JPEG Image Adversarial Steganography Method Based on the UT-GAN Model
Through the JPEG image adversarial steganography method based on the UT-GAN model, the gradient calculator and linear mapper are used to adjust the gradient and generate adversarial steganography images, solving the problem of weak dependence on large and anti-steganography analysis performance on the data set in the prior art, and achieving more efficient steganography performance.
Patent Information
- Application Number
- CN202510377816.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-28
AI Technical Summary
In the prior art, the image steganography method has a large dependence on data sets and has weak anti-steganography analysis performance, and lacks an effective non-data-driven solution.
The JPEG image adversarial steganography method based on the UT-GAN model is adopted, and the carrier image is preprocessed through the UT-GAN network to generate an adversarial steganography image. The gradient calculator and linear mapper are used to adjust the gradient, generate an adversarial gradient matrix, dynamically adjust the cost matrix, select the optimal adversarial steganography image, avoid dependence on the data set, and combine adversarial steganography with feature steganography and deep learning.
It improves the performance of steganography, avoids dependence on data sets, enhances the anti-steganography analysis ability of steganography images, and achieves more efficient steganography performance.
Smart Images

Figure CN119922272B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of image steganography, the technical field of countermeasure steganography and the field of adversarial networks in deep learning, and specifically to a JPEG image adversarial steganography method based on the UT-GAN model. Background Art
[0002] Image steganography aims to hide secret information in digital images in an imperceptible way. Recently, most steganography methods are designed under the framework of distortion minimization. Under this framework, the design of the embedding cost is a key aspect. The embedding cost refers to the degree of distortion or damage caused by hiding secret information within the embedding units of an image (such as pixels or DCT coefficients). Generally, regions with complex image textures exhibit relatively high embedding costs, while regions with simple and flat textures have low embedding costs. These different embedding costs will significantly affect the security performance of image steganography. Once the embedding cost is defined, syndrome-trellis codes (STC) are then used to embed the secret message and minimize the sum of the embedding costs. Inspired by the fast gradient sign method, some adversarial attack-based methods attempt to adjust the original embedding cost according to the gradients obtained from some pre-trained CNN steganographers, generally calculating the adversarial gradients based on deep learning-based steganalyzers. Note that the aforementioned adversarial attack-based methods can be considered improved strategies because they rely on existing steganography methods to calculate the initial embedding cost and pre-trained CNN-based steganalysis.
[0003] For example, ASDL-GAN is the first method to introduce the GAN model into image steganography to generate embedding probabilities. However, the steganography performance of ASDL-GAN is not as good as that of traditional HILL. Based on ASDL-GAN, UT-GAN improves the generator, embedding simulator and discriminator of ASDL-GAN, exceeding the performance of traditional steganography methods; however, the above various methods are data-driven end-to-end, and the defect is that they rely heavily on the dataset. Summary of the Invention
[0004] The present invention aims to solve at least one of the technical problems existing in the prior art; for this purpose, the present invention proposes a JPEG image adversarial steganography method based on the UT-GAN model to solve the technical problems of the prior art's heavy dependence on the dataset and the weak anti-steganalysis performance of existing image steganography methods.
[0005] To achieve the above object, the present invention provides a JPEG image adversarial steganography method based on the UT-GAN model, including the following steps:
[0006] S1: Preprocess the carrier image C through the UT-GAN network to generate an adversarial steganographic image S;
[0007] S2: Establish a gradient calculator and a linear mapper, and re-adjust the gradients of the generated adversarial steganographic image S and the carrier image C in S1 to further generate an adversarial gradient matrix G;
[0008] S3: Dynamically adjust the adversarial gradient matrix G to obtain a cost matrix P;
[0009] S4: Obtain K adversarial steganographic images L from the cost matrix P;
[0010] S5: Select the optimal adversarial steganographic image Z from the K adversarial steganographic images L.
