VLDB 2026 Research / reviewers in the wild / expert
Jessica J. Fridrich
dblp:f/JessicaJFridrich
· DBLP profile ↗
72ranked-venue papers
10as first author
14since 2021 · last 2025
0009-0003-6516-628XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 54 · 6 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 17 · 3 first-author · 2 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Secure Payload Scaling in Detector-Informed Batch Steganography: The Mismatched Detectors CaseabstractThis paper deals with the problem of batch steganography and pooled steganalysis when the sender uses a steganography detector to spread chunks of the payload across a bag of cover images while the Warden uses a possibly different detector for her pooled steganalysis.We investigate how much information can be communicated with increasing bag size 𝑛 at a fixed statistical detectability of Warden's detector.Specifically, we are interested in the scaling exponent 𝛾 of the secure payload 𝑃 (𝑛) = 𝑐𝑛 𝛾 .We approach this problem both theoretically from a statistical model of the soft output of a detector and practically using experiments on real datasets when giving both actors different detectors implemented as convolutional neural networks and a classifier with a rich model.While the effect of the detector mismatch depends on the payload allocation algorithm and the type of mismatch, in general the mismatch decreases the constant of proportionality 𝑐 as well as the exponent 𝛾.This stays true independently of who has the superior detector.Many trends observed in experiments qualitatively match the theoretical predictions derived within our model.Finally, we summarize our most important findings as lessons for the sender and for the Warden. Eli Dworetzky, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2025 | Effect of Acquisition Noise Outliers on SteganalysisabstractUnderstanding the mechanisms that lead to false alarms (erroneously detecting cover images as containing secrets) in steganalysis is a topic of utmost importance for practical applications.In this paper, we present evidence that a relatively small number of pixel outliers introduced by the image acquisition process can skew the soft output of a data driven detector to produce a strong false alarm.To verify this hypothesis, for a cover image we estimate a statistical model of the acquisition noise in the developed domain and identify pixels that contribute the most to the associated likelihood ratio test (LRT) for steganography.We call such cover elements LIEs (Locally Influential Elements).The effect of LIEs on the output of a data-driven detector is demonstrated by turning a strong false alarm into a correctly classified cover by introducing a relatively small number of "de-embedding" changes at LIEs.Similarly, we show that it is possible to introduce a small number of LIEs into a strong cover to make a data driven detector classify it as stego.Our findings are supported by experiments on two datasets with three steganographic algorithms and four types of data driven detectors. Edgar Kaziakhmedov, Jessica J. Fridrich, Patrick Bas |
IH&MMSec | 2 |
| 2024 | Improving Steganographic Security with Source BiasingabstractBy selecting covers in which steganographic embedding is harder to detect, the steganographer can decrease the chances of being caught by the Warden. On the other hand, sampling from the cover source with a bias is detectable on its own. In this paper, we study this trade-off theoretically within a simple source model. Our analysis predicts the existence of "bias security gain" when the sender selects the sampling bias optimally. Sampling with a bias initially morphs the ROC of Warden's detector to be asymmetrical, lowering the true positive rate for small false alarm rates. We provide a theorem, analogous to the square root law, for the joint critical rates of sampling bias and payload that achieve asymptotically constant detectability. Our analysis is verified experimentally. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2023 | On Comparing Ad Hoc Detectors with Statistical Hypothesis TestsabstractThis paper addresses how to fairly compare ROCs of ad hoc (or data driven) detectors with tests derived from statistical models of digital media. We argue that the ways ROCs are typically drawn for each detector type correspond to different hypothesis testing problems with different optimality criteria, making the ROCs uncomparable. To understand the problem and why it occurs, we model a source of natural images as a mixture of scene oracles and derive optimal detectors for the task of image steganalysis. Our goal is to guarantee that, when the data follows the statistical model adopted for the hypothesis test, the ROC of the optimal detector bounds the ROC of the ad hoc detector. While the results are applicable beyond the field of image steganalysis, we use this setup to point out possible inconsistencies when comparing both types of detectors and explain guidelines for their proper comparison. Experiments on an artificial cover source with a known model with real steganographic algorithms and deep learning detectors are used to confirm our claims. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2023 | Advancing the JPEG Compatibility Attack: Theory, Performance, Robustness, and PracticeabstractThe JPEG compatibility attack is a steganalysis method for detecting messages embedded in the spatial representation of an image under the assumption that the cover image was a decompressed JPEG. This paper addresses a number of open problems in previous art, namely the lack of theoretical insight into how and why the attack works, low detection accuracy for high JPEG qualities, robustness to the JPEG compressor and DCT coefficient quantizer, and real-life performance evaluation. To explain the main mechanism responsible for detection and to understand the trends exhibited by heuristic detectors, we adopt a model of quantization errors of DCT coefficients in the recompressed image, and within a simplified setup, we analyze the behavior of the most powerful detector. Empowered by our analysis, we resolve the performance deficiencies using an SRNet trained on a two-channel input consisting of the image and its SQ error. This detector is compared with previous state of the art on four content-adaptive stego methods and for a wide range of payloads and quality factors. The last sections of this paper are devoted to studying robustness of this detector with respect to JPEG compressors, quantizers, and errors in estimating the JPEG quantization table. Finally, to demonstrate practical usability of this attack, we test our detector on stego images outputted by real steganographic tools available on the Internet. Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2023 | Limits of Data Driven Steganography DetectorsabstractWhile deep learning has revolutionized image steganalysis in terms of performance, little is known about how much modern data driven detectors can still be improved. In this paper, we approach this difficult and currently wide open question by working with artificial but realistic looking images with a known statistical model that allows us to compute the detectability of modern content-adaptive algorithms with respect to the most powerful detectors. Multiple artificial image datasets are crafted with different levels of content complexity and noise power to assess their influence on the gap between both types of detectors. Experiments with SRNet as the heuristic detector indicate that independent noise contributes less to the performance gap than content of the same MSE. While this loss is rather small for smooth images, it can be quite large for textured images. A network trained on many realizations of a fixed textured scene will, however, recuperate most of the loss, suggesting that networks have the capacity to approximately learn the parameters of a cover source narrowed to a fixed scene. Edgar Kaziakhmedov, Eli Dworetzky, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2023 | Explaining the Bag Gain in Batch SteganographyabstractIn batch steganography, the sender distributes the secret payload among multiple images from a “bag” to decrease the chance of being caught. Recent work on this topic described an experimentally discovered phenomenon, which we call the “bag gain”: for fixed communication rate, pooled detectors experience a decrease in statistical detectability for initially increasing bag sizes, providing an opportunity for the sender to gain in security. The bag gain phenomenon is universal in the sense of manifesting under a wide spectrum of conditions. In this paper, we explain this experimental observation by adopting a statistical model of detector response. Despite the simplicity of the model, it does capture observed trends in detectability as a function of the bag size, the rate, and cover source properties. Additionally, and surprisingly, the model predicts that in certain cover sources the sender should avoid bag sizes that are too small as this can lead to a bag loss. Eli Dworetzky, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Detector-Informed Batch Steganography and Pooled SteganalysisabstractWe study the problem of batch steganography when the senders use feedback from a steganography detector. This brings an additional level of complexity to the table due to the highly non-linear and non-Gaussian response of modern steganalysis detectors as well as the necessity to study the impact of the inevitable mismatch between senders' and Warden's detectors. Two payload spreaders are considered based on the oracle generating possible cover images. Three different pooling strategies are devised and studied for a more comprehensive assessment of security. Substantial security gains are observed with respect to previous art - the detector-agnostic image-merging sender. Close attention is paid to the impact of the information available to the Warden on security. Yassine Yousfi, Eli Dworetzky, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2021 | Extending the Reverse JPEG Compatibility Attack to Double Compressed ImagesabstractThe reverse JPEG compatibility attack has recently been introduced as a very accurate and universal steganalysis algorithm for JPEG images with quality 99 or 100. The limitation to these two largest qualities appears fundamental as the prior work on this topic suggests. In this paper, we provide mathematical analysis and demonstrate experimentally that this attack can be extended to double compressed images when the first compression quality is 93 or larger and the second quality equal or larger than the first quality. Comparisons with state-of-the-art deep convolutional neural networks as well as detectors built in the JPEG domain show the merit of this work. Jan Butora, Jessica J. Fridrich |
