Hanzhou Wu

dblp:143/8193 · also Han-Zhou Wu · DBLP profile ↗
← Back
71ranked-venue papers
10as first author
53since 2021 · last 2026
0000-0002-1599-7232ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 30 · 7 first-author · 19 since 2021Security and privacy · 19 · 2 first-author · 13 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 6 since 2021Computer networks · 7 · 7 since 2021Databases, data management, data science and information retrieval · 6 · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CREF: Concept Response Fingerprints for Large Language Models
abstract
Protecting the intellectual property of Large Language Models (LLMs) is critical because training them requires massive computational resources and data. A key challenge is determining whether a suspicious model is derived from a specific base model after fine-tuning or structural modification. Existing fingerprinting methods rely on model weights or high-dimensional representations, leading to substantial storage overhead. We propose a non-intrusive fingerprinting framework Concept REsponse Fingerprints (CREF). Inspired by activation engineering, CREF constructs a set of concept activation vectors as semantic probes. It then measures the response strength of hidden representations along these concept activation vectors using shared inputs. The resulting concept response matrix serves as a compact fingerprint, and similarity between models is measured using centered kernel alignment. Experiments on multiple LLM families show that CREF reliably distinguishes derived models from independently trained models and remains robust to fine-tuning, pruning, parameter permutation, and scaling. Moreover, the fingerprint requires only kilobyte-level storage, making it practical for large-scale deployment and ownership verification.
Haiyong Tang, Hanzhou Wu, Gejian Zhao, Li Li 0103, Zhihua Xia, Xinpeng Zhang 0001
IH&MMSec2
2026 Robust Black-Box Fingerprinting for Large Language Models Against Composite Attacks via LLM Self-Evaluation and ArcFace
abstract
Existing black-box fingerprinting methods for large language models typically assume a single attack type, making them difficult to apply to realistic deployments involving multi-layer composite attacks. To address this limitation, this paper proposes a new black-box fingerprinting paradigm against composite attacks for commercial scenarios. For data construction, we design an LLM self-evaluation-based fingerprint probe selection mechanism. Candidate queries from multiple open-source datasets are fed into different base models, and a high-capability judge model is introduced to automatically assess output discrepancies across multiple dimensions, thereby selecting highly discriminative queries for constructing training and test sets. Methodologically, we reformulate black-box fingerprinting as a fine-grained identity authentication task. We employ a Transformer to model the semantic and logical features of question–answer sequences and incorporate ArcFace loss to impose angular-margin constraints. This compresses intra-class distributions of the same model under different attack conditions, enlarges inter-model decision boundaries, and learns more identity-invariant fingerprint representations. Furthermore, we systematically model and evaluate multi-layer composite attack chains composed of instruction tuning, quantization, distillation, RAG, and system prompts. Experimental results show that the proposed method significantly outperforms existing approaches under both single-layer and two-layer attack settings, and maintains over 61% Top-1 identification accuracy even in high-intensity three-layer composite attack scenarios.
Hongjie Zhang 0001, Hanzhou Wu
IH&MMSec3
2026 VulKnow: Enhancing Vulnerability Detection With Structured Knowledge and Large Language Models
abstract
The rapid proliferation of Internet-of-Things (IoT) systems has led to increasingly heterogeneous, resource-constrained, and security-sensitive software deployments. In this context, detecting vulnerabilities in embedded and system-level IoT code has become particularly critical, as even a single exploitable flaw may compromise entire networks or devices. Vulnerability detection in real-world software continues to pose significant challenges due to the intricate nature of program semantics, the diversity of vulnerability patterns, and the limited explainability offered by current machine learning models. Although Large Language Models (LLMs) have exhibited remarkable capabilities in comprehending and reasoning about source code, their effectiveness is frequently compromised by inadequate domain knowledge and instances of hallucinated outputs. To address these limitations, we propose VulKnow, a retrieval-augmented framework for vulnerability detection that harnesses structured vulnerability knowledge alongside multi-stage prompt-based reasoning. Specifically, VulKnow first constructs a structured knowledge base derived from authoritative sources such as CWE/CVE reports and standard library specifications. Sub-sequently, it conducts context-aware knowledge retrieval and integrates the retrieved items into an LLM-based initial filtering module. To ensure high-confidence and verifiable results, we design a multi-stage reasoning pipeline that progressively validates vulnerabilities through semantic prompts and consistency checks. Experiments conducted on multiple real-world datasets (Linux, Qemu, Big-Vul) demonstrate that VulKnow significantly enhances precision, recall, and explainability compared to existing static analysis tools as well as LLM-only baselines. This positions VulKnow as a reliable solution for practical vulnerability auditing scenarios.
Guixiang Liao, Yanli Chen 0001, Wei Ke 0003, Hanzhou Wu, Zhicheng Dong 0003
IEEE Internet Things J.4
2026 HSMNet: A multi-resolution grayscale image steganalysis method based on hybrid dilated convolution and self-attention multi-channel network
Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Guowei Shen, Hanzhou Wu
Inf. Sci.7
2026 SensMark: Robust and interpretable model watermarking via contextual sensitivity estimation and adaptive trigger insertion
Gejian Zhao, Hanzhou Wu, Bin Li 0011, Xinpeng Zhang 0001, Athanasios V. Vasilakos
Inf. Sci.2
2026 Dormant key: Unlocking universal adversarial control in text-to-image models
Jingqi Hu, Li Li 0103, Hanzhou Wu, Huixin Luo, Xinpeng Zhang 0001
Neural Networks3
2026 E2DE: An edge frequency domain coefficient prediction-based fast video dual-watermarking scheme for eliminating edge-discontinuity effects
Jianmu Wang, Guowei Shen, Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Zhenghui Liu, Hanzhou Wu
Signal Process.8
2026 Rotation, Scale, and Translation Resilient Black-Box Fingerprinting for Intellectual Property Protection of EaaS Models
abstract
Feature embedding has become a cornerstone technology for processing high-dimensional and complex data, which results in that Embedding as a Service (EaaS) models have been widely deployed in the cloud. To protect the intellectual property of EaaS models, existing methods apply digital watermarking to inject specific backdoor triggers into EaaS models by modifying training samples or network parameters. However, these methods inevitably produce detectable patterns through semantic analysis and exhibit susceptibility to geometric transformations including rotation, scaling, and translation (RST). To address this problem, we propose a novel fingerprinting framework called POSTER for EaaS models, rather than merely refining existing watermarking techniques. Different from watermarking, the proposed POSTER establishes EaaS model ownership through geometric analysis of embedding space's topological structure, rather than relying on the modified training samples or triggers. The key innovation lies in modeling the victim and suspicious embeddings as point clouds, allowing us to perform robust spatial alignment and similarity measurement, which inherently resists RST attacks. Experiments evaluated on visual and textual embedding tasks verify the superiority and applicability. This work reveals inherent characteristics of EaaS models and provides a promising solution for ownership verification of EaaS models under black-box scenarios.
