A reversible neural network-based multi-adversarial steganographic embedding method and related device

By using a multi-adversarial training method based on reversible neural networks, multi-adversarial steganography signals are directly generated and then embedded, weighted, and quantized. This solves the problem of adversarial perturbation-damaged steganography signals in existing technologies, and achieves adversarial steganography image generation with high concealment and strong anti-detection capabilities.

CN122496591APending Publication Date: 2026-07-31FOSHAN VIRTUAL REALITY BIG DATA IND RES INST CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FOSHAN VIRTUAL REALITY BIG DATA IND RES INST CO LTD
Filing Date
2026-04-24
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing end-to-end adversarial steganography methods can damage the integrity of the original stegographic signal when generating adversarial perturbations, reduce extraction accuracy, and potentially affect the visual quality of the carrier.

Method used

A multi-adversarial training method based on reversible neural networks is adopted. The multi-adversarial steganalysis signal is directly generated through the reversible neural network model that converges through multi-adversarial training. The signal is then subjected to embedding weighting and adversarial quantization processing to form an adversarial steganalysis image with high concealment, high extraction rate and strong anti-detection capability.

Benefits of technology

It effectively avoids secondary damage caused by post-perturbation, significantly improves the security of the algorithm, and generates images with high concealment and strong anti-detection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122496591A_ABST
    Figure CN122496591A_ABST
Patent Text Reader

Abstract

This invention discloses a multi-adversarial steganography embedding method and related apparatus based on a reversible neural network. The method includes: obtaining secret information and a carrier image; encoding the secret information using an encoder and inputting it along with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain an output multi-adversarial steganography signal; the reversible neural network model is composed of several cascaded reversible modules based on DenseNet, with the first and last sections being reversible modules based on VIT; embedding and weighting the multi-adversarial steganography signal and the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image; and performing adversarial quantization and post-processing on the multi-adversarial embedded steganography image to form an adversarial steganography image. In this embodiment of the invention, an adversarial steganography image with high concealment, high extraction rate, and strong anti-detection capability is directly generated through network iterative optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a multi-adversarial steganography embedding method and related apparatus based on reversible neural networks. Background Technology

[0002] Adversarial attacks, as an emerging attack paradigm in deep learning, disrupt the normal decision-making of a target model by constructing deceptive adversarial examples. In the field of steganalysis, this idea has been introduced to improve the security of steganalysis algorithms. Early traditional methods based on "distortion cost function + STCs" introduced the concept of adversarial embedding by transforming the symmetric embedding cost into an asymmetric cost and utilizing the gradient information of the target steganalyst to guide cost adjustment (i.e., determining the modification region).

[0003] However, end-to-end adversarial steganography is more direct: it uses a jointly trained network to simultaneously embed secret information and generate adversarial perturbations. The specific process is usually as follows: the stegenist generates a stegated image, and then adversarial perturbations are superimposed to deceive the steganalyzer. Although this "steganography first, adversarial" strategy enhances the ability to resist detection, its core drawback is the additional distortion introduced by the perturbation superposition operation itself. This inevitably damages the integrity of the original steganalyte signal, reduces the extraction accuracy, and may affect the visual quality of the carrier. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art. This invention provides a multi-adversarial steganalysis embedding method and related apparatus based on a reversible neural network. The method directly generates multi-adversarial steganalysis signals based on a reversible neural network model that has converged through multi-adversarial training. These signals are then embedded and weighted into a carrier image to form a multi-adversarial steganalysis image. Finally, adversarial quantization is performed, and the method achieves the direct generation of adversarial steganalysis images with high concealment, high extraction rate, and strong anti-detection capability through network iterative optimization. This fundamentally avoids the secondary damage problem caused by post-perturbation and significantly improves the security of the algorithm.

[0005] To address at least one of the aforementioned technical problems, embodiments of the present invention provide a multi-adversarial steganalysis embedding method based on a reversible neural network, the method comprising: The secret information and carrier image are obtained. The secret information is encoded by an encoder and then input together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial steganography signal. The reversible neural network model consists of reversible modules based on VIT at the front and back, and several reversible modules based on DenseNet cascaded in the middle. The multi-adversarial steganography signal is embedded and weighted with the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image. Adversarial quantization post-processing is performed on multi-adversarial embedded stegana images to form adversarial stegana images.

[0006] Optionally, the training process of the reversible neural network model based on multi-adversarial training convergence includes: The training secret information is encoded using an encoder and then input into a reversible neural network model along with the training carrier image to generate a training steganalysis signal. The training steganography signal is embedded and weighted with the training carrier image to form a training steganography image; The training steganalysis image is input into multiple steganalysis networks, and the gradient image of the training steganalysis image is calculated using the backpropagation algorithm to obtain the gradient image corresponding to the training steganalysis image. The embedding mask is generated based on the training steganalysis signal and the gradient image, and the mask loss function is obtained using the generated embedding mask. The reversible neural network model is subjected to carrier feedback processing using the mask loss function until the resulting training steganographic image is recognized as the training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

[0007] Optionally, the calculation formula for calculating the gradient image of the training stegana using the backpropagation algorithm is as follows: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

[0008] Optionally, the step of performing embedding mask generation processing based on the training stegographic signal and the gradient image, and obtaining the mask loss function using the generated embedding mask, includes: The formula for generating an embedding mask based on the trained stegographic signal and the gradient image is as follows: ; The formula for obtaining the mask loss function using the generated embedded mask is as follows: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

[0009] Optionally, the adversarial quantization post-processing of the multi-adversarial embedded stegana image to form an adversarial stegana image includes: Extract the quantized DCT coefficients from the multi-adversarial embedding steganography image, and use the quantized DCT coefficients to calculate the gradient map to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image. The adversarial embedding steganography image is rounded down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image to form an adversarial steganography image.

