Zichi Wang

dblp:168/4612 · DBLP profile ↗
← Back
55ranked-venue papers
9as first author
47since 2021 · last 2026
0000-0003-0283-5338ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 31 · 4 first-author · 26 since 2021Security and privacy · 11 · 3 first-author · 9 since 2021Computer networks · 8 · 7 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Steganalysis of neural networks using implicit features
abstract
Abstract Deep neural networks are used increasingly in daily life. Many models contain redundant parameters that render them susceptible to being exploited for transmitting secret data, thereby injecting malware or stealing sensitive data. Research on steganographic schemes for neural networks is therefore necessary. Existing steganalysis methods often require access to network parameters, while black-box approaches achieve limited accuracy. In this work, we propose a black-box steganalysis scheme that feeds a fixed sequence of images into the target network to extract implicit features, which are then used to train a steganalysis network. This is a black-box steganalysis framework without access to internal network parameter, leveraging output probabilities from fixed image sequences to capture model behavior and enabling steganography detection across diverse network architectures. Experiments show that our method improves accuracy by 6–39.65% compared to existing steganalysis schemes.
Jiaming Cao, Zichi Wang, Yunlong Hao, Xinpeng Zhang 0001
Cybersecur.2
2026 Robust Image Steganography in Real Social Networks Using Stable Diffusion
Linghui Long, Zichi Wang, Xinpeng Zhang 0001
IEEE Internet Things J.2
2026 Image-to-Image Steganography based on multimodal generative model
Jingyuan Jiang, Zichi Wang, Xinpeng Zhang 0001
Signal Process.2
2026 Cover Selection Method for JPEG Steganography
Xiyan Bi, Zichi Wang, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.2
2026 Model Steganography During Model Compression
abstract
Recently, many compressed neural network models have been implemented on embedded platforms. However, there is still a lack of steganographic methods that utilizes these compressed models for covert communication. In this paper, we propose a steganographic method during the model compression process, embedding secret data into the model to create a steganographic network, which applies to most model compression methods, such as model quantization, model pruning, and model distillation. The secret data receiver can extract the secret data using a corresponding extraction network, while ordinary users remain unaware of the existence of the secret data, thereby preventing suspicion. The extraction network is utilized concurrently with model compression to embed secret data, minimizing the impact of data embedding. Experimental results validate the effectiveness of the steganographic network in terms of size reduction, inference time reduction, and high accuracy, and the effectiveness in terms of capacity, security, and robustness for steganography. To enhance understanding of our work, we have uploaded a set of application instances embedding abstract content tohttps://github.com/timedeadline/Model_Steganography_during_Model_Compression.
Yunlong Hao, Zichi Wang, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2026 BARStega: A Burn After Reading Steganography Model Based on Latent Diffusion Model
abstract
We present 'Burn After Reading' - an innovative data protection mechanism featuring self-destructive capability - and integrate it into the steganography model, thus establishing the Burn After Reading Steganography Model (BARStega), a new architectural paradigm for secret data steganography. The concept of 'Burn After Reading' was first introduced into steganography research, it can be characterized as a self-destructive steganography protocol in which the stego image becomes invalidated after the initial data extraction operation, thus preventing subsequent attempts at secret data extraction. Our BARStega model ensures persistent protection of preexisting secret data, even in scenarios where the receiver's model is stolen by adversary. Through systematic optimization of the Stable Diffusion architecture for steganography requirements, our BARStega model enables both high controllability and high visual quality in stego image generation. Experimental results demonstrate that the proposed BARStega effectively facilitates the functionality of 'Burn After Reading'. Moreover, the model demonstrates competitiveness in both the accuracy of secret data extraction and security.
Jingyuan Jiang, Zichi Wang, Xinpeng Zhang 0001
IEEE Trans. Image Process.2
2026 Low-Distortion Steganography in Neural Networks
abstract
In steganography, the cover medium takes on various types, including images, videos. Due to the advent of deep learning, neural network models are increasingly employed as the cover medium. In existing approaches, the embedding of secret data results in an obvious degradation of the model's original task performance, such as image classification. This paper proposes a low-distortion steganography method that embeds secret data into neural network models without degrading the model's original performance. The method selectively modifies parameters with minimal correlation to the loss function, ensuring that the model's performance remains unaffected. Furthermore, a suitable modification amplitude is defined to minimize the impact on task performance. Experimental results demonstrate that the proposed method enables low-distortion steganography while significantly improving embedding capacity and security. Notably, a maximum of 3.25 M bits of secret data is successfully embedded into a VGG model on the MNIST dataset, resulting in less than 0.1% accuracy degradation, a significant improvement over previous methods.
Yunfei Xie, Zichi Wang
IEEE Trans. Multim.2
2026 Improving the Transferability of Adversarial Examples Through Spatial-Based Color Modification
abstract
Unrestricted adversarial attacks that modify the attributes or content of images have demonstrated significant potential. Among unrestricted adversarial attacks, color modification attacks that targeting image color have increasingly obtained attention from researchers. By perturbing the color information of images, color modification attacks can be more imperceptible to human vision compared with traditional adversarial perturbations constrained by$ L_{p}$-norm. Furthermore, the alteration of image attributes significantly disrupts the low-level features extracted by Deep Neural Networks (DNNs), effectively enhancing the transferability. However, current work focus solely on global image attributes, which limit the attack effectiveness. Therefore, this paper proposes Local-Global-Local (LGL), a novel color modification attack framework that incorporates spatial and color information of the image. The color distribution of the image is initialized at first, and then the color filter and spatial masks are used to adjust the global and local color distribution in more detail. Experimental results show that the proposed method achieves superior performance in terms of adversariality and transferability, while also demonstrating robustness against defense methods.
