Eli Dworetzky

dblp:323/3115 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0001-7792-1404ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 first-author · 7 since 2021
YearPublicationVenuePosition
2025 Secure Payload Scaling in Detector-Informed Batch Steganography: The Mismatched Detectors Case
abstract
This paper deals with the problem of batch steganography and pooled steganalysis when the sender uses a steganography detector to spread chunks of the payload across a bag of cover images while the Warden uses a possibly different detector for her pooled steganalysis.We investigate how much information can be communicated with increasing bag size 𝑛 at a fixed statistical detectability of Warden's detector.Specifically, we are interested in the scaling exponent 𝛾 of the secure payload 𝑃 (𝑛) = 𝑐𝑛 𝛾 .We approach this problem both theoretically from a statistical model of the soft output of a detector and practically using experiments on real datasets when giving both actors different detectors implemented as convolutional neural networks and a classifier with a rich model.While the effect of the detector mismatch depends on the payload allocation algorithm and the type of mismatch, in general the mismatch decreases the constant of proportionality 𝑐 as well as the exponent 𝛾.This stays true independently of who has the superior detector.Many trends observed in experiments qualitatively match the theoretical predictions derived within our model.Finally, we summarize our most important findings as lessons for the sender and for the Warden.
Eli Dworetzky, Jessica J. Fridrich
IH&MMSec1
2024 Improving Steganographic Security with Source Biasing
abstract
By selecting covers in which steganographic embedding is harder to detect, the steganographer can decrease the chances of being caught by the Warden. On the other hand, sampling from the cover source with a bias is detectable on its own. In this paper, we study this trade-off theoretically within a simple source model. Our analysis predicts the existence of "bias security gain" when the sender selects the sampling bias optimally. Sampling with a bias initially morphs the ROC of Warden's detector to be asymmetrical, lowering the true positive rate for small false alarm rates. We provide a theorem, analogous to the square root law, for the joint critical rates of sampling bias and payload that achieve asymptotically constant detectability. Our analysis is verified experimentally.
Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich
IH&MMSec1
2023 On Comparing Ad Hoc Detectors with Statistical Hypothesis Tests
abstract
This paper addresses how to fairly compare ROCs of ad hoc (or data driven) detectors with tests derived from statistical models of digital media. We argue that the ways ROCs are typically drawn for each detector type correspond to different hypothesis testing problems with different optimality criteria, making the ROCs uncomparable. To understand the problem and why it occurs, we model a source of natural images as a mixture of scene oracles and derive optimal detectors for the task of image steganalysis. Our goal is to guarantee that, when the data follows the statistical model adopted for the hypothesis test, the ROC of the optimal detector bounds the ROC of the ad hoc detector. While the results are applicable beyond the field of image steganalysis, we use this setup to point out possible inconsistencies when comparing both types of detectors and explain guidelines for their proper comparison. Experiments on an artificial cover source with a known model with real steganographic algorithms and deep learning detectors are used to confirm our claims.
Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich
IH&MMSec1
2023 Advancing the JPEG Compatibility Attack: Theory, Performance, Robustness, and Practice
abstract
The JPEG compatibility attack is a steganalysis method for detecting messages embedded in the spatial representation of an image under the assumption that the cover image was a decompressed JPEG. This paper addresses a number of open problems in previous art, namely the lack of theoretical insight into how and why the attack works, low detection accuracy for high JPEG qualities, robustness to the JPEG compressor and DCT coefficient quantizer, and real-life performance evaluation. To explain the main mechanism responsible for detection and to understand the trends exhibited by heuristic detectors, we adopt a model of quantization errors of DCT coefficients in the recompressed image, and within a simplified setup, we analyze the behavior of the most powerful detector. Empowered by our analysis, we resolve the performance deficiencies using an SRNet trained on a two-channel input consisting of the image and its SQ error. This detector is compared with previous state of the art on four content-adaptive stego methods and for a wide range of payloads and quality factors. The last sections of this paper are devoted to studying robustness of this detector with respect to JPEG compressors, quantizers, and errors in estimating the JPEG quantization table. Finally, to demonstrate practical usability of this attack, we test our detector on stego images outputted by real steganographic tools available on the Internet.
Eli Dworetzky, Edgar Kaziakhmedov, Jessica J. Fridrich
IH&MMSec1
2023 Limits of Data Driven Steganography Detectors
abstract
While deep learning has revolutionized image steganalysis in terms of performance, little is known about how much modern data driven detectors can still be improved. In this paper, we approach this difficult and currently wide open question by working with artificial but realistic looking images with a known statistical model that allows us to compute the detectability of modern content-adaptive algorithms with respect to the most powerful detectors. Multiple artificial image datasets are crafted with different levels of content complexity and noise power to assess their influence on the gap between both types of detectors. Experiments with SRNet as the heuristic detector indicate that independent noise contributes less to the performance gap than content of the same MSE. While this loss is rather small for smooth images, it can be quite large for textured images. A network trained on many realizations of a fixed textured scene will, however, recuperate most of the loss, suggesting that networks have the capacity to approximately learn the parameters of a cover source narrowed to a fixed scene.
Edgar Kaziakhmedov, Eli Dworetzky, Jessica J. Fridrich
IH&MMSec2
2023 Explaining the Bag Gain in Batch Steganography
abstract
In batch steganography, the sender distributes the secret payload among multiple images from a “bag” to decrease the chance of being caught. Recent work on this topic described an experimentally discovered phenomenon, which we call the “bag gain”: for fixed communication rate, pooled detectors experience a decrease in statistical detectability for initially increasing bag sizes, providing an opportunity for the sender to gain in security. The bag gain phenomenon is universal in the sense of manifesting under a wide spectrum of conditions. In this paper, we explain this experimental observation by adopting a statistical model of detector response. Despite the simplicity of the model, it does capture observed trends in detectability as a function of the bag size, the rate, and cover source properties. Additionally, and surprisingly, the model predicts that in certain cover sources the sender should avoid bag sizes that are too small as this can lead to a bag loss.
Eli Dworetzky, Jessica J. Fridrich
IEEE Trans. Inf. Forensics Secur.1
2022 Detector-Informed Batch Steganography and Pooled Steganalysis
abstract
We study the problem of batch steganography when the senders use feedback from a steganography detector. This brings an additional level of complexity to the table due to the highly non-linear and non-Gaussian response of modern steganalysis detectors as well as the necessity to study the impact of the inevitable mismatch between senders' and Warden's detectors. Two payload spreaders are considered based on the oracle generating possible cover images. Three different pooling strategies are devised and studied for a more comprehensive assessment of security. Substantial security gains are observed with respect to previous art - the detector-agnostic image-merging sender. Close attention is paid to the impact of the information available to the Warden on security.
Yassine Yousfi, Eli Dworetzky, Jessica J. Fridrich
IH&MMSec2