[0010] Optionally, the step of calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image includes: The quantized DCT coefficients are dequantized and subjected to inverse discrete cosine transform processing using the cross-entropy loss function in multiple steganalysis networks to form a gradient map corresponding to each quantized DCT coefficient in the adversarial embedded steganalysis image. The formula for dequantizing and performing inverse discrete cosine transformation on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks is as follows: ; in, Gradient plot; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

[0011] Optionally, the step of rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image includes: The adversarial embedding steganography image is rounded up or down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image to form an adversarial steganography image. The formulas for rounding up or rounding down are as follows: ; in, For adversarial steganography; To quantify the DCT coefficients; Gradient plot; It is a rounding function; This is the floor function.

[0012] In addition, embodiments of the present invention also provide a multi-adversarial steganography embedding device based on a reversible neural network, the device comprising: Stegation signal acquisition module: used to obtain secret information and carrier image, encode the secret information using an encoder and input it together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial stegation signal. The reversible neural network model consists of reversible modules based on VIT improvement at the front and back, and several reversible modules based on DenseNet cascaded in the middle. Embedding weighting module: used to embed and weight the multi-adversarial steganography signal and the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image; Post-quantization processing module: Used to perform adversarial quantization post-processing on multi-adversarial embedded stegana images to form adversarial stegana images.

[0013] In addition, embodiments of the present invention also provide an electronic device, including a processor and a memory, wherein the processor runs a computer program or code stored in the memory to implement the multi-adversarial steganography embedding method as described in any of the above.

[0014] In addition, embodiments of the present invention also provide a computer-readable storage medium for storing a computer program or code, which, when executed by a processor, implements the multi-adversarial steganography embedding method as described above.

[0015] In this embodiment of the invention, a multi-adversarial steganalytic signal is directly generated by a reversible neural network model that has converged through multi-adversarial training. This signal is then embedded and weighted into the carrier image to form a multi-adversarial steganalytic image. Finally, adversarial quantization post-processing is performed. This achieves the direct generation of an adversarial steganalytic image with high concealment, high extraction rate, and strong anti-detection capability through network iterative optimization. This fundamentally avoids the secondary damage problem caused by post-perturbation and significantly improves the security of the algorithm. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the multi-adversarial steganography embedding method based on a reversible neural network in an embodiment of the present invention. Figure 2 This is a framework diagram of reversible neural network multi-adversarial training in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structural composition of the reversible module based on VIT improvement in the reversible neural network in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structural composition of the multi-adversarial steganography embedding device based on a reversible neural network in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structural composition of the electronic device in an embodiment of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example 1, please refer to Figure 1 , Figure 1 This is a flowchart illustrating the multi-adversarial steganography embedding method based on a reversible neural network in an embodiment of the present invention.

[0020] like Figure 1 As shown, a multi-adversarial steganalysis embedding method based on a reversible neural network is described, the method comprising: S101: Obtain secret information and carrier image, encode the secret information using an encoder, and input it together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial steganography signal. The reversible neural network model consists of reversible modules based on VIT (Transformer) at the front and back, and several reversible modules based on DenseNet (Densely Connected Convolutional Networks) cascaded in the middle. In a specific implementation of this invention, the training process of the reversible neural network model based on multi-adversarial training convergence includes: encoding training secret information using an encoder and inputting it along with a training carrier image into the reversible neural network model to generate a training steganalytic signal; performing embedding weighting processing on the training steganalytic signal and the training carrier image to form a training steganalytic image; inputting the training steganalytic image into multiple steganalysis networks, and using a backpropagation algorithm to calculate the gradient image of the training steganalytic image to obtain the gradient image corresponding to the training steganalytic image; performing embedding mask generation processing based on the training steganalytic signal and the gradient image, and obtaining a mask loss function using the generated embedding mask; and using the mask loss function to perform carrier feedback processing on the reversible neural network model until the formed training steganalytic image is recognized as a training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

[0021] Furthermore, the calculation formula for calculating the gradient image of the training stegana using the backpropagation algorithm is as follows: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

[0022] Furthermore, the step of generating an embedding mask based on the trained steganalytic signal and the gradient image, and obtaining a mask loss function using the generated embedding mask, includes: The formula for generating an embedding mask based on the trained stegographic signal and the gradient image is as follows: ; The formula for obtaining the mask loss function using the generated embedded mask is as follows: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

[0023] Specifically, the reversible neural network consists of reversible modules at the beginning and end, improved from VIT, and several cascaded reversible modules based on DenseNet (Densely Connected Convolutional Networks) in the middle; for example... Figure 2As shown, a training dataset is first obtained, containing a number of training cryptographic information entries and a number of training carrier images. Then, the training cryptographic information is encoded using an encoder and input into a reversible neural network model along with the training carrier images to generate a training steganalytic signal. The training steganalytic signal and the training carrier images are then weighted and embedded to form a training steganalytic image. This training steganalytic image is then input into multiple steganalysis networks, and the gradient image is calculated using the backpropagation algorithm to obtain the corresponding gradient image. An embedding mask is generated based on the training steganalytic signal and the gradient image, and a mask loss function is obtained using the generated embedding mask. Finally, the mask loss function is used to perform carrier feedback processing on the reversible neural network model. The process then repeats, with the training cryptographic information encoded using the encoder and the training carrier images input into the reversible neural network model repeatedly until the resulting training steganalytic image is recognized as a training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

[0024] Multiple steganalysis networks are also networks that have converged during training, and can be networks formed by several mainstream network architectures such as XuNet, SRNet, YeNet, and DengNet. Then, a training dataset for the steganalysis network is constructed, that is, a carrier image set is constructed based on the classic BOSSBasever.1.01 and BOWS2 datasets. Subsequently, the S-UNIWARD adaptive steganography algorithm is used to calculate the embedding cost, and the corresponding steganography image set is generated by combining it with STC encoding at a set embedding rate. ; Utilizing pairing Supervised learning is performed on the dataset to pre-train a steganalysis network with discriminative capabilities. .