Zichi Wang, Xinpeng Zhang 0001, Guorui Feng
IEEE Trans. Multim.2
2025 On improving steganalysis against cover selection steganography
abstract
Abstract There are many cover selection methods currently in use within steganography to ensure that secret data embedded in digital images is hard to detect. This paper proposes an improved steganalytic method to enhance the detection accuracy on steganography in digital images by considering image texture complexity. We propose a measurement of image texture complexity based on gray level co-occurrence matrix-based (GLCM) multi-scale fusion, which is integrated into the classifier’s detection process. Our method refines the traditional classification process by exponentiating the probability of an image being voted “clear” with its calculated complexity value and comparing this value to the probability of it being voted “stego”. Images with higher texture complexity are more likely to be identified as containing secret data. Experimental results show that our method can effectively increase detection accuracy of steganalysis when cover selection is employed in steganography.
Haiteng Cao, Zichi Wang, Xinpeng Zhang 0001
Cybersecur.2
2025 General Steganography for Neural Network Models Based on Graph Convolutional Network
abstract
In this article, our idea is to propose a general steganographic framework for neural network models, embedding secret data during the network training process to obtain a stego network for covert communication. A novelty of this method is that it can be applied to various types of neural networks, such as neural networks that perform image classification, image segmentation, image generation, and language generation tasks. Additionally, our method enables data embedding in different layers of neural networks, including linear layers, convolutional layers, and transpose convolutional layers. In cover networks, the hidden layer is transformed into a graph structure to facilitate data embedding using graph convolutional networks (GCNs). Another novelty is that the parameters of the GCN can be randomly initialized or directly specified. The connectivity of the graph structure is predetermined collaboratively by the sender and receiver, eliminating the need to transmit the GCN parameters and graph connectivity. Using our framework, embedding and extraction of secret data can be successfully applied to different layers of the stego network. Experimental results demonstrate that the proposed method offers higher security at the same capacity and exhibits sufficient robustness. To enhance understanding of our work, we have uploaded a set of application instances embedding abstract content tohttps://github.com/timedeadline/ApplicationInstance.
Yunlong Hao, Zichi Wang, Jiaming Cao, Xinpeng Zhang 0001
IEEE Internet Things J.2
2025 Robust watermarking for diffusion models based on STDM and latent space fine-tuning
Li Li 0103, Xinpeng Zhang 0001, Guorui Feng, Zichi Wang, Deyang Wu, Hanzhou Wu
J. Inf. Secur. Appl.4
2025 Lossless steganographic network via model arithmetic operations
Yao Fan, Fuqiang Di, Minqing Zhang, Zichi Wang, Jia Liu 0016
Neural Networks4
2025 Protecting copyright of stable diffusion models from ambiguity attacks
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
Signal Process.3
2025 A Burn After Reading Data Hiding Framework
abstract
We propose a novel data hiding framework based on a multimodal generative model, named Burn After Reading Data Hiding (BarDH). Unlike previous related work in the field of data hiding, our proposed BarDH introduces a novel function: once the receiver extracts the secret data, the secret data cannot be extracted again. We have named this function as ‘Burn After Reading’. The concept of ‘Burn After Reading’ was first introduced into data hiding research. We believe that this mechanism constitutes a highly effective means of safeguarding secret data, such as in scenarios where the receiver's device has been hacked or stolen. Our proposed BarDH model enhances the multimodal generative model, Latent Diffusion Models (LDMs), better aligning it with data hiding tasks and requirements. Experimental results demonstrate that the proposed BarDH framework effectively facilitates the functionality of ‘Burn After Reading’. Simultaneously, the framework demonstrates competitiveness in both the accuracy of secret data extraction and security.
Jingyuan Jiang, Zichi Wang, Guanghui He 0003, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2025 Defending Against Adversarial Attack Through Generative Adversarial Networks
abstract
Deep neural networks are increasingly used in image processing tasks. However, deep learning models often show vulnerability when facing adversarial attacks. Active defense is an important method to deal with adversarial attacks in image identification. This letter proposes an active defense strategy for Generative Adversarial Networks (GAN) against adversarial attacks. The proposed method is that when the target network has been trained and remains unchanged, the perturbation generated by the generator is added to the original image and then input to the target network, which has little effect on the performance of the target network and can resist adversarial attacks well. The experimental results of implementing five adversarial attacks on three target network models based on the dataset MNIST and two target network models based on CIFAR10 and comparing them with two defense methods show that our method has achieved good performance in defense effect.
Haoxian Song, Zichi Wang, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2025 Untraceable Steganography: Towards the Anonymity of Steganographer
abstract
To protect sender's identity of covert communication, this paper proposes a new concept of steganography called untraceable steganography. The receiver can extract secret data from stego media without knowing who was the sender. Specifically, the stego media is produced by a number of individuals (including the sender and other normal individuals). Thus, the receiver cannot know who was the sender, since the media produced by the sender is only a part of stego media and the receiver cannot find the part produced by the sender from stego media. Therefore, the sender is anonymous during the whole process of steganography. That means this kind of steganography is untraceable. In this case, the sender's identity can be protected, and thus the security of steganography can be advanced in a higher level. A specific untraceable steganography scheme is designed in this paper for digital images, which achieves the function of untraceable steganography without decrease the undetectability of stego media.
