Xiaojing Ma 0002

dblp:45/7549 · DBLP profile ↗
← Back
28ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0001-6363-3209ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 12 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Security and privacy · 5 · 5 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Stealing Your Fingerprint via the Finger Friction Sound
abstract
Fingerprint authentication is widely adopted in modern identity verification systems due to its efficiency and cost-effectiveness. However, its extensive use poses significant risks, as fingerprint leakage could lead to sensitive information theft, severe financial and personnel losses, and even threats to national security. MasterPrint, which can accidentally match a significant proportion of fingerprint populations, underscores the vulnerabilities in fingerprint authentication systems. This paper introduces PrintListener++, a novel side-channel attack targeting Automatic Fingerprint Identification Systems (AFIS). PrintListener++ extracts first-level fingerprint pattern features from users’ fingertip-swiping actions on the touchscreens and synthesizes stronger targeted MasterPrints by integrating potential second-level features. Based on the generated MasterPrint templates, PrintListener++ reconstructs realistic fingerprint images, further expanding its potential threat. This attack method is highly covert and versatile, requiring only fingertip friction sound recordings, which can be easily obtained through social media platforms. Extensive real-world experiments demonstrate that PrintListener++ significantly enhances the attack potency of MasterPrint, raising critical security concerns for fingerprint authentication systems.
Man Zhou 0004, Lianmiao Wang, Yangguang Sun, Shuao Su, Xiaojing Ma 0002, Qi Li 0002, Qian Wang 0002
IEEE Trans. Netw.5
2025 SDBF: Steep-Decision-Boundary Fingerprinting for Hard-Label Tampering Detection of DNN Models
abstract
Cloud-based AI systems offer significant benefits but also introduce vulnerabilities, making deep neural network (DNN) models susceptible to malicious tampering. This tampering may involve harmful behavior injection or resource reduction, compromising model integrity and performance. To detect model tampering, hard-label fingerprinting techniques generate sensitive samples to probe and reveal tampering. Existing fingerprinting methods are mainly based on gradient-defined sensitivity or decision boundary, with the latter showing a manifest superior detection performance. However, all existing fingerprinting methods either suffer from insufficient sensitivity or incur high computational costs.In this paper, we theoretically analyze the black-box co-optimal tampering detection sensitivity of fingerprint samples in the context of decision boundary and gradient-defined sensitivity. Based on this, we further propose Steep-Decision-Boundary Fingerprinting (SDBF), a novel lightweight approach for hard-label tampering detection that inherently and efficiently combines the strengths of existing fingerprinting techniques. SDBF places fingerprint samples near the steep decision boundary, where the outputs of samples are inherently highly sensitive to tampering. We also design a Max Boundary Coverage Strategy (MBCS), which enhances samples’ diversity over the decision boundary. Theoretical analysis and extensive experimental results show that SDBF outperforms existing SOTA hard-label fingerprinting methods in both sensitivity and efficiency.
Xiaofan Bai, Shixin Li 0001, Xiaojing Ma 0002, Bin B. Zhu, Dongmei Zhang 0001, Linchen Yu
CVPR3
2025 Enhancing Adversarial Transferability with Checkpoints of a Single Model's Training
abstract
Adversarial attacks threaten the integrity of deep neural networks (DNNs), particularly in high-stakes applications. In this paper, we present a novel black-box adversarial attack that leverages the diverse checkpoints generated during a single model’s training trajectory. Unlike conventional ensemble attacks that require multiple surrogate models with diverse architectures, our approach exploits the intrinsic diversity captured over different training stages of a single surrogate model. By decomposing the learned representations into task-intrinsic and task-irrelevant components, we employ an accuracy gap-based selection strategy to identify checkpoints that predominantly capture transferable, task-intrinsic knowledge. Extensive experiments on ImageNet and CIFAR-10 demonstrate that our method consistently outperforms traditional ensemble attacks in terms of transferability, even under resource-constrained and practical settings. This work offers a resource-efficient solution for crafting highly transferable adversarial examples and provides new insights into the dynamics of adversarial vulnerability.
