EDBT 2026 Demo / reviewers in the wild / expert
Zhao-Xia Yin
dblp:63/7483 · also Zhaoxia Yin
· DBLP profile ↗
57ranked-venue papers
15as first author
37since 2021 · last 2026
0000-0003-0387-4806ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 31 · 9 first-author · 19 since 2021Artificial intelligence and machine learning · 16 · 2 first-author · 14 since 2021Security and privacy · 11 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RFNNS: Robust Fixed Neural Network Steganography with Universal Text-to-Image ModelsabstractWith the rapid development of generative AI, image steganography has garnered widespread attention due to its unique concealment. Recent studies have demonstrated the practical advantages of Fixed Neural Network Steganography (FNNS), notably its ability to achieve stable information embedding and extraction without any additional network training. However, the stego images generated by FNNS still exhibit noticeable distortion and limited robustness. These drawbacks compromise the security of the embedded information and restrict the practical applicability of the method. To address these limitations, we propose Robust Fixed Neural Network Steganography (RFNNS). Specifically, a texture-aware localization technique selectively embeds perturbations carrying secret information into regions of complex textures, effectively preserving visual quality. Additionally, a robust steganographic perturbation generation (RSPG) strategy is designed to enhance the decoding accuracy, even under common and unknown attacks. These robust perturbations are combined with AI-generated cover images to produce stego images. Experimental results demonstrate that RFNNS significantly improves robustness compared to state-of-the-art FNNS methods, achieving an average increase in SSIM of 23% for recovered secret images under common attacks. Furthermore, the LPIPS value of recovered secrets images against previously unknown attacks achieved by RFNNS was reduced to 39% of the SOTA method, underscoring its practical value for covert communication. Yu Cheng 0013, Jiuan Zhou, Zhao-Xia Yin, Xinpeng Zhang 0001 |
AAAI | 4 |
| 2026 | Red Teaming Large Reasoning ModelsabstractJiawei Chen, Yang Yang, Chao Yu, Yu Tian, Zhi Cao, Xue Yang, Linghao Li, Hang Su, Zhaoxia Yin. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Linghao Li, Hang Su 0006, Zhao-Xia Yin |
ACL (1) | 9 |
| 2026 | A survey of fragile model watermarking
Zhenzhe Gao, Yu Cheng 0013, Zhao-Xia Yin |
Signal Process. | 3 |
| 2026 | Generative Image Steganography With Minimum-Distance GuidanceabstractImage steganography conceals secret data within a digital image while preserving its innocent appearance. The advent of artificial intelligence generative models has given rise to a new paradigm known as generative image steganography, which hides secret data directly into the image generation process. However, existing generative image steganographic methods are typically only applicable to unquantized stego images, severely limiting their practicality in real-world scenarios. To address this limitation, we propose a generative image steganography with minimum-distance guidance based on a diffusion model, called MDStega. During the hiding phase, MDStega designs a secret data-driven residual image sampling mechanism, which establishes a dynamic mapping relationship between discrete secret data and continuous probability distributions, strictly preserving the distribution consistency between stego images and normally generated images. During the extraction phase, the minimum-distance guidance rule effectively suppresses the interference caused by stego image quantization on the extraction accuracy of secret data. Furthermore, MDStega does not require fine-tuning pre-trained models or training additional models, which significantly reduces computational overhead and training time. Experimental results demonstrate that MDStega is superior to state-of-the-art methods by not only ensuring secure concealment at 3 bits per pixel (bpp) in PNG format but also achieving a recovery accuracy of up to 99%, demonstrating strong practical potential. Yinyin Peng, Chengjie Gu, Donghui Hu, Yaofei Wang, Xianjin Rong, Zhao-Xia Yin |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Protecting Copyright of Medical Pre-trained Language Models: Training-Free Backdoor Model WatermarkingabstractWith the advancement of intelligent healthcare, medical pre-trained language models (Med-PLMs) have emerged and demonstrated significant effectiveness in downstream medical tasks. While these models are valuable assets, they are vulnerable to misuse and theft, requiring copyright protection. However, existing watermarking methods for pre-trained language models (PLMs) cannot be directly applied to Med-PLMs due to domain-task mismatch and inefficient watermark embedding. To fill this gap, we propose the first training-free backdoor model watermarking for Med-PLMs, employing low-frequency words as triggers and embedding the watermark by replacing their embeddings in the model's word embedding layer with those of specific medical terms. The watermarked Med-PLMs produce the same output for triggers as for the corresponding specified medical terms. We leverage this unique mapping to design tailored watermark extraction schemes for different downstream tasks, addressing the challenge of domain-task mismatch in previous methods. Experiments demonstrate superior effectiveness of our watermarking method across medical downstream tasks, robustness against model extraction, pruning, fusion-based backdoor removal attacks, and high efficiency with 10-second embedding. Our code is available at https://github.com/edu-yinzhaoxia/Med-PLMW. Cong Kong, Zhao-Xia Yin |
