Yaofei Wang

dblp:222/3830 · DBLP profile ↗
← Back
29ranked-venue papers
5as first author
25since 2021 · last 2026
0000-0002-7765-9239ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 16 · 1 first-author · 14 since 2021Security and privacy · 12 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 AEDR: Training-Free AI-Generated Image Attribution via Autoencoder Double-Reconstruction
abstract
The rapid advancement of image-generation technologies has made it possible for anyone to create photorealistic images using generative models, raising significant security concerns. To mitigate malicious use, tracing the origin of such images is essential. Reconstruction-based attribution methods offer a promising solution, but they often suffer from reduced accuracy and high computational costs when applied to state‑of‑the‑art (SOTA) models. To address these challenges, we propose AEDR (AutoEncoder Double-Reconstruction), a novel training‑free attribution method designed for generative models with continuous autoencoders. Unlike existing reconstruction‑based approaches that rely on the value of a single reconstruction loss, AEDR performs two consecutive reconstructions using the model’s autoencoder, and adopts the ratio of these two reconstruction losses as the attribution signal. This signal is further calibrated using the image homogeneity metric to improve accuracy, which inherently cancels out absolute biases caused by image complexity, with autoencoder‑based reconstruction ensuring superior computational efficiency. Experiments on eight top latent diffusion models show that AEDR achieves 25.5% higher attribution accuracy than existing reconstruction‑based methods, with requiring only 1% of the computational time.
Zijin Yang, Yaofei Wang, Weiming Zhang 0001, Kejiang Chen
AAAI3
2026 Breaking the Generative Steganography Trilemma: ANStega for Optimal Capacity, Efficiency, and Security
Yaofei Wang, Weilong Pang, Kejiang Chen, Jinyang Ding, Donghui Hu, Weiming Zhang 0001, Nenghai Yu
NDSS1
2026 Semantic-Aware and Semi-Fragile Diffusion Watermarking for Proactive Deepfake Detection
abstract
The rapid progress of deepfake technology, which primarily manipulates facial identity and image semantics, has made detection and defense critically important. Conventional global watermarking methods offer limited capacity for protecting key semantic content, as they typically rely on uniformly distributed watermarks across the entire image. This letter presents a method that weave watermarks as intrinsic components into the semantic content of images (facial regions) in the latent space. By aligning watermark embedding regions with facial content, we establish an inherent fragility mechanism wherein any deepfake manipulation that modifies facial semantics inevitably disrupts the watermark, enabling precise detection. Simultaneously, adversarial training of the extractor ensures robustness against conventional signal processing operations. A local entropy perception module dynamically adjusts embedding intensity based on regional texture complexity, maintaining high perceptual fidelity. Extensive experiments indicate that compared to advanced methods, the proposed approach maintains robustness against conventional benign operations while achieving reliable detection of deepfake forgeries, thereby enabling precise protection of image semantic content.
Rui Sun 0004, Xiaolu Yu, Yuwei Dai, Yaofei Wang
IEEE Signal Process. Lett.5
2026 GIANT: Generated Image Adversarial Steganography Based on Narrowed Targeting
abstract
With the rapid emergence of various generative models, generated images have increasingly become a prominent data medium on social platforms, making up a significantly higher proportion and providing fertile ground for steganography. However, research on steganography for generated images remains limited, and the distinctive attributes, especially the reproducibility of text-to-image (TTI) models, have not been effectively leveraged. In this paper, we propose GIANT (Generated Image Adversarial steganography based on Narrowed Targeting), a novel adversarial steganography framework for generated images that employs narrowed targeting to focus on embedding the secret message solely in the secure region and synchronizing the position to enhance the steganography security. GIANT achieves narrowed targeting by leveraging the reproducibility of TTI models and fusing two regions: (1) the minimal distortion region, which is localized by measuring steganographic distortion to evaluate the impact of modifications on the cover image distribution, and (2) the critical attention region, which is localized by using coarse-grained and fine-grained attention maps to evade steganalysis detection. Additionally, for positional synchronization of the secure region, the related prompts are transmitted alongside the stego image, allowing the receiver to reconstruct the cover image using a shared key and the provided prompt. Experimental results demonstrate that GIANT significantly improves security compared to conventional and adversarial steganographic methods designed for natural images, effectively countering state-of-the-art steganalyzers.
