Publications (48)
SoK: On the Survivability of Backdoor Attacks on Unconstrained Face Recognition Systems
Quentin Le Roux, Yannick Teglia, Teddy Furon +2
The widespread deployment of Deep Learning-based Face Recognition Systems raises many security concerns. While prior research has identified backdoor vulnerabilities on isolated co…
Backdoor Attacks on Deep Learning Face Detection
Quentin Le Roux, Yannick Teglia, Teddy Furon +1
Face Recognition Systems that operate in unconstrained environments capture images under varying conditions,such as inconsistent lighting, or diverse face poses. These challenges r…
Towards joint decoding of binary Tardos fingerprinting codes
Peter Meerwald, Teddy Furon
The class of joint decoder of probabilistic fingerprinting codes is of utmost importance in theoretical papers to establish the concept of fingerprint capacity. However, no impleme…
Walking on the Edge: Fast, Low-Distortion Adversarial Examples
Hanwei Zhang, Yannis Avrithis, Teddy Furon +1
Adversarial examples of deep neural networks are receiving ever increasing attention because they help in understanding and reducing the sensitivity to their input. This is natural…
Joint Learning of Assignment and Representation for Biometric Group Membership
Marzieh Gheisari, Teddy Furon, Laurent Amsaleg
This paper proposes a framework for group membership protocols preventing the curious but honest server from reconstructing the enrolled biometric signatures and inferring the iden…
The Good, the Bad, and the Ugly: three different approaches to break their watermarking system
Gaëtan Le Guelvouit, Teddy Furon, François Cayre
The Good is Blondie, a wandering gunman with a strong personal sense of honor. The Bad is Angel Eyes, a sadistic hitman who always hits his mark. The Ugly is Tuco, a Mexican bandit…
Automatic discovery of discriminative parts as a quadratic assignment problem
Ronan Sicre, Julien Rabin, Yannis Avrithis +2
Part-based image classification consists in representing categories by small sets of discriminative parts upon which a representation of the images is built. This paper addresses t…
AggNet: Learning to Aggregate Faces for Group Membership Verification
Marzieh Gheisari, Javad Amirian, Teddy Furon +1
In some face recognition applications, we are interested to verify whether an individual is a member of a group, without revealing their identity. Some existing methods, propose a…
Watermarking Makes Language Models Radioactive
Tom Sander, Pierre Fernandez, Alain Durmus +2
We investigate the radioactivity of text generated by large language models (LLM), i.e. whether it is possible to detect that such synthetic input was used to train a subsequent LL…
Evaluation of Security of ML-based Watermarking: Copy and Removal Attacks
Vitaliy Kinakh, Brian Pulfer, Yury Belousov +3
The vast amounts of digital content captured from the real world or AI-generated media necessitate methods for copyright protection, traceability, or data provenance verification.…
Randomized Smoothing under Attack: How Good is it in Pratice?
Thibault Maho, Teddy Furon, Erwan Le Merrer
Randomized smoothing is a recent and celebrated solution to certify the robustness of any classifier. While it indeed provides a theoretical robustness against adversarial attacks,…
Exact Unlearning from Proxies Induces Closeness Guarantees on Approximate Unlearning
Virgile Dine, Teddy Furon
This paper proposes a paradigm shift linking machine unlearning directly to the structure of the data distributions rather than a mere update of the neural network parameters. We s…
Fast Spectral Ranking for Similarity Search
Ahmet Iscen, Yannis Avrithis, Giorgos Tolias +2
Despite the success of deep learning on representing images for particular object retrieval, recent studies show that the learned representations still lie on manifolds in a high d…
Improving Unlearning with Model Updates Probably Aligned with Gradients
Virgile Dine, Teddy Furon, Charly Faure
We formulate the machine unlearning problem as a general constrained optimization problem. It unifies the first-order methods from the approximate machine unlearning literature. Th…
Hybrid Diffusion: Spectral-Temporal Graph Filtering for Manifold Ranking
Ahmet Iscen, Yannis Avrithis, Giorgos Tolias +2
State of the art image retrieval performance is achieved with CNN features and manifold ranking using a k-NN similarity graph that is pre-computed off-line. The two most successful…
Privacy Preserving Group Membership Verification and Identification
Marzieh Gheisari, Teddy Furon, Laurent Amsaleg
