Rainer Böhme

dblp:52/6295 · DBLP profile ↗
← Back
55ranked-venue papers
8as first author
21since 2021 · last 2026
0000-0003-4518-6227ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 3 first-author · 16 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 6 · 1 first-author · 3 since 2021Computer networks · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 When the Codec Hallucinates: User Perceptions of Miscompressed Images
abstract
People exchange images every day. New methods for image compression leverage neural networks to save bandwidth, but they can undermine the semantic integrity. The term miscompression refers to unintended semantic changes of image details, introduced by generative AI during neural (de)compression. Although prior work has speculated about the resulting risks, no empirical evidence exists on how people perceive these novel compression artifacts. In this study, 115 human subjects compared original images with conventionally compressed, neurally compressed, and miscompressed images. Participants perceive that miscompressions elevate the risk of misunderstandings when communicating with images. They also frequently attribute miscompressions to intentional editing, whereas conventional JPEG artifacts are more often recognized as distortions. This paper proposes a method to study this new phenomenon, provides the first empirical evidence of user perceptions of miscompressions, and derives implications for trust in images, as well as interface designs that mitigate the risk.
Nora Hofer, Rainer Böhme
CHI2
2026 Agility for Steganalysis: Dealing with Distribution Drift in JPEG File Structures
Matej Zorek, Tomás Pevný, Rainer Böhme
EuroS&P3
2026 Payload in Motion: On the Capacity of Video Steganography
abstract
Unlike still images, motion-compensated H.264 video offers a plethora of data types that can be considered for steganographic embedding by cover modification. Different strands of literature focus on specific embedding elements, for example motion vectors, prediction modes, or quantized transform coefficients. This paper presents the first systematic measurement study on the steganographic capacity offered by each embedding element. Using common video benchmark datasets and encoding parameters, we measure capacity in two ways: counting elements and approximating the entropy. We analyze the effect of the quantization parameter and different group-of-picture size regimes on the capacity. Matching the experiments of nine selected state-of-the-art steganographic methods for H.264 video, and calculating the payload ratio as a comparable metric, we find that quantized transform coefficients offer the highest capacity by a margin. Only if combined with motion vector steganography, payload ratios close to the ones offered by grayscale still image steganography can be achieved.
Verena Lachner, Rainer Böhme
IH&MMSec2
2025 Challenging Cases of Neural Image Compression: A Dataset of Visually Compelling Yet Semantically Incorrect Reconstructions
Nora Hofer, Rainer Böhme
ACM Multimedia2
2025 "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber Insurance
abstract
Individuals can become victims of security incidents, privacy violations, online scams, and social media abuse. In addition to prevention, users should create response strategies in case misfortune strikes. To better understand response to digital harm, we conducted the first study of personal cyber insurance in the US and the UK. We explored the supply-side via a content analysis of 24 cyber insurance policies. The results show personal cyber insurance compensates security, privacy and fraud incidents, with a slim majority also covering cyberbullying. Comparing these results to prior work, we find that coverage in the US and UK has significant differences to coverage in Germany. We study the demand-side via a survey distributed to 584 participants with an even US/UK split. Just 1.6% of respondents have cyber coverage and 8.5% are aware of the product. We introduce the concepts of risk uncertainty and coverage uncertainty, finding both are prevalent for personal cyber insurance. Studying coverage uncertainty, we discover a gap between insurers and participants, which is broadest for online fraud and narrowest for identity theft and cyber-bullying. Turning to risk uncertainty, we discovered that in the aggregate users are relatively well calibrated regarding the frequency of different incidents. Individuals estimate that fraud incidents have the greatest impact, followed by security and privacy incidents. Cyberbullying has very low estimated impact. Regarding purchasing a policy, participants raised uncertainties about contractual details, reporting requirements, victimization statistics, and access to security solutions.
Rachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins, Rainer Böhme, Daniel W. Woods
SP5
2024 Exploring Diffusion-Inspired Pixel Predictors for WS Steganalysis
abstract
Analytical estimators of the steganographic change rate in images, such as WS steganalysis, often operate on the noise residual. The residual can be obtained by estimating the cover content with pixel predictors and subtracting it from the image under analysis. In recent years, we have witnessed the success of new deep learning-based denoisers, such as U-Net, in various fields of image processing. In this study, we revisit WS steganalysis using a U-Net variant as a drop-in replacement for the linear filters originally proposed for cover prediction. A novel property of this U-Net variant is its hand-crafted loss function, which ensures that when predicting from stego images, the prediction errors are uncorrelated with the stego noise, an assumption required by WS steganalysis. Improving especially in the textured regions, the proposed predictor produces accurate and consistent change rate estimates. When used as a detector, our model significantly reduces false positives and thus potentially sets a new baseline for LSB replacement steganalysis.
