2
2017 Augmented convolutional feature maps for robust CNN-based camera model identification
abstract
Identifying the model of the camera that captured an image is an important forensic problem. While several algorithms have been proposed to accomplish this, their performance degrades significantly if the image is subject to post-processing. This is problematic since social media applications and photo-sharing websites typically resize and recompress images. In this paper, we propose a new convolutional neural network based approach to performing camera model identification that is robust to resampling and recompression. To accomplish this, we propose a new approach to low-level feature extraction that uses both a constrained convolutional layer and a nonlinear residual feature extractor in parallel. The feature maps produced by both of these layers are then concatenated and passed to subsequent convolutional layers for further feature extraction. Experimental results show that our proposed approach can significantly improve camera model identification performance in resampled and recompressed images.
Belhassen Bayar, Matthew C. Stamm
ICIP2
2017 Image filter identification using demosaicing residual features
abstract
Image filters have become a popular feature of photo editing software and camera phones. Filter identification can provide useful information for us to determine source and processing history of images. Currently, there is no forensic work done to perform filter identification. In this paper, we propose a framework to search for color correlations left by different filters in a set of interpolation residuals obtained from various demosaicing algorithms. To effectively capture the structures of color correlations, we design a diverse set of geometric co-occurrence patterns and gather both intra-channel and inter-channel color dependencies using co-occurrence matrices. Experiments conducted on two large image databases full demonstrate the ability of our framework to identify a wide range of filters provided by both cameras and third-party software.
Chen Chen 0059, Matthew C. Stamm
ICIP2
2017 Detecting anti-forensic attacks on demosaicing-based camera model identification
abstract
Many forensic algorithms have been developed to determine the model of an image's source camera by examining traces left by the camera's demosaicing algorithm. An anti-forensic attacker, however, can falsify these traces by maliciously using existing forensic techniques to estimate one camera's demosaicing filter, then use these estimates to re-demosaic an image captured by a different camera. Currently, there is no known defense against this attack, which is capable of fooling existing camera model identification algorithms. In this paper, we propose a new method to detect if an image's source camera model has been anti-forensically falsified. Our algorithm operates by characterizing the different content-independent local pixel relationships that are introduced by both authentic demosaicing algorithms and anti-forensic attacks. Experimental results show that our algorithm can detect an anti-forensic attack with over 99% accuracy, is robust to JPEG compression, and can even identify the true source camera model in certain circumstances.
Chen Chen 0059, Matthew C. Stamm
ICIP3
2017 A Generic Approach Towards Image Manipulation Parameter Estimation Using Convolutional Neural Networks
abstract
Estimating manipulation parameter values is an important problem in image forensics. While several algorithms have been proposed to accomplish this, their application is exclusively limited to one type of image manipulation. These existing techniques are often designed using classical approaches from estimation theory by constructing parametric models of image data. This is problematic since this process of developing a theoretical model then deriving a parameter estimator must be repeated each time a new image manipulation is derived. In this paper, we propose a new data-driven generic approach to performing manipulation parameter estimation. Our proposed approach can be adapted to operate on several different manipulations without requiring a forensic investigator to make substantial changes to the proposed method. To accomplish this, we reformulate estimation as a classification problem by partitioning the parameter space into disjoint subsets such that each parameter subset is assigned a distinct class. Subsequently, we design a constrained CNN-based classifier that is able to extract classification features directly from data as well as estimating the manipulation parameter value in a subject image. Through a set of experiments, we demonstrated the effectiveness of our approach using four different types of manipulations.
Belhassen Bayar, Matthew C. Stamm
IH&MMSec2
2017 Countering Anti-Forensics of Lateral Chromatic Aberration
abstract
Research has shown that lateral chromatic aberrations (LCA), an imaging fingerprint, can be anti-forensically modified to hide evidence of cut-and-paste forgery. In this paper, we propose a new technique for securing digital images against anti-forensic manipulation of LCA. To do this, we exploit resizing differences between color channels, which are induced by LCA anti-forensics, and define a feature vector to quantitatively capture these differences. Furthermore, we propose a detection method that exposes anti-forensically manipulated image patches. The technique algorithm is validated through experimental procedure, showing dependence on forgery patch size as well as anti-forensic scaling factor.
