Image confrontation steganography method based on latent layer feature domain self-adaption

By using a self-adaptive normalization layer and gradient-based perturbation updates, the method improves the migration security of adversarial steganography, reducing detection accuracy in non-targeted steganalysis and enhancing security in unknown scenarios.

CN120318056APending Publication Date: 2025-07-15CHENGDU UNIV OF INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510489694.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The existing deep learning-based image steganography method has insufficient migration security when fighting steganography analysis, making it difficult to achieve high steganography security in unknown steganography analysis scenarios.

Method used

By inserting an example normalization layer of latent layer feature domain adaptation into the steganography analysis network, adaptive scaling and interpolation are used to utilize the latent layer feature mean and variance of the carrier image for adaptive scaling and interpolation, combining gradient maps and distortion cost adjustments, adaptive adversarial perturbations are generated, and the carrier image is enhanced to improve migration security.

Benefits of technology

It significantly improves the migration security of the anti-steganography method, reduces the detection accuracy of the unknown steganography analyzer, and improves the steganography security in unknown scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120318056A_ABST
    Figure CN120318056A_ABST
Patent Text Reader

Abstract

The invention discloses an adaptive image confrontation steganography method based on a latent layer feature domain. The method comprises the following steps: dividing a steganography analysis network into a front part and a rear part; calculating a mean value and a variance of characteristic values obtained from the front parts of the carrier image and the other carrier image; according to the mean value and the variance, using a scaling and interpolation method to obtain a plurality of latent layer features; taking the latent layer features as learnable parameters of a normalization layer to obtain an adaptive normalization layer; self-adaptive normalization is inserted between the front portion and the rear portion of the steganalysis network, and a new steganalysis network is obtained; calculating a gradient map by using a new steganalysis network; and executing an image steganography method based on carrier enhancement or distortion cost adjustment by using the gradient map. According to the image steganography method, the IN layer is inserted into the steganography analysis network, the latent layer features of the image are used as parameters of the IN layer, and disturbance noise is adaptively added to an overlapped feature region concerned by each steganography analysis network through the latent layer feature domain, so that the migration safety of the image steganography method is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multimedia security, and in particular to an image adversarial steganography method based on latent feature domain adaptation. Background Technique

[0002] With the rapid development of information technology, data security has become a key issue, and information hiding technology is an important protection means. Information hiding technology is a kind of covert communication technology, aiming to hide secret information in a carrier and transmit it through a public channel, so that the secret information is not detected during the transmission process. Image steganography is an important branch of information hiding technology, mainly by embedding secret information into common digital images (referred to as: carrier images), and transmitting the image after embedding the secret information (referred to as: stego image) in a public channel without arousing the suspicion of third-party supervisors (such as: steganalysis personnel). Steganalysis technology, as the opposite of image steganography, aims to detect whether there is a secret message in an image. With the application of deep learning in computer vision, deep learning-based steganalysis technology has also developed rapidly, which has brought great challenges to image steganography technology. At present, in order to further resist deep learning-based steganalysis methods, steganographers have proposed an image steganography method based on adversarial samples.

[0003] The following documents can partially solve the above problems:

[0004] A patent application with publication number CN114820380A and invention name "Spatial Domain Steganography Carrier Image Enhancement Method Based on Content Adaptive Adversarial Perturbation". This method first designs a multi-granularity image texture description method, combining per-pixel fine-grained and statistical image feature coarse-grained methods to describe image texture features; then segments the image according to the image semantic features, selects the blocks with rich image texture information as candidate perturbation positions, and constructs a perturbation mask; finally, determines the optimal position of the adversarial perturbation according to the mask.

[0005] A patent application with publication number CN118869889A and invention name "A Transferable Image Adversarial Steganography Method Based on Neuron Attribution". The steps of this method are: 1. Determine key features based on neuron attribution; 2. Destroy the key features; 3. Perform adversarial embedding using the gradient map obtained by destroying the key features.