Martin Benes 0001, Rainer Böhme
IH&MMSec2
2024 Landscape More Secure Than Portrait? Zooming Into the Directionality of Digital Images With Security Implications
Benedikt Lorch, Rainer Böhme
USENIX Security Symposium2
2024 Economics of incident response panels in cyber insurance
abstract
Cyber insurance is becoming a popular cyber risk management tool. Beyond pure financial risk transfer, prior theoretical works anticipated that cyber insurance would influence the mitigation measures employed by policyholders, such as by excluding losses caused by security mismanagement or by offering premium discounts for security controls. Empirical literature has shown cyber insurance is ineffective at influencing pre-breach security levels; however, it has also identified how insurers indemnify the cost of a team of post-breach providers with expertise spanning legal, technical, and communications. Our work models the peculiarities of the institution, the panel, that triages incidents and assigns firms. In particular, we model the incomplete aspect of this contract in which policyholders may be assigned a less efficient firm, which can be interpreted as a bait and switch. At the same time, our context for the bait and switch is business-to-business (B2B) and differs from the usual understanding of the phenomenon as an upsell. Consequently, new managerial implications arise on the insurer-side of the market. We characterise the conditions under which policyholders accept their insurer's hotline recommendation for incident response under the incomplete contract. We additionally show how panels can mitigate the adverse selection problem with respect to policyholders' losses by including providers of differentiated efficiency.
Daniel G. Arce, Daniel W. Woods, Rainer Böhme
Comput. Secur.3
2023 Progressive JPEGs in the Wild: Implications for Information Hiding and Forensics
abstract
JPEG images stored in progressive mode have become more prevalent recently. An estimated 30% of all JPEG images on the most popular websites use progressive mode. Presumably, this surge is caused by the adoption of MozJPEG, an open-source library designed for web publishers. So far, the optimizations used by MozJPEG have not been considered by the multimedia security community, although they are highly relevant. The goal of this paper is to document these optimizations and make them accessible to the research community. Most notably, we find that Trellis optimization in MozJPEG modifies quantized DCT coefficients in order to improve the rate-distortion tradeoff using a perceptual model based on PSNR-HVS. This may compromise the reliability of known methods in steganography, steganalysis, and image forensics when dealing with images compressed with MozJPEG. We also find that the type and order of scans in progressive mode, which MozJPEG adjusts to the image, offer novel cues that can aid forensic source identification.
Nora Hofer, Rainer Böhme
IH&MMSec2
2023 Causes and Effects of Unanticipated Numerical Deviations in Neural Network Inference Frameworks
abstract
Hardware-specific optimizations in machine learning (ML) frameworks can cause numerical deviations of inference results. Quite surprisingly, despite using a fixed trained model and fixed input data, inference results are not consistent across platforms, and sometimes not even deterministic on the same platform. We study the causes of these numerical deviations for convolutional neural networks (CNN) on realistic end-to-end inference pipelines and in isolated experiments. Results from 75 distinct platforms suggest that the main causes of deviations on CPUs are differences in SIMD use, and the selection of convolution algorithms at runtime on GPUs. We link the causes and propagation effects to properties of the ML model and evaluate potential mitigations. We make our research code publicly available.
Alexander Schlögl, Nora Hofer, Rainer Böhme
NeurIPS3
2023 What can central bank digital currency designers learn from asking potential users?
Svetlana Abramova, Rainer Böhme, Helmut Elsinger, Helmut Stix, Martin Summer
SOUPS2
2023 Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet Case
Svetlana Abramova, Rainer Böhme
USENIX Security Symposium2
2023 Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach Attorneys
Daniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel Schwarcz
USENIX Security Symposium2
2022 Parallel Proof-of-Work with Concrete Bounds
abstract
Authorization is challenging in distributed systems that cannot rely on the identification of nodes. Proof-of-work offers an alternative gate-keeping mechanism, but its probabilistic nature is incompatible with conventional security definitions. Recent related work establishes concrete bounds for the failure probability of Bitcoin's sequential proof-of-work mechanism. We propose a new family of state replication protocols that use parallel proof-of-work. Our bottom-up design from an agreement sub-protocol allows us to give concrete bounds for the failure probability in adversarial synchronous networks. State updates can be sufficiently secure to support commits after one block, removing the risk of double-spending in many applications. We offer guidance on the optimal choice of parameters for a wide range of network and attacker assumptions. Simulations show that the proposed construction is robust even against partial violations of our design assumptions.
Patrik Keller, Rainer Böhme
AFT2
2022 Know Your Library: How the libjpeg Version Influences Compression and Decompression Results
abstract
Introduced in 1991, libjpeg has become a well-established library for processing JPEG images. Many libraries in high-level languages use libjpeg under the hood. So far, little attention has been paid to the fact that different versions of the library produce different outputs for the same input. This may have implications on security-related applications, such as image forensics or steganalysis, where evidence is generated by tracking small, imperceptible changes in JPEG-compressed signals. This paper systematically analyses all libjpeg versions since 1998, including the forked libjpeg-turbo (in its latest version). It compares the outputs of compression and decompression operations for a range of parameter settings. We identify up to three distinct behaviors for compression and up to six for decompression.