Owen Mayer, Matthew C. Stamm
IH&MMSec2
2016 Detecting Incipient Faults in Software Systems: A Compressed Sampling-Based Approach
abstract
The volume of data to be collected and processed for effective real-time monitoring of large-scale computing systems and networks poses significant Big Data challenges, and a scalable solution requires a systematic approach to dimensionality reduction during the data collection, transmission, and analysis phases. Compressive sampling can reduce the dimensionality of the data collected at the source prior to transmission to the monitoring station. Exploiting the fact that the compressed samples preserve in approximate form, the correlation information between data points in the original full-length signal, we develop a low-cost anomaly detection technique based on principal component analysis (PCA) aimed at incipient faults such as software aging—the key idea being PCA is performed directly on the compressed samples without having to reconstruct the original signal. Using case studies involving long-running enterprise benchmark applications, Trade6 and RuBBoS, with injected memory leaks, we show that the performance of the PCA-based detector when using just the compressed data is almost equivalent to the case in which the raw data is completely available, but achieved using significantly fewer samples with a compression rate exceeding 75%.
Salvador DeCelles, Tingshan Huang, Matthew C. Stamm, Nagarajan Kandasamy
CLOUD3
2016 Improved forgery detection with lateral chromatic aberration
abstract
In this paper we propose a technique to improve the accuracy of lateral chromatic aberration (LCA) based detection of copy-paste image forgeries. We propose a statistical model of the error between local estimates of LCA displacement vectors and those predicted by a global model. Using this statistical model, we formulate forgery detection as a hypothesis testing problem, and derive the optimal detection statistic for performing LCA-based forgery detection. Through a series of experiments, we demonstrate that our proposed technique outperforms existing approaches for conducting LCA-based forgery detection.
Owen Mayer, Matthew C. Stamm
ICASSP2
2016 Computationally efficient demosaicing filter estimation for forensic camera model identification
abstract
Determining the make and model of an image's source camera is an important forensic problem. While significant research has been conducted towards developing new camera model identification algorithms, little research has focused on controlling the computational cost of these algorithms. This becomes an important issue if forensic algorithms are to be used in “big data” scenarios. In this paper, we propose a new approach for controlling the computational cost associated with the algorithm proposed by Swaminathan et al. that identifies an image's source camera using least squares estimates of its demosaicing filter. Through a set of experiments, we show that our algorithm is able to achieve a higher classification accuracy at a fixed computational cost than the existing method. Similarly, our algorithm is able to reach a target classification accuracy at a lower computational cost.
Matthew C. Stamm
ICIP2
2016 A Deep Learning Approach to Universal Image Manipulation Detection Using a New Convolutional Layer
abstract
When creating a forgery, a forger can modify an image using many different image editing operations. Since a forensic examiner must test for each of these, significant interest has arisen in the development of universal forensic algorithms capable of detecting many different image editing operations and manipulations. In this paper, we propose a universal forensic approach to performing manipulation detection using deep learning. Specifically, we propose a new convolutional network architecture capable of automatically learning manipulation detection features directly from training data. In their current form, convolutional neural networks will learn features that capture an image's content as opposed to manipulation detection features. To overcome this issue, we develop a new form of convolutional layer that is specifically designed to suppress an image's content and adaptively learn manipulation detection features. Through a series of experiments, we demonstrate that our proposed approach can automatically learn how to detect multiple image manipulations without relying on pre-selected features or any preprocessing. The results of these experiments show that our proposed approach can automatically detect several different manipulations with an average accuracy of 99.10%.
Belhassen Bayar, Matthew C. Stamm
IH&MMSec2
2016 Information Theoretical Limit of Media Forensics: The Forensicability
abstract
While more and more forensic techniques have been proposed to detect the processing history of multimedia content, one starts to wonder if there exists a fundamental limit on the capability of forensics. In other words, besides keeping on searching what investigators can do, it is also important to find out the limit of their capability and what they cannot do. In this paper, we explore the fundamental limit of operation forensics by proposing an information theoretical framework. In particular, we consider a general forensic system of estimating operations' hypotheses based on extracted features from the multimedia content. In this system, forensicability is defined as the maximum forensic information that features contain about operations. Then, due to its conceptual similarity with mutual information in an information theory, forensicability is measured as the mutual information between features and operations' hypotheses. Such a measurement gives the error probability lower bound of all practical estimators, which use these features to detect the operations' hypotheses. Furthermore, it can determine the maximum number of hypotheses that we can theoretically detect. To demonstrate the effectiveness of our proposed information theoretical framework, we apply this framework on a forensic example of detecting the number of JPEG compressions based on normalized discrete cosine transform (DCT) coefficient histograms. We conclude that, when subband (2, 3) is used in detection and the size of the testing database is <;20000, the maximum number of JPEG compressions that we can expectedly perfectly detect using normalized DCT coefficient histogram features is four. Furthermore, we obtain the optimal strategies for investigators and forgers based on the fundamental measurement of forensicability.