ACM Multimedia | 4 |
| 2025 | Robust steganography with boundary-preserving overflow alleviation and adaptive error correction
Yu Cheng 0013, Zhenlin Luo, Zhao-Xia Yin |
Expert Syst. Appl. | 3 |
| 2025 | Efficient and transferable reversible adversarial attacks utilizing YUV color space
Yu-Cheng Fan, Zhao-Xia Yin |
Neurocomputing | 2 |
| 2025 | Adversarial Examples Detection With Enhanced Image Difference Features Based on Local Histogram EqualizationabstractDeep Neural Networks (DNNs) have recently made significant strides in various fields; however, they are susceptible to adversarial examples—crafted inputs with imperceptible perturbations that can mislead these networks. Notably, even when adversaries lack access to the complete model parameters, they can still generate adversarial examples targeting a range of DNN-based task systems. Various defense mechanisms have been proposed, such as feature compression and gradient masking. Nevertheless, extensive research indicates that these methods often address only specific attacks, rendering them ineffective against novel and unknown attack strategies. Recent studies have highlighted the efficacy of identifying adversarial examples in the frequency domain; however, these approaches are limited to frequency-based analysis. In this study, we experimentally observe that adversarial examples possess significant characteristics in local regions. Specifically, adversarial perturbations exhibit localized randomness, whereas the high-frequency information in normal examples is both locally coherent and semantically relevant. This critical distinction enables effectively distinguishing adversarial examples from normal ones. To leverage this insight, we aim to enhance the high-frequency features of input examples to amplify their feature disparities. We propose an image enhancement method utilizing local histogram equalization. Our experimental results demonstrate that this method substantially improves detector performance without modifying the existing detection models. Furthermore, this technique can be seamlessly integrated with task models, effectively reducing deployment costs in practical applications. Zhao-Xia Yin, Hang Su 0006, Jianteng Peng, Bin Luo 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Fragile Model Watermark for integrity protection: leveraging boundary volatility and sensitive sample-pairingabstractNeural networks have increasingly influenced people’s lives. Ensuring the faithful deployment of neural networks as designed by their model owners is crucial, as they may be susceptible to various malicious or unintentional modifications, such as backdooring and poisoning attacks. Fragile model watermarks aim to prevent unexpected tampering that could lead DNN models to make incorrect decisions. They ensure the detection of any tampering with the model as sensitively as possible. However, prior watermarking methods suffered from inefficient sample generation and insufficient sensitivity, limiting their practical applicability. Our approach employs a sample-pairing technique, placing the model boundaries between pairs of samples, while simultaneously maximizing logits. This ensures that the model’s decision results of sensitive samples change as much as possible and the Top-1 labels easily alter regardless of the direction it moves. Experimental evaluations conducted across multiple models and datasets demonstrate the superior sensitivity and generation efficiency of our method compared to the current approaches. Zhenzhe Gao, Zhenjun Tang, Zhao-Xia Yin, Baoyuan Wu, Yue Lu 0001 |
ICME | 3 |
| 2024 | Medical Image Classification Attack Based on Texture Manipulation
Yunrui Gu, Cong Kong, Zhao-Xia Yin, Yan Wang 0033, Qingli Li |
ICPR (12) | 3 |
| 2024 | Copyright Protection for Large Language Model EaaS via Unforgeable Backdoor Watermarking
Cong Kong, Shunquan Tan, Zhao-Xia Yin, Xinpeng Zhang 0001 |
ICPR (20) | 4 |
