EDBT 2026 Demo / reviewers in the wild / expert
Fangjun Huang
dblp:66/6224
· DBLP profile ↗
59ranked-venue papers
17as first author
26since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 31 · 7 first-author · 14 since 2021Security and privacy · 19 · 8 first-author · 5 since 2021Artificial intelligence and machine learning · 11 · 1 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fast reversible authentication framework for digital images
Yusong Chen, Fangjun Huang |
J. Inf. Secur. Appl. | 2 |
| 2026 | DyC-CLIP: Dynamic context-aware multi-modal prompt learning for zero-shot anomaly detection
Fangjun Huang, Chao Huang 0008 |
Pattern Recognit. | 2 |
| 2026 | Secure Distribution: Anti-collusion Watermarking via Spectral Weight Modulation in Latent Diffusion Models
Yunshu Dai, Jianwei Fei, Wenhong Huang, Fangjun Huang, Zhihua Xia |
Pattern Recognit. | 4 |
| 2026 | Compression-Resistant Adversarial Perturbation for Real-World Proactive Defense Against DeepfakesabstractThe Deepfakes can generate highly realistic fake images and videos, which may be used to spread false information, manipulate public opinion, and pose serious threats to individual privacy and social stability. In recent years, researchers have proposed proactive defense methods to disrupt the output of Deepfakes by adding adversarial perturbations to the original data. However, the added perturbations are often not robust to common image compression operations, which severely limits the practical application of these proactive defense methods in the real world. In this paper, we propose a new method for adaptively adding adversarial perturbations in the discrete cosine transform (DCT) domain, which can resist various compression operations in real-world scenarios. Specifically, DCT coefficients that remain stable during the compression process and have a significant impact on the output of Deepfakes are selected to add perturbations. In addition, a new perceptual loss is introduced to enhance the visual quality of adversarial examples while preserving their robustness against lossy image compression. Extensive experimental results have shown that our method has strong robustness and effective defense capabilities against various compression operations, including Joint Photographic Experts Group (JPEG) compression and other compression operations provided by those online social networks (OSNs) in the real world. Furthermore, it can significantly improve the visual quality of adversarial images compared to previously proposed DCT-based perturbation methods. Yixiang Feng, Fangjun Huang |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2026 | Provably Secure Generative Steganography Based on Adjustable Orthogonal MappingabstractGenerative steganography employs generative models to synthesize stego images directly from secret information, avoiding cover image modifications required in traditional steganography, thereby evading detection by steganalytic tools. The latest advances in image generation technology have spurred significant progress in the field of generative steganography. Nevertheless, existing generative steganography still encounters significant challenges in terms of provable security, robustness, capacity, and visual quality. To this end, we construct an adjustable orthogonal mapping (AOM) framework, and based on it propose a provably secure generative steganographic method, named GSAOM. Specifically, the sender employs AOM to convert the secret information into the latent variable that follows the standard normal distribution and then inputs it into the diffusion model to generate a high-quality stego image. Correspondingly, the receiver converts the stego image back into the latent variable through the inversion of the diffusion model, and then extracts the secret information via the inverse mapping of the AOM. Since both the latent variable exported from AOM and the latent variable randomly generated during regular image generation follow the standard normal distribution, our proposed GSAOM can achieve provable security. Additionally, AOM allows for adjustable capacity and can maximize the distinguishability of the extracted secret information, endowing GSAOM with advantages in capacity and robustness. Extensive experiments demonstrate that GSAOM performs well in capacity, visual quality, security, robustness, and