Martin Benes 0001, Nora Hofer, Rainer Böhme
IH&MMSec3
2022 The commodification of consent
abstract
In the commodification of consent, a legal concept designed to empower users has been transformed into an asset that can be traded across firms. Users interact with a consent dialog offered by one coalition member. The default setting allows any other coalition member, including both publishers and third-party vendors, to use this consent as a legal basis for processing personal data. In doing so, the commodification of consent creates interdependent privacy considerations within the notice and consent paradigm. This paper considers how this legal innovation could change the distribution of revenues among firms. Our model shows coalitions create the most value for firms with large consent deficits, which describes the proportion of users who the firm does not directly obtain consent from. The market leader in consent can capture all of the coalition fees by forming a series of 2-firm coalitions. Finally, a model extension shows how consent coalitions shift users towards providing consent to the coalition against the users’ wishes even though the probability of erroneously providing consent in a given dialog remains unchanged.
Daniel W. Woods, Rainer Böhme
Comput. Secur.2
2021 Bits Under the Mattress: Understanding Different Risk Perceptions and Security Behaviors of Crypto-Asset Users
abstract
Crypto-assets are unique in tying financial wealth to the secrecy of private keys. Prior empirical work has attempted to study end-user security from both technical and organizational perspectives. However, the link between individuals’ risk perceptions and security behavior was often obscured by the heterogeneity of the subjects in small samples. This paper contributes quantitative results from a survey of 395 crypto-asset users recruited by a novel combination of deep and broad sampling. The analysis accounts for heterogeneity with a new typology that partitions the sample in three robust clusters – cypherpunks, hodlers, and rookies – using five psychometric constructs. The constructs originate from established behavioral theories with items purposefully adapted to the domain. We demonstrate the utility of this typology in better understanding users’ characteristics and security behaviors. These insights inform the design of crypto-asset solutions, guide risk communication, and suggest directions for future digital currencies.
Svetlana Abramova, Artemij Voskobojnikov, Konstantin Beznosov, Rainer Böhme
CHI4
2021 Forensicability of Deep Neural Network Inference Pipelines
abstract
We propose methods to infer properties of the execution environment of machine learning pipelines by tracing characteristic numerical deviations in observable outputs. Results from a series of proof-of-concept experiments obtained on local and cloud-hosted machines give rise to possible forensic applications, such as the identification of the hardware platform used to produce deep neural network predictions. Finally, we introduce boundary samples that amplify the numerical deviations in order to distinguish machines by their predicted label only.
Alexander Schlögl, Tobias Kupek, Rainer Böhme
ICASSP3
2021 iNNformant: Boundary Samples as Telltale Watermarks
abstract
Boundary samples are special inputs to artificial neural networks crafted to identify the execution environment used for inference by the resulting output label. The paper presents and evaluates algorithms to generate transparent boundary samples. Transparency refers to a small perceptual distortion of the host signal (i.e., a natural input sample). For two established image classifiers, ResNet on FMNIST and CIFAR10, we show that it is possible to generate sets of boundary samples which can identify any of four tested microarchitectures. These sets can be built to not contain any sample with a worse peak signal-to-noise ratio than 70dB. We analyze the relationship between search complexity and resulting transparency.
Alexander Schlögl, Tobias Kupek, Rainer Böhme
IH&MMSec3
2021 SoK: Quantifying Cyber Risk
abstract
This paper introduces a causal model inspired by structural equation modeling that explains cyber risk outcomes in terms of latent factors measured using reflexive indicators. First, we use the model to classify empirical cyber harm studies. We discover cyber harms are not exceptional in terms of typical or extreme losses. The increasing frequency of data breaches is contested and stock market reactions to cyber incidents are becoming less damaging over time. Focusing on harms alone breeds fatalism; the causal model is most useful in evaluating the effectiveness of security interventions. We show how simple statistical relationships lead to spurious results in which more security spending or applying updates are associated with greater rates of compromise. When accounting for threat and exposure, indicators of security are shown to be important factors in explaining the variance in rates of compromise, especially when the studies use multiple indicators of the security level.