[0011] Furthermore: The specific steps of S1 are as follows:
[0012] S1-1: The generator based on U-Net converts the carrier image C into an embedding change probability map;
[0013] S1-2: Based on the change probability map and the random matrix N, use the hyperbolic tangent function to calculate and obtain a modified map M;
[0014] The value range of the random matrix N is between 0 and 1;
[0015] S1-3: Add the carrier image C and its corresponding modified map M to generate a stego adversarial image S, specifically: S = C + M.
[0016] Furthermore: In S2, when establishing the gradient calculator, the specific steps are as follows:
[0017] S2-1: Through the inverse discrete cosine transform IDCT, restore the spatial domain representations of the adversarial steganographic image S and the carrier image C;
[0018] S2-2: Re-non-fit DCT transform the pixels in the spatial domain representation image to obtain uncompressed distortion DCT coefficients;
[0019] S2-3: Perform residual filtering on the DCT coefficients, and through the combined operations of DCTR operation and NN-DCTR operation, separate the steganographic noise and the natural image content to generate a DCT matrix;
[0020] S2-4: Use phase splitting to refine the directionality of the DCT matrix, and split the DCT matrix into several sub-matrices;
[0021] S2-5: Statistically calculate the distribution characteristics of the histogram features of the sub-matrices, use a Gaussian histogram to capture the distribution shift caused by steganography to generate an objective function, and the objective function guides the generator of UT-GAN to adjust the steganography strategy to establish a gradient calculator.
[0022] Further: The echelon calculator performs an inverse operation on the loss function J of the carrier image C to generate an adversarial gradient matrix G.
[0023] Further: The specific steps of S3 are as follows:
[0024] S3-1: The carrier image C is preprocessed through the UT-GAN network to generate an identical embedding probability matrix , where each element represents the probability of modifying the pixel value by ±1 at the pixel value position (i, j);
[0025] S3-2: Since probability is inversely proportional to cost, the probability can be mapped to cost through negative logarithmic transformation, map the embedding probability matrix to a non-linearly increasing cost function and modify the embedding probability direction to generate a two-channel probability matrix, and then calculate the cost matrix P.
[0026] Further: The specific method of S4 is as follows:
[0027] Obtain the adversarial stego-image L from the cost matrix P adjusted in S3 through the STC simulator;
[0028] Determine the modification direction of each DCT coefficient through the interaction of random noise and cost;
[0029] Obtain the modification mapping in the STC simulator;
[0030] Use the Double-Tanh function as the embedding simulator, and construct a step function at all stages of obtaining the modification mapping during the training process;
[0031] Derive the step function, the generator, and the Double-Tanh function, continuously and dynamically adjust the cost matrix P, and approximate the optimal solution after K iterations. During this iterative process, K adversarial stego-images L are generated.
[0032] Further: The random noise is a random number uniformly distributed between 0 and 1.
[0033] Further: In S5, the optimal adversarial stego-image Z is defined as the image with the smallest distance from the carrier image C in the steganalysis space; this distance is measured in the NN-DCTR space; the selection process is normalized as follows:
[0034] ;
[0035] where d is the cover-stego distance calculation, the feature analysis feature vector of the carrier image C is denoted as , and the feature analysis feature vector of the adversarial stego-image Z is denoted as ; The set of adversarial steganographic images generated for K adversarial steganographic images L.
[0036] The beneficial effects of the present invention are as follows:
[0037] (1) A non-data-driven adversarial embedding scheme is proposed; compared with previous adversarial steganography schemes, the adversarial steganography in this application combines feature-based steganography and deep learning-based adversarial steganography, which not only avoids dependence on the dataset but also improves the anti-steganography performance of adversarial steganographic images.
[0038] (2) This application also proposes a novel gradient calculator, which replaces the deep learning-based steganalyzer (an algorithm for detecting hidden information in digital media) to calculate the adversarial gradient; different from traditional steganalysis, the design of the gradient calculator refers to the DCTR steganalysis, an approximate neural network as a steganographic feature extractor.