ICASSP | 2 |
| 2021 | Revisiting Perturbed QuantizationabstractIn this work, we revisit Perturbed Quantization steganography with modern tools available to the steganographer today, including near-optimal ternary coding and content-adaptive embedding with side-information. In PQ, side-information in the form of rounding errors is manufactured by recompressing a JPEG image with a judiciously selected quality factor. This side-information, however, cannot be used in the same fashion as in conventional side-informed schemes nowadays as this leads to highly detectable embedding. As a remedy, we utilize the steganographic Fisher information to allocate the payload among DCT modes. In particular, we show that the embedding should not be constrained to contributing coefficients only as in the original PQ but should be expanded to the so-called "contributing DCT modes." This approach is extended to color images by slightly modifying the SI-UNIWARD algorithm. Using the best detectors currently available, it is shown that by manufacturing side information with double compression, one can embed the same amount of information into the doubly-compressed cover image with a significantly better security than applying J-UNIWARD directly in the single-compressed image. At the end of the paper, we show that double compression with the same quality makes side-informed steganography extremely detectable and should be avoided. Jan Butora, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2021 | How to Pretrain for SteganalysisabstractIn this paper, we investigate the effect of pretraining CNNs on ImageNet on their performance when refined for steganalysis of digital images. In many cases, it seems that just 'seeing' a large number of images helps with the convergence of the network during the refinement no matter what the pretraining task is. To achieve the best performance, the pretraining task should be related to steganalysis, even if it is done on a completely mismatched cover and stego datasets. Furthermore, the pretraining does not need to be carried out for very long and can be done with limited computational resources. An additional advantage of the pretraining is that it is done on color images and can later be applied for steganalysis of color and grayscale images while still having on-par or better performance than detectors trained specifically for a given source. The refining process is also much faster than training the network from scratch. The most surprising part of the paper is that networks pretrained on JPEG images are a good starting point for spatial domain steganalysis as well. Jan Butora, Yassine Yousfi, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2021 | Improving EfficientNet for JPEG SteganalysisabstractIn this paper, we study the EfficientNet family pre-trained on ImageNet when used for steganalysis using transfer learning. We show that certain "surgical modifications" aimed at maintaining the input resolution in EfficientNet architectures significantly boost their performance in JPEG steganalysis, establishing thus new benchmarks. The modified models are evaluated by their detection accuracy, the number of parameters, the memory consumption, and the total floating point operations (FLOPs) on the ALASKA II dataset. We also show that, surprisingly, EfficientNets in their "vanilla form" do not perform as well as the SRNet in BOSSbase+BOWS2. This is because, unlike ALASKA II images, BOSSbase+BOWS2 contains aggressively subsampled images with more complex content. The surgical modifications in EfficientNet remedy this underperformance as well. Yassine Yousfi, Jan Butora, Jessica J. Fridrich, Clement Fuji Tsang |
IH&MMSec | 3 |
| 2021 | Image Steganography With Symmetric Embedding Using Gaussian Markov Random Field ModelabstractRecent advances on adaptive steganography show that the performance of image steganographic communication can be improved by incorporating the non-additive models that capture the dependencies among adjacent pixels. In this paper, a Gaussian Markov Random Field model (GMRF) with four-element cross neighborhood is proposed to characterize the interactions among local elements of cover images, and the problem of secure image steganography is formulated as the one of minimization of KL-divergence in terms of a series of low-dimensional clique structures associated with GMRF by taking advantages of the conditional independence of GMRF. The adoption of the proposed GMRF tessellates the cover image into two disjoint subimages, and an alternating iterative optimization scheme is developed to effectively embed the given payload while minimizing the total KL-divergence between cover and stego, i.e., the statistical detectability. Experimental results demonstrate that the proposed GMRF outperforms the prior arts of model based schemes, e.g., MiPOD, and rivals the state-of-the-art HiLL for practical steganography, where the selection channel knowledges are unavailable to steganalyzers. Wenkang Su 0001, Jiangqun Ni, Xianglei Hu, Jessica J. Fridrich |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2021 | Natural Steganography in JPEG Domain With a Linear Development PipelineabstractIn order to achieve high practical security, Natural Steganography (NS) uses cover images captured at ISO sensitivity ISO1and generates stego images mimicking ISO sensitivity ISO2> ISO1. This is achieved by adding a stego signal to the cover that mimics the sensor photonic noise. This paper proposes an embedding mechanism to perform NS in the JPEG domain after linear developments by explicitly computing the correlations between DCT coefficients before quantization. In order to compute the covariance matrix of the photonic noise in the DCT domain, we first develop the matrix representation of demosaicking, luminance averaging, pixel section, and 2D-DCT. A detailed analysis of the resulting covariance matrix is done in order to explain the origins of the correlations between the coefficients of 3 × 3 DCT blocks. An embedding scheme is then presented that takes into account all the correlations. It employs 4 sub-lattices and 64 lattices per sub-lattices. The modification probabilities of each DCT coefficient are then derived by computing conditional probabilities computed from a multivariate Gaussian distribution using the Cholesky decomposition of the covariance matrix. This derivation is also used to compute the embedding capacity of each image. Using a specific database called E1Base, we show that in the JPEG domain NS (J-Cov-NS) enables to achieve high capacity (more than 2 bits per non-zero AC DCT) and with high practical security (PE 40% using DCTR and PE 32% using SRNet) from QF 75 to QF 100). Théo Taburet, Patrick Bas, Wadih Sawaya, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Steganography and its Detection in JPEG Images Obtained with the "TRUNC" QuantizerabstractMany portable imaging devices use the operation of "trunc" (rounding towards zero) instead of rounding as the final quantizer for computing DCT coefficients during JPEG compression. We show that this has rather profound consequences for steganography and its detection. In particular, side-informed steganography needs to be redesigned due to the different nature of the rounding error. The steganographic algorithm J-UNIWARD becomes vulnerable to steganalysis with the JPEG rich model and needs to be adjusted for this source. Steganalysis detectors need to be retrained since a steganalyst unaware of the existence of the trunc quantizer will experience 100% false alarm. Jan Butora, Jessica J. Fridrich |
ICASSP | 2 |
