{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T01:12:12Z","timestamp":1743037932266,"version":"3.40.3"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030687793"},{"type":"electronic","value":"9783030687809"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-68780-9_37","type":"book-chapter","created":{"date-parts":[[2021,2,24]],"date-time":"2021-02-24T17:04:13Z","timestamp":1614186253000},"page":"453-469","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Forensics Through Stega Glasses: The Case of Adversarial Images"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2569-6185","authenticated-orcid":false,"given":"Beno\u00eet","family":"Bonnet","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1565-765X","authenticated-orcid":false,"given":"Teddy","family":"Furon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0873-5872","authenticated-orcid":false,"given":"Patrick","family":"Bas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,2,25]]},"reference":[{"key":"37_CR1","doi-asserted-by":"crossref","unstructured":"G\u00fcera, D.,\u00a0Wang, Y.,\u00a0Bondi, L.,\u00a0Bestagini, P.,\u00a0Tubaro, S.,\u00a0Delp, E.J.: A counter-forensic method for CNN-based camera model identification. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pp. 1840\u20131847.\u00a0IEEE (2017)","DOI":"10.1109\/CVPRW.2017.230"},{"key":"37_CR2","doi-asserted-by":"crossref","unstructured":"Barni, M., Stamm, M.C.,\u00a0Tondi, B.: Adversarial multimedia forensics: overview and challenges ahead. In: 2018 26th European Signal Processing Conference (EUSIPCO), pp. 962\u2013966.\u00a0IEEE (2018)","DOI":"10.23919\/EUSIPCO.2018.8553305"},{"key":"37_CR3","doi-asserted-by":"crossref","unstructured":"Quiring, E., Arp, D., Rieck, K.: Forgotten siblings: unifying attacks on machine learning and digital watermarking. In: IEEE European Symposium on Security and Privacy (2018)","DOI":"10.1109\/EuroSP.2018.00041"},{"key":"37_CR4","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Adversarial examples are not easily detected: bypassing ten detection methods. arXiv:1705.07263 (2017)","DOI":"10.1145\/3128572.3140444"},{"key":"37_CR5","unstructured":"Athalye, A., Carlini, N., Wagner, D.A.: Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: ICML, pp. 274\u2013283 (2018)"},{"key":"37_CR6","unstructured":"Tramer, F., Carlini, N., Brendel, W., Madry, A.: On adaptive attacks to adversarial example defenses (2020)"},{"key":"37_CR7","unstructured":"Tan, M., Le, Q.V.: Efficientnet: rethinking model scaling for convolutional neural networks. arXiv (2019)"},{"key":"37_CR8","doi-asserted-by":"crossref","unstructured":"Xie, C., Tan, M., Gong, B., Wang, J., Yuille, A., Le, Q.V.: Adversarial examples improve image recognition. arXiv (2019)","DOI":"10.1109\/CVPR42600.2020.00090"},{"issue":"5","key":"37_CR9","doi-asserted-by":"publisher","first-page":"1181","DOI":"10.1109\/TIFS.2018.2871749","volume":"14","author":"M Boroumand","year":"2018","unstructured":"Boroumand, M., Chen, M., Fridrich, J.: Deep residual network for steganalysis of digital images. IEEE Trans. Inf. Forensics Secur. 14(5), 1181\u20131193 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"37_CR10","doi-asserted-by":"crossref","unstructured":"Li, B., Wang, M., Huang, J., Li, X.: A new cost function for spatial image steganography. In: 2014 IEEE International Conference on Image Processing (ICIP), pp. 4206\u20134210. IEEE (2014)","DOI":"10.1109\/ICIP.2014.7025854"},{"issue":"2","key":"37_CR11","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1109\/TIFS.2015.2486744","volume":"11","author":"V Sedighi","year":"2016","unstructured":"Sedighi, V., Cogranne, R., Fridrich, J.: Content-adaptive steganography by minimizing statistical detectability. IEEE Trans. Inf. Forensics Secur. 11(2), 221\u2013234 (2016)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"9","key":"37_CR12","doi-asserted-by":"publisher","first-page":"1905","DOI":"10.1109\/TIFS.2015.2423656","volume":"10","author":"B Li","year":"2015","unstructured":"Li, B., Wang, M., Li, X., Tan, S., Huang, J.: A strategy of clustering modification directions in spatial image steganography. IEEE Trans. Inf. Forensics Secur. 10(9), 1905\u20131917 (2015)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"37_CR13","doi-asserted-by":"publisher","first-page":"2081","DOI":"10.1109\/TIFS.2019.2956590","volume":"15","author":"Y Wang","year":"2019","unstructured":"Wang, Y., Zhang, W., Li, W., Yu, X., Yu, N.: Non-additive cost functions for color image steganography based on inter-channel correlations and differences. IEEE Trans. Inf. Forensics Secur. 