[0006] Reference [1] (Yiwei Zhang, Weiming Zhang, Kejiang Chen, Jiayang Liu, Yujia Liu, and Nenghai Yu. 2018. Adversarial examples against deep neural network-based steganalysis [C] / / Proceedings of the 6th ACM Workshop on Information Hiding and Multimedia Security. 2018: 67-72.) discloses a method for adding adversarial perturbation noise to a carrier image. This method uses a steganalysis network to generate adversarial perturbation noise based on the gradient information of the input image and iteratively adds it to the carrier image to generate an adversarial carrier image. Then, secret information is added to generate a stego image and input it into the steganalysis network until the target steganalysis network cannot make a judgment.

[0007] Although the above method effectively improves the steganographic security performance and has a high steganographic efficiency. However, it can only achieve a high attack success rate against the target steganalyzer, and the attack success rate against non-target steganalyzers is relatively low, that is, the adversarial steganography transfer security is insufficient. In practical applications, adversarial steganography methods with insufficient transfer security often cannot achieve high steganographic security in unknown steganalysis scenarios, and there are security risks of being discovered. Summary of the Invention

[0008] The object of the present invention is to provide an image adversarial steganography method based on latent feature domain adaptation to improve the adversarial steganography transfer security.

[0009] The technical solution for achieving the object of the present invention is as follows:

[0010] An image adversarial steganography method based on latent feature domain adaptation includes:

[0011] Step 1, divide the steganalysis network into a front part and a rear part, where the front part is the rear part is Initialize the adversarial perturbation δ adv ;

[0012] Step 2, calculate the mean value μ and variance σ of the eigenvalues c obtained by the carrier image c passing through c ;

[0013] Step 3, randomly select a carrier image c′ and calculate the eigenvalues obtained by it passing through the mean μ c′ and the variance σ c′ ;

[0014] Step 4, obtaining multiple latent features using the scaling and interpolation method:

[0015] μ′ = α·(λμ c +(1 - λμ c′ ))

[0016] σ′ = β·(λσ c +(1 - λσ c′ ));

[0017] where α and β are scaling amplitude parameters, and λ is a mixing ratio parameter;

[0018] Step 5, taking the latent features as the learnable parameters of the IN layer to obtain the adaptive normalization layer L IN i.e.,

[0019] L IN = IN(c)| μ=μ′,σ=σ′ ;

[0020] where μ and σ are the learnable parameters of the IN layer;

[0021] Step 6, inserting L IN between the front and the back of the steganalysis network to obtain the steganalysis network

[0022] Step 7, obtaining t steganalysis networks according to the method of Step 3 - Step 6

[0023] Step 8, embedding secret information into the cover image c to obtain the stego image s';

[0024] Step 9, calculating the gradient maps G1, G2,..., G of the stego image s' in t , and then averaging all the gradient maps to obtain the gradient map G;

[0025] Step 10, updating the adversarial perturbation δ adv i.e.,

[0026] δ adv = ‖δ adv ‖2 + k·sign(G);

[0027] where ‖δ adv ‖2 is the 2 - norm of the current adversarial perturbation, k is the weighting coefficient, and sign(·) is the sign function;

[0028] Step 11, add the updated adversarial perturbation δ to the carrier image c adv to obtain the enhanced carrier image c adv , and then perform secret information embedding on c adv to obtain the enhanced stego-image s adv ;

[0029] Step 12, use the enhanced stego-image s adv as the stego-image s for adversarial steganalysis

[0030] A further technical solution further includes: Step 11', if the steganalysis network determines the enhanced stego-image s adv as the carrier image c, then continue; otherwise, use the enhanced stego-image s adv as the stego-image s', and return to Step 9

[0031] The present invention also provides another image adversarial steganography method based on latent feature domain adaptation, that is, replacing Steps 10, 11, and 12 of the aforementioned image adversarial steganography method with:

[0032] Step 10, calculate the initial distortion of the carrier image c using the basic distortion function

[0033]

[0034] wherein, represents the distortion after the i-th pixel of the carrier image c is ±1;

[0035] Step 11, update the distortion cost ρ of the i-th pixel of the carrier image c after being ±1 using the gradient map G i ,

[0036]

[0037] wherein, g i represents the i-th element of the gradient map G, and α is the distortion adjustment factor;

[0038] Step 12, embed the secret information into the carrier image c according to the distortion cost ρ i to obtain the stego-image s adv ;

[0039] It further includes Step 13, using the stego-image s adv as the stego-image s for adversarial steganalysis

[0040] A further technical solution further includes: Step 12', if the steganalysis network determines the stego-image s adv as the carrier image c, then continue; otherwise, use the stego-image sadv Use it as the stego-image s', let α = α + Δ, and return to step 9; where Δ represents the step size.