| 2020 | Turning Cost-Based Steganography into Model-BasedabstractAbstract Most modern steganographic schemes embed secrets by minimizing the total expected cost of modifications. However, costs are usually computed using heuristics and cannot be directly linked to statistical detectability. Moreover, as previously shown by Ker at al., cost-based schemes fundamentally minimize the wrong quantity that makes them more vulnerable to knowledgeable adversary aware of the embedding change rates. In this paper, we research the possibility to convert cost-based schemes to model-based ones by postulating that there exists payload size for which the change rates derived from costs coincide with change rates derived from some (not necessarily known) model. This allows us to find the steganographic Fisher information for each pixel (DCT coefficient), and embed other payload sizes by minimizing deflection. This rather simple measure indeed brings sometimes quite significant improvements in security especially with respect to steganalysis aware of the selection channel. Steganographic algorithms in both spatial and JPEG domains are studied with feature-based classifiers as well as CNNs. Jan Butora, Yassine Yousfi, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2020 | An Intriguing Struggle of CNNs in JPEG Steganalysis and the OneHot SolutionabstractDeep convolutional neural networks (CNNs) have become the tool of choice for steganalysis because they outperform older feature-based detectors by a large margin. However, recent work points at cases where feature-based detectors perform better than CNNs due to their failure to compute simple statistics of DCT coefficients. We introduce a shallow “OneHot” CNN, which encodes DCT coefficients using clipped one-hot encoding into a binary volumetric representation of the DCT plane fed to a convolutional block designed to learn relevant intra-block and inter-block relationships using vanilla and dilated convolutions. Methodology for plugging the “OneHot” network into conventional steganalysis CNNs is also introduced for an end-to-end learnable detector with improved performance. Yassine Yousfi, Jessica J. Fridrich |
IEEE Signal Process. Lett. | 2 |
| 2020 | Reverse JPEG Compatibility AttackabstractA novel steganalysis method for JPEG images is introduced that is universal in the sense that it reliably detects any type of steganography as well as small payloads. It is limited to quality factors 99 and 100. The detection statistic is formed from the rounding errors in the spatial domain after decompressing the JPEG image. The attack works whenever, during compression, the discrete cosine transform is applied to integer-valued signal. Reminiscent of the well-established JPEG compatibility steganalysis, we call the new approach the “reverse JPEG compatibility attack.” While the attack is introduced and analyzed under simplifying assumptions using reasoning based on statistical signal detection, the best detection in practice is obtained with machine learning tools. Experiments on diverse datasets of both grayscale and color images, five steganographic schemes, and with a variety of JPEG compressors demonstrate the universality and applicability of this steganalysis method in practice. Jan Butora, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Effect of JPEG Quality on Steganographic SecurityabstractAbstract This work investigates both theoretically and experimentally the security of JPEG steganography as a function of the quality factor. For a fixed relative payload, modern embedding schemes, such as J-UNIWARD and UED-JC, exhibit surprising non-monotone trends due to rounding and clipping of quantization steps. Their security generally increases with increasing quality factor but starts decreasing for qualities above 95. In contrast, old-fashion steganography, such as Jsteg, OutGuess, and model-based steganography, exhibit complementary trends. The results of empirical detectors closely match the trends exhibited by the KL divergence computed between models of cover and stego DCT modes. In particular, our analysis shows that the main reason for the complementary trends is the way modern schemes attenuate embedding change rates with increasing spatial frequency. Our model also provides guidance on how to adjust the embedding algorithm J-UNIWARD to substantially improve its security for high quality factors. Jan Butora, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2019 | Reference Channels for Steganalysis of Images with Convolutional Neural NetworksabstractWhen available, reference signals may dramatically improve the accuracy of steganalysis. Particularly powerful reference signals are embedding invariants that exist when the steganographic algorithm swaps values from small disjoint subsets of the cover elements' dynamic range, such as, but not limited to, embedding schemes utilizing least significant bit replacement. This paper describes a general method how to prepare such reference signals for a certain type of embedding operations, and incorporate them in detectors built as convolutional networks to improve their detection accuracy. The beneficial effect of reference signals is shown experimentally in both the spatial and especially JPEG domain, on model-based steganography and a generic LSB flipper with and without stochastic restoration of the histogram (OutGuess). Mo Chen 0005, Mehdi Boroumand, Jessica J. Fridrich |
IH&MMSec | 3 |
| 2019 | Computing Dependencies between DCT Coefficients for Natural Steganography in JPEG DomainabstractThis short paper is an extension of a family of embedding schemes called Natural Steganography, which embeds a message by mimicking heteroscedastic sensor noise in the JPEG domain. Under the assumption that the development from RAW uses linear de- mosaicking, we derive a closed-form for the covariance matrix of DCT coefficients from 3 × 3 JPEG blocks. This computation relies on a matrix formulation of all steps involved in the development pipeline, which includes demosaicking, conversion to luminance, DCT transform, and reordering. This matrix is then used for pseudo-embedding in the JPEG domain on four lattices of 8 × 8 DCT blocks. The results obtained with the computed covariance matrix are contrasted with the results previously obtained with the covariance matrix estimated using Monte Carlo sampling and scaling. The empirical security using DCTR features at JPEG quality 100 increased from PE = 14% using covariance estimation and scaling to PE = 43% using the newly derived analytic form. Théo Taburet, Patrick Bas, Jessica J. Fridrich, Wadih Sawaya |
IH&MMSec | 3 |
| 2019 | Breaking ALASKA: Color Separation for Steganalysis in JPEG DomainabstractThis paper describes the architecture and training of detectors developed for the ALASKA steganalysis challenge. For each quality factor in the range 60-98, several multi-class tile detectors implemented as SRNets were trained on various combinations of three input channels: luminance and two chrominance channels. To accept images of arbitrary size, the detector for each quality factor was a multi-class multi-layered perceptron trained on features extracted by the tile detectors. For quality 99 and 100, a new "reverse JPEG compatibility attack" was developed and also implemented using the SRNet via the tile detector. Throughout the paper, we explain various improvements we discovered during the course of the competition and discuss the challenges we encountered and trade offs that had to be adopted in order to build a detector capable of detecting steganographic content in a stego source of great diversity. Yassine Yousfi, Jan Butora, Jessica J. Fridrich, Eva Giboulot |
IH&MMSec | 3 |
| 2019 | Payload Scaling for Adaptive Steganography: An Empirical StudyabstractPayload-scaling laws of imperfect steganography inform the steganographer about how the size of secret payload should grow with cover size for constant statistical detectability. In this letter, we carry out an empirical study for the case when the steganographer and the steganalyst operate at a game-theoretic equilibrium. We first explore the possibility to leverage a generalization of the square root law to content-adaptive steganography due to Ker. Since this result does not appear to be tight enough for realistic cover sizes, we instead work with a detectability limited sender in image sources with a forced model as well as real images in both spatial and JPEG domain. The scaling is observed in practice when the images are carefully cropped to preserve the distribution of costs across scales. Eva Giboulot, Jessica J. Fridrich |
IEEE Signal Process. Lett. | 2 |
| 2019 | Deep Residual Network for Steganalysis of Digital ImagesabstractSteganography detectors built as deep convolutional neural networks have firmly established themselves as superior to the previous detection paradigm - classifiers based on rich media models. Existing network architectures, however, still contain elements designed by hand, such as fixed or constrained convolutional kernels, heuristic initialization of kernels, the thresholded linear unit that mimics truncation in rich models, quantization of feature maps, and awareness of JPEG phase. In this work, we describe a deep residual architecture designed to minimize the use of heuristics and externally enforced elements that is universal in the sense that it provides state-of-the-art detection accuracy for both spatial-domain and JPEG steganography. The key part of the proposed architecture is a significantly expanded front part of the detector that “computes noise residuals” in which pooling has been disabled to prevent suppression of the stego signal. Extensive experiments show the superior performance of this network with a significant improvement, especially in the JPEG domain. Further performance boost is observed by supplying the selection channel as a second channel. Mehdi Boroumand, Mo Chen 0005, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Applications of Explicit Non-Linear Feature Maps in SteganalysisabstractCurrently, the most popular detectors of content-adaptive image steganography are built using machine learning with images represented with rich features. Such high-dimensional descriptors, however, prevent utilization of more complex and potentially more accurate machine learning paradigms, such as kernelized support vector machines, due to infeasibly expensive training. In this paper, we demonstrate that explicit non-linear