A low-distortion image steganography method, device and medium based on deep learning
Patent Information
- Application Number
- CN202610997988.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-06
- Publication Date
- 2026-09-22
AI Technical Summary
一方面,对抗扰动可能被分配到平滑区域等不适宜修改的位置,导致图像视觉质量下降,且容易破坏图像统计特性;另一方面,对抗扰动与隐写嵌入过程相互独立,隐写修改方向可能与对抗扰动方向不一致,甚至相互抵消,造成额外嵌入成本增加;
本发明提供了一种低失真图像隐写方法,通过成本掩模对对抗扰动进行定向分配,并进一步根据扰动方向调整隐写修改概率,使对抗扰动与隐写嵌入协同,从而在提高抗隐写分析能力的同时降低图像失真。
Smart Images

Figure CN122802635A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of information hiding and image processing technology, and in particular to a low-distortion image steganography method, device, and medium based on deep learning. Background Technology
[0002] Image steganography is a technique that embeds secret information into a carrier image while minimizing its perceptibility or detection. Traditional image steganography methods typically analyze image content features and select regions with complex textures and high statistical redundancy for information embedding to reduce the impact of embedding modifications on the image's visual quality and statistical properties. For example, adaptive steganography algorithms such as WOW, S-UNIWARD, and HILL can calculate the embedding cost based on the local texture complexity of the image and prioritize embedding secret information into regions with lower modification costs.
[0003] With the development of deep learning technology, steganalysis models based on convolutional neural networks have demonstrated strong capabilities in detecting dense images. Deep learning steganalyzers such as YeNet, SRNet, and CovNet can automatically learn subtle statistical differences between the carrier image and the dense image, significantly challenging the security of traditional adaptive steganography algorithms. Even if traditional steganography algorithms can reduce visual distortion to some extent, the dense images they generate can still be accurately identified by deep learning steganalyzers.
[0004] To improve the ability of dense images to evade steganalysis, related technologies have attempted to introduce adversarial example techniques into the field of image steganography. These methods typically add perturbations to the image using adversarial attacks such as FGSM and PGD, causing the target steganalysis to misidentify the dense image as the carrier image. However, existing adversarial steganography methods often directly generate or superimpose adversarial perturbations across the entire image, and the perturbation distribution lacks an effective correlation with the image's own texture characteristics and the cost of steganographic embedding.
[0005] The above method has at least the following problems: On the one hand, adversarial perturbations may be assigned to unsuitable locations such as smooth regions, leading to a decrease in image visual quality and easily damaging image statistical properties; on the other hand, adversarial perturbations and steganography embedding processes are independent of each other, and the direction of steganography modification may be inconsistent with the direction of adversarial perturbations, or even cancel each other out, resulting in an increase in additional embedding costs. On the other hand, in order to achieve sufficient adversarial effect, existing methods usually need to introduce a large amount of perturbation, thereby increasing the overall embedding distortion and reducing the imperceptibility and practicality of dense images.
[0006] Therefore, how to ensure the reliable embedding of secret information and improve the anti-steganography capabilities of encrypted images while reducing the overall distortion introduced by adversarial perturbations and steganography embedding has become an urgent technical problem to be solved. Summary of the Invention
[0007] To address the shortcomings of existing technologies, embodiments of the present invention provide a low-distortion image steganography method, device, and medium based on deep learning.
[0008] In a first aspect, embodiments of the present invention provide a low-distortion image steganography method based on deep learning, the method comprising: Calculate the embedding cost map of the carrier image, perform a nonlinear transformation on the embedding cost map, and generate a cost mask; An optimization objective is constructed and solved to obtain the original adversarial perturbation; wherein, the optimization objective is to find an adversarial perturbation that makes the target steganalysis unable to recognize the carrier image after the adversarial perturbation has been added. The original adversarial perturbation is multiplied by the cost mask to obtain the optimized adversarial perturbation. The optimized adversarial perturbation is superimposed on the carrier image to obtain an adversarial carrier image; the embedding cost is recalculated based on the adversarial carrier image; the modification probability of each pixel in the adversarial carrier image is adaptively adjusted; based on the embedding cost and the adaptively adjusted modification probability, the secret information is embedded into the adversarial carrier image to generate a secret image; The dense image is input into the target steganalysis for detection; if the detection result is the carrier image, the dense image is output; otherwise, the adversarial perturbation is re-optimized until the detection result is the carrier image.