Zexin Fan, Kejiang Chen, Yaofei Wang, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Circuits Syst. Video Technol.3
2026 UPSEC: Unstable-Position-Synchronization-Based Erasure Code for High-Security Robust Steganography
abstract
People are accustomed to sharing images on online social networks (OSNs), which is suited for covert communication. Robust steganography can survive JPEG recompression from OSN but sacrifices considerable security. This paper endeavors to achieve high-security robust steganography, an issue that plagues the current field. We define truncation-affected coefficients as unstable coefficients; they are major sources of error during recompression.We find that the unstable coefficients remain unstable under repeated recompression, which means both sides of the steganographic communication can naturally synchronize their positions. Therefore, we propose the unstable position synchronization based erasure code (UPSEC), where we replace the value of the unstable coefficient with a constant and set the distortion of the unstable coefficient to infinity when embedding. The receiver locates the unstable coefficients and sets their values to the same constant before extraction. By UPSEC, the unstable coefficient is effectively erased, so recompression errors no longer influence message extraction. Therefore, UPSEC achieves improved security without compromising robustness. Experimental results show that UPSEC can improve security by about +14% when compared to the state-of-the-art method against SRNet.
Kejiang Chen, Weiming Zhang 0001, Yaofei Wang, Nenghai Yu
IEEE Trans. Circuits Syst. Video Technol.5
2026 Side-Information Estimated Steganography via Dual-Path Super-Resolution Reconstruction
abstract
Previous research has demonstrated that a spatial domain image can provide side-information to its downsampled cover image, allowing a steganographer to embed a secret message on the cover image more securely by modulating the initial distortion. Importantly, the steganographer must possess the original image with a higher resolution than the cover image. In practical scenarios, however, the steganographer typically only has the cover image in which he wishes to embed the secret message; he does not have access to the real, higher-resolution image. To improve the security of steganography, we would like to estimate the side-information from the cover image. This paper proposes a spatial domain image steganography framework of side-information estimated with polarity adjustment strategy based on dual-path super-resolution reconstruction, in which double estimated side-information can be used to modulate the initial distortion. How to estimate more realistic high-resolution images and how to develop an effective modulation strategy are the central issues of our methods. We use double super-resolution networks to reconstruct high-resolution images for estimating side-information, and then propose a simple and effective strategy to modulate the initial distortion using dual-path estimated side-information. Experiments demonstrate that the security of dual-path side-information steganography can significantly outperform that of conventional distortion techniques.
Kejiang Chen, Yaofei Wang, Jinyang Ding, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.3
2026 Generative Image Steganography With Minimum-Distance Guidance
abstract
Image steganography conceals secret data within a digital image while preserving its innocent appearance. The advent of artificial intelligence generative models has given rise to a new paradigm known as generative image steganography, which hides secret data directly into the image generation process. However, existing generative image steganographic methods are typically only applicable to unquantized stego images, severely limiting their practicality in real-world scenarios. To address this limitation, we propose a generative image steganography with minimum-distance guidance based on a diffusion model, called MDStega. During the hiding phase, MDStega designs a secret data-driven residual image sampling mechanism, which establishes a dynamic mapping relationship between discrete secret data and continuous probability distributions, strictly preserving the distribution consistency between stego images and normally generated images. During the extraction phase, the minimum-distance guidance rule effectively suppresses the interference caused by stego image quantization on the extraction accuracy of secret data. Furthermore, MDStega does not require fine-tuning pre-trained models or training additional models, which significantly reduces computational overhead and training time. Experimental results demonstrate that MDStega is superior to state-of-the-art methods by not only ensuring secure concealment at 3 bits per pixel (bpp) in PNG format but also achieving a recovery accuracy of up to 99%, demonstrating strong practical potential.