Hongjie Zhang 0001, Zhiqi Zhao, Hanzhou Wu, Zhihua Xia, Athanasios V. Vasilakos
IEEE Trans. Dependable Secur. Comput.3
2026 ShadowCoT: Cognitive Hijacking for Stealthy Reasoning Backdoors in LLMs
abstract
Chain-of-Thought (CoT) enhances an LLM’s ability to perform complex reasoning tasks, but it also introduces new security issues. In this work, we present ShadowCoT, a novel backdoor attack framework that targets the internal reasoning mechanism of LLMs. Unlike prior token-level or prompt-based attacks, ShadowCoT directly manipulates the model’s cognitive reasoning path, enabling it to hijack multi-step reasoning chains and produce logically coherent but adversarial outcomes. By conditioning on internal reasoning states, ShadowCoT learns to recognize and selectively disrupt key reasoning steps, effectively mounting a self-reflective cognitive attack within the target model. Our approach introduces a lightweight yet effective multi-stage injection pipeline, which selectively rewires attention pathways and perturbs intermediate representations with minimal parameter overhead (only 0.15% updated). ShadowCoT further leverages reinforcement learning and reasoning chain pollution (RCP) to autonomously synthesize stealthy adversarial CoTs that remain undetectable to advanced defenses. Extensive experiments across diverse reasoning benchmarks and LLMs show that ShadowCoT consistently achieves a state-of-the-art average Attack Success Rate of 91.2% (peaking at 94.4%) and a Hijacking Success Rate of 84.9% while preserving benign performance. These results reveal an emergent class of cognition-level threats and highlight the urgent need for defenses beyond shallowsurface-levelconsistency.
Gejian Zhao, Hanzhou Wu, Xinpeng Zhang 0001, Athanasios V. Vasilakos
IEEE Trans. Inf. Forensics Secur.2
2025 A Plug-and-Play and Invisible Multi-Bit Watermarking Scheme for Deep Neural Networks
Jingyu Ye, Zhenjun Tang, Hanzhou Wu
ICIC (18)4
2025 Flexible Multi-view Clustering with Dynamic Views Generation
abstract
Multi-view clustering is one of the fundamental unsupervised multimedia analysis tasks. Recent studies have mainly focused on developing multi-view clustering approaches, which can achieve state-of-the-art clustering performance. However, most of the existing works just focus on multi-view clustering with fixed views, which lacks flexibility with guidance of the views dynamically generated. Besides, these works ignore to integrate generating views in a dynamic manner and learning the common representation shared by different views into a unified framework. To this end, we propose the Flexible Multi-view Clustering with Dynamic Views Generation (FMCDVG). Specifically, FMCDVG adopts the graph convolutional network and auto-encoder to dynamically generate the topological graph representation and node attribute representation as two different views, respectively. FMCDVG introduces the latent representation shared by different feature representations and integrates multiple feature representations based on node attributes and graph structure into the latent representation with reconstruction through reconstructed encoding networks (REN). FMCDVG jointly conducts generating views in a dynamic manner and learning the common representation shared by different views in a unified optimization framework. We demonstrate that FMCDVG is able to consistently achieve better clustering performance than the state-of-the-art methods through comprehensive experiments.
Yalan Qin, Nan Pu, Hanzhou Wu, Zhaoxin Fan
ACM Multimedia3
2025 Robust Text Watermarking Based on Modifying the Stroke Components of Chinese Characters
abstract
ABSTRACT Traditional codebooks used for tracing information leakage in text documents often suffer from limitations in embedding capacity, robustness, and efficiency due to their manual generation process. This paper proposes a robust text watermarking method based on the stroke components of Chinese characters. By designing an innovative approach, Chinese character strokes are divided into several distinct components, with only specific ones being selectively modified to generate new glyphs, thus forming a unique codebook. The watermark signals are embedded by substituting the carrier glyph with the newly generated one, and the signals are extracted using a template matching method. Experimental results demonstrate that, compared to traditional manually designed codebooks, the proposed method significantly reduces human labor and computational overhead while maintaining high visual quality. Moreover, it exhibits superior robustness and adaptability across various challenging scenarios, including digital noise attacks, print‐scanning attacks, and print‐camera capture, making it a highly effective solution for protecting textual information.
Hai Chen, Yanli Chen 0001, Zhicheng Dong 0003, Yongrong Wang, Asad Malik 0002, Hanzhou Wu
IET Image Process.6
2025 FareMark: Model-Watermark-Driven Free-Rider Detection in Federated Learning Model
abstract
Federated Learning (FL) is increasingly adopted in Internet of Things (IoT) ecosystems, where distributed devices collaboratively train machine learning models while preserving data privacy. Well-trained models have high commercial value. If stolen, it will severely harm the interests of the model owner. In FL, a free-rider client can avoid contributing data or computing resources by establishing a deceptive local model and illegally obtaining the valuable global model for free, undermining the central server’s interests. While existing model watermarking methods primarily concentrate on identifying deep learning model misuse, they fail to adequately tackle the issue of identifying free-riders. To address such an issue, this paper presents a box-free watermarking scheme that enables multiple clients who participated in the training to embed private watermarks within the jointly trained federated deep learning model, while the free rider cannot if he did not participate in the training. To avoid conflicts between different clients, each client selects a unique trigger class and embeds watermarks into the global model during the training process. Furthermore, we propose a memory-enhancing local updating strategy to effectively fuse different watermarks into the global model. The proposed method can assist the center in identifying free-rider clients while also safeguarding the FL model’s intellectual property rights. The efficiency of the embedded watermarks is validated by experiments conducted on different models, and the performance of the resilience across various training settings and the robustness against different watermark removal methods are also tested.
Li Li 0103, Xinpeng Zhang 0001, Hanzhou Wu, Guorui Feng, Weiming Zhang 0001
IEEE Internet Things J.3
2025 StegGuard: Secrets Encoder and Decoder Act as Fingerprint of Self-Supervised Pretrained Model
abstract
In this work, we propose StegGuard, a novel fingerprinting mechanism to verify the ownership of a suspect pretrained model using steganography, where the pre-trained model is obtained via self-supervised learning. A critical perspective in StegGuard is that the unique characteristic of the transformation from an image to an embedding, conducted by the pre-trained model, can be equivalently captured by how an encoder embeds secrets into images and how a decoder extracts them from the embeddings with tolerable error. While each independently trained pre-trained model has a distinct transformation, a piracy model exhibits a transformation similar to that of the victim. Based on these observations, StegGuard learns a pair of secrets encoder and decoder as the fingerprint of the victim model. Additionally, a frequency-domain channel attention embedding block is introduced into the encoder to adaptively embed secrets into suitable frequency bands. During verification, if the secrets embedded into the query images can be extracted with an acceptable error from the embeddings of the query images, the suspect model is determined to be piracy; otherwise, it is deemed independent. Extensive experiments demonstrate that with as few as 100 query images, StegGuard achieves high piracy detection accuracy and robustness against model stealing attacks including model extraction, fine-tuning, pruning, embedding noising and shuffle. Compared to existing methods, StegGuard consistently achieves lower p-values for piracy models (as low as 1e-14) and higher p-values for independent models (up to 0.99), confirming its effectiveness and reliability.
