Regitive image steganography detection method and system and medium

Representative images are obtained through sampling and selection, and features are extracted using step-by-step analysis network and target feature matrix is ​​constructed. The target classifier is trained for steganography detection, which solves the problem of inaccurate image steganography information detection in the prior art, and achieves high accuracy and robustness of adversarial image steganography detection.

CN120047738APending Publication Date: 2025-05-27DONGHUA UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510122502.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, image steganography information detection is inaccurate and is particularly susceptible to adversarial embedding attacks, resulting in low detection accuracy.

Method used

By sampling and selecting, sub-images and representative images representing the original carrier image are obtained, and features are extracted using pre-trained step-analysis residual networks and target feature matrix is ​​constructed, and the target classifier is trained for steganography detection.

Benefits of technology

Effectively detecting steganographic images with adversarial perturbations improves the robustness and accuracy of the target classifier in image steganographic detection tasks and avoids adversarial sample attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047738A_ABST
    Figure CN120047738A_ABST
Patent Text Reader

Abstract

The invention provides an adversarial image steganography detection method and system and a medium, and the method comprises the steps: inputting a carrier image, and calculating the gradient value of each pixel in the carrier image; sampling the carrier image to obtain a plurality of sub-images; calculating an average gradient value of each sub-image according to the gradient values, sorting the sub-images according to the average gradient values and grouping the sub-images in sequence to obtain a plurality of sub-image sets, and respectively selecting representative images from each sub-image set; extracting feature vectors of the carrier image and the representative image to form a target feature matrix; training a classifier according to the target feature matrix to obtain a target classifier, and performing steganography detection on the to-be-detected image through the target classifier; according to the method, the robustness and accuracy of the target classifier in the image steganography detection task are improved, the adversarial samples can be effectively detected and screened out, and the application of the security steganography detection technology is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of image processing, relates to information hiding technology, particularly to image steganography detection, and specifically is an adversarial image steganography detection method, system and medium. Background Art

[0002] Steganography is an information hiding technology. The purpose of steganography is to embed certain secret information into carrier files and conceal the existence of this information by making reasonable modifications and adjustments to these files, so as to achieve the purpose of hiding communication.

[0003] Steganalysis aims to detect hidden information in a medium. Traditional image steganography detection is based on statistical methods and uses tools such as feature extractors and support vector machines (SVMs), but the accuracy is limited and it is vulnerable to attacks. In recent years, the application of convolutional neural networks (CNNs) has improved the accuracy of steganalysis. However, steganography is vulnerable to adversarial samples, and the analyzer is misled by adding imperceptible adversarial embeddings to the image. Summary of the Invention

[0004] The purpose of the present invention is to provide an adversarial image steganography detection method, system and medium, which are used to solve the problem of inaccurate detection of image steganographic information in the prior art.

[0005] In a first aspect, the present invention provides an adversarial image steganography detection method, and the method includes: inputting a carrier image and calculating the gradient value of each pixel in the carrier image; sampling the carrier image by using a sampling window to obtain a plurality of sub-images corresponding to the carrier image; calculating the average gradient value of each sub-image according to the gradient value, sorting the sub-images according to the average gradient value, sequentially dividing the sorted sub-images into a plurality of sub-image sets according to a preset quantity, and respectively selecting at least one sub-image from the sub-images included in each sub-image set as the representative image corresponding to the sub-image set; extracting the feature vector of the carrier image and the feature vector of the representative image through a stepwise analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image; training a classifier according to the target feature matrix to obtain a target classifier, and performing steganography detection on a to-be-detected image through the target classifier.

[0006] In an implementation manner of the first aspect, when the number of the sampled sub-images is less than a preset threshold, a sampling starting point is randomly selected for sampling.

