| DC Field | Value | Language |
| dc.contributor.author | SLIMANI, AYmen | - |
| dc.date.accessioned | 2026-10-07T08:36:07Z | - |
| dc.date.available | 2026-10-07T08:36:07Z | - |
| dc.date.issued | 2026 | - |
| dc.identifier.uri | https://repository.esi-sba.dz/jspui/handle/123456789/990 | - |
| dc.description | Supervisor : Dr. Amrane Abdelkader | en_US |
| dc.description.abstract | The Backpack scheme of Bernard et al. (IEEE TIFS, 2022) makes adversarial steganographic embedding
fully backpropagable: it replaces the two non-differentiable links in the min–max protocol (the
discrete embedding change and the payload constraint) by a Gumbel-softmax relaxation and an implicitly
differentiated Lagrange multiplier. The companion master’s report develops that theory. This
engineering report is the practical half: it reports what happens when the scheme is rebuilt from
scratch, verified equation by equation, and run at full scale on a production GPU cluster.
The work is organised as a staged ablation along three axes (binary before ternary embedding,
Fashion-MNIST before BOSSBase, spatial before JPEG) so that every regression is attributable to a
single component. Three results follow. First, in the JPEG domain the reproduction succeeds: on
BOSSBase at QF75 and 0.4 bpnzAC against a retrained XuNet, the detector’s probability of error
climbs from Perr = 0.0947 at the J-UNIWARD baseline to a peak of Perr = 0.4494 after seven
protocol iterations, against the 0.075 ! 0.476 reported in the source paper. Second, the protocol was
made roughly 36× faster per cover through a batched attack, a safeguarded-Newton λ solver, argmax
detector routing and dynamic batch sizing, every one of them gated behind a lossless-equivalence
test suite that proves the mathematics is unchanged. Third, in the spatial domain on Fashion-MNIST
the protocol improves the embedding at every iteration, raising Perr by roughly five points and more
than tripling the attack success rate, but at a rate an order of magnitude below the JPEG domain. Percover
telemetry over 10,000 covers localises the cause: between 66% and 90% of covers exhaust the
optimisation budget without reaching the detector’s decision threshold, and the median such cover
stops a full logit short of it. Two candidate explanations were eliminated by measurement along the
way, a mis-specified Monte-Carlo sample schedule and detectors that are provably blind at low payload,
and two further hypotheses were refuted directly: temperature annealing is confirmed working, and
threshold overshoot, which is real in the JPEG domain, is shown not to apply in the spatial one. An
incorrect definition of attack success, measured against the cover’s own score rather than the detector’s
decision threshold, was identified and corrected.
Finally, a controlled four-arm race under an automated fairness audit compares the paper’s Softmax-
Gumbel estimator against ReinMax, Gumbel-Rao and RLOO inside the protocol | en_US |
| dc.language.iso | en | en_US |
| dc.subject | Adversarial Embedding | en_US |
| dc.subject | Steganography | en_US |
| dc.subject | Min–Max Protocol | en_US |
| dc.subject | Backpack | en_US |
| dc.subject | Gumbel-Softmax | en_US |
| dc.subject | Gradient Estimators | en_US |
| dc.subject | Reproduction Study | en_US |
| dc.subject | GPU Cluster Engineering | en_US |
| dc.subject | XuNe | en_US |
| dc.subject | BOSSBase | en_US |
| dc.title | Adversarial Embedding at Scale: A Verified Implementation of the Backpack Min–Max Protocol and Its Behaviour Across the Spatial and JPEG Domains | en_US |
| dc.type | Thesis | en_US |
| Appears in Collections: | Ingenieur
|