Zichi Wang, Xinpeng Zhang 0001
IEEE Signal Process. Lett.1
2025 Watermark Removal Attack Against Text-to-Image Generative Model Watermarking
abstract
The artist's style can be quickly imitated by fine-tuning a text-to-image model using artist's artworks, which raises serious copyright concerns. Scholars have proposed many watermarking methods to protect the artists' copyright. To evaluate the security and enhance the performance of existing watermarking, this paper proposes a watermark removal attack for text-to-image generative model watermarking for the first time. This attack aims to invalidate watermarking designed to detect art theft mimicry in text-to-image models. In this method, a watermark recognition network and a watermark removal network are designed. The watermark recognition network identifies whether an artwork contains watermark, and the watermark removal network is used to remove it. Consequently, text-to-image models fine-tuned with watermark-removed artworks can reproduce an artist's style while evading watermark detection. This makes the copyright authentication of artworks ineffective. Experiments show that the proposed attack can effectively remove watermarks, with watermark extraction accuracy dropping below 48.64%. Additionally, the images after watermark removal retain high similarity to the original images, with PSNR exceeding 27.96 and SSIM exceeding 0.92.
Zihan Yuan, Li Li 0103, Zichi Wang, Jingyuan Jiang, Xinpeng Zhang 0001
IEEE Signal Process. Lett.3
2025 Generative Image Steganography Based on Text-to-Image Multimodal Generative Model
abstract
Image steganography, the technique of hiding secret messages within images, has recently advanced with generative image steganography, which hides messages during image creation. However, current generative steganography methods often face criticism for their low extraction accuracy and poor robustness—particularly their vulnerability to JPEG compression. To address these challenges, we propose a novel generative image steganography method based on the text-to-image multimodal generative model (StegaMGM). StegaMGM utilizes the initial random normalization distribution in the generative process of latent diffusion models (LDMs), the secret message is hidden in the generated image through message sampling, ensuring it follows the same probability distribution as typical image generative. The content of the stego image can also be controlled through the prompts. On the receiver side, using the shared prompt and diffusion inversion, can extract secret message with high accuracy. In the experimental section, we conducted detailed experiments to demonstrate the advantages of our proposed StegaMGM framework in extraction accuracy, resistance to JPEG compression, and security.
Jingyuan Jiang, Zichi Wang, Zihan Yuan, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.2
2025 Black-Box Steganography for Large Language Models
abstract
In recent years, the rapid development of deep learning has brought new opportunities for steganography. However, the current advanced white-box model steganography methods are not suitable for large language models. Since the parameter scale and complexity of large language models are far beyond that of ordinary models, retraining them to hide secret data is extremely challenging. Moreover, the cover parameters or structures of the embedded data are vulnerable to detection by attackers. To enhance practicality, we propose a black-box steganographic scheme for large language models, which embeds secret data into the third-party pre-trained large language models using backdoor techniques without knowing the internal complex structure and parameters of the large language models. Specifically, the sender first encodes the secret data into trigger labels and then uses a certain proportion of trigger samples and clean samples to fine-tune the third-party large language model to embed the secret data without significantly reducing the model performance. The receiver uses trigger samples to extract the secret data by interacting with the large language model, thereby achieving covert communication of the secret data. Experiments demonstrate the effectiveness of the proposed scheme in terms of embedding capacity, robustness, and security.
Zichi Wang, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.2
2025 Integrity Protection of Generative Adversarial Networks Using Fragile Watermarking
abstract
Deep learning has made remarkable achievements in the field of artificial intelligence. However, a well-trained deep neural network is at risk of being tampered with. Although some model watermarking schemes have been proposed to solve this problem, most of them are only oriented to discriminant models, and the integrity authentication schemes for generative models are urgently lacking. Especially, the integrity authentication problem of generative adversarial networks (GANs) that plays an important role in computer vision has not been properly solved. To address this problem, we propose a fragile model watermarking framework for GANs. Specifically, we use a secret key to generate specific information as the label and combine it with the watermark to form a trigger set. Then, we use the trigger set to train the GAN, the training process does not damage the model performance. We can achieve integrity authentication of the GAN using the output of the GAN for the specific label. A large number of experiments show that our proposed method has excellent performance, which can realize the integrity authentication of GANs. What’s more, the proposed method has good generalization and can be easily applied to different GAN architectures.
