Xianbo Mo

dblp:289/1669 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0001-9198-5041ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Active Adversarial Noise Suppression for Image Forgery Localization
abstract
Recent advances in deep learning have significantly propelled the development of image forgery localization. However, existing models remain highly vulnerable to adversarial attacks: imperceptible noise added to forged images can severely mislead these models. In this paper, we address this challenge with an Adversarial Noise Suppression Module (ANSM) that generates a defensive perturbation to suppress the attack effect of adversarial noise. We observe that forgery-relevant features extracted from adversarial and original forged images exhibit distinct distributions. To bridge this gap, we introduce Forgery-relevant Features Alignment (FFA) as a first-stage training strategy, which reduces distributional discrepancies by minimizing the channel-wise Kullback-Leibler divergence between these features. To further refine the defensive perturbation, we design a second-stage training strategy, termed Mask-guided Refinement (MgR), which incorporates a dual-mask constraint. MgR ensures that the defensive perturbation remains effective for both adversarial and original forged images, recovering forgery localization accuracy to their original level. Extensive experiments across various attack algorithms demonstrate that our method significantly restores the forgery localization model's performance on adversarial images. Notably, when ANSM is applied to original forged images, the performance remains nearly unaffected. To our best knowledge, this is the first report of adversarial defense in image forgery localization tasks.
Rongxuan Peng, Shunquan Tan, Xianbo Mo, Alex Chichung Kot, Jiwu Huang
IEEE Trans. Pattern Anal. Mach. Intell.3
2026 Query-Efficient Hard-Label Attacks Against Black-Box Image Forgery Localization Model via Reinforcement Learning
abstract
Deep learning-based image forgery localization models are increasingly deployed in real-world forensic services, yet their robustness against black-box adversarial manipulation remains insufficiently understood, calling for practical anti-forensics techniques to expose potential security weaknesses. Prior adversarial anti-forensics studies for forgery localization mainly assume white-box access, which limits their applicability to deployed systems where only hard, mask-like outputs are available and queries are tightly constrained. To bridge this gap, we propose AdvFor, a query-efficient black-box attack frame-work tailored for forgery localization with hard-label, mask-only, spatially dense binary feedback. AdvFor formulates the attacker–model interaction as a finite-horizon Markov Decision Process and learns a transferable attack policy from hard-mask feedback. Once trained, AdvFor can be deployed via fixed-length policy execution with onlyT=7 queries per image, avoiding per-image boundary refinement or query-dense direction/gradient estimation. The learned policy optimizes a structured objective—progressively suppressing forgery responses in the predicted localization mask so that the masks of forgery images approach an authentic-like (near-zero) output—while maintaining visual fidelity. Extensive experiments on six benchmark datasets and multiple modern forgery localization models demonstrate that AdvFor consistently achieves stronger attack performance than representative baselines under the same perturbation constraints, while operating in an ultra-low-query regime.We further validate AdvFor under common deployment-style defenses, showing its notable effectiveness in realistic settings.
Xianbo Mo, Shunquan Tan, Rongxuan Peng, Bin Li 0011, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.1
2025 Query-efficient Attack for Black-box Image Inpainting Forensics via Reinforcement Learning
abstract
Recently, image inpainting has become a common tool for manipulating nature images in a malicious manner, which has led to the rapid advancement of inpainting forensics. Although current forensics methods have shown precise location of inpainting regions and reliable robustness against image post-processing operations, it remains unclear whether they can effectively resist the possible attacks in real-world scenarios. To identify potential flaws, we propose a novel black-box anti-forensics framework to attack inpainting forensics methods, which employs reinforcement learning to generate a query-efficient countermeasure, named RLGC. To this end, we define reinforcement learning paradigm to model the Markov Decision Process of query-based black-box anti-forensics scenario. Specifically, pixel-wise agents are used to modulate anti-forensics images based on action selection and query forensics methods to obtain corresponding outputs. Later, reward function evaluates attack effect and image distortion with these outputs. To maximize the cumulative reward, policy and value networks are integrated and trained by Asynchronous Advantage Actor-Critic algorithm. Experimental results demonstrate that, without visually detectable distortion on anti-forensics images, RLGC achieves remarkable attack effects in a highly query-effcient way against various black-box inpainting forensics methods, even outperforming the most representative white-box attack method.
Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang
AAAI1
2024 A Keyless Extraction Framework Targeting at Deep Learning Based Image-Within-Image Models
abstract
Image-within-image technique aims to establish covert communication by concealing a secret image within a cover image. Compared with traditional steganography algorithms, the security of image-within-image technique has not been rigorously evaluated by steganalysis. Existing attack methods just brutally destroy the container image, resulting in the secret image cannot be revealed by the original decryption model (key). This paper introduces a novel keyless extraction framework, carrying out steganalysis on the container image without destroying it. Our approach utilizes collected pairs of container and revealed images to construct a master key, enabling us to extract secret image from container image without relying on the original key. Remarkably, the master key remains effective for multiple image-within-image techniques simultaneously, even when their encryption and decryption models are re-trained. In addition, we propose a patch-based data augmentation technique to adapt to scenarios with limited training samples, and we design a weighted loss function with three components to further enhance the visual quality of the extracted secret image. All the experiments are conducted on datasets derived from ImageNet, COCO and DIV2k. The results demonstrate that our approach can extract secret images with comparable visual quality to the original ones.