[0025] Steganalysis networks only update parameters during the pre-training phase. During subsequent training of the invertible neural network (INN) model, its parameters are frozen and do not participate in subsequent gradient updates. During the adversarial training phase... Its main function is to provide gradient information through the backpropagation mechanism to guide INN in generating steganographic images with anti-detection capabilities. In addition, two attack scenarios are defined: white-box attack refers to directly attacking the target model (XuNet or SRNet) used to generate gradients; black-box attack refers to using the above model as a proxy model to generate adversarial examples, and then attacking other targets with unknown parameters or structures.

[0026] The reversible neural network model consists of reversible modules based on VIT (see reference). Figure 3The middle section consists of several cascaded reversible modules based on DenseNet; during the forward process, the reversible modules in the reversible neural network model receive the carrier image. and secret information As input, the aim is to generate a encrypted image. Assume the first indivual( The input features of the reversible block are: The output features are The forward transformation process based on the affine coupling layer can be formally defined as: ; ; in, This is the Hadamard product of the matrix (i.e., element-wise multiplication). , and It represents any nonlinear transformation function.

[0027] It is worth noting that, thanks to the design characteristics of the affine coupling structure, these functions themselves do not require reversibility, which provides space for using complex deep networks to enhance feature extraction capabilities. In order to obtain excellent feature representation and reconstruction performance in image processing tasks, in the basic configuration of this embodiment, the classic 5-layer dense connection block is used to instantiate these three functions.

[0028] The reverse process of a reversible neural network model aims to extract hidden secret information from a coded image and reconstruct the original image. It's worth noting that the reverse process is completely identical to the forward process in terms of network topology, only the information flow is reversed; that is, information flows from the first image to the second. Block flow to the first Block. For the first block in the reverse process. There are reversible blocks, and the input is... The output is The inverse transform formula is derived as follows: ; ; in, This represents matrix division, specifically element-wise division of a matrix. Clearly, the above operations only involve basic algebraic operations such as addition, subtraction, multiplication, and division, which are mathematically rigorous and provably invertible, thus ensuring lossless information recovery.

[0029] While the basic reversible block based on DenseBlock performs excellently in local feature extraction, it still has limitations in capturing long-range dependencies and global semantic information due to the receptive field of convolution operations. To overcome this bottleneck, inspired by the Visual Transformer (ViT) and its self-attention mechanism, this embodiment designs an enhanced reversible module based on ViT, named Invertible Block-ViT (as shown in Figure 3). This module aims to leverage the global modeling capabilities of the Transformer to deeply capture the internal spatial correlations of the input data. Specifically, the transformation function in the original reversible block is specifically improved: the original DenseNet is replaced with the improved ViT reversible module, especially... μ ( The ViT function is introduced to enhance the expressive power of nonlinear mapping. In the feature extraction process of the ViT-based improved reversible module, the data processing flow is as follows: First, the feature map is divided into blocks and linearly mapped to sequence embeddings; second, it is input into the Transformer encoder for global feature interaction; third, at the output, the [CLS] token, typically used for classification tasks, is removed; finally, convolutional layers are used to reorganize and reduce the dimensionality of the remaining feature sequences, aligning their dimensions with the output dimensions required by the reversible block, thus completing the feature mapping. Considering the high computational complexity of ViT, a hybrid deployment strategy is adopted in the overall network architecture to improve model performance while maintaining computational efficiency: the first and twelfth (i.e., the beginning and end) reversible blocks of the network are replaced with the improved ViT-based reversible block (Invertible Block-ViT), while the remaining 10 modules retain the DenseNet-based basic structure. This design strengthens the network's capture of global features while maintaining the training stability of deep networks.

[0030] Multi-adversarial embedding (MAE) involves generating a steganalysis image during training using the forward pass of an invertible neural network (INN). This steganalysis image is then fed into the steganalysis network, and its gradient map is calculated using the backpropagation algorithm. The specific calculation process is shown in the following formula: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

[0031] The purpose of training adversarial image steganography is to improve the target steganalysis. Confidential image Mistakenly identified as target label ( According to the properties of the Fast Gradient Sign Method (FGSM), it is necessary to follow the gradient graph. Modify the input of the symbol in the opposite direction to train the stegana This reduces losses. To introduce the concept of adversarial examples into image steganography, existing adversarial image steganography methods utilize the gradient signs of the carrier image and the embedded image to update the original symmetric embedding cost to an asymmetric embedding cost; the regions that need to be modified are determined based on the gradients generated by multiple target steganalysis networks, as shown in the following formula: ; in, Represents a carrier or encrypted image. The target label is represented; once the asymmetric embedding cost is established, current adversarial image steganography techniques typically employ the adjoint lattice code (STC) method to embed the specified secret information into the carrier image, thereby obtaining the final steganographic image; this process shows that existing adversarial image steganography methods mainly achieve adversarial embedding by modifying the embedding cost, rather than integrating the concept of adversarial embedding into the training of the network itself; unlike these methods, the method proposed in this embodiment achieves adversarial embedding in an automated manner by combining the loss function with the gradient derived from the pre-trained steganalysis network; the process is summarized as follows: first, the output of the INN forward process (ranging from [0, 255]) is mapped to a steganalytic signal ranging from [-1, 1]. Carrier image With steganalysis signals The training steganalysis image is obtained by adding them together. Then, the training stegimages will be used. Input multiple steganalysis networks The gradient plot is derived according to formula (4). Next, using coordinates Steganographic signals Symbols and dense image gradients Generate an embedding mask: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