Xingdong Ren, Hanzhou Wu, Yinggui Wang, Guangling Sun
IEEE Internet Things J.2
2025 Robust watermarking for diffusion models based on STDM and latent space fine-tuning
Li Li 0103, Xinpeng Zhang 0001, Guorui Feng, Zichi Wang, Deyang Wu, Hanzhou Wu
J. Inf. Secur. Appl.6
2025 Automated localization and detection for robust image watermarking resistant to camera shooting
Yonghui Zhou, Bingbing Tan, Hanzhou Wu
J. Inf. Secur. Appl.6
2025 A multi-level additive distortion method for security improvement in palette image steganography
Yi Chen 0008, Hongxia Wang 0001, Yunhe Cui, Guowei Shen, Chun Guo 0004, Hanzhou Wu
J. Vis. Commun. Image Represent.7
2025 Robust copy-move detection and localization of digital audio based CFCC feature
Xiaojie Li 0001, Canghong Shi, Xianhua Niu, Ling Xiong, Hanzhou Wu, Qing Qian 0001
Multim. Tools Appl.6
2025 Margin-aware Noise-robust Contrastive Learning for Partially View-aligned Problem
abstract
In this article, we study a challenging problem in contrastive learning when just a portion of data is aligned in multi-view dataset due to temporal, spatial, or spatio-temporal asynchronism across views. It is important to study partially view-aligned data since this type of data is common in real-world application and easily leads to data inconsistency among different views. Such a Partially View-aligned Problem (PVP) in contrastive learning has been relatively less touched so far, especially in downstream tasks, i.e., classification and clustering. In order to solve this problem, we introduce a flexible margin and propose margin-aware noise-robust contrastive learning to simultaneously identify the within-category counterparts from the other view of one data point based on the established cross-view correspondence and learn a shared representation. To be specific, the proposed learning framework is built on a novel margin-aware noise-robust contrastive loss. Since data pairs are used as input for the proposed margin-aware noise-robust contrastive learning, we build positive pairs according to the known correspondences and negative pairs in the manner of random sampling. Our margin-aware noise-robust contrastive learning framework is able to effectively reduce or remove the impacts caused by the possible existing noise for the constructed pairs in a margin-aware manner, i.e., false negative pairs led by random sampling in PVP. We relax the proposed margin-aware noise-robust contrastive loss and then give a detailed mathematical analysis for the effectiveness of our loss. As an instantiation, we construct an example under the proposed margin-aware noise-robust contrastive learning framework for validation in this work. To the best of our knowledge, this is the first attempt of extending contrastive learning to a margin-aware noise-robust version for dealing with PVP. We also enrich the learning paradigm when there is noise in the data. Extensive experiments on different datasets demonstrate the promising performance of the proposed method in the classification and clustering tasks.
Yalan Qin, Nan Pu, Hanzhou Wu, Nicu Sebe
ACM Trans. Knowl. Discov. Data3
2025 Discriminative Anchor Learning for Efficient Multi-View Clustering
abstract
Multi-view clustering aims to study the complementary information across views and discover the underlying structure. For solving the relatively high computational cost for the existing approaches, works based on anchor have been presented recently. Even with acceptable clustering performance, these methods tend to map the original representation from multiple views into a fixed shared graph based on the original dataset. However, most studies ignore the discriminative property of the learned anchors, which ruin the representation capability of the built model. Moreover, the complementary information among anchors across views is neglected to be ensured by simply learning the shared anchor graph without considering the quality of view-specific anchors. In this paper, we propose discriminative anchor learning for multi-view clustering (DALMC) for handling the above issues. We learn discriminative view-specific feature representations according to the original dataset and build anchors from different views based on these representations, which increase the quality of the shared anchor graph. The discriminative feature learning and consensus anchor graph construction are integrated into a unified framework to improve each other for realizing the refinement. The optimal anchors from multiple views and the consensus anchor graph are learned with the orthogonal constraints. We give an iterative algorithm to deal with the formulated problem. Extensive experiments on different datasets show the effectiveness and efficiency of our method compared with other methods.
Yalan Qin, Nan Pu, Hanzhou Wu, Nicu Sebe
IEEE Trans. Multim.3
2024 Watermarking Text Documents With Watermarked Fonts
abstract
Watermarking text documents has become a cutting-edge research topic due to the increasing demand of protecting text documents from illegal copying, tampering, distribution and selling. When presenting a document on the computer screen, many existing text watermarking methods struggle in embedding large amounts of watermarks into documents invisibly to resist the most common screenshot attack. To deal with this problem, we present a screenshot resistant watermarking method for text documents based on font adaptive modification. In the proposed method, we generate a font variant to represent the watermark with high invisibility by adaptivly shifting the centroid of glyphs. The font variant is deemed watermarked and will be used for creating watermarked text documents. For watermark extraction, we exert a novel projection method with the support of semantic information to precisely segment glyphs in the document screenshot. The watermark is then recovered by analyzing the corresponding centroid shift of glyphs. Unlike the previous font-based watermarking method that alters the font of every glyph, we leave half of the glyphs with original font unchanged and use them to represent bit '0', which greatly improves the invisibility. Moreover, we achieve a high payload with one bit per glyph which outperforms the previous text document watermarking method. Experimental results evaluated on English and Chinese documents show that the proposed method is more robust and introduces less visual distortion than the previous method, which verify the superiority and applicability of our work.
Chenghua He, Deyang Wu, Xinpeng Zhang 0001, Hanzhou Wu
IH&MMSec4
2024 Suppressing High-Frequency Artifacts for Generative Model Watermarking by Anti-Aliasing
abstract
Protecting deep neural networks (DNNs) against intellectual property (IP) infringement has attracted an increasing attention in recent years. Recent advances focus on IP protection of generative models, which embed the watermark information into the image generated by the model to be protected. Although the generated marked image has good visual quality, it introduces noticeable artifacts to the marked image in high-frequency area, which severely impairs the imperceptibility of the watermark and thereby reduces the security of the watermarking system. To deal with this problem, we propose a novel framework for generative model watermarking that can suppress the high-frequency artifacts. The main idea is to design a new watermark embedding network that can suppress high-frequency artifacts by applying anti-aliasing. To realize anti-aliasing, we use low-pass filtering for the internal sampling layers of the new watermark embedding network. Meanwhile, joint loss optimization and adversarial training are applied to enhance the effectiveness and robustness. Experimental results indicate that the marked model not only maintains the performance very well on the original task, but also demonstrates better imperceptibility and robustness on the watermarking task. This work reveals the importance of suppressing high-frequency artifacts for enhancing imperceptibility and security of generative model watermarking.
Xinpeng Zhang 0001, Hanzhou Wu
IH&MMSec4
2024 Reducing High-Frequency Artifacts for Generative Model Watermarking via Wavelet Transform
abstract
As generative models find broader applications in Internet of Things (IoT) image processing tasks, safeguarding the copyright of these models assumes increasing significance. Embedding watermarks on the output images generated by such models has been proposed by some researchers as a means of protecting intellectual property. However, prevailing methods for generating model watermarks inadvertently introduce significant high-frequency artifacts in high-frequency regions, compromising the imperceptibility and security of the watermarking system. In pursuit of enhancing the imperceptibility of generative model watermarking, we propose a framework based on discrete wavelet transform. This framework effectively mitigates the high-frequency artifact issue and enhances the frequency-domain concealment of watermarking. Specifically, we introduce an embedded watermarking network, a frequency separation layer, and a watermark extraction network after the output of the target model. We construct a wavelet frequency domain separation layer by wavelet decomposition to decompose the image generated by the embedding network into different frequency components, and embed the watermark into the low-frequency region of the target model output image through joint training and joint loss optimization of the embedding and extraction networks. Extensive experiments conducted on two image processing tasks, i.e., painting transfer and de-raining, demonstrate that our method exhibits no discernible traces of high-frequency artifacts in the frequency domain of the image in both cases, thus boasting superior invisibility. Furthermore, our method demonstrates robustness against pre-processing attacks, such as noise addition, resizing, and image cropping.