feature maps coupled with simple classifiers improve the accuracy of current steganalysis detectors built as binary classifiers as well as quantitative detectors in the form of payload regressors. The non-linear map is obtained by approximating a symmetric positive semi-definite kernel on selected pairs of cover features. Exponential forms of kernels derived from symmetrized Ali-Silvey distances improve the detection accuracy of binary detectors and lower the error of quantitative detectors across all tested steganographic schemes on grayscale and color images. The learned non-linear map only weakly depends on the cover source and its learning has a low computational complexity. The technique can also be used for unsupervised feature dimensionality reduction. For payload regressors, the dimensionality can be significantly reduced while simultaneously decreasing the estimation error. Mehdi Boroumand, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Practical strategies for content-adaptive batch steganography and pooled steganalysisabstractThis paper investigates practical strategies for distributing payload across images with content-adaptive steganography and for pooling outputs of a single-image detector for steganalysis. Adopting a statistical model for the detector's output, the steganographer minimizes the power of the most powerful detector of an omniscient Warden, while the Warden, informed by the payload spreading strategy, detects with the likelihood ratio test in the form of a matched filter. Experimental results with state-of-the-art content-adaptive additive embedding schemes and rich models are included to show the relevance of the results. Rémi Cogranne, Vahid Sedighi, Jessica J. Fridrich |
ICASSP | 3 |
| 2017 | Steganography with two JPEGs of the same sceneabstractIt is widely recognized that incorporating side-information at the sender can significantly improve steganographic security in practice. Currently, most side-informed schemes for digital images utilize a high quality “precover” image that is subsequently processed and then jointly quantized and embedded with a secret. In this paper, we investigate an alternative form of side-information in the form of two JPEG images of the same scene. The second JPEG image is used to determine the preferred polarity of embedding changes and to modulate their costs. Tests on real imagery show a very significant improvement in empirical security with respect to steganography utilizing a single JPEG image. Tomás Denemark, Jessica J. Fridrich |
ICASSP | 2 |
| 2017 | Nonlinear Feature Normalization in SteganalysisabstractIn this paper, we propose a method for normalization of rich feature sets to improve detection accuracy of simple classifiers in steganalysis. It consists of two steps: 1) replacing random subsets of empirical joint probability mass functions (co-occurrences) by their conditional probabilities and 2) applying a non-linear normalization to each element of the feature vector by forcing its marginal distribution over covers to be uniform. We call the first step random conditioning and the second step feature uniformization. When applied to maxSRMd2 features in combination with simple classifiers, we observe a gain in detection accuracy across all tested stego algorithms and payloads. For better insight, we investigate the gain for two image formats. The proposed normalization has a very low computational complexity and does not require any feedback from the stego class. Mehdi Boroumand, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2017 | JPEG-Phase-Aware Convolutional Neural Network for Steganalysis of JPEG ImagesabstractDetection of modern JPEG steganographic algorithms has traditionally relied on features aware of the JPEG phase. In this paper, we port JPEG-phase awareness into the architecture of a convolutional neural network to boost the detection accuracy of such detectors. Another innovative concept introduced into the detector is the "catalyst kernel" that, together with traditional high-pass filters used to pre-process images allows the network to learn kernels more relevant for detection of stego signal introduced by JPEG steganography. Experiments with J-UNIWARD and UED-JC embedding algorithms are used to demonstrate the merit of the proposed design. Mo Chen 0005, Vahid Sedighi, Mehdi Boroumand, Jessica J. Fridrich |
IH&MMSec | 4 |
| 2017 | Steganography With Multiple JPEG Images of the Same SceneabstractIt is widely recognized that incorporating side-information at the sender can significantly improve steganographic security in practice. Currently, most side-informed schemes utilize a high-quality “precover” image that is subsequently processed and then jointly quantized and embedded with a secret. In this paper, we investigate an alternative form of side-information-a set of multiple JPEG images of the same scene-for applications when the sender does not have access to a precover. The additional JPEG images are used to determine the preferred polarity of embedding changes to modulate the costs of changing individual DCT coefficients in an existing embedding scheme. Tests on real images with synthesized acquisition noise and on real multiple acquisitions obtained with a tripod-mounted and hand-held digital camera show a rather significant improvement in empirical security with respect to steganography utilizing a single JPEG image. The proposed empirically determined modulation of embedding costs is justified using Monte-Carlo simulations by showing that qualitatively the same modulation minimizes the Bhattacharyya distance between a quantized generalized Gaussian model of cover and stego DCT coefficients corrupted by AWG acquisition noise. Tomás Denemark, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Effect of saturated pixels on security of steganographic schemes for digital imagesabstractWhen hiding messages in digital images, care needs to be exercised how the embedding changes are executed in or near saturated pixels. In this paper, we consider three different rules that are currently being used that adjust the embedding in saturated pixels and assess their impact on empirical steganographic security of four modern embedding algorithms. Surprisingly, the rules can have a major effect, especially in image sources with stronger noise. We show that the preferred way to treat saturated patches during message hiding is to adjust the pixel costs to entirely avoid making embedding changes in saturated pixels despite the ensuing loss of embedding capacity. This paper hopes to raise the awareness of the importance of treatment of saturated pixels in steganography to avoid introducing easily correctable flaws that may negatively affect security. Vahid Sedighi, Jessica J. Fridrich |
ICIP | 2 |
| 2016 | Boosting Steganalysis with Explicit Feature MapsabstractExplicit non-linear transformations of existing steganalysis features are shown to boost their ability to detect steganography in combination with existing simple classifiers, such as the FLD-ensemble. The non-linear transformations are learned from a small number of cover features using Nyström approximation on pilot vectors obtained with kernelized PCA. The best performance is achieved with the exponential form of the Hellinger kernel, which improves the detection accuracy by up to 2-3% for spatial-domain contentadaptive steganography. Since the non-linear map depends only on the cover source and its learning has a low computational complexity, the proposed approach is a practical and low cost method for boosting the accuracy of existing detectors built as binary classifiers. The map can also be used to significantly reduce the feature dimensionality (by up to factor of ten) without performance loss with respect to the non-transformed features. Mehdi Boroumand, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2016 | Steganalysis Features for Content-Adaptive JPEG SteganographyabstractAll the modern steganographic algorithms for digital images are content adaptive in the sense that they restrict the embedding modifications to complex regions of the cover, which are difficult to model for the steganalyst. The probabilities with which the individual cover elements are modified (the selection channel) are jointly determined by the size of the embedded payload and the content complexity. The most accurate detection of content-adaptive steganography is currently achieved with the detectors built as classifiers trained on cover and stego features that incorporate the knowledge of the selection channel. While the selection-channel-aware features have been proposed for detection of spatial domain steganography, an equivalent for the JPEG domain does not exist. Since modern steganographic algorithms for JPEG images are currently best detected with the features formed by the histograms of the noise residuals split by their JPEG phase, we use such feature sets as a starting point in this paper and extend their design to incorporate the knowledge of the selection channel. This is achieved by accumulating in the histograms a quantity that bounds the expected absolute distortion of the residual. The proposed features can be efficiently computed and provide a substantial detection gain across all the tested algorithms especially for small payloads. Tomás Denemark, Mehdi Boroumand, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Content-Adaptive Steganography by Minimizing Statistical DetectabilityabstractMost current steganographic schemes embed the secret payload by minimizing a heuristically defined distortion. Similarly, their security is evaluated empirically using classifiers