EDBT 2026 Demo / reviewers in the wild / expert
Jan Butora
dblp:244/5269
· DBLP profile ↗
18ranked-venue papers
13as first author
13since 2021 · last 2026
0000-0002-2540-1420ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 11 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Better Inversion of Diffusion Models for Generative SteganographyabstractTraditional inversion algorithms attempt to directly invert the diffusion sampling equation. In this work, built on Latent Diffusion Models (LDMs), we propose a family of algorithms with varying time complexities that perform the search of an antecedent within the latent space and/or the Variational Autoencoder (VAE) decoder. Aurélien Noirault, Tomás Pevný, Jan Butora, Vincent Itier, Patrick Bas |
IH&MMSec | 3 |
| 2024 | The Adobe Hidden Feature and its Impact on Sensor AttributionabstractIf the extraction of sensor fingerprints represents nowadays an important forensic tool for sensor attribution, it has been shown recently in [2,3,12] that images coming from several sensors were more prone to generate False Positives (FP) by presenting a common "leak". In this paper, we investigate the possible cause of this leak and after inspecting the EXIF metadata of the sources causing FP, we found out that they were related to the Adobe Lightroom or Camera Raw software. The cross-correlation between residuals on images presenting FP reveals periodic peaks showing the presence of a periodic pattern. By developing our own images with Adobe Lightroom we are able to show that all developments from raw images (or 16 bits per channel coded) to 8 bits-coded images also embed a periodic 128x128 pattern very similar to a watermark. However, we also show that the watermark depends on both the content and the architecture used to develop the image. The rest of the paper presents two different ways of removing this watermark, one by removing it from the image noise component, and the other by removing it in the pixel domain. We show that for a camera presenting FP in [12], we were able to prevent the False Positives. A discussion with Adobe representatives informed us that the company decided to add this pattern in order to induce dithering. Jan Butora, Patrick Bas |
IH&MMSec | 1 |
| 2024 | Errorless Robust JPEG Steganography Using Outputs of JPEG CodersabstractRobust steganography is a technique of hiding secret messages in images so that the message can be recovered after additional image processing. One of the most popular processing operations is JPEG recompression. Unfortunately, most of today's steganographic methods addressing this issue only provide a probabilistic guarantee of recovering the secret and are consequently not errorless. That is unacceptable since even a single unexpected change can make the whole message unreadable if it is encrypted. We propose to create a robust set of DCT coefficients by inspecting their behavior during recompression, which requires access to the targeted JPEG compressor. This is done by dividing the DCT coefficients into 64 non-overlapping lattices because one embedding change can potentially affect many other coefficients from the same DCT block during recompression. The robustness is then combined with standard steganographic costs creating a lattice embedding scheme robust against JPEG recompression. Through experiments, we show that the size of the robust set and the scheme's security depends on the ordering of lattices during embedding. We verify the validity of the proposed method with three typical JPEG compressors and theSlackinstant messaging application. We benchmark its security for various embedding payloads, three different ways of ordering the lattices, and a range of Quality Factors. Finally, this method is errorless by construction, meaning the embedded message will always be readable. Jan Butora, Pauline Puteaux, Patrick Bas |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Size-Independent Reliable CNN for RJCA SteganalysisabstractDetection of image steganography is principally implemented with supervised machine learning detectors. There are two main drawbacks to this approach: the detectors are overly specific to a given image source, and the performance guarantees are only empirical. In this work, we further study a previously proposed deep learning detector that exploits natural image structure imposed by JPEG compression with high quality. We show in a controlled environment that for a fixed JPEG compressor, the soft outputs of a deep learning classifier - the logits - follow a Gaussian distribution. We prove a scaling law stating that the variance of this distribution scales linearly with the image size. By disabling padding in the convolutional neural network, we demonstrate that the mean of the logit distribution does not change, allowing us to directly analyze images of different sizes. Focusing on the logits, we show that we can prescribe a threshold with a theoretical false positive rate for a wide range of image sizes, which is then closely satisfied on real cover images, even for small probabilities such as 10-4. Moreover, the detection power on steganographic images still generalizes to non-adaptive and content-adaptive steganography. Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Finding Incompatible Blocks for Reliable JPEG SteganalysisabstractThis article presents a refined notion of incompatible JPEG images for a quality factor of 100. It can detect the presence of steganographic schemes embedding in DCT coefficients. We show that, within the JPEG pipeline, the combination of the DCT transform with the quantization function can map several blocks in the pixel domain to the same block in the DCT domain. However, not every DCT block can be obtained: we call those blocks incompatible. In particular, incompatibility can happen when DCT coefficients are manually modified to embed a message. We show that the problem of distinguishing compatible blocks from incompatible ones is an inverse problem with or without solution and we propose two different methods to solve it. The first one is heuristic-based, fast to find a solution if it exists. The second is formulated as an Integer Linear Programming problem and can detect incompatible blocks only for a specific DCT transform in a reasonable amount of time. We show that the probability for a block to become incompatible only relies on the number of modifications. Finally, using the heuristic algorithm we can derive a Likelihood Ratio Test depending on the number of compatible blocks per image to perform steganalysis. We simulate the result of this test and show that it outperforms a deep learning detector e-SRNet for every payload between 0.001 and 0.01 bpp by using only 10% of the blocks from$\bf 256\times 256$images. A Selection-Channel-Aware version of the test is even more powerful and outperforms e-SRNet while using only 1% of the blocks. Etienne Levecque, Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Analysis and Mitigation of the False Alarms of the Reverse JPEG Compatibility AttackabstractThe Reverse JPEG Compatibility Attack can be used for steganalysis of JPEG images compressed with Quality Factor 100 by detecting increased variance of decompression rounding errors. In this work, we point out the dangers associated with this attack by showing that in an uncontrolled environment, the variance can be elevated simply by using a different JPEG compressor. If not careful, the steganalyst can wrongly misclassify cover images. In order to deal with the diversity associated to the devices or softwares generating JPEGs, we propose in this paper to build a deep learning detector trained on a huge dataset of downloaded images. Experimental evaluation shows that such a detector can provide operational false alarms as small as 10-4, while still correctly classifying 90% of stego images. Furthermore, it is shown that this performance is directly applicable to other image datasets. As a side product, we indicate that the attack is not applicable to images developed with a specific JPEG compressor based on the trunc quantization function. Jan Butora, Patrick Bas, Rémi Cogranne |
IH&MMSec | 1 |
| 2023 | Compatibility and Timing Attacks for JPEG SteganalysisabstractThis paper introduces a novel compatibility attack to detect a steganographic message embedded in the DCT domain of a JPEG image at high-quality factors (close to 100). Because the JPEG compression is not a surjective function, i.e. not every DCT blocks can be mapped from a pixel block, embedding a message in the DCT domain can create incompatible blocks. We propose a method to find such a block, which directly proves that a block has been modified during the embedding. This theoretical method provides many advantages such as being completely independent to Cover Source Mismatch, having good detection power, and perfect reliability since false alarms are impossible as soon as incompatible blocks are found. We show that finding an incompatible block is equivalent to proving the infeasibility of an Integer Linear Programming problem. However, solving such a problem requires considerable computational power and has not been reached for 8x8 blocks. Instead, a timing attack approach is presented to perform steganalysis without potentially any false alarms for large computing power. Etienne Levecque, Patrick Bas, Jan Butora |
IH&MMSec | 3 |
| 2023 | Side-Informed Steganography for JPEG Images by Modeling Decompressed ImagesabstractSide-informed steganography has always been among the most secure approaches in the field. However, a majority of existing methods for JPEG images use the side information, here the rounding error, in a heuristic way. For the first time, we show that the usefulness of the rounding error comes from its covariance with the embedding changes. Unfortunately, this covariance between continuous and discrete variables is not analytically available. An estimate of the covariance is proposed, which allows to model steganography as a change in the variance of DCT coefficients. Since steganalysis today is best performed in the spatial domain, we derive a likelihood ratio test to preserve a model of a decompressed JPEG image. The proposed method then bounds the power of this test by minimizing the Kullback-Leibler divergence between the cover and stego distributions. We experimentally demonstrate in two popular datasets that it achieves state-of-the-art performance against deep learning detectors. Moreover, by considering a different pixel variance estimator for images compressed with Quality Factor 100, even greater improvements are obtained. Jan Butora, Patrick Bas |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Fighting the Reverse JPEG Compatibility Attack: Pick your SideabstractIn this work we aim to design a steganographic scheme undetectable by the Reverse JPEG Compatibility Attack (RJCA). The RJCA, while only effective for JPEG images compressed with quality factors 99 and 100, was shown to work mainly due to change in variance of the rounding errors after decompression of the DCT coefficients, which is induced by embedding