Kassem Kallas

dblp:158/5079 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0001-7689-4125ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 2 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Turning Distillation against Obfuscation: A Recovery Framework for DNN White-Box Watermarks
abstract
White-box watermarking embeds ownership signatures directly into DNN parameters, yet it faces a critical blind spot: topology-altering obfuscation. By modifying a model’s internal structure while preserving its input-output behavior, an attacker can misalign the watermark from its expected parameter locations, causing standard white-box extractors to fail. We investigate whether existing white-box watermarks remain verifiable after such attacks by introducing Distillation-as-Defense: rather than reversing the obfuscation, we distill the obfuscated model (Teacher) into a student with the original architecture, forcing it to reconstruct the functional watermark representation. We systematically evaluate ten white-box watermarking schemes—eight static (weight-based) and two dynamic (activation-based)—across classifiers, generative models, and transformers. Dynamic methods consistently recover their watermarks under feature-map alignment distillation, while most static methods fail on deep architectures due to internal representation redundancy. These findings reveal that current white-box schemes were not designed with distillation robustness in mind. We conclude that resistance to distillation is a necessary condition for a white-box watermark to withstand topology-altering obfuscation, and we discuss a concrete design guidelines toward this goal.
Mahdieh Pouresmaeil, Reda Bellafqira, Kassem Kallas, Gwenolé Quellec, Gouenou Coatrieux
IH&MMSec3
2026 ROSE: Extended Evaluation of RObust and SEcure Black-Box DNN Watermarking
abstract
Deep neural networks (DNNs) are valuable industrial assets requiring reliable intellectual-property protection. This paper extends ROSE [1], a black-box watermarking protocol for MLaaS settings that quantifies ownership through statistical rarity (expressed as R = −log2(p), in bits) and adversarial computational work. ROSE binds trigger-label pairs to a secret key through a hash-based mechanism, limiting a posteriori forgery and supporting formal reasoning about verification strength. We present an expanded theoretical analysis together with an extensive empirical evaluation across multiple image-classification datasets and architectures, including CNNs, ResNets, and Vision Transformers. Experiments show that ROSE preserves primary task accuracy at low trigger fractions, achieves high watermark recovery, and yields rarity values reaching several hundred bits. The method is evaluated under a broad range of model and input-level perturbations, including fine-tuning, pruning, quantization, image transformations, and sanitizers such as Neural Cleanse and Neural Laundering. In double-watermarking settings, overwriting attempts introduce ambiguity only at the cost of substantial accuracy loss, thereby preserving the practical verifiability of the original claim. Efficiency measurements indicate low overhead: embedding remains comparable to standard training and verification incurs minimal latency. More precisely, the verification cost scales primarily with the number of trigger evaluations rather than directly with model size. While this suggests favorable protocol-level scalability, the present empirical study is restricted to the image-classification architectures evaluated in this paper. Overall, ROSE provides a practical black box watermarking framework that combines strong ownership verifiability, empirical robustness, and low verification overhead in the studied setting.
Kassem Kallas, Teddy Furon
IEEE Trans. Dependable Secur. Comput.1
2025 Energy Backdoor Attack to Deep Neural Networks
abstract
The rise of deep learning (DL) has increased computing complexity and energy use, prompting the adoption of application specific integrated circuits (ASICs) for energy-efficient edge and mobile deployment. However, recent studies have demonstrated the vulnerability of these accelerators to energy attacks. Despite the development of various inference time energy attacks in prior research, backdoor energy attacks remain unexplored. In this paper, we design an innovative energy backdoor attack against deep neural networks (DNNs) operating on sparsity-based accelerators. Our attack is carried out in two distinct phases: backdoor injection and backdoor stealthiness. Experimental results using ResNet-18 and MobileNet-V2 models trained on CIFAR-10 and Tiny ImageNet datasets show the effectiveness of our proposed attack in increasing energy consumption on trigger samples while preserving the model’s performance for clean/regular inputs. This demonstrates the vulnerability of DNNs to energy backdoor attacks. The source code of our attack is available at: https://github.com/hbrachemi/energybackdoor.