Xiaoyu Chu, Yan Chen 0007, Matthew C. Stamm, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.3
2015 Compressive Sensing Forensics
abstract
Identifying a signal's origin and how it was acquired is an important forensic problem. While forensic techniques currently exist to determine a signal's acquisition history, these techniques do not account for the possibility that a signal could be compressively sensed. This is an important problem since compressive sensing techniques have seen increased popularity in recent years. In this paper, we propose a set of forensic techniques to identify signals acquired by compressive sensing. We do this by first identifying the fingerprints left in a signal by compressive sensing. We then propose two compressive sensing detection techniques that can operate on a broad class of signals. Since compressive sensing fingerprints can be confused with fingerprints left by traditional image compression techniques, we propose a forensic technique specifically designed to identify compressive sensing in digital images. In addition, we propose a technique to forensically estimate the number of compressive measurements used to acquire a signal. Through a series of experiments, we demonstrate that each of our proposed techniques can perform reliably under realistic conditions. Simulation results show that both our zero ratio detector and distribution-based detector yield perfect detections for all reasonable conditions that compressive sensing is used in applications, and the specific two-step detector for images can at least achieve probability of detection of 90% for probability of false alarm <;10%. In addition, our estimator for the number of compressive measurements can well reflect the real number.
Xiaoyu Chu, Matthew C. Stamm, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.2
2015 On Antiforensic Concealability With Rate-Distortion Tradeoff
abstract
A signal's compression history is of particular forensic significance because it contains important information about the origin and authenticity of a signal. Because of this, antiforensic techniques have been developed that allow a forger to conceal manipulation fingerprints. However, when antiforensic techniques are applied to multimedia content, distortion maybe introduced, or the data size may be increased. Furthermore,when compressing an antiforensically modified forgery, a tradeoff between the rate and distortion is introduced into the system. As a result, a forger must balance three factors, such as how much the fingerprints can be forensically concealed, the data rate, and the distortion, are interrelated to form a 3D tradeoff. In this paper, we characterize this tradeoff by defining concealability and using it to measure the effectiveness of an antiforensic attack. Then, to demonstrate this tradeoff in a realistic scenario, we examine the concealability-rate-distortion tradeoff in double JPEG compression antiforensics. To evaluate this tradeoff, we propose flexible antiforensic dither as an attack in which the forger can vary the strength of antiforensics. To reduce the time and computational complexity associated with decoding a JPEG file, applying antiforensics, and recompressing, we propose anantiforensic transcoder to efficiently complete these tasks in one step. Through simulation, two surprising results are revealed. One is that if a forger uses a lower quality factor in the second compression, applying antiforensics can both increase concealability and decrease the data rate. The other is that for any pairing of concealability and distortion values, achieved using a higher secondary quality factor, can also be achieved using a lower secondary quality factor at a lower data rate. As a result, the forger has an incentive to always recompress using a lower secondary quality factor.
Xiaoyu Chu, Matthew C. Stamm, Yan Chen 0007, K. J. Ray Liu
IEEE Trans. Image Process.2
2014 Information theoretical limit of compression forensics
abstract
Multimedia forensics concerns on extracting forensic information from suspicious multimedia contents. This information was embedded into the content inadvertently whenever an operation happened. Investigators may estimate the possible operations by obtaining features from the multimedia content and applying detection algorithms based on the statistics. While most existing works focus on improving detection performance and finding what more we can do, understanding the fundamental limit on the forensic information that we can obtain from the extracted features is also important. It enables us to understand the limit of forensicability. In this paper, we explore the fundamental limit of forensicability by introducing an information theoretical framework for multimedia forensics. We use mutual information as the measure of forensic information conveyed by features to investigators. To show the analytical process, we take the case of multiple JPEG compression forensics as an example. We claim that, under typical circumstances, the maximum number of compressions that we can detect by examine DCT coefficients is up to 4, in an expected sense. In addition, we also find the patterns of compression quality factors that contain the most and least forensic information.