Rongxuan Peng, Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang
ICASSP2
2024 Employing Reinforcement Learning to Construct a Decision-Making Environment for Image Forgery Localization
abstract
The widespread misuse of advanced image editing tools and deep generative techniques has led to a proliferation of images with altered content in real-life scenarios, often without any discernible traces of tampering. This has created a potential threat to security and credibility of images. Image forgery localization is an urgent technique. In this paper, we propose a novel reinforcement learning-based framework CoDE (Construct Decision-making Environment) that can provide reliable localization result of tampered area in forged images. We model the forgery localization task as a Markov Decision Process (MDP), where each pixel is equipped with an agent that performs Gaussian distribution-based continuous action to iteratively update the respective forgery probability, so as to achieve pixel-level image forgery localization. In order to construct the state transitions within MDP, we propose a twin-flow state encoder to handle the updated state, which consists of the forged image and its corresponding forgery probability map. What’s more, considering that the tampered area is often sparse in practical image tampering scenarios, we design a reward function specifically for these sparse tampered area. This reward function can guide the agent to more effectively learn the optimal strategy for maximizing the cumulative reward. Extensive experiments conducted on a variety of benchmark datasets demonstrate CoDE’s superior localization accuracy and robustness against image degradation caused by transmission through Online Social Networks (OSNs) and various post-processing attacks.
Rongxuan Peng, Shunquan Tan, Xianbo Mo, Bin Li 0011, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.3
2023 Poster: Query-efficient Black-box Attack for Image Forgery Localization via Reinforcement Learning
abstract
Recently, deep learning has been widely used in forensics tools to detect and localize forgery images. However, its susceptibility to adversarial attacks highlights the need for the exploration of anti-forensics research. To achieve this, we introduce an innovative and query-efficient black-box anti-forensics framework tailored for the generation of adversarial forgery images. This framework is designed to simulate the query dynamics of online forensic services, utilizing a Markov Decision Process formulation within the paradigm of reinforcement learning. We further introduce a novel reward function, which evaluates the efficacy of attacks based on the disjunction between query results and attack targets. To improve the query efficiency of these attacks, an actor-critic algorithm is employed to maximize cumulative rewards. Empirical findings substantiate the efficacy of our proposed methodology. Specifically, it demonstrates pronounced adversarial effects on a range of prevailing image forgery detectors, while ensuring negligible visually perceptible distortions in the resultant anti-forensics images.
Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang
CCS1
2023 ReLOAD: Using Reinforcement Learning to Optimize Asymmetric Distortion for Additive Steganography
abstract
Recently, the success of non-additive steganography has demonstrated that asymmetric distortion can remarkably improve security performance compared with symmetric cost functions. However, most of current existing additive steganographic methods are still based on symmetric distortion. In this paper, for the first time we optimize asymmetric distortion for additive steganography and propose an A3C (Asynchronous Advantage Actor-Critic) based steganographic framework, called ReLOAD. ReLOAD is composed of an actor and a critic, where the former guides action selection for pixel-wise distortion modulation, and the latter evaluates the performance of modulated distortion. Meanwhile, a reward function that considers embedding effects is proposed to unify the goal of steganography and reinforcement learning, so that the minimization of embedding effects can be achieved by learning secure policy to maximize total rewards. Statistical analysis shows that compared with non-additive steganography, ReLOAD achieves lower change rates and makes embedding traces more consistent with cover image textures. Comprehensive experiments conducted on both hand-crafted feature-based and deep learning-based steganalyzers show that ReLOAD significantly promotes the state-of-the-art security performance of current additive methods and even outperforms non-additive steganography when the modification distribution gets sparser.
Xianbo Mo, Shunquan Tan, Weixuan Tang 0004, Bin Li 0011, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.1
2021 MCTSteg: A Monte Carlo Tree Search-Based Reinforcement Learning Framework for Universal Non-Additive Steganography
abstract
Recent research has shown that non-additive image steganographic frameworks effectively improve security performance through adjusting distortion distribution. However, as far as we know, all of the existing non-additive proposals are based on handcrafted policies, and can only be applied to a specific image domain, which heavily prevent non-additive steganography from releasing its full potentiality. In this paper, we propose an automatic non-additive steganographic distortion learning framework called MCTSteg to remove the above restrictions. Guided by the reinforcement learning paradigm, we combine Monte Carlo Tree Search (MCTS) and steganalyzer-based environmental model to build MCTSteg. MCTS makes sequential decisions to adjust distortion distribution without human intervention. Our proposed environmental model is used to obtain feedbacks from each decision. Due to its self-learning characteristic and domain-independent reward function, MCTSteg has become the first reported universal non-additive steganographic framework which can work in both spatial and JPEG domains. Extensive experimental results show that MCTSteg can effectively withstand the detection of both hand-crafted feature-based and deep-learning-based steganalyzers. In both spatial and JPEG domains, the security performance of MCTSteg steadily outperforms the state of the art by a clear margin under different scenarios.
Xianbo Mo, Shunquan Tan, Bin Li 0011, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.1