Katarzyna Kapusta

dblp:169/2552 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0003-0963-4782ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Watermarking Large Vision-Language Models: The Vision Encoder is all You Need
abstract
As large vision-language models (VLMs) see increasing adoption, the need for robust ownership verification becomes essential. However, training or fine-tuning these models is computationally intensive, making traditional watermarking approaches impractical. To address this, we introduce a lightweight, black-box watermarking technique that focuses solely on the vision encoder of the VLM, significantly reducing the resource requirements. By leveraging the bi-modal capabilities of VLMs, our method embeds owner-specific information by pairing a particular text prompt with a relevant image. When presented with this unique text-image combination and asked, "Who is your owner?", the model produces an explicit answer identifying its owner. This does not require access to model weights. We validated our approach on several models and demonstrated how it enables efficient and reliable watermark verification, all while bypassing the need to retrain or fine-tune the entire model.
Boussad Addad, Katarzyna Kapusta, Olivier Bettan
IH&MMSec2
2024 SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data Space
abstract
In this paper, we present the SECURED project11Funded in part by the European Union (EU), Grant Agreement no. 10109571. Views and opinions expressed are those of the authors and do not necessarily reflect those of the EU or the Health and Digital Executive Agency. Neither the EU nor the granting authority are responsible for them., aimed at improving privacy-preserving processing of data in the health domain. The technologies developed in the project will be demonstrated in four health-related use cases and with the involvement of SME's selected through an open funding call.
Francesco Regazzoni 0001, Gergely Ács, Albert Zoltan Aszalos, Christos Avgerinos, Nikolaos Bakalos, Josep Lluís Berral, Joppe W. Bos, Marco Brohet, Andrés G. Castillo, Gareth T. Davies, Stefanos Florescu, Pierre-Elisée Flory, Alberto Gutierrez-Torre, Evangelos Haleplidis, Alice Héliou, Sotiris Ioannidis, Alexander El-Kady, Katarzyna Kapusta, Konstantina Karagianni, Pieter Kruizinga, Kyrian Maat, Zoltán Ádám Mann, Kalliopi Mastoraki, SeoJeong Moon, Maja Nisevic, Balazs Pejo, Kostas Papagiannopoulos, Vassilis Paliouras, Paolo Palmieri 0001, Francesca Palumbo, Juan Carlos Pérez Baun, Péter Pollner, Eduard Porta-Pardo, Luca Pulina, Muhammad Ali Siddiqi, Daniela Spajic, Christos Strydis, George Tasopoulos, Vincent Thouvenot, Christos Tselios, Apostolos P. Fournaris
DATE18
2024 A White-Box Watermarking Modulation for Encrypted DNN in Homomorphic Federated Learning
abstract
International audience
Mohammed Lansari, Reda Bellafqira, Katarzyna Kapusta, Vincent Thouvenot, Olivier Bettan, Gouenou Coatrieux
SECRYPT3
2022 PE-AONT: Partial Encryption All or Nothing Transform
abstract
International audience
Katarzyna Kapusta, Gérard Memmi
SECRYPT1
2022 A Secure Federated Learning: Analysis of Different Cryptographic Tools
abstract
International audience
Oana Stan, Vincent Thouvenot, Aymen Boudguiga, Katarzyna Kapusta, Martin Zuber, Renaud Sirdey
SECRYPT4
2021 A Protocol for Secure Verification of Watermarks Embedded into Machine Learning Models
abstract
Machine Learning is a well established tool used in a variety of applications. As training advanced models requires considerable amounts of meaningful data in addition to specific knowledge, a new business model separate models creators from model users. Pre-trained models are sold or made available as a service. This raises several security challenges, among others the one of intellectual property protection. Therefore, a new research track actively seeks to provide techniques for model watermarking that would enable model identification in case of suspicion of model theft or misuse. In this paper, we focus on the problem of secure watermarks verification, which affects all of the proposed techniques and until now was barely tackled. First, we revisit the existing threat model. In particular, we explain the possible threats related to a semi-honest or dishonest verification authority. Secondly, we show how to reduce trust requirements between participants by performing the watermarks verification on encrypted data. Finally, we describe a novel secure verification protocol as well as detail its possible implementation using Multi-Party Computation. The proposed solution does not only preserve the confidentiality of the watermarks but also helps detecting evasion attacks. It could be adopted to work with other authentication schemes based on watermarking, especially with image watermarking schemes.
Katarzyna Kapusta, Vincent Thouvenot, Olivier Bettan, Hugo Beguinet, Hugo Senet
IH&MMSec1
2020 Revisiting Shared Data Protection Against Key Exposure
abstract
This paper puts a new light on computational secret sharing with a view towards distributed storage environments. It starts with revisiting the security model for encrypted data protection against key exposure. The goal of this revisiting is to take advantage of the characteristics of distributed storage in order to design faster key leakage resisting schemes, with the same security properties as the existing ones in this context of distributed storage.
Katarzyna Kapusta, Matthieu Rambaud, Gérard Memmi
AsiaCCS1
2019 All-Or-Nothing data protection for ubiquitous communication: Challenges and perspectives
Han Qiu 0001, Katarzyna Kapusta, Zhihui Lu 0002, Meikang Qiu, Gérard Memmi
Inf. Sci.2
2018 Circular AON: A Very Fast Scheme to Protect Encrypted Data Against Key Exposure
abstract
In this poster, we introduce CAON: a novel variation of an all-ornothing transform that aims at protecting encrypted data against exposure of cryptographic material.We improve the fastest relevant scheme by reducing the number of exclusive-or operations made in addition to encryption by almost a half. We believe that CAON can be easily integrated inside modern distributed storage systems or multi-cloud data solutions in order to reinforce confidentiality level of the stored data at the cost of a very small performance overhead.
Katarzyna Kapusta, Gérard Memmi
CCS1
2016 POSTER: A Keyless Efficient Algorithm for Data Protection by Means of Fragmentation
abstract
Although symmetric ciphers may provide strong computational security, a key leakage makes the encrypted data vulnerable. In a distributed storage environment, reinforcement of data protection consists of dispersing data over multiple servers in a way that no information can be obtained from data fragments until a defined threshold of them has been collected. A secure fragmentation is usually enabled by secret sharing, information dispersal algorithms or data shredding. However, these solutions suffer from various limitations, like additional storage requirement or performance burden. This poster presents a novel flexible keyless fragmentation scheme, balancing memory use and performance with security. It could be applied in many different contexts, such as dispersal of outsourced data over one or multiple clouds or in resource-restrained environments like sensor networks. The scheme has been implemented in JAVA and Matlab. Preliminary analysis shows good performance and data protection.
Katarzyna Kapusta, Gérard Memmi, Hassan N. Noura
CCS1