generalization. Fangjun Huang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | OmniMark: Efficient and Scalable Latent Diffusion Model FingerprintingabstractWe introduce OmniMark, a novel and efficient fingerprinting method for Latent Diffusion Models (LDM). OmniMark can encode user-specific fingerprints across diverse dimensions of the weights of the LDM, including kernels, filters, channels, and spatial domains. The LDM is fine-tuned to encode the invisible fingerprint into generated images, which can be decoded by a decoder. By altering fingerprints and re-encoding the weights, OmniMark supports efficient and scalable ad-hoc generation ( Jianwei Fei, Yunshu Dai, Zhihua Xia, Fangjun Huang |
AAAI | 4 |
| 2025 | DiffAttack: Imperceptible and Transferable Audio Adversarial Attack via Diffusion ModelabstractRecently, adversarial attacks on speaker recognition systems have garnered significant interest. However, existing methods focus on injecting subtle perturbations into audio, which may compromise auditory quality. To address this problem, we propose a novel approach named DiffAttack, which employs a diffusion model for generating high-quality adversarial samples. Firstly, we extract the Mel spectrogram of the original audio. Subsequently, the Mel spectrogram is optimized to fool the speaker recognition system while preserving the high auditory quality of the attacked audio. Lastly, a conditional diffusion model is used to reconstruct the adversarial audio from the optimized Mel spectrogram. Experimental evaluations on ECAPA and ResNet, two advanced speaker recognition systems, demonstrate that our method exceeds those state-of-the-art methods in terms of attack success rate, transferability, and auditory quality. Yunshu Dai, Fangjun Huang |
ICASSP | 3 |
| 2025 | Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance TraceabilityabstractAs AI generative models evolve, face swap technology has become increasingly accessible, raising concerns over potential misuse. Celebrities may be manipulated without consent, and ordinary individuals may fall victim to identity fraud. To address these threats, we propose Secure Swap, a method that protects persons of interest (POI) from face-swapping abuse and embeds a unique, invisible watermark into nonPOI swapped images for traceability. By introducing an ID Passport layer, Secure Swap redacts POI faces and generates watermarked outputs for nonPOI. A detachable watermark encoder and decoder are trained with the model to ensure provenance tracing. Experimental results demonstrate that Secure Swap not only preserves face swap functionality but also effectively prevents unauthorized swaps of POI and detects different embedded model’s watermarks with high accuracy. Specifically, our method achieves a 100% success rate in protecting POI and over 99% watermark extraction accuracy for nonPOI. Besides fidelity and effectiveness, the robustness of protected models against image-level and model-level attacks in both online and offline application scenarios is also experimentally demonstrated. Yunshu Dai, Jianwei Fei, Fangjun Huang, Chip-Hong Chang |
ICML | 3 |
| 2025 | Variance as a Catalyst: Efficient and Transferable Semantic Erasure Adversarial Attack for Customized Diffusion ModelsabstractLatent Diffusion Models (LDMs) enable fine-tuning with only a few images and have become widely used on the Internet. However, it can also be misused to generate fake images, leading to privacy violations and social risks. Existing adversarial attack methods primarily introduce noise distortions to generated images but fail to completely erase identity semantics.
In this work, we identify the variance of VAE latent code as a key factor that influences image distortion. Specifically, larger variances result in stronger distortions and ultimately erase semantic information. Based on this finding, we propose a Laplace-based (LA) loss function that optimizes along the fastest variance growth direction, ensuring each optimization step is locally optimal. Additionally, we analyze the limitations of existing methods and reveal that their loss functions often fail to align gradient signs with the direction of variance growth. They also struggle to ensure efficient optimization under different variance distributions. To address these issues, we further propose a novel Lagrange Entropy-based (LE) loss function.