equipped with rich image models. In this paper, we pursue an alternative approach based on a locally estimated multivariate Gaussian cover image model that is sufficiently simple to derive a closed-form expression for the power of the most powerful detector of content-adaptive least significant bit matching but, at the same time, complex enough to capture the non-stationary character of natural images. We show that when the cover model estimator is properly chosen, the state-of-the-art performance can be obtained. The closed-form expression for detectability within the chosen model is used to obtain new fundamental insight regarding the performance limits of empirical steganalysis detectors built as classifiers. In particular, we consider a novel detectability limited sender and estimate the secure payload of individual images. Vahid Sedighi, Rémi Cogranne, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Improving Steganographic Security by Synchronizing the Selection ChannelabstractThis paper describes a general method for increasing the security of additive steganographic schemes for digital images represented in the spatial domain. Additive embedding schemes first assign costs to individual pixels and then embed the desired payload by minimizing the sum of costs of all changed pixels. The proposed framework can be applied to any such scheme -- it starts with the cost assignment and forms a non-additive distortion function that forces adjacent embedding changes to synchronize. Since the distortion function is purposely designed as a sum of locally supported potentials, one can use the Gibbs construction to realize the embedding in practice. The beneficial impact of synchronizing the embedding changes is linked to the fact that modern steganalysis detectors use higher-order statistics of noise residuals obtained by filters with sign-changing kernels and to the fundamental difficulty of accurately estimating the selection channel of a non-additive embedding scheme implemented with several Gibbs sweeps. Both decrease the accuracy of detectors built using rich media models, including their selection-channel-aware versions. Tomás Denemark, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2015 | Effect of Imprecise Knowledge of the Selection Channel on SteganalysisabstractIt has recently been shown that steganalysis of content-adaptive steganography can be improved when the Warden incorporates in her detector the knowledge of the selection channel -- the probabilities with which the individual cover elements were modified during embedding. Such attacks implicitly assume that the Warden knows at least approximately the payload size. In this paper, we study the loss of detection accuracy when the Warden uses a selection channel that was imprecisely determined either due to lack of information or the stego changes themselves. The loss is investigated for two types of qualitatively different detectors -- binary classifiers equipped with selection-channel-aware rich models and optimal detectors derived using the theory of hypothesis testing from a cover model. Two different embedding paradigms are addressed -- steganography based on minimizing distortion and embedding that minimizes the detectability of an optimal detector within a chosen cover model. Remarkably, the experimental and theoretical evidence are qualitatively in agreement across different embedding methods, and both point out that inaccuracies in the selection channel do not have a strong effect on steganalysis detection errors. It pays off to use imprecise selection channel rather than none. Our findings validate the use of selection-channel-aware detectors in practice. Vahid Sedighi, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2015 | Modeling and Extending the Ensemble Classifier for Steganalysis of Digital Images Using Hypothesis Testing TheoryabstractThe machine learning paradigm currently predominantly used for steganalysis of digital images works on the principle of fusing the decisions of many weak base learners. In this paper, we employ a statistical model of such an ensemble and replace the majority voting rule with a likelihood ratio test. This allows us to train the ensemble to guarantee desired statistical properties, such as the false-alarm probability and the detection power, while preserving the high detection accuracy of original ensemble classifier. It also turns out the proposed test is linear. Moreover, by replacing the conventional total probability of error with an alternative criterion of optimality, the ensemble can be extended to detect messages of an unknown length to address composite hypotheses. Finally, the proposed well-founded statistical formulation allows us to extend the ensemble to multi-class classification with an appropriate criterion of optimality and an optimal associated decision rule. This is useful when a digital image is tested for the presence of secret data hidden by more than one steganographic method. Numerical results on real images show the sharpness of the theoretically established results and the relevance of the proposed methodology. Rémi Cogranne, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Low-Complexity Features for JPEG Steganalysis Using Undecimated DCTabstractThis paper introduces a novel feature set for steganalysis of JPEG images. The features are engineered as first-order statistics of quantized noise residuals obtained from the decompressed JPEG image using 64 kernels of the discrete cosine transform (DCT) (the so-called undecimated DCT). This approach can be interpreted as a projection model in the JPEG domain, forming thus a counterpart to the projection spatial rich model. The most appealing aspect of this proposed steganalysis feature set is its low computational complexity, lower dimensionality in comparison with other rich models, and a competitive performance with respect to previously proposed JPEG domain steganalysis features. Vojtech Holub, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Universal distortion function for steganography in an arbitrary domainabstractCurrently, the most successful approach to steganography in empirical objects, such as digital media, is to embed the payload while minimizing a suitably defined distortion function. The design of the distortion is essentially the only task left to the steganographer since efficient practical codes exist that embed near the payload-distortion bound. The practitioner’s goal is to design the distortion to obtain a scheme with a high empirical statistical detectability. In this paper, we propose a universal distortion design called universal wavelet relative distortion (UNIWARD) that can be applied for embedding in an arbitrary domain. The embedding distortion is computed as a sum of relative changes of coefficients in a directional filter bank decomposition of the cover image. The directionality forces the embedding changes to such parts of the cover object that are difficult to model in multiple directions, such as textures or noisy regions, while avoiding smooth regions or clean edges. We demonstrate experimentally using rich models as well as targeted attacks that steganographic methods built using UNIWARD match or outperform the current state of the art in the spatial domain, JPEG domain, and side-informed JPEG domain. Vojtech Holub, Jessica J. Fridrich, Tomás Denemark |
EURASIP J. Inf. Secur. | 2 |
| 2014 | Effect of Image Downsampling on Steganographic SecurityabstractThe accuracy of steganalysis in digital images primarily depends on the statistical properties of neighboring pixels, which are strongly affected by the image acquisition pipeline as well as any processing applied to the image. In this paper, we study how the detectability of embedding changes is affected when the cover image is downsampled prior to embedding. This topic is important for practitioners because the vast majority of images posted on websites, image sharing portals, or attached to e-mails are downsampled. It is also relevant to researchers as the security of steganographic algorithms is commonly evaluated on databases of downsampled images. In the first part of this paper, we investigate empirically how the steganalysis results depend on the parameters of the resizing algorithm-the choice of the interpolation kernel, the scaling factor (resize ratio), antialiasing, and the downsampled pixel grid alignment. We report on several novel phenomena that appear valid universally across the tested cover sources, steganographic methods, and steganalysis features. This paper continues with a theoretical analysis of the simplest interpolation kernel - the box kernel. By fitting a Markov chain model to pixel rows, we analytically compute the Fisher information rate for any mutually independent embedding operation and derive the proper scaling of the secure payload with resizing. For least significant bit (LSB) matching and a limited range of downscaling, the theory fits experiments rather well, which indicates the existence of a new scaling law expressing the length of the secure payload when the cover size is modified by subsampling. Jan Kodovský, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Multivariate gaussian model for designing additive distortion for steganographyabstractCurrently, the most successful approach to steganography in empirical objects, such as digital media, is to cast the embedding problem as source coding with a fidelity constraint. The sender specifies the costs of changing each cover element and then embeds a given payload by minimizing the total embedding cost. Since efficient practical codes exist that embed near the rate-distortion bound, the remaining task left to the steganographer is the fidelity measure - the choice of the costs. In the past, the costs were obtained either in an ad hoc manner or determined from the effects of embedding in a chosen feature space. In this paper, we adopt a different strategy in which the cover is modeled as a sequence of independent but not necessarily identically distributed quantized Gaussians and the embedding change probabilities are derived to minimize the total KL divergencewithin the chosen model for a given embedding operation and payload. Despite the simplicity of the adoptedmodel, the resulting stegosystem exhibits security that is comparable to current state-of-the-art methods methods across a wide range of payloads. Jessica J. Fridrich, Jan Kodovský |
