VLDB 2026 Research / reviewers in the wild / expert
Shunquan Tan
dblp:02/4567
· DBLP profile ↗
68ranked-venue papers
9as first author
45since 2021 · last 2026
0000-0002-7457-3691ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 33 · 4 first-author · 23 since 2021Security and privacy · 30 · 5 first-author · 17 since 2021Artificial intelligence and machine learning · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Active Adversarial Noise Suppression for Image Forgery LocalizationabstractRecent advances in deep learning have significantly propelled the development of image forgery localization. However, existing models remain highly vulnerable to adversarial attacks: imperceptible noise added to forged images can severely mislead these models. In this paper, we address this challenge with an Adversarial Noise Suppression Module (ANSM) that generates a defensive perturbation to suppress the attack effect of adversarial noise. We observe that forgery-relevant features extracted from adversarial and original forged images exhibit distinct distributions. To bridge this gap, we introduce Forgery-relevant Features Alignment (FFA) as a first-stage training strategy, which reduces distributional discrepancies by minimizing the channel-wise Kullback-Leibler divergence between these features. To further refine the defensive perturbation, we design a second-stage training strategy, termed Mask-guided Refinement (MgR), which incorporates a dual-mask constraint. MgR ensures that the defensive perturbation remains effective for both adversarial and original forged images, recovering forgery localization accuracy to their original level. Extensive experiments across various attack algorithms demonstrate that our method significantly restores the forgery localization model's performance on adversarial images. Notably, when ANSM is applied to original forged images, the performance remains nearly unaffected. To our best knowledge, this is the first report of adversarial defense in image forgery localization tasks. Rongxuan Peng, Shunquan Tan, Xianbo Mo, Alex Chichung Kot, Jiwu Huang |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2026 | Enhancing JPEG Steganography With GANs via Adaptive Modification Loss and Random MaskingabstractLearning adaptive embedding costs with deep learning has become an important direction for improving steganographic security. However, most existing approaches focus on spatial-domain images, while effective cost learning for JPEG images remains challenging due to the complexity introduced by block-wise discrete cosine transform and lossy quantization. In this paper, we present an enhanced GAN-based framework that learns asymmetric embedding costs for JPEG images from scratch, improving both content adaptivity and training stability. Specifically, we introduce an adaptive modification loss that directly links the generator’s predicted embedding probabilities to the actual modification behavior, enabling fully data-driven and content-aware optimization without relying on handcrafted filters or quantization-dependent heuristics. In addition, we propose a random masking strategy applied during later training stages to prevent discriminator dominance and maintain informative adversarial feedback. Extensive experiments on multiple benchmark datasets and under various steganalytic detectors demonstrate that the proposed method consistently improves steganographic security over existing JPEG-domain approaches. Ablation studies further validate the effectiveness of the proposed loss design and training strategy. Tianrui Gu, Bohong Li, Weiqi Luo 0001, Peijia Zheng, Shunquan Tan, Jiwu Huang |
IEEE Trans. Circuits Syst. Video Technol. | 5 |
| 2026 | Query-Efficient Hard-Label Attacks Against Black-Box Image Forgery Localization Model via Reinforcement LearningabstractDeep learning-based image forgery localization models are increasingly deployed in real-world forensic services, yet their robustness against black-box adversarial manipulation remains insufficiently understood, calling for practical anti-forensics techniques to expose potential security weaknesses. Prior adversarial anti-forensics studies for forgery localization mainly assume white-box access, which limits their applicability to deployed systems where only hard, mask-like outputs are available and queries are tightly constrained. To bridge this gap, we propose AdvFor, a query-efficient black-box attack frame-work tailored for forgery localization with hard-label, mask-only, spatially dense binary feedback. AdvFor formulates the attacker–model interaction as a finite-horizon Markov Decision Process and learns a transferable attack policy from hard-mask feedback. Once trained, AdvFor can be deployed via fixed-length policy execution with onlyT=7 queries per image, avoiding per-image boundary refinement or query-dense direction/gradient estimation. The learned policy optimizes a structured objective—progressively suppressing forgery responses in the predicted localization mask so that the masks of forgery images approach an authentic-like (near-zero) output—while maintaining visual fidelity. Extensive experiments on six benchmark datasets and multiple modern forgery localization models demonstrate that AdvFor consistently achieves stronger attack performance than representative baselines under the same perturbation constraints, while operating in an ultra-low-query regime.We further validate AdvFor under common deployment-style defenses, showing its notable effectiveness in realistic settings. Xianbo Mo, Shunquan Tan, Rongxuan Peng, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | DiffEraser: Generalized Text Erasure Based on Latent Diffusion PriorabstractText removal is an important task in processing both scene and document images. However, existing scene text removal (STR) methods are primarily focus on scene text images. The STR models (trained by scene text images) perform poorly on document images with dense, complex textured backgrounds. We discover that the limitations of existing methods can be attributed to the difficuties in background features estimation in the regions to be erased, which is based on the knowledge from neighboring regions in the input images and priors learned from the training data. The background features estimation performance degrades under the cross-domain scenarios, and compromises the quality of STR results. To address these issues, we introduce DiffEraser, a novel text removal framework that leverages prior knowledge from the Latent Diffusion Model (LDM) for removing text in both scene and document images. Our DiffEraser incorporates two key innovations to fully exploit the prior knowledge of LDM. First, we replace the conventional Variational Auto-Encoders (VAE) encoder with a Diffusion-Prior (DP) encoder, aiming to integrate the heterogeneous information from the LDM prior knowledge in latent space with the multi-level encoded features of the input image. Second, we introduce a Latent-Fusion (LF) decoder that integrates the heterogeneous features from both the LDM and DP encoders to generate high-quality text-erased results. To evaluate the generalization performance of our DiffEraser, we focus on the cross-domain protocols and construct a document image dataset, NPID295, which contains 295 types of passports and identity cards. Notably, when trained on a scene text dataset, DiffEraser significantly outperforms existing STR methods in the challenging NPID295 dataset. The resources of this work will be available online upon acceptance. Zhihao Chen 0011, Changsheng Chen 0001, Shunquan Tan, Jiwu Huang |
IEEE Trans. Image Process. | 4 |
| 2025 | Query-efficient Attack for Black-box Image Inpainting Forensics via Reinforcement LearningabstractRecently, image inpainting has become a common tool for manipulating nature images in a malicious manner, which has led to the rapid advancement of inpainting forensics. Although current forensics methods have shown precise location of inpainting regions and reliable robustness against image post-processing operations, it remains unclear whether they can effectively resist the possible attacks in real-world scenarios. To identify potential flaws, we propose a novel black-box anti-forensics framework to attack inpainting forensics methods, which employs reinforcement learning to generate a query-efficient countermeasure, named RLGC. To this end, we define reinforcement learning paradigm to model the Markov Decision Process of query-based black-box anti-forensics scenario. Specifically, pixel-wise agents are used to modulate anti-forensics images based on action selection and query forensics methods to obtain corresponding outputs. Later, reward function evaluates attack effect and image distortion with these outputs. To maximize the cumulative reward, policy and value networks are integrated and trained by Asynchronous Advantage Actor-Critic algorithm. Experimental results demonstrate that, without visually detectable distortion on anti-forensics images, RLGC achieves remarkable attack effects in a highly query-effcient way against various black-box inpainting forensics methods, even outperforming the most representative white-box attack method. Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
AAAI | 2 |