Shixin Li 0001, Chaoxiang He, Xiaojing Ma 0002, Bin B. Zhu, Shuo Wang 0012, Hongsheng Hu, Dongmei Zhang 0001, Linchen Yu
CVPR3
2025 RESF: Regularized-Entropy-Sensitive Fingerprinting for Black-Box Tamper Detection of Large Language Models
abstract
The proliferation of Machine Learning as a Service (MLaaS) has enabled widespread deployment of large language models (LLMs) via cloud APIs, but also raises critical concerns about model integrity and security.Existing black-box tamper detection methods, such as watermarking and fingerprinting, rely on the stability of model outputs-a property that does not hold for inherently stochastic LLMs.We address this challenge by formulating blackbox tamper detection for LLMs as a hypothesistesting problem.To enable efficient and sensitive fingerprinting, we derive a first-order surrogate for KL divergence-the entropy-gradient norm-to identify prompts most responsive to parameter perturbations.Building on this, we propose Regularized Entropy-Sensitive Fingerprinting (RESF), which enhances sensitivity while regularizing entropy to improve output stability and control false positives.To further distinguish tampering from benign randomness, such as temperature shifts, RESF employs a lightweight two-tier sequential test combining support-based and distributional checks with rigorous false-alarm control.Comprehensive analysis and experiments across multiple LLMs show that RESF achieves up to 98.80% detection accuracy under challenging conditions, such as minimal LoRA fine-tuning with five optimized fingerprints.RESF consistently demonstrates strong sensitivity and robustness, providing an effective and scalable solution for black-box tamper detection in cloud-deployed LLMs.
Pingyi Hu, Xiaofan Bai, Xiaojing Ma 0002, Chaoxiang He, Dongmei Zhang 0001, Bin B. Zhu
EMNLP3
2025 Consensus-Robust Transfer Attacks via Parameter and Representation Perturbations
abstract
Adversarial examples crafted on one model often exhibit poor transferability to others, hindering their effectiveness in black-box settings. This limitation arises from two key factors: (i) \emph{decision-boundary variation} across models and (ii) \emph{representation drift} in feature space. We address these challenges through a new perspective that frames transferability for \emph{untargeted attacks} as a \emph{consensus-robust optimization} problem: adversarial perturbations should remain effective across a neighborhood of plausible target models. To model this uncertainty, we introduce two complementary perturbation channels: a \emph{parameter channel}, capturing boundary shifts via weight perturbations, and a \emph{representation channel}, addressing feature drift via stochastic blending of clean and adversarial activations. We then propose \emph{CORTA} (COnsensus--Robust Transfer Attack), a lightweight attack instantiated from this robust formulation using two first-order strategies: (i) sensitivity regularization based on the squared Frobenius norm of logits’ Jacobian with respect to weights, and (ii) Monte Carlo sampling for blended feature representations. Our theoretical analysis provides a certified lower bound linking these approximations to the robust objective. Extensive experiments on CIFAR-100 and ImageNet show that CORTA significantly outperforms state-of-the-art transfer-based methods---including ensemble approaches---across CNN and Vision Transformer targets. Notably, CORTA achieves a \emph{19.1 percentage-point gain in transfer success rate over the best prior method} while using only a single surrogate model.
Shixin Li 0001, Xiaojing Ma 0002, Xiaofan Bai, Pingyi Hu, Dongmei Zhang 0001, Bin B. Zhu
NeurIPS3
2025 CaphandAuth: Robust and Anti-spoofing Hand Authentication via COTS Capacitive Touchscreens
abstract
Utilizing unique physiological or behavioral traits, biometrics offers an intuitive authentication approach. However, common biometric modalities are susceptible to ambient factors and privacy concerns. This paper proposes CaphandAuth, a novel capacitive touchscreen-based hand authentication system. Using intrinsic capacitive imaging within the touchscreen, it provides a new secure, cost-effective, and user-friendly biometric authentication solution that is inherently resilient to environmental factors. To this end, CaphandAuth captures consecutive capacitive frames as the hand moves across the touchscreen. These frames are processed with an innovative super-resolution algorithm tailored for deformable objects to enhance details. A learning-based feature extractor then derives expressive and adaptive feature representations from the enhanced images. Extensive experiments demonstrate that CaphandAuth achieves an authentication accuracy of 99.84% and an equal error rate (EER) of 2.77% on a commercial tablet. Moreover, Caphand-Auth exhibits formidable resilience to diverse deceiving attempts, including handprint simulation attacks, counterfeit spoofing attacks, and puppet attacks, making it a robust and secure solution in real-world scenarios.