ICASSP | 1 |
| 2013 | Steganalysis in resized imagesabstractIt is well known that the security of a given steganographic algorithm strongly depends on the statistical properties of the cover source. In this paper, we study how downsampling affects steganographic security. The secure payload no longer scales according to the square-root law because resizing changes the statistical properties of the cover source. We demonstrate this experimentally for various types of resizing algorithms and their settings and thoroughly interpret the results. Modeling digital images as Markov chains allows us to compute the Fisher information rate for the simplest resizing algorithm with the box kernel and derive the proper scaling of the secure payload with resizing. The theory fits experimental data, which indicates the existence of a new scaling law expressing the length of secure payload when the cover length is not modified by adding or removing pixels but, instead, by subsampling. Since both steganography and steganalysis is today commonly evaluated through controlled experiments on resized images (e.g., the BOSSbase), the effect of resizing on security is of utmost importance to practitioners. Jan Kodovský, Jessica J. Fridrich |
ICASSP | 2 |
| 2013 | Digital image steganography using universal distortionabstractCurrently, the most secure practical steganographic schemes for empirical cover sources embed their payload while minimizing a distortion function designed to capture statistical detectability. Since there exists a general framework for this embedding paradigm with established payload-distortion bounds as well as near-optimal practical coding schemes, building an embedding scheme has been essentially reduced to the distortion design. This is not an easy task as relating distortion to statistical detectability is a hard and open problem. In this article, we propose an innovative idea to measure the embedding distortion in one fixed domain independently of the domain where the embedding changes (and coding) are carried out. The proposed universal distortion is additive and evaluates the cost of changing an image element (e.g., pixel or DCT coefficient) from directional residuals obtained using a Daubechies wavelet filter bank. The intuition is to limit the embedding changes only to those parts of the cover that are difficult to model in multiple directions while avoiding smooth regions and clean edges. The utility of the universal distortion is demonstrated by constructing steganographic schemes in the spatial, JPEG, and side-informed JPEG domains, and comparing their security to current state-of-the-art methods using classifiers trained with rich media models. Vojtech Holub, Jessica J. Fridrich |
IH&MMSec | 2 |
| 2013 | Moving steganography and steganalysis from the laboratory into the real worldabstractThere has been an explosion of academic literature on steganography and steganalysis in the past two decades. With a few exceptions, such papers address abstractions of the hiding and detection problems, which arguably have become disconnected from the real world. Most published results, including by the authors of this paper, apply "in laboratory conditions" and some are heavily hedged by assumptions and caveats; significant challenges remain unsolved in order to implement good steganography and steganalysis in practice. This position paper sets out some of the important questions which have been left unanswered, as well as highlighting some that have already been addressed successfully, for steganography and steganalysis to be used in the real world. Andrew D. Ker, Patrick Bas, Rainer Böhme, Rémi Cogranne, Scott Craver, Tomás Filler, Jessica J. Fridrich, Tomás Pevný |
IH&MMSec | 7 |
| 2013 | Effect of Cover Quantization on Steganographic Fisher InformationabstractThe square-root law of imperfect steganography ties the embedding change rate and the cover length with statistical detectability. In this paper, we extend the law to consider the effects of cover quantization. Assuming the individual cover elements are quantized i.i.d. samples drawn from an underlying continuous-valued “precover” distribution, the steganographic Fisher information scales as Δ”, where Δ is the quantization step and is determined jointly by the smoothness of the precover distribution and the properties of the embedding function. This extension is relevant for understanding the effects of the pixel color depth and the JPEG quality factor on the length of secure payload. Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Random Projections of Residuals for Digital Image SteganalysisabstractThe traditional way to represent digital images for feature based steganalysis is to compute a noise residual from the image using a pixel predictor and then form the feature as a sample joint probability distribution of neighboring quantized residual samples-the so - called co-occurrence matrix. In this paper, we propose an alternative statistical representation - instead of forming the co-occurrence matrix, we project neighboring residual samples onto a set of random vectors and take the first-order statistic (histogram) of the projections as the feature. When multiple residuals are used, this representation is called the projection spatial rich model (PSRM). On selected modern steganographic algorithms embedding in the spatial, JPEG, and side-informed JPEG domains, we demonstrate that the PSRM can achieve a more accurate detection as well as a substantially improved performance versus dimensionality trade-off than state-of-the-art feature sets. Vojtech Holub, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | Rich Models for Steganalysis of Digital ImagesabstractWe describe a novel general strategy for building steganography detectors for digital images. The process starts with assembling a rich model of the noise component as a union of many diverse submodels formed by joint distributions of neighboring samples from quantized image noise residuals obtained using linear and nonlinear high-pass filters. In contrast to previous approaches, we make the model assembly a part of the training process driven by samples drawn from the corresponding cover- and stego-sources. Ensemble classifiers are used to assemble the model as well as the final steganalyzer due to their low computational complexity and ability to efficiently work with high-dimensional feature spaces and large training sets. We demonstrate the proposed framework on three steganographic algorithms designed to hide messages in images represented in the spatial domain: HUGO, edge-adaptive algorithm by Luo, and optimally coded ternary$\pm {\hbox{1}}$embedding. For each algorithm, we apply a simple submodel-selection technique to increase the detection accuracy per model dimensionality and show how the detection saturates with increasing complexity of the rich model. By observing the differences between how different submodels engage in detection, an interesting interplay between the embedding and detection is revealed. Steganalysis built around rich image models combined with ensemble classifiers is a promising direction towards automatizing steganalysis for a wide spectrum of steganographic schemes. Jessica J. Fridrich, Jan Kodovský |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | Ensemble Classifiers for Steganalysis of Digital MediaabstractToday, the most accurate steganalysis methods for digital media are built as supervised classifiers on feature vectors extracted from the media. The tool of choice for the machine learning seems to be the support vector machine (SVM). In this paper, we propose an alternative and well-known machine learning tool—ensemble classifiers implemented as random forests—and argue that they are ideally suited for steganalysis. Ensemble classifiers scale much more favorably w.r.t. the number of training examples and the feature dimensionality with performance comparable to the much more complex SVMs. The significantly lower training complexity opens up the possibility for the steganalyst to work with rich (high-dimensional) cover models and train on larger training sets—two key elements that appear necessary to reliably detect modern steganographic algorithms. Ensemble classification is portrayed here as a powerful developer tool that allows fast construction of steganography detectors with markedly improved detection accuracy across a wide range of embedding methods. The power of the proposed framework is demonstrated on three steganographic methods that hide messages in JPEG images. Jan Kodovský, Jessica J. Fridrich, Vojtech Holub |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | From Blind to Quantitative SteganalysisabstractA quantitative steganalyzer is an estimator of the number of embedding changes introduced by a specific embedding operation. Since for most algorithms the number of embedding changes correlates with the message length, quantitative steganalyzers are important forensic tools. In this paper, a general method for constructing quantitative steganalyzers from features used in blind detectors is proposed. The core of the method is a support vector regression, which is used to learn the mapping between a feature vector extracted from the investigated object and the embedding change rate. To demonstrate the generality of the proposed approach, quantitative steganalyzers are constructed for a variety of steganographic algorithms in both JPEG transform and spatial domains. The estimation accuracy is investigated in detail and compares favorably with state-of-the-art quantitative steganalyzers. Tomás Pevný, Jessica J. Fridrich, Andrew D. Ker |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | Modern Trends in Steganography and Steganalysis