Hanzhou Wu, Zichi Wang, Xinpeng Zhang 0001
IEEE Internet Things J.3
2024 Robust Blind Video Watermarking Based on Ring Tensor and BCH Coding
abstract
Video Internet of Things (IoT) is widely used in the fields of safe city, smart transportation, and logistics warehousing, which facilitates the acquisition of important environmental and semantic information. However, the tampering of unauthorized video data may seriously violate user privacy and even harm society. Although the existing video watermarking technology provides an effective solution for copyright protection, it still faces challenges to achieve robust copyright authentication in the complex IoT environment. In this article, a robust blind video watermarking based on ring Tensor and Bose-Chaudhuri–Hocquenghem (BCH) coding is proposed. First, ring sub-bands of different sizes are constructed in the spatial domain of the video, and the ring sub-bands of consecutive video frames are combined into a ring tensor for copyright watermark embedding. Second, to balance the imperceptibility and robustness of the copyright watermark, an adaptive BCH coding scheme is developed, which uses the modified differential entropy to calculate the video complexity and automatically selects the appropriate watermark coding parameters. Finally, a quaternary synchronization watermark embedding strategy is designed to solve the time synchronization destruction caused by video frame rate conversion. A synchronization ring is constructed within each video frame using the strong correlation between adjacent frames. When the video is subjected to temporal synchronization attacks, the synchronization watermark is extracted from the synchronization ring to restore the synchronization of the copyright watermark. Extensive experimental results demonstrate that the proposed scheme can effectively resist common video processing while exhibiting excellent robustness against video attacks in complex Internet environments.
Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu, Deyang Wu
IEEE Internet Things J.5
2024 Adaptive Robust Watermarking for Resisting Multiple Distortions in Real Scenes
abstract
An efficient and reliable digital watermarking scheme is needed in a complex network environment to solve image copyright disputes. However, most existing digital watermarking technologies can only resist common image processing and perform poorly against complex attacks. To this end, an adaptive robust watermarking for resisting multiple distortions in real scenes is proposed in this work. First, to reduce the impact of common attacks on the robustness of the algorithm, two-level stationary wavelet transform (SWT) is applied to extract low-frequency sub-band of host image, which is subsequently divided into nonoverlapping sub-blocks. Then, a circular sub-block method is designed for watermark embedding. Moreover, an improved Schur decomposition is proposed to control the variation range of eigenvalues. Meanwhile, an adaptive robust factor and embedding strength strategy are proposed to ensure image reconstruction in real number field, thereby balancing the invisibility and robustness of the watermark. Finally, the logistic encryption and repetition code are performed on the watermark to improve the security and error correction capabilities of the watermark. Extensive experiments demonstrate that the proposed scheme has higher performance than some representative watermarking schemes in complex combined attacks and real-world scenarios.
Deyang Wu, Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu
IEEE Internet Things J.6
2024 Effective Backdoor Attack on Graph Neural Networks in Spectral Domain
abstract
The susceptibility of graph neural networks (GNNs) to backdoor attacks poses a significant potential threat to GNN-based Internet of Things (IoT) systems. In such attacks, GNNs are manipulated to behave abnormally when presented with maliciously crafted samples known as trigger samples, which can be exploited by attackers for their malicious intent. To address this issue, this article studies the vulnerability of GNNs from the attacker’s angle by proposing a novel backdoor attack on GNNs. Our technical motivation is that most existing backdoor attacks only treat GNNs as black box and define trigger samples in the spatial domain, which lack deeper insights and further exploitation of GNNs, limiting the attacking effectiveness. Inspired by frequency-based backdoor attacks in vision domain and spectral graph theory, we propose an effective graph backdoor attack based on the spectral domain of graph data, which injects trigger signals into the frequency spectrum of normal attributed graphs. By injecting subtle trigger signal into the important frequency band of important node features, the learning of backdoor and clean data are entangled. As a result, it becomes hard for the defender to remove the backdoor without degrading the model’s normal performance, improving the robustness of the attack. Experiments on both homophilic graphs and heterophilic graphs, with commonly used GNN architectures show that our proposed method achieves high-attack success rate without significantly degrading the normal performance of the victim GNN. The attack is also shown to be robust against various processing toward graph data due to the entanglement strategy.
Hanzhou Wu, Xinpeng Zhang 0001
IEEE Internet Things J.2
2024 Transferable adversarial attack based on sensitive perturbation analysis in frequency domain
Zichi Wang, Hanzhou Wu, Xinpeng Zhang 0001
Inf. Sci.4
2024 Enhancing robustness in video data hiding against recompression with a wide parameter range
Yanli Chen 0001, Asad Malik 0002, Hongxia Wang 0001, Ben He 0004, Yonghui Zhou, Hanzhou Wu
J. Inf. Secur. Appl.6
2024 Automatic, Robust, and Blind Video Watermarking Resisting Camera Recording
abstract
As a secondary generation method, video recording will cause irreversible damage to the watermark within the video, which has always been challenging in video forensics. Although many video watermarking methods are reported in the literature, these methods, however, still cannot well resist camera recording. This has motivated the authors in this paper to introduce a new video watermarking method to resist camera recording. For the proposed method, two watermarks, i.e., copyright watermark and synchronization watermark, are embedded into the well-selected frequency domain coefficients. The synchronization watermark is used to ensure that the copyright watermark can be successfully extracted at the decoder side. To extract the copyright watermark without manual assistance, a neural network based segmentation model is applied to identify the watermarked video-playing region in the camera-recorded video. Meanwhile, automatic perspective correction is performed on the watermarked video-playing region so that the watermark information can be extracted accurately. The experiments show that the watermark data can be embedded into the raw video successfully and extracted from the camera-recorded video accurately by applying the proposed method. And, the proposed method significantly outperforms related works in terms of robustness in different scenarios, which has verified the superiority and applicability of the proposed method.
Lina Lin, Deyang Wu, Jiayan Wang, Yanli Chen 0001, Xinpeng Zhang 0001, Hanzhou Wu
IEEE Trans. Circuits Syst. Video Technol.6
2024 Robust and Imperceptible Black-Box DNN Watermarking Based on Fourier Perturbation Analysis and Frequency Sensitivity Clustering
abstract
Recently, more and more attention has been focused on the intellectual property protection of deep neural networks (DNNs), promoting DNN watermarking to become a hot research topic. Compared with embedding watermarks directly into DNN parameters, inserting trigger-set watermarks enables us to verify the ownership without knowing the internal details of the DNN, which is more suitable for application scenarios. The cost is we have to carefully craft the trigger samples. Mainstream methods construct the trigger samples by inserting a noticeable pattern to the clean samples in the spatial domain, which does not consider sample imperceptibility, sample robustness and model robustness, and therefore has limited the watermarking performance and the model generalization. It has motivated the authors in this paper to propose a novel DNN watermarking method based on Fourier perturbation analysis and frequency sensitivity clustering. First, we analyze the perturbation impact of different frequency components of the input sample on the task functionality of the DNN by applying random perturbation. Then, by K-means clustering, we determine the frequency components that result in superior watermarking performance for crafting the trigger samples. Our experiments show that the proposed work not only maintains the performance of the DNN on its original task, but also provides better watermarking performance compared with related works.