Man Zhou 0004, Xiaoxiao Qiao, Zijian Ling, Qin Liu 0003, Xiaojing Ma 0002, Zhengxiong Li
SenSys7
2025 NUSGuard: Smart Device Anti-Eavesdropping Protection Based on Near-Ultrasonic Interference
abstract
Voice assistants (VAs) have become ubiquitous in smart devices, and are highly valued for their ability to perform a variety of tasks through voice interaction, offering users hands-free convenience. However, the always-on microphones of VAs have raised significant privacy concerns in recent years. In this paper, we propose and implement NUSGuard, a novel and practical anti-eavesdropping system. To our knowledge, it is the first system to utilize the built-in speakers of commercial off-the-shelf (COTS) devices for anti-eavesdropping, thereby eliminating the need for dedicated ultrasonic transmitters. Specifically, it exploits human ears’ insensitivity to near-ultrasonic signals and the inherent non-linearity of mic to inject jamming noises into the microphones of unauthorized smart devices. Furthermore, we propose a robust mixed-noise scheme and a lexical-level automatic jammer control strategy, effectively disrupting unauthorized recordings while maintaining seamless voice interaction with authorized VA devices. Extensive digital and real-world experiments have demonstrated NUSGuard’s superior performance in terms of jamming effectiveness and security.
Xiaoxiao Qiao, Man Zhou 0004, Hongwei Li 0001, Zhihao Yao 0001, Xiaojing Ma 0002
IEEE Trans. Inf. Forensics Secur.7
2024 MysticMask: Adversarial Mask for Impersonation Attack Against Face Recognition Systems
abstract
In our increasingly interconnected digital world, face recognition serves as a vital security layer for identity verification. However, impersonation attacks pose a significant threat to face recognition systems. While adversarial attacks have proven effective in impersonation, current methods primarily target face recognition, overlooking other crucial processes in real-world applications, such as action-based liveness detection.To address this gap, we introduce MysticMask, a novel adversarial mask attack designed to penetrate the entire face recognition pipeline for impersonation. MysticMask operates in the 3D domain, leveraging foldable medical face masks that automatically align with facial landmarks, enabling accurate physical simulations. MysticMask attacks all processes in a face recognition system simultaneously, including face detection, action-based liveness detection, and face recognition. Additionally, a landmark alignment technique is proposed to pass action-based liveness detection. Extensive experiments conducted in both simulated 3D and real-world scenarios demonstrate MysticMask’s superiority over state-of-the-art methods.
Chaoxiang He, Yimiao Zeng, Xiaojing Ma 0002, Bin B. Zhu, Shixin Li 0001, Hai Jin 0001
ICME3
2024 Intersecting-Boundary-Sensitive Fingerprinting for Tampering Detection of DNN Models
abstract
Cloud-based AI services offer numerous benefits but also introduce vulnerabilities, allowing for tampering with deployed DNN models, ranging from injecting malicious behaviors to reducing computing resources. Fingerprint samples are generated to query models to detect such tampering. In this paper, we present Intersecting-Boundary-Sensitive Fingerprinting (IBSF), a novel method for black-box integrity verification of DNN models using only top-1 labels. Recognizing that tampering with a model alters its decision boundary, IBSF crafts fingerprint samples from normal samples by maximizing the partial Shannon entropy of a selected subset of categories to position the fingerprint samples near decision boundaries where the categories in the subset intersect. These fingerprint samples are almost indistinguishable from their source samples. We theoretically establish and confirm experimentally that these fingerprint samples’ expected sensitivity to tampering increases with the cardinality of the subset. Extensive evaluation demonstrates that IBSF surpasses existing state-of-the-art fingerprinting methods, particularly with larger subset cardinality, establishing its state-of-the-art performance in black-box tampering detection using only top-1 labels. The IBSF code is available at https://github.com/CGCL-codes/IBSF.