Jessica J. Fridrich |
IWDW | 1 |
| 2011 | Minimizing Additive Distortion in Steganography Using Syndrome-Trellis CodesabstractThis paper proposes a complete practical methodology for minimizing additive distortion in steganography with general (nonbinary) embedding operation. Let every possible value of every stego element be assigned a scalar expressing the distortion of an embedding change done by replacing the cover element by this value. The total distortion is assumed to be a sum of per-element distortions. Both the payload-limited sender (minimizing the total distortion while embedding a fixed payload) and the distortion-limited sender (maximizing the payload while introducing a fixed total distortion) are considered. Without any loss of performance, the nonbinary case is decomposed into several binary cases by replacing individual bits in cover elements. The binary case is approached using a novel syndrome-coding scheme based on dual convolutional codes equipped with the Viterbi algorithm. This fast and very versatile solution achieves state-of-the-art results in steganographic applications while having linear time and space complexity w.r.t. the number of cover elements. We report extensive experimental results for a large set of relative payloads and for different distortion profiles, including the wet paper channel. Practical merit of this approach is validated by constructing and testing adaptive embedding schemes for digital images in raster and transform domains. Most current coding schemes used in steganography (matrix embedding, wet paper codes, etc.) and many new ones can be implemented using this framework. Tomás Filler, Jan Judas, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2011 | Defending Against Fingerprint-Copy Attack in Sensor-Based Camera IdentificationabstractSensor photoresponse nonuniformity has been proposed as a unique identifier (fingerprint) for various forensic tasks, including digital-camera ballistics in which an image is matched to the specific camera that took it. The problem investigated here concerns the situation when an adversary estimates the sensor fingerprint from a set of images and superimposes it onto an image from a different camera to frame an innocent victim. This paper proposes a reliable method for detecting such fake fingerprints under rather mild and general assumptions about the adversary's activity and the means available to the victim. The proposed method is subjected to experiments to evaluate its reliability as well as its limitations. The conclusion that can be made from this study is that planting a sensor fingerprint in an image without leaving a trace is significantly more difficult than previously thought. Miroslav Goljan, Jessica J. Fridrich, Mo Chen 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | Erratum to "Defending Against Fingerprint-Copy Attack in Sensor-Based Camera Identification" [Mar 11 227-236]abstractDue to a production error, the above titled paper (ibid., vol. 6, no. 1, pp. 227-236, Mar. 11), was published as a correspondence in the March 2011 issue of IEEE Transactions on Information Forensics and Security. This paper was actually accepted as a Regular Paper and should have been published as such. Miroslav Goljan, Jessica J. Fridrich, Mo Chen 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | Gibbs Construction in SteganographyabstractWe make a connection between steganography design by minimizing embedding distortion and statistical physics. The unique aspect of this work and one that distinguishes it from prior art is that we allow the distortion function to be arbitrary, which permits us to consider spatially dependent embedding changes. We provide a complete theoretical framework and describe practical tools, such as the thermodynamic integration for computing the rate-distortion bound and the Gibbs sampler for simulating the impact of optimal embedding schemes and constructing practical algorithms. The proposed framework reduces the design of secure steganography in empirical covers to the problem of finding local potentials for the distortion function that correlate with statistical detectability in practice. By working out the proposed methodology in detail for a specific choice of the distortion function, we experimentally validate the approach and discuss various options available to the steganographer in practice. Tomás Filler, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | Quantitative Structural Steganalysis of JstegabstractQuantitative steganalysis strives to estimate the change rate defined as the relative number of embedding changes introduced by steganography. In this paper, we propose two new classes of quantitative steganalysis methods for the steganographic algorithm Jsteg. The first class obtains the change-rate estimate using a maximum likelihood estimator equipped with a precover model. While this approach provides better accuracy than existing structural attacks, it becomes computationally intractable with increasing complexity of the cover model. The second class of methods computes the change-rate estimate by minimizing an objective function constructed from a heuristically formed zero message hypothesis. The advantage of this heuristic approach is a low implementation complexity and modular architecture that allows flexible incorporation of higher order statistics of discrete cosine transform coefficients. The proposed methods are experimentally compared with current state-of-the-art methods. Jan Kodovský, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | Steganalysis by subtractive pixel adjacency matrixabstractThis paper presents a method for detection of steganographic methods that embed in the spatial domain by adding a low-amplitude independent stego signal, an example of which is least significant bit (LSB) matching. First, arguments are provided for modeling the differences between adjacent pixels using first-order and second-order Markov chains. Subsets of sample transition probability matrices are then used as features for a steganalyzer implemented by support vector machines. The major part of experiments, performed on four diverse image databases, focuses on evaluation of detection of LSB matching. The comparison to prior art reveals that the presented feature set offers superior accuracy in detecting LSB matching. Even though the feature set was developed specifically for spatial domain steganalysis, by constructing steganalyzers for ten algorithms for JPEG images, it is demonstrated that the features detect steganography in the transform domain as well. Tomás Pevný, Patrick Bas, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2009 | Complete characterization of perfectly secure stego-systems with mutually independent embedding operationabstractWithout any assumption on the cover source, this paper presents a complete characterization of all perfectly secure stego-systems that employ mutually independent embedding operation. It is shown that for a fixed embedding operation, the only perfectly secure stego-systems are those whose cover distribution is an element of a linear vector space with basis vectors determined by the embedding operation. Moreover, we also prove that such stego-systems are perfectly secure if and only if the Fisher information with respect to the embedding change rate is zero and thus Fisher information can be seen as an equivalent descriptor of steganographic security. This result is important for deriving steganographic capacity of imperfect stego-systems with covers modeled as Markov chains [1]. It also suggests that Fisher information could be used for benchmarking. Tomás Filler, Jessica J. Fridrich |
ICASSP | 2 |
| 2009 | Asymptotic behavior of the ZZW embedding constructionabstractWe analyze the asymptotic behavior of the embedding construction for steganography proposed by Zhang, Zhang, and Wang (ZZW) at the 10th information hiding by deriving a closed-form expression for the limit between embedding efficiency of the ZZW construction and the theoretical upper bound as a function of relative payload. This result confirms the experimental observation made in the original publication. Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2008 | Using sensor pattern noise for camera model identificationabstractSensor photo-response non-uniformity (PRNU) was introduced by Lukáš et al. [1] to solve the problem of digital camera sensor identification. The PRNU is the main component of a camera fingerprint that can reliably identify a specific camera. This fingerprint can be estimated from multiple images taken by the camera. In this paper, we demonstrate that the same fingerprint can be used for identification of camera brand and model. This is possible due to the fact that fingerprints estimated from images in the TIFF/JPEG format contain local structure due to various in-camera processing that can be detected by extracting a set of numerical features from the fingerprints and classifying them using pattern classification methods. We estimate and classify fingerprints for more than 4500 digital cameras spanning 8 different brands and 17 models. The average probability of correctly classified camera brand was 90.8%. Tomás Filler, Jessica J. Fridrich, Miroslav Goljan |
