papers

Publications (48)

cs.CV2026

SoK: On the Survivability of Backdoor Attacks on Unconstrained Face Recognition Systems

Quentin Le Roux, Yannick Teglia, Teddy Furon +2

The widespread deployment of Deep Learning-based Face Recognition Systems raises many security concerns. While prior research has identified backdoor vulnerabilities on isolated co…

cs.CV2025

Backdoor Attacks on Deep Learning Face Detection

Quentin Le Roux, Yannick Teglia, Teddy Furon +1

Face Recognition Systems that operate in unconstrained environments capture images under varying conditions,such as inconsistent lighting, or diverse face poses. These challenges r…

cs.IT2011

Towards joint decoding of binary Tardos fingerprinting codes

Peter Meerwald, Teddy Furon

The class of joint decoder of probabilistic fingerprinting codes is of utmost importance in theoretical papers to establish the concept of fingerprint capacity. However, no impleme…

cs.CV2019

Walking on the Edge: Fast, Low-Distortion Adversarial Examples

Hanwei Zhang, Yannis Avrithis, Teddy Furon +1

Adversarial examples of deep neural networks are receiving ever increasing attention because they help in understanding and reducing the sensitivity to their input. This is natural…

cs.CV2020

Joint Learning of Assignment and Representation for Biometric Group Membership

Marzieh Gheisari, Teddy Furon, Laurent Amsaleg

This paper proposes a framework for group membership protocols preventing the curious but honest server from reconstructing the enrolled biometric signatures and inferring the iden…

cs.GR2008

The Good, the Bad, and the Ugly: three different approaches to break their watermarking system

Gaëtan Le Guelvouit, Teddy Furon, François Cayre

The Good is Blondie, a wandering gunman with a strong personal sense of honor. The Bad is Angel Eyes, a sadistic hitman who always hits his mark. The Ugly is Tuco, a Mexican bandit…

cs.CV2016

Automatic discovery of discriminative parts as a quadratic assignment problem

Ronan Sicre, Julien Rabin, Yannis Avrithis +2

Part-based image classification consists in representing categories by small sets of discriminative parts upon which a representation of the images is built. This paper addresses t…

cs.CV2022

AggNet: Learning to Aggregate Faces for Group Membership Verification

Marzieh Gheisari, Javad Amirian, Teddy Furon +1

In some face recognition applications, we are interested to verify whether an individual is a member of a group, without revealing their identity. Some existing methods, propose a…

cs.CR2024

Watermarking Makes Language Models Radioactive

Tom Sander, Pierre Fernandez, Alain Durmus +2

We investigate the radioactivity of text generated by large language models (LLM), i.e. whether it is possible to detect that such synthetic input was used to train a subsequent LL…

cs.CV2024

Evaluation of Security of ML-based Watermarking: Copy and Removal Attacks

Vitaliy Kinakh, Brian Pulfer, Yury Belousov +3

The vast amounts of digital content captured from the real world or AI-generated media necessitate methods for copyright protection, traceability, or data provenance verification.…

cs.CR2022

Randomized Smoothing under Attack: How Good is it in Pratice?

Thibault Maho, Teddy Furon, Erwan Le Merrer

Randomized smoothing is a recent and celebrated solution to certify the robustness of any classifier. While it indeed provides a theoretical robustness against adversarial attacks,…

cs.LG2026

Exact Unlearning from Proxies Induces Closeness Guarantees on Approximate Unlearning

Virgile Dine, Teddy Furon

This paper proposes a paradigm shift linking machine unlearning directly to the structure of the data distributions rather than a mere update of the neural network parameters. We s…

cs.CV2018

Fast Spectral Ranking for Similarity Search

Ahmet Iscen, Yannis Avrithis, Giorgos Tolias +2

Despite the success of deep learning on representing images for particular object retrieval, recent studies show that the learned representations still lie on manifolds in a high d…

cs.LG2025

Improving Unlearning with Model Updates Probably Aligned with Gradients

Virgile Dine, Teddy Furon, Charly Faure

We formulate the machine unlearning problem as a general constrained optimization problem. It unifies the first-order methods from the approximate machine unlearning literature. Th…

cs.CV2018

Hybrid Diffusion: Spectral-Temporal Graph Filtering for Manifold Ranking

Ahmet Iscen, Yannis Avrithis, Giorgos Tolias +2

State of the art image retrieval performance is achieved with CNN features and manifold ranking using a k-NN similarity graph that is pre-computed off-line. The two most successful…