| 2024 | Exploring the Robustness of Decision-Level Through Adversarial Attacks on LLM-Based Embodied ModelsabstractEmbodied intelligence empowers agents with a profound sense of perception, enabling them to respond in a manner closely aligned with real-world situations. Large Language Models (LLMs) delve into language instructions with depth, serving a crucial role in generating plans for intricate tasks. Thus, LLM-based embodied models further enhance the agent's capacity to comprehend and process information. However, this amalgamation also ushers in new challenges in the pursuit of heightened intelligence. Specifically, attackers can manipulate LLMs to produce irrelevant or even malicious outputs by altering their prompts. Confronted with this challenge, we observe a notable absence of multi-modal datasets essential for comprehensively evaluating the robustness of LLM-based embodied models. Consequently, we construct the Embodied Intelligent Robot Attack Dataset (EIRAD), tailored specifically for robustness evaluation. Additionally, two attack strategies are devised, including untargeted attacks and targeted attacks, to effectively simulate a range of diverse attack scenarios. At the same time, during the attack process, to more accurately ascertain whether our method is successful in attacking the LLM-based embodied model, we devise a new attack success evaluation method utilizing the BLIP2 model. Recognizing the time and cost-intensive nature of the GCG algorithm in attacks, we devise a scheme for prompt suffix initialization based on various target tasks, thus expediting the convergence process. Experimental results demonstrate that our method exhibits a superior attack success rate when targeting LLM-based embodied models, indicating a lower level of decision-level robustness in these models. Shuyuan Liu, Shouwei Ruan, Hang Su 0006, Zhao-Xia Yin |
ACM Multimedia | 5 |
| 2024 | Semi-fragile neural network watermarking for content authentication and tampering localization
Zihan Yuan, Xinpeng Zhang 0001, Zichi Wang, Zhao-Xia Yin |
Expert Syst. Appl. | 4 |
| 2024 | Reversible attack based on local visible adversarial perturbation
Abel Andrew, Zhao-Xia Yin |
Multim. Tools Appl. | 4 |
| 2024 | Adaptive watermarking with self-mutual check parameters in deep neural networks
Zhenzhe Gao, Zhao-Xia Yin, Hongjian Zhan, Yue Lu 0001 |
Pattern Recognit. Lett. | 2 |
| 2024 | General Pairwise Modification Framework for Reversible Data Hiding in JPEG ImagesabstractPairwise modification is one of the most effective ways to solve the critical issues of balancing the embedding capacity, image distortion, and file expansion in JPEG reversible data hiding (RDH). To design a satisfactory scheme based on pairwise modification, existing schemes focus on improving pairing rules, two-dimensional (2D) mappings, or ordering strategies separately while neglecting the connections between them. As a result, once pairing rules are changed, the correlative 2D mapping and ordering strategies are no longer available. To address such issues, this study proposes a framework that automatically generates optimal 2D mappings and efficient ordering strategies only by carefully initializing pairing rules. To construct optimal 2D mappings, a 2D mapping mathematical model is built to form a feasible 2D mapping solution space, in which optimal solutions are found, to assign efficient mappings for pairs with high probability. To design efficient ordering strategies, all frequencies are ranked according to an embedding evaluation model to determine more suitable ACs for data embedding. To initialize better pairing rules, this study selects nonzero ACs within ±2 for interblock pairing to form a more centralized pairwise histogram. The experimental results show that the proposed scheme introduces minor file expansion and obtains better visual quality than existing JPEG RDH schemes when the payload is the same as. Xiaoyi Zhou, Kaiyue Hou, Yu-Jian Zhuang, Zhao-Xia Yin, Wenbao Han |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2023 | Multi-Label Adversarial Attack Based on Label CorrelationabstractThe vulnerabilities of multi-label models concerning adversarial attacks have been paid much attention. In the multi-label model, the labels are not independent of each other. However, the existing multi-label adversarial attack works do not adequately consider label correlations, thus unable to cost the most minor disturbance while ensuring the attack success rate. To address this issue, we develop a method that uses the label correlation. For targeted attacks, we build a label correlation matrix using cosine distance and select the label with the highest correlation score with the attacked label as the target label. For untargeted attacks, we choose the attacked label with the lowest confidence because of the label correlation. The proposed method can achieve low attack costs with high success rates, as demonstrated in experimental results. Mingzhi Ma, Weijie Zheng 0006, Wanli Lv, Hang Su 0006, Zhao-Xia Yin |
ICIP | 6 |