Xiaoyu Chu, Yan Chen 0007, Matthew C. Stamm, K. J. Ray Liu
ICASSP3
2013 Concealability-rate-distortion tradeoff in image compression anti-forensics
abstract
Due to the ease with which digital multimedia content can be modified, a number of techniques to forensically detect forgeries have been developed. Meanwhile, anti-forensic operations have been developed to defeat forensic techniques. When anti-forensics is applied, a forger must balance between the amount that editing fingerprints have been concealed and the distortion introduced to the content. Additionally, the forger may compress the forgery for storage or transmission, which introduces a tradeoff between data rate and distortion. In this paper, we define a measure of an anti-forensic technique's effectiveness which we call concealability and examine the tradeoff between concealability, rate, and distortion. We then characterize the concealability-rate-distortion (C-R-D) surface for double JPEG compression anti-forensics. To do this, we propose a new technique known as flexible anti-forensic dither to hide double JPEG fingerprints. From our experiments, we identify two surprising results related to the C-R-D surface.
Xiaoyu Chu, Matthew C. Stamm, Yan Chen 0007, K. J. Ray Liu
ICASSP2
2013 Protection against reverse engineering in digital cameras
abstract
Over the past decade, a number of digital forensic techniques have been developed to authenticate digital signals. One important set of forensic techniques operates by estimating signal processing components of a digital camera's signal processing pipeline, then using these estimates to perform forensic tasks such as camera identification or forgery detection. However, because these techniques are capable of estimating a camera's internal signal processing components, these forensic techniques can be used for reverse engineering. In this paper, we propose integrating an anti-forensic module into a digital camera's processing pipeline to protect against forensic reverse engineering. Our proposed technique operates by removing linear dependencies amongst an output images interpolated color values and by disrupting the color sampling grid. Experimental results show that our proposed technique can be effectively used to protect against the forensic reverse engineering of key components of a digital camera's processing pipeline.
Matthew C. Stamm, K. J. Ray Liu
ICASSP1
2013 Anti-forensics of median filtering
abstract
A number of forensic techniques have been developed to identify the use of digital multimedia editing operations. In response, several anti-forensic operations have been designed to fool forensic algorithms. One operation that has received considerable attention is median filtering, since it can be used for image enhancement or anti-forensic purposes. As a result, several median filtering detectors have been developed. In this paper, we propose an anti-forensic technique to disguise the use of median filtering. We do this by first proposing a model for an unaltered image's pixel difference distribution. We then modify a median filter image's pixel difference distribution using anti-forensic noise so that it no longer contains median filtering fingerprints. Through a series of experiments, we are able to show that our anti-forensic technique can fool existing median filtering detectors under realistic conditions.
Zhung-Han Wu, Matthew C. Stamm, K. J. Ray Liu
ICASSP2
2013 Robust Median Filtering Forensics Using an Autoregressive Model
abstract
In order to verify the authenticity of digital images, researchers have begun developing digital forensic techniques to identify image editing. One editing operation that has recently received increased attention is median filtering. While several median filtering detection techniques have recently been developed, their performance is degraded by JPEG compression. These techniques suffer similar degradations in performance when a small window of the image is analyzed, as is done in localized filtering or cut-and-paste detection, rather than the image as a whole. In this paper, we propose a new, robust median filtering forensic technique. It operates by analyzing the statistical properties of the median filter residual (MFR), which we define as the difference between an image in question and a median filtered version of itself. To capture the statistical properties of the MFR, we fit it to an autoregressive (AR) model. We then use the AR coefficients as features for median filter detection. We test the effectiveness of our proposed median filter detection techniques through a series of experiments. These results show that our proposed forensic technique can achieve important performance gains over existing methods, particularly at low false-positive rates, with a very small dimension of features.