| 2025 | A GAN Framework for Asymmetric Embedding Costs Learning in JPEG SteganographyabstractA key challenge in current steganography research is automatically learning image embedding costs without relying on existing costs. To date, there has been limited work on JPEG steganography, and the reported methods primarily rely on learning symmetric embedding, which fails to fully exploit the relationships between different modification directions within an embedding unit. This limitation restricts their security, leaving room for improvements in JPEG steganography techniques. To address this issue, we propose a GAN-based framework for JPEG steganography that learns asymmetric embedding costs from scratch. Our approach extends a modern framework of spatial steganography by incorporating a key IDCT module, which facilitates the conversion between JPEG and spatial domains. This enables the integration of effective spatial steganographic and steganalytic techniques into our framework for JPEG steganography. Additionally, we use a dual-branch UNet to generate separate embedding probabilities for +1 and -1 DCT coefficients and introduce a specialized loss function to guide DCT modifications. This loss function is designed by converting the modified DCT coefficients back to the spatial domain and analyzing various spatial residuals. Extensive experiments demonstrate that our method significantly outperforms existing JPEG steganography techniques, achieving state-of-the-art security performance. Furthermore, many ablation experiments validate the rationale of our model. Bohong Li, Weiqi Luo 0001, Peijia Zheng, Shunquan Tan, Jiwu Huang |
ICME | 4 |
| 2025 | Identification of Generative Forged Western Blot ImagesabstractWith the rapid advancement of AI generative image technologies, the quality of fabricated images has significantly improved, posing a serious challenge to research integrity. Western blot (WB) images, frequently used in scientific publications, have become a primary target for forgery, leading to serious academic misconduct. However, detecting AI-generated WB images remains particularly challenging due to the low texture complexity and structural simplicity of WB images. To address this issue, we propose a novel detection framework for generative WB forgeries by leveraging large-scale pretrained models with targeted fine-tuning. This approach retains the generalization capabilities of the backbone model while adapting it to the unique characteristics of WB images. Moreover, we introduce an adversarial feature alignment module with a direction-aware domain classifier designed according to the banded and structural nature of WB images, which enhances robustness under limited data and across unseen generative styles. Extensive experiments demonstrate that our method consistently achieves superior performance compared with existing approaches across multiple generative models, low-resource target domains, and cross-domain settings, showing higher detection accuracy, stronger generalization, and robustness to common post-processing operations. These results highlight the practical applicability of the proposed framework in real-world scientific integrity monitoring. Yunqiao Zhang, Shunquan Tan, Jiwu Huang |
TrustCom | 2 |
| 2025 | SEAP: squeeze-and-excitation attention guided pruning for lightweight steganalysis networksabstractIn recent years, the increasing computational and storage demands of deep steganalysis models have drawn attention to lightweight architectures. While pruning algorithms for image steganalysis networks have been proposed, they often do not apply to networks equipped with mobile inverted bottleneck (MBConv) structures, such as EfficientNet. In this paper, we propose a Squeeze-and-Excitation Attention-based Pruning framework for image steganalysis networks, named SEAP. The method adopts a block-wise structured pruning strategy guided by the SE channel attention mechanism, where unimportant channels within each MBConv block are identified based on SE attention values and soft masks. Since pruning is conducted independently within each MBConv block and the input/output dimensions of the block remain unchanged, potential pruning conflicts across blocks are effectively avoided. In addition, we propose a sparsity regularization mechanism that adaptively adjusts the regularization strength based on the network structure, helping to preserve detection performance. Extensive experimental results demonstrate that the pruned network retains only a small fraction of the original network’s parameters and computational costs while achieving performance comparable to the original unpruned networks. Shenghai Luo, Shunquan Tan, Zhenjun Li |
EURASIP J. Inf. Secur. | 3 |
| 2025 | CTNet: A Convolutional Transformer Network for Color Image Steganalysis
Kangkang Wei, Weiqi Luo 0001, Shunquan Tan, Jiwu Huang |
J. Comput. Sci. Technol. | 3 |
| 2025 | Universal forged image detection and localization via self-supervised data generation and large-scale model adaptation
Yang Su 0005, Shunquan Tan, Yunqiao Zhang, Jiwu Huang |
Multim. Syst. | 2 |
| 2025 | Few-shot based learning recaptured image detection with multi-scale feature fusion and attention
Israr Hussain, Shunquan Tan, Jiwu Huang |
Pattern Recognit. | 2 |
| 2025 | Elastic Supernet with Dynamic Training for JPEG steganalysis
Qiushi Li 0001, Shunquan Tan, Bin Li 0011, Jiwu Huang |
Signal Process. | 2 |
| 2025 | Prompt Engineering-Assisted Malware Dynamic Analysis Using GPT-4abstractMalware detection remains a critical challenge due to the increasing use of code obfuscation, packing, and wrapping techniques, which hinder traditional static analysis methods. Dynamic analysis, particularly through the examination of Application Programming Interface (API) call sequences, has emerged as an effective approach for identifying malicious behaviors. However, existing deep learning models often struggle to generate high-quality representations of API calls and are unable to handle previously unseen APIs, thereby limiting detection performance and model generalization. To address these challenges, we propose a novel malware dynamic analysis framework that leveragesGPT-4prompt engineering to generate descriptive text for each API call within a sequence. These descriptions are then encoded using a pre-trained BERT model to produce rich, knowledge-enhanced representations of API sequences. Our method not only incorporates external knowledge for improved semantic understanding but also enables the representation of unknown API calls, thus enhancing generalization. We further design a CNN-based classifier to extract features from the enriched representations for malware detection and classification. Extensive experiments on five benchmark datasets demonstrate that our approach outperforms state-of-the-art methods, achieving superior detection accuracy and generalization across different datasets. Especially, the detection accuracy on the Catak dataset increased by 12.38%, which highlights the significant improvement of our method in challenging scenarios. The code is available. Pei Yan, Shunquan Tan, Miaohui Wang, Jiwu Huang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Evading Detection Actively: Toward Anti-Forensics Against Forgery LocalizationabstractAnti-forensics seeks to eliminate or conceal traces of tampering artifacts. Typically, anti-forensic methods are designed to deceive binary detectors and persuade them to misjudge the authenticity of an image. However, to the best of our knowledge, no attempts have been made to deceive forgery detectors at the pixel level and mis-locate forged regions. Traditional adversarial attack methods cannot be directly used against forgery localization due to the following defects: 1) they tend to just naively induce the target forensic models to flip their pixel-level pristine or forged decisions; 2) their anti-forensics performance tends to be severely degraded when faced with the unseen forensic models; 3) they lose validity once the target forensic models are retrained with the anti-forensics images generated by them. To tackle the three defects, we propose SEAR (Self-supErvised Anti-foRensics), a novel self-supervised and adversarial training algorithm that effectively trains deep-learning anti-forensic models against forgery localization. SEAR sets a pretext task to reconstruct perturbation for self-supervised learning. In adversarial training, SEAR employs a forgery localization model as a supervisor to explore tampering features and constructs a deep-learning concealer to erase corresponding traces. We have conducted large-scale experiments across diverse datasets. The experimental results demonstrate that, through the combination of self-supervised learning and adversarial learning, SEAR successfully deceives the state-of-the-art forgery localization methods, as well as tackle the three defects regarding traditional adversarial attack methods mentioned above. Long Zhuo, Shenghai Luo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | A Keyless Extraction Framework Targeting at Deep Learning Based Image-Within-Image ModelsabstractImage-within-image technique aims to establish covert communication by concealing a secret image within a cover image. Compared with traditional steganography algorithms, the security of image-within-image technique has not been rigorously evaluated by steganalysis. Existing attack methods just brutally destroy the container image, resulting in the secret image cannot be revealed by the original decryption model (key). This paper introduces a novel keyless extraction framework, carrying out steganalysis on the container image without destroying it. Our approach utilizes collected pairs of container and revealed images to construct a master key, enabling us to extract secret image from container image without relying on the original key. Remarkably, the master key remains effective for multiple image-within-image techniques simultaneously, even when their encryption and decryption models are re-trained. In addition, we propose a patch-based data augmentation technique to adapt to scenarios with limited training samples, and we design a weighted loss function with three components to further enhance the visual quality of the extracted secret image. All the experiments are conducted on datasets derived from ImageNet, COCO and DIV2k. The results demonstrate that our approach can extract secret images with comparable visual quality to the original ones. Rongxuan Peng, Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
