VLDB 2026 Research / reviewers in the wild / expert
Chuan Qin 0003
dblp:24/2771-3
· DBLP profile ↗
14ranked-venue papers
3as first author
10since 2021 · last 2024
0000-0002-5841-8210ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 10 · 2 first-author · 7 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | AAS: Automatic Virtual Data Augmentation for Deep Image SteganalysisabstractIn recent years, steganalysis based on deep learning has evolved rapidly. However, training deep learning models is data-consuming. The models are prone to overfitting when data is limited. Data augmentation is an effective method to mitigate overfitting. Existing data augmentation methods in steganalysis can be categorized into cover enrichment and virtual augmentation. They are used in different stages. Cover enrichment refers to introducing additional cover-stego pairs in some ways, which is performed prior to training. In contrast, virtual augmentation augments data during training. Existing virtual augmentation methods are designed heuristically and rely on expert knowledge. In this paper, we propose the first automatic virtual data augmentation method for steganalysis. Specifically, we design an augmentation network that augments cover and stego images by intelligently adding noises. The augmentation network is trained adversarially with the steganalyzer to generate diverse data. Meanwhile, a “class-invariant” module prevents the augmentation network from changing the original data distribution too much. A “stabilizer” loss function is designed that keeps the adversarial training stable by constraining the number of noises. The experimental results show that the proposed method outperforms existing virtual augmentation methods. Moreover, combining the proposed method and cover enrichment can further boost performance. Jiansong Zhang 0006, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Image Adversarial Steganography Based on Joint DistortionabstractImage steganography is the technique of concealing secret messages into digital images without arousing suspicion from detectors. Recently, adversarial steganography has received much attention from the research community, since it is effective in deceiving target deep-learning-based steganalysis (DLS) and designing more secure embedding distortion. However, how to combine adversarial steganography with handcrafted adjustment strategies to design adversarial steganography based on joint distortion has not been discussed yet. In this paper, incorporating adversarial steganography and joint distortion assignment, we present a novel adversarial steganographic scheme named JAS (Joint Adversarial Steganography). We compute joint distortion and adjust it based on joint gradient, which is a vector consisting of the gradients of two adjacent pixels, until the resulting stego image could deceive the target DLS. Furthermore, by combining JAS with synchronizing modification directions profile, we enhance the steganography security more desirably. Experiments demonstrate that the proposed method effectively enhances the anti-detection ability of joint distortion steganography. Zexin Fan, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu |
ICASSP | 3 |
| 2023 | Calibration-based Steganalysis for Neural Network SteganographyabstractRecent research has shown that neural network models can be used to steal sensitive data or embed malware. Therefore, steganalysis for neural networks is urgently needed. However, existing neural network steganalysis methods do not perform well under small embedding rates. In addition, because of the large number of parameters, the neural network steganography method under a small embedding rate can embed enough information into the model for malicious purposes. To address this problem, this paper proposes a calibration-based steganalysis method, which fine-tunes the original neural network model without implicit constraints to obtain a reference model, then extracts and fuses statistical moments from the parameter distributions of the original model and its reference model, and finally trains a logistic regressor for detection. Extensive experiments show that the proposed method has superior performance in detecting steganographic neural network models under small embedding rates. Na Zhao 0009, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu |
IH&MMSec | 3 |