Xiangui Kang, Matthew C. Stamm, Anjie Peng, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.2
2012 Forensic identification of compressively sensed images
abstract
Due to the ease with which digital images can be forged, a great deal of work has been done in the field of digital image forensics. A particularly important problem is to forensically determine an image's acquisition and storage history. Recent research has shown that a new acquisition technique known as compressive sensing can be used to capture a digital image. Images acquired by compressive sensing can not be easily forensically distinguished from the images captured using standard digital cameras, nor from those which have undergone Discrete Wavelet Transform (DWT) based compressions. In this paper, we propose a two step detection scheme to identify the images acquired by compressive sensing. The first step identifies unaltered images captured using standard digital cameras and the second step separates compressively sensed images from ones compressed using DWT-based techniques. Our simulations show the first step of detection can achieve a probability of detection (Pd) of 100% for probability of false alarm (Pf) less than 4%, and the second step gets Pdnearly 90% with Pfof 10%.
Xiaoyu Chu, Matthew C. Stamm, Wan-Yi Sabrina Lin, K. J. Ray Liu
ICASSP2
2012 Forensics vs. anti-forensics: A decision and game theoretic framework
abstract
In order to combat the spread of digital forgeries, researchers have developed a variety of forensic techniques to verify the authenticity of digital multimedia files. Though many of these techniques can reliably detect traditional forgeries, recent research has shown that they can easily be fooled by anti-forensic operations designed to hide evidence of forgery. In response, new forensic techniques have been developed to detect the use of anti-forensics. In light of this, there is now a need to develop a theoretical understanding of the interactions between a forger using anti-forensics and a forensic investigator. In this paper, we propose techniques to evaluate the performance of anti-forensic algorithms along with a game theoretic framework for analyzing the interplay between forensics and anti-forensics. Furthermore, we propose a new automatic video frame deletion detection technique along with a technique to detect the use of video anti-forensics. We evaluate these techniques using our proposed analytical framework.
Matthew C. Stamm, Wan-Yi Sabrina Lin, K. J. Ray Liu
ICASSP1
2012 Forensic identification of compressively sensed signals
abstract
Identifying a signal's origin and how it was acquired is an important problem for digital forensics. Recently, compressive sensing has achieved substantial attention due to its ability to accurately acquire sparse signals at rates below the Nyquist rate. The increased popularity of this signal acquisition technique gives rise to a new forensic problem: is it possible to distinguish signals that have been compressively sensed from traditionally sampled ones? In our previous work, we addressed this problem of differentiating between traditionally acquired and compressively sensed images. In this paper, we examine the problem of distinguishing traditionally sampled signals from compressively sensed ones for a broader class of signals. We categorize those compressive sensing applicable signals into two cases: sparse signals with noise and nearly sparse signals. For each category, we discuss the traces left in a signal by compressive sensing and propose a corresponding detection scheme. Experimental results show that both of our proposed detection schemes can be effectively used to distinguish compressively sensed signals from traditionally sensed signals.
Xiaoyu Chu, Matthew C. Stamm, K. J. Ray Liu
ICIP2
2012 Temporal Forensics and Anti-Forensics for Motion Compensated Video
abstract
Due to the ease with which digital information can be altered, many digital forensic techniques have been developed to authenticate multimedia content. Similarly, a number of anti-forensic operations have recently been designed to make digital forgeries undetectable by forensic techniques. However, like the digital manipulations they are designed to hide, many anti-forensic operations leave behind their own forensically detectable traces. As a result, a digital forger must balance the trade-off between completely erasing evidence of their forgery and introducing new evidence of anti-forensic manipulation. Because a forensic investigator is typically bound by a constraint on their probability of false alarm (P_fa), they must also balance a trade-off between the accuracy with which they detect forgeries and the accuracy with which they detect the use of anti-forensics. In this paper, we analyze the interaction between a forger and a forensic investigator by examining the problem of authenticating digital videos. Specifically, we study the problem of adding or deleting a sequence of frames from a digital video. We begin by developing a theoretical model of the forensically detectable fingerprints that frame deletion or addition leaves behind, then use this model to improve upon the video frame deletion or addition detection technique proposed by Wang and Farid. Next, we propose an anti-forensic technique designed to fool video forensic techniques and develop a method for detecting the use of anti-forensics. We introduce a new set of techniques for evaluating the performance of anti-forensic operations and develop a game theoretic framework for analyzing the interplay between a forensic investigator and a forger. We use these new techniques to evaluate the performance of each of our proposed forensic and anti-forensic techniques, and identify the optimal actions of both the forger and forensic investigator.
