Active Image Steganography Defense Method and System Based on Signal Enhancement
By introducing signal enhancement techniques into image steganography defense, utilizing a dual-channel parallel network model and the Laplacian operator to simulate signal distribution, and adding salt-and-pepper noise to enhance the steganographic signal, the problems of incomplete information erasure and poor image restoration in existing methods are solved, achieving efficient destruction of secret information and restoration of image quality.
Patent Information
- Application Number
- CN202610191576.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-10
- Publication Date
- 2026-05-26
AI Technical Summary
Existing image steganography defense methods fail to fully consider the global and local relationships of an image when blocking the propagation of secret information, resulting in incomplete information erasure and affecting the recovery of the original image.
An active image steganography defense method based on signal enhancement is adopted. The global structural features and local detail features of the image steganography signal are extracted through a dual-channel parallel network model. The Laplacian operator is used to simulate the distribution of the steganography signal. Salt and pepper noise is added to enhance the signal at highly suspicious locations. The original image is restored through inverse difference operation.
It achieves precise destruction of secret information and high-quality recovery of the original image, improving the effectiveness of image steganography defense and is suitable for real-world application scenarios such as online social networks.
Smart Images

Figure CN122093507A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of image steganography defense technology, and in particular to an active image steganography defense method and system based on signal enhancement. Background Technology
[0002] Image steganography utilizes the redundancy of image content to embed secret information without altering the image's perceptual characteristics, achieving covert communication through network transmission. This provides a certain level of technical protection for network information security, but it also creates opportunities for malicious actors to spread illegal information. The purpose of steganalysis is to defend against the malicious spread of secret information carried by multimedia, such as images, videos, text, and audio, across networks. In image steganography, passive defense typically focuses on detecting coded images. Both hand-designed feature-based and deep learning-based steganalysis methods have their advantages and have achieved high detection accuracy. However, single passive defense methods neglect methods to block the spread of secret information from other directions, making it difficult for image steganography to comprehensively defend against the spread of illegal secret information in practical applications. Therefore, from the perspective of image steganography defense tasks, in addition to passive steganography, in-depth research should be conducted on active defense (SAD) methods targeting secret information to gain the initiative in blocking the spread of secret information.
[0003] The transmission of classified information can be broadly divided into three steps: the sender embeds the classified information into an image, the image is transmitted over a public channel, and the receiver extracts the classified information from the image. The embedding and extraction of classified information by both the sender and receiver involves encryption and decryption techniques. Cracking encryption requires prior cryptographic knowledge to develop corresponding defense strategies. However, regardless of the encryption technology used, the transmission of the classified image over a public channel is essential. This process can be automatically completed using network transmission protocols, making it the simplest step and the most direct way to block the spread of classified information. Therefore, effectively blocking the transmission of classified information over a public channel is crucial to overcoming this challenge.
[0004] To block the spread of illicit secret information, an effective current solution is to erase the secret information from the coded image using the SAD method. This method erases the secret information and restores the image quality of the input coded image, thereby eliminating the secret information. Due to the imperceptible nature of the secret information, the coded image and the original image are visually indistinguishable. Therefore, the coded image does not affect the normal communication of ordinary users, while the receiver can extract the secret information from it. After active defense, the coded image shows no obvious visual change, but the receiver can no longer extract the normal secret information. Existing methods for covert communication based on deep learning steganography use deep neural networks to learn the pixel and edge distribution of the image, effectively removing the secret information by restoring the distribution of the original image. While this method can effectively restore the coded image to the original image, it relies on the assumption that "the carrier image and the coded image do not exist in the real world," thus having certain limitations and being suitable for specific target societies. In contrast to the limitations of the above methods, a general destructive steganography network that can maintain image quality has been proposed, applicable to online social networks. This network includes an attack module and an optimization module, as well as a loss function applicable to both. Experiments demonstrate that the network processes steganographic images of good quality and can resist various robust steganography algorithms. Based on real-world network applications, a proactive steganography defense network framework for online social networking platforms has also been proposed. This framework mainly consists of two neural networks: Scaling-Net and SC-Net. Scaling-Net focuses on processing excessively large images, while SC-Net can handle normal-sized images. Experiments show that this network framework can effectively remove secret information from images while maintaining image quality, compensating for the shortcomings of proactive steganography defense when dealing with images of different sizes. Although current SAD methods have corresponding strategies for various steganography scenarios, they have not yet considered the essential distribution of secret information from the perspective of the global and local relationships of the image when dealing with the tasks of erasing secret information and restoring the original image. This may lead to incomplete image information erasure and affect the restoration effect of the original image. Summary of the Invention
[0005] To address the shortcomings of existing image steganography defense methods, this invention provides an active image steganography defense method and system based on signal enhancement. By simulating the distribution strategy of steganographic signals, noise is introduced to enhance the signal at highly suspicious steganographic locations while relatively reducing the impact on other parts of the image. A dual-channel parallel network model is used to extract the global structural features and local detail features of the steganographic signals in the image. By complementing these two types of feature information, the steganographic signal features are restored from different dimensions, providing a steganographic feature inverse for restoring the original image and improving the effectiveness of active image steganography defense.
[0006] According to the design scheme provided by the present invention, on the one hand, an active image steganography defense method based on signal enhancement is provided, comprising:
[0007] The process involves acquiring a steganalysis image to be processed and adding interference noise to the image based on signal texture features, thereby enhancing the steganalysis signal of the image through interference noise.
[0008] The enhanced image to be processed is input into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution location of steganalysis signals by mining the correlation and spatial relationship between image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting global structural features of steganalysis signals, a lower-layer network for extracting local features of steganalysis signals, a feature fusion layer for fusing global and local features of steganalysis signals, and a reconstruction output layer for reconstructing the output of steganalysis signals based on the fused features of steganalysis signals.
[0009] As a signal enhancement-based active image steganography defense method of the present invention, further, interference noise is added to the image to be processed based on signal texture features, including:
[0010] The Laplacian operator is used to extract the texture feature map of the image, and the Laplacian operator is used to calculate the gray-level difference of the neighboring pixels of the image.
[0011] Interference noise is added to the steganalysis image based on a preset noise intensity and according to the texture feature map, so that the added interference noise covers the steganalysis signal texture position. The interference noise is salt and pepper noise.