| 2023 | Local Texture Complexity Guided Adversarial AttackabstractExtensive research revealed that deep neural networks are vulnerable to adversarial examples. In addition, recent studies have demonstrated that convolutional neural networks tend to recognize the texture (high-frequency components) rather than the shape (low-frequency components) of images. Thus, crafting adversarial perturbation in the frequency domain is proposed to enhance the attack strength. However, these methods either will increase the perceptibility of adversarial examples to the human visual system (HVS) or increase the computational effort in generating adversarial examples. To generate adversarial examples with better imperceptibility while consuming less computational effort, we propose an adversarial attack method to construct adversarial examples in the frequency domain with guidance from the local texture complexity of the image. Experiments on ImageNet and CIFAR-10 show that the proposed method is effective in generating adversarial examples imperceptible to the HVS. Jiefei Zhang, Jie Wang 0050, Zhao-Xia Yin |
ICIP | 4 |
| 2023 | Imperceptible Adversarial Attack on S Channel of HSV ColorspaceabstractDeep neural network models are vulnerable to subtle but adversarial perturbations that alter the model. Adversarial perturbations are typically computed for RGB images and, therefore, are evenly distributed among RGB channels. Compared with RGB images, HSV images can express the Hue, saturation, and brightness more intuitively. We find that the adversarial perturbation in the S-channel ensures a high attack success rate, while the perturbation is small, and the visual quality of the adversarial examples is good. Using this finding, we propose an attack method, SPGD, to improve the visual quality of adversarial examples by generating perturbations on the S-channel. Based on the attack principle of the PGD method, the RGB image was converted into an HSV image. The gradient calculated by the model on the S channel was superimposed on the S channel and then combined with the non-interference H and V channels to convert back to the RGB image. The iteration stops until the attack succeed. We compare the SPGD method with the existing state-of-the-art attack methods. The results show that SPGD minimizes pixel perturbation while maintaining a high attack success rate and achieves the best results in terms of structural similarity, imperceptibility, the minimum number of iterations, and the shortest run time. Zhao-Xia Yin, Jiefei Zhang, Bin Luo 0001 |
IJCNN | 2 |
| 2023 | AdvFAS: A robust face anti-spoofing framework against adversarial examplesabstractEnsuring the reliability of face recognition systems against presentation attacks necessitates the deployment of face anti-spoofing techniques. Despite considerable advancements in this domain, the ability of even the most state-of-the-art methods to defend against adversarial examples remains elusive. While several adversarial defense strategies have been proposed, they typically suffer from constrained practicability due to inevitable trade-offs between universality, effectiveness, and efficiency. To overcome these challenges, we thoroughly delve into the coupled relationship between adversarial detection and face anti-spoofing. Based on this, we propose a robust face anti-spoofing framework, namely AdvFAS, that leverages two coupled scores to accurately distinguish between correctly detected and wrongly detected face images. Extensive experiments demonstrate the effectiveness of our framework in a variety of settings, including different attacks, datasets, and backbones, meanwhile enjoying high accuracy on clean examples. Moreover, we successfully apply the proposed method to detect real-world adversarial examples. Xiao Yang 0028, Mingzhi Ma, Bihui Chen, Jianteng Peng, Yandong Guo, Zhao-Xia Yin, Hang Su 0006 |
Comput. Vis. Image Underst. | 8 |
| 2023 | Robust image steganography against lossy JPEG compression based on embedding domain selection and adaptive error correction
Xiaolong Duan, Bin Li 0011, Zhao-Xia Yin, Xinpeng Zhang 0001, Bin Luo 0001 |
Expert Syst. Appl. | 3 |
| 2023 | Reversible data hiding based on automatic contrast enhancement using histogram expansion
Yajie Yue, Zhao-Xia Yin |
J. Vis. Commun. Image Represent. | 3 |
| 2023 | Reversible attack based on adversarial perturbation and reversible data hiding in YUV colorspace
Zhao-Xia Yin, Bin Luo 0001 |
Pattern Recognit. Lett. | 1 |
| 2022 | Neural Network Fragile watermarking With No Model Performance DegradationabstractDeep neural networks are vulnerable to malicious fine-tuning attacks such as data poisoning and backdoor attacks. Therefore, in recent research, it is proposed how to detect malicious fine-tuning of neural network models. However, it usually negatively affects the performance of the protected model. Thus, we propose a novel neural network fragile watermarking with no model performance degradation. In the process of watermarking, we train a generative model with the specific loss function and secret key to generate triggers that are sensitive to the fine-tuning of the target classifier. In the process of verifying, we adopt the watermarked classifier to get labels of each fragile trigger. Then, malicious fine-tuning can be detected by comparing secret keys and labels. Experiments on classic datasets and classifiers show that the proposed method can effectively detect model malicious fine-tuning with no model performance degradation. Zhao-Xia Yin, Xinpeng Zhang 0001 |