ICIP | 2 |
| 2008 | Determining Image Origin and Integrity Using Sensor NoiseabstractIn this paper, we provide a unified framework for identifying the source digital camera from its images and for revealing digitally altered images using photo-response nonuniformity noise (PRNU), which is a unique stochastic fingerprint of imaging sensors. The PRNU is obtained using a maximum-likelihood estimator derived from a simplified model of the sensor output. Both digital forensics tasks are then achieved by detecting the presence of sensor PRNU in specific regions of the image under investigation. The detection is formulated as a hypothesis testing problem. The statistical distribution of the optimal test statistics is obtained using a predictor of the test statistics on small image blocks. The predictor enables more accurate and meaningful estimation of probabilities of false rejection of a correct camera and missed detection of a tampered region. We also include a benchmark implementation of this framework and detailed experimental validation. The robustness of the proposed forensic methods is tested on common image processing, such as JPEG compression, gamma correction, resizing, and denoising. Mo Chen 0005, Jessica J. Fridrich, Miroslav Goljan, Jan Lukás |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2008 | Detection of Double-Compression in JPEG Images for Applications in SteganographyabstractThis paper presents a method for the detection of double JPEG compression and a maximum-likelihood estimator of the primary quality factor. These methods are essential for construction of accurate targeted and blind steganalysis methods for JPEG images. The proposed methods use support vector machine classifiers with feature vectors formed by histograms of low-frequency discrete cosine transformation coefficients. The performance of the algorithms is compared to selected prior art. Tomás Pevný, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2008 | Multiclass Detector of Current Steganographic Methods for JPEG FormatabstractThe aim of this paper is to construct a practical forensic steganalysis tool for JPEG images that can properly analyze both single- and double-compressed stego images and classify them to selected current steganographic methods. Although some of the individual modules of the steganalyzer were previously published by the authors, they were never tested as a complete system. The fusion of the modules brings its own challenges and problems whose analysis and solution is one of the goals of this paper. By determining the stego algorithm, this tool provides the first step needed for extracting the secret message. Given a JPEG image, the detector assigns it to 6 popular steganographic algorithms. The detection is based on feature extraction and supervised training of two banks of multi-classifiers realized using support vector machines. For accurate classification of single-compressed images, a separate multi-classifier is trained for each JPEG quality factor from a certain range. Another bank of multiclassifiers is trained for double-compressed images for the same range of primary quality factors. The image under investigation is first analyzed using a pre-classifier that detects selected cases of double-compression and estimates the primary quantization table. It then sends the image to the appropriate single- or double-compression multiclassifier. The error is estimated from more than 2.6 million images. The steganalyzer is also tested on two previously unseen methods to examine its ability to generalize. Tomás Pevný, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2007 | Identifying Common Source Digital Camera from Image PairsabstractIn this paper, we propose a method for verifying whether two digital images were obtained using the same digital camera. The method uses test statistics derived from a two-channel detector taking as input the noise residuals from both images. It is not assumed that the camera that took the images is available. Miroslav Goljan, Mo Chen 0005, Jessica J. Fridrich |
ICIP (6) | 3 |
| 2007 | Grid Colorings in SteganographyabstractA proper vertex coloring of a graph is called rainbow if, for each vertex$v$, all neighbors of$v$receive distinct colors. A$k$-regular graph$G$is called rainbow (or domatically full) if it admits a rainbow$(k+1)$-coloring. The$d$-dimensional grid graph$G_d$is the graph whose vertices are the points of${\BBZ}^d$and two vertices are adjacent if and only if their$l_1$-distance is$1$. We use a simple construction to prove that$G_d$is rainbow for all$d\ge 1$. We discuss an important application of this result in steganography. Jessica J. Fridrich, Petr Lisonek |
IEEE Trans. Inf. Theory | 1 |
| 2006 | Wet paper codes with improved embedding efficiencyabstractWet paper codes were previously proposed as a tool for construction of steganographic schemes with arbitrary (nonshared) selection channels. In this paper, we propose a new approach to wet paper codes using random linear codes of small codimension that at the same time improves the embedding efficiency (number of random message bits embedded per embedding change). Practical algorithms are given and their performance is evaluated experimentally and compared to theoretically achievable bounds. An approximate formula for the embedding efficiency of the proposed scheme is derived. The proposed coding method can be modularly combined with most steganographic schemes to improve their security. Jessica J. Fridrich, Miroslav Goljan, David Soukal |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | Matrix embedding for large payloadsabstractMatrix embedding is a previously introduced coding method that is used in steganography to improve the embedding efficiency (increase the number of bits embedded per embedding change). Higher embedding efficiency translates into better steganographic security. This gain is more important for long messages than for shorter ones because longer messages are, in general, easier to detect. In this paper, we present two new approaches to matrix embedding for large payloads suitable for practical steganographic schemes-one based on a family of codes constructed from simplex codes and the second one based on random linear codes of small dimension. The embedding efficiency of the proposed methods is evaluated with respect to theoretically achievable bounds Jessica J. Fridrich, David Soukal |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2006 | Digital camera identification from sensor pattern noiseabstractIn this paper, we propose a new method for the problem of digital camera identification from its images based on the sensor's pattern noise. For each camera under investigation, we first determine its reference pattern noise, which serves as a unique identification fingerprint. This is achieved by averaging the noise obtained from multiple images using a denoising filter. To identify the camera from a given image, we consider the reference pattern noise as a spread-spectrum watermark, whose presence in the image is established by using a correlation detector. Experiments on approximately 320 images taken with nine consumer digital cameras are used to estimate false alarm rates and false rejection rates. Additionally, we study how the error rates change with common image processing, such as JPEG compression or gamma correction. Jan Lukás, Jessica J. Fridrich, Miroslav Goljan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2005 | Digital "bullet scratches" for imagesabstractThe problem investigated in this paper is identification of sensor that was used to obtain a given digital image. We show that the high-medium frequency component of the sensor pattern noise is an equivalent of "bullet scratches" for digital images and can be used for reliable forensic identification. For each sensor, we first calculate its reference pattern (an estimate of the sensor pattern noise) by averaging the noise component from multiple images. This pattern serves as a unique identification fingerprint whose presence in a given image is established using a correlation detector. The proposed identification technique was tested on several thousand images obtained by nine digital cameras. In all cases, we were able to correctly identify the camera that took the image. We also show that it is possible to identify the camera from images subjected to combined processing, including lossy JPEG compression, gamma correction, recoloring, and resizing. Jan Lukás, Jessica J. Fridrich, Miroslav Goljan |
ICIP (3) | 2 |
| 2005 | Towards Multi-class Blind Steganalyzer for JPEG Images
Tomás Pevný, Jessica J. Fridrich |
IWDW | 2 |
| 2005 | Perturbed quantization steganography
Jessica J. Fridrich, Miroslav Goljan, David Soukal |
Multim. Syst. | 1 |
| 2003 | Quantitative steganalysis of digital images: estimating the secret message length
Jessica J. Fridrich, Miroslav Goljan, Dorin Hogea, David Soukal |
Multim. Syst. | 1 |
| 2003 | Security of data hiding technologies
Sviatoslav Voloshynovskiy, Thierry Pun, Jessica J. Fridrich, Fernando Pérez-González, Nasir Memon |
Signal Process. | 3 |