ICASSP | 3 |
| 2024 | Improving VGG-Style Convnet for JPEG SteganalysisabstractThe steganalysis of JPEG images is a crucial area of research. Deep-learning based steganalysis methods have achieved superior detection performance. All methods for JPEG steganalysis rely on residual networks. Although the incorporation of residual connections has enhanced detection performance, it has also led to a notable increase in computational complexity. Furthermore, most of these methods are not complete end-to-end models. In their approaches, traditional hand-crafted filters are employed for image preprocessing. To avoid relying on residual connections and prior knowledge, we propose an end-to-end VGG-style ConvNet. During training, the model utilizes a multi-branch architecture, while it is transformed into a VGG-style ConvNet through structural reparameterization during inference. We conduct extensive experiments on ALASKA KAGGLE dataset and ALASKA II dataset, demonstrating that the proposed method achieves state-of-the-art results in the JPEG domain comparable to other CNN-based steganalyzers such as UCNet and EfficientNet, with clearly better convergence capacity and lower model complexity. Zhuofan Yang, Qiushi Li 0001, Shenghai Luo, Shunquan Tan, Bin Li 0011 |
ICASSP | 4 |
| 2024 | Copyright Protection for Large Language Model EaaS via Unforgeable Backdoor Watermarking
Cong Kong, Shunquan Tan, Zhao-Xia Yin, Xinpeng Zhang 0001 |
ICPR (20) | 3 |
| 2024 | Velocity Field-Based Surveillance Video Frame Deletion Detection Using Siamese Network
Yang Su 0005, Shunquan Tan, Jiwu Huang |
ICPR (22) | 2 |
| 2024 | A Novel Universal Image Forensics Localization Model Based on Image Noise and Segment Anything ModelabstractMaliciously manipulated images have inflicted severe negative impacts on people's lives, making the development of forgery localization techniques imperative. The goal of forgery localization is to segment regions containing tampering traces. In this paper, we treat tampered areas as distinct targets within the noise feature map, utilizing noise features to filter objects in the source image and achieve forgery localization. Our approach involves designing a transformer-based forgery feature extractor, which seamlessly integrates two key features during the extraction process: target features obtained from the image segmentation model Segment Anything Model, and noise features extracted by the steganalysis rich model filters. This extractor can effectively extract forgery features in the image and a mask was applied to localize the tampered regions. Extensive experimentation across multiple datasets underscores the robust competitiveness of our model and its strong transfer learning capabilities. Yang Su 0005, Shunquan Tan, Jiwu Huang |
IH&MMSec | 2 |
| 2024 | GAN-based Symmetric Embedding Costs Adjustment for Enhancing Image Steganographic SecurityabstractDesigning embedding costs is pivotal in modern image steganography. Many studies have shown adjusting symmetric embedding costs to asymmetric ones can enhance steganographic security. However, most existing methods heavily depend on manually defined parameters or rules, limiting security performance improvements. To overcome this limitation, we introduce an advanced GAN-based framework that transitions symmetric costs to asymmetric ones without the need for the manual intervention seen in existing approaches, such as the detailed specification of cost modulation directions and magnitudes. In our framework, we firstly achieve symmetric costs for a cover image, which is randomly split into two sub-images, with part of the secret information embedded into one. Subsequently, we design a GAN model to adjust the embedding costs of the second sub-image to asymmetric, facilitating the secure embedding of the remaining secret information. To support our phased embedding approach, our GAN's discriminator incorporates two steganalyers with different tasks: distinguishing the generator's final output, i.e., the stego image, from both the input cover image and the partially embedded stego image, providing diverse guidance to the generator. In addition, we introduce a simple yet effective update strategy to ensure a stable training process. Comprehensive experiments demonstrate that our method significantly enhances security over existing symmetric steganography techniques, achieving state-of-the-art levels compared to other methods focused on embedding costs adjustments. Additionally, detailed ablation studies validate our approach's effectiveness. Miaoxin Ye, Saixing Zhou, Weiqi Luo 0001, Shunquan Tan, Jiwu Huang |
ACM Multimedia | 4 |
| 2024 | A semi-supervised deep learning approach for cropped image detection
Israr Hussain, Shunquan Tan, Jiwu Huang |
Expert Syst. Appl. | 2 |
| 2024 | A knowledge distillation based deep learning framework for cropped images detection in spatial domain
Israr Hussain, Shunquan Tan, Jiwu Huang |
Signal Process. Image Commun. | 2 |
| 2024 | Enhanced Dynamic Analysis for Malware Detection With Gradient AttackabstractMalware detection is an effective way to prevent the intrusion of malware into computer systems, and the API-based dynamic analysis method can effectively detect obfuscated and packaged malware. However, existing methods still suffer from limited detection accuracy and weak generalization. To address this issue, this paper presents a gradient attack-based malware dynamic analysis method. Through exerting adversarial noise into the embedding layer, the malware detection model can learn more robust representations of API sequences during training, achieving broader coverage of sample representations. The strategy of normalizing attack noise and recovering attacked representation is designed, which controls the strength of the gradient attack within a reasonable range and prevents a negative impact on the model's detection performance. The proposed method can be applied to existing API-based malware detection models to enhance their detection performance, indicating the strong generality of the proposed method. Experimental results on two benchmark datasets (i.e.,AliyunandCatak) demonstrate the effectiveness of the proposed gradient attack method, which further improves the detection performance of the mainstream API-based models, with an average accuracy increase of 2.80% and 3.66% on these two datasets, respectively. Pei Yan, Shunquan Tan, Miaohui Wang, Jiwu Huang |
IEEE Signal Process. Lett. | 2 |
| 2024 | Employing Reinforcement Learning to Construct a Decision-Making Environment for Image Forgery LocalizationabstractThe widespread misuse of advanced image editing tools and deep generative techniques has led to a proliferation of images with altered content in real-life scenarios, often without any discernible traces of tampering. This has created a potential threat to security and credibility of images. Image forgery localization is an urgent technique. In this paper, we propose a novel reinforcement learning-based framework CoDE (Construct Decision-making Environment) that can provide reliable localization result of tampered area in forged images. We model the forgery localization task as a Markov Decision Process (MDP), where each pixel is equipped with an agent that performs Gaussian distribution-based continuous action to iteratively update the respective forgery probability, so as to achieve pixel-level image forgery localization. In order to construct the state transitions within MDP, we propose a twin-flow state encoder to handle the updated state, which consists of the forged image and its corresponding forgery probability map. What’s more, considering that the tampered area is often sparse in practical image tampering scenarios, we design a reward function specifically for these sparse tampered area. This reward function can guide the agent to more effectively learn the optimal strategy for maximizing the cumulative reward. Extensive experiments conducted on a variety of benchmark datasets demonstrate CoDE’s superior localization accuracy and robustness against image degradation caused by transmission through Online Social Networks (OSNs) and various post-processing attacks. Rongxuan Peng, Shunquan Tan, Xianbo Mo, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Hiding Face Into Background: A Proactive Countermeasure Against Malicious Face SwappingabstractFace information in public images is vulnerable to tampering. Some studies have used pre-embedded watermarks to detect tampering but cannot recover the original face. To address this, we propose a proactive face hiding network that conceals face information in the background region for the first time. Our framework includes three U-Net-based modules: a preparation network, an encoder, and a