Experimental results demonstrate that our methods achieve state-of-the-art performance on CelebA-HQ and VGGFace2. Both proposed loss functions effectively lead diffusion models to generate pure-noise images with identity semantics completely erased. Furthermore, our methods exhibit strong transferability across diverse models and efficiently complete attacks with minimal computational resources. Our work provides a practical and efficient solution for privacy protection. Yanmei Fang, Yunshu Dai, Fangjun Huang |
ICML | 5 |
| 2025 | MNet: A multi-scale network for visible watermark removal
Wenhong Huang, Yunshu Dai, Jianwei Fei, Fangjun Huang |
Neural Networks | 4 |
| 2025 | New Visible Watermark Protection Mechanism Based on Information HidingabstractWith the rise of digital media, protecting image property has become a critical issue. Visible watermarks, once a key tool for copyright protection, have become increasingly vulnerable to removal methods using deep neural networks (DNNs). This poses a significant threat to the ability of visible watermarks to protect image ownership and copyright. To address this increasingly severe challenge, we propose a novel visible watermark protection mechanism based on information hiding. Unlike traditional methods of directly adding perturbations to protected images, we hide adversarial perturbations in watermarked images through a specially designed reversible information exchange (RIE) module, which includes multiple discrete wavelet transform (DWT) and affine coupling blocks. This design can concentrate the perturbations on textured areas of the watermarked images, making them less visually noticeable. Meanwhile, theoretical analysis indicates that the difference between the adversarial image (i.e., the watermarked image after embedding the adversarial perturbation) generated by our method and the watermarked image is completely controllable. To evaluate the proposed mechanism in various scenarios, based on several widely used datasets (i.e., LOGO-Gray, LOGO-H, and LOGO-L), we further synthesize two new datasets, namely LOGO-Multi and LOGO-Full. LOGO-Multi contains images embedded with multiple watermarks, and LOGO-Full contains images embedded with a watermark covering the whole image. Extensive testing on five datasets demonstrates that, compared to the baseline methods, the proposed scheme can greatly improve the visual quality of adversarial images and enhance their capability to resist various watermark removal techniques. Wenhong Huang, Yunshu Dai, Jianwei Fei, Fangjun Huang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | IDGuard: Robust, General, Identity-Centric POI Proactive Defense Against Face Editing AbuseabstractIn this work, we propose IDGuard, a novel proactive defense method from the perspective of developers, to protect Persons-of-Interest (POI) such as national leaders from face editing abuse. We build a bridge between identities and model behavior, safeguarding POI identities rather than merely certain face images. Given a face editing model, IDGuard enables it to reject editing any image containing POI identities while retaining its editing functionality for regular use. Specifically, we insert an ID Normalization Layer into the original face editing model and introduce an ID Extractor to extract the identities of input images. To differentiate the editing behavior between POI and nonPOI, we use a transformer-based ID Encoder to encode extracted POI identities as parameters of the ID Normalization Layer. Our method supports the simultaneous protection of multiple POI and allows for the addition of new POI in the inference stage, without the need for retraining. Extensive experiments show that our method achieves 100% protection accuracy on POI images even if they are neither included in the training set nor subject to any preprocessing. Notably, our method exhibits excellent robustness against image and model attacks and maintains 100% protection performance when generalized to various face editing models, further demonstrating its practicality. Yunshu Dai, Jianwei Fei, Fangjun Huang |
CVPR | 3 |
| 2024 | LOFT: Latent Space Optimization and Generator Fine-Tuning for Defending Against DeepfakesabstractDeepFakes pose a significant threat to individual reputations and society as a whole. Existing proactive defense strategies concentrate on adding adversarial perturbations to images to disrupt or nullify the generation of DeepFakes, but these approaches are easily detectable by human perception and can be removed. To address this challenge, we propose a three-stage framework called LOFT (Latent Space Optimization and Generator Fine-Tuning for Defending against DeepFakes). First, encoding the original image into the latent space to obtain a latent code that captures facial features. Second, utilizing Adversarial Latent Optimization to optimize the latent code for reconstructing the image and defending against DeepFake manipulation. Third, fine-tuning the generator to enhance the reconstructed image’s visual quality and defense capability further. Our study evaluates the effectiveness of our proposed framework through two distinct DeepFake tasks: attribute editing and face reenactment. Various experimental results demonstrate that our proposed framework outperforms the existing benchmark in both visual quality and defense capability. Shaoyou Zeng, Fangjun Huang, Yanmei Fang |