[0039] (3) Considering the trade-off between security and efficiency, in the implementation of the research scheme, first, the UT-GAN adversarial network is used to generate adversarial steganographic images, and on this basis, the cost is continuously modified through an embedding simulator, and finally, the optimal adversarial steganographic images are obtained. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] To more clearly illustrate the technical solutions in the embodiments of the present invention and the prior art, the following will briefly introduce the drawings required for description in the embodiments and the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0041] Figure 1 It is the flowchart of the method of the present invention;
[0042] Figure 2 It is the operation flowchart of the gradient calculator of the present invention;
[0043] Figure 3 It is the steganalysis space image of the optimal image selected by using the adversarial steganography network ADV-EMB provided by the present invention;
[0044] Figure 4 It is the steganalysis space image of the optimal image selected by using the method proposed by the present invention provided by the present invention;
[0045] Figure 5 It is the schematic diagram of the relationship between the steganography distance (d) and the covering steganography at different adjustable rates (k) by using different steganography algorithms provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be described and explained below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments provided by the present invention without creative efforts fall within the scope of protection of the present invention.
[0047] Obviously, the accompanying drawings in the following description are only some examples or embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, the present invention can also be applied to other similar scenarios based on these drawings.
[0048] In addition, it can also be understood that although the efforts made in this development process may be complex and lengthy, for those of ordinary skill in the art related to the content disclosed in the present invention, some design, manufacturing or production changes based on the technical content disclosed in the present invention are only conventional technical means and should not be understood as insufficient disclosure of the content of the present invention.
[0049] If there is no special instruction, all embodiments and optional embodiments of the present invention can be combined with each other to form new technical solutions.
[0050] Please refer to Figure 1 The method flow chart provided for the present invention, the steps are as follows:
[0051] S1: Preprocess the carrier image C through the UT-GAN network to generate an adversarial steganographic image S;
[0052] S2: Re-adjust the gradient of the adversarial steganographic image S and the carrier image C generated in S1 by establishing a gradient calculator and a linear mapper to generate an adversarial gradient matrix G;
[0053] S3: Dynamically adjust the adversarial gradient matrix G to obtain a cost matrix P;
[0054] S4: Further obtain K adversarial steganographic images L in the cost matrix P;
[0055] S5: Select the optimal adversarial steganographic image Z from the K adversarial steganographic images L.
[0056] Specifically:
[0057] S1-1: The generator based on U-Net converts the carrier image C into an embedding change probability map;
[0058] S1-2: Based on the change probability map and the random matrix N, use the hyperbolic tangent function to calculate and obtain the modified map M;
[0059] The value range of the random matrix N is between 0 and 1;
[0060] S1-3: Add the carrier image C and its corresponding modified image M to generate the steganography adversarial image S, specifically: S = C + M.
[0061] In S2, a gradient calculator is established. Please refer to Figure 2 , and the gradient calculator mainly includes 5 operations, specifically the following steps:
[0062] S2-1: Through the inverse discrete cosine transform IDCT, restore the spatial domain representations of the steganography adversarial image S and the carrier image C. This step is similar to converting the DCT coefficient matrix C to the spatial domain matrix W in DCTR; without considering the DC bias and dequantization, the following formula is the discrete cosine transform block transformation function:
[0063] ;
[0064] Among them, is the DCT coefficient matrix of the block, is the spatial matrix of the block, and are both parameters, and their values are: , When = 0, ; When ≠ 0, ≠ 0, ;
[0065] Since the inverse discrete cosine transform is divided into blocks, each block does not affect other blocks, so it is very suitable for designing the adversarial gradient; the gradient of each block in the DCT coefficient matrix is denoted as , and each element is denoted as ; similarly, the gradient of the spatial matrix W can be denoted as , and the element can be denoted as ; According to the differential chain calculation rule, can be obtained from the following formula:
[0066] ;
[0067] Among them, Indicates the sensitivity of the loss function to spatial or frequency domain variables. S2-2: Re-perform the non-fitting DCT transform on the pixels in the spatial domain representation image to obtain the DCT coefficients without compression distortion;