Hanzhou Wu, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Semantic-Preserving Linguistic Steganography by Pivot Translation and Semantic-Aware Bins Coding
abstract
Linguistic steganography (LS) aims to embed secret information into a highly encoded text for covert communication. It can be roughly divided to two main categories, i.e., modification based LS (MLS) and generation based LS (GLS). MLS embeds secret data by slightly modifying a given text without impairing the meaning of the text, whereas GLS uses a well trained language model to directly generate a text carrying secret data. A common disadvantage for MLS methods is that the embedding payload is very small, whose return is well preserving the semantic quality of the text. In contrast, GLS enables the data hider to embed a large payload, which has to pay the high price of uncontrollable semantics. In this article, we propose a novel LS method to modify a given text by pivoting it between two different languages and embed secret data using a semantic-aware information encoding strategy. Our purpose is to alter the expression of the given text, enabling a large payload to be embedded while keeping the semantic information unchanged. Experiments have shown that the proposed work not only achieves a large embedding payload, but also shows superior performance in maintaining the semantic consistency and resisting linguistic steganalysis.
Hanzhou Wu, Biao Yi, Guorui Feng, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Elastic Multi-View Subspace Clustering With Pairwise and High-Order Correlations
abstract
Multi-view clustering has become an important research topic in machine learning and computer vision communities, which aims at achieving a consensus partition of data points across different views. However, the existing multi-view clustering methods fail to simultaneously consider the pairwise and high-order correlations among different views in the process of obtaining the final results. In this paper, we propose the Elastic multi-view Subspace Clustering with pairwise and high-order Correlations (ESCC) to solve this problem. ESCC simultaneously explores the pairwise and high-order correlations among different views, resulting in a more comprehensive shared representation. ESCC formulates these two kinds of correlations into a unified objective framework, which are able to be jointly optimized to refine each other. As an instantiation, we construct an example of ESCC (e-ESCC) in this work. To be specific, e-ESCC uses the multi-layer neural networks to study the pairwise correlation from multiple views with the guidance of the latent representation. It is also able to help obtain the nonlinear subspaces of the multi-view data. e-ESCC collects multi-view similarity matrices into a tensor and utilizes the low-rank tensor norm to exploit the high-order correlation among different views. The augmented Lagrangian multiplier is adopted to solve the formulated problem of e-ESCC. Experiments on seven data sets validate the superiority of our method over 13 state-of-the-art multi-view clustering methods under six metrics.
Yalan Qin, Nan Pu, Hanzhou Wu
IEEE Trans. Knowl. Data Eng.3
2024 Flexible Tensor Learning for Multi-View Clustering With Markov Chain
abstract
Multi-view clustering has gained great progress recently, which employs the representations from different views for improving the final performance. In this paper, we focus on the problem of multi-view clustering based on the Markov chain by considering low-rank constraints. Since most existing methods fail to simultaneously characterize the relations among different entries in a tensor from the global perspective and describe local structures of similarity matrices of a tensor, we propose a novel Flexible Tensor Learning for Multi-view Clustering with the Markov chain (FTLMCM) to solve this problem. We also construct transition probability matrices based on the Markov chain to fully utilize the connection between the Markov chain and spectral clustering. Specifically, the low-rank constraints of the tensor, the frontal slices and the lateral slices of the tensor are imposed on the objective function of the proposed method to achieve these goals. Besides, these three constraints can be optimized jointly to achieve mutual refinement. FTLMCM also uses the tensor rotation to better explore the relationships among different views. We formulate FTLMCM as a problem of low-rank tensor recovery and solve it with the augmented Lagrangian multiplier. Experiments on six different benchmark data sets under six metrics demonstrate that the proposed method is able to achieve better clustering performance.
Yalan Qin, Zhenjun Tang, Hanzhou Wu, Guorui Feng
IEEE Trans. Knowl. Data Eng.3
2024 EDMC: Efficient Multi-View Clustering via Cluster and Instance Space Learning
abstract
Multi-view subspace clustering aims to cluster the data lying in a union of subspaces with low dimensions. The commonly used spectral clustering performs the final clustering based on an n×n affinity graph, which suffers from relative high time and space complexity. Some existing works have chosen key anchors with uniform sampling strategy orK-means for dealing with large-scale datasets. However, few of them pay attention to the physical meaning of cluster representation in the column of the dataset for learning informative anchors, which is independent from the instance representation. In this paper, we propose efficient dual multi-view clustering (EDMC) with relative low complexity. To be specific, EDMC makes full use of cluster representation space in the column of the dataset to help produce informative anchors, which has a clear physical meaning and is independent of instance representation in the row. It simultaneously explores the cluster and instance subspace representations to learn anchors for large-scale datasets. We perform anchor learning and efficient multi-view clustering in a unified framework and then adopt an alternative optimization strategy for solving the formulated problem. Extensive experiments performed on different datasets in terms of several metrics validate the superiority of the proposed method.
Yalan Qin, Nan Pu, Hanzhou Wu
IEEE Trans. Multim.3
2023 A novel model watermarking for protecting generative adversarial network
Yuyan Ma, Ning Zheng 0001, Hanzhou Wu, Yanli Chen 0002, Ming Xu 0001, Xiangyang Luo 0001
Comput. Secur.4
2023 Robust periodic blind watermarking based on sub-block mapping and block encryption
Jiayan Wang, Deyang Wu, Li Li 0103, Jing Zhao 0027, Hanzhou Wu
Expert Syst. Appl.5
2023 A novel watermarking framework for intellectual property protection of NLG APIs
Hanzhou Wu, Xinpeng Zhang 0001
Neurocomputing2
2023 Data hiding during image processing using capsule networks
Zichi Wang, Guorui Feng, Hanzhou Wu, Xinpeng Zhang 0001
Neurocomputing3
2023 A blockchain-based privacy-preserving auditable authentication scheme with hierarchical access control for mobile cloud computing
Ling Xiong, Fagen Li, Xianhua Niu, Hanzhou Wu
J. Syst. Archit.5
2023 Hiding data hiding
Hanzhou Wu, Gen Liu 0002, Xinpeng Zhang 0001
Pattern Recognit. Lett.1
2023 A Fast Method for Robust Video Watermarking Based on Zernike Moments
abstract
Watermarking by Zernike moments has been proven to be effective in providing high rotational resistance. However, due to the high computational complexity, the conventional video watermarking methods using Zernike moments are developed for videos with low resolution. Moreover, according to the properties of Zernike moments, only the matrices of equal height and width can be calculated since the inscribed circle of the original image matrix is selected as the area to be processed, but most of the available videos on the Internet do not meet such requirement. To solve the above problem, this paper proposes a fast watermarking method based on Zernike moments for high resolution videos to resist various attacks. In the proposed method, the frames of a video sequence are firstly grouped, from which a certain number of frame pairs are then selected for watermark embedding. For each frame pair to be embedded, we partition one frame into a set of disjoint blocks and apply singular value decomposition to each block to obtain a square feature matrix. Thereafter, by calculating all the Zernike moments, secret information is embedded into the selected Zernike moments to achieve superior robustness while keeping imperceptibility. Finally, according to the video encoding framework, we overwrite the frame difference of the frame pair by the watermark to resist compression and transcoding attacks. Furthermore, we propose two optional methods for compensating the special cases of rotation and scaling attacks during watermark detection. Experiments demonstrate the advantage of our method over the existing robust watermarking methods.