[0007] In an implementation manner of the first aspect, the step of sequentially dividing the sorted sub-images into a plurality of sub-image sets according to a preset quantity includes: sequentially selecting a preset quantity of the sorted sub-images in order as a sub-image set until grouping is completed for each of the sub-images; wherein, the quantity of sub-images included in the last sub-image set is less than or equal to the preset quantity.

[0008] In an implementation manner of the first aspect, the preset quantity is greater than or equal to three; three sub-images are respectively selected from the sub-images included in each of the sub-image sets as the representative images corresponding to the sub-image sets; the representative images include: a first representative image, a second representative image, and a third representative image; the step of respectively selecting at least one sub-image from the sub-images included in each of the sub-image sets as the representative image corresponding to the sub-image set includes: selecting the sub-image with the largest average gradient value in each of the sub-image sets as the first representative image; selecting the sub-image with the smallest average gradient value in each of the sub-image sets as the second representative image; randomly selecting one sub-image in each of the sub-image sets as the third representative image.

[0009] In an implementation manner of the first aspect, the step of extracting the feature vector of the carrier image and the feature vector of the representative image through the step-by-step analysis residual network and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image includes: extracting the feature vector of the carrier image through the step-by-step analysis residual network; calculating the steganographic probability of the representative image according to the average gradient value; according to the steganographic probability, extracting the feature vector of the representative image through the step-by-step analysis residual network and calculating the statistic of the feature vector of the representative image; splicing the statistics together to form a statistic matrix, and splicing the statistic matrix with the feature vector of the carrier image to form the target feature matrix.

[0010] In an implementation manner of the first aspect, the statistics at least include the maximum value, minimum value, average value, and variance of the feature vector of the representative image.

[0011] In an implementation manner of the first aspect, the feature vectors of the carrier image and the representative image are both N-dimensional; the quantity of the carrier images is K; the number of rows of the target feature matrix is K, and the number of columns of the target feature matrix is N×(m + γ); wherein, m represents the number of the statistics; γ represents the number of the sub-image sets.

[0012] In a second aspect, the present invention provides an adversarial image steganography detection system, which includes: a calculation module for inputting a carrier image and calculating the gradient value of each pixel in the carrier image; a sampling module for sampling the carrier image using a sampling window to obtain a plurality of sub-images corresponding to the carrier image; a sorting module for calculating the average gradient value of each sub-image according to the gradient value, sorting the sub-images according to the average gradient value, sequentially dividing the sorted sub-images into a plurality of sub-image sets according to a preset quantity, and respectively selecting at least one sub-image from the sub-images included in each sub-image set as the representative image corresponding to the sub-image set; a splicing module for extracting the feature vector of the carrier image and the feature vector of the representative image through a step-by-step analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image; a detection module for training a classifier according to the target feature matrix to obtain a target classifier, and performing steganography detection on a to-be-detected image through the target classifier.

[0013] In a third aspect, the present invention also discloses a computer-readable storage medium, on which a computer program is stored, and when the program is executed, the above-mentioned adversarial image steganography detection method is implemented.

[0014] As described above, the adversarial image steganography detection method, system and medium of the present invention have the following beneficial effects:

[0015] In this application, sub-images and representative images representing the original carrier image are obtained through sampling and selection, and a pre-trained step-by-step analysis residual network is used to extract features from the images and construct a target feature matrix. Then, a classifier is trained according to the target feature matrix to obtain a target classifier, and finally, steganography detection is performed on the carrier image to be detected (i.e., the to-be-detected image) according to the target classifier, so as to effectively detect steganographic images with adversarial perturbations. While retaining the prediction ability of the target classifier, the target classifier is also protected from adversarial sample attacks, improving the robustness and accuracy of the target classifier in the image steganography detection task. This method can effectively detect and screen out adversarial samples, which is helpful for applying secure steganography detection technology. Description of the Drawings

[0016] Figure 1 It shows a flowchart of the adversarial image steganography detection method described in an embodiment of the present invention.