recovery network. Special loss functions are designed to achieve our objective of recovering the original face from a protected image attacked by face swapping. In addition, we develop a neural network-based JPEG simulator and a differentiable simulator, offering a fresh perspective on addressing the robustness problem associated with JPEG compression. Our method generates protected images with a peak signal-to-noise ratio (PSNR) of 40.947 dB in experiments. Even after different face attacks, the recovered images maintain PSNR between 28.368 and 33.847 dB. After the attack of JPEG compression, the PSNR of the recovered image decreases by a maximum of 2.142 dB. Our scheme effectively generates high-quality protected images that resist face swapping and JPEG compression attacks, enabling recovery of the original faces. Heng Yao 0001, Shunquan Tan, Chuan Qin 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Poster: Query-efficient Black-box Attack for Image Forgery Localization via Reinforcement LearningabstractRecently, deep learning has been widely used in forensics tools to detect and localize forgery images. However, its susceptibility to adversarial attacks highlights the need for the exploration of anti-forensics research. To achieve this, we introduce an innovative and query-efficient black-box anti-forensics framework tailored for the generation of adversarial forgery images. This framework is designed to simulate the query dynamics of online forensic services, utilizing a Markov Decision Process formulation within the paradigm of reinforcement learning. We further introduce a novel reward function, which evaluates the efficacy of attacks based on the disjunction between query results and attack targets. To improve the query efficiency of these attacks, an actor-critic algorithm is employed to maximize cumulative rewards. Empirical findings substantiate the efficacy of our proposed methodology. Specifically, it demonstrates pronounced adversarial effects on a range of prevailing image forgery detectors, while ensuring negligible visually perceptible distortions in the resultant anti-forensics images. Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
CCS | 2 |
| 2023 | VHNet: A Video Hiding Network with robustness to video coding
Heng Yao 0001, Shunquan Tan, Chuan Qin 0001 |
J. Inf. Secur. Appl. | 3 |
| 2023 | Binary steganography based on generative adversarial nets
Yucheng Guan, Shunquan Tan, Qifen Li |
Multim. Tools Appl. | 2 |
| 2023 | Learning Features of Intra-Consistency and Inter-Diversity: Keys Toward Generalizable Deepfake DetectionabstractPublic concerns about deepfake face forgery are continually rising in recent years. Most deepfake detection approaches attempt to learn discriminative features between real and fake faces through end-to-end trained deep neural networks. However, the majorities of them suffer from the problem of poor generalization across different data sources, forgery methods, and/or post-processing operations. In this paper, following the simple but effective principle in discriminative representation learning, i.e., towards learning features of intra-consistency within classes and inter-diversity between classes, we leverage a novel transformer-based self-supervised learning method and an effective data augmentation strategy towards generalizable deepfake detection. Considering the differences between the real and fake images are often subtle and local, the proposed method firstly utilizes Self Prediction Learning (SPL) to learn rich hidden representations by predicting masked patches at a pre-training stage. Intra-class consistency clues in images can be mined without deepfake labels. After pre-training, the discrimination model is then fine-tuned via multi-task learning, including a deepfake classification task and a forgery mask estimation task. It is facilitated by our new data augmentation method called Adjustable Forgery Synthesizer (AFS), which can conveniently simulate the process of synthesizing deepfake images with various levels of visual reality in an explicit manner. AFS greatly prevents overfitting due to insufficient diversity in training data. Comprehensive experiments demonstrate that our method outperforms the state-of-the-art competitors on several popular benchmark datasets in terms of generalization to unseen forgery methods and untrained datasets. Yuzhen Lin, Bin Li 0011, Shunquan Tan |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2023 | Learning Deep Co-Occurrence FeaturesabstractWe exploit the computational capability of deep convolutional neural network (CNN) architecture and the natural interpretability of the co-occurrence matrix (CM) to learn deep co-occurrence features (DCOFs). The DCOFs represent the statistics of the co-occurrences of pixels thus overcoming the black box nature of traditional deep representation learning while at the same time solving the inherent computational difficulty of CM. We propose a parametric co-occurrence matrix (PCM) model to approximate the CM with multivariate Gaussian functions, and have developed three approaches to decomposing the PCM model into linear and nonlinear operations such that the model can be easily implemented using standard CNN operations and to learn the DCOFs of arbitrary shapes. The CNN implementation of the PCM model, termed PCMCNN, can be used as a standard plugin module of a deep learning system and adaptively learns the DCOFs for downstream applications. We demonstrate the broad applicability of the DCOFs and their effectiveness in fine-grained image classification tasks such as texture classification and GAN (generative adversarial network) image detection. The introduction of the PCMCNN module makes it much more compact and efficient than conventional implementations of deep learning models, achieving comparable classification performances to state of the art methods on a variety of benchmarking datasets with models that are more than 30 folds smaller and 11 times less complex. The small model size for learning the DCOFs makes the new method particularly effective for few shot classification of large number of texture categories where the small number of training samples can easily cause traditional deep learning models to overfit. This work shows the potential benefits of combining the principles of traditional handcrafted features and deep representation learning to take advantage of both for advancing state of the art. Guanglin Li 0007, Bin Li 0011, Shunquan Tan, Guoping Qiu |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2023 | STD-NET: Search of Image Steganalytic Deep-Learning Architecture via Hierarchical Tensor DecompositionabstractSteganalysis aims to reveal covert communication established via steganography. In the arm race with steganography, steganalysis has evolved from the old-style hand-crafted features set to deep-learning architectures. However, recent studies show that the majority of existing deep steganalysis models have a large amount of redundancy, which leads to a huge waste of storage and computing resources. The existing model compression method cannot flexibly compress the convolutional layer in residual shortcut block so that a satisfactory shrinking rate cannot be obtained. In this paper, we propose STD-NET, an unsupervised deep-learning architecture search approach via hierarchical tensor decomposition for image steganalysis. Our proposed strategy will not be restricted by various residual connections, since this strategy does not change the number of input and output channels of the convolution block. We propose a normalized distortion threshold to evaluate the sensitivity of each involved convolutional layer of the base model to guide STD-NET to compress target network in an efficient and unsupervised approach, and obtain two network structures of different shapes with low computation cost and similar performance compared with the original one. Extensive experiments have confirmed that, on one hand, our model can achieve comparable or even better detection performance in various steganalytic scenarios due to the great adaptivity of the obtained network architecture. On the other hand, the experimental results also demonstrate that our proposed strategy is more efficient and can remove more redundancy compared with previous steganalytic network compression methods. Shunquan Tan, Qiushi Li 0001, Laiyuan Li, Bin Li 0011, Jiwu Huang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | ReLOAD: Using Reinforcement Learning to Optimize Asymmetric Distortion for Additive SteganographyabstractRecently, the success of non-additive steganography has demonstrated that asymmetric distortion can remarkably improve security performance compared with symmetric cost functions. However, most of current existing additive steganographic methods are still based on symmetric distortion. In this paper, for the first time we optimize asymmetric distortion for additive steganography and propose an A3C (Asynchronous Advantage Actor-Critic) based steganographic framework, called ReLOAD. ReLOAD is composed of an actor and a critic, where the former guides action selection for pixel-wise distortion modulation, and the latter evaluates the performance of modulated distortion. Meanwhile, a reward function that considers embedding effects is proposed to unify the goal of steganography and reinforcement learning, so that the minimization of embedding effects can be achieved by learning secure policy to maximize total rewards. Statistical analysis shows that compared