[0068] This step calculates the non-fitting DCT based on the spatial domain matrix W, which is equivalent to filtering the residual through 64 DCT kernels. The size of the DCT kernel is ; The kernel corresponding to the position (u, v) in the DCT domain is denoted as , and its elements can be calculated by the following formula:
[0069] ;
[0070] In NN-DCTR, this operation can be implemented by the convolution operation in CNN; the convolution kernel is fixed at ;
[0071] S2-3: Perform residual filtering on the DCT coefficients, and separate the steganographic noise and natural image content through the combined operation of DCTR operation and NN-DCTR operation;
[0072] This step is similar to the corresponding operation in DCTR;
[0073] In DCTR, this operation shortens the dynamic range of the residual to improve the efficiency of extracting the DCT matrix features contained in the histogram. The operation in DCTR is represented by the following formula:
[0074] ;
[0075] Among them, is the rounding function; is the truncation function; is the quantization parameter, which depends on the JPEG quantization factor, is the absolute value of the input value in the DCTR quantization operation;
[0076] In NN-DCTR, replace the DCTR formula with the following formula and fix T at 2:
[0077] ;
[0078] S2-4: Use phase splitting to refine the directionality of the DCT matrix and enhance the feature discrimination;
[0079] This step is the same as the DCT operation in DCTR; the DCT block size is , and then an unmodified DCT matrix is split into 64 sub-matrices; the non-fitting DCT matrix corresponding to the frequency (k, l) is denoted as , and its sub-matrix corresponding position (a, b) is denoted as , the following formula is a splitting function:
[0080] ;
[0081] S2-5: Statistically analyze the distribution characteristics of the residuals after splitting in each phase. The Gaussian histogram captures the distribution shift caused by steganography to generate an objective function. The objective function guides the generator of UT-GAN to adjust the steganography strategy to establish a gradient calculator, and further calculates the Gaussian histogram. This step is an approximation of calculating the histogram features of the submatrix extracted in S2-4. Since the operation of calculating the histogram is not differentiable, it cannot be directly applied to a fully differentiable structure. Therefore, a differentiable alternative method called the Gaussian histogram layer is adopted. It is an integral part of the neural network structure used to optimize the kernel of the semantic support peer-to-peer computing information retrieval model PSRM. It uses the accumulation of Gaussian functions to simulate histogram bins, and the specific formula is as follows:
[0082] ;
[0083] ;
[0084] ;
[0085] where g(d) represents the Gaussian histogram, represents the number of elements in set C, which is used for normalization; is an element of the DCT coefficient matrix; d represents the center position of the Gaussian kernel, that is, the discrete center value representing the histogram bin; D represents the total number of bins of the Gaussian histogram, that is, the discrete or continuous value range covered by the histogram is divided into D intervals; is the Dirac function, which is equal to 1 at c; k represents the horizontal frequency index of the two-dimensional discrete cosine transform (DCT) coefficient; is a parameter that determines the shape of the Gaussian function; represents L with respect to the Gaussian histogram The gradient of a certain bin in; Before calculating the histogram, the sub - matrices can also be merged to avoid excessive computational load; An unsampled discrete cosine transform (DCT) can be divided into 64 sub - matrices. According to symmetry and the most optimal merging strategy, these 64 sub - matrices can be merged into 25 matrices. (One unsampled DCT can be split into 64 sub - matrices, usually referring to an image being divided into 8×8 blocks (64 pixels), each block can be regarded as a sub - matrix and is ready for DCT transformation; Directly calculating the Gaussian histogram for each sub - matrix will result in a huge computational load because 64 independent histograms need to be processed. Merging based on symmetry; The merged sub - matrices can share some computational steps, such as histogram normalization and smoothing. Here, 25 is the optimal value of the sub - matrices merged based on symmetry).
[0086] In S2, the linear mapper is specifically as shown in the following formula:
[0087] ;
[0088] Among them, both w and b are parameters determined by the data, Z is the adversarial steganographic image, and the eigen - vector of the feature analysis of image Z is denoted as ; Since so , ; The purpose of generating the linear mapper is to construct the adversarial gradient of the original image for the loss function J; Given the original image C and the corresponding steganographic image S, w and b can be obtained from the following formula:
[0089] ;
[0090] ;
[0091] Among them, is the inner - product operation.