Hanene Brachemi Meftah, Wassim Hamidouche, Sid Ahmed Fezza, Olivier Déforges, Kassem Kallas
ICASSP5
2024 Strategic safeguarding: A game theoretic approach for analyzing attacker-defender behavior in DNN backdoors
abstract
Deep neural networks (DNNs) are fundamental to modern applications like face recognition and autonomous driving. However, their security is a significant concern due to various integrity risks, such as backdoor attacks. In these attacks, compromised training data introduce malicious behaviors into the DNN, which can be exploited during inference or deployment. This paper presents a novel game-theoretic approach to model the interactions between an attacker and a defender in the context of a DNN backdoor attack. The contribution of this approach is multifaceted. First, it models the interaction between the attacker and the defender using a game-theoretic framework. Second, it designs a utility function that captures the objectives of both parties, integrating clean data accuracy and attack success rate. Third, it reduces the game model to a two-player zero-sum game, allowing for the identification of Nash equilibrium points through linear programming and a thorough analysis of equilibrium strategies. Additionally, the framework provides varying levels of flexibility regarding the control afforded to each player, thereby representing a range of real-world scenarios. Through extensive numerical simulations, the paper demonstrates the validity of the proposed framework and identifies insightful equilibrium points that guide both players in following their optimal strategies under different assumptions. The results indicate that fully using attack or defense capabilities is not always the optimal strategy for either party. Instead, attackers must balance inducing errors and minimizing the information conveyed to the defender, while defenders should focus on minimizing attack risks while preserving benign sample performance. These findings underscore the effectiveness and versatility of the proposed approach, showcasing optimal strategies across different game scenarios and highlighting its potential to enhance DNN security against backdoor attacks.
Kassem Kallas, Quentin Le Roux, Wassim Hamidouche, Teddy Furon
EURASIP J. Inf. Secur.1
2023 Mixer: DNN Watermarking using Image Mixup
abstract
It is crucial to protect the intellectual property rights of DNN models prior to their deployment. The DNN should perform two main tasks: its primary task and watermarking task. This paper proposes a lightweight, reliable, and secure DNN watermarking that attempts to establish strong ties between these two tasks. The samples triggering the watermarking task are generated using image Mixup either from training or testing samples. This means that there is an infinity of triggers not limited to the samples used to embed the watermark in the model at training. The extensive experiments on image classification models for different datasets as well as exposing them to a variety of attacks, show that the proposed watermarking provides protection with an adequate level of security and robustness.
Kassem Kallas, Teddy Furon
ICASSP1
2022 Deep Learning for Path Loss Prediction in the 3.5 GHz CBRS Spectrum Band
abstract
In the 3.5 GHz Citizens Broadband Radio Service (CBRS) band, accurate path loss prediction is very important to protect the incumbent from harmful interference caused by the lower tier users. The current CBRS standards developed by the Wireless Innovation Forum use the irregular terrain model (ITM), also known as the Longley-Rice model, for path loss calculation. However, the model does not include clutter data, and thus, it underestimates the path loss. This paper utilizes a model-aided deep learning (DL) technique with satellite images to improve path loss prediction. Numerical study shows that the proposed approach can achieve a 4.23 dB root mean square error (RMSE) and outperform the Longley-Rice model and some tuned or fitted propagation models.