Daniel W. Woods, Rainer Böhme
SP2
2021 Privacy Preference Signals: Past, Present and Future
abstract
Abstract Privacy preference signals are digital representations of how users want their personal data to be processed. Such signals must be adopted by both the sender (users) and intended recipients (data processors). Adoption represents a coordination problem that remains unsolved despite efforts dating back to the 1990s. Browsers implemented standards like the Platform for Privacy Preferences (P3P) and Do Not Track (DNT), but vendors profiting from personal data faced few incentives to receive and respect the expressed wishes of data subjects. In the wake of recent privacy laws, a coalition of AdTech firms published the Transparency and Consent Framework (TCF), which defines an optin consent signal. This paper integrates post-GDPR developments into the wider history of privacy preference signals. Our main contribution is a high-frequency longitudinal study describing how TCF signal gained dominance as of February 2021. We explore which factors correlate with adoption at the website level. Both the number of third parties on a website and the presence of Google Ads are associated with higher adoption of TCF. Further, we show that vendors acted as early adopters of TCF 2.0 and provide two case-studies describing how Consent Management Providers shifted existing customers to TCF 2.0. We sketch ways forward for a pro-privacy signal.
Maximilian Hils, Daniel W. Woods, Rainer Böhme
Proc. Priv. Enhancing Technol.3
2020 Watching the Weak Link into Your Home: An Inspection and Monitoring Toolkit for TR-069
Maximilian Hils, Rainer Böhme
ACNS (2)2
2020 On the Difficulty of Hiding Keys in Neural Networks
abstract
In order to defend neural networks against malicious attacks, recent approaches propose the use of secret keys in the training or inference pipelines of learning systems. While this concept is innovative and the results are promising in terms of attack mitigation and classification accuracy, the effectiveness relies on the secrecy of the key. However, this aspect is often not discussed. In this short paper, we explore this issue for the case of a recently proposed key-based deep neural network. White-box experiments on multiple models and datasets, using the original key-based method and our own extensions, show that it is currently possible to extract secret key bits with relatively limited effort.
Tobias Kupek, Cecilia Pasquini, Rainer Böhme
IH&MMSec3
2020 Measuring the Emergence of Consent Management on the Web
abstract
Privacy laws like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) have pushed internet firms processing personal data to obtain user consent. Uncertainty around sanctions for non-compliance led many websites to embed a Consent Management Provider (CMP), which collects users' consent and shares it with third-party vendors and other websites. Our paper maps the formation of this ecosystem using longitudinal measurements. Primary and secondary data sources are used to measure each actor within the ecosystem. Using 161 million browser crawls, we estimate that CMP adoption doubled from June 2018 to June 2019 and then doubled again until June 2020. Sampling 4.2 million unique domains, we observe that CMP adoption is most prevalent among moderately popular websites (Tranco top 50-10k) but a long tail exists. Using APIs from the ad-tech industry, we quantify the purposes and lawful bases used to justify processing personal data. A controlled experiment on a public website provides novel insights into how the time-to-complete of two leading CMPs' consent dialogues varies with the preferences expressed, showing how privacy aware users incur a significant time cost.
Maximilian Hils, Daniel W. Woods, Rainer Böhme
Internet Measurement Conference3
2020 Trembling triggers: exploring the sensitivity of backdoors in DNN-based face recognition
abstract
Abstract Backdoor attacks against supervised machine learning methods seek to modify the training samples in such a way that, at inference time, the presence of a specific pattern (trigger) in the input data causes misclassifications to a target class chosen by the adversary. Successful backdoor attacks have been presented in particular for face recognition systems based on deep neural networks (DNNs). These attacks were evaluated for identical triggers at training and inference time. However, the vulnerability to backdoor attacks in practice crucially depends on the sensitivity of the backdoored classifier to approximate trigger inputs. To assess this, we study the response of a backdoored DNN for face recognition to trigger signals that have been transformed with typical image processing operators of varying strength. Results for different kinds of geometric and color transformations suggest that in particular geometric misplacements and partial occlusions of the trigger limit the effectiveness of the backdoor attacks considered. Moreover, our analysis reveals that the spatial interaction of the trigger with the subject’s face affects the success of the attack. Experiments with physical triggers inserted in live acquisitions validate the observed response of the DNN when triggers are inserted digitally.
Cecilia Pasquini, Rainer Böhme
EURASIP J. Inf. Secur.2
2020 Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR
abstract
Abstract The European Union’s General Data Protection Regulation (GDPR) requires websites to ask for consent to the use of cookies forspecific purposes. This enlarges the relevant design space for consent dialogs. Websites could try to maximize click-through rates and positive consent decision, even at the risk of users agreeing to more purposes than intended. We evaluate a practice observed on popular websites by conducting an experiment with one control and two treatment groups (N= 150 university students in two countries). We hypothesize that users’ consent decision is influenced by (1) the number of options, connecting to the theory of choice proliferation, and (2) the presence of a highlighted default button (“select all”), connecting to theories of social norms and deception in consumer research. The results show that participants who see a default button accept cookies for more purposes than the control group, while being less able to correctly recall their choice. After being reminded of their choice, they regret it more often and perceive the consent dialog as more deceptive than the control group. Whether users are presented one or three purposes has no significant effect on their decisions and perceptions. We discuss the results and outline policy implications.