ICIP | 1 |
| 2022 | High Capacity Reversible Data Hiding for Encrypted 3D Mesh Models Based on Topology
Lulu Cheng, Zhao-Xia Yin |
IWDW | 4 |
| 2022 | Universal adversarial perturbation for remote sensing imagesabstractRecently, with the application of deep learning in the remote sensing image (RSI) field, the classification accuracy of the RSI has been dramatically improved compared with traditional technology. However, even the state-of-the-art object recognition convolutional neural networks are fooled by the universal adversarial perturbation (UAP). The research on UAP is mostly limited to ordinary images, and RSIs have not been studied. To explore the basic characteristics of UAPs of RSIs, this paper proposes a novel method combining an encoder-decoder network with an attention mechanism to generate the UAP of RSIs. Firstly, the former is used to generate the UAP, which can learn the distribution of perturbations better, and then the latter is used to find the sensitive regions concerned by the RSI classification model. Finally, the generated regions are used to fine-tune the perturbation making the model misclassified with fewer perturbations. The experimental results show that the UAP can make the classification model misclassify, and the attack success rate of our proposed method on the RSI data set is as high as 97.09%. Guorui Feng, Zhao-Xia Yin, Bin Luo 0001 |
MMSP | 3 |
| 2022 | PISA: Pixel skipping-based attentional black-box adversarial attack
Jie Wang 0050, Zhao-Xia Yin, Jing Jiang 0021, Jin Tang 0001, Bin Luo 0001 |
Comput. Secur. | 2 |
| 2022 | Attention-guided black-box adversarial attacks with large-scale multiobjective evolutionary optimizationabstractFooling deep neural networks (DNNs) with black-box optimization has become a popular adversarial attack fashion, as the prior structural knowledge of DNNs is always unknown. Nevertheless, recent black-box adversarial attacks may struggle to balance their attack ability and visual quality of the generated adversarial examples (AEs) in tackling high-resolution images. In this paper, we propose an attention-guided black-box adversarial attack based on the large-scale multiobjective evolutionary optimization, termed LMOA. By considering the spatial semantic information of images, we first take advantage of the attention map to determine the perturbed pixels. Instead of attacking the entire image, reducing the perturbed pixels with the attention mechanism can help to avoid the notorious curse of dimensionality and thereby improve the performance of attacking. Second, a large-scale multiobjective evolutionary algorithm traverse the reduced pixels in the salient region. Benefiting from its characteristics, the generated AEs can fool target DNNs while being invisible by human vision. Extensive experimental results have verified the effectiveness of the proposed LMOA on the ImageNet data set. More importantly, it is more competitive to generate high-resolution AEs with the better visual quality than the existing black-box adversarial attacks. Jie Wang 0050, Zhao-Xia Yin, Jing Jiang 0021, Yang Du 0014 |
Int. J. Intell. Syst. | 2 |
| 2022 | New framework for code-mapping-based reversible data hiding in JPEG images
Yang Du 0014, Zhao-Xia Yin |
Inf. Sci. | 2 |
| 2022 | High-capacity reversible data hiding in encrypted 3D mesh models based on multi-MSB prediction
Lulu Cheng, Zhao-Xia Yin |
Signal Process. | 3 |
| 2022 | High Capacity Lossless Data Hiding in JPEG Bitstream Based on General VLC MappingabstractAs a branch of reversible data hiding (RDH), lossless data hiding (LDH) technique is important especially. Because LDH can not only reconstruct the cover image losslessly but also keep the visual quality of the marked image no degradation. This article proposes a new LDH scheme for JPEG images by general variable length code (VLC) mapping. In this scheme, the run size values are first reordered. Then a feasible solution space is generated. A simulated embedding model is established to find the optimal solution from the feasible solution space. The optimal mapping relationship is constructed according to the optimal solution. According to the optimal GVM relationship, the Huffman table in the file header is modified and then the additional data can be embedded by replacing the used VLC with the VLCs in the same mapping set. Experimental results demonstrate that most of the JPEG images using the proposed scheme cause less file size increments than previous RDH schemes while keeping the marked JPEG image with no distortion. Furthermore, the proposed scheme can obtain high embedding capacity. Yang Du 0014, Zhao-Xia Yin, Xinpeng Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Reversible Data Hiding in Encrypted Images Based on Pixel Prediction and Bit-Plane CompressionabstractReversible