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
ACM Trans. Multim. Comput. Commun. Appl.3
2024 Semi-fragile neural network watermarking for content authentication and tampering localization
Zihan Yuan, Xinpeng Zhang 0001, Zichi Wang, Zhao-Xia Yin
Expert Syst. Appl.3
2024 Reducing High-Frequency Artifacts for Generative Model Watermarking via Wavelet Transform
abstract
As generative models find broader applications in Internet of Things (IoT) image processing tasks, safeguarding the copyright of these models assumes increasing significance. Embedding watermarks on the output images generated by such models has been proposed by some researchers as a means of protecting intellectual property. However, prevailing methods for generating model watermarks inadvertently introduce significant high-frequency artifacts in high-frequency regions, compromising the imperceptibility and security of the watermarking system. In pursuit of enhancing the imperceptibility of generative model watermarking, we propose a framework based on discrete wavelet transform. This framework effectively mitigates the high-frequency artifact issue and enhances the frequency-domain concealment of watermarking. Specifically, we introduce an embedded watermarking network, a frequency separation layer, and a watermark extraction network after the output of the target model. We construct a wavelet frequency domain separation layer by wavelet decomposition to decompose the image generated by the embedding network into different frequency components, and embed the watermark into the low-frequency region of the target model output image through joint training and joint loss optimization of the embedding and extraction networks. Extensive experiments conducted on two image processing tasks, i.e., painting transfer and de-raining, demonstrate that our method exhibits no discernible traces of high-frequency artifacts in the frequency domain of the image in both cases, thus boasting superior invisibility. Furthermore, our method demonstrates robustness against pre-processing attacks, such as noise addition, resizing, and image cropping.
Hanzhou Wu, Zichi Wang, Xinpeng Zhang 0001
IEEE Internet Things J.4
2024 Robust Blind Video Watermarking Based on Ring Tensor and BCH Coding
abstract
Video Internet of Things (IoT) is widely used in the fields of safe city, smart transportation, and logistics warehousing, which facilitates the acquisition of important environmental and semantic information. However, the tampering of unauthorized video data may seriously violate user privacy and even harm society. Although the existing video watermarking technology provides an effective solution for copyright protection, it still faces challenges to achieve robust copyright authentication in the complex IoT environment. In this article, a robust blind video watermarking based on ring Tensor and Bose-Chaudhuri–Hocquenghem (BCH) coding is proposed. First, ring sub-bands of different sizes are constructed in the spatial domain of the video, and the ring sub-bands of consecutive video frames are combined into a ring tensor for copyright watermark embedding. Second, to balance the imperceptibility and robustness of the copyright watermark, an adaptive BCH coding scheme is developed, which uses the modified differential entropy to calculate the video complexity and automatically selects the appropriate watermark coding parameters. Finally, a quaternary synchronization watermark embedding strategy is designed to solve the time synchronization destruction caused by video frame rate conversion. A synchronization ring is constructed within each video frame using the strong correlation between adjacent frames. When the video is subjected to temporal synchronization attacks, the synchronization watermark is extracted from the synchronization ring to restore the synchronization of the copyright watermark. Extensive experimental results demonstrate that the proposed scheme can effectively resist common video processing while exhibiting excellent robustness against video attacks in complex Internet environments.
Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu, Deyang Wu
IEEE Internet Things J.4
2024 Adaptive Robust Watermarking for Resisting Multiple Distortions in Real Scenes
abstract
An efficient and reliable digital watermarking scheme is needed in a complex network environment to solve image copyright disputes. However, most existing digital watermarking technologies can only resist common image processing and perform poorly against complex attacks. To this end, an adaptive robust watermarking for resisting multiple distortions in real scenes is proposed in this work. First, to reduce the impact of common attacks on the robustness of the algorithm, two-level stationary wavelet transform (SWT) is applied to extract low-frequency sub-band of host image, which is subsequently divided into nonoverlapping sub-blocks. Then, a circular sub-block method is designed for watermark embedding. Moreover, an improved Schur decomposition is proposed to control the variation range of eigenvalues. Meanwhile, an adaptive robust factor and embedding strength strategy are proposed to ensure image reconstruction in real number field, thereby balancing the invisibility and robustness of the watermark. Finally, the logistic encryption and repetition code are performed on the watermark to improve the security and error correction capabilities of the watermark. Extensive experiments demonstrate that the proposed scheme has higher performance than some representative watermarking schemes in complex combined attacks and real-world scenarios.
Deyang Wu, Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu
IEEE Internet Things J.5
2024 Watermarking for Stable Diffusion Models
abstract
In the scenario of text data and image data interact of the Internet of Things (IoT) applications, the problem of copyright protection of the text-to-image models is threatened due to the replicability and portability of the neural network model. In order to solve this problem, we propose a model watermarking for the typical text-to-image diffusion models (DMs)–stable DMs (SDMs), which is a key aspect of the copyright protection of text-to-image models. Our scheme injects watermark into an SDM and makes the SDM generate watermark through a predefined prompt. The ownership of the SDM can be proved by the different output results of the model to the predefined prompt. The proposed method does not require raw training data and internal details of SDMs, which only need a predefined prompt and watermark to fine tune the pretrained SDM with minimal epoch. A large number of experiments show that our watermarking technology is effective, and can realize the copyright protection of the SDMs on the premise of less influence on the original function.