[0012] As an active image steganography defense method based on signal enhancement of the present invention, the upper network further includes: a median filtering layer, three independent sparse feature enhancement blocks and a convolutional layer, wherein each sparse feature enhancement block includes: a deformable CR block, a DSRB residual block and a CR block, wherein the DSRB residual block obtains the context information of the image spatial features by shifting the feature map in different directions when capturing image features.
[0013] As a signal enhancement-based image steganalysis active defense method of the present invention, the DSRB residual block further utilizes convolutional layers and activation functions to extract image features and uses residual structures to ensure the transmission of feature maps in the network. The convolutional layers use 1×1 convolution to capture global image features. The convolutional layers use a spatial displacement mechanism to offset the feature maps in different directions to capture the correlation and spatial relationship of steganalysis signals in the image. The spatial displacement mechanism uses stride to locate and extract pixel features in the feature maps.
[0014] As a signal enhancement-based image steganalysis active defense method of the present invention, the lower layer network is a network structure built on the DNCNN structure, which consists of multiple convolutional layers to learn local image features and mine image structural information according to the relationship between different layers.
[0015] As a signal enhancement-based image steganalysis active defense method of the present invention, the lower layer network further includes: a first combined layer composed of convolution and Swish activation function, a second combined layer composed of deformable convolution and Swish activation function, and a convolutional layer for fusing feature maps, wherein the second combined layer consists of multiple layers.
[0016] As a signal enhancement-based active image steganalysis defense method of the present invention, the image steganalysis active defense network training process further includes:
[0017] Construct a sample dataset, wherein each sample in the sample dataset includes a sample pair consisting of a steganalyte image and a corresponding carrier image, wherein the carrier image is an original clean image without added steganalyte signals;
[0018] Adding interference noise to the steganographic image enhances the steganographic signal. The enhanced steganographic image is then input into the image steganography active defense network to obtain the steganographic signal residual feature map.
[0019] Inverse recovery and reconstruction based on residual feature maps yields a reconstructed image with stegtext erased.
[0020] Using the carrier image as the optimization target, the difference between the carrier image and the reconstructed image is used as the loss function. The network parameters are updated through the backpropagation process, so that the model learns the distribution law of the stegographic signal until the loss converges.
[0021] Furthermore, this invention also provides an active image steganography defense system based on signal enhancement, comprising: an image noise-adding module and an image restoration module, wherein,
[0022] The image noise-adding module is used to acquire the hidden image to be processed and add interference noise to the hidden image according to the signal texture features, so as to enhance the steganographic signal of the hidden image through interference noise.
[0023] The image restoration module is used to input the enhanced image to be processed into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution location of steganalysis signals by mining the correlation and spatial relationship between image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting global structural features of steganalysis signals, a lower-layer network for extracting local features of steganalysis signals, a feature fusion layer for fusing global and local features of steganalysis signals, and a reconstruction output layer for reconstructing the output of steganalysis signals based on the fused features of steganalysis signals.
[0024] The beneficial effects of this invention are:
[0025] 1. This invention simulates the distribution of steganalytic signals based on image texture details, enhances the steganalytic signals by adding noise and filtering, while preserving the original features of other areas of the image. A Deep Perception Network (DPNet) is used to optimize the enhanced image. The upper layer focuses on extracting the global structural features of the steganalytic signals, while the lower layer focuses on learning local image details and the correlation between different layers. The features of the two layers complement each other and are fused into a complete steganalytic feature map. Finally, DPNet is trained with the overlay image as the optimization target, thereby achieving proactive defense against steganography.
[0026] 2. Inspired by the characteristics of image steganalysis texture distribution, this invention utilizes a strategy of using the Laplacian operator to guide plate noise to simulate steganalysis signal distribution. This strategy specifically enhances the signal strength at highly suspicious steganalysis locations while minimizing damage to other areas of the image, laying the foundation for accurate steganalysis location. By constructing a dual-channel parallel network model (DPNet), the upper and lower layers of the network respectively focus on extracting global structural features and local detail features of the steganalysis signal, achieving information complementarity. Simultaneously, by combining Spatial Shift and 1×1 convolution, the correlation and spatial relationship between the overall steganalysis signals of the image are effectively mined, thus more clearly restoring their distribution location. This invention achieves proactive defense against image steganalysis without needing to know the steganalysis algorithm type and embedding rate. Through image noise addition and neural network modeling, it achieves dual destruction of secret information in the image under a heterogeneous balance state, while also restoring the quality of the original image in the process. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of the active image steganography defense process based on signal enhancement in the embodiment;
[0028] Figure 2This is a schematic diagram illustrating the principle of proactive steganography defense in a social network in the embodiment;
[0029] Figure 3 This is a schematic diagram illustrating the principle of the DPNet steganography disruption strategy based on image signal enhancement in the embodiment.
[0030] Figure 4 This is a schematic diagram of different noise distributions based on the example carrier image in the embodiment;
[0031] Figure 5 This is a schematic diagram of the image signal enhancement comparison between salt-and-pepper noise guided by the Laplacian operator and the original salt-and-pepper noise in the embodiment.
[0032] Figure 6 This is a schematic diagram of DPNet disrupting the steganalysis network structure based on image steganalysis signal enhancement in the embodiment.
[0033] Figure 7 This is a schematic diagram illustrating the filtering effect of different filters on salt-and-pepper noise in the embodiments;
[0034] Figure 8 This is a schematic diagram of the sparse feature enhancement structure in the embodiment;
[0035] Figure 9 This is a schematic diagram of the DSRB residual structure in the embodiment;
[0036] Figure 10 This is a schematic diagram of the feature offset effect of Spatial Shift in the embodiment;
[0037] Figure 11 This is a schematic diagram of the LNet network structure, which is the lower layer of DPNet in the embodiment.
[0038] Figure 12 This is a schematic diagram of the Swish activation function curve in the embodiment;
[0039] Figure 13 This example illustrates a comparison of PSNR / SSIM between a traditional machine learning model and DPNet. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of this invention clearer and more understandable, the invention will be further described in detail below with reference to the accompanying drawings and technical solutions.