Dominique Machuletz, Rainer Böhme
Proc. Priv. Enhancing Technol.2
2019 Information-Theoretic Bounds for the Forensic Detection of Downscaled Signals
abstract
The detection of rescaling operations represents an important task in multimedia forensics. While many effective heuristics have been proposed, there is no theory on the forensic detectability revealing the conditions of more or less reliable detection. We study the problem of discriminating 1D and 2D genuine signals from signals that have been downscaled with the goal of quantifying the statistical distinguishability between these two hypotheses. This is done by assuming known signal models and deriving the expressions of statistical distances that are linked to the hypothesis testing theory, namely, the symmetrized form of Kullback-Leibler divergence known as the Jeffreys divergence, and the Bhattacharyya divergence. The analysis is performed for varying parameters of both the genuine signal model (variance and one-step correlation) and the rescaling process (rescaling factor, interpolation kernel, grid shift, and anti-alias filter), thus allowing us to reveal the insights on their influence and interplay. In addition to the signal itself, we consider the signal transformations (prefilter and covariance matrix estimators) that are often involved in practical rescaling detectors, showing that they yield similar results in terms of distinguishability. Numerical tests on synthetic and real signals confirm the main observations from the theoretical analysis.
Cecilia Pasquini, Rainer Böhme
IEEE Trans. Inf. Forensics Secur.2
2018 Webcam Covering as Planned Behavior
abstract
Most of today's laptops come with an integrated webcam placed above the screen to enable video conferencing. Due to the risk of webcam spying attacks, some laptop users seem to be concerned about their privacy and seek protection by covering the webcam. This paper is the first to investigate personal characteristics and beliefs of users with and without webcam covers by applying the Theory of Planned Behavior. We record the privacy behavior of 180 users, develop a path model, and analyze it by applying Partial Least Squares. The analysis indicates that privacy concerns do not significantly influence users' decision to use a webcam cover. Rather, this behavior is influenced by users' attitudes, social environment, and perceived control over protecting privacy. Developers should take this as a lesson to design privacy enhancing technologies which are convenient, verifiably effective and endorsed by peers.
Dominique Machuletz, Stefan Laube, Rainer Böhme
CHI3
2018 Towards A Theory of Jpeg Block Convergence
abstract
The convergence statistics of JPEG blocks has been shown to be a useful tool to forensically analyze high quality compressed images. Since current approaches are based on empirical observations, we propose a theoretical analysis explaining the case of grayscale images and maximum quality JPEG compression (i.e., quality factor equal to 100). The approximate distribution of the stable block ratio at different compression stages is derived, showing that it ultimately depends on the variance of the quantization noise in the DCT domain. We apply such results to discriminate never compressed images and images compressed once with maximum quality, by resorting to results on JPEG error statistics. Tests on image patches with different size and content validate the theoretical results, which allow for obtaining high accuracy through a calibration-free maximum likelihood classification rule.
Cecilia Pasquini, Rainer Böhme
ICIP2
2018 Special Issue on the Economics of Security and Privacy: Guest Editors' Introduction
abstract
This editorial introduces the special issue on the economics of security and privacy.
Rainer Böhme, Richard Clayton 0001, Jens Grossklags, Katrina Ligett, Patrick Loiseau, Galina Schwartz
ACM Trans. Internet Techn.1
2018 Rotten Apples or Bad Harvest? What We Are Measuring When We Are Measuring Abuse
abstract
Internet security and technology policy research regularly uses technical indicators of abuse to identify culprits and to tailor mitigation strategies. As a major obstacle, current inferences from abuse data that aim to characterize providers with poor security practices often use a naive normalization of abuse (abuse counts divided by network size) and do not take into account other inherent or structural properties of providers. Even the size estimates are subject to measurement errors relating to attribution, aggregation, and various sources of heterogeneity. More precise indicators are costly to measure at Internet scale. We address these issues for the case of hosting providers with a statistical model of the abuse data generation process, using phishing sites in hosting networks as a case study. We decompose error sources and then estimate key parameters of the model, controlling for heterogeneity in size and business model. We find that 84% of the variation in abuse counts across 45,358 hosting providers can be explained with structural factors alone. Informed by the fitted model, we systematically select and enrich a subset of 105 homogeneous “statistical twins” with additional explanatory variables, unreasonable to collect for all hosting providers. We find that abuse is positively associated with the popularity of websites hosted and with the prevalence of popular content management systems. Moreover, hosting providers who charge higher prices (after controlling for level differences between countries) witness less abuse. These structural factors together explain a further 77% of the remaining variation. This calls into question premature inferences from raw abuse indicators about the security efforts of actors, and suggests the adoption of similar analysis frameworks in all domains where network measurement aims at informing technology policy.