[0032] Finally, the following mask loss was designed based on the embedded mask. : ; This mask loss can guide secret information to be embedded into specific security enhancement regions; for example, when the sign of the steganalysis signal matches the sign of the gradient of the trained steganalysis, the adversarial strength is enhanced. Increase mask loss At this point, the steg signal generated during the forward process of INN... The amount of modification at this pixel location should be reduced because the same amount of change will increase the loss function value at that location; ultimately, the goal of this embodiment is to minimize the discriminative loss of the target model, thereby deceiving multiple steganalysis networks into classifying the training steganagraph as a clean training vector image; in other words, satisfying Location This reduces the embedding probability; the secret information is iteratively embedded into the training vector image along the opposite direction of the gradient map symbol, minimizing the impact of multiple pre-trained steganalysis networks as much as possible. The cross-entropy loss is used; therefore, the training steganalysis image will be judged as the training carrier image by the pre-trained steganalysis network as much as possible.

[0033] Therefore, by obtaining the secret information and the carrier image, encoding the secret information using an encoder, and then inputting it along with the carrier image into a reversible neural network model based on multi-adversarial training convergence, the output multi-adversarial steganography signal can be obtained.

[0034] S102: The multi-adversarial steganography signal is embedded and weighted with the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image. In the specific implementation of this invention, after obtaining the multi-adversarial steganography signal, it is necessary to embed and weight the adversarial steganography signal with the carrier image to finally form a multi-adversarial steganography image. The multi-adversarial steganography image is a floating-point data image, so it needs to be subjected to adversarial quantization operations afterward.

[0035] S103: Perform adversarial quantization post-processing on the multi-adversarial embedded stegana image to form an adversarial stegana image.

[0036] In a specific implementation of this invention, the adversarial quantization post-processing of the multi-adversarial embedding steganographic image to form an adversarial steganographic image includes: extracting the quantized DCT coefficients from the multi-adversarial embedding steganographic image; calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image; and rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image.

[0037] Furthermore, the step of calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image includes: dequantizing and performing inverse discrete cosine transform processing on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks to form the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image; the formula for dequantizing and performing inverse discrete cosine transform on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks is as follows: ; in, Gradient plot; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

[0038] Furthermore, the step of rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image includes: rounding the adversarial embedding steganographic image up or down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image; the formula for rounding up or down is as follows: ; in, For adversarial steganography; To quantify the DCT coefficients; Gradient plot; It is a rounding function; This is the floor function.

[0039] Specifically, after the forward pass of the invertible neural network (INN), the secret information is embedded into the carrier image, thereby generating a multi-adversarial steganalysis image; in fact, this output is represented as floating-point data. For the spatial domain case, the unrounded multi-adversarial steganalysis image is first obtained. The pixels of the rounded multi-adversarial steganography image are then obtained through adversarial quantization post-processing. Quantization DCT coefficients for multi-adversarial steganography in the JPEG domain It needs to undergo a decompression process to convert it into pixels of the rounded multi-adversarial steganography image. The post-processing operation proposed in this embodiment mainly operates on this rounding step. The aforementioned adversarial quantization post-processing operation can significantly improve the security of steganography. Next, taking the JPEG domain as an example, this post-processing operation will be described in detail. Given the DCT coefficients of the coded image to be rounded... Calculate its gradient using the following formula: ; in, Gradient plot; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

[0040] After the above calculations, the multi-adversarial steganography image was obtained. The gradient corresponding to each quantized DCT coefficient Subsequently, Round to the nearest integer. This operation produces the smallest rounding error; if the rounding direction is opposite to the gradient sign, then it satisfies... and (or and If this indicates that rounding helps reduce loss, then the rounding value of the image should be set to [value to be filled in]. Otherwise, follow these settings: ; in, For adversarial steganography; To quantify the DCT coefficients; Gradient plot; It is a rounding function; This is the floor function.

[0041] By using gradient maps to limit the rounding direction of quantized DCT coefficients (i.e., rounding up or rounding down), the goal is to ensure that reversible neural networks can accurately recover secret information and carrier images when performing inverse operations. In other words, by inputting adversarial steganography images into the reversible neural network and passing them through the inverse operation, the corresponding secret information and carrier images can be accurately recovered.

[0042] The adversarial quantization process described above will be illustrated with a specific example: Suppose a certain quantization DCT coefficient of a multi-adversarial stegana image... It can calculate its nearest integer. If gradient Then the rounding value of the multi-adversarial steganography image is set to ;otherwise, .

[0043] In this embodiment of the invention, a multi-adversarial steganalytic signal is directly generated by a reversible neural network model that has converged through multi-adversarial training. This signal is then embedded and weighted into the carrier image to form a multi-adversarial steganalytic image. Finally, adversarial quantization post-processing is performed. This achieves the direct generation of an adversarial steganalytic image with high concealment, high extraction rate, and strong anti-detection capability through network iterative optimization. This fundamentally avoids the secondary damage problem caused by post-perturbation and significantly improves the security of the algorithm.

[0044] Example 2, please refer to Figure 4 , Figure 4This is a schematic diagram of the structural composition of the multi-adversarial steganography embedding device based on a reversible neural network in an embodiment of the present invention.