[0041] In image steganography defense, blocking the spread of unauthorized secret information is currently an effective solution, which involves erasing the secret information from the image using the SAD (Side Altering and Decryption) method. Figure 1As shown, it can erase secret information and restore image quality from an input steganographic image, thereby achieving the purpose of eliminating secret information. Due to the imperceptible nature of secret information, there is no significant visual difference between the steganographic image and the original image. Therefore, the steganographic image does not affect the normal communication of ordinary users, while the receiver can extract the secret information from the steganographic image. After active defense, the steganographic image does not show obvious visual changes, but the receiver can no longer extract the normal secret information from the image. Although current SAD methods have corresponding strategies for various steganography scenarios, they have not yet considered the nature of secret information distribution from the perspective of the global and local relationship of the image when it comes to the task of erasing secret information and restoring the original image. This may lead to incomplete erasure of image information and affect the restoration effect of the original image. Therefore, in the embodiments of this invention, see [link to relevant documentation]. Figure 1 As shown, an active defense method for image steganography based on signal enhancement is provided, comprising:
[0042] S101. Obtain the hidden image to be processed, and add interference noise to the hidden image to be processed according to the signal texture features, so as to enhance the steganographic signal of the hidden image through interference noise.
[0043] S102. The enhanced image to be processed is input into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution position of the steganalysis signal by mining the correlation and spatial relationship between the image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting the global structural features of the steganalysis signal, a lower-layer network for extracting the local features of the steganalysis signal, a feature fusion layer for fusing the global structural features and local features of the steganalysis signal, and a reconstruction output layer for reconstructing the output of the steganalysis signal based on the fused steganalysis signal features.
[0044] Noise manifests as isolated pixels or pixel blocks in an image, unrelated to the image content, but modifications to these pixels disrupt both global and local information. Essentially, image steganography is very similar to noise generation; both alter image pixels and affect the global statistical properties of the image, changing the correlation between local pixels. Therefore, image denoising methods can be applied to the field of image steganography. A deeper understanding of steganography algorithms reveals that, to enhance the imperceptibility of coded images, they minimize embedding operations on individual images, thereby enhancing the concealment of secret information. This results in existing steganalysis networks not completely erasing (completely erasing) the secret information. Therefore, inspired by the reverse thinking of steganography algorithms and the principles of image denoising, adding specific noise to coded images can randomly destroy the pixels containing the secret information while simultaneously enhancing the difference between the coded and original images, making it easier to erase the secret information from the coded image.
[0045] like Figure 3 As shown, due to the strong concealment of steganalytic signals, in this embodiment, steganalytic signals from salt-and-pepper noise-enhanced images with similar distributions can be selected, such as... Figure 3 The blue noise addition process involves minimizing interference from anomalous signals to restore the original image in the second stage. To achieve this, Laplacian noise is used to simulate image texture distribution and guide salt-and-pepper noise, maximizing the destruction of the stegographic signal while minimizing interference. Then, a median filter is used to eliminate redundant signals in the enhanced image. Next, two layers of DPNet (UNet and LNet) are used to extract global and local features of the image, respectively. Finally, the network model is trained using the original image as the optimization target to reduce the loss function value.
[0046] Based on the distribution characteristics of hidden information in image texture and edges, adding noise to a steganographic image can randomly cover the pixels containing the steganographic information. This simultaneously helps in subsequent noise removal while destroying the steganographic information, achieving indiscriminate attack on the image and thus enhancing the steganographic signal. Therefore, the act of adding artificial noise to a steganographic image, widening the pixel difference between the steganographic image and the original image, and destroying the secret information in the image, is called signal enhancement of the steganographic image. This process is described as follows:
[0047]
[0048]
[0049]
[0050] in, It is the original image. It is a confidential image. For carrying classified information, For network input images that have been processed with artificial noise, Artificial noise, For images with steganalysis noise removed via a network, To proactively defend against the erasure of secret information and artificial noise by the network, and .
[0051] To avoid irreparable damage to the image from added noise, and to maximize the random probability of noise covering the pixels containing the steganalytic information, it is necessary to determine the type of noise to be added to the carrier image and the noise loading rate parameter. Therefore, experiments were conducted comparing the four most common types of noise (Gaussian noise, salt-and-pepper noise, multiplicative noise, and Poisson noise) to determine the image noise most similar to the steganalytic signal distribution. First, a small amount of steganalytic information was embedded into the carrier image, and the pixel difference between the carrier image and the steganalytic image was calculated. Then, the four types of noise were added to the carrier image in appropriate amounts, and the pixel difference between the noisy image and the carrier image was calculated.
[0052] Comparing noise distribution with hidden information distribution as follows Figure 4 As shown in the table, Gaussian noise is concentrated in the least bright, textured regions of the image; multiplicative noise is uniformly and randomly distributed throughout the image; Poisson noise is distributed randomly as continuous lines throughout the image; and salt-and-pepper noise has the highest similarity to the steganatical signal. Therefore, it can be preliminarily concluded that among the most common image noises, salt-and-pepper noise is suitable as noise to enhance the steganatical signal of encrypted images. To further demonstrate that salt-and-pepper noise can destroy the steganatical information in encrypted images to the maximum extent, and thus indirectly confirm that the distribution of salt-and-pepper noise is most similar to the distribution of the steganatical signal, the experiment was extended to comprehensively consider the complexity of steganography, the nature of noise, and the requirements of image denoising. Two classic steganography algorithms, S-UNIWARD and WOW, were used to encrypt 100 random images from the BOSSbase database, and salt-and-pepper noise, Gaussian noise, multiplicative noise, and Poisson noise were added to them respectively. The bit error rate was used as an evaluation of the degree of noise destruction of steganatical information. The experimental results are shown in Table 1:
[0053] Table 1. Image bit error rate under two steganography algorithms and four common noise conditions.