[0009] In a second aspect, embodiments of the present invention provide an electronic device, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to perform the above-described deep learning-based low-distortion image steganography method.
[0010] Thirdly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the aforementioned low-distortion image steganography method based on deep learning.
[0011] Fourthly, embodiments of the present invention provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the aforementioned deep learning-based low-distortion image steganography method.
[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention provides a low-distortion image steganography method that uses a cost mask to target adversarial perturbations and further adjusts the steganalysis probability according to the perturbation direction, so that adversarial perturbations and steganalysis embedding work together, thereby improving anti-steganography analysis capabilities while reducing image distortion. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 A flowchart illustrating a low-distortion image steganography method based on deep learning provided in an embodiment of the present invention; Figure 2 This is an architecture diagram of a low-distortion image steganography method based on deep learning provided in an embodiment of the present invention. Figure 3 This is a schematic diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0016] It should be noted that, unless otherwise specified, the features in the following embodiments and implementation methods can be combined with each other.
[0017] like Figure 1 and Figure 2 As shown, this embodiment of the invention provides a low-distortion image steganography method based on deep learning, the method comprising the following steps: Step S1, calculate the carrier image Embedded cost diagram For embedded cost graph Perform a nonlinear transformation to generate a cost mask.
[0018] Specifically, step S1 includes the following sub-steps: Step S101: Calculate the carrier image using the WOW algorithm. Embedded cost diagram The expression is as follows: In the formula, Represents pixels Embedding cost; It is a directional filter bank. In this example, it uses 30 high-pass filters from the Spatial Rich Model (SRM), including filters in the horizontal, vertical and diagonal directions. Represents filter Convolution operation with carrier image c; , It is a constant parameter to prevent division by zero.
[0019] Step S102, in order to map the cost value to the [0,1] interval, the embedded cost map is... Max-min normalization is performed, as shown in the following expression: In the formula, , .
[0020] Step S103: In order to enhance the contrast between textured and smooth regions, the normalized embedding cost map is... A nonlinear transformation is performed to generate a cost mask; the expression is as follows: In the formula, These are parameters that control the reinforcement strength; in this example, we take... This sigmoid transformation can effectively suppress the weights of smooth regions while enhancing the weights of textured regions.
[0021] Step S2: Construct and solve the optimization objective to obtain the original adversarial perturbation; wherein, the optimization objective is to find an adversarial perturbation that makes the target steganalysis unable to recognize the carrier image after the adversarial perturbation has been added.
[0022] Specifically, the expression for the optimization objective is as follows: In the formula, k is a hyperparameter that balances the magnitude of the perturbation and the classification loss. t is the classification loss function of the target steganalysis, and t is the target label (the target steganalysis aims to classify the dense image as the carrier image). It is the maximum permissible amplitude of the disturbance. The constraints ensure that the carrier image after adding the optimal adversarial perturbation is within the effective pixel value range.
[0023] Furthermore, this example employs an improved projective gradient descent (PGD) method to solve the optimization objective; the expression is as follows: In the formula, This indicates that the perturbation is projected onto the set of constraints. Projection operations within, It's the learning rate. t represents the target label and t represents the iteration round.
[0024] It should be noted that this example dynamically adjusts the learning rate for different regions based on the local texture characteristics of the image. A larger learning rate is used in regions with complex textures to accelerate convergence, while a smaller learning rate is used in smooth regions to avoid over-modification. A momentum term is also introduced to smooth the gradient update direction, accelerating the convergence process and improving the stability of the optimization. Furthermore, this example includes an early stopping mechanism, which terminates the optimization process prematurely when the perturbation reaches a sufficiently strong adversarial effect, avoiding unnecessary computational overhead.
[0025] Step S3: Multiply the original adversarial perturbation by the cost mask to obtain the optimized adversarial perturbation.
[0026] Furthermore, the expression is as follows: In the formula, This represents the optimized counter-perturbation. This represents the original adversarial perturbation. Indicates cost mask, This indicates a pixel-by-pixel multiplication operation.