When convoking privacy, group membership verification checks if a biometric trait corresponds to one member of a group without revealing the identity of that member. Similarly, gro…
The Effective Key Length of Watermarking Schemes
Patrick Bas, Teddy Furon
Whereas the embedding distortion, the payload and the robustness of digital watermarking schemes are well understood, the notion of security is still not completely well defined. T…
FBI: Fingerprinting models with Benign Inputs
Thibault Maho, Teddy Furon, Erwan Le Merrer
Recent advances in the fingerprinting of deep neural networks detect instances of models, placed in a black-box interaction scheme. Inputs used by the fingerprinting protocols are…
Watermarking Images in Self-Supervised Latent Spaces
Pierre Fernandez, Alexandre Sablayrolles, Teddy Furon +2
We revisit watermarking techniques based on pre-trained deep networks, in the light of self-supervised approaches. We present a way to embed both marks and binary messages into the…
SWIFT: Semantic Watermarking for Image Forgery Thwarting
Gautier Evennou, Vivien Chappelier, Ewa Kijak +1
This paper proposes a novel approach towards image authentication and tampering detection by using watermarking as a communication channel for semantic information. We modify the H…
Functional Invariants to Watermark Large Transformers
Pierre Fernandez, Guillaume Couairon, Teddy Furon +1
The rapid growth of transformer-based models increases the concerns about their integrity and ownership insurance. Watermarking addresses this issue by embedding a unique identifie…
Group Membership Verification with Privacy: Sparse or Dense?
Marzieh Gheisari, Teddy Furon, Laurent Amsaleg
Group membership verification checks if a biometric trait corresponds to one member of a group without revealing the identity of that member. Recent contributions provide privacy f…
Panorama to panorama matching for location recognition
Ahmet Iscen, Giorgos Tolias, Yannis Avrithis +2
Location recognition is commonly treated as visual instance retrieval on "street view" imagery. The dataset items and queries are panoramic views, i.e. groups of images taken at a…
Smooth Adversarial Examples
Hanwei Zhang, Yannis Avrithis, Teddy Furon +1
This paper investigates the visual quality of the adversarial examples. Recent papers propose to smooth the perturbations to get rid of high frequency artefacts. In this work, smoo…
Worst case attacks against binary probabilistic traitor tracing codes
Teddy Furon, Luis Perez-Freire
An insightful view into the design of traitor tracing codes should necessarily consider the worst case attacks that the colluders can lead. This paper takes an information-theoreti…
Three Bricks to Consolidate Watermarks for Large Language Models
Pierre Fernandez, Antoine Chaffin, Karim Tit +2
The task of discerning between generated and natural texts is increasingly challenging. In this context, watermarking emerges as a promising technique for ascribing generated text…
RoBIC: A benchmark suite for assessing classifiers robustness
Thibault Maho, Benoît Bonnet, Teddy Furon +1
Many defenses have emerged with the development of adversarial attacks. Models must be objectively evaluated accordingly. This paper systematically tackles this concern by proposin…
A constructive and unifying framework for zero-bit watermarking
Teddy Furon
In the watermark detection scenario, also known as zero-bit watermarking, a watermark, carrying no hidden message, is inserted in content. The watermark detector checks for the pre…
Memory vectors for similarity search in high-dimensional spaces
Ahmet Iscen, Teddy Furon, Vincent Gripon +2
We study an indexing architecture to store and search in a database of high-dimensional vectors from the perspective of statistical signal processing and decision theory. This arch…
Task-Agnostic Attacks Against Vision Foundation Models
Brian Pulfer, Yury Belousov, Vitaliy Kinakh +2
The study of security in machine learning mainly focuses on downstream task-specific attacks, where the adversarial example is obtained by optimizing a loss function specific to th…
Active Image Indexing
Pierre Fernandez, Matthijs Douze, Hervé Jégou +1
Image copy detection and retrieval from large databases leverage two components. First, a neural network maps an image to a vector representation, that is relatively robust to vari…
Guidance Watermarking for Diffusion Models
Enoal Gesny, Eva Giboulot, Teddy Furon +1
This paper introduces a novel watermarking method for diffusion models. It is based on guiding the diffusion process using the gradient computed from any off-the-shelf watermark de…