ICASSP | 3 |
| 2024 | Enhancing Adversarial Transferability on Vision Transformer by Permutation-Invariant AttacksabstractVision Transformers (ViTs) have demonstrated remarkable performance in computer vision. However, they are still susceptible to adversarial examples. In this paper, we propose a novel adversarial attack method tailored for ViTs, by leveraging the inherent permutation-invariant of ViTs to generate highly transferable adversarial examples. Specifically, we split the image into patches of different scales and permute the local patches to generate diverse inputs. By optimizing perturbations on the permuted image set, we can prevent the generated adversarial examples from overfitting to the surrogate model, thereby enhancing transferability. Extensive experiments conducted on ImageNet demonstrate that the permutation-invariant (PI) attack significantly improves transferability between ViTs and from ViTs to CNNs. PI is applicable to diverse ViTs and can seamlessly integrate with existing attack methods further enhancing transferability. Our approach surpasses state-of-the-art ensemble methods for input transformation and achieves a notable performance improvement of 11.9% on average. Yanmei Fang, Fangjun Huang |
ICME | 3 |
| 2024 | Evading DeepFake Detectors via Conditional Diffusion ModelsabstractDetectors are the core component of DeepFake detection to distinguish between real and fake content, but they are vulnerable to adversarial attacks. Existing attack strategies focus on injecting visible perturbations into forgeries, which may degrade image quality. In this work, we propose an invisible attack to evade Deepfake detectors while maintaining minimal artifacts on human perception. First, we encode the fake image as latent code, which contains editable and semantic features. Then, the latent code is optimized to fool the detector while preserving the high visual quality of the attacked image. Finally, we use a conditional diffusion model to reconstruct the adversarial fake face from the optimized latent code. We tested three spatial and two frequency detectors on the StyleGAN2 and StarGAN-V2 synthesis models. Experimental results demonstrate the proposed attack strategy achieves superior performance in attack effectiveness and visual quality compared to existing competitors. Fangjun Huang |
IH&MMSec | 2 |
| 2024 | Patch Attacks on Vision Transformer via Skip Attention Gradients
Yanmei Fang, Fangjun Huang |
PRCV (8) | 3 |
| 2024 | Fast hypercomplex continuous orthogonal moments
Fangjun Huang |
Expert Syst. Appl. | 2 |
| 2024 | Face Omron Ring: Proactive defense against face forgery with identity awareness
Yunshu Dai, Jianwei Fei, Fangjun Huang, Zhihua Xia |
Neural Networks | 3 |
| 2024 | MaGAT: Mask-Guided Adversarial Training for Defending Face Editing GAN Models From Proactive DefenseabstractThe malicious misuse of face editing technology has endangered individual privacy and reputation. Adversarial attack-based proactive defense has been proposed to against it, which could prevent facial images from being successfully manipulated by face editing GAN models. However, the malicious manipulators could defeat proactive defense through adversarial training. Therefore, studying the effectiveness of proactive defense against adversarially trained models is critical to realize reliable proactive defense actions in real world scenario. In this letter we propose a Mask-Guided Adversarial Training (MaGAT) framework to defend face editing GAN models from proactive defense, which aims at training GAN models to still output original desirable images even if the input images are adversarial examples. Extensive experiments demonstrate that the effectiveness of MaGAT still maintains on dataset unseen during training, which means it is potentially applicable for real world applications whose input images are unknown before. Shengwei Luo, Fangjun Huang |
IEEE Signal Process. Lett. | 2 |
| 2024 | CNN-Based Reversible Data Hiding for JPEG ImagesabstractIn the field of Joint photographic experts group (JPEG) reversible data hiding (RDH), due to the weak correlation between the adjacent alternating current (AC) coefficients in the JPEG image, the existing JPEG RDH methods cannot effectively find those extension coefficients with high embedding efficiency and prioritize them for carrying message bits. In this paper, a new convolutional neural network (CNN)-based JPEG RDH scheme is proposed. First, the Laplacian distribution model is applied to roughly pre-estimate the expansion probability of the AC coefficients. Then, the approximate pre-estimated expansion probability and the actual expansion probability of the AC coefficients are used to train the carefully designed CNN-based estimation model, and the embedding efficiency of each AC coefficient can be calculated through the output of the CNN