changes incompatible with the JPEG format. One remedy to preserve the aforementioned format is utilizing during the embedding the rounding errors created during the JPEG compression, but no steganographic method is known to be resilient to RJCA without this knowledge. Inspecting the effect of embedding changes on variance and also mean of decompression rounding errors, we propose a steganographic method allowing resistance against RJCA without any side-information. To resist RJCA, we propose a distortion metric making all embedding changes within a DCT block dependent, resulting in a lattice-based embedding. Then it turns out it is enough to cleverly pick the side of the (binary) embedding changes through inspection of their effect on the variance of decompression rounding errors and simply use uniform costs in order to enforce their sparsity across DCT blocks. To increase security against detectors in the spatial (pixel) domain, we show an easy way of combining the proposed methodology with steganography designed for spatial domain security, further improving the undetectability for quality factor 99. The improvements over existing non-informed steganography are up to 40% in terms of detector's accuracy. Jan Butora, Patrick Bas |
IH&MMSec | 1 |
| 2021 | Extending the Reverse JPEG Compatibility Attack to Double Compressed ImagesabstractThe reverse JPEG compatibility attack has recently been introduced as a very accurate and universal steganalysis algorithm for JPEG images with quality 99 or 100. The limitation to these two largest qualities appears fundamental as the prior work on this topic suggests. In this paper, we provide mathematical analysis and demonstrate experimentally that this attack can be extended to double compressed images when the first compression quality is 93 or larger and the second quality equal or larger than the first quality. Comparisons with state-of-the-art deep convolutional neural networks as well as detectors built in the JPEG domain show the merit of this work. Jan Butora, Jessica J. Fridrich |
ICASSP | 1 |
| 2021 | Revisiting Perturbed QuantizationabstractIn this work, we revisit Perturbed Quantization steganography with modern tools available to the steganographer today, including near-optimal ternary coding and content-adaptive embedding with side-information. In PQ, side-information in the form of rounding errors is manufactured by recompressing a JPEG image with a judiciously selected quality factor. This side-information, however, cannot be used in the same fashion as in conventional side-informed schemes nowadays as this leads to highly detectable embedding. As a remedy, we utilize the steganographic Fisher information to allocate the payload among DCT modes. In particular, we show that the embedding should not be constrained to contributing coefficients only as in the original PQ but should be expanded to the so-called "contributing DCT modes." This approach is extended to color images by slightly modifying the SI-UNIWARD algorithm. Using the best detectors currently available, it is shown that by manufacturing side information with double compression, one can embed the same amount of information into the doubly-compressed cover image with a significantly better security than applying J-UNIWARD directly in the single-compressed image. At the end of the paper, we show that double compression with the same quality makes side-informed steganography extremely detectable and should be avoided. Jan Butora, Jessica J. Fridrich |
IH&MMSec | 1 |
| 2021 | How to Pretrain for SteganalysisabstractIn this paper, we investigate the effect of pretraining CNNs on ImageNet on their performance when refined for steganalysis of digital images. In many cases, it seems that just 'seeing' a large number of images helps with the convergence of the network during the refinement no matter what the pretraining task is. To achieve the best performance, the pretraining task should be related to steganalysis, even if it is done on a completely mismatched cover and stego datasets. Furthermore, the pretraining does not need to be carried out for very long and can be done with limited computational resources. An additional advantage of the pretraining is that it is done on color images and can later be applied for steganalysis of color and grayscale images while still having on-par or better performance than detectors trained specifically for a given source. The refining process is also much faster than training the network from scratch. The most surprising part of the paper is that networks pretrained on JPEG images are a good starting point for spatial domain steganalysis as well. Jan Butora, Yassine Yousfi, Jessica J. Fridrich |
IH&MMSec | 1 |
| 2021 | Improving EfficientNet for JPEG SteganalysisabstractIn this paper, we study the EfficientNet family pre-trained on ImageNet when used for steganalysis using transfer learning. We show that certain "surgical modifications" aimed at maintaining the input resolution in EfficientNet architectures significantly boost their performance in JPEG steganalysis, establishing thus new benchmarks. The modified models are evaluated by their detection accuracy, the number of parameters, the memory consumption, and the total floating point operations (FLOPs) on the ALASKA II dataset. We also show that, surprisingly, EfficientNets in their "vanilla form" do not perform as well as the SRNet in BOSSbase+BOWS2. This is because, unlike ALASKA II images, BOSSbase+BOWS2 contains aggressively subsampled images with more complex content. The surgical modifications in EfficientNet remedy this underperformance as well. Yassine Yousfi, Jan Butora, Jessica J. Fridrich, Clement Fuji Tsang |