[0017] Figure 2 It shows a structural block diagram of the adversarial image steganography detection system described in an embodiment of the present invention. Detailed Embodiments

[0018] The following describes the implementation manners of the present invention through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0019] It should be noted that the diagrams provided in the following embodiments only schematically illustrate the basic concept of the present invention. The diagrams only show the components related to the present invention rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0020] Refer to Figure 1 and Figure 2 The following embodiments of the present invention provide an adversarial image steganography detection method, system, and medium. By sampling and selection, sub-images and representative images representing the original carrier image are obtained, and a pre-trained step analysis residual network is used to extract features from the images and construct a target feature matrix. The classifier is trained according to the target feature matrix to obtain a target classifier, and finally, the carrier image to be detected (i.e., the image to be tested) is subjected to steganography detection according to the target classifier, so as to effectively detect steganographic images with adversarial perturbations. While retaining the prediction ability of the target classifier, the target classifier is also protected from adversarial samples, improving the robustness and accuracy of the target classifier in the image steganography detection task. This method can effectively detect and screen out adversarial samples, which helps to apply secure steganography detection technology.

[0021] Next, the technical solutions in the embodiments of the present invention will be described in detail with reference to the accompanying drawings in the embodiments of the present invention.

[0022] As Figure 1 shown, in an embodiment, the present invention provides an adversarial image steganography detection method, and the method includes the following steps:

[0023] S101. Input a carrier image and calculate the gradient value of each pixel in the carrier image.

[0024] It should be noted that since steganographic embedding algorithms usually attempt to make minimal modifications to the image to hide information, this means that only a part of the pixels will be changed. For each pixel in the input carrier image, calculate its gradient value to facilitate subsequent segmentation sampling of the carrier image according to the gradient value of the pixel. The gradient value can reflect the degree of change of the pixel value in the image, and usually operators such as Sobel or Prewitt are used to calculate.

[0025] Furthermore, a heat map can be generated based on the gradient value of each pixel. In the heat map, regions with higher brightness represent pixels with larger gradient values, and these regions may contain more steganographic information. By comparing the residual images of the cover image and the stego image after steganographic processing, the distribution of steganographic embedding is analyzed. The residual image shows the changes caused by steganographic embedding, and sparsity means that these changes are mainly concentrated in certain regions of the image. The steganographic probability of each pixel being used for steganographic embedding is estimated using the pixel gradient value. Pixels with higher gradient values are more likely to be used for steganography because their changes can be more naturally incorporated into the texture and contour of the image.

[0026] S102. Sample the cover image using a sampling window to obtain multiple sub-images corresponding to the cover image.

[0027] In this embodiment, first, a cover image of the original input is sampled using a sampling window of a preset size, where the window and step size are a×a and b respectively, to obtain multiple sub-images.

[0028] It should be noted that during the sampling process, when the number of the obtained sub-images is less than the preset threshold c, the sampling starting point is randomly selected for sampling. For each cover image, c sub-images are ensured to be obtained.

[0029] It should be noted that the specific value set for the preset threshold c is not a condition limiting the present invention. In practical applications, it can be set according to the specific application scenario.

[0030] The purpose of randomly selecting the sampling starting point is to increase the randomness and coverage of sampling, ensure that features are evenly captured from different regions of the image, avoid sampling bias, and reduce the omission of important information. This method helps to improve the generalization ability of the target classifier because it can enable the target classifier to access more diverse data, thus having good performance for different image sizes and contents. In addition, random sampling helps to ensure that the set of sampled sub-images can comprehensively represent the entire image as much as possible, providing a rich data basis for subsequent image analysis or machine learning tasks.

[0031] S103. Calculate the average gradient value of each sub-image according to the gradient value, sort the sub-images according to the average gradient value, divide the sorted sub-images into multiple sub-image sets in sequence according to a preset quantity, and select at least one sub-image from the sub-images included in each sub-image set as the representative image corresponding to the sub-image set.