model. In the embedding stage, a new adaptive embedding strategy called coefficient selection strategy is proposed, which is more efficient than those previously proposed selection strategies based on block selection and frequency selection. Finally, the AC coefficient with greater embedding efficiency will be preferentially used for data hiding. Extensive experimental results demonstrate the effectiveness of our proposed CNN-based method compared with the state-of-the-art JPEG RDH methods. Xie Yang, Fangjun Huang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2024 | Robust Generative Steganography Based on Image MappingabstractCoverless steganography requires no modification of the cover image and can effectively resist steganalysis, which has received widespread attention from researchers in recent years. However, existing coverless image steganographic methods are achieved by constructing a mapping between the secret information and images in a known dataset. This image dataset needs to be sent to the receiver, which consumes substantial resources and poses a risk of information leakage. In addition, existing methods cannot achieve high-accuracy extraction when facing various attacks. To address the aforementioned issues, we propose a robust generative steganography based on image mapping (GSIM). This method establishes prompts based on the topic and quantity requirements first and then generate the candidate image database according to the prompts, which can be independently generated by both the sender and receiver without the need for transmission. In order to improve the robustness of the algorithm, our proposed GSIM utilizes prompts and fractional-order Chebyshev-Fourier moments (FrCHFMs) to construct the mapping between the generated images and the predefined binary sequences, as well as uses speeded-up robust features (SURFs) as auxiliary features in the information extraction phase. The experimental results show that GSIM is superior to existing coverless image steganographic methods in terms of capacity, security, and robustness. Fangjun Huang |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2023 | Average Gradient-Based Adversarial AttackabstractDeep neural networks (DNNs) are vulnerable to adversarial attacks which can fool the classifiers by adding small perturbations to the original example. The added perturbations in most existing attacks are mainly determined by the gradient of the loss function with respect to the current example. In this paper, a new average gradient-based adversarial attack is proposed. In our proposed method, via utilizing the gradient of each iteration in the past, a dynamic set of adversarial examples is constructed first in each iteration. Then, according to the gradient of the loss function with respect to all the examples in the constructed dynamic set and the current adversarial example, the average gradient can be calculated, which is used to determine the added perturbations. Different from the existing adversarial attacks, the proposed average gradient-based attack optimizes the added perturbations through a dynamic set of adversarial examples, where the size of the dynamic set increases with the number of iterations. Our proposed method possesses good extensibility and can be integrated into most existing gradient-based attacks. Extensive experiments demonstrate that, compared with the state-of-the-art gradient-based adversarial attacks, the proposed attack can achieve higher attack success rates and exhibit better transferability, which is helpful to evaluate the robustness of the network and the effectiveness of the defense method. Chen Wan, Fangjun Huang, Xianfeng Zhao |
IEEE Trans. Multim. | 2 |
| 2022 | Adaptive Robust Watermarking Method Based on Deep Neural Networks
Chen Wan, Fangjun Huang |
IWDW | 3 |
| 2022 | Reversible data hiding in JPEG images based on coefficient-first selection
Xie Yang, Taoyu Wu, Fangjun Huang |
Signal Process. | 3 |
| 2022 | New CNN-Based Predictor for Reversible Data HidingabstractIn this letter, we propose a convolutional neural network (CNN) based predictor for reversible data hiding (RDH). Firstly, a new image division strategy is presented, which can divide the cover image into four independent parts. Via using it, any pixel in each part can be predicted by all its 8-neighbor pixels to generate the preprocessed images. Then, the preprocessed image is fed into a carefully designed CNN-based prediction model to output the predicted image, which is used to build the prediction-error histogram for RDH. Experimental results demonstrate that a sharply distributed prediction-error histogram (i.e., small prediction errors) can be easily obtained by our proposed CNN-based predictor. Furthermore, combining with the classical prediction-error expansion (PEE) embedding strategy, a series of new RDH algorithms with higher visual quality can be formed in contrast to the state-of-the-art RDH schemes. Xie Yang, Fangjun Huang |
IEEE Signal Process. Lett. | 2 |