Matthew C. Stamm, Wan-Yi Sabrina Lin, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.1
2011 Anti-forensics for frame deletion/addition in MPEG video
abstract
Due to the ease with which digital information can be altered, many digital forensic techniques have recently been developed to authenticate multimedia content. One important digital forensic result is that adding or deleting frames from an MPEG video sequence introduces a temporally distributed fingerprint into the video can be used to identify frame deletion or addition. By contrast, very little research exists into anti-forensic operations designed to make digital forgeries undetectable by forensic techniques. In this paper, we propose an anti-forensic technique capable of removing the temporal fingerprint from MPEG videos that have undergone frame addition or deletion. We demonstrate that our proposed anti-forensic technique can effectively remove this fingerprint through a series of experiments.
Matthew C. Stamm, K. J. Ray Liu
ICASSP1
2011 Anti-Forensics of Digital Image Compression
abstract
As society has become increasingly reliant upon digital images to communicate visual information, a number of forensic techniques have been developed to verify the authenticity of digital images. Amongst the most successful of these are techniques that make use of an image's compression history and its associated compression fingerprints. Little consideration has been given, however, to anti-forensic techniques capable of fooling forensic algorithms. In this paper, we present a set of anti-forensic techniques designed to remove forensically significant indicators of compression from an image. We do this by first developing a generalized framework for the design of anti-forensic techniques to remove compression fingerprints from an image's transform coefficients. This framework operates by estimating the distribution of an image's transform coefficients before compression, then adding anti-forensic dither to the transform coefficients of a compressed image so that their distribution matches the estimated one. We then use this framework to develop anti-forensic techniques specifically targeted at erasing compression fingerprints left by both JPEG and wavelet-based coders. Additionally, we propose a technique to remove statistical traces of the blocking artifacts left by image compression algorithms that divide an image into segments during processing. Through a series of experiments, we demonstrate that our anti-forensic techniques are capable of removing forensically detectable traces of image compression without significantly impacting an image's visual quality. Furthermore, we show how these techniques can be used to render several forms of image tampering such as double JPEG compression, cut-and-paste image forgery, and image origin falsification undetectable through compression-history-based forensic means.
Matthew C. Stamm, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.1
2010 Forensic estimation and reconstruction of a contrast enhancement mapping
abstract
Due to the ease with which convincing digital image forgeries can be created, a need has arisen for digital forensic techniques capable of detecting image manipulation. Once image alterations have been identified, the next logical forensic task is to recover as much information as possible about the unaltered version of image and the operation used to modify it. Previous work has dealt with the forensic detection of contrast enhancement in digital images. In this paper we propose an iterative algorithm to jointly estimate any arbitrary contrast enhancement mapping used to modify an image as well as the pixel value histogram of the image before contrast enhancement. To do this, we use a probabilistic model of an image's pixel value histogram to determine which histogram entries are most likely to correspond to contrast enhancement artifacts. Experimental results are presented to demonstrate the effectiveness of our proposed method.
Matthew C. Stamm, K. J. Ray Liu
ICASSP1
2010 Anti-forensics of JPEG compression
abstract
The widespread availability of photo editing software has made it easy to create visually convincing digital image forgeries. To address this problem, there has been much recent work in the field of digital image forensics. There has been little work, however, in the field of anti-forensics, which seeks to develop a set of techniques designed to fool current forensic methodologies. In this work, we present a technique for disguising an image's JPEG compression history. An image's JPEG compression history can be used to provide evidence of image manipulation, supply information about the camera used to generate an image, and identify forged regions within an image. We show how the proper addition of noise to an image's discrete cosine transform coefficients can sufficiently remove quantization artifacts which act as indicators of JPEG compression while introducing an acceptable level of distortion. Simulation results are provided to verify the efficacy of this anti-forensic technique.