[0032] Specifically, after obtaining c sub-images through sampling, the average gradient value of each sub-image is calculated according to the gradient value of each pixel of the carrier image obtained previously. Subsequently, the sub-images are sorted according to the average gradient value of each sub-image, and this average gradient value represents the steganographic probability of the pixels in the sub-image.

[0033] In this embodiment, the preset quantity is less than or equal to the preset threshold.

[0034] It should be noted that the specific value set for the preset quantity is not a condition for limiting the present invention. In actual applications, it can be set according to the specific application scenario.

[0035] In one embodiment, the step of sequentially dividing the sorted sub-images into multiple sub-image sets according to a preset quantity includes: sequentially selecting a preset quantity of the sorted sub-images as a sub-image set in order until grouping is completed for each of the sub-images.

[0036] Wherein, the number of sub-images included in the last sub-image set is less than or equal to the preset quantity.

[0037] Specifically, after sorting, every x (corresponding to the preset quantity) sorted sub-images are divided into a group (i.e., a sub-image set). For example, it is set that four (i.e., the preset quantity is 4) sub-images are in a group. Then, a representative sub-image is randomly selected from each group as the representative image.

[0038] In this way, the c sub-images sampled from each original carrier image are finally divided into γ sub-image sets. The following formula is satisfied:

[0039] represents rounding up.

[0040] In one embodiment, a sub-image is selected from the sub-images included in each sub-image set as the representative image corresponding to the respective sub-image set.

[0041] For example, if c is set to 16, 24, or 32, and x is set to 4, then 4, 6, or 8 sub-image sets will be obtained respectively. Each sub-image set contains 4 sub-images, and finally 4, 6, or 8 representative images will be obtained respectively; if c is set to 15 and x is set to 4, then 4 sub-image sets will be obtained, but the first 3 sub-image sets each contain 4 sub-images, and the last sub-image set only contains 3 sub-images, and finally 4 representative images will also be obtained. These representative images are subsequently used for feature extraction for subsequent steganalysis.

[0042] In one embodiment, the sub-images are sorted in ascending order of the average gradient value.

[0043] Among them, the sorting process of the sub-images is expressed by the following formula:

[0044] [P r1 ,P r2 ,...,P rc ,[r 1 ,r 2 ,...,r c = sort([P 1 ,P 2 ,...,P c ,[G 1 ,G 2 ,...,G c );

[0045] Among them, P r1 ,P r2 ,...,P rc respectively represent the 1st, 2nd,..., c-th sub-images after sorting; r 1 ,r 2 ,...,r c respectively represent the 1st, 2nd,..., c-th sub-images P r1 ,P r2 ,...,P rc 's average gradient values; P 1 ,P 2 ,...,P c respectively represent the 1st, 2nd,..., c-th sub-images before sorting (i.e., multiple sub-images obtained by directly sampling the carrier image), G 1 ,G 2 ,...,G c respectively represent the 1st, 2nd,..., c-th sub-images P 1 ,P 2 ,...,P c 's average gradient values.

[0046] It should be noted that the sort function uses common sorting techniques in the field to sort the sub-images according to the average gradient values so as to process the sub-images in a specific order, so it will not be elaborated in detail here.

[0047] Specifically, through the sort function, each sub-image is sorted according to its average gradient value for subsequent selection of representative images with different steganography probabilities.

[0048] In one embodiment, the preset quantity is greater than or equal to three; three sub-images are respectively selected from the sub-images included in each of the sub-image sets as the representative images corresponding to the sub-image sets; the representative images include: a first representative image, a second representative image, and a third representative image.

[0049] In this embodiment, the step of respectively selecting at least one sub-image from the sub-images included in each of the sub-image sets as the representative image corresponding to the sub-image set includes: selecting the sub-image with the largest average gradient value in each of the sub-image sets as the first representative image; selecting the sub-image with the smallest average gradient value in each of the sub-image sets as the second representative image; randomly selecting one sub-image in each of the sub-image sets as the third representative image.