data hiding in encrypted images (RDHEI) receives growing attention because it protects the content of the original image while the embedded data can be accurately extracted and the original image can be reconstructed lossless. To make full use of the correlation of the adjacent pixels, this paper proposes an RDHEI scheme based on pixel prediction and bit-plane compression. Firstly, to vacate room for data embedding, the prediction error of the original image is calculated and used for bit-plane rearrangement and compression. Then, the image after vacating room is encrypted by a stream cipher. Finally, the additional data is embedded in the vacated room by multi-LSB substitution. Experimental results show that the embedding capacity of the proposed method outperforms the state-of-the-art methods. Zhao-Xia Yin, Yinyin Peng, Youzhi Xiang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | On Generating JPEG Adversarial ImagesabstractAdversarial attacks slightly perturb the original image to fool deep neural networks (DNN). Various schemes have been proposed to generate uncompressed adversarial images, which are usually ineffective after being compressed during the transmission. In this paper, we propose to generate JPEG adversarial images directly from the DNN. Two adversarial rounding schemes, including fast rounding and iterative rounding, are proposed to produce quantized DCT coefficients of JPEG adversarial images. Both schemes use the gradients of adversarial images in the DCT domain to guide the rounding. In fast rounding, we propose a novel indicator to evaluate the importance of the DCT coefficients for adversarial attacks, where only those with high importance are adversarially rounded to reduce the distortion. In iterative rounding, we additionally incorporate a loss function to mea-sure the distortion caused by adversarial rounding. The experiments show that our schemes can obtain effective JPEG adversarial images with low distortion. Mengte Shi, Sheng Li 0006, Zhao-Xia Yin, Xinpeng Zhang 0001, Zhenxing Qian |
ICME | 3 |
| 2021 | Fragile Neural Network Watermarking with Trigger Image Set
Renjie Zhu, Ping Wei 0004, Sheng Li 0006, Zhao-Xia Yin, Xinpeng Zhang 0001, Zhenxing Qian |
KSEM | 4 |
| 2021 | Separable Reversible Data Hiding Based on Integer Mapping and Multi-MSB Prediction for Encrypted 3D Mesh Models
Zhao-Xia Yin, Lulu Cheng, Bin Luo 0001 |
PRCV (2) | 1 |
| 2021 | On the security and robustness of "Keyless dynamic optimal multi-bit image steganography using energetic pixels"
Longfei Ke, Zhao-Xia Yin |
Multim. Tools Appl. | 2 |
| 2021 | Reversible data hiding in encrypted images based on pixel prediction and multi-MSB planes rearrangementabstractGreat concern has arisen in the field of reversible data hiding in encrypted images (RDHEI) due to the development of cloud storage and privacy protection. RDHEI is an effective technology that can embed additional data after image encryption, extract additional data error-free and reconstruct original images losslessly. In this paper, a high-capacity and fully reversible RDHEI method is proposed, which is based on pixel prediction and multi-MSB (most significant bit) planes rearrangement. First, the median edge detector (MED) predictor is used to calculate the predicted value. Next, unlike previous methods, in our proposed method, signs of prediction errors (PEs) are represented by one bit plane and absolute values of PEs are represented by other bit planes. Then, we divide bit planes into uniform blocks and non-uniform blocks, and rearrange these blocks. Finally, according to different pixel prediction schemes, different numbers of additional data are embedded adaptively. The experimental results prove that our method has higher embedding capacity compared with state-of-the-art RDHEI methods. Zhao-Xia Yin, Xiaomeng She, Jin Tang 0001, Bin Luo 0001 |
Signal Process. | 1 |
| 2020 | Defense against adversarial attacks by low-level image transformationsabstractDeep neural networks (DNNs) are vulnerable to adversarial examples, which can fool classifiers by maliciously adding imperceptible perturbations to the original input. Currently, a large number of research on defending adversarial examples pay little attention to the real-world applications, either with high computational complexity or poor defensive effects. Motivated by this observation, we develop an efficient preprocessing module to defend adversarial attacks. Specifically, before an adversarial example is fed into the model, we perform two low-level image transformations, WebP compression and flip operation, on the picture. Then we can get a de-perturbed sample that can be correctly classified by DNNs. WebP compression is utilized to remove the small adversarial noises. Due to the introduction of loop filtering, there will be no square effect like JPEG compression, so the visual quality of the denoised image is higher. And flip operation, which flips the image once along one side of the image, destroys the specific structure of adversarial perturbations. By taking class activation mapping to localize the discriminative image regions, we show that flipping image may mitigate adversarial effects. Extensive experiments demonstrate that the proposed scheme outperforms the state-of-the-art defense methods. It can effectively defend adversarial attacks while ensuring only slight accuracy drops on normal images. Zhao-Xia Yin, Jie Wang 0050, Jin Tang 0001, Wenzhong Wang |