Samaneh Tajalizadehkhoob, Rainer Böhme, Carlos Gañán, Maciej Korczynski, Michel van Eeten
ACM Trans. Internet Techn.2
2017 Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared Hosting
abstract
Hosting providers play a key role in fighting web compromise, but their ability to prevent abuse is constrained by the security practices of their own customers. Shared hosting, offers a unique perspective since customers operate under restricted privileges and providers retain more control over configurations. We present the first empirical analysis of the distribution of web security features and software patching practices in shared hosting providers, the influence of providers on these security practices, and their impact on web compromise rates. We construct provider-level features on the global market for shared hosting -- containing 1,259 providers -- by gathering indicators from 442,684 domains. Exploratory factor analysis of 15 indicators identifies four main latent factors that capture security efforts: content security, webmaster security, web infrastructure security and web application security. We confirm, via a fixed-effect regression model, that providers exert significant influence over the latter two factors, which are both related to the software stack in their hosting environment. Finally, by means of GLM regression analysis of these factors on phishing and malware abuse, we show that the four security and software patching factors explain between 10% and 19% of the variance in abuse at providers, after controlling for size. For web-application security for instance, we found that when a provider moves from the bottom 10% to the best-performing 10%, it would experience 4 times fewer phishing incidents. We show that providers have influence over patch levels--even higher in the stack, where CMSes can run as client-side software--and that this influence is tied to a substantial reduction in abuse levels.
Samaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian, Rainer Böhme, Tyler Moore 0001, Wouter Joosen, Michel van Eeten
CCS5
2017 Information-theoretic Bounds of Resampling Forensics: New Evidence for Traces Beyond Cyclostationarity
abstract
Although several methods have been proposed for the detection of resampling operations in multimedia signals and the estimation of the resampling factor, the fundamental limits for this forensic task leave open research questions. In this work, we explore the effects that a downsampling operation introduces in the statistics of a 1D signal as a function of the parameters used. We quantify the statistical distance between an original signal and its downsampled version by means of the Kullback-Leibler Divergence (KLD) in case of a wide-sense stationary 1st-order autoregressive signal model. Values of the KLD are derived for different signal parameters, resampling factors and interpolation kernels, thus predicting the achievable hypothesis distinguishability in each case. Our analysis reveals unexpected detectability in case of strong downsampling due to the local correlation structure of the original signal. Moreover, since existing detection methods generally leverage the cyclostationarity of resampled signals, we also address the case where the autocovariance values are estimated directly by means of the sample autocovariance from the signal under investigation. Under the considered assumptions, the Wishart distribution models the sample covariance matrix of a signal segment and the KLD under different hypotheses is derived.
Cecilia Pasquini, Rainer Böhme
IH&MMSec2
2017 On the Statistical Properties of Syndrome Trellis Coding
Olaf Markus Köhler, Cecilia Pasquini, Rainer Böhme
IWDW3
2017 Decoy Password Vaults: At Least as Hard as Steganography?
Cecilia Pasquini, Pascal Schöttle, Rainer Böhme
SEC3
2016 Forensics of High Quality and Nearly Identical JPEG Image Recompression
abstract
We address the known problem of detecting a previous compression in JPEG images, focusing on the challenging case of high and very high quality factors (>= 90) as well as repeated compression with identical or nearly identical quality factors. We first revisit the approaches based on Benford--Fourier analysis in the DCT domain and block convergence analysis in the spatial domain. Both were originally conceived for specific scenarios. Leveraging decision tree theory, we design a combined approach complementing the discriminatory capabilities. We obtain a set of novel detectors targeted to high quality grayscale JPEG images.
Cecilia Pasquini, Pascal Schöttle, Rainer Böhme, Giulia Boato, Fernando Pérez-González
IH&MMSec3
2016 Measuring the Influence of Perceived Cybercrime Risk on Online Service Avoidance
abstract
Cybercrime is a pervasive threat for today's Internet-dependent society. While the real extent and economic impact is hard to quantify, scientists and officials agree that cybercrime is a huge and still growing problem. A substantial fraction of cybercrime's overall costs to society can be traced to indirect opportunity costs, resulting from unused online services. This paper presents a parsimonious model that builds on technology acceptance research and insights from criminology to identify factors that reduce Internet users' intention to use online services. We hypothesize that avoidance of online banking, online shopping and online social networking is increased by cybercrime victimization and media reports. The effects are mediated by the perceived risk of cybercrime and moderated by the user's confidence online. We test our hypotheses using a structural equation modeling analysis of a representative pan-European sample. Our empirical results confirm the negative impact of perceived risk of cybercrime on the use of all three online service categories and support the role of cybercrime experience as an antecedent of perceived risk of cybercrime. We further show that more confident Internet users perceive less cybercriminal risk and are more likely to use online banking and online shopping, which highlights the importance of consumer education.