Yinyin Peng, Chengjie Gu, Donghui Hu, Yaofei Wang, Xianjin Rong, Zhao-Xia Yin
IEEE Trans. Dependable Secur. Comput.4
2025 SparSamp: Efficient Provably Secure Steganography Based on Sparse Sampling
Yaofei Wang, Gang Pei, Kejiang Chen, Jinyang Ding, Weilong Pang, Donghui Hu, Weiming Zhang 0001
USENIX Security Symposium1
2025 CoAS: Composite Audio Steganography Based on Text and Speech Synthesis
abstract
Digital steganography is the practice of embedding secret information in original normal data to enable covert communication. With the rapid advancement of generative models, generative steganography has gained renewed vitality. As a key medium on the Internet, audio has also become a focus of steganographic research. However, existing audio steganography methods rely on traditional audio synthesis models, which often suffer from suboptimal synthesis quality. In contrast, diffusion models perform well in audio synthesis tasks, but there is a lack of targeted secure audio steganography methods based on them. In addition, existing steganography schemes are generally limited to transmitting only the steganographic object, and other key elements need to be negotiated in advance, which limits their practicality. To address these issues, we propose CoAS, a composite audio steganography method based on text and speech synthesis. Firstly, we use a provably secure linguistic steganography method to embed the synchronous side information required for audio steganography, and then replace the gaussian noise in the diffusion models with message-driven sampling during the audio generation process. Both theoretical analysis and experimental results validate the security and practicality of our composite steganography method in the real world. Audio samples are available at https://meterial.github.io/coas.github.io.
Yiming Li 0009, Kejiang Chen, Yaofei Wang, Guanjie Wang, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Inf. Forensics Secur.3
2025 Rethinking Prefix-Based Steganography for Enhanced Security and Efficiency
abstract
Generative models have demonstrated remarkable capabilities in synthesizing realistic content, creating new opportunities for secure communication through steganography---the practice of embedding covert messages within seemingly innocuous data. While prefix-based steganography, which encodes secret messages into shared probability intervals during generative sampling, has emerged as a promising paradigm for provably secure communication, its practical adoption remains constrained by inherent tradeoffs between security, capacity, and efficiency. To address these challenges, we propose two enhancements. The first enhancement optimizes quantization distortion in existing frameworks to minimize KL divergence, thereby enhancing theoretical security. The second redesigns the sampling mechanism via distribution coupling to amplify steganographic capacity, achieving this without incurring substantial computational overhead. Experimental validation on text generation task confirms our enhancements substantially outperform previous implementations, demonstrating notable capacity improvements, marked security enhancements, and efficiency gains on consumer-grade hardware. Cross-task comparisons with popular provably secure steganography further establish the proposed enhancements as achieving superior security-capacity-efficiency tradeoffs across diverse generative scenarios, advancing the practical deployment of provably secure steganography systems.
Donghui Hu, Yaofei Wang, Kejiang Chen, Yinyin Peng, Xianjin Rong, Chen Gu, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.3
2024 Image Steganography with Deep Orthogonal Fusion of Multi-Scale Channel Attention
abstract
Due to the steganography of hiding images requires that the secret message be a full-size image, to improve the universality of steganography and decoding accuracy than hiding images, this paper presents image steganography with the deep orthogonal fusion of multi-scale channel attention (SOFMC). To achieve this, the secret data is reshaped into a three-dimensional tensor and fused into shallow and deep representations of the cover image. The deep orthogonal fusion of multi-scale channel attention (OFMC) is designed to calibrate the relationships among the channels. The OFMC can yield the channel attention vectors of the feature map at different scales and use orthogonal fusion to integrate the above channel information of different receptive fields. In the specific implementation, we encapsulate OFMC into the blocks of the basic network in the generator and extractor. The designed blocks are highly flexible and can be cascaded by dense connection as needed. Experimental results demonstrate that SOFMC is superior to previous methods in the decoding accuracy, security, and quality of stego images.
Yinyin Peng, Donghui Hu, Gang Pei, Yaofei Wang
ICASSP4
2024 LDStega: Practical and Robust Generative Image Steganography based on Latent Diffusion Models
abstract
Generative image steganography has gained significant attention due to its ability to hide secret data during image generation. However, existing generative image steganography methods still face challenges in terms of controllability, usability, and robustness, making it difficult to apply real-world scenarios. We propose a practical and robust generative image steganography based on Latent Diffusion Models, called LDStega. LDStega takes controllable condition text as input and designs an encoding strategy in the reverse process of the Latent Diffusion Models to couple latent space generation with data hiding. The encoding strategy selects a sampling interval from a candidate pool of truncated Gaussian distributions guided by secret data to generate the stego latent space. Subsequently, the stego latent space is fed into the Decoder to generate the stego image. The receiver extracts the secret data from the globally Gaussian distribution of the lossy-reconstructed latent space in the reverse process. Experimental results demonstrate that LDStega achieves high extraction accuracy while controllably generating image content and saving the stego image in the widely used PNG and JPEG formats. Additionally, LDStega outperforms state-of-the-art techniques in resisting common image attacks.