Int. J. Intell. Syst. | 1 |
| 2020 | Adaptive grayscale image coding scheme based on dynamic multi-grouping absolute moment block truncation coding
Jun-Chou Chuang, Yu-Chen Hu, Chia-Mei Chen, Zhao-Xia Yin |
Multim. Tools Appl. | 4 |
| 2020 | Reversible Data Hiding in JPEG Images With Multi-Objective OptimizationabstractAmong various methods of reversible data hiding (RDH) in JPEG images, only rate-distortion, i.e. the image quality with given payload, is taken into consideration during algorithm designing. However, file size expansion is another important evaluation metric for JPEG RDH methods. Based on this situation, we propose a JPEG RDH method considering both the rate-distortion and the file size expansion at the same time while designing the algorithm. The multi-objective optimization strategy is utilized to realize the balance of the two objectives. Specifically, the cover signal is divided into several non-overlapping parts firstly, and after that, the embedding costs of each part are calculated. Next, the optimized combination of parts for embedding data is gained by multi-objective optimization. Experimental results show that the proposed algorithm outperforms the state-of-the-art methods in terms of rate-distortion and file size expansion performance. Zhao-Xia Yin, Bin Luo 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2020 | An Improved Reversible Data Hiding in Encrypted Images Using Parametric Binary Tree LabelingabstractThis work proposes an improved reversible data hiding scheme in encrypted images using parametric binary tree labeling(IPBTL-RDHEI), which takes advantage of the spatial correlation in the entire original image but not in small image blocks to reserve room for hiding data. Then the original image is encrypted with an encryption key and the parametric binary tree is used to label encrypted pixels into two different categories. Finally, one of the two categories of encrypted pixels can embed secret information by bit replacement. According to the experimental results, compared with several state-of-the-art methods, the proposed IPBTL-RDHEI method achieves higher embedding rate and outperforms the competitors. Due to the reversibility of IPBTL-RDHEI, the original plaintext image and the secret information can be restored and extracted losslessly and separately. Youqing Wu, Youzhi Xiang, Yutang Guo, Jin Tang 0001, Zhao-Xia Yin |
IEEE Trans. Multim. | 5 |
| 2020 | Reversible Data Hiding in Encrypted Images Based on Multi-MSB Prediction and Huffman CodingabstractWith the development of cloud storage and privacy protection, reversible data hiding in encrypted images (RDHEI) has attracted increasing attention as a technology that can: embed additional data in the image encryption domain, ensure that the embedded data can be extracted error-free, and the original image can be restored losslessly. In this paper, a high-capacity RDHEI algorithm based on multi-MSB (most significant bit) prediction and Huffman coding is proposed. At first, multi-MSB of each pixel was predicted adaptively and marked by Huffman coding in the original image. Then, the image was encrypted by a stream cipher method. At last, the vacated space can be used to embed additional data by multi-MSB substitution. Experimental results show that our method achieved higher embedding capacity while comparing with the state-of-the-art methods. Zhao-Xia Yin, Youzhi Xiang, Xinpeng Zhang 0001 |
IEEE Trans. Multim. | 1 |
| 2019 | Reversible data hiding based on reducing invalid shifting of pixels in histogram shifting
Yujie Jia, Zhao-Xia Yin, Xinpeng Zhang 0001, Yonglong Luo |
Signal Process. | 2 |
| 2018 | A Strategy of Distinguishing Texture Feature for Reversible Data Hiding Based on Histogram Shifting
Yinyin Peng, Zhao-Xia Yin |
IWDW | 2 |
| 2018 | Convolution Neural Network with Active Learning for Information Extraction of Enterprise Announcements
Zhao-Xia Yin |
NLPCC (2) | 2 |
| 2018 | Image authentication scheme based on reversible fragile watermarking with two images
Yinyin Peng, Xuejing Niu, Zhao-Xia Yin |
J. Inf. Secur. Appl. | 4 |
| 2018 | Distortion function based on residual blocks for JPEG steganography
Qingde Wei, Zhao-Xia Yin, Zichi Wang, Xinpeng Zhang 0001 |
Multim. Tools Appl. | 2 |
| 2018 | Reversible data hiding in encrypted AMBTC images
Zhao-Xia Yin, Xuejing Niu, Xinpeng Zhang 0001, Jin Tang 0001, Bin Luo 0001 |
Multim. Tools Appl. | 1 |