ROSE: A RObust and SEcure DNN Watermarking
Kassem Kallas, Teddy Furon
Protecting the Intellectual Property rights of DNN models is of primary importance prior to their deployment. So far, the proposed methods either necessitate changes to internal mo…
Adversarial Images through Stega Glasses
Benoît Bonnet, Teddy Furon, Patrick Bas
This paper explores the connection between steganography and adversarial images. On the one hand, ste-ganalysis helps in detecting adversarial perturbations. On the other hand, ste…
An Asymmetric Fingerprinting Scheme based on Tardos Codes
Ana Charpentier, Caroline Fontaine, Teddy Furon +1
Tardos codes are currently the state-of-the-art in the design of practical collusion-resistant fingerprinting codes. Tardos codes rely on a secret vector drawn from a publicly know…
Efficient Diffusion on Region Manifolds: Recovering Small Objects with Compact CNN Representations
Ahmet Iscen, Giorgos Tolias, Yannis Avrithis +2
Query expansion is a popular method to improve the quality of image retrieval with both conventional and CNN representations. It has been so far limited to global image similarity.…
Watermark Anything with Localized Messages
Tom Sander, Pierre Fernandez, Alain Durmus +2
Image watermarking methods are not tailored to handle small watermarked areas. This restricts applications in real-world scenarios where parts of the image may come from different…
WaterMax: breaking the LLM watermark detectability-robustness-quality trade-off
Eva Giboulot, Teddy Furon
Watermarking is a technical means to dissuade malfeasant usage of Large Language Models. This paper proposes a novel watermarking scheme, so-called WaterMax, that enjoys high detec…
Aggregation and Embedding for Group Membership Verification
Marzieh Gheisari, Teddy Furon, Laurent Amsaleg +2
This paper proposes a group membership verification protocol preventing the curious but honest server from reconstructing the enrolled signatures and inferring the identity of quer…
How to choose your best allies for a transferable attack?
Thibault Maho, Seyed-Mohsen Moosavi-Dezfooli, Teddy Furon
The transferability of adversarial examples is a key issue in the security of deep neural networks. The possibility of an adversarial example crafted for a source model fooling ano…
An alternative proof of the vulnerability of retrieval in high intrinsic dimensionality neighborhood
Teddy Furon
This paper investigates the vulnerability of the nearest neighbors search, which is a pivotal tool in data analysis and machine learning. The vulnerability is gauged as the relativ…
Anti-sparse coding for approximate nearest neighbor search
Hervé Jégou, Teddy Furon, Jean-Jacques Fuchs
This paper proposes a binarization scheme for vectors of high dimension based on the recent concept of anti-sparse coding, and shows its excellent performance for approximate neare…
Orientation covariant aggregation of local descriptors with embeddings
Giorgos Tolias, Teddy Furon, Hervé Jégou
Image search systems based on local descriptors typically achieve orientation invariance by aligning the patches on their dominant orientations. Albeit successful, this choice intr…
Mixer: DNN Watermarking using Image Mixup
Kassem Kallas, Teddy Furon
It is crucial to protect the intellectual property rights of DNN models prior to their deployment. The DNN should perform two main tasks: its primary task and watermarking task. Th…
SurFree: a fast surrogate-free black-box attack
Thibault Maho, Teddy Furon, Erwan Le Merrer
Machine learning classifiers are critically prone to evasion attacks. Adversarial examples are slightly modified inputs that are then misclassified, while remaining perceptively cl…
Defending Adversarial Examples via DNN Bottleneck Reinforcement
Wenqing Liu, Miaojing Shi, Teddy Furon +1
This paper presents a DNN bottleneck reinforcement scheme to alleviate the vulnerability of Deep Neural Networks (DNN) against adversarial attacks. Typical DNN classifiers encode t…
Proactive Detection of Voice Cloning with Localized Watermarking
Robin San Roman, Pierre Fernandez, Alexandre Défossez +3
In the rapidly evolving field of speech generative models, there is a pressing need to ensure audio authenticity against the risks of voice cloning. We present AudioSeal, the first…
The Stable Signature: Rooting Watermarks in Latent Diffusion Models
Pierre Fernandez, Guillaume Couairon, Hervé Jégou +2
Generative image modeling enables a wide range of applications but raises ethical concerns about responsible deployment. This paper introduces an active strategy combining image wa…