[0092] The specific method for generating the adversarial gradient matrix G is:
[0093] Define the loss function: For a neural network, its loss function is denoted as , specifically the loss function of the steganalysis detector ; S is the adversarial steganographic image; y is the target category of the adversarial steganographic image; Through the established gradient calculator, perform reverse operations, and for , represents the gradient of the loss function with respect to the pixels of the cover image C, which is used to optimize the local sensitivity of steganographic modification.
[0094] For the steganalysis detector , its criterion for determining whether the image S is an adversarial steganographic image is:
[0095] ;
[0096] Among them, Cover is the original image; Stego is the stego image.
[0097] In S3, the cost matrix P is dynamically adjusted according to the adversarial gradient matrix G, which specifically includes the following steps:
[0098] S3-1: The carrier image C is preprocessed through the UT-GAN network to generate an identical embedding probability matrix , where each element represents the probability of modifying the pixel value by ±1 at the pixel value position (i, j);
[0099] S3-2: Since probability is inversely proportional to cost, the probability can be mapped to cost through negative logarithmic transformation. The embedding probability is mapped to a non-linearly increasing cost function and the embedding probability direction is modified to generate a two-channel probability matrix, and then the cost matrix P is calculated. The two-channel probability matrix is as follows:
[0100] ;
[0101] Among them, is the probability of increasing the pixel value by 1, is the probability of decreasing the pixel value by 1, represents not making any modification at the pixel position (i, j), that is, keeping the original value.
[0102] In S4, in order to simulate message embedding, this step attempts to simulate STC, and the stego steganographic image is further generated from the adjusted cost in S3 through the STC simulator; for this purpose, a random noise is first generated, where is independent and identically distributed (i.i.d) for all i and j, and each element is drawn from a uniform distribution on the interval [0, 1];
[0103] By comparing P and , the modification mapping in the STC simulator is defined as follows:
[0104] ;
[0105] represents the modification simulated in the interval [-1, +1];
[0106] Since the above step function is non-differentiable, the Double-Tanh function is used as the embedding simulator to obtain the modification mapping All stages; it replaces the discrete step function with a differentiable approximation, making the backpropagation process in the GAN (Generative Adversarial Network) possible;
[0107] Construct the step function And take the derivatives of the generator and the Double-Tanh function, synchronously minimize the steganography detection probability and visual distortion, and iteratively update the parameters through backpropagation to continuously and dynamically adjust the obtained cost matrix P. During this process, new adversarial images will be generated. Through K parameter updates and image state iterations, gradually approach the Pareto optimal solution (i.e., the balance point with the lowest detection probability and the smallest distortion), thereby generating K adversarial steganographic images L.
[0108] The Double-Tanh function is defined as follows:
[0109] ;
[0110] Among them, the parameter λ controls the accuracy of the simulation. Set λ = 60, and finally use Double-Tanh to complete the message embedding.
[0111] In S5, as Figure 3 and Figure 4 shown, they are respectively the steganalysis space images for selecting the optimal image by the adversarial steganography network ADV-EMB provided in the embodiments of the present invention and the steganalysis space images for selecting the optimal image adopted in this article;
[0112] Select the adversarial steganographic image that meets the criteria as the optimal output. Usually, the criterion is to select the optimal image that can deceive the opponent and has the minimum adjustment cost;
[0113] Figure 3 Demonstrates the selection operation in the adversarial steganography network ADV-EMB; from a geometric perspective, the steganalyzer is a hyperplane in the steganalysis space, which divides the space into two parts corresponding to cover and steganography; in the space, the adversarial gradient G acts as the momentum approaching C and is perpendicular to the hyperplane; Z1, Z2, Z3 are candidates for the optimal steganographic image Z; according to the criterion, Z2 is the selection; Z3 is located in the steganography area (deceiving the opponent) and is close to the hyperplane (minimum adjustment cost); the criterion used in ADV-EMB requires the steganalyzer, so it depends on the knowledge of the dataset.