[0050] Specifically, the sub-image with the largest average gradient value is selected as the first representative image in each sub-image set. Since the gradient value can reflect the degree of pixel change in the image, a higher average gradient value may indicate that the sub-image contains more edge or texture information, and this information may be related to steganographic embedding. Therefore, this sub-image with the largest average gradient value is selected as the representative image because it may contain more features related to steganographic embedding.

[0051] The sub-image with the smallest average gradient value is selected as the second representative image in each sub-image set. Since the gradient value can reflect the degree of pixel change in the image, the sub-image with the smallest average gradient value represents the area with less change in the image. These areas may not be used for steganographic embedding or the impact of steganographic embedding is small. Such sub-images can provide supplementary information for analysis to help the target classifier understand the characteristics of the image without steganographic embedding.

[0052] One sub-image is randomly selected in each of the sub-image sets as the third representative image to increase the diversity and representativeness of the samples. During the process of sub-image sampling and analysis, this method helps to ensure that not only the areas with the highest or lowest gradient values are concerned, but also a wider range of features can be captured from different parts of the image.

[0053] S104. Extract the feature vectors of the carrier image and the representative images through a step-by-step analysis residual network, and form a target feature matrix based on the feature vectors of the carrier image and the representative images.

[0054] It should be noted that the purpose of extracting the feature vectors of the carrier image is to capture the key information in the carrier image, and this information can be used for subsequent steganalysis. Specifically, the feature vectors of the carrier image are extracted through step-by-step analysis of the residual network. These feature vectors reflect the steganographic probability and statistical characteristics in the carrier image. The feature vectors of these carrier images provide the basis for constructing the target feature matrix, helping the target classifier learn how to identify steganographic information from the image, thereby improving the accuracy and robustness of steganalysis detection.

[0055] Since the formula for the steganographic probability of image measurement is as follows:

[0056] y = F γ (p 1:γ , g 1:γ );

[0057] Wherein, F γ () represents the functional relationship between the extracted feature vector representing the image, the sub-image sampling, and the steganographic probability; y represents the extracted feature vector representing the image; p 1:γ represents γ representative sub-image sets obtained by sampling, sorting, and grouping from the carrier image; these sub-image sets are obtained through the sorting and selection process described above, and each sub-image set represents a specific part or feature of the carrier image, g 1:γ represents the steganographic probability corresponding to the sub-images in p 1:γ , and these steganographic probabilities are calculated based on the average gradient value of each sub-image, reflecting the possibility of each sub-image being used for steganographic embedding; for any input image, the feature vector can be obtained.

[0058] It should be noted that the F γ () function is implemented through a specific feature engineering method. Specifically, first, a pre-trained SRNet model is used as a feature extractor to extract 512-dimensional feature vectors from each sub-image. Then, the correlation in the original image is reconstructed by calculating the maximum value, minimum value, mean value, and variance of these feature vectors, thereby obtaining the final input feature vector. The technical means adopted are conventional in the field, so it will not be elaborated in detail here.

[0059] In one embodiment, both the feature vector of the carrier image and the feature vector of the representative image are N-dimensional.

[0060] In one embodiment, N is 512.

[0061] In one embodiment, extracting the feature vector of the carrier image and the feature vector of the representative image through step-by-step analysis of the residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image includes:

[0062] Extract the feature vector of the carrier image through the step - by - step analysis residual network;

[0063] Calculate the steganographic probability of the representative image according to the average gradient value;

[0064] According to the steganographic probability, extract the feature vector of the representative image through the step - by - step analysis residual network, and calculate the statistic of the feature vector of the representative image;

[0065] Stitch the statistics together to form a statistical matrix, and stitch the statistical matrix and the feature vector of the carrier image together to form the target feature matrix.

