Jiansong Zhang 0006

dblp:38/6831-6 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-9288-8665ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Leveraging Fluctuations of Black-Box Generative Models for Secure Deep Image Steganography
abstract
Image steganography is an essential technique for concealing information by embedding secret information within images to make it undetectable. In recent years, with the rapid development and popularization of text-to-image generation models, many generated images have been disseminated through the Internet, thus making generated images ideal covers for steganography. Given that the distribution of generated images is more easily modeled than natural images, steganographic methods based on generated images exhibit higher security. Nevertheless, these methods typically require white-box access to the generative model, while contemporary popular generative models are black-box models. We observed that slight modifications in the input parameters of black-box image generative models result in subtle differences between generated images, offering new camouflage advantages for image steganography. Based on this observation, we propose an image steganography method based on the fluctuation of generative models. This approach leverages the fluctuation of image generative models, disguising stego images to appear as if they were generated by the parameter fluctuations of the generative model. Experimental results show that our proposed method outperforms baseline methods when facing steganalysis attacks, significantly enhancing steganographic security without compromising image quality.
Xiangkun Wang, Kejiang Chen, Jiansong Zhang 0006, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.3
2025 Reversible adversarial visible image watermarking
abstract
Visible watermarking serves as a crucial security mechanism for safeguarding the copyright of digital images. Recent advancements, however, have shown that deep neural networks can effectively remove these watermarks without altering the underlying host image, posing a substantial risk to copyright protection . Motivated by the susceptibility of neural networks to adversarial perturbations, various adversarial visible watermarking techniques have been introduced. Nonetheless, these approaches often overlook the need for image reversibility, which is vital for authorized sharing while maintaining privacy. To address this issue, we propose R eversible A dversarial V isible W atermarking (RAVW), which uses Gradient-weighted Class Activation Mapping (Grad-CAM) to pinpoint the important regions in the host image that are optimal for watermark embedding . It then employs an end-to-end generative model to create reversible adversarial visible watermarks within these regions, effectively counteracting watermark removal networks. Additionally, authorized users can eliminate the visible watermark via a dedicated restoration module. Comprehensive experimental evaluations confirm the robustness of our method in preserving visible watermarks and its effectiveness against watermark removal networks.
Xue Xie, Jiansong Zhang 0006, Kejiang Chen, Weiming Zhang 0001, Nenghai Yu
Signal Process.3
2024 Steganography With Generated Images: Leveraging Volatility to Enhance Security
abstract
The development of generative AI applications has revolutionized the data environment for steganography, providing a new source of steganographic cover. However, existing generative data-based steganography methods typically require white-box access, rendering them unsuitable for black-box generative models. To overcome this limitation, we propose a novel steganography method for generated images, which leverages the volatility of generative models and is applicable in black-box scenarios. The volatility of generative models refers to the ability to generate a series of images with slight variations by fine-tuning the input parameters of the model. These generated images exhibit varying degrees of volatility in different areas. To resist steganalysis, we mask steganographic modifications by confusing them with the inherent volatility of the model. Specifically, by modeling distributions of generated pixels and estimating the parameters of the distributions, the occurrence probabilities of generated pixels can be obtained, which serve as an effective measure for steganographic modification probabilities to render stego images as indistinguishable as possible from the images producible by the model. Moreover, we further combine it with existing costs to develop a more comprehensive steganographic algorithm. Experimental results show that the proposed method significantly outperforms baseline and comparative methods in resisting both feature-based and CNN-based steganalyzers.
Jiansong Zhang 0006, Kejiang Chen, Weixiang Li, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.1
2024 AAS: Automatic Virtual Data Augmentation for Deep Image Steganalysis
abstract
In recent years, steganalysis based on deep learning has evolved rapidly. However, training deep learning models is data-consuming. The models are prone to overfitting when data is limited. Data augmentation is an effective method to mitigate overfitting. Existing data augmentation methods in steganalysis can be categorized into cover enrichment and virtual augmentation. They are used in different stages. Cover enrichment refers to introducing additional cover-stego pairs in some ways, which is performed prior to training. In contrast, virtual augmentation augments data during training. Existing virtual augmentation methods are designed heuristically and rely on expert knowledge. In this paper, we propose the first automatic virtual data augmentation method for steganalysis. Specifically, we design an augmentation network that augments cover and stego images by intelligently adding noises. The augmentation network is trained adversarially with the steganalyzer to generate diverse data. Meanwhile, a “class-invariant” module prevents the augmentation network from changing the original data distribution too much. A “stabilizer” loss function is designed that keeps the adversarial training stable by constraining the number of noises. The experimental results show that the proposed method outperforms existing virtual augmentation methods. Moreover, combining the proposed method and cover enrichment can further boost performance.