Yinyin Peng, Yaofei Wang, Donghui Hu, Kejiang Chen, Xianjin Rong, Weiming Zhang 0001
ACM Multimedia2
2024 SpotAttack: Covering Spots on Surface to Attack LiDAR-Based Autonomous Driving Systems
abstract
LiDAR significantly contributes to autonomous driving systems (ADSs) through its perception, prediction and decision layers. Recent research has focused on implementing adversarial attack on LiDAR-based ADS by generating perturbed point cloud adversarial samples. However, most state-of-the-art attacks focus on stationary scenarios, making it difficult to apply them in dynamic scenarios with multiframe point clouds. In this article, we introduce SpotAttack, a novel adversarial attack that targets specific areas of a vehicle’s surface using distributed patches. Unlike traditional adversarial mechanism that mislead the object classification through pixel perturbations, our designed spots decrease the reflectivity of LiDAR rays, causing the point clouds in these patches to be obscured. As a result, the 3-D object detection network will produce incorrect pose estimations based on the adversarial point cloud samples. To ensure the effectiveness of SpotAttack in dynamic scenarios, we establish a position matrix for multiobjective optimization and adopt genetic algorithm (GA) to address the nondifferentiable issue in spots generation. We conduct extensive experiments in three typical scenarios, and the results demonstrate that the proposed attack can manipulate LiDAR perception and influence ADS decision making.
Qiusheng Huang, Chen Gu, Yaofei Wang, Donghui Hu
IEEE Internet Things J.3
2024 HiFi-GANw: Watermarked Speech Synthesis via Fine-Tuning of HiFi-GAN
abstract
Advancements in speech synthesis technology bring generated speech closer to natural human voices, but they also introduce a series of potential risks, such as the dissemination of false information and voice impersonation. Therefore, it becomes significant to detect any potential misuse of the released speech content. This letter introduces an active strategy that combines audio watermarking with the HiFi-GAN vocoder to embed an invisible watermark in all synthesized speech for detection purposes. We first pre-train a watermark extraction network as the watermark extractor, and then use the watermark extraction loss and speech quality loss of the extractor to adjust the HiFi-GAN generator to ensure that the watermark can be extracted from the synthesized speech. We evaluate the imperceptibility and robustness of the watermark across various speech synthesis models. The experimental results demonstrate that our method effectively withstands various attacks and exhibits excellent imperceptibility. Moreover, our method is universal and compatible with various vocoder-based speech synthesis models.
Xiangyu Cheng, Yaofei Wang, Chang Liu 0089, Donghui Hu, Zhaopin Su
IEEE Signal Process. Lett.2
2024 Upward Robust Steganography Based on Overflow Alleviation
abstract
Images with low quality factor (QF) are widely available and apposite as steganography cover, which will be JPEG recompressed with a preset larger QF when uploaded to online social networks. This scenario is known as “Upward Robust,” which is currently a hotspot of robust steganography. The state-of-the-art algorithm is Generalized dither Modulation-based robust Adaptive Steganography (GMAS). However, GMAS can only realize limited resistance to detection and compression due to robust domain selection. To overcome this problem, we meticulously explore three lossy operations in JPEG recompression and discover that the key problem is spatial overflow. Then, two preprocessing methods, overall scaling (OS) and specific truncation (ST), were presented to remove overflow before message embedding and generate a reference image. After pre-processing, the stability of the image coefficients during JPEG recompression will be significantly enhanced. Therefore, we no longer need robust domain selection and all coefficients are eligible as cover, which improves security and embedding capacity. Additionally, the reference image was employed as guidance to build asymmetric distortion for removing overflow during embedding. Experimental results show that the proposed methods significantly surpass GMAS in terms of security and achieve comparable robustness.