| 2021 | PID-Based Approach to Adversarial AttacksabstractAdversarial attack can misguide the deep neural networks (DNNs) with adding small-magnitude perturbations to normal examples, which is mainly determined by the gradient of the loss function with respect to inputs. Previously, various strategies have been proposed to enhance the performance of adversarial attacks. However, all these methods only utilize the gradients in the present and past to generate adversarial examples. Until now, the trend of gradient change in the future (i.e., the derivative of gradient) has not been considered yet. Inspired by the classic proportional-integral-derivative (PID) controller in the field of automatic control, we propose a new PID-based approach for generating adversarial examples. The gradients in the present and past, and the derivative of gradient are considered in our method, which correspond to the components of P, I and D in the PID controller, respectively. Extensive experiments consistently demonstrate that our method can achieve higher attack success rates and exhibit better transferability compared with the state-of-the-art gradient-based adversarial attacks. Furthermore, our method possesses good extensibility and can be applied to almost all available gradient-based adversarial attacks. Chen Wan, Biaohua Ye, Fangjun Huang |
AAAI | 3 |
| 2020 | Reversible Data Hiding Based on Prediction-Error-Ordering
Jianqiang Qin, Fangjun Huang |
PRCV (1) | 2 |
| 2020 | Reversible data hiding for JPEG images based on pairwise nonzero AC coefficient expansion
Fangjun Huang |
Signal Process. | 2 |
| 2019 | JPEG Reversible Data Hiding with Matrix Embedding
Fangjun Huang, Jiayong Li |
ICIG (3) | 1 |
| 2019 | Reversible Data Hiding Based on Partitioning the Prediction Values
Haihang Wu, Fangjun Huang |
IWDW | 2 |
| 2019 | Reversible data hiding in JPEG images based on zero coefficients and distortion cost function
Fuqiang Di, Minqing Zhang, Fangjun Huang, Jia Liu 0016, Yongjun Kong |
Multim. Tools Appl. | 3 |
| 2019 | Designing adaptive JPEG steganography based on the statistical properties in spatial domain
Fangjun Huang |
Multim. Tools Appl. | 2 |
| 2019 | Digital image forensics of non-uniform deblurring
Huimei Xiao, Wei Lu 0001, Hongmei Liu 0001, Fangjun Huang |
Signal Process. Image Commun. | 6 |
| 2019 | Reversible Data Hiding Based on Multiple Two-Dimensional Histograms ModificationabstractIn pairwise prediction-error expansion (pairwise PEE) based reversible data hiding (RDH), the correlations among prediction errors are considered and utilized. The obtained performance is better than traditional PEE-based RDH. However, their performance can further be improved. In this letter, a new RDH algorithm based on multiple two-dimensional (2-D) histograms modification is proposed. In our new algorithm, by considering the predetermined pixel pair and its neighbors, a new prediction strategy which can be utilized to predict each element in the pixel pair is proposed. And then, according to the local complexities of the predetermined pixel pairs, multiple 2-D prediction-error sub-histograms are constructed. Moreover, eight new 2-D-maps are designed, and for each kind of 2-D prediction-error sub-histogram, the corresponding optimal 2-D mapping is exhaustively searched to further improve the performance of the proposed algorithm. Extensive experiments demonstrate the superiority of our scheme. Jianqiang Qin, Fangjun Huang |
IEEE Signal Process. Lett. | 2 |
| 2019 | Reversible Data Hiding With Automatic Brightness Preserving Contrast EnhancementabstractReversible data hiding with automatic contrast enhancement methods provide an interoperable way to reduce the storage requirement for automatic image enhancement applications: original image can be recovered from the enhanced image without any additional information. Unlike the previous work, where the goal was to maximize the contrast, the proposed method increases the contrast to an appropriate level using an idea called brightness preservation. This is achieved by using an adaptive bin selection process based on the original brightness. Extensive experimental results verify that the enhanced images produced using the proposed method are visually and quantitatively superior than the existing work. Suah Kim, Rolf Lussi, Xiaochao Qu, Fangjun Huang, Hyoung Joong Kim |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2018 | Reversible data hiding in encrypted images with high capacity by bitplane operations and adaptive embedding
Fuqiang Di, Fangjun Huang, Minqing Zhang, Jia Liu 0016, Xiaoyuan Yang 0002 |
Multim. Tools Appl. | 2 |
| 2016 | Framework for improving the security performance of ordinary distortion functions of JPEG steganography
Fangjun Huang, Hyoung Joong Kim |
Multim. Tools Appl. | 1 |