[0114] In contrast, the criterion of the algorithm used in this article does not depend on the dataset; the criterion is that the best steganographic image has the minimum distance from the cover image C in the steganalysis space; in the gradient calculator, the weights of the linear mapper are calculated using a single cover-stego pair (C, S); actually, the linear mapper constructs a hyperplane in the middle of C and S; as Figure 4As shown, the dashed line that divides the entire plane represents the hyperplane, which is located in the middle of C and S; G can be calculated with reference to the hyperplane.
[0115] Z1, Z2, and Z3 are candidates; according to this criterion, Z1 is selected because it has the smallest distance from C; this criterion stems from a general idea that the smaller the distance between distributions, the higher the probability of the distribution.
[0116] The criterion for the present invention to select the optimal adversarial stego-image is: the smallest distance from the cover image C in the steganalysis space, representing the optimal stego-image;
[0117] In the steganalysis space, the distance between two samples can be measured by the norm; the concept of the cover-stego distance is the distance between two samples reflected by the cover-stego operation; the calculation of the cover-stego distance is denoted as d; given the N-dimensional steganalysis feature set f, the calculation formula for the cover-stego distance between the cover image C and the adversarial stego-image S is as follows:
[0118] ;
[0119] After generating K adversarial stego-images L through K iterations, the generated set of adversarial stego-images is denoted as ;
[0120] Then, the best adversarial stego-image Z is selected from the K adversarial stego-images L; the optimal stego-image Z has the characteristic of the smallest cover-stego distance to the cover image C in the steganalysis feature space; this distance is measured in the NN-DCTR space; the selection process can be standardized as follows:
[0121] ;
[0122] where d is the calculation of d in the above formula The eigenanalysis feature vector of the cover image C is denoted as and the eigenanalysis feature vector of the adversarial stego-image Z is denoted as .
[0123] A specific embodiment provided by the present invention:
[0124] Detection performance analysis: NN-DCTR is a fully differentiable version of DCTR; the detection performance of NN-DCTR was experimentally tested and compared with DCTR; the experimental results are shown in Table 1:
[0125]
[0126] Steganalyzer: is a tool or algorithm used to detect hidden information in images or other media;
[0127] Steganography: Steganography;
[0128] For security performance;
[0129] As can be seen from Table 1: When traditional steganography selects the J-UNIWARD steganography algorithm and the UERWARD steganography algorithm, the total error rate of NN-DCTR (e.g., the part corresponding to the J-UNIWARD steganography algorithm 48.7 + 46.1 + 41.6 + 38.7) is significantly greater than that of DCTR, and its detection performance slightly decreases; however, in DCTR, rounding operations and histogram operations are non-differentiable. Although there is an error in the differentiation of NN-DCTR compared with the original version, resulting in a loss of detection performance; despite the loss, considering that NN-DCTR has the ability of differentiable rounding operations and histogram operations, NN-DCTR is still an effective alternative to DCTR.
[0130] Optimal adversarial stego-image selection: In SE (the steganography algorithm provided by the present invention), the selection of the optimal adversarial stego-image is an important part of this scheme; as introduced in the present invention, the selection criterion of the present invention is the covering stego-distance d; adjust the number of adjustable elements k to generate multiple adversarial stego-images; select the stego-image with the smallest d as the optimal image; in this section, multiple adversarial stego-images are generated at different adjustable rates k; and the cover-stego (the pair of the original image and the image after embedding the secret information) distance d is visualized; select the image marked 1013 as an example, the payload rate is fixed at 0.4 bpnzac, and there are 9 adjustable ratios in each scheme, k ∈ {0.1, 0.2, …, 0.9}.
[0131] As Figure 5 shown: The result comparison diagrams of respectively adopting the J-UINWAED and UERD steganography algorithms (named J-SE and U-SE respectively) and the steganography algorithm SE proposed in this paper; it can be seen that the covering stego-distance changes with the change of the adjustable rate; selecting the rate with the smallest covering-stego distance is optimal; for different algorithms, the minimum covering-stego distance of SE is smaller than that of U-SE and J-SE, and for the covering-stego distances at different ratios, the average stego-distance of SE is less than that of J-SE and U-SE, and according to the smaller the covering-stego distance, the more "accurate" the generated adversarial gradient; thus, it is concluded that the adversarial steganography algorithm proposed in this paper generates a more "accurate" adversarial gradient.