[0045] like Figure 4 As shown, a multi-adversarial steganalysis embedding device based on a reversible neural network includes: Steganographic signal acquisition module 401: used to obtain secret information and carrier image, encode the secret information using an encoder and input it together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial steganographic signal. The reversible neural network model is composed of reversible modules based on VIT improvement at the front and back, and several reversible modules based on DenseNet cascaded in the middle. In a specific implementation of this invention, the training process of the reversible neural network model based on multi-adversarial training convergence includes: encoding training secret information using an encoder and inputting it along with a training carrier image into the reversible neural network model to generate a training steganalytic signal; performing embedding weighting processing on the training steganalytic signal and the training carrier image to form a training steganalytic image; inputting the training steganalytic image into multiple steganalysis networks, and using a backpropagation algorithm to calculate the gradient image of the training steganalytic image to obtain the gradient image corresponding to the training steganalytic image; performing embedding mask generation processing based on the training steganalytic signal and the gradient image, and obtaining a mask loss function using the generated embedding mask; and using the mask loss function to perform carrier feedback processing on the reversible neural network model until the formed training steganalytic image is recognized as a training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

[0046] Furthermore, the calculation formula for calculating the gradient image of the training stegana using the backpropagation algorithm is as follows: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

[0047] Furthermore, the step of generating an embedding mask based on the trained steganalytic signal and the gradient image, and obtaining a mask loss function using the generated embedding mask, includes: The formula for generating an embedding mask based on the trained stegographic signal and the gradient image is as follows: ; The formula for obtaining the mask loss function using the generated embedded mask is as follows: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

[0048] Specifically, the reversible neural network consists of reversible modules at the beginning and end, improved from VIT, with several cascaded reversible modules based on DenseNet in the middle; for example... Figure 2As shown, a training dataset is first obtained, containing a number of training cryptographic information entries and a number of training carrier images. Then, the training cryptographic information is encoded using an encoder and input into a reversible neural network model along with the training carrier images to generate a training steganalytic signal. The training steganalytic signal and the training carrier images are then weighted and embedded to form a training steganalytic image. This training steganalytic image is then input into multiple steganalysis networks, and the gradient image is calculated using the backpropagation algorithm to obtain the corresponding gradient image. An embedding mask is generated based on the training steganalytic signal and the gradient image, and a mask loss function is obtained using the generated embedding mask. Finally, the mask loss function is used to perform carrier feedback processing on the reversible neural network model. The process then repeats, with the training cryptographic information encoded using the encoder and the training carrier images input into the reversible neural network model repeatedly until the resulting training steganalytic image is recognized as a training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

[0049] Multiple steganalysis networks are also networks that have converged during training, and can be networks formed by several mainstream network architectures such as XuNet, SRNet, YeNet, and DengNet. Then, a training dataset for the steganalysis network is constructed, that is, a carrier image set is constructed based on the classic BOSSBasever.1.01 and BOWS2 datasets. Subsequently, the S-UNIWARD adaptive steganography algorithm is used to calculate the embedding cost, and the corresponding steganography image set is generated by combining it with STC encoding at a set embedding rate. ; Utilizing pairing Supervised learning is performed on the dataset to pre-train a steganalysis network with discriminative capabilities. .

[0050] Steganalysis networks only update parameters during the pre-training phase. During subsequent training of the invertible neural network (INN) model, its parameters are frozen and do not participate in subsequent gradient updates. During the adversarial training phase... Its main function is to provide gradient information through the backpropagation mechanism to guide INN in generating steganographic images with anti-detection capabilities. In addition, two attack scenarios are defined: white-box attack refers to directly attacking the target model (XuNet or SRNet) used to generate gradients; black-box attack refers to using the above model as a proxy model to generate adversarial examples, and then attacking other targets with unknown parameters or structures.

[0051] The reversible neural network model consists of reversible modules based on VIT (see reference). Figure 3The middle section consists of several cascaded reversible modules based on DenseNet; during the forward process, the reversible modules in the reversible neural network model receive the carrier image. and secret information As input, the aim is to generate a encrypted image. Assume the first indivual( The input features of the reversible block are: The output features are The forward transformation process based on the affine coupling layer can be formally defined as: ; ; in, This is the Hadamard product of the matrix (i.e., element-wise multiplication). , and It represents any nonlinear transformation function.

[0052] It is worth noting that, thanks to the design characteristics of the affine coupling structure, these functions themselves do not require reversibility, which provides space for using complex deep networks to enhance feature extraction capabilities. In order to obtain excellent feature representation and reconstruction performance in image processing tasks, in the basic configuration of this embodiment, the classic 5-layer dense connection block is used to instantiate these three functions.

[0053] The reverse process of a reversible neural network model aims to extract hidden secret information from a coded image and reconstruct the original image. It's worth noting that the reverse process is completely identical to the forward process in terms of network topology, only the information flow is reversed; that is, information flows from the first image to the second. Block flow to the first Block. For the first block in the reverse process. There are reversible blocks, and the input is... The output is The inverse transform formula is derived as follows: ; ; in, This represents matrix division, specifically element-wise division of a matrix. Clearly, the above operations only involve basic algebraic operations such as addition, subtraction, multiplication, and division, which are mathematically rigorous and provably invertible, thus ensuring lossless information recovery.