15, 2081\u20132095 (2019)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"37_CR14","doi-asserted-by":"crossref","unstructured":"Qiu, X., Li, H., Luo, W., Huang, J.: A universal image forensic strategy based on steganalytic model. In: Proceedings of ACM IH&MMSec 2014, New York, NY, USA, pp. 165\u2013170 (2014)","DOI":"10.1145\/2600918.2600941"},{"key":"37_CR15","doi-asserted-by":"publisher","first-page":"459","DOI":"10.1016\/j.compeleceng.2017.05.008","volume":"62","author":"S Farooq","year":"2017","unstructured":"Farooq, S., Yousaf, M.H., Hussain, F.: A generic passive image forgery detection scheme using local binary pattern with rich models. Comput. Electr. Eng. 62, 459\u2013472 (2017)","journal-title":"Comput. Electr. Eng."},{"issue":"2","key":"37_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3190575","volume":"14","author":"W Luo","year":"2018","unstructured":"Luo, W., Li, H., Yan, Q., Yang, R., Huang, J.: Improved audio steganalytic feature and its applications in audio forensics. ACM Trans. Multimedia Comput. Commun. Appl. 14(2), 1\u201314 (2018)","journal-title":"ACM Trans. Multimedia Comput. Commun. Appl."},{"key":"37_CR17","doi-asserted-by":"crossref","unstructured":"Tuama, A., Comby, F., Chaumont, M.: Camera model identification based machine learning approach with high order statistics features. In: EUSIPCO, pp. 1183\u20131187 (2016)","DOI":"10.1109\/EUSIPCO.2016.7760435"},{"issue":"3","key":"37_CR18","doi-asserted-by":"publisher","first-page":"868","DOI":"10.1109\/TIFS.2012.2190402","volume":"7","author":"J Fridrich","year":"2012","unstructured":"Fridrich, J., Kodovsky, J.: Rich models for steganalysis of digital images. IEEE Trans. Inf. Forensics Secur. 7(3), 868\u2013882 (2012)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"5","key":"37_CR19","doi-asserted-by":"publisher","first-page":"708","DOI":"10.1109\/LSP.2016.2548421","volume":"23","author":"G Xu","year":"2016","unstructured":"Xu, G., Wu, H.-Z., Shi, Y.-Q.: Structural design of convolutional neural networks for steganalysis. IEEE Signal Process. Lett. 23(5), 708\u2013712 (2016)","journal-title":"IEEE Signal Process. Lett."},{"key":"37_CR20","doi-asserted-by":"crossref","unstructured":"Yousfi, Y., Butora, J., Fridrich, J., Giboulot, Q.: Breaking ALASKA: color separation for steganalysis in jpeg domain. In: Proceedings of ACM IH&MMSec 2019, pp. 138\u2013149 (2019)","DOI":"10.1145\/3335203.3335727"},{"key":"37_CR21","doi-asserted-by":"crossref","unstructured":"Fan, W., Wang, K., Cayre, F.: General-purpose image forensics using patch likelihood under image statistical models. In: IEEE International Workshop on Information Forensics and Security (WIFS), pp. 1\u20136 (2015)","DOI":"10.1109\/WIFS.2015.7368606"},{"key":"37_CR22","doi-asserted-by":"crossref","unstructured":"Chen, Z., Tondi, B., Li, X., Ni, R., Zhao, Y., Barni, M.: A gradient-based pixel-domain attack against SVM detection of global image manipulations. In: IEEE WIFS, pp. 1\u20136 (2017)","DOI":"10.1109\/WIFS.2017.8267668"},{"key":"37_CR23","doi-asserted-by":"crossref","unstructured":"Sch\u00f6ttle, P., Schl\u00f6gl, A., Pasquini, C., B\u00f6hme, R.: Detecting adversarial examples - a lesson from multimedia security. In: European Signal Processing Conference (EUSIPCO), pp. 947\u2013951 (2018)","DOI":"10.23919\/EUSIPCO.2018.8553164"},{"key":"37_CR24","doi-asserted-by":"crossref","unstructured":"Liu, J., et al.: Detection based defense against adversarial examples from the steganalysis point of view. In: IEEE\/CVF CVPR, pp. 4820\u20134829 (2019)","DOI":"10.1109\/CVPR.2019.00496"},{"key":"37_CR25","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. In: 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, 7\u20139 May 2015, Conference Track Proceedings (2015). http:\/\/arxiv.org\/abs\/1409.1556"},{"key":"37_CR26","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: ICLR 2015, San Diego, CA, USA (2015)"},{"key":"37_CR27","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: ICLR 2018, Vancouver, Canada, BC (2018)"},{"key":"37_CR28","doi-asserted-by":"crossref","unstructured":"Rony, J., Hafemann, L.G., Oliveira, L.S., Ayed, I.B., Sabourin, R., Granger, E.: Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses. In: Proceedings of the IEEE CVPR (2019)","DOI":"10.1109\/CVPR.2019.00445"},{"key":"37_CR29","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security and Privacy (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"37_CR30","doi-asserted-by":"crossref","unstructured":"Bonnet, B., Furon, T., Bas, P.: What if adversarial samples were digital images? In: Proceedings of ACM IH&MMSec 2020, pp. 55\u201366 (2020)","DOI":"10.1145\/3369412.3395062"},{"key":"37_CR31","unstructured":"Krizhevsky, A., Sutskever, I., Hinton, G.E.: Imagenet classification with deep convolutional neural networks. In: Proceedings of the 25th International Conference on Neural Information Processing Systems - Volume 1, series NIPS 2012, pp. 1097\u20131105. Curran Associates Inc., Red Hook (2012)"},{"key":"37_CR32","doi-asserted-by":"crossref","unstructured":"Szegedy, C.: Going deeper with convolutions. In: 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 1\u20139 (2015)","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"37_CR33","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: IEEE Conference on Computer Vision and Pattern Recognition (CVPR) 2016, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"37_CR34","doi-asserted-by":"crossref","unstructured":"Ma, S., Liu, Y., Tao, G., Lee, W., Zhang, X.: NIC: detecting adversarial samples with neural network invariant checking. In: NDSS 2019, San Diego, California, USA (2019)","DOI":"10.14722\/ndss.2019.23415"},{"key":"37_CR35","doi-asserted-by":"crossref","unstructured":"Meng, D., Chen, H.: Magnet: a two-pronged defense against adversarial examples. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 135\u2013147. ACM (2017)","DOI":"10.1145\/3133956.3134057"},{"key":"37_CR36","doi-asserted-by":"crossref","unstructured":"Taran, O., Rezaeifar, S., Holotyak, T., Voloshynovskiy, S.: Defending against adversarial attacks by randomized diversification. In: IEEE CVPR, Long Beach, USA (2019)","DOI":"10.1109\/CVPR.2019.01148"},{"issue":"1","key":"37_CR37","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13635-020-00106-x","volume":"2020","author":"O Taran","year":"2020","unstructured":"Taran, O., Rezaeifar, S., Holotyak, T., Voloshynovskiy, S.: Machine learning through cryptographic glasses: combating adversarial attacks by key-based diversified aggregation. EURASIP J. Inf. Secur. 2020(1), 1\u201318 (2020). https:\/\/doi.org\/10.1186\/s13635-020-00106-x","journal-title":"EURASIP J. Inf. Secur."},{"issue":"3","key":"37_CR38","doi-asserted-by":"publisher","first-page":"920","DOI":"10.1109\/TIFS.2011.2134094","volume":"6","author":"T Filler","year":"2011","unstructured":"Filler, T., Judas, J., Fridrich, J.: Minimizing additive distortion in steganography using syndrome-trellis codes. IEEE Trans. Inf. Forensics Secur. 6(3), 920\u2013935 (2011)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"8","key":"37_CR39","doi-asserted-by":"publisher","first-page":"2074","DOI":"10.1109\/TIFS.2019.2891237","volume":"14","author":"W Tang","year":"2019","unstructured":"Tang, W., Li, B., Tan, S., Barni, M., Huang, J.: CNN-based adversarial embedding for image steganography. IEEE Trans. Inf. Forensics Secur. 14(8), 2074\u20132087 (2019)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"37_CR40","doi-asserted-by":"publisher","first-page":"812","DOI":"10.1109\/TIFS.2020.3021913","volume":"16","author":"S Bernard","year":"2021","unstructured":"Bernard, S., Bas, P., Klein, J., Pevny, T.: Explicit optimization of min max steganographic game. IEEE Trans. Inf. Forensics Secur. 16, 812\u2013823 (2021)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"37_CR41","doi-asserted-by":"publisher","first-page":"115992","DOI":"10.1016\/j.image.2020.115992","volume":"89","author":"X Shi","year":"2020","unstructured":"Shi, X., Tondi, B., Li, B., Barni, M.: CNN-based steganalysis and parametric adversarial embedding: a game-theoretic framework. Sig. Process. Image Commun. 89, 115992 (2020)","journal-title":"Sig. Process. Image Commun."},{"key":"37_CR42","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy (2018)"},{"key":"37_CR43","unstructured":"Dohmatob, E.: Generalized no free lunch theorem for adversarial robustness. In: Proceedings of International Conference on Machine Learning, Long Beach, California, USA (2019)"},{"key":"37_CR44","doi-asserted-by":"crossref","unstructured":"Cogranne, R., Sedighi, V., Fridrich, J., Pevn\u1ef3, T.: Isensembleclassifier needed for steganalysis in high-dimensional feature spaces? In: 2015 IEEE International Workshop on Information Forensics and Security (WIFS), IEEE, pp. 1\u20136 (2015)","DOI":"10.1109\/WIFS.2015.7368597"},{"key":"37_CR45","doi-asserted-by":"crossref","unstructured":"Goljan, M., Fridrich, J., Cogranne, R.: Rich model for steganalysis of color images. In: 2014 IEEE International Workshop on Information Forensics and Security, WIFS 2014, pp. 185\u2013190, April 2015","DOI":"10.1109\/WIFS.2014.7084325"}],"container-title":["Lecture Notes in Computer Science","Pattern Recognition. ICPR International Workshops and Challenges"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-68780-9_37","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,2,24]],"date-time":"2021-02-24T17:39:34Z","timestamp":1614188374000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-68780-9_37"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030687793","9783030687809"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-68780-9_37","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"25 February 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICPR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Pattern Recognition","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 January 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 January 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ICPR2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.icpr2020.it\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}