Markus Riek, Rainer Böhme, Tyler Moore 0001
IEEE Trans. Dependable Secur. Comput.2
2016 Game Theory and Adaptive Steganography
abstract
According to conventional wisdom, content-adaptive embedding offers more steganographic security than random uniform embedding. We scrutinize this view and note that it is barely substantiated in the literature as only recently adaptive steganographic systems are tested against an attacker who anticipates the adaptivity and incorporates this knowledge into the detection strategy. For a better theoretical understanding of strategical embedding and detection, we propose a game-theoretic framework to study adaptive steganography while taking the knowledge of the steganalyst into account. We instantiate the framework with a stylized cover model and study both parties' optimal strategies. The model has a unique equilibrium in mixed strategies, which depends on the heterogeneity of the cover source. We add realism by introducing imperfect recoverability of the adaptivity criterion and prove that naïve adaptive embedding-the strategy implemented in many practical schemes-is only optimal if perfect steganography is possible or if the adaptivity criterion is not recoverable at all. In practice, where steganography is imperfect and adaptivity criteria are partially recoverable, the optimal embedding strategy is between naïve adaptive and random uniform embedding.
Pascal Schöttle, Rainer Böhme
IEEE Trans. Inf. Forensics Secur.2
2014 "Steganalysis in Technicolor" Boosting WS detection of stego images from CFA-interpolated covers
abstract
Steganographic security in empirical covers is best understood for grayscale images. However, the world, and almost all digital images of it, are more colorful. This paper extends the weighted stego-image (WS) steganalysis method to detect stego images produced from covers that exhibit traces of color filter array (CFA) interpolation, which is common for images acquired with digital cameras. The approach combines techniques of CFA forensics with state-of-the-art WS steganalysis. Empirical results from large datasets indicate significant increases in detection performance, in particular for small payloads. This specific weakness of color covers calls into question the common assumption that grayscale image steganography generalizes to color images by treating each chroma channel independently.
Matthias Kirchner, Rainer Böhme
ICASSP2
2014 Predictable rain?: steganalysis of public-key steganography using wet paper codes
abstract
Symmetric steganographic communication requires a secret stego-key pre-shared between the communicating parties. Public-key steganography (PKS) overcomes this inconvenience. In this case, the steganographic security is based solely on the underlying asymmetric encryption function. This implies that the embedding positions are either public or hidden by clever coding, for instance using Wet Paper Codes (WPC), but with public code parameters. We show that using WPC with efficient encoding algorithms may leak information which can facilitate an attack. The public parameters allow an attacker to predict among the possible embedding positions the ones most likely used for embedding. This approach is independent of the embedding operation. We demonstrate it for the case of least significant bit (LSB) replacement and present two new variants of Weighted Stego-Image (WS) steganalysis specifically tailored to detect PKS using efficient WPC. Experiments show that our WS variants can detect PKS with higher accuracy than known methods, especially for low embedding rates. The attack is applicable even if a hybrid stegosystem is constructed and public-key cryptography is only used to encapsulate a secret stego-key.
Matthias Carnein, Pascal Schöttle, Rainer Böhme
IH&MMSec3
2014 Too Much Choice: End-User Privacy Decisions in the Context of Choice Proliferation
Stefan Korff, Rainer Böhme
SOUPS2
2014 Secure Team Composition to Thwart Insider Threats and Cyber-Espionage
abstract
We develop a formal nondeterministic game model for secure team composition to counter cyber-espionage and to protect organizational secrets against an attacker who tries to sidestep technical security mechanisms by offering a bribe to a project team member. The game captures the adversarial interaction between the attacker and the project manager who has a secret she wants to protect but must share with a team of individuals selected from within her organization. Our interdisciplinary work is important in the face of the multipronged approaches utilized by well-motivated attackers to circumvent the fortifications of otherwise well-defended targets.
Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme
ACM Trans. Internet Techn.5
2013 Managing the Weakest Link - A Game-Theoretic Approach for the Mitigation of Insider Threats
Aron Laszka, Benjamin Johnson 0001, Pascal Schöttle, Jens Grossklags, Rainer Böhme
ESORICS5
2013 Block convergence in repeated transform coding: JPEG-100 forensics, carbon dating, and tamper detection
abstract
Repeated rounding of sample blocks in alternating domains creates complex convergence paths. We study convergence and block stability for JPEG images compressed with quality factor 100 and derive methods to detect such compression in grayscale bitmap images, to estimate the number of recompressions, to identify the DCT implementation used for compression, and to uncover local tampering if image parts have been compressed with JPEG-100 at least once.
Shiyue Lai, Rainer Böhme
ICASSP2
2013 Moving steganography and steganalysis from the laboratory into the real world
abstract
There has been an explosion of academic literature on steganography and steganalysis in the past two decades. With a few exceptions, such papers address abstractions of the hiding and detection problems, which arguably have become disconnected from the real world. Most published results, including by the authors of this paper, apply "in laboratory conditions" and some are heavily hedged by assumptions and caveats; significant challenges remain unsolved in order to implement good steganography and steganalysis in practice. This position paper sets out some of the important questions which have been left unanswered, as well as highlighting some that have already been addressed successfully, for steganography and steganalysis to be used in the real world.