[0066] In one embodiment, the statistics at least include, but are not limited to, the maximum value, minimum value, average value and variance of the feature vector of the representative image.

[0067] It should be noted that through the calculation of statistics, the target classifier can better understand the distribution and variation of features, thereby improving the accuracy of steganography detection.

[0068] It should be noted that the purpose of the above stitching is to integrate the original features (i.e., the feature vector of the carrier image) and statistical features (i.e., the corresponding statistical matrix) to provide richer information to the classifier. This feature fusion method can help the target classifier capture the global and local patterns of steganographic embedding in the carrier image, thereby improving the accuracy of steganalysis. By combining statistics such as the maximum value, minimum value, average value and variance, the target classifier can better understand the distribution and variation of features, which is especially important when dealing with images with steganographic embedding.

[0069] In one embodiment, the number of carrier images is K; the number of rows of the target feature matrix is K, and the number of columns of the target feature matrix is N×(m + γ); where m represents the number of statistics; γ represents the number of sub - image sets.

[0070] In this embodiment, K≥1 and K is an integer; m≥1 and m is an integer.

[0071] For example, in one embodiment, N = 512, m = 4 (i.e., the statistics include the maximum value, minimum value, average value, variance), then the number of columns of the corresponding target feature matrix is 512×(4 + γ).

[0072] It should be noted that for each original carrier image, γ sub-image sets obtained through sampling and sorting can yield a 512×γ-dimensional feature vector through feature extraction; in this embodiment, if there are K carrier images, after feature extraction, a γ feature matrix with K rows and 512 columns can be obtained, facilitating the construction of a sufficiently large data set, which will be used to train or validate the steganalysis model (i.e., the target classifier). This data set should contain a sufficient number of samples so that the steganalysis model can learn how to identify the presence of steganography from statistical features. These originally input carrier images may include normal images (images without steganographic content) and images with steganographic content. Such a data set can help the steganalysis model distinguish between these two cases. This ensures that the steganalysis model can generalize to new, unseen images, rather than just performing well on specific images seen during training. By using multiple carrier images, the steganalysis model can learn more generalized features, thereby improving its effectiveness and accuracy in practical applications. This also helps evaluate the robustness of the steganalysis model under different images and conditions.

[0073] Specifically, for K carrier images, 512-dimensional feature vectors of each carrier image are obtained through feature extraction (such as using a pre-trained SRNet); for each carrier image, γ sub-image sets are obtained through sampling, and each sub-image set corresponds to a 512-dimensional feature vector (corresponding to the feature vector of the representative image mentioned above); for every γ sub-image sets, the statistics of their 512-dimensional feature vectors are calculated respectively: maximum value, minimum value, average value, and variance, which will generate 4 statistics, and each statistic is a 512-dimensional vector. By concatenating the above 4 statistics, a matrix with K rows and 512×4 columns is formed. This matrix contains the statistical information of the carrier image features. Subsequently, the statistical matrices of each sub-image set are concatenated to form a larger target feature matrix. Each row of this target feature matrix represents a carrier image, and each column represents a feature (including the original features corresponding to the carrier image and the statistical features corresponding to the representative image). The dimension of the final target feature matrix is K rows and 512×(4 + γ) columns.

[0074] It should be noted that during the steganalysis process, after the target feature matrix is obtained in step S104, this target feature matrix is subsequently used to train a classifier, such as a support vector machine or an ensemble classifier, to enable it to identify whether there is steganographic information in the image. By combining the statistical matrices of all representative images with the feature vectors of the carrier images and concatenating them into a larger target feature matrix, the dimension of this target feature matrix is extended to K rows and 512×(4 + γ) columns.

[0075] S105. Train a classifier based on the target feature matrix to obtain a target classifier, and perform steganography detection on the image to be tested through the target classifier.

[0076] Specifically, use the target feature matrix obtained in step S104 to train the classifier, so that the trained target classifier can predict a new image to be tested and determine whether it contains steganographic information, thereby achieving effective steganography detection. This process not only improves the detection accuracy but also enhances the robustness of the target classifier against adversarial attacks.