Shiyi Chen, Asad Malik 0002, Xinpeng Zhang 0001, Guorui Feng, Hanzhou Wu
IEEE Trans. Circuits Syst. Video Technol.5
2022 Exploiting Language Model For Efficient Linguistic Steganalysis
abstract
Recent advances in linguistic steganalysis have successively applied CNN, RNN, GNN and other efficient deep models for detecting secret information in generative texts. These methods tend to seek stronger feature extractors to achieve higher steganalysis effects. However, we have found through experiments that there actually exists significant difference between automatically generated stego texts and carrier texts in terms of the conditional probability distribution of individual words. Such kind of difference can be naturally captured by the language model used for generating stego texts. Through further experiments, we conclude that this ability can be transplanted to a text classifier by pre-training and fine-tuning to improve the detection performance. Motivated by this insight, we propose two methods for efficient linguistic steganalysis. One is to pre-train a language model based on RNN, and the other is to pre-train a sequence autoencoder. The results indicate that the two methods have different degrees of performance gain compared to the randomly initialized RNN, and the convergence speed is significantly accelerated. Moreover, our methods achieved the best performance compared to related works, while providing a solution for real-world scenario where there are more cover texts than stego texts.
Biao Yi, Hanzhou Wu, Guorui Feng, Xinpeng Zhang 0001
ICASSP2
2022 Graph Representation Learning for Spatial Image Steganalysis
abstract
In this article, we introduce a novel graph representation learning architecture for spatial image steganalysis, which was motivated by the reasonable assumption that steganographic modifications will inevitably distort the statistical characteristics of the latent graph features determined from the cover images. In the architecture, we translate each image to a graph, in which the nodes represent the patches of the image and the edges between nodes indicate the local relationships between the corresponding patches. Each graph node is then associated with a feature vector determined from the corresponding patch by a shallow convolutional neural network (CNN). By feeding the graph containing node features to an attention network, the discriminative features can be learned for efficient spatial steganalysis. The experiments indicate that the reported architecture in this paper achieves a competitive detection performance compared to the benchmark CNN, which demonstrates the potential of graph neural network for steganalysis and may inspire us to develop advanced works.
Qiyun Liu, Limengnan Zhou, Hanzhou Wu
MMSP3
2022 General Framework for Reversible Data Hiding in Texts Based on Masked Language Modeling
abstract
With the fast development of natural language processing, recent advances in information hiding focus on covertly embedding secret information into texts. These algorithms either modify a given cover text or directly generate a text containing secret information, which, however, are not reversible, meaning that the original text not carrying secret information cannot be perfectly recovered unless much side information are shared in advance. To tackle with this problem, in this paper, we propose a general framework to embed secret information into a given cover text, for which the embedded information and the original cover text can be perfectly retrieved from the marked text. The main idea of the proposed method is to use a masked language model to generate such a marked text that the cover text can be reconstructed by collecting the words of some positions and the words of the other positions can be processed to extract the secret information. Our results show that the original cover text and the secret information can be successfully embedded and extracted. Meanwhile, the marked text carrying secret information has good fluency and semantic quality, indicating that the proposed method has satisfactory security, which has been verified by experimental results. Furthermore, there is no need for the data hider and data receiver to share the language model, which significantly reduces the side information and thus has good potential in applications.
Xiaoyan Zheng, Yurun Fang, Hanzhou Wu
MMSP3
2022 Surveillance video anomaly detection via non-local U-Net frame prediction
Guorui Feng, Hanzhou Wu
Multim. Tools Appl.3
2022 Enforced block diagonal subspace clustering with closed form solution
Yalan Qin, Hanzhou Wu, Guorui Feng
Pattern Recognit.2
2022 ALiSa: Acrostic Linguistic Steganography Based on BERT and Gibbs Sampling
abstract
In this letter, we propose a novel linguistic steganographic method that directly conceals a token-level secret message in a seemingly-natural steganographic text generated by the off-the-shelf BERT model equipped with Gibbs sampling. Compared with all modification based linguistic steganographic methods, the proposed method does not modify a given cover text. Instead, the proposed method utilizes the secret message to directly generate the steganographic text. Compared with mainstream generation based linguistic steganographic methods, the proposed method enables the receiver to collect the tokens of the specific positions to directly constitute the secret message, without a complex decoding process and much side information shared between the sender and the receiver. Experimental results show that the proposed method can generate fluent, highly readable steganographic texts, while enjoying pretty good anti-steganalysis ability. This work has great application potential in real-time covert communication.
Biao Yi, Hanzhou Wu, Guorui Feng, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2022 Semi-Supervised Structured Subspace Learning for Multi-View Clustering
abstract
Multi-view clustering aims at simultaneously obtaining a consensus underlying subspace across multiple views and conducting clustering on the learned consensus subspace, which has gained a variety of interest in image processing. In this paper, we propose the Semi-supervised Structured Subspace Learning algorithm for clustering data points from Multiple sources (SSSL-M). We explicitly extend the traditional multi-view clustering with a semi-supervised manner and then build an anti-block-diagonal indicator matrix with small amount of supervisory information to pursue the block-diagonal structure of the shared affinity matrix. SSSL-M regularizes multiple view-specific affinity matrices into a shared affinity matrix based on reconstruction through a unified framework consisting of backward encoding networks and the self-expressive mapping. The shared affinity matrix is comprehensive and can flexibly encode complementary information from multiple view-specific affinity matrices. An enhanced structural consistency of affinity matrices from different views can be achieved and the intrinsic relationships among affinity matrices from multiple views can be effectively reflected in this manner. Technically, we formulate the proposed model as an optimization problem, which can be solved by an alternating optimization scheme. Experimental results over seven different benchmark datasets demonstrate that better clustering results can be obtained by our method compared with the state-of-the-art approaches.
Yalan Qin, Hanzhou Wu, Xinpeng Zhang 0001, Guorui Feng
IEEE Trans. Image Process.2
2021 Exploiting texture characteristics and spatial correlations for robustness metric of data hiding with noisy transmission
abstract
Abstract Data hiding aims to embed a secret message into a digital object such as image by slightly modifying the object content without arousing noticeable artefacts. The resultant object containing hidden information will be sent to a desired receiver via some insecure channels, e.g. images transmitted through noisy channel, social networks are vulnerable to unknown pollution or compression by a third party, which may lead the transmitted objects to be attacked such that the reconstructed message has a significant error rate. It therefore requires us to use robust embedding strategies for data hiding to realise reliable message retrieval. To this end, in this paper, a metric model to estimate the robustness of data hiding for noisy transmission based on the statistical characteristics of cover and embedding operation is presented, the former is mainly reflected by spatial frequency and texture feature, and the latter embedding operation is mainly reflected by embedding modification. The goal is to ensure that both statistical characteristics and embedding operation can be used to maximise the embedding robustness. To the best knowledge, it is the first time to estimate robustness before data hiding by a special metric model. Experimental results show that, by combining the proposed metric model in three classical data hiding methods, i.e. BPS, DE and QIM, the robustness can be significantly improved, which demonstrates its superiority and applicability.