Kejiang Chen, Weiming Zhang 0001, Yaofei Wang
IEEE Trans. Multim.4
2023 ICStega: Image Captioning-based Semantically Controllable Linguistic Steganography
abstract
Nowadays, social media has become the preferred communication platform for web users but brought security threats. Linguistic steganography hides secret data into text and sends it to the intended recipient to realize covert communication. Compared to edit-based linguistic steganography, generation-based approaches largely improve the payload capacity. However, existing methods can only generate stego text alone. Another common behavior in social media is sending semantically related image-text pairs. In this paper, we put forward a novel image captioning-based stegosystem, where the secret messages are embedded into the generated captions. Thus, the semantics of the stego text can be controlled and the secret data can be transmitted by sending semantically related image-text pairs. To balance the conflict between payload capacity and semantic preservation, we proposed a new sampling method called Two-Parameter Semantic Control Sampling to cutoff low-probability words. Experimental results have shown that our method can control diversity, payload capacity, security, and semantic accuracy at the same time.
Yaofei Wang, Kejiang Chen, Jinyang Ding, Weiming Zhang 0001, Nenghai Yu
ICASSP2
2023 StegaDDPM: Generative Image Steganography based on Denoising Diffusion Probabilistic Model
abstract
Image steganography is the technology of concealing secret messages within an image. Recently, generative image steganography has been developed, which conceals secret messages during image generation. However, existing generative image steganography schemes are often criticized for their poor steganographic capacity and extraction accuracy. To ensure secure and dependable communication, we propose a novel generative image steganography based on the denoising diffusion probabilistic model, called StegaDDPM. StegaDDPM utilizes the probability distribution between the intermediate state and generated image in the reverse process of the diffusion model. The secret message is hidden in the generated image through message sampling, which follows the same probability distribution as normal generation. The receiver uses two shared random seeds to reproduce the reverse process and accurately extract secret data. Experimental results show that StegaDDPM outperforms state-of-the-art methods in terms of steganographic capacity, extraction accuracy, and security. In addition, it can securely conceal and accurately extract secret messages up to 9 bits per pixel.
Yinyin Peng, Donghui Hu, Yaofei Wang, Kejiang Chen, Gang Pei, Weiming Zhang 0001
ACM Multimedia3
2023 Discop: Provably Secure Steganography in Practice Based on "Distribution Copies"
abstract
Steganography is the act of disguising the transmission of secret information as seemingly innocent. Although provably secure steganography has been proposed for decades, it has not been mainstream in this field because its strict requirements (such as a perfect sampler and an explicit data distribution) are challenging to satisfy in traditional data environments. The popularity of deep generative models is gradually increasing and can provide an excellent opportunity to solve this problem. Several methods attempting to achieve provably secure steganography based on deep generative models have been proposed in recent years. However, they cannot achieve the expected security in practice due to unrealistic conditions, such as the balanced grouping of discrete elements and a perfect match between the message and channel distributions. In this paper, we propose a new provably secure steganography method in practice named Discop, which constructs several "distribution copies" during the generation process. At each time step of generation, the message determines from which "distribution copy" to sample. As long as the receiver agrees on some shared information with the sender, he can extract the message without error. To further improve the embedding rate, we recursively construct more "distribution copies" by creating Huffman trees. We prove that Discop can strictly maintain the original distribution so that the adversary cannot perform better than random guessing. Moreover, we conduct experiments on multiple generation tasks for diverse digital media, and the results show that Discop’s security and efficiency outperform those of previous methods.
Jinyang Ding, Kejiang Chen, Yaofei Wang, Na Zhao 0009, Weiming Zhang 0001, Nenghai Yu
SP3
2023 Robust audio copy-move forgery detection on short forged slices using sliding window
Zhaopin Su, Mengke Li 0001, Guofu Zhang, Qinfang Wu, Yaofei Wang
J. Inf. Secur. Appl.5
2023 Robust Steganography for High Quality Images
abstract
With the prosperity of online social networks (OSNs), people usually share photos taken with their mobile phones to OSN, which is suitable for covert communication. However, these images have high quality factors (QFs) and will be JPEG recompressed with low QFs by OSNs, which precludes existing robust steganography methods using low QF images. Therefore, we propose a Postprocessing and precise dither Modulation based robust Adaptive Steganography method (PMAS) for high quality images. Precise dither modulation ensures the robustness of the modified coefficients and improves security by reducing the magnitude of modifications. Postprocessing amends the coefficients that changed after recompression to ensure the robustness of unmodified coefficients. Additionally, we devise heuristics to mitigate post-processing and explore the relationship between the modification magnitude and distortion assignment with novel scaling functions, which all contribute to security. The experimental results demonstrate that PMAS is competent for high quality images, and the effect of every module in PMAS is verified.