Xiaofan Bai, Chaoxiang He, Xiaojing Ma 0002, Bin B. Zhu, Hai Jin 0001
ICML3
2024 Towards Stricter Black-box Integrity Verification of Deep Neural Network Models
abstract
Cloud-based machine learning services offer significant advantages but also introduce the risk of tampering with cloud-deployed deep neural network (DNN) models. Black-box integrity verification (BIV) allows model owners and end-users to determine if a cloud-deployed DNN model has been tampered with by examining only the top-1 label responses. Fingerprinting generates fingerprint samples to query the model, achieving BIV with no impact on the model's accuracy. In this paper, we present BIVBench, the first comprehensive benchmark for BIV of DNN models. BIVBench covers 16 types of model modifications, providing extensive coverage of practical modification scenarios. Our analysis reveals that existing fingerprinting methods, which are typically focused on significant tampering, lack the sensitivity needed to effectively detect subtle yet common and potentially severe modifications. To address this limitation, we propose MiSentry (Model Integrity Sentry), a novel fingerprinting method that leverages meta-learning. MiSentry strategically incorporates a few subtly modified models into the meta-learning model zoo and maximizes the divergence of output predictions between the target model and the modified models in the model zoo to generate highly sensitive, generalizable, and effective fingerprint samples. Extensive evaluations using BIVBench demonstrate that MiSentry outperforms existing state-of-the-art methods overall and significantly surpasses them in detecting subtle modifications. The BIVBench and supplementary materials are available at: https://github.com/CGCL-codes/BIVBench.
Chaoxiang He, Xiaofan Bai, Xiaojing Ma 0002, Bin B. Zhu, Pingyi Hu, Jiayun Fu, Hai Jin 0001, Dongmei Zhang 0001
ACM Multimedia3
2024 DorPatch: Distributed and Occlusion-Robust Adversarial Patch to Evade Certifiable Defenses
Chaoxiang He, Xiaojing Ma 0002, Bin B. Zhu, Yimiao Zeng, Hanqing Hu, Xiaofan Bai, Hai Jin 0001, Dongmei Zhang 0001
NDSS2
2024 PrintListener: Uncovering the Vulnerability of Fingerprint Authentication via the Finger Friction Sound
Man Zhou 0004, Shuao Su, Qian Wang 0002, Qi Li 0002, Xiaojing Ma 0002, Zhengxiong Li
NDSS6
2023 Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes
Jiayun Fu, Xiaojing Ma 0002, Bin B. Zhu, Pingyi Hu, Ruixin Zhao, Yaru Jia, Peng Xu 0003, Hai Jin 0001, Dongmei Zhang 0001
NDSS2
2022 ChartStamp: Robust Chart Embedding for Real-World Applications
abstract
Deep learning-based image embedding methods are typically designed for natural images and may not work for chart images due to their homogeneous regions, which lack variations to hide data both robustly and imperceptibly. In this paper, we propose ChartStamp, the first chart embedding method that is robust to real-world printing and displaying (printed on paper and displayed on screen, respectively, and then captured with a camera) while maintaining a good perceptual quality. ChartStamp hides 100, 1,000, or 10,000 raw bits into a chart image, depending on the designated robustness to printing, displaying, or JPEG. To ensure perceptual quality, it introduces a new perceptual model to guide embedding to insensitive regions of a chart image and a smoothness loss to ensure smoothness of the embedding residual in homogeneous regions. ChartStamp applies a distortion layer approximating designated real-world manipulations to train a model robust to these manipulations. Our experimental evaluation indicates that ChartStamp achieves the robustness and embedding capacity on chart images similar to their state-of-the-art counterparts on natural images. Our user studies indicate that ChartStamp achieves better perceptual quality than existing robust chart embedding methods and that our perceptual model outperforms the existing perceptual model.