Matthew C. Stamm, Steven K. Tjoa, Wan-Yi Sabrina Lin, K. J. Ray Liu
ICASSP1
2010 Harmonic variable-size dictionary learning for music source separation
abstract
Dictionary learning through matrix factorization has become widely popular for performing music transcription and source separation. These methods learn a concise set of dictionary atoms which represent spectrograms of musical objects. However, there is no guarantee that the atoms learned will be perceptually meaningful, particularly when there exists significant spectral and temporal overlap among the musical sources. In this paper, we propose a novel dictionary learning method that imposes additional harmonic constraints upon the atoms of the learned dictionary while allowing the dictionary size to grow appropriately during the learning procedure. When there is significant spectral-temporal overlap among the musical sources, our method outperforms popular existing matrix factorization methods as measured by the recall and precision of learned dictionary atoms.
Steven K. Tjoa, Matthew C. Stamm, Wan-Yi Sabrina Lin, K. J. Ray Liu
ICASSP2
2010 Wavelet-based image compression anti-forensics
abstract
Because digital images can be modified with relative ease, considerable effort has been spent developing image forensic algorithms capable of tracing an image's processing history. In contrast to this, relatively little consideration has been given to anti-forensic operations designed to mislead forensic techniques. In this paper, we propose an anti-forensic technique capable of removing artifacts indicative of wavelet-based image compression from an image. Our technique operates by adding anti-forensic dither to a previously compressed image's wavelet coefficients so that the anti-forensically modified wavelet coefficient distribution matches a model of the coefficient distribution before compression. Simulation results show that our algorithm is capable of fooling current forensic image compression detection algorithms 100% of the time.
Matthew C. Stamm, K. J. Ray Liu
ICIP1
2010 Undetectable image tampering through JPEG compression anti-forensics
abstract
Recently, a number of digital image forensic techniques have been developed which are capable of identifying an image's origin, tracing its processing history, and detecting image forgeries. Though these techniques are capable of identifying standard image manipulations, they do not address the possibility that anti-forensic operations may be designed and used to hide evidence of image tampering. In this paper, we propose an anti-forensic operation capable of removing blocking artifacts from a previously JPEG compressed image. Furthermore, we show that by using this operation along with another anti-forensic operation which we recently proposed, we are able to fool forensic methods designed to detect evidence of JPEG compression in decoded images, determine an image's origin, detect double JPEG compression, and identify cut-and-paste image forgeries.
Matthew C. Stamm, Steven K. Tjoa, Wan-Yi Sabrina Lin, K. J. Ray Liu
ICIP1
2010 Forensic detection of image manipulation using statistical intrinsic fingerprints
abstract
As the use of digital images has increased, so has the means and the incentive to create digital image forgeries. Accordingly, there is a great need for digital image forensic techniques capable of detecting image alterations and forged images. A number of image processing operations, such as histogram equalization or gamma correction, are equivalent to pixel value mappings. In this paper, we show that pixel value mappings leave behind statistical traces, which we shall refer to as a mapping's intrinsic fingerprint, in an image's pixel value histogram. We then propose forensic methods for detecting general forms globally and locally applied contrast enhancement as well as a method for identifying the use of histogram equalization by searching for the identifying features of each operation's intrinsic fingerprint. Additionally, we propose a method to detect the global addition of noise to a previously JPEG-compressed image by observing that the intrinsic fingerprint of a specific mapping will be altered if it is applied to an image's pixel values after the addition of noise. Through a number of simulations, we test the efficacy of each proposed forensic technique. Our simulation results show that aside from exceptional cases, all of our detection methods are able to correctly detect the use of their designated image processing operation with a probability of 99% given a false alarm probability of 7% or less.
Matthew C. Stamm, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.1
2008 Blind forensics of contrast enhancement in digital images
abstract
Digital images have seen increased use in applications where their authenticity is of prime importance. This proves to be problematic due to the widespread availability of digital image editing software. As a result, there is a need for the development of reliable techniques for verifying an image's authenticity. In this paper, a blind forensic algorithm is proposed for detecting the use of global contrast enhancement operations to modify digital images. Furthermore, a separate algorithm is proposed to identify the use of histogram equalization, a commonly implemented contrast enhancement operation. Both algorithms perform detection by seeking out unique artifacts introduced into an image's histogram as a result of the particular operation examined. Additionally, results are presented showing the effectiveness of both proposed algorithms.
Matthew C. Stamm, K. J. Ray Liu
ICIP1