[0054] While the basic reversible block based on DenseBlock performs excellently in local feature extraction, it still has limitations in capturing long-range dependencies and global semantic information due to the receptive field of convolution operations. To overcome this bottleneck, inspired by the Visual Transformer (ViT) and its self-attention mechanism, this embodiment designs an enhanced reversible module based on ViT, named Invertible Block-ViT (as shown in Figure 3). This module aims to leverage the global modeling capabilities of the Transformer to deeply capture the internal spatial correlations of the input data. Specifically, the transformation function in the original reversible block is specifically improved: the original DenseNet is replaced with the improved ViT reversible module, especially... μ ( The ViT function is introduced to enhance the expressive power of nonlinear mapping. In the feature extraction process of the ViT-based improved reversible module, the data processing flow is as follows: First, the feature map is divided into blocks and linearly mapped to sequence embeddings; second, it is input into the Transformer encoder for global feature interaction; third, at the output, the [CLS] token, typically used for classification tasks, is removed; finally, convolutional layers are used to reorganize and reduce the dimensionality of the remaining feature sequences, aligning their dimensions with the output dimensions required by the reversible block, thus completing the feature mapping. Considering the high computational complexity of ViT, a hybrid deployment strategy is adopted in the overall network architecture to improve model performance while maintaining computational efficiency: the first and twelfth (i.e., the beginning and end) reversible blocks of the network are replaced with the improved ViT-based reversible block (Invertible Block-ViT), while the remaining 10 modules retain the DenseNet-based basic structure. This design strengthens the network's capture of global features while maintaining the training stability of deep networks.

[0055] Multi-adversarial embedding (MAE) involves generating a steganalysis image during training using the forward pass of an invertible neural network (INN). This steganalysis image is then fed into the steganalysis network, and its gradient map is calculated using the backpropagation algorithm. The specific calculation process is shown in the following formula: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

[0056] The purpose of training adversarial image steganography is to improve the target steganalysis. Confidential image Mistakenly identified as target label ( According to the properties of the Fast Gradient Sign Method (FGSM), it is necessary to follow the gradient graph. Modify the input of the symbol in the opposite direction to train the stegana This reduces losses. To introduce the concept of adversarial examples into image steganography, existing adversarial image steganography methods utilize the gradient signs of the carrier image and the embedded image to update the original symmetric embedding cost to an asymmetric embedding cost; the regions that need to be modified are determined based on the gradients generated by multiple target steganalysis networks, as shown in the following formula: ; in, Represents a carrier or encrypted image. The target label is represented; once the asymmetric embedding cost is established, current adversarial image steganography techniques typically employ the adjoint lattice code (STC) method to embed the specified secret information into the carrier image, thereby obtaining the final steganographic image; this process shows that existing adversarial image steganography methods mainly achieve adversarial embedding by modifying the embedding cost, rather than integrating the concept of adversarial embedding into the training of the network itself; unlike these methods, the method proposed in this embodiment achieves adversarial embedding in an automated manner by combining the loss function with the gradient derived from the pre-trained steganalysis network; the process is summarized as follows: first, the output of the INN forward process (ranging from [0, 255]) is mapped to a steganalytic signal ranging from [-1, 1]. Carrier image With steganalysis signals The training steganalysis image is obtained by adding them together. Then, the training stegimages will be used. Input multiple steganalysis networks The gradient plot is derived according to formula (4). Next, using coordinates Steganographic signals Symbols and dense image gradients Generate an embedding mask: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

[0057] Finally, the following mask loss was designed based on the embedded mask. : ; This mask loss can guide secret information to be embedded into specific security enhancement regions; for example, when the sign of the steganalysis signal matches the sign of the gradient of the trained steganalysis, the adversarial strength is enhanced. Increase mask loss At this point, the steg signal generated during the forward process of INN... The amount of modification at this pixel location should be reduced because the same amount of change will increase the loss function value at that location; ultimately, the goal of this embodiment is to minimize the discriminative loss of the target model, thereby deceiving multiple steganalysis networks into classifying the training steganagraph as a clean training vector image; in other words, satisfying Location This reduces the embedding probability; the secret information is iteratively embedded into the training vector image along the opposite direction of the gradient map symbol, minimizing the impact of multiple pre-trained steganalysis networks as much as possible. The cross-entropy loss is used; therefore, the training steganalysis image will be judged as the training carrier image by the pre-trained steganalysis network as much as possible.

[0058] Therefore, by obtaining the secret information and the carrier image, encoding the secret information using an encoder, and then inputting it along with the carrier image into a reversible neural network model based on multi-adversarial training convergence, the output multi-adversarial steganography signal can be obtained.

[0059] Embedding weighting module 402: used to embed and weight the multi-adversarial steganography signal and the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image; In the specific implementation of this invention, after obtaining the multi-adversarial steganography signal, it is necessary to embed and weight the adversarial steganography signal with the carrier image to finally form a multi-adversarial steganography image. The multi-adversarial steganography image is a floating-point data image, so it needs to be subjected to adversarial quantization operations afterward.

[0060] Quantization post-processing module 403: used to perform adversarial quantization post-processing on multi-adversarial embedded stegana images to form adversarial stegana images.

[0061] In a specific implementation of this invention, the adversarial quantization post-processing of the multi-adversarial embedding steganographic image to form an adversarial steganographic image includes: extracting the quantized DCT coefficients from the multi-adversarial embedding steganographic image; calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image; and rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image.

[0062] Furthermore, the step of calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image includes: dequantizing and performing inverse discrete cosine transform processing on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks to form the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image; the formula for dequantizing and performing inverse discrete cosine transform on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks is as follows: ; in, Gradient plot; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

[0063] Furthermore, the step of rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image includes: rounding the adversarial embedding steganographic image up or down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image; the formula for rounding up or down is as follows: ; in, For adversarial steganography; To quantify the DCT coefficients; Gradient plot; It is a rounding function; This is the floor function.