[0054]
[0055] Table 1 shows that adding noise to a steganographic image can interfere with subtle changes in the image, destroying the hidden features of the steganographic information, thus making the steganographic information difficult to extract and understand accurately, thereby achieving the purpose of active defense. Data shows that when destroying the secret information of the S-UNIWARD steganography algorithm, the average bit error rates (BER) obtained by adding salt-and-pepper noise, Gaussian noise, multiplicative noise, and Poisson noise are 0.87630, 0.82583, 0.81190, and 0.54739, respectively. Among them, salt-and-pepper noise yields the highest BER value when attacking the S-UNIWARD steganography algorithm. When destroying the secret information of the WOW steganography algorithm, the average BER obtained by adding salt-and-pepper noise, Gaussian noise, multiplicative noise, and Poisson noise are 0.87522, 0.82468, 0.81168, and 0.54803, respectively. Among them, salt-and-pepper noise yields the highest BER value when attacking the WOW steganography algorithm. Based on the above data analysis, it can be determined that salt-and-pepper noise is used to enhance the steganographic signal in densely packed images.
[0056] It is known that adding salt-and-pepper noise to a steganographic image can destroy the secret information. However, since the impact of ordinary noise on the coverage of steganographic information and image content is uncertain, it also reduces the overall image quality, blurring details and edges to some extent. This results in less than ideal visual effects after the network restores the image. To make this type of noise controllable and effective only at the location of the steganographic information, improvements to salt-and-pepper noise are chosen. The latest adaptive steganography algorithms select the optimal embedding position and embedding strength based on the color distribution, edge information, texture, and other features of the carrier image to ensure the effectiveness of the hidden information.
[0057] Specifically, in this embodiment, the Laplacian operator can be used to extract the texture feature map of the steganalysis image. The Laplacian operator is used to calculate the gray-level difference of neighboring pixels in the image. Based on a preset noise intensity and according to the texture feature map, interference noise is added to the steganalysis image so that the added interference noise covers the texture position of the steganalysis signal. The interference noise is salt and pepper noise.
[0058] Leveraging the characteristics of the embedding location in steganography algorithms, the Laplacian operator is introduced into the signal enhancement module. By utilizing the Laplacian operator's ability to calculate the gray-level difference between neighboring pixels, the second-order gray-level changes in the image are identified to analyze and enhance edge distribution and texture details. Salt-and-pepper noise is then added to the obtained image texture feature map to simulate and enhance the steganographic signal. The principle of the Laplacian operator is as follows:
[0059]
[0060] in, Indicates the pixel position of the image Laplace transform at the point, and These represent the second derivatives of the image in the horizontal and vertical directions, respectively. For example... Figure 5 As shown, the Laplacian operator is used to enhance the contrast of the steganalysis signal.
[0061] Figure 5 In this study, the Laplacian operator was not used to directly apply salt-and-pepper noise to the stegana image. The noise signal distribution was too widespread and random, failing to directly interfere with and destroy the stegana signal in the image. This resulted in inaccurate interference with the stegana signal in the initial stage, thus affecting the model's performance. Conversely, using the Laplacian operator for texture analysis to apply salt-and-pepper noise to the image better simulates the distribution pattern of the stegana signal. Figure 5 It can be seen that by simulating the characteristics of the adaptive steganography algorithm, adding noise after performing texture analysis on the steganography image can make the noise accurately cover the areas with more steganography signals and cover the areas with less image texture, thereby achieving the effect of scrambling and enhancing the steganography signals in the steganography information.
[0062] Let the image If the image is a dense image, then the image after directly adding salt-and-pepper noise is represented as:
[0063]
[0064] Therefore, the image after adding salt-and-pepper noise to the texture using the Laplacian operator is represented as:
[0065]
[0066] in, Salt and pepper noise intensity, It is a salt and pepper noise function. It is the image texture portion extracted by the Laplacian operator.
[0067] Additionally, let the image quality function be defined. Image loss function , To maintain the original image quality, then:
[0068]
[0069] Therefore, adding texture noise to an image using the Laplacian operator has the following properties:
[0070] Property 1: Yes Add to , .
[0071] Property 2: ,like ,but:
[0072]
[0073] prove.
[0074] (1) The loss from directly adding salt and pepper noise is The loss of adding salt-and-pepper noise only to the texture portion is Since directly adding salt-and-pepper noise affects the entire image, and the Laplacian operator extracts texture only from the high-frequency components of the image, therefore:
[0075]
[0076] Based on noise intensity The impact on image quality can be expressed as:
[0077]
[0078]
[0079] because Therefore:
[0080]
[0081] Therefore, for ,have
[0082]
[0083] (2) Define the difference in image quality between the two methods as:
[0084]
[0085] but The rate of change is:
[0086] because ,but:
[0087] so .
[0088] Therefore, with the increase in noise intensity The increase in quality gap As the noise level increases, the difference in image quality between adding salt and pepper noise directly and adding it only to the texture portion will become increasingly larger.
[0089] For most methods of secret communication using steganography, the imperceptibility of the steganographic information is extremely important. Steganographic information is often embedded in a small number of pixels, and the embedded signal or noise is very weak compared to the image content, making direct removal of steganographic signals from the image ineffective. Therefore, steganography sanitization strategies that optimize the original clean image have become a new option. Experiments have shown that this approach can make the steganographic image closer to the original image, and it is a simple and effective network training strategy. Inspired by the above strategy, a deep learning-based steganography sanitization network model uses the original image as the optimization target of the attack model. Utilizing the nonlinear fitting capability of convolutional neural networks, it indirectly removes the embedded steganographic information from the image through feature extraction and image restoration, thereby mapping the steganographic image containing steganographic information back to the original image without steganographic information, achieving the purpose of destroying the steganographic information. This strategy is effective and has multiple advantages, for the following reasons:
[0090] (1) The network training process does not require prior knowledge, nor does it need to know the steganography method and embedding rate used in the image. Therefore, it has the advantages of universality and simplicity.
[0091] (2) Deep learning models need to preserve the main content and quality of the image as much as possible while removing steg information. The original image is usually visually high quality, so it can serve as a reference standard to help the model maintain the visual quality of the image to the greatest extent while removing steg information and reducing the difference between the original and restored images.
[0092] (3) The original image, the coded image, and the reconstructed image after active defense have high visual similarity. The deep learning model with the original image as the optimization target can achieve imperceptibility to attacks on steganographic information.