[0041] Preferably, the steganalysis network is SRNet, whose last layer is the Type 1s layer. Alternatively, the steganalysis network is LWENet, whose last layer is the layer5 layer. Alternatively, the steganalysis network is CovNet, whose last layer is the group2 layer.

[0042] In the present invention, an IN layer (Instance Normalization layer) is inserted into the steganalysis network, and the latent feature of the image is used as the parameter of the IN layer, which can better retain the image edge information and local texture features; the perturbation noise is adaptively added to the overlapping feature regions concerned by each steganalysis network through the latent feature domain, so as to improve the transfer security of the image steganography method. The present invention is more suitable for the application scenarios of real image steganography. Brief Description of the Drawings

[0043] Figure 1 It is a flowchart of an embodiment of the present invention. Detailed Embodiments

[0044] The present invention will be further described below in conjunction with specific embodiments.

[0045] As Figure 1 shown, the image adversarial steganography method based on the latent feature domain adaptation includes

[0046] Step 1: Calculate the latent feature of the carrier image c in the steganalysis network;

[0047] Step 1.1 For a given steganalysis network where represents the front and back parts of the steganalysis network. Calculate the mean and variance μ of the latent c , σ c feature values of the carrier image c in the steganalysis network;

[0048] Step 1.2 Randomly select a carrier image c' from the dataset and calculate the mean and variance μ of the latent c′ , σ c′ feature values of the feature in the steganalysis network;

[0049] Step 2: Adaptively instance normalize the layer according to the latent feature values

[0050] Step 2.1 Use the means and variances μ and σ calculated in Steps 1.2 and 1.3, and use scaling and interpolation methods to simulate multiple latent features:

[0051] μ′ = α·(λμ c +(1 - λμ c′ ))

[0052] σ′ = β·(λσ c +(1 - λσ c′ ))

[0053] where α and β control the scaling amplitude, and λ controls the mixing ratio.

[0054] Initialize the network parameters of the adaptive instance normalization layer L IN with μ′ and σ′:

[0055] L IN = IN(c)| μ=μ′,σ=σ′ .

[0056] where μ and σ are the learnable parameters of the IN layer;

[0057] Step 2.2 Insert the L IN layer into the steganalysis network and define it as:

[0058]

[0059] Step 2.3 Repeat Steps 1.2 to 2.3 to obtain t steganalysis networks

[0060] Step 3: Embed secret information into the cover image c to obtain the stego image s';

[0061] Step 4: Use the backpropagation mechanism of the steganalysis network to calculate the gradient maps G1, G2, …, G in the t steganalysis networks for the stego image s', and average these gradient maps G1, G2, …, G t to obtain the final gradient map G; Step 5: If the carrier-enhanced image steganography method is selected, execute Step 5.1; if the distortion-cost-adjusted image steganography method is selected, execute Step 5.2; t Step 5.1 Use the gradient map G to enhance the cover image c;

[0062] Step 5.1.1 Update the adversarial perturbation δ

[0063] using the gradient map G adv (the adversarial perturbation δ adv(Initialized before, that is:

[0064] δ adv =‖δ adv ‖2 + k·sign(G)

[0065] where ‖δ adv ‖2 is the 2-norm of the current adversarial perturbation, k is the weighting coefficient, and sign(·) is the sign function;

[0066] Step 5.1.2 Add the updated adversarial perturbation δ to the cover image c adv to obtain the enhanced cover image c adv , and then perform secret information embedding on c adv to obtain the enhanced stego-image s adv ; The enhanced stego-image s obtained at this time adv can be used as the stego-image against steganalysis.