Kejiang Chen, Weiming Zhang 0001, Yaofei Wang, Nenghai Yu
IEEE Trans. Circuits Syst. Video Technol.4
2023 Cover Reproducible Steganography via Deep Generative Models
abstract
Whereas cryptography easily arouses attacks by means of encrypting a secret message into a suspicious form, steganography is advantageous for its resilience to attacks by concealing the message in an innocent-looking cover signal. Minimal distortion steganography, one of the mainstream steganography frameworks, embeds messages while minimizing the distortion caused by the modification on the cover elements. Due to the unavailability of the original cover signal for the receiver, message embedding is realized by finding the coset leader of the syndrome function of steganographic codes migrated from channel coding, which is complex and has limited performance. Fortunately, deep generative models and the robust semantic of generated data make it possible for the receiver to perfectly reproduce the cover signal from the stego signal. With this advantage, we propose cover-reproducible steganography where the source coding, e.g., arithmetic coding, serves as the steganographic code. Specifically, the decoding process of arithmetic coding is used for message embedding and its encoding process is regarded as message extraction. Taking text-to-speech and text-to-image synthesis tasks as two examples, we illustrate the feasibility of cover-reproducible steganography. Steganalysis experiments and theoretical analysis are conducted to demonstrate that the proposed methods outperform the existing methods in most cases.
Kejiang Chen, Hang Zhou 0007, Yaofei Wang, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.3
2022 An Effective Steganalysis for Robust Steganography with Repetitive JPEG Compression
abstract
With the development of social networks, traditional covert communication requires more consideration of lossy processes of Social Network Platforms (SNPs), which is called robust steganography. Since JPEG compression is a universal processing of SNPs, a method using repeated JPEG compression to fit transport channel matching is recently proposed and shows strong compression-resist performance. However, the repeated JPEG compression will inevitably introduce other artifacts into the stego image. Using only traditional steganalysis methods does not work well towards such robust steganography under low payload. In this paper, we propose a simple and effective method to detect the mentioned steganography by chasing both steganographic perturbations as well as continuous compression artifacts. We introduce compression-forensic features as a complement to steganalysis features, and then use the ensemble classifier for detection. Experiments demonstrate that this method owns a similar and better performance with respect to both traditional and neural-network-based steganalysis.
Jinliu Feng, Yaofei Wang, Kejiang Chen, Weiming Zhang 0001, Nenghai Yu
ICASSP2
2022 Improving robust adaptive steganography via minimizing channel errors
Kejiang Chen, Weiming Zhang 0001, Yaofei Wang, Nenghai Yu
Signal Process.4
2021 BBC++: Enhanced Block Boundary Continuity on Defining Non-Additive Distortion for JPEG Steganography
abstract
Recently, Li et al. proposed an effective non-additive distortion model for JPEG steganography by preserving Block Boundary Continuity (BBC) in the spatial domain. However, the method based on BBC only explored how the modifications of DCT coefficient pairs at the same mode in adjacent blocks will impact on BBC. In this paper, we propose a method to enhance the BBC, called BBC++, by considering the mutual impact on the BBC from all DCT coefficients in adjacent blocks. To do that, we design updating strategies for both covers and costs in multi-round embedding processions. During the embedding, the cover is updated to repair the BBC after embedding and the corresponding costs are updated to keep the BBC from being destroyed in the next embedding. Experimental results show that the BBC++ can better maintain BBC and outperform previous non-additive distortion steganography when resisting modern JPEG steganalyzers.