Yanli Chen 0001, Hongxia Wang 0001, Hanzhou Wu, Yonghui Zhou, Limengnan Zhou, Yi Chen 0008
IET Image Process.3
2021 Structured subspace learning-induced symmetric nonnegative matrix factorization
Yalan Qin, Hanzhou Wu, Guorui Feng
Signal Process.2
2021 Linguistic Steganalysis With Graph Neural Networks
abstract
Recent linguistic steganalysis methods model texts as sequences and use deep learning models to extract discriminative features for detecting the presence of secret information in texts. However, natural language has a complex syntactic structure and sequences have limited representation ability for text modeling. Moreover, previous methods tend to extract features from local continuous word sequences, which cannot effectively model global characteristics. In this paper, we present a linguistic steganalysis method with graph neural network. In the proposed method, texts are translated as directed graphs with the associated information, where nodes denote words and edges show associations between the words. By training a graph convolutional network for feature extraction, each node of a graph can collect contextual information to update self-expression, accordingly effectively solving the problem of poor representation of polysemous words. Meanwhile, we adopt a globally-shared matrix to record correlation strengths between words so that each text can effectively utilize the global information to obtain the better self-representation. Experimental results have shown that the proposed work achieves the state-of-the-art performance comparing with the previous works.
Hanzhou Wu, Biao Yi, Feng Ding 0007, Guorui Feng, Xinpeng Zhang 0001
IEEE Signal Process. Lett.1
2021 Watermarking Neural Networks With Watermarked Images
abstract
Watermarking neural networks is a quite important means to protect the intellectual property (IP) of neural networks. In this paper, we introduce a novel digital watermarking framework suitable for deep neural networks that output images as the results, in which any image outputted from a watermarked neural network must contain a certain watermark. Here, the host neural network to be protected and a watermark-extraction network are trained together, so that, by optimizing a combined loss function, the trained neural network can accomplish the original task while embedding a watermark into the outputted images. This work is totally different from previous schemes carrying a watermark by network weights or classification labels of the trigger set. By detecting watermarks in the outputted images, this technique can be adopted to identify the ownership of the host network and find whether an image is generated from a certain neural network or not. We demonstrate that this technique is effective and robust on a variety of image processing tasks, including image colorization, super-resolution, image editing, semantic segmentation and so on.
Hanzhou Wu, Gen Liu 0002, Yuwei Yao, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.1
2021 Adaptive Video Data Hiding through Cost Assignment and STCs
abstract
With the increasing popularity of digital video communication, video data hiding has become an active research topic in covert communication and privacy protection. Traditional video data hiding methods often use quantized discrete cosine transform (QDCT) coefficients to carry a sufficient payload. However, since QDCT coefficients expose texture features and motion characteristics of the present video frame heavily, data embedding with QDCT coefficients may lead to significant intra-frame distortion and inter-frame distortion drift. To avoid obvious visual artifacts and keep bit-rate within a satisfactory level of the marked video, data embedding in QDCT coefficients should take into account both the intra-frame and inter-frame distortion impacts. It motivates the authors to propose an efficient cost assignment-based video data hiding method in this paper. The proposed cost assignment method aims to accurately evaluate the data embedding distortion. Specifically, the proposed scheme considers intra-frame changes and intra-frame distortion drift, for which the texture and motion changes of frames can be measured. The frame position is also used to reflect a cumulative distortion difference of multiple frames. For data embedding, syndrome-trellis code (STC) is adopted to minimize the overall distortion. Experimental results show that the proposed method significantly outperforms existing works in terms of payload-distortion performance.
Yanli Chen 0001, Hongxia Wang 0001, Hanzhou Wu, Zhiqiang Wu 0001, Tao Li 0016, Asad Malik 0002
IEEE Trans. Dependable Secur. Comput.3
2020 Patch-Level Selection and Breadth-First Prediction Strategy for Reversible Data Hiding
abstract
A core work in reversible data hiding is designing an embedding method enabling the hider to take advantages of smooth elements as many as possible while the detection procedure for marked elements is invertible to the receiver. It motivates us to introduce a novel patch-level selection and breadth-first prediction strategy for efficient reversible data hiding. However, different from conventional works, the proposed work allows us to preferentially and simultaneously use adjacent smooth elements as many as possible. Experiments show that it significantly outperforms a part of state-of-the-arts at relatively low embedding rates, demonstrating the superiority.
Hanzhou Wu
ICASSP1
2020 Towards Criminal Sketching with Generative Adversarial Network
abstract
Criminal sketching aims to draw an approximation portrait of the criminal suspect by details of the criminal suspect that the observer can remember. However, even for a professional artist, it would need much time to complete sketching and draw a good portrait. It therefore motivates us to study forensic sketching with a generative adversarial network based architecture, which allows us to synthesize a real-like portrait of the criminal suspect described by an eyewitness. The proposed work contains two steps: sketch generation and portrait generation. For the former, a facial outline is sketched based on the descriptive details. For the latter, the facial details are completed to generate a portrait. To make the portrait more realistic, we use a portrait discriminator, which can not only learn the discriminative features between the faces synthesized by the generator and the real faces, but also recognize the face attributes. Experiments have shown that this work achieves promising performance for criminal sketching.
Hanzhou Wu, Yuwei Yao, Xinpeng Zhang 0001, Jiangfeng Wang
MMSP1
2020 A passive forensic scheme for copy-move forgery based on superpixel segmentation and K-means clustering
Hongxia Wang 0001, Yi Chen 0008, Hanzhou Wu, Huan Wang 0010
Multim. Tools Appl.4
2020 Adaptive video data hiding with low bit-rate growth based on texture selection and ternary syndrome-trellis coding
Hanzhou Wu, Xinpeng Zhang 0001
Multim. Tools Appl.2
2020 METEOR: Measurable Energy Map Toward the Estimation of Resampling Rate via a Convolutional Neural Network
abstract
In recent years, with the improvements in machine learning, image forensics has made considerable progress in detecting editing manipulations. This progress also raises more questions in image forensics research, such as can the parameters applied in a manipulation be estimated. Many parameter estimation works have already been performed. However, most of these works are based on mathematical analyses. In this paper, we attempt to solve a particular parameter estimation problem from a different aspect. Specifically, a new convolutional neural network (CNN) model is proposed to estimate the resampling rate for resampled images regardless of whether the image is upscaled or downscaled. This model features an original layer to generate a measurable energy map toward the estimation of resampling rate (METEOR). The METEOR layer is demonstrated to be an outstanding method that can assist in enhancing the estimation performance of the CNN. Furthermore, the METEOR layer can also increase the robustness of the CNN against JPEG compression, which makes it extremely important in realistic application scenarios. Our work has verified that machine learning, particularly CNNs, with proper optimization can also be refined to adapt to parameter estimation in digital forensics with excellent performance and robustness.