IH&MMSec | 2 |
| 2020 | Steganography and its Detection in JPEG Images Obtained with the "TRUNC" QuantizerabstractMany portable imaging devices use the operation of "trunc" (rounding towards zero) instead of rounding as the final quantizer for computing DCT coefficients during JPEG compression. We show that this has rather profound consequences for steganography and its detection. In particular, side-informed steganography needs to be redesigned due to the different nature of the rounding error. The steganographic algorithm J-UNIWARD becomes vulnerable to steganalysis with the JPEG rich model and needs to be adjusted for this source. Steganalysis detectors need to be retrained since a steganalyst unaware of the existence of the trunc quantizer will experience 100% false alarm. Jan Butora, Jessica J. Fridrich |
ICASSP | 1 |
| 2020 | Turning Cost-Based Steganography into Model-BasedabstractAbstract Most modern steganographic schemes embed secrets by minimizing the total expected cost of modifications. However, costs are usually computed using heuristics and cannot be directly linked to statistical detectability. Moreover, as previously shown by Ker at al., cost-based schemes fundamentally minimize the wrong quantity that makes them more vulnerable to knowledgeable adversary aware of the embedding change rates. In this paper, we research the possibility to convert cost-based schemes to model-based ones by postulating that there exists payload size for which the change rates derived from costs coincide with change rates derived from some (not necessarily known) model. This allows us to find the steganographic Fisher information for each pixel (DCT coefficient), and embed other payload sizes by minimizing deflection. This rather simple measure indeed brings sometimes quite significant improvements in security especially with respect to steganalysis aware of the selection channel. Steganographic algorithms in both spatial and JPEG domains are studied with feature-based classifiers as well as CNNs. Jan Butora, Yassine Yousfi, Jessica J. Fridrich |
IH&MMSec | 1 |
| 2020 | Reverse JPEG Compatibility AttackabstractA novel steganalysis method for JPEG images is introduced that is universal in the sense that it reliably detects any type of steganography as well as small payloads. It is limited to quality factors 99 and 100. The detection statistic is formed from the rounding errors in the spatial domain after decompressing the JPEG image. The attack works whenever, during compression, the discrete cosine transform is applied to integer-valued signal. Reminiscent of the well-established JPEG compatibility steganalysis, we call the new approach the “reverse JPEG compatibility attack.” While the attack is introduced and analyzed under simplifying assumptions using reasoning based on statistical signal detection, the best detection in practice is obtained with machine learning tools. Experiments on diverse datasets of both grayscale and color images, five steganographic schemes, and with a variety of JPEG compressors demonstrate the universality and applicability of this steganalysis method in practice. Jan Butora, Jessica J. Fridrich |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Effect of JPEG Quality on Steganographic SecurityabstractAbstract This work investigates both theoretically and experimentally the security of JPEG steganography as a function of the quality factor. For a fixed relative payload, modern embedding schemes, such as J-UNIWARD and UED-JC, exhibit surprising non-monotone trends due to rounding and clipping of quantization steps. Their security generally increases with increasing quality factor but starts decreasing for qualities above 95. In contrast, old-fashion steganography, such as Jsteg, OutGuess, and model-based steganography, exhibit complementary trends. The results of empirical detectors closely match the trends exhibited by the KL divergence computed between models of cover and stego DCT modes. In particular, our analysis shows that the main reason for the complementary trends is the way modern schemes attenuate embedding change rates with increasing spatial frequency. Our model also provides guidance on how to adjust the embedding algorithm J-UNIWARD to substantially improve its security for high quality factors. Jan Butora, Jessica J. Fridrich |
IH&MMSec | 1 |
| 2019 | Breaking ALASKA: Color Separation for Steganalysis in JPEG DomainabstractThis paper describes the architecture and training of detectors developed for the ALASKA steganalysis challenge. For each quality factor in the range 60-98, several multi-class tile detectors implemented as SRNets were trained on various combinations of three input channels: luminance and two chrominance channels. To accept images of arbitrary size, the detector for each quality factor was a multi-class multi-layered perceptron trained on features extracted by the tile detectors. For quality 99 and 100, a new "reverse JPEG compatibility attack" was developed and also implemented using the SRNet via the tile detector. Throughout the paper, we explain various improvements we discovered during the course of the competition and discuss the challenges we encountered and trade offs that had to be adopted in order to build a detector capable of detecting steganographic content in a stego source of great diversity. Yassine Yousfi, Jan Butora, Jessica J. Fridrich, Eva Giboulot |
IH&MMSec | 2 |