Jiansong Zhang 0006, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.1
2024 Natias: Neuron Attribution-Based Transferable Image Adversarial Steganography
abstract
Image steganography is a technique to conceal secret messages within digital images. Steganalysis, on the contrary, aims to detect the presence of secret messages within images. Recently, deep-learning-based steganalysis methods have achieved excellent detection performance. As a countermeasure, adversarial steganography has garnered considerable attention due to its ability to effectively deceive deep-learning-based steganalysis. However, steganalysts often employ unknown steganalytic models for detection. Therefore, the ability of adversarial steganography to deceive non-target steganalytic models, known as transferability, becomes especially important. Nevertheless, existing adversarial steganographic methods do not consider how to enhance transferability. To address this issue, we propose a novel adversarial steganographic scheme named Natias. Specifically, we first attribute the output of a steganalytic model to each neuron in the target middle layer to identify critical features. Next, we corrupt these critical features that may be adopted by diverse steganalytic models. Consequently, it can promote the transferability of adversarial steganography. Our proposed method can be seamlessly integrated with existing adversarial steganography frameworks. Thorough experimental analyses affirm that our proposed technique possesses improved transferability when contrasted with former approaches, and it attains heightened security in retraining scenarios.
Zexin Fan, Kejiang Chen, Jiansong Zhang 0006, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Inf. Forensics Secur.4
2024 Toward Secure and Robust Steganography for Black-Box Generated Images
abstract
The progression of text-to-image generation models has incited an upsurge in disseminating generated images across social networks, providing a fertile ground for steganography. Presently, the majority of generated images are crafted utilizing black-box APIs and social networks employ lossy compression on uploaded images. However, there is a dearth of steganographic research conducted on black-box generated images, and the distinctive attributes of the generation model have not been harnessed, resulting in a performance that fails to achieve both security and robustness simultaneously. To address these challenges, we propose an innovative steganographic framework, Steganography based on Concomitantly shaRing generated Images and PrompTs (SCRIPT). This framework ensures security and robustness by precisely identifying robust coefficients within the image for message embedding and synchronizing their positions. For precise identification, we assess the ability of coefficients to withstand unknown spatial perturbations, employing this metric to quantify their robustness. For positional synchronization of robust coefficients, the relevant prompts are uploaded alongside the stego image, allowing the recipient to reconstruct the cover image using a mutually agreed random seed and the provided prompt. Subsequently, positional synchronization is achieved by consistently adopting an identical method for selecting robust coefficients between the sender and the recipient. By amalgamating these strategies, SCRIPT significantly surpasses prior algorithms. Empirical results validate our approach, with a noteworthy 98% message extraction success rate and a substantial 20%+ enhancement in security across diverse payloads.
Kejiang Chen, Jiansong Zhang 0006, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Inf. Forensics Secur.3
2022 Distribution-Preserving-Based Automatic Data Augmentation for Deep Image Steganalysis
abstract
In recent years, deep learning-based steganalyzers far outperformed handcrafted feature-based steganalyzers. However, a large amount of data is needed to train deep learning networks. For steganalysis tasks, the steganographic traces are subtle and the steganographic signals are difficult to be captured when the number of cover/stego pairs in the training set is insufficient. Data augmentation has been proved to be effective in improving accuracy and generalization for deep learning models. Yet not all data augmentation methods are universal for all tasks. When performing data augmentation, we argue that data distribution under the target tasks should be maintained. Since the steganalysis task is more concerned with the high-frequency signals of the images, if the high-frequency signals are unchanged, the data distribution from the perspective of steganalysis will remain largely unchanged. Based on this principle, we designed a neural network called cover augmentation network, which enriches the dataset by intelligently adding noise to the original cover to generate the augmented cover. Further, we designed a whole process of data augmentation based on the cover augmentation network. Experimental results show that the proposed data augmentation method can effectively improve the performance of steganalysis networks, and the advantage is significant at low payloads.
Jiansong Zhang 0006, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu
IEEE Trans. Multim.1