Andrew D. Ker, Patrick Bas, Rainer Böhme, Rémi Cogranne, Scott Craver, Tomás Filler, Jessica J. Fridrich, Tomás Pevný
IH&MMSec3
2013 Bitspotting: Detecting Optimal Adaptive Steganography
Benjamin Johnson 0001, Pascal Schöttle, Aron Laszka, Jens Grossklags, Rainer Böhme
IWDW5
2013 Trading Agent Kills Market Information - Evidence from Online Social Lending
Rainer Böhme, Jens Grossklags
WINE1
2011 The security cost of cheap user interaction
abstract
Human attention is a scarce resource, and lack thereof can cause severe security breaches. As most security techniques rely on considerate human intervention in one way or another, this resource should be consumed economically. In this context, we postulate the view that every false alarm or unnecessary user interaction imposes a negative externality on all other potential consumers of this chunk of attention. The paper identifies incentive problems that stimulate overconsumption of human attention in security applications. It further outlines a lump-of-attention model, devised against the backdrop of established theories in the behavioral sciences, and discusses incentive mechanisms to fix the misallocation problem in security notification, for instance the idea of a Pigovian tax on attention consumption.
Rainer Böhme, Jens Grossklags
NSPW1
2010 Trained to accept?: a field experiment on consent dialogs
abstract
A typical consent dialog was shown in 2 x 2 x 3 experimental variations to 80,000 users of an online privacy tool. We find that polite requests and button texts pointing to a voluntary decision decrease the probability of consent---in contrast to findings in social psychology. Our data suggests that subtle positive effects of polite requests indeed exist, but stronger negative effects of heuristic processing dominate the aggregated results. Participants seem to be habituated to coercive interception dialogs---presumably due to ubiquitous EULAs---and blindly accept terms the more their presentation resembles a EULA. Response latency and consultation of online help were taken as indicators to distinguish more systematic from heuristic responses.
Rainer Böhme, Stefan Köpsell
CHI1
2008 Hiding Traces of Resampling in Digital Images
abstract
Resampling detection has become a standard tool for forensic analyses of digital images. This paper presents new variants of image transformation operations which are undetectable by resampling detectors based on periodic variations in the residual signal of local linear predictors in the spatial domain. The effectiveness of the proposed method is supported with evidence from experiments on a large image database for various parameter settings. We benchmark detectability as well as the resulting image quality against conventional linear and bicubic interpolation and interpolation with a sinc kernel. These early findings on ldquocounter-forensicrdquo techniques put into question the reliability of known forensic tools against smart counterfeiters in general, and might serve as benchmarks and motivation for the development of much improved forensic techniques.
Matthias Kirchner, Rainer Böhme
IEEE Trans. Inf. Forensics Secur.2
2007 Can we trust digital image forensics?
abstract
Compared to the prominent role digital images play in nowadays multimedia society, research in the field of image authenticity is still in its infancy. Only recently, research on digital image forensics has gained attention by addressing tamper detection and image source identification. However, most publications in this emerging field still lack rigorous discussions of robustness against strategic counterfeiters, who anticipate the existence of forensic techniques. As a result, the question of trustworthiness of digital image forensics arises. This work will take a closer look at two state-of-the-art forensic methods and proposes two counter-techniques; one to perform resampling operations undetectably and another one to forge traces of image origin. Implications for future image forensic systems will be discussed.
Thomas Gloe, Matthias Kirchner, Antje Winkler, Rainer Böhme
ACM Multimedia4
2007 On the Security of "A Steganographic Scheme for Secure Communications Based on the Chaos and the Euler Theorem"
abstract
This paper contains a security analysis of the construction of a public key steganographic system based on chaos theory and the Euler theorem (PKS-CE) as proposed by Lou and Sung in a previous issue of this transactions. Our analysis results in attack strategies on two different layers: first, we identify weaknesses of the embedding function, which allow a passive warden to tell steganographic images from clean carriers apart. Second, we show that the allegedly asymmetric trap-door function in fact can be efficiently inverted solely with the knowledge of its public parameters, thus revealing the secret message as plain text to a passive adversary. Experimental results from a re-implementation further indicate that the claimed robustness of the embedded message against transformations of the carrier medium was far too optimistic. Finally, we demonstrate that a secure alternative system can easily be constructed from standard primitives if the strong assumptions made in PKS-CE for the mutual key exchange can actually be fulfilled.
Rainer Böhme, Christian Keiler
IEEE Trans. Multim.1
2006 On the Limits of Cyber-Insurance
Rainer Böhme, Gaurav Kataria
TrustBus1
2005 Feature-based encoder classification of compressed audio streams
Rainer Böhme, Andreas Westfeld
Multim. Syst.1
2004 Breaking Cauchy Model-Based JPEG Steganography with First Order Statistics
Rainer Böhme, Andreas Westfeld
ESORICS1