| 2016 | Reversible Data Hiding in JPEG ImagesabstractAmong various digital image formats used in daily life, the Joint Photographic Experts Group (JPEG) is the most popular. Therefore, reversible data hiding (RDH) in JPEG images is important and useful for many applications such as archive management and image authentication. However, RDH in JPEG images is considerably more difficult than that in uncompressed images because there is less information redundancy in JPEG images than that in uncompressed images, and any modification in the compressed domain may introduce more distortion in the host image. Furthermore, along with the embedding capacity and fidelity (visual quality), which have to be considered for uncompressed images, the storage size of the marked JPEG file should be considered. In this paper, based on the philosophy behind the JPEG encoder and the statistical properties of discrete cosine transform (DCT) coefficients, we present some basic insights into how to select quantized DCT coefficients for RDH. Then, a new histogram shifting-based RDH scheme for JPEG images is proposed, in which the zero coefficients remain unchanged and only coefficients with values 1 and -1 are expanded to carry message bits. Moreover, a block selection strategy based on the number of zero coefficients in each 8 × 8 block is proposed, which can be utilized to adaptively choose DCT coefficients for data hiding. Experimental results demonstrate that by using the proposed method we can easily realize high embedding capacity and good visual quality. The storage size of the host JPEG file can also be well preserved. Fangjun Huang, Xiaochao Qu, Hyoung Joong Kim, Jiwu Huang |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2016 | New Framework for Reversible Data Hiding in Encrypted DomainabstractIn the past more than one decade, hundreds of reversible data hiding (RDH) algorithms have been reported. Via exploring the correlation between the neighboring pixels (or coefficients), extra information can be embedded into the host image reversibly. However, these RDH algorithms cannot be accomplished in encrypted domain directly, since the correlation between the neighboring pixels will disappear after encryption. In order to accomplish RDH in encrypted domain, specific RDH schemes have been designed according to the encryption algorithm utilized. In this paper, we propose a new simple yet effective framework for RDH in encrypted domain. In the proposed framework, the pixels in a plain image are first divided into sub-blocks with the size of $m\times n$ . Then, with an encryption key, a key stream (a stream of random or pseudorandom bits/bytes that are combined with a plaintext message to produce the encrypted message) is generated, and the pixels in the same sub-block are encrypted with the same key stream byte. After the stream encryption, the encrypted $m\times n$ sub-blocks are randomly permutated with a permutation key. Since the correlation between the neighboring pixels in each sub-block can be well preserved in the encrypted domain, most of those previously proposed RDH schemes can be applied to the encrypted image directly. One of the main merits of the proposed framework is that the RDH scheme is independent of the image encryption algorithm. That is, the server manager (or channel administrator) does not need to design a new RDH scheme according to the encryption algorithm that has been conducted by the content owner; instead, he/she can accomplish the data hiding by applying the numerous RDH algorithms previously proposed to the encrypted domain directly. Fangjun Huang, Jiwu Huang, Yun Q. Shi 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Feature Selection for High Dimensional Steganalysis
Yanping Tan, Fangjun Huang, Jiwu Huang |
IWDW | 2 |
| 2015 | Local pixel patternsabstractIn this paper, a new class of image texture operators is proposed. We firstly determine that the number of gray levels in each B × B subblock is a fundamental property of the local image texture. Thus, an occurrence histogram for each B × B sub-block can be utilized to describe the texture of the image. Moreover, using a new multi-bit plane strategy, i.e., representing the image texture with the occurrence histogram of the first one or more significant bit-planes of the input image, more powerful operators for describing the image texture can be obtained. The proposed approach is invariant to gray scale variations since the operators are, by definition, invariant under any monotonic transformation of the gray scale, and robust to rotation. They can also be used as supplementary operators to local binary patterns (LBP) to improve their capability to resist illuminance variation, surface transformations, etc. Fangjun Huang, Xiaochao Qu, Hyoung Joong Kim, Jiwu Huang |
Comput. Vis. Media | 1 |
| 2014 | Reversible Data Hiding Based on Combined Predictor and Prediction Error Expansion
Xiaochao Qu, Suah Kim, Run Cui, Fangjun Huang, Hyoung Joong Kim |
IWDW | 4 |
| 2013 | Distortion function designing for JPEG steganography with uncompressed side-imageabstractIn this paper, we present a new framework for designing distortion functions of joint photographic experts group (JPEG) steganography with uncompressed side-image. In our framework, the discrete cosine transform (DCT) coefficients, including all direct current (DC) coefficients and alternating current (AC) coefficients, are divided into two groups: first-priority group (FPG) and second-priority group (SPG). Different strategies are established to associate the distortion values to the coefficients in FPG and SPG, respectively. In this paper, three scenarios for dividing the coefficients into FPG and SPG are exemplified, which can be utilized to form a series of new distortion functions. Experimental results demonstrate that while applying these generated distortion functions to JPEG steganography, the intrinsic statistical characteristics of the carrier image will be preserved better than the prior-art, and consequently the security performance of the corresponding JPEG steganography can be improved significantly. Fangjun Huang, Weiqi Luo 0001, Jiwu Huang, Yun Q. Shi 0001 |