[0064] Specifically, after the forward pass of the invertible neural network (INN), the secret information is embedded into the carrier image, thereby generating a multi-adversarial steganalysis image; in fact, this output is represented as floating-point data. For the spatial domain case, the unrounded multi-adversarial steganalysis image is first obtained. The pixels of the rounded multi-adversarial steganography image are then obtained through adversarial quantization post-processing. Quantization DCT coefficients for multi-adversarial steganography in the JPEG domain It needs to undergo a decompression process to convert it into pixels of the rounded multi-adversarial steganography image. The post-processing operation proposed in this embodiment mainly operates on this rounding step. The aforementioned adversarial quantization post-processing operation can significantly improve the security of steganography. Next, taking the JPEG domain as an example, this post-processing operation will be described in detail. Given the DCT coefficients of the coded image to be rounded... Calculate its gradient using the following formula: ; in, Gradient plot; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

[0065] After the above calculations, the multi-adversarial steganography image was obtained. The gradient corresponding to each quantized DCT coefficient Subsequently, Round to the nearest integer. This operation produces the smallest rounding error; if the rounding direction is opposite to the gradient sign, then it satisfies... and (or and If this indicates that rounding helps reduce loss, then the rounding value of the image should be set to [value to be filled in]. Otherwise, follow these settings: ; in, For adversarial steganography; To quantify the DCT coefficients; Gradient plot; It is a rounding function; This is the floor function.

[0066] By using gradient maps to limit the rounding direction of quantized DCT coefficients (i.e., rounding up or rounding down), the goal is to ensure that reversible neural networks can accurately recover secret information and carrier images when performing inverse operations. In other words, by inputting adversarial steganography images into the reversible neural network and passing them through the inverse operation, the corresponding secret information and carrier images can be accurately recovered.

[0067] The adversarial quantization process described above will be illustrated with a specific example: Suppose a certain quantization DCT coefficient of a multi-adversarial stegana image... It can calculate its nearest integer. If gradient Then the rounding value of the multi-adversarial steganography image is set to ;otherwise, .

[0068] In this embodiment of the invention, a multi-adversarial steganalytic signal is directly generated by a reversible neural network model that has converged through multi-adversarial training. This signal is then embedded and weighted into the carrier image to form a multi-adversarial steganalytic image. Finally, adversarial quantization post-processing is performed. This achieves the direct generation of an adversarial steganalytic image with high concealment, high extraction rate, and strong anti-detection capability through network iterative optimization. This fundamentally avoids the secondary damage problem caused by post-perturbation and significantly improves the security of the algorithm.

[0069] This invention provides a computer-readable storage medium storing a computer program. When executed by a processor, this program implements the multi-adversarial steganography embedding method of any of the above embodiments. The computer-readable storage medium includes, but is not limited to, any type of disk (including floppy disks, hard disks, optical disks, CD-ROMs, and magneto-optical disks), ROM (Read-Only Memory), RAM (Random Access Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory, magnetic cards, or optical cards. In other words, the storage device includes any medium that stores or transmits information in a readable form by a device (e.g., a computer, a mobile phone), and can be a read-only memory, a disk, or an optical disk, etc.

[0070] This invention also provides a computer application running on a computer, which is used to execute the multi-adversarial steganography embedding method of any of the above embodiments.

[0071] also, Figure 5 This is a schematic diagram of the structural composition of the electronic device in an embodiment of the present invention.

[0072] This invention also provides an electronic device, such as... Figure 5 As shown. The electronic device includes a processor 502, a memory 503, an input unit 504, and a display unit 505, among other devices. Those skilled in the art will understand that... Figure 5 The structural components of the illustrated electronic device do not constitute a limitation on all devices and may include more or fewer components than illustrated, or combine certain components. Memory 503 can be used to store application program 501 and various functional modules. Processor 502 runs application program 501 stored in memory 503, thereby performing various functional applications and data processing of the device. Memory can be internal memory or external memory, or both. Internal memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, or random access memory. External memory may include hard disks, floppy disks, ZIP disks, USB flash drives, magnetic tapes, etc. The memory disclosed in this invention includes, but is not limited to, these types of memory. The memory disclosed in this invention is only an example and not a limitation.

[0073] Input unit 504 is used to receive signal input and user-input keywords. Input unit 504 may include a touch panel and other input devices. The touch panel can collect user touch operations on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel) and drive the corresponding connection device according to a pre-set program; other input devices may include, but are not limited to, one or more of physical keyboards, function keys (such as play control buttons, power buttons, etc.), trackballs, mice, joysticks, etc. Display unit 505 can be used to display user-input information or information provided to the user, as well as various menus of the terminal device. Display unit 505 may be in the form of a liquid crystal display, organic light-emitting diode, etc. Processor 502 is the control center of the terminal device, connecting various parts of the entire device through various interfaces and lines, performing various functions and processing data by running or executing software programs and / or modules stored in memory 503, and calling data stored in memory.

[0074] As one embodiment, the electronic device includes: one or more processors 502, a memory 503, and one or more application programs 501, wherein the one or more application programs 501 are stored in the memory 503 and configured to be executed by the one or more processors 502, and the one or more application programs 501 are configured to execute the multi-adversarial steganography embedding method corresponding to any of the embodiments described above.

[0075] In this embodiment of the invention, a multi-adversarial steganalytic signal is directly generated by a reversible neural network model that has converged through multi-adversarial training. This signal is then embedded and weighted into the carrier image to form a multi-adversarial steganalytic image. Finally, adversarial quantization post-processing is performed. This achieves the direct generation of an adversarial steganalytic image with high concealment, high extraction rate, and strong anti-detection capability through network iterative optimization. This fundamentally avoids the secondary damage problem caused by post-perturbation and significantly improves the security of the algorithm.