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
IEEE Internet Things J.3
2024 Transferable adversarial attack based on sensitive perturbation analysis in frequency domain
Zichi Wang, Hanzhou Wu, Xinpeng Zhang 0001
Inf. Sci.3
2024 Identification of the Original Images
Haoxian Song, Zichi Wang, Xinpeng Zhang 0001
J. Vis. Commun. Image Represent.2
2024 Maximizing steganalysis performance using siamese networks for image
Lingyan Fan, Jinxin Qiu, Zichi Wang
Multim. Tools Appl.3
2024 Ambiguity attack against text-to-image diffusion model watermarking
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
Signal Process.3
2024 Diverse Batch Steganography Using Model-Based Selection and Double-Layered Payload Assignment
abstract
Batch steganography regarding to image-selection and payload-allocation has gained increasing attention due to the secure demanding of data hiding of real scenario. However, due to the predefined selection mechanism, the chosen images are always complex which means that the diversity of the selected cover set is finite. In this paper, we develop a diverse and secure batch steganography scheme including the model-based generation and double-layered payload assignment. To construct the diverse image set, we use the Kullback-Leibler (KL) divergence to quantify the diversity increment and, relying on steganographic distortion, we select multiple image subsets (class) to create the diverse cover set in which each subset is modelled as the normal distribution with proper model parameters. Depending on the distortion of image subset, we assign the payload into all subsets with between-class allocation. Moreover, for the assigned payload of each subset, we introduce the linear model to achieve the within-class allocation. Finally, we obtain a diverse cover set along with suitable payload. Extensive experiments demonstrate the practicality of the proposed method in diversity and, compared with other selection methods, exhibit higher security on multiple steganalytic tools.
Fengyong Li, Zichi Wang, Wen Si, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.3
2024 Cover Selection in Encrypted Images
abstract
Existing effective cover selection methods aim to select the complex images as covers to achieve the highly security with the aid of the embedding distortion computed from a natural image. However, the calculation of the embedding distortion divulges the image content to a steganographer. To overcome this issue, this work proposes a novel cover selection scheme in encrypted images to achieve the image content-protection and cover-selection simultaneously. In the first phase, the content owner encrypts several most significant bits (MSBs) of each image using an encryption key and the encrypted image is shuffled by block. Meanwhile, with a sampling key, the content owner selects some encrypted blocks and outputs them to the steganographer. In the second phase, the steganographer calculates first-order noise residuals of adjacent pixels of the acquired blocks along different directions. Importantly, we design a texture descriptor named as structured Local binary pattern (SLBP) to encode all the residuals by which the images owing the maximal SLBP values are chosen as the optimal covers. We demonstrate the security of our proposed scheme on multiple steganographic and steganalytic methods and the extensive results show that our scheme exhibits excellent performance without knowing of the original image content. Moreover, the results testify that the designed SLBP achieves the perfect evaluation of image complexity.
Zichi Wang, Fengyong Li, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.3
2024 Robust Image Steganography Against General Downsampling Operations With Lossless Secret Recovery
abstract
Resisting the operations in lossy channels is a challenge for image steganography. In this article, we propose a novel robust steganographic method to resist the image downsampling operation. Unlike the existing schemes, our method guarantees lossless secret recovery from the stego-image after general image downsampling operations, which considers the undetectability of the stego-images on both sides (sender and receiver) of the lossy channel. We first downsample the cover image to get its downsampled version on the receiver side, and select a set of embeddable pixels (i.e., the pixels that can be modified for data embedding) from the downsampled image. Then, we generate a stego-image on the receiver side (termed as the receiver stego-image) such that the distortion caused by the data embedding is minimized. Based on the receiver stego-image, we modify the cover image to produce the stego-image on the sender side (termed as the sender stego-image). The modification takes the embedding cost into account and makes sure that the downsampled version of the sender stego-image produces the same embeddable pixels as the receiver stego-image. Experimental results show that our method performs significantly better than the existing schemes in terms of robustness and undetectability for resisting general image downsampling operations.
Sheng Li 0006, Zichi Wang, Xiudong Zhang, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Perceptual Image Hashing Using Feature Fusion of Orthogonal Moments
abstract
Due to the limited number of stable image feature descriptors and the simplistic concatenation approach to hash generation, existing hashing methods have not achieved a satisfactory balance between robustness and discrimination. To this end, a novel perceptual hashing method is proposed in this paper using feature fusion of fractional-order continuous orthogonal moments (FrCOMs). Specifically, two robust image descriptors, i.e., fractional-order Chebyshev Fourier moments (FrCHFMs) and fractional-order radial harmonic Fourier moments (FrRHFMs), are used to extract global structural features of a color image. Then, the canonical correlation analysis (CCA) strategy is employed to fuse these features during the final hash generation process. Compared to direct concatenation, CCA excels in eliminating redundancies between feature vectors, resulting in a shorter hash sequence and higher authentication performance. A series of experiments demonstrate that the proposed method achieves satisfactory robustness, discrimination and security. Particularly, the proposed method exhibits better tampering detection ability and robustness against combined content-preserving manipulations in practical applications.
Zichi Wang, Guorui Feng, Xinpeng Zhang 0001, Chuan Qin 0001
IEEE Trans. Multim.2
2024 Multi-Source Style Transfer via Style Disentanglement Network
abstract
Despite the great success of deep neural networks for style transfer tasks, the entanglement of content and style in images leads to more style information not being captured. To tackle this problem, a novel style disentanglement network is proposed to transfer multi-source style elements. Specifically, we specialize in designing a learnable content style separation module, which can efficiently extract content and style components from images in the latent space. This method differs from the previous approaches by predefining content and style layers in the network. Under the condition of content and style separation, we continue to propose the multi-style swap module, which allows the content image to match more style elements. Additionally, by introducing alternate training strategies for the main and auxiliary decoders as well as style disentanglement loss, the stylized results look very similar to the original artworks. Experimental results demonstrate the superiority of our proposed method compared with existing schemes.