Jiayun Fu, Bin B. Zhu, Yayi Zou, Weiwei Cui 0001, Yun Wang 0012, Dongmei Zhang 0001, Xiaojing Ma 0002, Hai Jin 0001
ACM Multimedia9
2022 Privacy-preserving Motion Detection for HEVC-compressed Surveillance Video
abstract
In the cloud era, a large amount of data is uploaded to and processed by public clouds. The risk of privacy leakage has become a major concern for cloud users. Cloud-based video surveillance requires motion detection, which may reveal the privacy of people in a surveillance video. Privacy-preserving video surveillance allows motion detection while protecting privacy. The existing scheme [ 25 ], designed to detect motion on encrypted and H.264-compressed surveillance videos, does not work well on more advanced video compression schemes such as HEVC. In this article, we propose the first motion detection method on encrypted and HEVC-compressed videos. It adopts a novel approach that exploits inter-prediction reference relationships among coding blocks to detect motion regions. The partition pattern and the number of coding bits of each detection block used in prior art are also used to help detect motion regions. Spatial and temporal consistency of a moving object and Kalman filtering are applied to segment connected/merged motion regions, remove noise and background motions, and refine trajectories and shapes of detected moving objects. Experimental results indicate that our detection method achieves high detection recall, precision, and F1-score for surveillance videos of both high and low resolutions with various scenes. It has a similarly high detection accuracy on encrypted and HEVC-compressed videos as that of the existing motion detection method [ 25 ] on encrypted and H.264-compressed videos. Our proposed method incurs no bit-rate overhead and has a very low computational complexity for both motion detection and encryption of HEVC videos.
Changming Liu, Xiaojing Ma 0002, Sixing Cao, Jiayun Fu, Bin B. Zhu
ACM Trans. Multim. Comput. Commun. Appl.2
2021 Feature-Indistinguishable Attack to Circumvent Trapdoor-Enabled Defense
abstract
Deep neural networks (DNNs) are vulnerable to adversarial attacks. A great effort has been directed to developing effective defenses against adversarial attacks and finding vulnerabilities of proposed defenses. A recently proposed defense called Trapdoor-enabled Detection (TeD) deliberately injects trapdoors into DNN models to trap and detect adversarial examples targeting categories protected by TeD. TeD can effectively detect existing state-of-the-art adversarial attacks. In this paper, we propose a novel black-box adversarial attack on TeD, called Feature-Indistinguishable Attack (FIA). It circumvents TeD by crafting adversarial examples indistinguishable in the feature (i.e., neuron-activation) space from benign examples in the target category. To achieve this goal, FIA jointly minimizes the distance to the expectation of feature representations of benign samples in the target category and maximizes the distances to positive adversarial examples generated to query TeD in the preparation phase. A constraint is used to ensure that the feature vector of a generated adversarial example is within the distribution of feature vectors of benign examples in the target category. Our extensive empirical evaluation with different configurations and variants of TeD indicates that our proposed FIA can effectively circumvent TeD. FIA opens a door for developing much more powerful adversarial attacks. The FIA code is available at: https://github.com/CGCL-codes/FeatureIndistinguishableAttack.
Chaoxiang He, Bin B. Zhu, Xiaojing Ma 0002, Hai Jin 0001, Shengshan Hu
CCS3
2021 Chartem: Reviving Chart Images with Data Embedding
abstract
In practice, charts are widely stored as bitmap images. Although easily consumed by humans, they are not convenient for other uses. For example, changing the chart style or type or a data value in a chart image practically requires creating a completely new chart, which is often a time-consuming and error-prone process. To assist these tasks, many approaches have been proposed to automatically extract information from chart images with computer vision and machine learning techniques. Although they have achieved promising preliminary results, there are still a lot of challenges to overcome in terms of robustness and accuracy. In this paper, we propose a novel alternative approach called Chartem to address this issue directly from the root. Specifically, we design a data-embedding schema to encode a significant amount of information into the background of a chart image without interfering human perception of the chart. The embedded information, when extracted from the image, can enable a variety of visualization applications to reuse or repurpose chart images. To evaluate the effectiveness of Chartem, we conduct a user study and performance experiments on Chartem embedding and extraction algorithms. We further present several prototype applications to demonstrate the utility of Chartem.