[0076] Furthermore, the above provides a detailed description of a multi-adversarial steganography embedding method and related apparatus based on a reversible neural network provided by the embodiments of the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A multi-adversarial steganalysis embedding method based on a reversible neural network, characterized in that, The method includes: The secret information and carrier image are obtained. The secret information is encoded by an encoder and then input together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial steganography signal. The reversible neural network model consists of reversible modules based on VIT at the front and back, and several reversible modules based on DenseNet cascaded in the middle. The multi-adversarial steganography signal is embedded and weighted with the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image. Adversarial quantization post-processing is performed on multi-adversarial embedded stegana images to form adversarial stegana images.

2. The multi-adversarial steganography embedding method according to claim 1, characterized in that, The training process of the reversible neural network model based on multi-adversarial training convergence includes: The training secret information is encoded using an encoder and then input into a reversible neural network model along with the training carrier image to generate a training steganalysis signal. The training steganography signal is embedded and weighted with the training carrier image to form a training steganography image; The training steganalysis image is input into multiple steganalysis networks, and the gradient image of the training steganalysis image is calculated using the backpropagation algorithm to obtain the gradient image corresponding to the training steganalysis image. The embedding mask is generated based on the training steganalysis signal and the gradient image, and the mask loss function is obtained using the generated embedding mask. The reversible neural network model is subjected to carrier feedback processing using the mask loss function until the resulting training steganographic image is recognized as the training carrier image in multiple steganalysis networks, thus forming a reversible neural network model based on multi-adversarial training convergence.

3. The multi-adversarial steganography embedding method according to claim 2, characterized in that, The calculation formula for calculating the gradient image of the training stegana using the backpropagation algorithm is as follows: ; in, It is a gradient image; To train steganographic images; Define the target tag To train carrier images, To train steganographic images; For multiple steganalysis networks, when there are When performing steganography analysis on a network, ; For the first The output of a steganalysis network , With target label Binary cross-entropy loss between them; This is the total loss function; To train the gradient of the stegana; For the first The proportion of each steganography analysis network.

4. The multi-adversarial steganography embedding method according to claim 2, characterized in that, The step of generating an embedding mask based on the trained steganalytic signal and the gradient image, and obtaining a mask loss function using the generated embedding mask, includes: The formula for generating an embedding mask based on the trained stegographic signal and the gradient image is as follows: ; The formula for obtaining the mask loss function using the generated embedded mask is as follows: ; ; in, coordinates The gradient image below; coordinates The training steganographic signal below; coordinates Embedded mask below; For training carrier images; To train steganographic images; Masking factor; It is a constant, and ; Let the mask loss function be used. Let the mean square error function be used. for The normalized form.

5. The multi-adversarial steganography embedding method according to claim 1, characterized in that, The adversarial quantization post-processing of the multi-adversarial embedded stegana image to form an adversarial stegana image includes: Extract the quantized DCT coefficients from the multi-adversarial embedding steganography image, and use the quantized DCT coefficients to calculate the gradient map to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image. The adversarial embedding steganography image is rounded down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image to form an adversarial steganography image.

6. The multi-adversarial steganography embedding method according to claim 5, characterized in that, The step of calculating the gradient map using the quantized DCT coefficients to obtain the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image includes: The quantized DCT coefficients are dequantized and subjected to inverse discrete cosine transform processing using the cross-entropy loss function in multiple steganalysis networks to form a gradient map corresponding to each quantized DCT coefficient in the adversarial embedded steganalysis image. The formula for dequantizing and performing inverse discrete cosine transformation on the quantized DCT coefficients using the cross-entropy loss function in multiple steganalysis networks is as follows: ; in, For gradient plots; To quantify the DCT coefficients; The correct category label; This process includes dequantization and inverse discrete cosine transform. For the first The cross-entropy loss function of steganalysis networks; for The gradient; For quality factor; For the first The proportion of each steganography analysis network.

7. The multi-adversarial steganography embedding method according to claim 5, characterized in that, The step of rounding the adversarial embedding steganographic image based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganographic image to form an adversarial steganographic image includes: The adversarial embedding steganography image is rounded up or down based on the gradient map corresponding to each quantized DCT coefficient in the adversarial embedding steganography image to form an adversarial steganography image. The formulas for rounding up or rounding down are as follows: ; in, For adversarial steganography; To quantify the DCT coefficients; For gradient plots; It is a rounding function; This is the floor function.

8. A multi-adversarial steganography embedding device based on a reversible neural network, characterized in that, The device includes: Stegation signal acquisition module: used to obtain secret information and carrier image, encode the secret information using an encoder and input it together with the carrier image into a reversible neural network model based on multi-adversarial training convergence to obtain the output multi-adversarial stegation signal. The reversible neural network model consists of reversible modules based on VIT improvement at the front and back, and several reversible modules based on DenseNet cascaded in the middle. Embedding weighting module: used to embed and weight the multi-adversarial steganography signal and the carrier image to form a multi-adversarial steganography image, wherein the multi-adversarial steganography image is a floating-point data image; Post-quantization processing module: Used to perform adversarial quantization post-processing on multi-adversarial embedded stegana images to form adversarial stegana images.

9. An electronic device comprising a processor and a memory, characterized in that, The processor runs a computer program or code stored in the memory to implement the multi-adversarial steganography embedding method as described in any one of claims 1 to 7.

10. A computer-readable storage medium for storing computer programs or code, characterized in that, When the computer program or code is executed by a processor, the multi-adversarial steganography embedding method as described in any one of claims 1 to 7 is implemented.