Sheng Li 0006, Zichi Wang, Xinpeng Zhang 0001, Guorui Feng
IEEE Trans. Multim.3
2024 Art Image Inpainting With Style-Guided Dual-Branch Inpainting Network
abstract
Traditionally, art images have to be restored by professionals for a very long time. It is also possible to maintain the artistic value of damaged art images by digitizing them and restoring them through computer-aided means. However, existing advanced image inpainting methods are mainly intended for natural images and are not suitable for art images. Thus, we propose a novel style-guided dual-branch inpainting network (SDI-Net) to address the above-mentioned issue. Specifically, our SDI-Net consists of a style reconstruction (SR) branch and a style inpainting (SI) branch, in which the SR branch provides intermediate supervision (style and content supervision) for the SI branch. The SI branch performs art image inpainting with a coarse-to-fine approach. At the coarse inpainting stage, the content and style of art image are separated and preliminarily inpainted under the supervision of SI branch. In addition, we propose a class style learning (CSL) module to inpaint the style feature guided by the style label, which can provide more effective brushstrokes from the same class of art images. The coarse inpainted results can be obtained by fusing the inpainted style feature with the inpainted content feature. At the fine inpainting stage, a style attention (SA) module is proposed in the decoder to further refine the coarse inpainted results. We employ the style loss, the content loss, the multi-class style adversarial loss, and the reconstruction loss to jointly train the proposed SDI-Net. A variety of experiments demonstrate the effectiveness of the proposed method, which allows the filled brushstrokes to appear as realistic as possible.
Zichi Wang, Xinpeng Zhang 0001, Guorui Feng
IEEE Trans. Multim.2
2023 Neural Network Steganography Using Extractor Matching
Yunfei Xie, Zichi Wang
IWDW2
2023 Data hiding during image processing using capsule networks
Zichi Wang, Guorui Feng, Hanzhou Wu, Xinpeng Zhang 0001
Neurocomputing1
2023 A general steganographic framework for neural network models
Ziyun Yang, Zichi Wang, Xinpeng Zhang 0001
Inf. Sci.2
2023 JPEG Steganography With Content Similarity Evaluation
abstract
Content similarity is a representative property of natural images, for example, similar regions, which is utilized by modern steganalysis. Existing JPEG steganographic methods mainly focus on the complexity of content but ignore content similarity. This article investigates content similarity to improve the undetectability of JPEG steganography. Specifically, the content similarity of DCT blocks and the 64 parallel channels is used to design the distortion function. Given a JPEG image, initial embedding costs are assigned for quantized DCT coefficients using an appropriate algorithm among the existing distortion functions. Then, the similarities of blocks and channels are used to update the initial embedding costs, respectively. After combination, the final distortion function can be obtained. Using syndrome trellis coding (STC), which achieves minimal embedding distortion with respect to a given distortion function, secret data are embedded into the cover image with a final distortion function. Experimental results show that our scheme achieves better undetectability than current state-of-the-art JPEG steganographic methods.
Zichi Wang, Guorui Feng, Zhenxing Qian, Xinpeng Zhang 0001
IEEE Trans. Cybern.1
2023 Cover Selection for Steganography Using Image Similarity
abstract
Existing cover selection methods for steganography mainly focus on embedding distortion of each image, but ignore the similarity between images. When the cover images are similar, a number of relevant samples are provided to steganalysis, which is disadvantageous to steganography. This paper proposes a new cover selection method to joint image similarity and embedding distortion. Due to the difference between steganography and other image processing tasks, e.g., image reconstruction, image recognition, we propose a customized method to calculate image similarity for steganography based on SVD (singular value decomposition). Importantly, the small singular values (instead of the large ones) are employed, since it is suitable for the properties of steganography. In addition, embedding distortion is calculated by the current distortion minimization framework. The obtained image similarity and embedding distortion are combined to form a new cover selection strategy. As a result, the properties of batch images can be fully used. Experimental results show that our scheme outperforms the state-of-the-art cover selection methods when they are checked by modern steganalytic tools.
Zichi Wang, Guorui Feng, Liquan Shen, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.1
2022 Perceptual Model Hashing: Towards Neural Network Model Authentication
abstract
A lot of excellent neural network models are valuable wealth to the field of artificial intelligence, which may be plagiarized and distributed without authorization. For this reason, few research establishments and industries reveal the internals of their neural network models. To authenticate suspicious pirated models, this letter proposes a gray-box hashing method for the neural network models that designed for image classification. In the proposed method, the hash sequence of original model can be extracted without knowing both the structure and weight parameters except the vectors in output layer. To the best of our knowledge, this is the first work focusing on gray-box perceptual model hashing to identify and authenticate neural network models. Experimental results show that our method performs satisfactory perceptual robustness and discrimination capability, and can effectively classify perceptual similar versions of the original model and distinct models.
Zichi Wang, Guorui Feng, Xinpeng Zhang 0001, Chuan Qin 0001
MMSP2
2022 Robust Watermarking for Neural Network Models Using Residual Network
abstract
The training process of a neural network model requires plenty of costs, and so the intellectual property of neural network models should be protected. To this end, we propose a robust watermarking scheme for neural network models in this paper. In our scheme, an independent network is specially designed to help embedding watermarks into a given host network, and also be used for watermark extraction. The independent network is designed based on the residual structure which is sensitive to the parameter changes of the host network and conducive to finding suitable embedding locations. In addition, some residual blocks are randomly discarded during watermark embedding, which can increase the robustness against popular model attacks. Experimental results show that our scheme achieves satisfactory watermark verification performance without decreasing the original performance of the host network, even if the host network has been maliciously tampered.
