EDBT 2026 Demo / reviewers in the wild / expert
Nora Hofer
dblp:299/5700
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When the Codec Hallucinates: User Perceptions of Miscompressed ImagesabstractPeople exchange images every day. New methods for image compression leverage neural networks to save bandwidth, but they can undermine the semantic integrity. The term miscompression refers to unintended semantic changes of image details, introduced by generative AI during neural (de)compression. Although prior work has speculated about the resulting risks, no empirical evidence exists on how people perceive these novel compression artifacts. In this study, 115 human subjects compared original images with conventionally compressed, neurally compressed, and miscompressed images. Participants perceive that miscompressions elevate the risk of misunderstandings when communicating with images. They also frequently attribute miscompressions to intentional editing, whereas conventional JPEG artifacts are more often recognized as distortions. This paper proposes a method to study this new phenomenon, provides the first empirical evidence of user perceptions of miscompressions, and derives implications for trust in images, as well as interface designs that mitigate the risk. Nora Hofer, Rainer Böhme |
CHI | 1 |
| 2025 | Challenging Cases of Neural Image Compression: A Dataset of Visually Compelling Yet Semantically Incorrect Reconstructions
Nora Hofer, Rainer Böhme |
ACM Multimedia | 1 |
| 2024 | Increasing Trust in Image Analysis by Detecting Trellis Quantization in JPEG ImagesabstractJPEG image forensics investigates the authenticity and origin of compressed images. Many established methods rely on assumptions about the statistical distribution of quantized discrete cosine transform coefficients. However, JPEG implementations that use trellis quantization, such as mozjpeg, produce images that challenge these assumptions. In this study, we demonstrate that artifacts resulting from trellis quantization can compromise the reliability of established forensic methods and cause false alarms for innocuous images. We address this issue by presenting methods to detect trellis artifacts and validating their robustness in scenarios commonly encountered in forensic analyses. Nora Hofer |
ICIP | 1 |
| 2023 | Progressive JPEGs in the Wild: Implications for Information Hiding and ForensicsabstractJPEG images stored in progressive mode have become more prevalent recently. An estimated 30% of all JPEG images on the most popular websites use progressive mode. Presumably, this surge is caused by the adoption of MozJPEG, an open-source library designed for web publishers. So far, the optimizations used by MozJPEG have not been considered by the multimedia security community, although they are highly relevant. The goal of this paper is to document these optimizations and make them accessible to the research community. Most notably, we find that Trellis optimization in MozJPEG modifies quantized DCT coefficients in order to improve the rate-distortion tradeoff using a perceptual model based on PSNR-HVS. This may compromise the reliability of known methods in steganography, steganalysis, and image forensics when dealing with images compressed with MozJPEG. We also find that the type and order of scans in progressive mode, which MozJPEG adjusts to the image, offer novel cues that can aid forensic source identification. Nora Hofer, Rainer Böhme |
IH&MMSec | 1 |
| 2023 | Causes and Effects of Unanticipated Numerical Deviations in Neural Network Inference FrameworksabstractHardware-specific optimizations in machine learning (ML) frameworks can cause numerical deviations of inference results. Quite surprisingly, despite using a fixed trained model and fixed input data, inference results are not consistent across platforms, and sometimes not even deterministic on the same platform. We study the causes of these numerical deviations for convolutional neural networks (CNN) on realistic end-to-end inference pipelines and in isolated experiments. Results from 75 distinct platforms suggest that the main causes of deviations on CPUs are differences in SIMD use, and the selection of convolution algorithms at runtime on GPUs. We link the causes and propagation effects to properties of the ML model and evaluate potential mitigations. We make our research code publicly available. Alexander Schlögl, Nora Hofer, Rainer Böhme |
NeurIPS | 2 |
| 2022 | Know Your Library: How the libjpeg Version Influences Compression and Decompression ResultsabstractIntroduced in 1991, libjpeg has become a well-established library for processing JPEG images. Many libraries in high-level languages use libjpeg under the hood. So far, little attention has been paid to the fact that different versions of the library produce different outputs for the same input. This may have implications on security-related applications, such as image forensics or steganalysis, where evidence is generated by tracking small, imperceptible changes in JPEG-compressed signals. This paper systematically analyses all libjpeg versions since 1998, including the forked libjpeg-turbo (in its latest version). It compares the outputs of compression and decompression operations for a range of parameter settings. We identify up to three distinct behaviors for compression and up to six for decompression. Martin Benes 0001, Nora Hofer, Rainer Böhme |
IH&MMSec | 2 |
| 2021 | Adversarial Examples Against a BERT ABSA Model - Fooling Bert With L33T, Misspellign, and Punctuation, abstractThe BERT model is de facto state-of-the-art for aspect-based sentiment analysis (ABSA), an important task in natural language processing. Similar to every other model based on deep learning, BERT is vulnerable to so-called adversarial examples: strategically modified inputs that cause a change in the model’s prediction of the underlying input. In this paper we propose three new methods to create character-level adversarial examples against BERT and evaluate their effectiveness on the ABSA task. Specifically, our attack methods mimic human behavior and use leetspeak, common misspellings, or misplaced commas. By concentrating these changes on important words, we are able to maximize misclassification rates with minimal changes. To the best of our knowledge, we are the first to look into adversarial examples for the ABSA task and the first to propose these attacks. Nora Hofer, Pascal Schöttle, Alexander Rietzler, Sebastian Stabinger |
ARES | 1 |