[0027] To understand the mathematical meaning of the dot product operation, consider the perturbation. L2 norm: because The optimized perturbation norm must be less than or equal to the original perturbation norm. Specifically, in the smooth region ( The disturbance was significantly suppressed; in areas with complex textures ( The disturbances are largely preserved.
[0028] It's important to note that the theoretical basis for this allocation strategy can be explained using information theory. In image processing, regions with complex textures have higher information entropy, enabling them to hide more modifications without attracting attention. Conversely, smooth regions have lower information entropy, making even minor modifications easily noticeable. Therefore, concentrating perturbations in high-entropy regions is an optimization strategy consistent with information theory principles.
[0029] Step S4: The optimized adversarial perturbation is superimposed on the carrier image to obtain an adversarial carrier image; the embedding cost is recalculated based on the adversarial carrier image; the modification probability of each pixel in the adversarial carrier image is adaptively adjusted; based on the embedding cost and the adaptively adjusted modification probability, the secret information is embedded in the adversarial carrier image to generate a secret image.
[0030] Specifically, step S4 includes the following sub-steps: Step S401: The optimized adversarial perturbation is superimposed on the carrier image to obtain the adversarial carrier image; the expression is as follows: c adv = c + δ optimized In the formula, c adv This represents an adversarial carrier image.
[0031] Step S402, use the WOW algorithm to calculate the adversarial carrier image c adv Embedding cost p adv ... Step S403: Adaptively adjust the modification probability of each pixel in the adversarial carrier image.
[0032] Furthermore, in this example, based on adversarial noise The sign and size are dynamically adjusted to modify the probability; For each pixel Its adversarial noise is defined as Then, based on adversarial noise... Probability of sign adjustment modification: when When (prefers to increase pixel value): when When (preferring to reduce pixel values): In the formula, It is a hyperparameter for controlling the intensity of adjustment. and Represents the pixel conduct and The probability of modification. After adjustment, the probability needs to be renormalized to ensure... ,in This indicates the probability of not modifying the code.
[0033] Step S404, based on embedding cost p adv The adaptively adjusted modification probability embeds the secret information m into the adversarial carrier image c.adv Generate a dense image S.
[0034] Step S5: Input the cryptic image into the target steganalysis analyzer for detection; if the detection result is a carrier image, output the cryptic image; otherwise, re-optimize the adversarial perturbation until the detection result is a carrier image.
[0035] For example, the target steganalysis analyzer includes, but is not limited to, SRNet, Ye-Net, Xu-Net, Yedroudj-Net, and US-CovNet.
[0036] Furthermore, this example uses publicly available standard datasets: the BOSSbase dataset and the BOWS2 dataset. Both datasets contain 10,000 grayscale images of size 512×512. Following common practices in steganalysis research, this example resizes all images to 256×256 and uses bicubic interpolation to maintain image quality.
[0037] The dataset was split as follows: 8,000 images were randomly selected from BOSSbase as the training set, and 2,000 images were selected as the test set. The BOWS2 dataset was used for additional validation and robustness testing. All images were converted to grayscale during preprocessing and normalized to a floating-point range of [0, 1].
[0038] Table 1 shows the comparison of the average L2 norm introduced by different methods at an embedding rate of 0.4 bpp.
[0039] Table 1: Comparison of Cost Efficiency of Different Methods Table 1 shows the cost-efficiency comparison of the additional embedding introduced by each method compared to the WOW method. The average L2 norm represents the adversarial perturbation... The L2 norm, i.e. This is used to measure the magnitude of the disturbance; the relative cost is the proportion of each method to the L2 norm of FGSM+WOW, i.e. The cost reduction rate is the percentage decrease in the L2 norm relative to the FGSM+WOW benchmark, i.e. The cost-effectiveness ratio is defined as the missed detection rate achievable per unit L2 norm perturbation, i.e. ,in The missed detection rate is denoted by 0.4 bpp embedding rate against the YeNet steganalyst; a higher value indicates a greater security gain per unit cost. The efficiency rating is a comprehensive evaluation level based on cost-effectiveness. As shown in Table 1, this method reduces the L2 norm from 835.27 for the benchmark steganalysis method FGSM+WOW to 446.81, achieving a cost reduction rate of 46.5%. This means that while maintaining security, it significantly reduces additional embedding distortion. The cost-effectiveness ratio of this method is 0.00186, which is 2.35 times that of FGSM+WOW, indicating that this method achieves greater security improvement per unit cost.