Lecong Wang, Zichi Wang, Chuan Qin 0001
MMSP2
2022 Multi-source Data Hiding in Neural Networks
abstract
This paper proposes a multi-source data hiding scheme for neural networks, in which multiple senders can simultaneously transmit different secret data to a receiver using the same neural network. In our scheme, multiple senders execute data embedding in the overlapping position of a network, so that the existence of other senders can be concealed. Each sender uses a unique embedding key to scramble the parameters for embedding, preventing an attacker or other senders from pretending him. In addition, data embedding is achieved during the training process of the neural network instead of modifying the neural network after training. As a result, the operation of data embedding has a tiny impact on the original neural network. On the receiver side, the corresponding embedding key is used to extract the secret data, while additional decoding networks are unnecessary. Experiments verified the effectiveness and security of our scheme, including embedding capacity and undetectability.
Ziyun Yang, Zichi Wang, Xinpeng Zhang 0001, Zhenjun Tang
MMSP2
2022 Repeatable Data Hiding: Towards the Reusability of Digital Images
abstract
This article proposes a repeatable data hiding framework for digital images, in which the distortion caused by data hiding is invariable no matter how many times the embedding operation is executed. As a result, the usability of images can be always guaranteed. To achieve repeatable data hiding, we deduce the theoretical modification probabilities of the elements in cover image (an image used for data hiding). Then we design an embedding framework to make the practical modification probabilities of cover elements equal to the deduced ones. When additional data is embedded into cover image with the deduced probabilities, the modification-trace of current embedding is replaced by the latter embedding. That means multiple embeddings do not produce new modification-trace, so that the distortion caused by data hiding is invariable. Therefore, the repeatability of data hiding can be guaranteed. Finally, we describe some applications of repeatable data hiding, e.g., logistics management, authentication database management, and steganography, to show the practicability of our framework.
Zichi Wang, Guorui Feng, Xinpeng Zhang 0001
IEEE Trans. Circuits Syst. Video Technol.1
2022 Unified Performance Evaluation Method for Perceptual Image Hashing
abstract
In recent decades, a large number of perceptual image hashing schemes have been designed to secure the authenticity and integrity of digital images. However, the feasible criterion to evaluate the performances of hashing schemes has not been developed yet. To this end, a unified performance evaluation method for perceptual image hashing schemes is proposed in this paper. The proposed evaluation method contains six modules: robustness, discrimination, tampering detection, security, computational efficiency and hash length. The order relationship analysis (ORA) is employed to assign the score proportion of each module in accordance with the relative importance of performance, which allows the customizability of user. The real scores of modules and the outputted final score can reflect the performances of perceptual image hashing schemes intuitively and convincingly. Experimental results demonstrate that the proposed evaluation method is practical and effective for the complete and comprehensive evaluation of perceptual image hashing schemes.
Chuan Qin 0001, Zichi Wang, Zhenxing Qian, Xinpeng Zhang 0001
IEEE Trans. Inf. Forensics Secur.3
2021 Reversible Privacy Protection with the Capability of Antiforensics
abstract
In this paper, we propose a privacy protection scheme using image dual-inpainting and data hiding. In the proposed scheme, the privacy contents in the original image are concealed, which are reversible that the privacy content can be perfectly recovered. We use an interactive approach to select the areas to be protected, that is, the protection data. To address the disadvantage that single image inpainting is susceptible to forensic localization, we propose a dual-inpainting algorithm to implement the object removal task. The protection data is embedded into the image with object removed using a popular data hiding method. We further use the pattern noise forensic detection and the objective metrics to assess the proposed method. The results on different scenarios show that the proposed scheme can achieve better visual quality and antiforensic capability than the state-of-the-art works.
Liyun Dou, Zichi Wang, Zhenxing Qian, Guorui Feng
Secur. Commun. Networks2
2021 Batch Steganography via Generative Network
abstract
Batch steganography is a technique that hides information into multiple covers. To achieve a better performance on the security of data hiding, we propose a novel strategy of batch steganography using a generative network. In this method, the approaches of cover selection, payload allocation, and distortion evaluation are considered in the round. We define a quality metric to evaluate the distortion between the cover image and the stego. When training the generation function, we define an objective function containing two parts: the entropy loss and the steganalytic loss. While the entropy loss is used to represent the gap between the payload inside stego images and the entire embedding capacity, the steganalytic loss is used to assess the data embedding impact using the proposed quality metric. With back-propagation, we minimize the objective function to obtain an optimal solution. Accordingly, different payloads can be allocated to different images, and the ± 1 modification probability for pixels in each cover can be calculated. Finally, we embed information into the selected images by STC. Experimental results show that the proposed method achieves a better undetectability against modern steganalytic tools.