[0067] To further improve the security of the stego-image, the following processing can be continued:

[0068] Step 5.1.3 Use the steganalysis network to determine the enhanced stego-image s adv : If the steganalysis network determines the enhanced stego-image s adv as the cover image c, then take s adv as the final stego-image s; otherwise, take the enhanced stego-image s adv as the stego-image s', and return to Step 4 for execution.

[0069] Step 5.2 Adjust the distortion cost of the cover image c using the gradient map G;

[0070] Step 5.2.1 Calculate the initial distortion of the cover image c using the basic distortion function

[0071]

[0072] where represents the distortion after the i-th pixel of the cover image c is ±1;

[0073] Step 5.2.2 Update the distortion cost ρ after the i-th pixel of the cover image c is ±1 using the gradient map G i :

[0074]

[0075] where g i represents the i-th element of the gradient map G, and α is the distortion adjustment factor;

[0076] Step 5.2.3 Embed the secret information into the cover image c according to the distortion cost ρ i to obtain the stego-image s adv ; At this time, the obtained stego-image s adv can be used as the stego-image against steganalysis.

[0077] To further improve the security of the stego-image, the following processing can be continued:

[0078] Step 5.2.4 Input the stego-image s adv into the steganalysis network for discrimination. If the stego-image s adv is discriminated as a cover image, then s adv is used as the final stego-image s; otherwise, the stego-image s adv is used as the stego-image s', and let α = α + Δ, and return to step 4 for execution. In this embodiment, Δ = 0.1.

[0079] In this embodiment, the steganalysis network can be SRNet, CovNet, SiaStegNet or LWENet; the steganography can adopt algorithms such as HUGO, WOW, UNIWARD or HILL.

[0080] The comparison of the security performance between the present invention and the existing technical methods is as follows in the table:

[0081] Table 1. Detection accuracy p of non-target steganalysis detectors under the target attack of the deep learning-based steganalysis detector SRNet combined with the ADS method acc (%).

[0082]

[0083] The literatures shown in the table are as follows:

[0084] [2] Boroumand M, Chen M, Fridrich J. Deep Residual Network for Steganalysis of Digital Images[J]. IEEE Transactions on Information Forensics and Security, 2019, 14(5): 1181 - 1193. doi: 10.1109 / TIFS.2018.2871749.

[0085] [3]Deng X,Chen B,Luo W,et al.Fast and Effective Global CovariancePooling Network for Image Steganalysis[J].ACM,2019.DOI:10.1145 / 3335203.3335739.

[0086] [4]Sharp T.An implementation of key-based digital signalsteganography[C] / / International workshop on information hiding.Berlin,Heidelberg:Springer Berlin Heidelberg,2001:13-26.

[0087] [5]Weng S,Chen M,Yu L,et al.Lightweight and effective deep imagesteganalysis network[J].IEEE Signal Processing Letters,2022,29:1888-1892.

[0088] Among them: the payload (bpp, bit per pixel) refers to the secret information carrying capacity of the original steganography method, that is, the number of bits of secret information embedded in each pixel on average in the cover image; the bold numbers indicate the lowest accuracy rate, that is, the best anti-attack effect.

[0089] As shown in Table 1, the method of the present invention can enhance the transfer security of the anti-steganography method. For example, when the payload is 0.2 bpp, the detection accuracy p of the method proposed by the present invention compared with the ADS method acc decreases by 27.50%, 27.39%, and 36.11% respectively. It shows that the present invention can improve the transfer security of the anti-steganography method, and thus can achieve higher steganography security in unknown steganalysis scenarios. Among them, the detection accuracy p acc is defined as follows:

[0090]

[0091] Among them, TN represents the number of correctly identified cover images, and TP represents the number of correctly classified stego images.

[0092] Table 2. Detection accuracy p of the non-target steganalyzer under the attack of the ADS method, respectively selecting the Type 1s layer, Type 2s layer, and Type 3s of the steganalyzer SRNet as the insertion layer acc (%).