[0093] Currently, image denoising networks can effectively process and restore images affected by noise, improving image quality and removing artifacts. However, some models still suffer from insufficient adaptability to complex noise and improper handling of image details and texture information, resulting in poor transferability in practical applications. To delve deeper into the relationship between the pixel locations of steganalysis and the original image, starting from the global statistical characteristics of the image and the correlation between pixels, combining global information and local features of the image can better restore the original image. Furthermore, given the specific noise added to the enhanced stegana signal, its characteristics of covering the stegana signal location, and its distribution along image texture and edges, traditional image denoising networks are not suitable for denoising and restoring steganalysis tasks requiring active defense. Therefore, considering the specific nature of steganalysis tasks, the proposed DPNet in this embodiment primarily focuses on denoising and image restoration of signal-enhanced images. By adding filters to the upper-layer network to remove abnormal signals in the image, it achieves secondary destruction of the stegana signal. In addition, the design of the upper and lower layer structures of DPNet focuses on the overall distribution characteristics and local detail features of the image stegana signal, respectively. The two types of features extracted in parallel complement each other, ensuring the integrity of the extracted image residual features (stegana signal). Finally, the image is reconstructed by inverse recovery of the residual feature map, and the parameters are trained and optimized using the original image as the target.
[0094] like Figure 6 As shown, DPNet consists of two layers. The upper layer, UNet, comprises a median filter layer, three independently designed sparse feature enhancement modules, and a convolutional layer to learn global steganalytic features of the image. Additionally, stacked residual structures—deep space transformation residual blocks—acquire contextual information about high-order image features, helping the network model noise and steganalytic information within the image content. The feature extraction process is as follows:
[0095]
[0096]
[0097] in, For the fusion of features between the upper and lower network layers, The image represents the signal enhancement. For the upper-layer network structure, represent structure, Represents 3 sequentially connected Module, Represents the median filter layer. This is the lower-level network structure.
[0098] Through the special structure of the upper-layer network, combined with specific noise added in the early stages, the network can extract global stegographic signal enhancement features from the stegographic image while preserving the overall structure and features of the image, thus improving the effectiveness of subsequent networks in destroying stegographic information. The lower-layer network consists of multiple convolutional layers, used to learn local details of the image and focus on the relationships between different layers, mining more structural information. This allows the network to preserve detail information when extracting features, avoiding excessive smoothing that leads to detail loss. In addition, the features extracted by the lower-layer network complement the upper-layer network, learning global features and local details of the image respectively, thus gaining a more comprehensive understanding and processing of image content, thereby achieving the purpose of destroying stegographic information and restoring the image. Finally, the two sub-networks merge their extracted feature information, converting low-frequency information into high-frequency information, thereby extracting noise signals from the network. The specific principle is as follows:
[0099]
[0100]
[0101] in, Represents an independent convolutional neural network structure. and The meaning is the same as the formula above. This represents the noise residual map extracted by DPNet.
[0102] Specifically, the upper network includes: a median filter layer, three independent sparse feature enhancement blocks and a convolutional layer. Each sparse feature enhancement block includes: a deformable CR block, a DSRB residual block and a CR block. The DSRB residual block obtains the contextual information of the image spatial features by shifting the feature map in different directions when capturing image features.
[0103] The DSRB residual block uses convolutional layers and activation functions to extract image features and uses residual structures to ensure the transfer of feature maps in the network. The convolutional layers use 1×1 convolution to capture global image features. The convolutional layers use a spatial displacement mechanism to shift the feature map in different directions to capture the correlation and spatial relationship of the stegographic signal in the image. The spatial displacement mechanism uses stride to locate and extract pixel features in the feature map.
[0104] Salt-and-pepper noise introduces randomly distributed black and white dots (black for pepper noise, white for salt noise) into an image, causing visual artifacts such as noise, color distortion, and artifacts. For covert communication security, reduced image clarity and discernibility can alert the receiver to an attack, hindering subsequent steganography defenses. One effective method for noise removal is adding filters. Research shows that different types of noise have different distribution characteristics, allowing for the use of appropriate filters for denoising. Therefore, in this embodiment, a suitable filter is added to the upper-layer network to remove specific noise added during the initial enhancement of the steganographic signal. To select an effective noise filter, four common filters were compared to denoise salt-and-pepper noise, with the following results: Figure 7 As shown. Compared to other filtering methods, median filtering can better preserve image details while removing salt-and-pepper noise, avoiding image blurring and thus improving the accuracy of features learned by the image denoising network model. Therefore, in this embodiment, median filtering is used in the upper layer of DPNet to perform preliminary image cleaning, significantly reducing the impact of noise on the image, thereby accelerating the convergence process of the steganalytic active defense model and improving the efficiency and stability of model training.
[0105] On the other hand, the filtered image signal differs significantly from the unfiltered signal, primarily in the increased difficulty of feature extraction. Therefore, inspired by image restoration, a feature enhancement network (SFE) module is designed to improve feature extraction performance by addressing image degradation caused by signal fluctuations. To better capture local image features, detailed features are preserved during high-frequency signal extraction, restoring the complete structure of the steganalytic signal. In this embodiment, a sparse feature enhancement module is designed to address the sparsity of the image. Each SFE module consists of a Conv+ReLU, a Deformable Conv+ReLU, and a DSRB module, as shown in the specific structure below. Figure 8 As shown, in order to improve the network model's ability to perceive images and adapt to different image structures, the SFE module uses deformable Conv+ReLU to process features in the first layer, and then performs deep feature extraction through the DSRB module and Conv+ReLU.
[0106] DSRB, as the foundational module for feature extraction in the upper-layer network, mainly consists of specific convolutional layers and activation functions to extract image features after median filtering. The residual structure ensures that the input feature map continues to propagate within the network. The specific structure is as follows: Figure 9 As shown.
[0107] First, to obtain the global steganalytic features embedded in the secret information, this network module replaces some traditional 3×3 convolutions with 1×1 convolutions. Leveraging the effectiveness of 1×1 convolutions in capturing global image features, features from different channels are combined to obtain higher-order feature information. Simultaneously, to capture the correlation and spatial relationships of the steganalytic signals in the image, Spatial Shift is introduced into this module and combined with 1×1 convolutions, referred to as Conv-Shift Layer. The Conv-Shift Layer reduces the computational cost and parameter count of the network while obtaining feature information from a wider spatial range. By shifting the input feature map in different directions, it enhances the model's robustness to spatial transformations such as translation and rotation, thereby better capturing the spatial structure and correlations in the image, such as... Figure 10 As shown.
