← Search

Florian Kerschbaum

5 accepted papers

2024

Leveraging Optimization for Adaptive Attacks on Image Watermarks

ICLR 2024poster

Untrustworthy users can misuse image generators to synthesize high-quality deepfakes and engage in unethical activities. Watermarking deters misuse by marking generated content with a hidden message, enabling its detection using a secret watermarking key. A core security property of watermarking is…

2021

Deep Neural Network Fingerprinting by Conferrable Adversarial Examples

ICLR 2021spotlight

In Machine Learning as a Service, a provider trains a deep neural network and gives many users access. The hosted (source) model is susceptible to model stealing attacks, where an adversary derives a surrogate model from API access to the source model. For post hoc detection of such attacks, the pro…

Cited by 186SourcePDFScholar