[0040] Table 2 shows the missed detection rates of different methods when facing traditional steganalysis (SRM+EC) and deep learning steganalysis (YeNet).
[0041] Table 2: Comparison of security performance of different steganography methods As shown in Table 2 above, our proposed method achieved the highest missed detection rate across all embedding rates and different steganalysts, demonstrating comprehensive security advantages. At an embedding rate of 0.4 bpp, against the YeNet steganalyst, our method achieved a missed detection rate of 0.83, a 151% improvement compared to the traditional WOW method's 0.33, and a 10.7% improvement compared to Tang et al.'s 0.75. Furthermore, our method exhibited the smallest decrease in missed detection rate with increasing embedding rate, indicating that it maintains stable security performance under varying loads.
[0042] Table 3: Comparison of visual quality indicators for different methods The visual quality of steganalyte images directly affects their usability in practical applications. Table 3 shows the comparison results of visual quality indicators for steganalyte images generated by different methods. Among them, PSNR (Peak Signal-to-Noise Ratio) is used to measure the degree of image distortion, with the unit being dB. The higher the PSNR value, the less image distortion and the better the visual quality. SSIM (Structural Similarity Index) is used to measure the similarity of structural information between two images, with a value range of [0, 1]. The closer the SSIM value is to 1, the better the structure of the image is preserved. VIF (Visual Information Fidelity) evaluates the visual fidelity of an image based on a statistical model of natural scenes, with a value range of [0, 1]. The closer the VIF value is to 1, the more visually similar the steganalyte image is to the original image. The visual quality level is a comprehensive evaluation level based on the three indicators PSNR, SSIM, and VIF, and is divided into four levels: "Excellent", "Good", "Average", and "Poor". As shown in Table 3, the PSNR of this method reaches 42.18dB, which is 5.73dB higher than FGSM+WOW and 3.42dB higher than Tang and other methods; the SSIM index reaches 0.978, which is close to the traditional WOW index of 0.992, indicating that this method preserves the structural information of the image very well; the VIF index reaches 0.91, which is excellent, indicating that the dense image is visually highly similar to the original image.
[0043] To evaluate the robustness of this method to different steganalysis models, this example performs miss detection on a variety of advanced steganalysis models to determine whether the cryptic image is detected as the carrier image. The results are shown in Table 4.
[0044] Table 4: Missed detection rate of this method under different steganalysts As shown in Table 4, our proposed method maintained the highest missed detection rate across all steganalysts tested, demonstrating excellent cross-model generalization ability. Compared to methods such as Tang, our method consistently achieved performance improvements of 10.7%–12.2% across various steganalysts, indicating the general applicability of the improvement. Even against the CovNet model with the strongest detection capabilities, our method still achieved a missed detection rate of 0.78, representing a 169% improvement over traditional methods.
[0045] In summary, through the systematic experimental evaluation described above, the low-distortion image steganography method proposed in this example can reduce the total L2 norm perturbation by 44% while maintaining excellent security, thus solving the core problem of excessive cost in adversarial steganography. Furthermore, it outperforms existing methods in multiple dimensions, including missed detection rate, visual quality, and robustness, especially demonstrating outstanding performance against advanced deep learning steganalyzers. Finally, the intelligent perturbation selection mechanism provided in this example has clear physical meaning; the perturbation distribution is highly correlated with image texture characteristics, facilitating understanding and analysis.
[0046] Accordingly, this application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; and, when the one or more programs are executed by the one or more processors, causing the one or more processors to implement the deep learning-based low-distortion image steganography method described above. Figure 3 The diagram shown illustrates a hardware structure of any device with data processing capabilities for implementing the deep learning-based low-distortion image steganography method provided in this embodiment of the invention, except... Figure 3 In addition to the processor, memory, and network interface shown, any data processing device in the embodiment may also include other hardware depending on the actual function of the data processing device, which will not be described in detail here.