[0132] Non - adversarial Steganalysis Test: In this part of the test, the steganographer knows the structure of the steganalyzer, but the steganalyzer does not know the adversarial embedding operation. That is, the steganalyzer is a non - adversarial steganalyzer. In this experiment, the DCTR steganalyzer, SRM steganalyzer, and GFR steganalyzer are used as the target steganalyzers and are trained by the image set ; The SE algorithm is the method proposed in the present invention. It calculates the gradient to modify the embedding cost using an embedding simulator, thereby generating an adversarial stego - image dataset ; To compare the transferability of the adversarial stego - images, the experiment is also tested under the condition of non - adversarial steganalysis testing; The experiment is tested at embedding rates from 0.1 to 0.4 respectively;
[0133] Here, the following introductions are made for each item used:
[0134] Steganalyzer is a steganalyzer, which are the DCTR steganalyzer, SRM steganalyzer, and GFR steganalyzer in sequence, and all are trained by the cover image C and traditional stego - images;
[0135] ASDL - GAN: Automatic Steganographic Distortion Learning Generative Adversarial Network;
[0136] UT - GAN: A steganography embedding framework based on the Generative Adversarial Network (GAN), whose main feature is to combine a U - Net generator and a dual TAN function to optimize the embedding cost;
[0137] SPAR - RL: An automatic image steganography embedding framework based on deep reinforcement learning;
[0138] It can be seen that although the security performance of each steganography algorithm in the non - adversarial steganalyzer decreases as the embedding rate increases, it can be clearly seen that when using the method SE of this application in the DCTR steganalyzer, SRM steganalyzer, and GFR steganalyzer respectively, in the range of embedding rates from 0.1 to 0.4, the accuracy corresponding to the embedding rate is stably among the top two of the accuracies corresponding to each embedding rate of all steganography methods. The specific analysis results are shown in Table 2 below:
[0139]
[0140] Adversarial Steganalysis Test: In this part of the test, the steganographer knows the structure of the steganalyzer, and at the same time the steganalyzer knows the adversarial embedding operation, that is, the steganalyzer is an adversarial steganalyzer; in this experiment, the CuNet steganalyzer, SRNet steganalyzer and CovNet steganalyzer are used as adversarial steganalyzers and trained by the image set; the embedding simulator is used to calculate the gradient to modify the embedding cost, so as to generate an adversarial steganographic image dataset; the experiment was tested at embedding rates from 0.1 to 0.4; as shown in Table 3 below:
[0141]
[0142] The Steganalyzer is a steganalyzer, which are the CuNet steganalyzer, SRNet steganalyzer and CovNet steganalyzer in turn, and all are trained by the carrier image C and traditional steganographic images; Steganography is a steganographic algorithm. In the experiment, the traditional steganographic algorithm J-UNIWARD, the GAN-based steganographic method, and the adversarial-sample-based steganographic algorithm SE proposed in this paper are compared.
[0143] It can be seen that although the security performance of each steganographic algorithm in the adversarial steganalyzer decreases as the embedding rate increases, it can be clearly seen that when using the inventive method SE in the CuNet steganalyzer, SRNet steganalyzer and CovNet steganalyzer respectively, in the embedding rate change of 0.1 - 0.4, the accuracy corresponding to the embedding rate is also stable among the top two of the accuracies corresponding to each embedding rate of all steganographic methods, and is more stable while maintaining a high accuracy.
[0144] The above has given a very detailed application description of one or more embodiments of the present invention, but the content described is only a specific example of the present invention and cannot be considered as limiting the scope of implementation of the present invention. Any other methods and changes proposed based on the content of the present invention should fall within the scope of patent protection of the present invention.