[0108] The specific principle of Spatial Shift is as follows: Let the input image matrix be... Image size is ,in, Represents the height of the image. Represents the width of the image, and the offset is expressed as... and , representing the amount of offset in the horizontal and vertical directions, respectively. Let this be the step size. Assume each pixel... The new position after the offset is represented as The offset result is as follows:
[0109]
[0110]
[0111] If When set to 1, Spatial Shift extracts the surrounding 8 pixels. The spatial shift step size set can be defined as {(0, 1), (0, -1), (1, 0), (1, 1), (1-1), (-1, 0), (-1, 1), (-1, -1)}. By utilizing the step size to locate the target pixel features, the network model can use pixels to generate new features and enrich the feature set.
[0112] When removing secret information from images, steganalysis active defense networks need to preserve the image's detailed information. This allows the network to maintain the image's clarity, overall quality, and realism while destroying the secret information, thus preventing detection by the communicating parties. In this embodiment, the lower-layer network is specifically a DNCNN-based network structure, composed of multiple convolutional layers. These layers learn local image features and mine image structural information based on the relationships between different layers. The lower-layer network includes: a first combined layer consisting of convolutions and Swish activation functions; a second combined layer consisting of deformable convolutions and Swish activation functions; and convolutional layers that fuse feature maps. The second combined layer consists of multiple layers.
[0113] like Figure 11 As shown, the lower-layer network is based on the DNCNN structure and improved to extract deep detail features of the steganalytic signal in areas where secret information is concentrated. It mainly consists of three different network layers, as follows:
[0114] 1) Conv + Swish
[0115] The first layer of the lower network consists of a regular convolution with a kernel size of 3×3 and a Swish activation function. Using a 3×3 convolution kernel, the network can extract subtle image features, which is very important for detecting texture details in dense images, because texture details in an image usually affect the details and local features of the image. By extracting features through convolution, the network can better capture these subtle features affected by noise.
[0116] The ReLU activation function is widely used in deep learning. While its good fitting ability helps neural networks learn complex nonlinear relationships, it still has shortcomings in extracting local image details, especially in handling negative features. Figure 11 As shown, when the input is negative, the gradient of ReLU is 0. This may cause the gradient vanishing problem when the network learns local details of the image, making it impossible for some detailed features to be effectively learned and propagated. This may affect the network's learning and restoration of detailed features of the image, thus preventing the network from effectively learning and extracting local features of the image, thereby affecting its ability to remove secret information.
[0117] To address this issue, this embodiment uses the Swish activation function in the lower-layer network to enhance the network's ability to learn local image details. Unlike the ReLU activation function, the Swish activation function allows some information transfer even with negative inputs and does not suppress the activation of that data to zero. In digital images, negative values represent edge and detail information; therefore, the Swish activation function can better preserve these details without directly suppressing them to zero like ReLU. Figure 12 As shown:
[0118] Compared to the ReLU activation function, the Swish activation function is a smooth S-shaped curve. As the input value increases, the output value gradually approaches the input value, meaning that even small changes in the input will result in a more continuous change in the output. Therefore, the introduction of the Swish activation function can help the network capture more complex noise patterns, thereby greatly enhancing the network's ability to learn local details in images.
[0119] 2) Deformable Conv + Swish
[0120] For layers 2-13, deformable convolutions are used to select features from the image, and batch normalization is subsequently used to further stabilize the network's training process, reducing the risks of gradient explosion and gradient vanishing. Batch normalization helps the model generalize better to data not seen in the steganalytic noise set, thus making the model more robust to real noise.
[0121] 3) Conv
[0122] The final layer uses ordinary convolution to combine and process the final feature maps learned by the network, and adjusts the convolution of the lower network features to the same dimension as the upper network features, so as to better fuse with the upper network features and thus extract more comprehensive image stegographic signal features.
[0123] The training process for the image steganalysis active defense network can be designed to include:
[0124] Construct a sample dataset, wherein each sample in the sample dataset includes a sample pair consisting of a steganalyte image and a corresponding carrier image, wherein the carrier image is an original clean image without added steganalyte signals;
[0125] Adding interference noise to the steganographic image enhances the steganographic signal. The enhanced steganographic image is then input into the image steganography active defense network to obtain the steganographic signal residual feature map.
[0126] Inverse recovery and reconstruction based on residual feature maps yields a reconstructed image with stegtext erased.
[0127] Using the carrier image as the optimization target, the difference between the carrier image and the reconstructed image is used as the loss function. The network parameters are updated through the backpropagation process, so that the model learns the distribution law of the stegographic signal until the loss converges.
[0128] Utilizing the principles of signal enhancement and image restoration, this method first effectively enhances the signal of highly concealed coded images. Second, a median filter is used to filter out abnormal signals in the image, thus destroying the secret information while preserving the image content quality. Then, DPNet is used to extract the steganalytic feature inverse from the signal-enhanced image. Finally, the original image is used for restoration, achieving the goal of proactive defense against coded images without being detected by the parties involved in covert communication.
[0129] Furthermore, based on the above method, this embodiment of the invention also provides an image steganography active defense system based on signal enhancement, comprising: an image noise-adding module and an image restoration module, wherein,
[0130] The image noise-adding module is used to acquire the hidden image to be processed and add interference noise to the hidden image according to the signal texture features, so as to enhance the steganographic signal of the hidden image through interference noise.
[0131] The image restoration module is used to input the enhanced image to be processed into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution location of steganalysis signals by mining the correlation and spatial relationship between image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting global structural features of steganalysis signals, a lower-layer network for extracting local features of steganalysis signals, a feature fusion layer for fusing global and local features of steganalysis signals, and a reconstruction output layer for reconstructing the output of steganalysis signals based on the fused features of steganalysis signals.
[0132] To verify the effectiveness of this solution, the following explanation is based on experimental data:
[0133] The performance of DPNet was tested using standard datasets. The two standard datasets are as follows:
[0134] 1) BOSSbase1.01 image database, which contains 10,000 512×512 grayscale images, including natural scene images, human images and texture images, with different lighting, viewpoints and image complexities.