| 2022 | Patch Steganalysis: A Sampling Based Defense Against Adversarial SteganographyabstractIn recent years, the classification accuracy of CNN (convolutional neural network) steganalyzers has rapidly improved. However, as general CNN classifiers will misclassify adversarial samples, CNN steganalyzers can hardly detect adversarial steganography, which combines adversarial samples and steganography. Adversarial training and preprocessing are two effective methods to defend against adversarial samples. But literature shows adversarial training is ineffective for adversarial steganography. Steganographic modifications will also be destroyed by preprocessing, which aims to wipe out adversarial perturbations. In this paper, we propose a novel sampling based defense method for steganalysis. Specifically, by sampling image patches, CNN steganalyzers can bypass the sparse adversarial perturbations and extract effective features. Additionally, by calculating statistical vectors and regrouping deep features, the impact on the classification accuracy of common samples is effectively compressed. The experiments show that the proposed method can significantly improve the robustness against adversarial steganography without adversarial training. Chuan Qin 0003, Na Zhao 0009, Weiming Zhang 0001, Nenghai Yu |
ICASSP | 1 |
| 2022 | Robustness enhancement against adversarial steganography via steganalyzer outputs
Chuan Qin 0003, Weiming Zhang 0001, Hang Zhou 0007, Yuan He 0011, Nenghai Yu |
J. Inf. Secur. Appl. | 1 |
| 2022 | Distribution-Preserving-Based Automatic Data Augmentation for Deep Image SteganalysisabstractIn recent years, deep learning-based steganalyzers far outperformed handcrafted feature-based steganalyzers. However, a large amount of data is needed to train deep learning networks. For steganalysis tasks, the steganographic traces are subtle and the steganographic signals are difficult to be captured when the number of cover/stego pairs in the training set is insufficient. Data augmentation has been proved to be effective in improving accuracy and generalization for deep learning models. Yet not all data augmentation methods are universal for all tasks. When performing data augmentation, we argue that data distribution under the target tasks should be maintained. Since the steganalysis task is more concerned with the high-frequency signals of the images, if the high-frequency signals are unchanged, the data distribution from the perspective of steganalysis will remain largely unchanged. Based on this principle, we designed a neural network called cover augmentation network, which enriches the dataset by intelligently adding noise to the original cover to generate the augmented cover. Further, we designed a whole process of data augmentation based on the cover augmentation network. Experimental results show that the proposed data augmentation method can effectively improve the performance of steganalysis networks, and the advantage is significant at low payloads. Jiansong Zhang 0006, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Multim. | 3 |
| 2021 | Adversarial Examples Detection Beyond Image SpaceabstractDeep neural networks have been proved that they are vulnerable to adversarial examples, which are generated by adding human-imperceptible perturbations to images. To defend these adversarial examples, various detection based methods have been proposed. However, most of them perform poorly on detecting adversarial examples with extremely slight perturbations. By exploring these adversarial examples, we find that there exists compliance between perturbations and prediction confidence, which guides us to detect few-perturbation attacks from the aspect of prediction confidence. To detect both few-perturbation attacks and large-perturbation attacks, we propose a method beyond image space by a two-stream architecture, in which the image stream focuses on the pixel artifacts and the gradient stream copes with the confidence artifacts. The experimental results show that the proposed method outperforms the existing methods under oblivious attacks and is verified effective to defend omniscient attacks as well. Kejiang Chen, Yuefeng Chen, Hang Zhou 0007, Chuan Qin 0003, Xiaofeng Mao, Weiming Zhang 0001, Nenghai Yu |
ICASSP | 4 |
| 2021 | Adversarial steganography based on sparse cover enhancement
Chuan Qin 0003, Weiming Zhang 0001, Xiaoyi Dong, Hongyue Zha, Nenghai Yu |
J. Vis. Commun. Image Represent. | 1 |
| 2021 | Adversarial batch image steganography against CNN-based pooled steganalysis
Li Li 0103, Weiming Zhang 0001, Chuan Qin 0003, Kejiang Chen, Wenbo Zhou 0004, Nenghai Yu |
Signal Process. | 3 |
| 2021 | Feature-Preserving Tensor Voting Model for Mesh SteganalysisabstractThe standard tensor voting technique shows its versatility in tasks such as object recognition and semantic segmentation by recognizing feature points and sharp edges that can segment a model into several patches. We propose a neighborhood-level representation-guided tensor voting model for 3D mesh steganalysis. Because existing steganalytic methods do not analyze correlations among neighborhood faces, they are not very effective at discriminating stego meshes from cover meshes. In this paper, we propose to utilize a tensor voting model to reveal the artifacts caused by embedding data. In the proposed steganalytic scheme, the normal voting tensor (NVT) operation is performed on original mesh faces and smoothed mesh faces separately. Then, the absolute values of the differences between the eigenvalues of the two tensors (from the original face and the smoothed face) are regarded as features that capture intricate relationships among the vertices. Subsequently, the extracted features are processed with a nonlinear mapping to boost the feature effectiveness. The experimental results show that the proposed feature sets prevail over state-of-the-art feature sets including LFS64 and ELFS124 under various steganographic schemes. Hang Zhou 0007, Kejiang Chen, Weiming Zhang 0001, Chuan Qin 0003, Nenghai Yu |