Jiayun Fu, Bin B. Zhu, Weiwei Cui 0001, Yun Wang 0012, Dongmei Zhang 0001, Xiaojing Ma 0002
IEEE Trans. Vis. Comput. Graph.10
2019 AutoCVSS: An Approach for Automatic Assessment of Vulnerability Severity Based on Attack Process
Deqing Zou, Ju Yang, Zhen Li 0027, Hai Jin 0001, Xiaojing Ma 0002
GPC5
2019 Decoding Homomorphically Encrypted Flac Audio without Decryption
abstract
Homomorphic Encryption (HE) allows processing cipher-text data, but it is a challenge to enable complex methods such as multimedia decompression in the HE domain. In this paper, we propose a novel scheme to enable FLAC (Free Lossless Audio Codec) decompression in the HE domain. FLAC applies linear prediction to predict the current sample and Golomb coding to encode residuals. FLAC decoding relies heavily on dynamic controls that HE does not support due to unknown values of control variables after encryption. Our scheme regularizes dynamic controls in FLAC decoding with static controls by calculating an encrypted matching bit for each possible value of a control variable and producing candidate results as if it were a match. The summation of each possible value’s candidate results multiplied by its matching bit is equivalent to selecting the results of the matched control value. Our FLAC decoding scheme enables Single-Instruction Multiple-Data (SIMD): multiple (e.g., 256) plaintexts are packed and encrypted into a single ciphertext, and decoding one encrypted frame corresponds to decoding multiple plaintext frames. Our scheme is applicable to other audio compression standards based on similar technologies. Experimental results are also reported.
Bin B. Zhu, Xiaojing Ma 0002, P. Takis Mathiopoulos, Xia Xie 0003, Hong Huang 0001
ICASSP3
2019 High Performance DDoS Attack Detection System Based on Distribution Statistics
Xia Xie 0003, Xiaoyang Hu, Hai Jin 0001, Hanhua Chen, Xiaojing Ma 0002, Hong Huang 0001
NPC6
2018 Privacy-Preserving Cloud-Based Video Surveillance with Adjustable Granularity of Privacy Protection
abstract
Cloud-based video surveillance requires protecting privacy yet allowing cloud to perform motion detection and tracking. Prior art allows performing surveillance on encrypted videos but details of trajectories of moving objects are exposed. In this paper, we propose a video surveillance system that supports adjustable granularity of motion detection and tracking for fine-grained control on conflicting requirements between privacy protection and accuracy of motion detection and tracking. Our encryption adds a permutation layer to conventional format-compliant selective encryption to ensure motion information can be recovered only at a given granularity yet incurs a very small impact on the bitrate and processing speed of video compression. Our motion detection method estimates both local and global motions to distinguish foreground motions from background motions and deduce trajectories of foreground moving objects. Experimental results indicate that our system has fulfilled the design goal.