[0135] 2) The BOSW2 image database contains 10,000 512×512 grayscale images. These categories cover a variety of different scenes and targets, such as street scenes, indoor environments, natural landscapes, and objects.
[0136] Considering the computational power and time consumption of GPUs, 10,000 images were randomly selected and their resolution adjusted to 256×256 based on the aforementioned dataset. The training, test, and validation sets were partitioned into the database in an 8:1:1 ratio to ensure data distribution consistency. All experiments were run on an 11th generation Intel® Core™ i5-11400H CPU at 2.70GHz and 2.69GHz, and an Nvidia RTX 3050 GPU. Parameter settings for specific networks are detailed in Table 2.
[0137] Table 2 DPNET Network Parameter Settings
[0138]
[0139] Peak signal-to-noise ratio (PSNR) and structural similarity index (SSIM) were used to evaluate the image quality after active defense. Higher PSNR and SSIM values indicate better image quality after active defense.
[0140] PSNR is a metric used to measure image quality. It evaluates image quality by calculating the peak signal-to-noise ratio between the original image and the compressed image.
[0141] The PSNR formula is as follows:
[0142] Where MAX represents the maximum possible value of an image pixel. For 8-bit images, MSE is typically 255. MSE is the mean squared error, used to measure the average difference in pixels between the original and compressed images. The formula for calculating MSE is:
[0143]
[0144] Where I represents the pixel value of the original image, and K represents the pixel value of the compressed and decompressed images. M and N represent the width and height of the image, respectively.
[0145] SSIM (Structural Similarity Index) is a metric used to measure image similarity. Its calculation takes into account brightness, contrast, and structural features. The formula for calculating SSIM is as follows:
[0146]
[0147] in and These represent the average values of the x and y values of the image, respectively. and Let x and y represent the variances of the images, respectively. This represents the covariance of the images x and y. and It is a constant used in the stabilization formula. The value range is from -1 to 1. The closer the similarity is to 1, the higher the similarity between the two images.
[0148] To thoroughly evaluate the performance of the proposed model, DPNet was compared with several mainstream networks (such as FFDNet, CBDNet, and RIDNET). All networks were validated on the same dataset, and two common steganography algorithms, WOW and S-uniward, were used, with payloads ranging from 0.01 bpp to 0.05 bpp, respectively. To verify the performance of each module, comparative tests were conducted in both signal augmentation and non-signal augmentation scenarios.
[0149] 1. Ablation experiments under signal enhancement conditions:
[0150] To verify the effectiveness of signal enhancement techniques, an experiment was conducted using the presente database. Images were divided into two groups: one group received signal enhancement processing, while the other group received no processing. The experiment was designed to intentionally introduce differences in noise type and intensity between the two groups. This design aimed to improve the reliability of the experimental results and comprehensively evaluate the performance of signal enhancement techniques under different noise environments. By introducing different types and intensities of noise, the anti-noise capability of signal enhancement techniques and their effect on improving image quality can be tested more comprehensively. This design ensures accurate evaluation of the performance of signal enhancement techniques under various noise conditions.
[0151] Table 3 Experimental Study of Image Signal Enhancement and Non-Enhancement under WOW Steganography Algorithm Conditions
[0152]
[0153] As shown in Table 3, under the WOW steganography algorithm and five different load conditions, the average PSNR of the image network after training without enhanced S&P signals is 37.04, and the average SSIM is 0.9445; while the average PSNR of the image network after training with enhanced S&P signals is 38.05, and the average SSIM is 0.9602. It can be seen that the average PSNR is improved by 4.87%, and the SSIM index is improved by 1.66%.
[0154] Table 4 Experimental Study of Image Signal Enhancement and Non-Enhancement Using the S-UNIWARD Stegation Algorithm
[0155]
[0156] As shown in Table 4, under the S-uniward steganography algorithm, for images without S&P signal enhancement, the average PSNR after network training is 37.62, and the average SSIM is 0.9518. For images with S&P signal enhancement, the average PSNR increases to 38.91 after network training, and the average SSIM reaches 0.9606. An average PSNR improvement of 3.42% and an SSIM improvement of 0.92% were observed. This indicates that signal enhancement technology significantly improves the image restoration quality after removing steganographic information. Experimental results show that signal enhancement can effectively improve image recognition and contrast, thereby enhancing the removal of steganographic information and promoting image restoration. This technological advantage helps the model better learn effective signals and distinguish noise, thus improving the accuracy and robustness of denoising.
[0157] 2. Results of using S&P signal enhancement
[0158] To verify the effectiveness of the model in this embodiment, it is first compared with several classic traditional machine learning models. These models typically employ manually designed feature extraction methods, such as KSVD, MCWNNM, and TWSC. These methods rely on predefined prior knowledge of the image and usually use optimization algorithms to remove steganalytic information from the image and restore image quality. Their advantages include low computational complexity, making them suitable for scenarios with relatively little steganalytic information in the image and specific to the task. However, their performance is limited when there is a large amount of steganalytic information in the image.
[0159] from Figure 13 The comprehensive comparison results show that traditional machine learning models perform steganalysis and image restoration tasks stably. Combining experimental data from both WOW and S-UNIWARD algorithms, the average PSNR of traditional models under different load rates is approximately 37.58 dB, and the average SSIM is approximately 0.942. However, compared to DPNet, these traditional methods show significant differences in both PSNR and SSIM. Experimental results demonstrate that DPNet achieves significant performance improvements across different steganalysis algorithms; for example, it achieves a maximum PSNR improvement of 8.81% in the S-UNIWARD algorithm and a maximum SSIM improvement of 8.68% in the WOW algorithm. These results fully demonstrate that DPNet has a significant advantage over traditional machine learning models when handling different steganalysis algorithms.
[0160] In preliminary experiments, the DPNet model was compared and analyzed with various traditional machine learning denoising models. The study found that DPNet significantly outperformed methods such as KSVD and TWSC in both PSNR and SSIM metrics, fully demonstrating its efficiency and advantages in image steganalysis and image inpainting tasks.
[0161] To further validate the potential of the DPNet model, this paper compares it with current important deep learning denoising models (including CDnCNNB, FFDNet, and RIDNet). Due to their advanced architecture and powerful learning capabilities, these deep learning models have achieved significant results in the field of image denoising.