IEEE Trans. Vis. Comput. Graph. | 4 |
| 2020 | GreedyFool: Distortion-Aware Sparse Adversarial AttackabstractModern deep neural networks(DNNs) are vulnerable to adversarial samples. Sparse adversarial samples are a special branch of adversarial samples that can fool the target model by only perturbing a few pixels. The existence of the sparse adversarial attack points out that DNNs are much more vulnerable than people believed, which is also a new aspect for analyzing DNNs. However, current sparse adversarial attack methods still have some shortcomings on both sparsity and invisibility. In this paper, we propose a novel two-stage distortion-aware greedy-based method dubbed as ''GreedyFool". Specifically, it first selects the most effective candidate positions to modify by considering both the gradient(for adversary) and the distortion map(for invisibility), then drops some less important points in the reduce stage. Experiments demonstrate that compared with the start-of-the-art method, we only need to modify 3 times fewer pixels under the same sparse perturbation setting. For target attack, the success rate of our method is 9.96% higher than the start-of-the-art method under the same pixel budget. Xiaoyi Dong, Dongdong Chen 0001, Jianmin Bao, Chuan Qin 0003, Lu Yuan 0001, Weiming Zhang 0001, Nenghai Yu, Dong Chen 0003 |
NeurIPS | 4 |
| 2020 | Shortening the Cover for Fast JPEG SteganographyabstractRecently, the most effective steganographic schemes for JPEG images are based on minimal distortion model with Syndrome-Trellis Codes (STCs) as the coding method. However, the execution time of STCs will be severely long for message embedding to the cover object of large size, which cannot meet the demand for real-time communication in a real-world application. According to the time complexity O(2hn), it is suggested in the STCs to accelerate the embedding process by decreasing the constraint height h. However, smaller h corresponds to lower steganographic security. In this paper, we investigate the possibility of shortening the cover (reducing the length n) for speeding up the execution of STCs without weakening the steganographic security. After introducing some properties of cover selection with proofs, we propose several algorithms designed for JPEG images to construct a preferable shortened cover containing DCT coefficients of smaller costs as much as possible. The experimental results display the superiority of the proposed algorithm on the speed profit and the security when compared with the method of decreasing h. With confidence, a JPEG image of arbitrary quality factor can be safely shortened to 1/4 of the original, and correspondingly the execution of STCs can be four times faster. Weixiang Li, Wenbo Zhou 0004, Weiming Zhang 0001, Chuan Qin 0003, Huanhuan Hu, Nenghai Yu |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2019 | Direct Adversarial Attack on Stego Sandwiched Between Black BoxesabstractDue to the amazing progresses in deep learning techniques, steganography has now been challenged to tackle not only artificial feature-based but also effective deep-learning-based steganalysis. Recent steganographers have tried to conduct adversarial attacks to defend the steganalysis networks by fine-tuning the embedding details with the help of adversarial information, which, however, mostly are white-box attacks. This research studies a novel method to conduct stegano-graphic adversarial attacks in practical scenario where stegos are sandwiched between black boxes. In our case, the toolboxes to generate stegos are steganographic black boxes where embedding adjustments are prohibited, and networks to detect stegos are semi-black boxes where most of the steganalysis networks' details are unavailable. By reforming few-pixel-attack into the form of extraction conservation noises and add them directly onto stegos, we ensure the message extraction and launch the attack in practical scenario. Experiments show that the proposed method can significantly boost the error rate of the deep-learning-based steganalysis and at the same time keep a comparable error rate when facing artificial feature-based steganalysis. Hongyue Zha, Weiming Zhang 0001, Chuan Qin 0003, Nenghai Yu |
ICIP | 3 |
| 2018 | Reversible visual transformation via exploring the correlations within color images
Dongdong Hou, Chuan Qin 0003, Nenghai Yu, Weiming Zhang 0001 |
J. Vis. Commun. Image Represent. | 2 |