[0047] Accordingly, this application also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the deep learning-based low-distortion image steganography method described above. The computer-readable storage medium can be an internal storage unit of any data-processing device as described in any of the foregoing embodiments, such as a hard disk or memory. The computer-readable storage medium can also be an external storage device, such as a plug-in hard disk, smart media card (SMC), SD card, flash card, etc., equipped on the device. Furthermore, the computer-readable storage medium can include both internal storage units of any data-processing device and external storage devices. The computer-readable storage medium is used to store the computer program and other programs and data required by the data-processing device, and can also be used to temporarily store data that has been output or will be output.
[0048] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only.
[0049] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.
Claims
1. A low-distortion image steganography method based on deep learning, characterized in that, The method includes: Calculate the embedding cost map of the carrier image, perform a nonlinear transformation on the embedding cost map, and generate a cost mask; An optimization objective is constructed and solved to obtain the original adversarial perturbation; wherein, the optimization objective is to find an adversarial perturbation that makes the target steganalysis unable to recognize the carrier image after the adversarial perturbation has been added. The original adversarial perturbation is multiplied by the cost mask to obtain the optimized adversarial perturbation. The optimized adversarial perturbation is superimposed on the carrier image to obtain an adversarial carrier image; the embedding cost is recalculated based on the adversarial carrier image; the modification probability of each pixel in the adversarial carrier image is adaptively adjusted; based on the embedding cost and the adaptively adjusted modification probability, the secret information is embedded into the adversarial carrier image to generate a secret image; The dense image is input into the target steganalysis for detection; if the detection result is the carrier image, the dense image is output; otherwise, the adversarial perturbation is re-optimized until the detection result is the carrier image.
2. The low-distortion image steganography method based on deep learning according to claim 1, characterized in that, The process of calculating the embedding cost map of the carrier image, performing a nonlinear transformation on the embedding cost map, and generating a cost mask includes: The embedding cost map of the carrier image is calculated using an adaptive steganography algorithm; Max-min normalization is applied to the embedded cost graph; A nonlinear transformation is performed on the embedded cost map after max-min normalization to generate a cost mask.
3. The low-distortion image steganography method based on deep learning according to claim 1, characterized in that, The process of constructing and solving the optimization objective to obtain the original adversarial perturbation includes: The expression for the optimization objective is as follows: ; ; ; In the formula, k is a hyperparameter that balances the magnitude of the perturbation and the classification loss. Here, t is the classification loss function of the target steganalysis, and t is the target label. It is the maximum permissible amplitude of the disturbance. Constraints ensure the addition of resistance to disturbances Subsequent carrier image Within the effective pixel value range, H represents the image height, and W represents the image width.
4. The low-distortion image steganography method based on deep learning according to claim 3, characterized in that, The objective function is solved using the projected gradient descent method; the expression is as follows: ; In the formula, This indicates that the perturbation is projected onto the set of constraints. Projection operations within, It's the learning rate. t represents the target label and t represents the iteration round.
5. The low-distortion image steganography method based on deep learning according to claim 4, characterized in that, The learning rate is dynamically adjusted based on the local texture characteristics of the carrier image, wherein the learning rate for complex texture regions is greater than that for smooth texture regions.
6. The low-distortion image steganography method based on deep learning according to claim 1, characterized in that, The process of adaptively adjusting the modification probability of each pixel in the adversarial vector image includes: For each pixel in the adversarial carrier image Its adversarial noise is defined as ; According to the adversarial noise Probability of sign adjustment modification: when hour, ; when hour, ; In the formula, It is a hyperparameter for controlling the intensity of adjustment. and Represents the pixel conduct and The modified probability needs to be renormalized after adjustment to ensure... ,in This indicates the probability of not making any changes.
7. The low-distortion image steganography method based on deep learning according to claim 1, characterized in that, The target steganalysis analyzer uses the SRNet model.
8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor, the one or more computer programs being executed by the at least one processor to enable the at least one processor to perform the deep learning-based low-distortion image steganography method as described in any one of claims 1-7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the low-distortion image steganography method based on deep learning as described in any one of claims 1-7.
10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the low-distortion image steganography method based on deep learning as described in any one of claims 1-7.