with non-additive steganography, ReLOAD achieves lower change rates and makes embedding traces more consistent with cover image textures. Comprehensive experiments conducted on both hand-crafted feature-based and deep learning-based steganalyzers show that ReLOAD significantly promotes the state-of-the-art security performance of current additive methods and even outperforms non-additive steganography when the modification distribution gets sparser. Xianbo Mo, Shunquan Tan, Weixuan Tang 0004, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Learning General Gaussian Mixture Model with Integral Cosine SimilarityabstractGaussian mixture model (GMM) is a powerful statistical tool in data modeling, especially for unsupervised learning tasks. Traditional learning methods for GMM such as expectation maximization (EM) require the covariance of the Gaussian components to be non-singular, a condition that is often not satisfied in real-world applications. This paper presents a new learning method called G$^2$M$^2$ (General Gaussian Mixture Model) by fitting an unnormalized Gaussian mixture function (UGMF) to a data distribution. At the core of G$^2$M$^2$ is the introduction of an integral cosine similarity (ICS) function for comparing the UGMF and the unknown data density distribution without having to explicitly estimate it. By maximizing the ICS through Monte Carlo sampling, the UGMF can be made to overlap with the unknown data density distribution such that the two only differ by a constant scalar, and the UGMF can be normalized to obtain the data density distribution. A Siamese convolutional neural network is also designed for optimizing the ICS function. Experimental results show that our method is more competitive in modeling data having correlations that may lead to singular covariance matrices in GMM, and it outperforms state-of-the-art methods in unsupervised anomaly detection. Guanglin Li 0001, Bin Li 0011, Changsheng Chen 0001, Shunquan Tan, Guoping Qiu |
IJCAI | 4 |
| 2022 | ISP-GAN: inception sub-pixel deconvolution-based lightweight GANs for colorization
Long Zhuo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
Multim. Tools Appl. | 2 |
| 2022 | Hybrid deep-learning framework for object-based forgery detection in video
Shunquan Tan, Baoying Chen, Jishen Zeng, Bin Li 0011, Jiwu Huang |
Signal Process. Image Commun. | 1 |
| 2022 | One-Class Double Compression Detection of Advanced Videos Based on Simple Gaussian Distribution ModelabstractPassive video forensics has become an active topic in recent years. Generally, a pristine video obtained from surveillance cameras or other video recording devices is single compressed. At the same time, double lossy compression will certainly be introduced in tampered videos since it needs to go through recompression to perform tampering on a commonly used compressed video. In the video’s double compression, some traces are left due to the intrinsic effects of recompression. Traditional supervised learning is inefficient because it requires two classes (the pristine and the manipulated) that occur in the video to be exhaustively assigned labels. Actually, compared with pristine videos, manipulated videos with labels are more difficult to obtain. To address this problem, in this paper, one-class classification, which is often used for anomaly detection and only needs the target class, is introduced. We first treat all decompressed video frames as still images and extract subtractive pixel adjacency matrix (SPAM) steganalysis features to detect traces left in the double compression process. Then we adopt a Gaussian density-based one-class classifier since SPAM features extracted from pristine video frames approximately subject to the Gaussian distribution. Furthermore, we improve the robustness of the classifier by using ensemble strategy. Experimental results indicate that our proposed method exceeds other more complex one-class classification methods, and outperforms fully-supervised learning methods only by feeding features from single compressed video frames to our one-class classifier. Qiushi Li 0001, Shengda Chen, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2022 | Gradually Enhanced Adversarial Perturbations on Color Pixel Vectors for Image SteganographyabstractCompared to element-wise embedding, vector-wise embedding based on CPV (color pixel vector) shows its superiority in color image steganography. However, when working with an adversarial embedding scheme for introducing adversarial perturbations, its success rate of deceiving a target CNN (convolutional neural network) steganalyzer dramatically drops. In this paper, inspired by the I-FGSM (iterative fast gradient sign method), we present an effective steganography for color images. Specifically, after decomposing an image into several non-overlapped sub-images, we iteratively and gradually increase the possibilities of generating adversarial perturbations for the CPVs in each sub-image by changing their adversarial costs. The costs are incrementally adjusted with a small step so that their maximum relative variation is minimized. Leveraging a new designed cost adjustment criterion, more modification patterns of CPV can participate in producing effective adversarial perturbations. Extensive experiments demonstrate that the proposed method achieves a high success rate in deceiving the target CNN steganalyzer and stably defending against the detection of other non-target steganalytic schemes for color images. Xinghong Qin, Bin Li 0011, Shunquan Tan, Weixuan Tang 0004, Jiwu Huang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2022 | Universal Deep Network for Steganalysis of Color Image Based on Channel RepresentationabstractUp to now, most existing steganalytic methods were designed for grayscale images, and are not suitable for the color images that are widely used in social networks. In this paper, we design a universal color image steganalysis network (called UCNet) for the spatial and JPEG domains. The proposed method includes preprocessing, convolutional, and classification modules. To preserve the steganalytic features in each color channel, the preprocessing module first separates the input image into three channels based on the corresponding embedding spaces (i.e., RGB in the spatial domain, and YCbCr in the JPEG domain), and then extracts the image residuals with 62 fixed high-pass filters. Finally, all truncated residuals are concatenated for subsequent analysis, rather than adding them together in the first layer as in existing CNN-based steganalyzers. To accelerate network convergence and effectively reduce the number of parameters, the convolutional module contains three carefully designed types of layers with different shortcut connections and group convolution structures, to further learn the high-level steganalytic features. In the classification module, we employ global average pooling and a fully connected layer for classification. We conduct extensive experiments on ALASKA II to demonstrate that the proposed method can achieve state-of-the-art results that are comparable with other modern CNN-based steganalyzers (e.g., SRNet and LC-Net) in both the spatial and JPEG domains, with relatively few memory requirements and short training times. Furthermore, we also provide some necessary descriptions and carry out numerous ablation experiments to verify the rationality of the network design. Kangkang Wei, Weiqi Luo 0001, Shunquan Tan, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Self-Adversarial Training Incorporating Forgery Attention for Image Forgery LocalizationabstractImage editing techniques enable people to modify the content of an image without leaving visual traces and thus may cause serious security risks. Hence the detection and localization of these forgeries become quite necessary and challenging. Furthermore, unlike other tasks with extensive data, there is usually a lack of annotated forged images for training due to annotation difficulties. In this paper, we propose a self-adversarial training strategy and a reliable coarse-to-fine network that utilizes a self-attention mechanism to localize forged regions in forgery images. The self-attention module is based on a Channel-Wise High Pass Filter block (CW-HPF). CW-HPF leverages inter-channel relationships of features and extracts noise features by high pass filters. Based on the CW-HPF, a self-attention mechanism, calledforgery attention, is proposed to capture rich contextual dependencies of intrinsic inconsistency extracted from tampered regions. Specifically, we append two types of attention modules on top of CW-HPF respectively to model internal interdependencies in spatial dimension and external dependencies among channels. We exploit a coarse-to-fine network to enhance the noise inconsistency between original and tampered regions. More importantly, to address the issue of insufficient training data, we design a self-adversarial training strategy that expands training data dynamically to achieve more robust performance. Specifically, in each training iteration, we perform adversarial attacks against our network to generate adversarial examples and train our model on them. The proposed method is based on the assumption of content-changed manipulations. Extensive experimental results demonstrate that our proposed algorithm steadily outperforms state-of-the-art methods by a clear margin in different benchmark datasets. Long Zhuo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Image Steganography Based on Iterative Adversarial Perturbations Onto a Synchronized-Directions Sub-ImageabstractNowadays a steganography has to face challenges to both feature-based staganalysis and convolutional neural network (CNN) based steganalysis. In this paper, we present a novel steganographic scheme to incorporate synchronizing modification directions and iterative adversarial perturbations to enhance steganographic performance. Firstly an existing steganographic function is employed to compute initial costs. Then the secret message bits are embedded following clustering modification directions profile. If the target CNN classifier discriminates the resulting stego image as the correct class, we change costs in adversarial manners, and then choose a sub-image to re-embed message with changed costs. Adversarial intensity will be iteratively increased until the adversarial stego image can deceive the target CNN classifier, which guarantees that applied adversarial perturbations are minimal and it is unnecessary to search the optimal adversarial intensity. Experiments demonstrate that the proposed method effectively enhances security to counter both feature-based classifiers and CNN classifiers, no matter they are targeted or non-targeted. Xinghong Qin, Shunquan Tan, Weixuan Tang 0004, Bin Li 0011, Jiwu Huang |