Nan Zhong, Zhenxing Qian, Zichi Wang, Xinpeng Zhang 0001, Xiaolong Li 0001
IEEE Trans. Circuits Syst. Video Technol.3
2020 Steganographic Distortion Function for Enhanced Images
Zichi Wang, Guorui Feng, Xinpeng Zhang 0001
IWDW1
2020 Practical Cover Selection for Steganography
abstract
This letter focus on a practical scenario of cover selection for steganography, in which a part of the available images of the sender have been processed to improve visual quality, e.g., contrast enhancement, image denoising. In this case, not only the embedding distortion (caused by steganography), but also the processing distortion (caused by processing) should be considered when selecting cover image. We propose a cover selection method to combine the two kinds of distortion together to measure the suitability for steganography of the available images. To calculate the processing distortion, a classifier is trained to distinguish the processed images with the original ones. The classifier is then used to measure the possibility of the existence of processing. High possibility means high processing distortion. In addition, the current distortion minimization framework designed for steganography is employed to calculate the embedding distortion. Finally, both kinds of distortion are combined to form the total distortion, and the image with the minimal total distortion is selected as cover. Using the selected image for embedding, high undetectability can be achieved.
Zichi Wang, Xinpeng Zhang 0001, Zhenxing Qian
IEEE Signal Process. Lett.1
2020 A New Steganography Method for Dynamic GIF Images Based on Palette Sort
abstract
This paper proposes a new steganography method for hiding data into dynamic GIF (Graphics Interchange Format) images. When using the STC framework, we propose a new algorithm of cost assignment according to the characteristics of dynamic GIF images, including the image palette and the correlation of interframes. We also propose a payload allocation algorithm for different frames. First, we reorder the palette of GIF images to reduce the modifications on pixel values when modifying the index values. As the different modifications on index values would result in different impacts on pixel values, we assign the elements with less impact on pixel values with small embedding costs. Meanwhile, small embedding costs are also assigned for the elements in the regions that the interframe changes are large enough. Finally, we calculate an appropriate payload for each frame using the embedding probability obtained from the proposed distortion function. Experimental results show that the proposed method has a better security performance than state-of-the-art works.
Jingzhi Lin, Zhenxing Qian, Zichi Wang, Xinpeng Zhang 0001, Guorui Feng
Wirel. Commun. Mob. Comput.3
2019 Towards Robust Image Steganography
abstract
Posting images on social network platforms is happening everywhere and every single second. Thus, the communication channels offered by various social networks have a great potential for covert communication. However, images transmitted through such channels will usually be JPEG compressed, which fails most of the existing steganographic schemes. In this paper, we propose a novel image steganography framework that is robust for such channels. In particular, we first obtain the channel compressed version (i.e., the channel output) of the original image. Secret data is embedded into the channel compressed original image by using any of the existing JPEG steganographic schemes, which produces the stego-image after the channel transmission. To generate the corresponding image before the channel transmission (termed the intermediate image), we propose a coefficient adjustment scheme to slightly modify the original image based on the stego-image. The adjustment is done such that the channel compressed version of the intermediate image is exactly the same as the stego-image. Therefore, after the channel transmission, secret data can be extracted from the stego-image with 100% accuracy. Various experiments are conducted to show the effectiveness of the proposed framework for image steganography robust to JPEG compression.
Jinyuan Tao, Sheng Li 0006, Xinpeng Zhang 0001, Zichi Wang
IEEE Trans. Circuits Syst. Video Technol.4
2018 Distortion function based on residual blocks for JPEG steganography
Qingde Wei, Zhao-Xia Yin, Zichi Wang, Xinpeng Zhang 0001
Multim. Tools Appl.3
2018 Joint Cover-Selection and Payload-Allocation by Steganographic Distortion Optimization
abstract
This letter proposes a batch steganographic method, which combines cover-selection and payload-allocation by steganographic distortion optimization. We first proved that with the value of payload increasing, the first-order derivative of steganographic distortion of a single cover is monotonically increasing. Then, we deduced that the first-order derivative of steganographic distortion of covers that selected from a given set should be equal if the total steganographic distortion of the corresponding selected covers is minimal. Finally, an algorithm was designed to combine cover-selection and payload-allocation, so that the optimal stego-covers can be obtained. Experiment results show that the undetectability is obviously improved when using the proposed steganographic method.
Zichi Wang, Xinpeng Zhang 0001, Zhao-Xia Yin
IEEE Signal Process. Lett.1
2016 Distortion Function for Spatial Image Steganography Based on the Polarity of Embedding Change
Zichi Wang, Jinpeng Lv, Qingde Wei, Xinpeng Zhang 0001
IWDW1
2016 Lossless and Reversible Data Hiding in Encrypted Images With Public-Key Cryptography
abstract
This paper proposes lossless, reversible, and combined data hiding schemes for ciphertext images encrypted by public-key cryptosystems with probabilistic and homomorphic properties. In the lossless scheme, the ciphertext pixels are replaced with new values to embed the additional data into several least significant bit planes of ciphertext pixels by multilayer wet paper coding. Then, the embedded data can be directly extracted from the encrypted domain, and the data-embedding operation does not affect the decryption of original plaintext image. In the reversible scheme, a preprocessing is employed to shrink the image histogram before image encryption, so that the modification on encrypted images for data embedding will not cause any pixel oversaturation in plaintext domain. Although a slight distortion is introduced, the embedded data can be extracted and the original image can be recovered from the directly decrypted image. Due to the compatibility between the lossless and reversible schemes, the data-embedding operations in the two manners can be simultaneously performed in an encrypted image. With the combined technique, a receiver may extract a part of embedded data before decryption, and extract another part of embedded data and recover the original plaintext image after decryption.
Xinpeng Zhang 0001, Jing Long, Zichi Wang, Hang Cheng
IEEE Trans. Circuits Syst. Video Technol.3