cs.CV2019

Privacy Preserving Group Membership Verification and Identification

Marzieh Gheisari, Teddy Furon, Laurent Amsaleg

When convoking privacy, group membership verification checks if a biometric trait corresponds to one member of a group without revealing the identity of that member. Similarly, gro…

cs.CR2012

The Effective Key Length of Watermarking Schemes

Patrick Bas, Teddy Furon

Whereas the embedding distortion, the payload and the robustness of digital watermarking schemes are well understood, the notion of security is still not completely well defined. T…

cs.CR2022

FBI: Fingerprinting models with Benign Inputs

Thibault Maho, Teddy Furon, Erwan Le Merrer

Recent advances in the fingerprinting of deep neural networks detect instances of models, placed in a black-box interaction scheme. Inputs used by the fingerprinting protocols are…

cs.CV2022

Watermarking Images in Self-Supervised Latent Spaces

Pierre Fernandez, Alexandre Sablayrolles, Teddy Furon +2

We revisit watermarking techniques based on pre-trained deep networks, in the light of self-supervised approaches. We present a way to embed both marks and binary messages into the…

cs.CR2025

SWIFT: Semantic Watermarking for Image Forgery Thwarting

Gautier Evennou, Vivien Chappelier, Ewa Kijak +1

This paper proposes a novel approach towards image authentication and tampering detection by using watermarking as a communication channel for semantic information. We modify the H…

cs.CR2024

Functional Invariants to Watermark Large Transformers

Pierre Fernandez, Guillaume Couairon, Teddy Furon +1

The rapid growth of transformer-based models increases the concerns about their integrity and ownership insurance. Watermarking addresses this issue by embedding a unique identifie…

cs.CR2020

Group Membership Verification with Privacy: Sparse or Dense?

Marzieh Gheisari, Teddy Furon, Laurent Amsaleg

Group membership verification checks if a biometric trait corresponds to one member of a group without revealing the identity of that member. Recent contributions provide privacy f…

cs.CV2017

Panorama to panorama matching for location recognition

Ahmet Iscen, Giorgos Tolias, Yannis Avrithis +2

Location recognition is commonly treated as visual instance retrieval on "street view" imagery. The dataset items and queries are panoramic views, i.e. groups of images taken at a…

cs.CV2019

Smooth Adversarial Examples

Hanwei Zhang, Yannis Avrithis, Teddy Furon +1

This paper investigates the visual quality of the adversarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artefacts. In this work, smoo…

cs.IT2009

Worst case attacks against binary probabilistic traitor tracing codes

Teddy Furon, Luis Perez-Freire

An insightful view into the design of traitor tracing codes should necessarily consider the worst case attacks that the colluders can lead. This paper takes an information-theoreti…

cs.CL2023

Three Bricks to Consolidate Watermarks for Large Language Models

Pierre Fernandez, Antoine Chaffin, Karim Tit +2

The task of discerning between generated and natural texts is increasingly challenging. In this context, watermarking emerges as a promising technique for ascribing generated text…

cs.CV2023

RoBIC: A benchmark suite for assessing classifiers robustness

Thibault Maho, Benoît Bonnet, Teddy Furon +1

Many defenses have emerged with the development of adversarial attacks. Models must be objectively evaluated accordingly. This paper systematically tackles this concern by proposin…

cs.MM2007

A constructive and unifying framework for zero-bit watermarking

Teddy Furon

In the watermark detection scenario, also known as zero-bit watermarking, a watermark, carrying no hidden message, is inserted in content. The watermark detector checks for the pre…

cs.CV2017

Memory vectors for similarity search in high-dimensional spaces

Ahmet Iscen, Teddy Furon, Vincent Gripon +2

We study an indexing architecture to store and search in a database of high-dimensional vectors from the perspective of statistical signal processing and decision theory. This arch…

cs.CV2025

Task-Agnostic Attacks Against Vision Foundation Models

Brian Pulfer, Yury Belousov, Vitaliy Kinakh +2

The study of security in machine learning mainly focuses on downstream task-specific attacks, where the adversarial example is obtained by optimizing a loss function specific to th…

cs.IR2022

Active Image Indexing

Pierre Fernandez, Matthijs Douze, Hervé Jégou +1

Image copy detection and retrieval from large databases leverage two components. First, a neural network maps an image to a vector representation, that is relatively robust to vari…

cs.CR2026

Guidance Watermarking for Diffusion Models

Enoal Gesny, Eva Giboulot, Teddy Furon +1

This paper introduces a novel watermarking method for diffusion models. It is based on guiding the diffusion process using the gradient computed from any off-the-shelf watermark de…