[0077] The protection scope of the adversarial image steganography detection method described in the embodiments of the present invention is not limited to the execution order of the steps listed in this embodiment. Any solution achieved by adding or subtracting steps of the prior art and replacing steps according to the principles of the present invention is included in the protection scope of the present invention.

[0078] The embodiments of the present invention also provide a computer-readable storage medium, on which a computer program is stored. When the program is executed by an electronic device, the above-mentioned adversarial image steganography detection method is implemented.

[0079] Those of ordinary skill in the art can understand that all or part of the steps in the method of the above embodiments can be completed by instructing a processor through a program. The program can be stored in a computer-readable storage medium. The storage medium is a non-transitory medium, such as random access memory, read-only memory, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof. The above storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid-state disk (SSD)).

[0080] The embodiments of the present invention also provide an adversarial image steganography detection system. The adversarial image steganography detection system can implement the adversarial image steganography detection method described in the present invention. However, the implementation devices of the adversarial image steganography detection method described in the present invention include, but are not limited to, the structure of the adversarial image steganography detection system listed in this embodiment. Any structural deformation and replacement of the prior art made according to the principles of the present invention are included in the protection scope of the present invention.

[0081] Such as Figure 2As shown, in one embodiment, the present invention provides an adversarial image steganography detection system, which includes:

[0082] A calculation module 201 for inputting a carrier image and calculating the gradient value of each pixel in the carrier image.

[0083] A sampling module 202 for sampling the carrier image using a sampling window to obtain a plurality of sub-images corresponding to the carrier image.

[0084] A sorting module 203 for calculating the average gradient value of each sub-image according to the gradient value, sorting the sub-images according to the average gradient value, sequentially dividing the sorted sub-images into a plurality of sub-image sets according to a preset quantity, and respectively selecting at least one sub-image from the sub-images included in each sub-image set as the representative image corresponding to the sub-image set.

[0085] A splicing module 204 for extracting the feature vector of the carrier image and the feature vector of the representative image through a step-by-step analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image.

[0086] A detection module 205 for training a classifier according to the target feature matrix to obtain a target classifier, and performing steganography detection on a to-be-detected image through the target classifier.

[0087] It should be noted that the structures and principles of the calculation module 201, the sampling module 202, the sorting module 203, the splicing module 204, and the detection module 205 correspond one by one to the steps (steps S101 to S105) in the above adversarial image steganography detection method. The specific working principle can also refer to the introduction of the adversarial image steganography detection method in the foregoing embodiments, so it will not be elaborated here.

[0088] In several embodiments provided by the present invention, it should be understood that the disclosed system, device, or method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules / units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or modules or units can be in an electrical, mechanical, or other form.

[0089] The modules / units described as separate components may or may not be physically separated, and the components shown as modules / units may or may not be physical modules, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules / units can be selected according to actual needs to achieve the objectives of the embodiments of the present invention. For example, in various embodiments of the present invention, the functional modules / units can be integrated in one processing module, or each module / unit can exist physically alone, or two or more modules / units can be integrated in one module / unit.

[0090] Those of ordinary skill in the art should further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0091] The descriptions of the processes or structures corresponding to the above respective drawings each have their own focuses. For parts not detailed in a certain process or structure, reference can be made to the relevant descriptions of other processes or structures.

[0092] The above embodiments merely illustrate the principles and effects of the present invention and are not intended to limit the present invention. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or changes completed by those with ordinary knowledge in the technical field without departing from the spirit and technical ideas disclosed by the present invention should still be covered by the claims of the present invention.