ICASSP | 2 |
| 2021 | A novel deep learning framework for double JPEG compression detection of small size blocks
Israr Hussain, Shunquan Tan, Bin Li 0011, Xinghong Qin, Dostdar Hussain, Jiwu Huang |
J. Vis. Commun. Image Represent. | 2 |
| 2021 | FeatureTransfer: Unsupervised Domain Adaptation for Cross-Domain Deepfake DetectionabstractRecently, various Deepfake detection methods have been proposed, and most of them are based on convolutional neural networks (CNNs). These detection methods suffer from overfitting on the source dataset and do not perform well on cross-domain datasets which have different distributions from the source dataset. To address these limitations, a new method named FeatureTransfer is proposed in this paper, which is a two-stage Deepfake detection method combining with transfer learning. Firstly, The CNN model pretrained on a third-party large-scale Deepfake dataset can be used to extract the more transferable feature vectors of Deepfake videos in the source and target domains. Secondly, these feature vectors are fed into the domain-adversarial neural network based on backpropagation (BP-DANN) for unsupervised domain adaptive training, where the videos in the source domain have real or fake labels, while the videos in the target domain are unlabelled. The experimental results indicate that the proposed method FeatureTransfer can effectively solve the overfitting problem in Deepfake detection and greatly improve the performance of cross-dataset evaluation. Baoying Chen, Shunquan Tan |
Secur. Commun. Networks | 2 |
| 2021 | MCTSteg: A Monte Carlo Tree Search-Based Reinforcement Learning Framework for Universal Non-Additive SteganographyabstractRecent research has shown that non-additive image steganographic frameworks effectively improve security performance through adjusting distortion distribution. However, as far as we know, all of the existing non-additive proposals are based on handcrafted policies, and can only be applied to a specific image domain, which heavily prevent non-additive steganography from releasing its full potentiality. In this paper, we propose an automatic non-additive steganographic distortion learning framework called MCTSteg to remove the above restrictions. Guided by the reinforcement learning paradigm, we combine Monte Carlo Tree Search (MCTS) and steganalyzer-based environmental model to build MCTSteg. MCTS makes sequential decisions to adjust distortion distribution without human intervention. Our proposed environmental model is used to obtain feedbacks from each decision. Due to its self-learning characteristic and domain-independent reward function, MCTSteg has become the first reported universal non-additive steganographic framework which can work in both spatial and JPEG domains. Extensive experimental results show that MCTSteg can effectively withstand the detection of both hand-crafted feature-based and deep-learning-based steganalyzers. In both spatial and JPEG domains, the security performance of MCTSteg steadily outperforms the state of the art by a clear margin under different scenarios. Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | CALPA-NET: Channel-Pruning-Assisted Deep Residual Network for Steganalysis of Digital ImagesabstractOver the past few years, detection performance improvements of deep-learning based steganalyzers have been usually achieved through structure expansion. However, excessive expanded structure results in huge computational cost, storage overheads, and consequently difficulty in training and deployment. In this paper we propose CALPA-NET, a ChAnneL-Pruning-Assisted deep residual network architecture search approach to shrink the network structure of existing vast, over-parameterized deep-learning based steganalyzers. We observe that the broad inverted-pyramid structure of existing deep-learning based steganalyzers might contradict the well-established model diversity oriented philosophy, and therefore is not suitable for steganalysis. Then a hybrid criterion combined with two network pruning schemes is introduced to adaptively shrink every involved convolutional layer in a data-driven manner. The resulting network architecture presents a slender bottleneck-like structure. We have conducted extensive experiments on BOSSBase + BOWS2 dataset, more diverse ALASKA dataset and even a large-scale subset extracted from ImageNet CLS-LOC dataset. The experimental results show that the model structure generated by our proposed CALPA-NET can achieve comparative performance with less than two percent of parameters and about one third FLOPs compared to the original steganalytic model. The new model possesses even better adaptivity, transferability, and scalability. Shunquan Tan, Weilong Wu, Zilong Shao, Qiushi Li 0001, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Image Tampering Localization Using a Dense Fully Convolutional NetworkabstractThe emergence of powerful image editing software has substantially facilitated digital image tampering, leading to many security issues. Hence, it is urgent to identify tampered images and localize tampered regions. Although much attention has been devoted to image tampering localization in recent years, it is still challenging to perform tampering localization in practical forensic applications. The reasons include the difficulty of learning discriminative representations of tampering traces and the lack of realistic tampered images for training. Since Photoshop is widely used for image tampering in practice, this paper attempts to address the issue of tampering localization by focusing on the detection of commonly used editing tools and operations in Photoshop. In order to well capture tampering traces, a fully convolutional encoder-decoder architecture is designed, where dense connections and dilated convolutions are adopted for achieving better localization performance. In order to effectively train a model in the case of insufficient tampered images, we design a training data generation strategy by resorting to Photoshop scripting, which can imitate human manipulations and generate large-scale training samples. Extensive experimental results show that the proposed approach outperforms state-of-the-art competitors when the model is trained with only generated images or fine-tuned with a small amount of realistic tampered images. The proposed method also has good robustness against some common post-processing operations. Peiyu Zhuang, Haodong Li 0001, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Identification of deep network generated images using disparities in color components
Haodong Li 0001, Bin Li 0011, Shunquan Tan, Jiwu Huang |
Signal Process. | 3 |
| 2019 | Detecting double JPEG compression and its related anti-forensic operations with CNN
Bin Li 0011, Hu Luo, Shunquan Tan |
Multim. Tools Appl. | 4 |