Yaofei Wang, Weixiang Li, Weiming Zhang 0001, Xinzhi Yu, Kunlin Liu, Nenghai Yu
IEEE Trans. Circuits Syst. Video Technol.1
2021 Non-Additive Cost Functions for JPEG Steganography Based on Block Boundary Maintenance
abstract
Recent advances show that a reasonable non-additive cost function can significantly improve the security level of additive cost based steganography. So far, there is only one principle, called block boundary continuity (BBC), that has been proposed to define the non-additive cost function for JPEG steganography, and it aims at synchronizing the modification direction of inter-block boundaries in the spatial domain. In this article, we found that JPEG steganography usually introduces more and larger modifications on the boundary than on the inside of each intra-block in the spatial domain, which is another important factor affecting security. Therefore, we present a new principle, called block boundary maintenance (BBM), to minimize the modifications on the spatial block boundaries. In theory, we deduce the BBM principle on how to modify a pair of DCT coefficients of the intra-block to reduce the modifications on the spatial block boundary. According to the BBM principle, we design a new strategy to define non-additive cost functions for JPEG steganography by exploiting the coefficient correlation of the intra-block in the DCT domain. The experimental results show that the BBM-based strategy can minimize modifications on the spatial block boundaries and thus achieve a high-security level when resisting modern JPEG steganalysis. Furthermore, the two principles of BBC and BBM can be fused to further improve the empirical security.
Yaofei Wang, Weiming Zhang 0001, Weixiang Li, Nenghai Yu
IEEE Trans. Inf. Forensics Secur.1
2020 Robust adaptive steganography based on generalized dither modulation and expanded embedding domain
Xinzhi Yu, Kejiang Chen, Yaofei Wang, Weixiang Li, Weiming Zhang 0001, Nenghai Yu
Signal Process.3
2020 JPEG Steganography With Estimated Side-Information
abstract
Previous studies have exhibited that incorporating side-information, e.g., a high-quality precover image, can significantly improve steganographic security for JPEG images. This motivates us to estimate the side-information for traditional steganographic scenario in which only a JPEG image is available. It is expected to achieve high-level security by utilizing the estimated side-information similar to side-informed steganography, even though the estimated side-information is not perfectly precise. In this paper, a general framework of side-information estimated (SIE) JPEG steganography is proposed, under which the core problems are how to better estimate the precover and modulate the distortion function correspondingly. To address the two problems, we test several denoising filters and a deblocking filter to obtain the estimated precover, and we introduce two implementation models for modulating the costs. We finally recommend the combination of the deblocking filter and the modulation model using the polarity of the estimated rounding error. The experimental results show that the proposed method dramatically improves the existing additive distortions for images of an arbitrary quality factor and outperforms the state-of-the-art methods based on estimating side-information when resisting modern steganalysis.
Weixiang Li, Kejiang Chen, Weiming Zhang 0001, Hang Zhou 0007, Yaofei Wang, Nenghai Yu
IEEE Trans. Circuits Syst. Video Technol.5
2020 Non-Additive Cost Functions for Color Image Steganography Based on Inter-Channel Correlations and Differences
abstract
Despite the strong presence of color images for communication, scholars have mainly devoted their attention to research on steganography for grayscale images. In contrast to grayscale images, color images have three interrelated color channels, and the relationships among the three channels have a strong impact on the steganography security. In this paper, we present a steganographic scheme for spatial color images by exploiting the correlations and differences between the color channels. We find that the G channel has a stronger correlation with R and B than the one between R and B, and thus, synchronizing the modification directions of the R and B channels with those from the G channel will have better resistance to detection. In addition, the payload capacity and the distribution of complex regions between channels are different. Based on these findings, we design a new strategy for defining non-additive costs for color image steganography, called G-channel-related Inter-channel Non-Additive (GINA) strategy. The GINA strategy can make the modification directions of the R and B channels consistent with those of the G channel and can adaptively distribute the embedding capacity between the three channels. Specifically, this strategy will not violate the Complexity Prior rule. The experimental results show that the proposed GINA strategy can significantly improve the performance in terms of resisting color image steganalysis compared with previous methods.
Yaofei Wang, Weiming Zhang 0001, Weixiang Li, Xinzhi Yu, Nenghai Yu
IEEE Trans. Inf. Forensics Secur.1
2018 Improving the Embedding Strategy for Batch Adaptive Steganography
Xinzhi Yu, Kejiang Chen, Weiming Zhang 0001, Yaofei Wang, Nenghai Yu
IWDW4