Claims

1. A method for detecting adversarial image steganography, characterized in that: The method comprises: Input a carrier image and calculate the gradient value of each pixel in the carrier image; Sampling the carrier image using a sampling window to obtain a plurality of sub-images corresponding to the carrier image; Calculating an average gradient value of each of the sub-images according to the gradient values, sorting the sub-images according to the average gradient values, dividing the sorted sub-images into a plurality of sub-image sets according to a preset number, and selecting at least one sub-image from the sub-images included in each of the sub-image sets as a representative image corresponding to the sub-image set; Extracting the feature vector of the carrier image and the feature vector of the representative image through a step analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image; The classifier is trained according to the target feature matrix to obtain a target classifier, and the steganography detection is performed on the image to be tested by the target classifier.

2. The adversarial image steganography detection method according to claim 1, characterized in that: When the number of the sub-images obtained by sampling is less than a preset threshold, a sampling starting point is randomly selected for sampling.

3. The adversarial image steganography detection method according to claim 1, characterized in that: The step of dividing the sorted sub-images into a plurality of sub-image sets in sequence according to a preset number includes: selecting a preset number of sub-images in order from the sorted sub-images as a sub-image set until each sub-image is grouped; wherein the number of sub-images contained in the last sub-image set is less than or equal to the preset number.

4. The adversarial image steganography detection method according to claim 1, characterized in that: The preset number is greater than or equal to three; three sub-images are selected from the sub-images included in each of the sub-image sets as representative images corresponding to the sub-image set; The representative images include: a first representative image, a second representative image and a third representative image; The selecting at least one sub-image from each of the sub-images included in the sub-image set as a representative image corresponding to the sub-image set comprises: Selecting a sub-image with the largest average gradient value in each of the sub-image sets as the first representative image; Selecting a sub-image with the smallest average gradient value in each of the sub-image sets as the second representative image; A sub-image is randomly selected from each of the sub-image sets as the third representative image.

5. The adversarial image steganography detection method according to claim 4, characterized in that: The step of extracting the feature vector of the carrier image and the feature vector of the representative image through a step analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image comprises: Extracting a feature vector of the carrier image by using the step analysis residual network; Calculating the steganographic probability of the representative image according to the average gradient value; According to the steganalysis probability, extracting the feature vector of the representative image through the step analysis residual network, and calculating the statistics of the feature vector of the representative image; The statistics are concatenated together to form a statistical matrix, and the statistical matrix is ​​concatenated with the feature vector of the carrier image to form the target feature matrix.

6. The adversarial image steganography detection method according to claim 5, characterized in that: The statistics include at least the maximum value, the minimum value, the average value and the variance of the feature vector representing the image.

7. The adversarial image steganography detection method according to claim 5 or 6, characterized in that: The feature vector of the carrier image and the feature vector of the representative image are both N-dimensional; the number of the carrier images is K; the number of rows of the target feature matrix is ​​K, and the number of columns of the target feature matrix is ​​N×(m+γ); wherein m represents the number of the statistics; and γ represents the number of the sub-image sets.

8. An adversarial image steganography detection system, characterized in that: The system comprises: A calculation module, used for inputting a carrier image and calculating a gradient value of each pixel in the carrier image; A sampling module, used for sampling the carrier image using a sampling window to obtain a plurality of sub-images corresponding to the carrier image; a sorting module, configured to calculate an average gradient value of each of the sub-images according to the gradient values, sort the sub-images according to the average gradient values, divide the sorted sub-images into a plurality of sub-image sets in sequence according to a preset number, and select at least one sub-image from the sub-images included in each of the sub-image sets as a representative image corresponding to the sub-image set; A splicing module, used for extracting the feature vector of the carrier image and the feature vector of the representative image through a step analysis residual network, and forming a target feature matrix based on the feature vector of the carrier image and the feature vector of the representative image; The detection module is used to train a classifier according to the target feature matrix to obtain a target classifier, and perform steganalysis detection on the image to be detected through the target classifier.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed, the adversarial image steganography detection method described in any one of claims 1 to 7 is implemented.