Thao T. Nguyen, Raied Caromi, Kassem Kallas, Michael R. Souryal
WCNC3
2019 On the Transferability of Adversarial Examples against CNN-based Image Forensics
abstract
Recent studies have shown that Convolutional Neural Networks (CNN) are relatively easy to attack through the generation of so called adversarial examples. Such vulnerability also affects CNN-based image forensic tools. Research in deep learning has shown that adversarial examples exhibit a certain degree of transferability, i.e., they maintain part of their effectiveness even against CNN models other than the one targeted by the attack. This is a very strong property undermining the usability of CNN's in security-oriented applications. In this paper, we investigate if attack transferability also holds in image forensics applications. With specific reference to the case of manipulation detection, we analyse the results of several experiments considering different sources of mismatch between the CNN used to build the adversarial examples and the one adopted by the forensic analyst. The analysis ranges from cases in which the mismatch involves only the training dataset, to cases in which the attacker and the forensic analyst adopt different architectures. The results of our experiments show that, in the majority of the cases, the attacks are not transferable, thus easing the design of proper countermeasures at least when the attacker does not have a perfect knowledge of the target detector.
Mauro Barni, Kassem Kallas, Ehsan Nowroozi, Benedetta Tondi
ICASSP2
2019 A New Backdoor Attack in CNNS by Training Set Corruption Without Label Poisoning
abstract
Backdoor attacks against CNNs represent a new threat against deep learning systems, due to the possibility of corrupting the training set so to induce an incorrect behaviour at test time. To avoid that the trainer recognises the presence of the corrupted samples, the corruption of the training set must be as stealthy as possible. Previous works have focused on the stealthiness of the perturbation injected into the training samples, however they all assume that the labels of the corrupted samples are also poisoned. This greatly reduces the stealthiness of the attack, since samples whose content does not agree with the label can be identified by visual inspection of the training set or by running a pre-classification step. In this paper we present a new backdoor attack without label poisoning Since the attack works by corrupting only samples of the target class, it has the additional advantage that it does not need to identify beforehand the class of the samples to be attacked at test time. Results obtained on the MNIST digits recognition task and the traffic signs classification task show that backdoor attacks without label poisoning are indeed possible, thus raising a new alarm regarding the use of deep learning in security-critical applications.
Mauro Barni, Kassem Kallas, Benedetta Tondi
ICIP2
2019 Luminance-based video backdoor attack against anti-spoofing rebroadcast detection
abstract
We introduce a new backdoor attack against a deep-learning video rebroadcast detection network. In addition to the difficulties of working with video signals rather than still images, injecting a backdoor into a deep learning model for rebroadcast detection presents the additional problem that the backdoor must survive the digital-to-analog and analog-to-digital conversion associated to video rebroadcast. To cope with this problem, we have built a backdoor attack that works by varying the average luminance of video frames according to a predesigned sinusoidal function. In this way, robustness against geometric transformation is automatically achieved, together with a good robustness against luminance transformations associated to display and recapture, like Gamma correction and white balance. Our experiments demonstrate the effectiveness of the proposed backdoor attack, especially when the attack is carried out by also corrupting the labels of the attacked training samples.
Abhir Bhalerao, Kassem Kallas, Benedetta Tondi, Mauro Barni
MMSP2
2016 A Game-Theoretic Framework for Optimum Decision Fusion in the Presence of Byzantines
abstract
Optimum decision fusion in the presence of malicious nodes - often referred to as Byzantines - is hindered by the necessity of exactly knowing the statistical behavior of Byzantines. In this paper, we focus on a simple, yet widely adopted, setup in which a fusion center (FC) is asked to make a binary decision about a sequence of system states by relying on the possibly corrupted decisions provided by local nodes. We propose a game-theoretic framework, which permits to exploit the superior performance provided by optimum decision fusion, while limiting the amount of a priori knowledge required. We use numerical simulations to derive the optimum behavior of the FC and the Byzantines in a game-theoretic sense, and to evaluate the achievable performance at the equilibrium point of the game. We analyze several different setups, showing that in all cases, the proposed solution permits to improve the accuracy of data fusion. We also show that, in some cases, it is preferable for the Byzantines to minimize the mutual information between the status of the observed system and the reports submitted to the FC, rather than always flipping the decision made by the local nodes.
Andrea Abrardo, Mauro Barni, Kassem Kallas, Benedetta Tondi
IEEE Trans. Inf. Forensics Secur.3