[0162] Table 5 Comparison of PSNR / SSIM results between DPNET and deep learning models in the WOW steganography algorithm
[0163]
[0164] Table 6 Comparison of PSNR / SSIM results between DPNET and deep learning models in the T-UNIWARD steganography algorithm
[0165]
[0166] Based on the comprehensive comparison results in Tables 5 and 6, DPNet still demonstrates a leading performance advantage when facing various mainstream deep learning models. Notably, DPNet exhibits consistent superiority across different steganography algorithms such as WOW and S-UNIWARD, achieving a maximum performance improvement of over 20% compared to the baseline model (e.g., PSNR and SSIM improvements both exceed 22%). This indicates that DPNet not only outperforms traditional methods but also significantly surpasses existing advanced deep learning models, demonstrating strong competitiveness and application potential. Its outstanding performance in image detail preservation further proves the enormous development potential of the model in this embodiment for proactive image steganography defense in practical applications. The experimental results show that this solution does not require knowledge of the type of steganography algorithm or its embedding rate, minimizing the impact on image quality while erasing secret information, and outperforming other proactive defense methods in both secret information erasure and image recovery.
[0167] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of the invention.
[0168] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.
[0169] The units and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations are not considered to be beyond the scope of this invention.
[0170] Those skilled in the art will understand that all or part of the steps in the above methods can be implemented by a program instructing related hardware, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk. Optionally, all or part of the steps in the above embodiments can also be implemented using one or more integrated circuits. Accordingly, each module / unit in the above embodiments can be implemented in hardware or as a software functional module. This invention is not limited to any particular combination of hardware and software.
[0171] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for active defense against image steganography based on signal enhancement, characterized in that, Include: The process involves acquiring a steganalysis image to be processed and adding interference noise to the image based on signal texture features, thereby enhancing the steganalysis signal of the image through interference noise. The enhanced image to be processed is input into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution location of steganalysis signals by mining the correlation and spatial relationship between image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting global structural features of steganalysis signals, a lower-layer network for extracting local features of steganalysis signals, a feature fusion layer for fusing global and local features of steganalysis signals, and a reconstruction output layer for reconstructing the output of steganalysis signals based on the fused features of steganalysis signals.
2. The image steganography active defense method based on signal enhancement according to claim 1, characterized in that, Adding interference noise to the image to be processed based on signal texture features, including: The Laplacian operator is used to extract the texture feature map of the image, and the Laplacian operator is used to calculate the gray-level difference of the neighboring pixels of the image. Interference noise is added to the steganalysis image based on a preset noise intensity and according to the texture feature map, so that the added interference noise covers the steganalysis signal texture position. The interference noise is salt and pepper noise.
3. The image steganography active defense method based on signal enhancement according to claim 1, characterized in that, The upper network includes a median filter layer, three independent sparse feature enhancement blocks, and a convolutional layer. Each sparse feature enhancement block includes a deformable CR block, a DSRB residual block, and a CR block. The DSRB residual block obtains the contextual information of the image spatial features by shifting the feature map in different directions when capturing image features.
4. The image steganography active defense method based on signal enhancement according to claim 3, characterized in that, The DSRB residual block uses convolutional layers and activation functions to extract image features and uses residual structures to ensure the transfer of feature maps in the network. The convolutional layers use 1×1 convolution to capture global image features. The convolutional layers use a spatial displacement mechanism to shift the feature map in different directions to capture the correlation and spatial relationship of the stegographic signal in the image. The spatial displacement mechanism uses stride to locate and extract pixel features in the feature map.
5. The image steganography active defense method based on signal enhancement according to claim 1, characterized in that, The lower-level network is a network structure built on the DNCNN structure. This network structure consists of multiple convolutional layers to learn local image features and mine image structural information based on the relationship between different layers.
6. The image steganography active defense method based on signal enhancement according to claim 5, characterized in that, The lower-level network includes: a first combined layer consisting of convolution and Swish activation functions, a second combined layer consisting of deformable convolution and Swish activation functions, and a convolutional layer that performs feature map fusion processing, wherein the second combined layer consists of multiple layers.
7. The image steganography active defense method based on signal enhancement according to claim 1, characterized in that, The training process of an image steganalysis active defense network includes: Construct a sample dataset, wherein each sample in the sample dataset includes a sample pair consisting of a steganalyte image and a corresponding carrier image, wherein the carrier image is an original clean image without added steganalyte signals; Adding interference noise to the steganographic image enhances the steganographic signal. The enhanced steganographic image is then input into the image steganography active defense network to obtain the steganographic signal residual feature map. Inverse recovery and reconstruction based on residual feature maps yields a reconstructed image with stegtext erased. Using the carrier image as the optimization target, the difference between the carrier image and the reconstructed image is used as the loss function. The network parameters are updated through the backpropagation process, so that the model learns the distribution law of the stegographic signal until the loss converges.
8. An active defense system for image steganography based on signal enhancement, characterized in that, It includes: an image noise reduction module and an image restoration module, wherein, The image noise-adding module is used to acquire the hidden image to be processed and add interference noise to the hidden image according to the signal texture features, so as to enhance the steganographic signal of the hidden image through interference noise. The image restoration module is used to input the enhanced image to be processed into a pre-trained image steganalysis active defense network. The image steganalysis active defense network is used to restore the steganalysis signal features, so as to recover the original carrier image in the image to be processed through inverse difference operation. The image steganalysis active defense network adopts a dual-channel parallel network model to restore the distribution location of steganalysis signals by mining the correlation and spatial relationship between image steganalysis signals. The dual-channel parallel network model includes: an upper-layer network for extracting global structural features of steganalysis signals, a lower-layer network for extracting local features of steganalysis signals, a feature fusion layer for fusing global and local features of steganalysis signals, and a reconstruction output layer for reconstructing the output of steganalysis signals based on the fused features of steganalysis signals.
9. An electronic device, characterized in that, include: At least one processor, and a memory coupled to said at least one processor; The memory stores a computer program that can be executed by the at least one processor to implement the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, enables the implementation of the method as described in any one of claims 1 to 7.