[0093]

[0094] According to the experimental results of SRNet, it can be seen that selecting the first few layers of the steganalyzer as the insertion position has a better effect, because the shallow layers of the steganalyzer retain more image texture features.

Claims

1. An image adversarial steganography method based on latent feature domain adaptation, characterized in that Including: Step 1, divide the steganalysis network into two parts: the front part and the back part, where the front part is and the back part is Initialize the adversarial perturbation δ adv ; Step 2, calculate the mean value μ of the eigenvalues obtained by the carrier image c and the variance σ c ; c ; Step 3, randomly select a carrier image c′, and calculate the mean value μ of the eigenvalues obtained and the variance σ c′ ′; c ′ Step 4: Obtain multiple latent features using scaling and interpolation methods: μ′ = α·(λσ c +(1 - λμ c′ )), σ′ = β·(λσ c +(1 - λσ c′ )); where α and β are scaling amplitude parameters, and λ is a mixing ratio parameter; Step 5: Use the latent feature as the learnable parameter of the IN layer to obtain the adaptive normalization layer L IN , that is L IN = IN(c)| μ=μ′,σ=σ′ ; where μ and σ are learnable parameters of the IN layer; Step 6, insert L IN between the front and the back of the steganalysis network to obtain the steganalysis network Step 7, according to the method of Steps 3 - 6, obtain t steganalysis networks Step 8: Embed secret information into the carrier image c to obtain the stego-image s'; Step 9, calculate the gradient maps G1, G2, …, G of the encrypted image s’, and then average all the gradient maps to obtain the gradient map G; t ​ Step 10, update the adversarial perturbation δ using the gradient map G adv , that is δ adv = ‖δ adv ‖² + k·sign(G); where, ‖δ adv ‖2 is the 2-norm of the current adversarial perturbation, k is the weighting coefficient, and sign(·) is the sign function; Step 11, add the updated adversarial perturbation δ to the carrier image c adv to obtain the enhanced carrier image c adv , and then perform secret information embedding on c adv to obtain the enhanced stego-image s adv ; Step 12, using the enhanced stego-image s adv as the stego-image s against steganalysis.

2. The image adversarial steganography method according to claim 1, characterized in that Also included: Step 11’, if the steganalysis network determines the enhanced stego-image s adv as the cover image c, then continue; otherwise, use the enhanced stego-image s adv as the stego-image s’, and return to Step 9.

3. The image adversarial steganography method according to claim 1, wherein The said Step 10, Step 11, and Step 12 are respectively replaced with: Step 10: Calculate the initial distortion of the carrier image c using the basic distortion function Among them, represents the distortion after adding or subtracting 1 to the i-th pixel of the carrier image c; Step 11, update the distortion cost ρ after adding or subtracting 1 to the i-th pixel of the carrier image c using the gradient map G i , where g i represents the i-th element of the gradient map G, and α is the distortion adjustment factor; Step 12, according to the distortion cost ρ i Embed the secret information into the carrier image c to obtain the stego-image s adv ; It also includes step 13, using the stego-image s adv as the stego-image s against steganalysis.

4. The image adversarial steganography method according to claim 3, wherein, Also included: Step 12', if the steganalysis network determines the stego-image s adv as the cover image c, then continue; otherwise, take the stego-image s adv as the stego-image s', and let α = α + Δ, return to Step 9; where Δ represents the step size.

5. The image adversarial steganography method according to any one of claims 1-4, characterized in that The steganalysis network is SRNet, whose last layer is the Type 1s layer.

6. The image adversarial steganography method according to any one of claims 1-4, characterized in that The steganalysis network F is LWENet, and its last layer is layer 5.

7. The image adversarial steganography method according to any one of claims 1-4, characterized in that, The steganalysis network F is CovNet, and its last layer is the group2 layer.

Citation Information

Patent Citations

  • Spatial-domain steganography carrier image enhancement method based on content self-adaption adversarial disturbance

    CN114820380A

  • Migratable image confrontation steganography method based on neuron attribution

    CN118869889A