| 2018 | Joint Cover-Selection and Payload-Allocation by Steganographic Distortion OptimizationabstractThis letter proposes a batch steganographic method, which combines cover-selection and payload-allocation by steganographic distortion optimization. We first proved that with the value of payload increasing, the first-order derivative of steganographic distortion of a single cover is monotonically increasing. Then, we deduced that the first-order derivative of steganographic distortion of covers that selected from a given set should be equal if the total steganographic distortion of the corresponding selected covers is minimal. Finally, an algorithm was designed to combine cover-selection and payload-allocation, so that the optimal stego-covers can be obtained. Experiment results show that the undetectability is obviously improved when using the proposed steganographic method. Zichi Wang, Xinpeng Zhang 0001, Zhao-Xia Yin |
IEEE Signal Process. Lett. | 3 |
| 2017 | An Improved Lossless Data Hiding Scheme in JPEG Bitstream by VLC Mapping
Yang Du 0014, Zhao-Xia Yin, Xinpeng Zhang 0001 |
MSN | 2 |
| 2017 | Data hiding in AMBTC images using quantization level modification and perturbation technique
Wien Hong, Tung-Shou Chen, Zhao-Xia Yin, Bin Luo 0001, Yuan-bo Ma |
Multim. Tools Appl. | 3 |
| 2017 | Reversible data hiding in encrypted images based on multi-level encryption and block histogram modification
Zhao-Xia Yin, Andrew Abel, Jin Tang 0001, Xinpeng Zhang 0001, Bin Luo 0001 |
Multim. Tools Appl. | 1 |
| 2016 | Reversible data hiding in encrypted image based on block histogram shiftingabstractSince there is good potential for practical applications such as encrypted image authentication, content owner identification and privacy protection, reversible data hiding in encrypted image (RDHEI) has attracted increasing attention in recent years. In this paper, we propose and evaluate a new separable RDHEI framework. Additional data can be embedded into a cipher image previously encrypted using Josephus traversal and a stream cipher. A block histogram shifting (BHS) approach using self-hidden peak pixels is adopted to perform reversible data embedding. Depending on the keys held, legal receivers can extract only the embedded data with the data hiding key, or, they can decrypt an image very similar to the original with the decryption key. They can extract both the embedded data and recover the original image error-free if both keys are available. The results demonstrate that higher embedding payload, better quality of decrypted-marked image and error-free image recovery are achieved. Zhao-Xia Yin, Andrew Abel, Xinpeng Zhang 0001, Bin Luo 0001 |
ICASSP | 1 |
| 2016 | Reversible Data Hiding in Encrypted AMBTC Compressed Images
Xuejing Niu, Zhao-Xia Yin, Xinpeng Zhang 0001, Jin Tang 0001, Bin Luo 0001 |
IWDW | 2 |
| 2016 | MDE-based image steganography with large embedding capacityabstractThe big data era calls for image steganography with large embedding capacity and good image quality. Previous methods described in the literature pay more attention to image quality rather than payload. This paper proposes a large capacity steganographic method based on modification direction exploitation and pixel pair matching. By virtue of a reference matrix with particular properties, one or two 9-ary digits can be embedded into each cover pixel pair depending on different payloads. Experimental results demonstrate high embedding capacity as well as good image quality and security. Copyright © 2015 John Wiley & Sons, Ltd. Zhao-Xia Yin, Bin Luo 0001 |
Secur. Commun. Networks | 1 |
| 2015 | Second-order steganographic method based on adaptive reference matrixabstractA second‐order steganographic method (SOS) based on pixel pair matching and modification direction exploiting (MDE) is proposed in this study. In SOS, each cover pixel pair is used to conceal two secret digits in a B ‐ary notational system. Therefore the maximum embedding rate (ER) is up to log 2 B bit per pixel (bpp). It is different from the previous MDE‐based methods in which only one secret digit in base B can be embedded into each cover pixel pair and the maximum ER is ½log 2 B bpp. The experimental results demonstrate the improvements to the proposed method in terms of capacity, efficiency and detection rate compared to recent MDE‐based methods. Take B = 3 as an example. The ER is 1.585 bpp and the corresponding average peak‐signal‐to‐noise‐rate is 49.89 dB, demonstrating the best image quality with the same embedding rate compared to recent MDE‐based methods. Zhao-Xia Yin, Chin-Chen Chang 0001, Bin Luo 0001 |
IET Image Process. | 1 |
| 2009 | A High Embedding Efficiency Steganography Scheme for Wet Paper CodesabstractIn this paper, a good data hiding scheme has been proposed. This scheme embeds messages into a still image based on (Fridrich, et.al; 2005; Dumitrescu, et.al; 2003) Hamming codes oriented wet paper codes . It embeds a segment of three secret bits into a group of seven cover pixels at a time. The experimental results show that the proposed scheme achieves high embedding efficiency and acceptable capacity. Zhao-Xia Yin, Chin-Chen Chang 0001 |
IAS | 1 |