Xiaojing Ma 0002, Huan Peng, Hai Jin 0001, Bin B. Zhu
ICIP1
2018 JPEG Decompression in the Homomorphic Encryption Domain
abstract
Privacy-preserving processing is desirable for cloud computing to relieve users' concern of loss of control of their uploaded data. This may be fulfilled with homomorphic encryption. With widely used JPEG, it is desirable to enable JPEG decompression in the homomorphic encryption domain. This is a great challenge since JPEG decoding needs to determine a matched codeword, which then extracts a codeword-dependent number of coefficients. With no access to the information of encrypted content, a decoder does not know which codeword is matched, and thus cannot tell how many coefficients to extract, not to mention to compute their values. In this paper, we propose a novel scheme that enables JPEG decompression in the homomorphic encryption domain. The scheme applies a statically controlled iterative procedure to decode one coefficient per iteration. In one iteration, each codeword is compared with the bitstream to compute an encrypted Boolean that represents if the codeword is a match or not. Each codeword would produce an output coefficient and generate a new bitstream by dropping consumed bits as if it were a match. If a codeword is associated with more than one coefficient, the codeword is replaced with the codeword representing the remaining undecoded coefficients for the next decoding iteration. The summation of each codeword's output multiplied by its matching Boolean is the output of the current iteration. This is equivalent to selecting the output of a matched codeword. A side benefit of our statically controlled decoding procedure is that paralleled Single-Instruction Multiple-Data (SIMD) is fully supported, wherein multiple plaintexts are encrypted into a single plaintext, and decoding a ciphertext block corresponds to decoding all corresponding plaintext blocks. SIMD also reduces the total size of ciphertexts of an image. Experimental results are reported to show the performance of our proposed scheme.
Xiaojing Ma 0002, Changming Liu, Sixing Cao, Bin B. Zhu
ACM Multimedia1
2017 Fully Reversible Privacy Region Protection for Cloud Video Surveillance
abstract
Privacy becomes one of the major concerns of cloud-based multimedia applications such as cloud video surveillance. Privacy protection of surveillance videos aims to protect privacy information without hampering normal processing tasks of the cloud. Privacy Region Protection only protects the privacy region while keeping the non-privacy region visually intact to facilitate processing in the cloud. However, full reversibility, i.e. the complete recovery of the original video which is critical to digital investigation and law enforcement has not been properly addressed in privacy region protection. In this paper, we introduce fully reversible privacy region protection into cloud video surveillance and propose a novel fully reversible privacy protection method for H.264/AVC compressed video. All the operations are performed in the compressed domain and avoid lossy re-encoding, so the original H.264/AVC compressed video can be fully recovered. To our best knowledge, the proposed scheme is the first fully reversible one for privacy region protection. Experimental results and performance comparison demonstrate the effectiveness and efficiency of the proposed approach.
Xiaojing Ma 0002, Laurence T. Yang, Yang Xiang 0001, Wenjun Zeng 0001, Deqing Zou, Hai Jin 0001
IEEE Trans. Cloud Comput.1
2015 A new robust data hiding method for H.264/AVC without intra-frame distortion drift
Yunxia Liu 0002, Xiaojing Ma 0002, Hongguo Zhao
Neurocomputing3
2015 A robust reversible data hiding scheme for H.264 without distortion drift
Yunxia Liu 0002, Leiming Ju, Xiaojing Ma 0002, Hongguo Zhao
Neurocomputing4
2014 A robust without intra-frame distortion drift data hiding algorithm based on H.264/AVC
Yunxia Liu 0002, Zhitang Li, Xiaojing Ma 0002
Multim. Tools Appl.3
2013 A robust data hiding algorithm for H.264/AVC video streams
Yunxia Liu 0002, Zhitang Li, Xiaojing Ma 0002
J. Syst. Softw.3
2010 A Data Hiding Algorithm for H.264/AVC Video Streams Without Intra-Frame Distortion Drift
abstract
Intra-frame distortion drift is a big problem of data hiding in H.264/AVC video streams. Based on a thorough investigation of this problem, a novel readable data-hiding algorithm, which can embed data into the quantized discrete cosine transform (DCT) coefficients of I frames without bringing any intra-frame distortion drift into the H.264/advanced video coding (AVC) video host, is presented in this paper. We exploit several paired-coefficients of a 4$\,\times\,$4 DCT block to accumulate the embedding induced distortion. The directions of intra-frame prediction are utilized to avert the distortion drift. It is proved analytically and shown experimentally that the proposed algorithm can achieve high embedding capacity and low visual distortion. Performance comparisons with other existing schemes are provided to demonstrate the superiority of the proposed scheme.
Xiaojing Ma 0002, Zhitang Li, Bochao Zhang
IEEE Trans. Circuits Syst. Video Technol.1