Claims
1. A JPEG image adversarial steganography method based on the UT-GAN model, characterized in that: The steps include: S1: Preprocess the carrier image C through the UT-GAN network to generate the adversarial steganographic image S; S2: Establish a gradient calculator and a linear mapper to re-adjust the gradients of the adversarial stego-image S and the carrier image C generated in S1, and further generate an adversarial gradient matrix G; S3: Dynamically adjust the adversarial gradient matrix G to obtain the cost matrix P; S4: Obtain K adversarial steganographic images L in the cost matrix P; S5: Select the best adversarial stego image Z from the K adversarial stego images L; In S2, a gradient calculator is established, which specifically includes the following steps: S2-1: Recover the spatial domain representation of the adversarial steganographic image S and the carrier image C through inverse discrete cosine transform IDCT; S2-2: re-perform non-fitting DCT transformation on the pixels in the spatial domain representation image to obtain DCT coefficients without compression distortion; S2-3: Perform residual filtering on the DCT coefficients, separate the steganographic noise from the natural image content through the combined operation of DCTR operation and NN-DCTR operation, and generate a DCT matrix; S2-4: Phase splitting is used to refine the directionality of the DCT matrix, and the DCT matrix is split into several sub-matrices; S2-5: The statistical submatrix calculates the distribution characteristics of the histogram features, and uses the Gaussian histogram to capture the distribution shift caused by steganography to generate the objective function. The objective function guides the generator of UT-GAN to adjust the steganography strategy and establish a gradient calculator.
2. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: The S1 specifically includes the following steps: S1-1: The U-Net-based generator converts the carrier image C into an embedding change probability map; S1-2: Based on the change probability graph and the random matrix N, the modified graph M is calculated using the hyperbolic tangent function; The value range of the random matrix N is between 0 and 1; S1-3: Add the carrier image C and its corresponding modified image M to generate a dense adversarial image S, specifically: S=C+M.
3. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: In S2, The gradient calculator performs the reverse operation on the loss function J of the carrier image C to generate the adversarial gradient matrix G.
4. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: The S3 specifically includes the following steps: S3-1: Preprocess the carrier image C through the UT-GAN network to generate the same embedding probability matrix , where each element Indicates the probability of modifying the pixel value at the pixel value position (i, j) by ±1; S3-2: Since the probability is inversely proportional to the cost, the probability can be mapped to the cost through a negative logarithmic transformation, and the embedded probability matrix Map it into a nonlinear increasing cost function and modify the embedding probability direction to generate a dual-channel probability matrix, and then calculate the cost matrix P.
5. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: The specific method of S4 is: Obtain the adversarial steganographic image L from the cost matrix P adjusted in S3 through the STC simulator; Determine the modification direction of each DCT coefficient through the interaction of random noise and cost; Get the modified mapping in the STC simulator; The Double-Tanh function is used as an embedding simulator to obtain all stages of the modified mapping during the training process and construct a step function; The step function, generator and Double-Tanh function are derived, and the cost matrix P is continuously and dynamically adjusted. After K iterations, the optimal solution is approached. In this iterative process, K adversarial steganographic images L are generated.
6. The JPEG image anti-steganography method based on the UT-GAN model according to claim 5 is characterized in that: The random noise is a random number uniformly distributed between 0 and 1.
7. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: In S2-5: Sub-matrices can also be merged, and the merging process is based on the symmetry of all matrices and the merging strategy adopted; Merging strategies include horizontal merging, vertical merging, and block merging.
8. The JPEG image anti-steganography method based on the UT-GAN model according to claim 1, characterized in that: In S5, the optimal adversarial stegographic image Z is defined as the image with the smallest distance to the carrier image C in the steganalysis space; the distance is measured in the NN-DCTR space; the selection process is standardized as follows: ; Among them, d is the coverage-steganography distance calculation, and the feature analysis feature vector of the carrier image C is recorded as , the feature analysis feature vector of the adversarial steganalysis image Z is recorded as ; The set of adversarial steganagrams generated for K adversarial steganagrams L.
Citation Information
Patent Citations
Image confrontation steganography method and device based on joint distortion
CN115695673A