Feng Ding 0007, Hanzhou Wu, Guopu Zhu, Yun Q. Shi 0001
IEEE Trans. Circuits Syst. Video Technol.2
2019 Ensemble Steganalysis Based on Deep Residual Network
Qiangjie Li, Guorui Feng, Hanzhou Wu, Xinpeng Zhang 0001
IWDW3
2019 Broadcasting Steganography in the Blockchain
Mengtian Xu, Hanzhou Wu, Guorui Feng, Xinpeng Zhang 0001, Feng Ding 0007
IWDW2
2019 Reversible data hiding in homomorphically encrypted image using interpolation technique
Asad Malik 0002, Hongxia Wang 0001, Tailong Chen, Tianlong Yang, Ahmad Neyaz Khan, Hanzhou Wu, Yanli Chen 0001
J. Inf. Secur. Appl.6
2019 Reversible video data hiding using zero QDCT coefficient-pairs
Yi Chen 0008, Hongxia Wang 0001, Hanzhou Wu
Multim. Tools Appl.3
2018 Ensemble Reversible Data Hiding
abstract
The conventional reversible data hiding (RDH) algorithms often consider the host as a whole to embed a secret payload. In order to achieve satisfactory rate-distortion performance, the secret bits are embedded into the noise-like component of the host such as prediction errors. From the rate-distortion optimization view, it may be not optimal since the data embedding units use the identical parameters. This motivates us to present a segmented data embedding strategy for efficient RDH in this paper, in which the raw host could be partitioned into multiple subhosts such that each one can freely optimize and use the data embedding parameters. Moreover, it enables us to apply different RDH algorithms within different subhosts, which is defined as ensemble. Notice that, the ensemble defined here is different from that in machine learning. Accordingly, the conventional operation corresponds to a special case of the proposed work. Since it is a general strategy, we combine some state-of-the-art algorithms to construct a new system using the proposed embedding strategy to evaluate the rate-distortion performance. Experimental results have shown that, the ensemble RDH system could outperform the original versions in most cases, which has shown the superiority and applicability.
Hanzhou Wu, Wei Wang 0025, Jing Dong 0003, Hongxia Wang 0001
ICPR1
2018 An adaptive data hiding algorithm with low bitrate growth for H.264/AVC video stream
Yi Chen 0008, Hongxia Wang 0001, Hanzhou Wu
Multim. Tools Appl.3
2018 An efficient fingerprint identification algorithm based on minutiae and invariant moment
Jing Sang, Hongxia Wang 0001, Qing Qian 0001, Hanzhou Wu, Yi Chen 0008
Pers. Ubiquitous Comput.4
2017 Separable Reversible Data Hiding for Encrypted Palette Images With Color Partitioning and Flipping Verification
abstract
Reversible data hiding (RDH) into encrypted images is of increasing attention to researchers as the original content can be perfectly reconstructed after the embedded data are extracted while the content owner's privacy remains protected. The existing RDH techniques are designed for grayscale images and, therefore, cannot be directly applied to palette images. Since the pixel values in a palette image are not the actual color values, but rather the color indexes, RDH in encrypted palette images is more challenging than that designed for normal image formats. To the best knowledge of the authors, there is no suitable RDH scheme designed for encrypted palette images that has been reported, while palette images have been widely utilized. This has motivated us to design a reliable RDH scheme for encrypted palette images. The proposed method adopts a color partitioning method to use the palette colors to construct a certain number of embeddable color triples, whose indexes are self-embedded into the encrypted image so that a data hider can collect the usable color triples to embed the secret data. For a receiver, the embedded color triples can be determined by verifying a self-embedded check code that enables the receiver to retrieve the embedded data only with the data hiding key. Using the encryption key, the receiver can roughly reconstruct the image content. Experiments have shown that our proposed method has the property that the presented data extraction and image recovery are separable and reversible. Compared with the state-of-the-art works, our proposed method can provide a relatively high data-embedding payload, maintain high peak signal-to-noise ratio values of the decrypted and marked images, and have a low computational complexity.
Hanzhou Wu, Yun Q. Shi 0001, Hongxia Wang 0001, Linna Zhou
IEEE Trans. Circuits Syst. Video Technol.1
2016 PPE-Based Reversible Data Hiding
abstract
We propose to utilize the prediction-error of prediction error (PPE) of a pixel to reversibly carry the secret data in this letter. In the proposed method, the pixels to be embedded are firstly predicted with their neighboring pixels to obtain the prediction errors (PEs). By exploiting the PEs of the neighboring pixels, the prediction of the PEs of the pixels to be embedded can be then determined. And, a sorting technique based on the local complexity of a pixel is used to collect the PPEs to generate an ordered PPE sequence so that, smaller PPEs will be processed first for data embedding. By reversibly shifting the PPE histogram (PPEH) with optimized parameters, the pixels corresponding to the altered PPEH bins can be finally modified to carry the entire secret data. Experimental results have implied that, the proposed algorithm can benefit from the prediction procedure, sorting technique as well as parameters selection, and therefore outperform some state-of-the-art works in terms of payload-distortion performance.
Hanzhou Wu, Hongxia Wang 0001, Yun Q. Shi 0001
IH&MMSec1
2016 Ensemble of CNNs for Steganalysis: An Empirical Study
abstract
There has been growing interest in using convolutional neural networks (CNNs) in the fields of image forensics and steganalysis, and some promising results have been reported recently. These works mainly focus on the architectural design of CNNs, usually, a single CNN model is trained and then tested in experiments. It is known that, neural networks, including CNNs, are suitable to form ensembles. From this perspective, in this paper, we employ CNNs as base learners and test several different ensemble strategies. In our study, at first, a recently proposed CNN architecture is adopted to build a group of CNNs, each of them is trained on a random subsample of the training dataset. The output probabilities, or some intermediate feature representations, of each CNN, are then extracted from the original data and pooled together to form new features ready for the second level of classification. To make best use of the trained CNN models, we manage to partially recover the lost information due to spatial subsampling in the pooling layers when forming feature vectors. Performance of the ensemble methods are evaluated on BOSSbase by detecting S-UNIWARD at 0.4 bpp embedding rate. Results have indicated that both the recovery of the lost information, and learning from intermediate representation in CNNs instead of output probabilities, have led to performance improvement.
Guanshuo Xu, Hanzhou Wu, Yun Q. Shi 0001
IH&MMSec2
2016 Structural Design of Convolutional Neural Networks for Steganalysis
abstract
Recent studies have indicated that the architectures of convolutional neural networks (CNNs) tailored for computer vision may not be best suited to image steganalysis. In this letter, we report a CNN architecture that takes into account knowledge of steganalysis. In the detailed architecture, we take absolute values of elements in the feature maps generated from the first convolutional layer to facilitate and improve statistical modeling in the subsequent layers; to prevent overfitting, we constrain the range of data values with the saturation regions of hyperbolic tangent (TanH) at early stages of the networks and reduce the strength of modeling using 1×1 convolutions in deeper layers. Although it learns from only one type of noise residual, the proposed CNN is competitive in terms of detection performance compared with the SRM with ensemble classifiers on the BOSSbase for detecting S-UNIWARD and HILL. The results have implied that well-designed CNNs have the potential to provide a better detection performance in the future.
Guanshuo Xu, Hanzhou Wu, Yun Q. Shi 0001
IEEE Signal Process. Lett.2
2015 Multi-layer assignment steganography using graph-theoretic approach
Hanzhou Wu, Hongxia Wang 0001, Xiuying Yu
Multim. Tools Appl.1
2014 Efficient Reversible Data Hiding Based on Prefix Matching and Directed LSB Embedding
Hanzhou Wu, Hongxia Wang 0001, Linna Zhou
IWDW1