| 2019 | CNN-Based Adversarial Embedding for Image SteganographyabstractSteganographic schemes are commonly designed in a way to preserve image statistics or steganalytic features. Since most of the state-of-the-art steganalytic methods employ a machine learning (ML)-based classifier, it is reasonable to consider countering steganalysis by trying to fool the ML classifiers. However, simply applying perturbations on stego images as adversarial examples may lead to the failure of data extraction and introduce unexpected artifacts detectable by other classifiers. In this paper, we present a steganographic scheme with a novel operation called adversarial embedding (ADV-EMB), which achieves the goal of hiding a stego message while at the same time fooling a convolutional neural network (CNN)-based steganalyzer. The proposed method works under the conventional framework of distortion minimization. In particular, ADV-EMB adjusts the costs of image elements modifications according to the gradients back propagated from the target CNN steganalyzer. Therefore, modification direction has a higher probability to be the same as the inverse sign of the gradient. In this way, the so-called adversarial stego images are generated. Experiments demonstrate that the proposed steganographic scheme achieves better security performance against the target adversary-unaware steganalyzer by increasing its missed detection rate. In addition, it deteriorates the performance of other adversary-aware steganalyzers, opening the way to a new class of modern steganographic schemes capable of overcoming powerful CNN-based steganalysis. Weixuan Tang 0004, Bin Li 0011, Shunquan Tan, Mauro Barni, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | WISERNet: Wider Separate-Then-Reunion Network for Steganalysis of Color ImagesabstractUntil recently, deep steganalyzers in the spatial domain have been all designed for gray-scale images. In this paper, we propose the wider separate-then-reunion network (WISERNet) for steganalysis of color images. We provide theoretical rationale to claim that the summation in normal convolution is one sort of linear collusion attack which reserves strong correlated patterns while impairs uncorrelated noises. Therefore, in the bottom convolutional layer which aims at suppressing correlated image contents, we adopt separate channel-wise convolution without summation instead. Conversely, in the upper convolutional layers, we believe that the summation in normal convolution is beneficial. Therefore, we adopt united normal convolution in those layers and make them remarkably wider to reinforce the effect of linear collusion attack. As a result, our proposed wide-and-shallow, separate-then-reunion network structure is specifically suitable for color image steganalysis. We have conducted extensive experiments on color image datasets generated from BOSSBase raw images and another large-scale dataset that contains 100, 000 raw images, with different demosaicking algorithms and down-sampling algorithms. The experimental results show that our proposed network outperforms other state-of-the-art color image steganalytic models either hand crafted or learned using deep networks in the literature by a clear margin. Specifically, it is noted that the detection performance gain is achieved with less than half the complexity compared to the most advanced deep-learning steganalyzer as far as we know, which is scarce in the literature. Jishen Zeng, Shunquan Tan, Guangqing Liu, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | VPCID - A VoIP Phone Call Identification Database
Yuankun Huang, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IWDW | 2 |
| 2018 | Content-Adaptive Steganalysis via Augmented Utilization of Selection-Channel Information
Shijun Zhou, Weixuan Tang 0004, Shunquan Tan, Bin Li 0011 |
IWDW | 3 |
| 2018 | Source camera model identification based on convolutional neural networks with local binary patterns coding
Bo Wang 0024, Jianfeng Yin, Shunquan Tan, Yabin Li, Ming Li 0011 |
Signal Process. Image Commun. | 3 |
| 2018 | ReST-Net: Diverse Activation Modules and Parallel Subnets-Based CNN for Spatial Image SteganalysisabstractRecent steganalytic schemes reveal embedding traces in a promising way by using convolutional neural networks (CNNs). However, further improvements, such as exploring complementary data processing operations and using wider structures, were not extensively studied so far. In this letter, we design a new CNN in these aspects in order to better capture embedding artifacts. Specifically, on the one hand, we propose to process information diversely with a module called diverse activation module. On the other hand, we build a wide structure with parallel subnets using several filter groups for preprocessing. To accelerate the training process, we pretrain the subnets independently. Extensive experiments show that the proposed method is effective in detecting content-adaptive steganographic schemes. Bin Li 0011, Weihang Wei, Anselmo Ferreira, Shunquan Tan |
IEEE Signal Process. Lett. | 4 |
| 2018 | New Steganalytic Features for Spatial Image Steganography Based on Derivative Filters and Threshold LBP OperatorabstractThe standard local binary pattern (LBP) operator shows its versatility in performing image classification-related tasks, including texture analysis, object recognition, and steganalysis. However, a conventional well-designed scheme utilizing LBP operator and histogram-based features does not have obvious advantage when compared with the well-known steganalytic scheme spatial rich model (SRM). In this paper, we propose an adapted LBP version, called threshold LBP (TLBP), to reveal the artifacts caused by data embedding. In the proposed steganalytic scheme, the TLBP operation is performed on residual images which are obtained by using a set of high-order derivative filters to capture intricate relationships among pixels. After performing TLBP operation, second order co-occurrence matrix features are formed and then processed with aggregation and non-linear mapping for boosting feature effectiveness. Experimental results show that the proposed TLBP features prevail over SRM features under various steganographic conditions. Bin Li 0011, Zhongpeng Li, Shijun Zhou, Shunquan Tan |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Large-Scale JPEG Image Steganalysis Using Hybrid Deep-Learning FrameworkabstractAdoption of deep learning in image steganalysis is still in its initial stage. In this paper, we propose a generic hybrid deep-learning framework for JPEG steganalysis incorporating the domain knowledge behind rich steganalytic models. Our proposed framework involves two main stages. The first stage is hand-crafted, corresponding to the convolution phase and the quantization and truncation phase of the rich models. The second stage is a compound deep-neural network containing multiple deep subnets, in which the model parameters are learned in the training procedure. We provided experimental evidence and theoretical reflections to argue that the introduction of threshold quantizers, though disabling the gradient-descent-based learning of the bottom convolution phase, is indeed cost-effective. We have conducted extensive experiments on a large-scale data set extracted from ImageNet. The primary data set used in our experiments contains 500 000 cover images, while our largest data set contains five million cover images. Our experiments show that the integration of quantization and truncation into deep-learning steganalyzers do boost the detection performance by a clear margin. Furthermore, we demonstrate that our framework is insensitive to JPEG blocking artifact alterations, and the learned model can be easily transferred to a different attacking target and even a different data set. These properties are of critical importance in practical applications. Jishen Zeng, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Automatic Steganographic Distortion Learning Using a Generative Adversarial NetworkabstractGenerative adversarial network has shown to effectively generate artificial samples indiscernible from their real counterparts with a united framework of two subnetworks competing against each other. In this letter, we first propose an automatic steganographic distortion learning framework using a generative adversarial network, which is composed of a steganographic generative subnetwork and a steganalytic discriminative subnetwork. Via alternately training these two oppositional subnetworks, our proposed framework can automatically learn embedding change probabilities for every pixel in a given spatial cover image. The learnt embedding change probabilities can then be converted to embedding distortions, which can be adopted in the existing framework of minimal-distortion embedding. Under this framework, the distortion function is directly related to the undetectability against the oppositional evolving steganalyzer. Experimental results show that with adversarial learning, our proposed framework can effectively evolve from nearly naive random ±1 embedding at the beginning to much more advanced content-adaptive embedding which tries to embed secret bits in textural regions. The security performance is also steadily improved with increasing training iterations. Weixuan Tang 0004, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Signal Process. Lett. | 2 |
| 2017 | Pixel-Decimation-Assisted Steganalysis of Synchronize-Embedding-Changes SteganographyabstractThis paper deals with the state-of-the-art synchronize-embedding-changes (SECs) steganography. We propose the pixel-decimation-assisted steganalytic feature set, a novel feature set construction protocol that extends upon the recent selection-channel-aware spatial rich model maxSRMd2. Our method is based on pixel decimation, a specific type of image downsampling. Based on theoretical analysis and empirical evaluation, we clearly demonstrate that our method impairs the synchronization of embedding changes in SEC steganography, and improves the accuracy of embedding change probability estimation. Our method significantly improves stego image detection performance when extended from a selection-channel-aware rich-model feature set (maxSRMd2) and is robust to different image downsampling methods. Furthermore, increasing the number of sweeps in SEC steganography has no effect to the performance of our proposed method even though it further strengthens synchronization of embedding changes. It is worth noting that with ensemble classifier, the above-mentioned performance improvements are achieved at a little extra cost. Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Automatic Detection of Object-Based Forgery in Advanced VideoabstractPassive multimedia forensics has become an active topic in recent years. However, less attention has been paid to video forensics. Research on video forensics, and especially on automatic detection of object-based video forgery, is still in its infancy. In this paper, we develop an approach for automatic identification and forged segment localization of object-based forged video encoded with advanced frameworks. The proposed approach starts with a frame manipulation detector. An automatic algorithm is proposed to identify object-based video forgery based on the frame manipulation detector. Then, a two-stage automatic algorithm is provided to accurately locate the forged video segments in the suspicious video. To construct the proposed frame manipulation detector, motion residuals are generated from the target video frame sequence. We regard the object-based forgery in video frames as image tampering in the motion residuals and employ the feature extractors that are originally built for still image steganalysis to extract forensic features from the motion residuals. The experiments show that the proposed approach achieves excellent results in both forged video identification and automatic forged temporal segment localization. Shengda Chen, Shunquan Tan, Bin Li 0011, Jiwu Huang |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2015 | Revealing the Trace of High-Quality JPEG Compression Through Quantization Noise AnalysisabstractTo identify whether an image has been JPEG compressed is an important issue in forensic practice. The state-of-the-art methods fail to identify high-quality compressed images, which are common on the Internet. In this paper, we provide a novel quantization noise-based solution to reveal the traces of JPEG compression. Based on the analysis of noises in multiple-cycle JPEG compression, we define a quantity called forward quantization noise. We analytically derive that a decompressed JPEG image has a lower variance of forward quantization noise than its uncompressed counterpart. With the conclusion, we develop a simple yet very effective detection algorithm to identify decompressed JPEG images. We show that our method outperforms the state-of-the-art methods by a large margin especially for high-quality compressed images through extensive experiments on various sources of images. We also demonstrate that the proposed method is robust to small image size and chroma subsampling. The proposed algorithm can be applied in some practical applications, such as Internet image classification and forgery detection. Bin Li 0011, Tian-Tsong Ng, Xiaolong Li 0001, Shunquan Tan, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | A Strategy of Clustering Modification Directions in Spatial Image SteganographyabstractMost of the recently proposed steganographic schemes are based on minimizing an additive distortion function defined as the sum of embedding costs for individual pixels. In such an approach, mutual embedding impacts are often ignored. In this paper, we present an approach that can exploit the interactions among embedding changes in order to reduce the risk of detection by steganalysis. It employs a novel strategy, called clustering modification directions (CMDs), based on the assumption that when embedding modifications in heavily textured regions are locally heading toward the same direction, the steganographic security might be improved. To implement the strategy, a cover image is decomposed into several subimages, in which message segments are embedded with well-known schemes using additive distortion functions. The costs of pixels are updated dynamically to take mutual embedding impacts into account. Specifically, when neighboring pixels are changed toward a positive/negative direction, the cost of the considered pixel is biased toward the same direction. Experimental results show that our proposed CMD strategy, incorporated into existing steganographic schemes, can effectively overcome the challenges posed by the modern steganalyzers with high-dimensional features. Bin Li 0011, Xiaolong Li 0001, Shunquan Tan, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | Statistical Model of JPEG Noises and Its Application in Quantization Step EstimationabstractIn this paper, we present a statistical analysis of JPEG noises, including the quantization noise and the rounding noise during a JPEG compression cycle. The JPEG noises in the first compression cycle have been well studied; however, so far less attention has been paid on the statistical model of JPEG noises in higher compression cycles. Our analysis reveals that the noise distributions in higher compression cycles are different from those in the first compression cycle, and they are dependent on the quantization parameters used between two successive cycles. To demonstrate the benefits from the analysis, we apply the statistical model in JPEG quantization step estimation. We construct a sufficient statistic by exploiting the derived noise distributions, and justify that the statistic has several special properties to reveal the ground-truth quantization step. Experimental results demonstrate that the proposed estimator can uncover JPEG compression history with a satisfactory performance. Bin Li 0011, Tian-Tsong Ng, Xiaolong Li 0001, Shunquan Tan, Jiwu Huang |
IEEE Trans. Image Process. | 4 |
| 2014 | Investigation on Cost Assignment in Spatial Image SteganographyabstractRelating the embedding cost in a distortion function to statistical detectability is an open vital problem in modern steganography. In this paper, we take one step forward by formulating the process of cost assignment into two phases: 1) determining a priority profile and 2) specifying a cost-value distribution. We analytically show that the cost-value distribution determines the change rate of cover elements. Furthermore, when the cost-values are specified to follow a uniform distribution, the change rate has a linear relation with the payload, which is a rare property for content-adaptive steganography. In addition, we propose some rules for ranking the priority profile for spatial images. Following such rules, we propose a five-step cost assignment scheme. Previous steganographic schemes, such as HUGO, WOW, S-UNIWARD, and MG, can be integrated into our scheme. Experimental results demonstrate that the proposed scheme is capable of better resisting steganalysis equipped with high-dimensional rich model features. Bin Li 0011, Shunquan Tan, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | Targeted steganalysis of adaptive pixel-value differencing steganographyabstractThe adaptive pixel-value differencing steganography proposed by Luo et al. is a state-of-the-art content-adaptive steganographic method which resists blind steganalytic attacks. In this paper, the authors point out that the combination of rotate operation and ternary embedding units in the adaptive pixel-value differencing steganography introduces intrinsic statistical imbalance which can be used to construct a targeted steganalytic algorithm. Experimental results reveal that the proposed method can obtain excellent results for detecting stego images even when the embedding rate is low. Shunquan Tan, Bin Li 0011 |
ICIP | 1 |
| 2012 | Targeted Steganalysis of Edge Adaptive Image Steganography Based on LSB Matching Revisited Using B-Spline FittingabstractIn this letter, the authors point out that the readjusting phase of edge adaptive image steganography based on LSB matching revisited introduces a pulse distortion to the long exponential tail of the histogram of the absolute difference of the pixel pairs. Making use of this observation, a targeted steganalytic method based on B-Spline fitting is proposed. Experimental results show that the proposed method obtains excellent results for detecting stego images with low embedding rate. The dominant performance of our method compared with state-of-the-art blind steganalyzers, such as SPAM and SRM is apparent. Furthermore, our method can accurately estimate the threshold used in the secret data embedding procedure and can separate the stego images with unit block size from those with block sizes greater than one. Shunquan Tan, Bin Li 0011 |
IEEE Signal Process. Lett. | 1 |
| 2011 | Steganalysis of LSB Matching Revisited for Consecutive Pixels Using B-Spline Functions
Shunquan Tan |
IWDW | 1 |
| 2007 | Effect of Different Coding Patterns on Compressed Frequency Domain Based Universal JPEG Steganalysis
Bin Li 0011, Fangjun Huang, Shunquan Tan, Jiwu Huang, Yun Q. Shi 0001 |
IWDW | 3 |
| 2007 | Steganalysis of Enhanced BPCS Steganography Using the Hilbert-Huang Transform Based Sequential Analysis
Shunquan Tan, Jiwu Huang, Yun Q. Shi 0001 |
IWDW | 1 |
| 2006 | Steganalysis of JPEG2000 Lazy-Mode Steganography using the Hilbert-Huang Transform Based Sequential AnalysisabstractIn this paper, we present a steganalytic method to attack JPEG2000 lazy-mode steganography proposed by Su et al. The key element of the method is the Hilbert-Huang transform based analysis of the code-block noise variance sequences of stego images and non-stego noisy images. The Hilbert transform based characteristic vectors are constructed via empirical mode decomposition of the sequences and the support vector machine classifier is used in classification. Experimental results have demonstrated effectiveness of the proposed steganalytic method. According to our best knowledge, this method is the first successful attack of JPEG2000 lazy-mode steganography. And furthermore, the proposed method takes first step towards the application of Hilbert-Huang transform in steganalysis and proves its great advantage. Shunquan Tan, Jiwu Huang, Zhihua Yang, Yun Q. Shi 0001 |
ICIP | 1 |