cs.CR2022

ROSE: A RObust and SEcure DNN Watermarking

Kassem Kallas, Teddy Furon

Protecting the Intellectual Property rights of DNN models is of primary importance prior to their deployment. So far, the proposed methods either necessitate changes to internal mo…

cs.CR2020

Adversarial Images through Stega Glasses

Benoît Bonnet, Teddy Furon, Patrick Bas

This paper explores the connection between steganography and adversarial images. On the one hand, ste-ganalysis helps in detecting adversarial perturbations. On the other hand, ste…

cs.CR2010

An Asymmetric Fingerprinting Scheme based on Tardos Codes

Ana Charpentier, Caroline Fontaine, Teddy Furon +1

Tardos codes are currently the state-of-the-art in the design of practical collusion-resistant fingerprinting codes. Tardos codes rely on a secret vector drawn from a publicly know…

cs.CV2019

Efficient Diffusion on Region Manifolds: Recovering Small Objects with Compact CNN Representations

Ahmet Iscen, Giorgos Tolias, Yannis Avrithis +2

Query expansion is a popular method to improve the quality of image retrieval with both conventional and CNN representations. It has been so far limited to global image similarity.…

cs.CV2025

Watermark Anything with Localized Messages

Tom Sander, Pierre Fernandez, Alain Durmus +2

Image watermarking methods are not tailored to handle small watermarked areas. This restricts applications in real-world scenarios where parts of the image may come from different…

cs.CR2024

WaterMax: breaking the LLM watermark detectability-robustness-quality trade-off

Eva Giboulot, Teddy Furon

Watermarking is a technical means to dissuade malfeasant usage of Large Language Models. This paper proposes a novel watermarking scheme, so-called WaterMax, that enjoys high detec…

cs.CR2019

Aggregation and Embedding for Group Membership Verification

Marzieh Gheisari, Teddy Furon, Laurent Amsaleg +2

This paper proposes a group membership verification protocol preventing the curious but honest server from reconstructing the enrolled signatures and inferring the identity of quer…

cs.CR2023

How to choose your best allies for a transferable attack?

Thibault Maho, Seyed-Mohsen Moosavi-Dezfooli, Teddy Furon

The transferability of adversarial examples is a key issue in the security of deep neural networks. The possibility of an adversarial example crafted for a source model fooling ano…

cs.LG2022

An alternative proof of the vulnerability of retrieval in high intrinsic dimensionality neighborhood

Teddy Furon

This paper investigates the vulnerability of the nearest neighbors search, which is a pivotal tool in data analysis and machine learning. The vulnerability is gauged as the relativ…

cs.CV2011

Anti-sparse coding for approximate nearest neighbor search

Hervé Jégou, Teddy Furon, Jean-Jacques Fuchs

This paper proposes a binarization scheme for vectors of high dimension based on the recent concept of anti-sparse coding, and shows its excellent performance for approximate neare…

cs.CV2014

Orientation covariant aggregation of local descriptors with embeddings

Giorgos Tolias, Teddy Furon, Hervé Jégou

Image search systems based on local descriptors typically achieve orientation invariance by aligning the patches on their dominant orientations. Albeit successful, this choice intr…

cs.CR2022

Mixer: DNN Watermarking using Image Mixup

Kassem Kallas, Teddy Furon

It is crucial to protect the intellectual property rights of DNN models prior to their deployment. The DNN should perform two main tasks: its primary task and watermarking task. Th…

cs.CR2020

SurFree: a fast surrogate-free black-box attack

Thibault Maho, Teddy Furon, Erwan Le Merrer

Machine learning classifiers are critically prone to evasion attacks. Adversarial examples are slightly modified inputs that are then misclassified, while remaining perceptively cl…

cs.CV2020

Defending Adversarial Examples via DNN Bottleneck Reinforcement

Wenqing Liu, Miaojing Shi, Teddy Furon +1

This paper presents a DNN bottleneck reinforcement scheme to alleviate the vulnerability of Deep Neural Networks (DNN) against adversarial attacks. Typical DNN classifiers encode t…

cs.SD2024

Proactive Detection of Voice Cloning with Localized Watermarking

Robin San Roman, Pierre Fernandez, Alexandre Défossez +3

In the rapidly evolving field of speech generative models, there is a pressing need to ensure audio authenticity against the risks of voice cloning. We present AudioSeal, the first…

cs.CV2023

The Stable Signature: Rooting Watermarks in Latent Diffusion Models

Pierre Fernandez, Guillaume Couairon, Hervé Jégou +2

Generative image modeling enables a wide range of applications but raises ethical concerns about responsible deployment. This paper introduces an active strategy combining image wa…