IH&MMSec | 1 |
| 2013 | Improved Algorithm of Edge Adaptive Image Steganography Based on LSB Matching Revisited Algorithm
Fangjun Huang, Yane Zhong, Jiwu Huang |
IWDW | 1 |
| 2012 | New Channel Selection Criterion for Spatial Domain Steganography
Yane Zhong, Fangjun Huang |
IWDW | 2 |
| 2012 | New Channel Selection Rule for JPEG SteganographyabstractIn this paper, we present a new channel selection rule for joint photographic experts group (JPEG) steganography, which can be utilized to find the discrete cosine transform (DCT) coefficients that may introduce minimal detectable distortion for data hiding. Three factors are considered in our proposed channel selection rule, i.e., the perturbation error (PE), the quantization step (QS), and the magnitude of quantized DCT coefficient to be modified (MQ). Experimental results demonstrate that higher security performance can be obtained in JPEG steganography via our new channel selection rule. Fangjun Huang, Jiwu Huang, Yun Q. Shi 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2011 | Steganalysis of JPEG steganography with complementary embedding strategyabstractRecently, a new high-performance JPEG steganography with a complementary embedding strategy (JPEG-CES) was presented. It can disable many specific steganalysers such as the Chi-square family and S family detectors, which have been used to attack J-Steg, JPHide, F5 and OutGuess successfully. In this work, a study on the security performance of JPEG-CES is reported. Our theoretical analysis demonstrates that in this algorithm, the number of the different quantised discrete cosine transform (qDCT) coefficients and the symmetry of the qDCT coefficient histogram both will be disturbed when the secret message is embedded. Moreover, the intrinsic sign and magnitude dependencies that existed in intra-block and inter-block qDCT coefficients will be disturbed too. Thus it may be detected by some modern universal steganalysers which can catch these disturbances. In this work, the authors have proposed two new steganalytic approaches. Through exploring the distortions that have been introduced into the qDCT coefficient histogram and the dependencies existed in the intra-block and inter-block sense, respectively, these two alternative steganalysers can detect JPEG-CES effectively. In addition, via merging the features of these two steganalysers, a more reliable classifier can be obtained. Fangjun Huang, Weiqi Luo 0001, Jiwu Huang |
IET Inf. Secur. | 1 |
| 2011 | A more secure steganography based on adaptive pixel-value differencing scheme
Weiqi Luo 0001, Fangjun Huang, Jiwu Huang |
Multim. Tools Appl. | 2 |
| 2010 | New JPEG Steganographic Scheme with High Security Performance
Fangjun Huang, Yun Q. Shi 0001, Jiwu Huang |
IWDW | 1 |
| 2010 | An experimental study on the security performance of YASSabstractThis paper presents an experimental study on the security performance of Yet Another Steganographic Scheme (YASS). It reports: 1) YASS's security performance with different input images, i.e., uncompressed images and JPEG compressed images; 2) YASS's security performance compared with two other JPEG steganographic schemes MB1 and F5; and 3) some experimental results about extended YASS. Fangjun Huang, Jiwu Huang, Yun Q. Shi 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Detecting Double JPEG Compression With the Same Quantization MatrixabstractDetection of double joint photographic experts group (JPEG) compression is of great significance in the field of digital forensics. Some successful approaches have been presented for detecting double JPEG compression when the primary compression and the secondary compression have different quantization matrixes. However, when the primary compression and the secondary compression have the same quantization matrix, no detection method has been reported yet. In this paper, we present a method which can detect double JPEG compression with the same quantization matrix. Our algorithm is based on the observation that in the process of recompressing a JPEG image with the same quantization matrix over and over again, the number of different JPEG coefficients, i.e., the quantized discrete cosine transform coefficients between the sequential two versions will monotonically decrease in general. For example, the number of different JPEG coefficients between the singly and doubly compressed images is generally larger than the number of different JPEG coefficients between the corresponding doubly and triply compressed images. Via a novel random perturbation strategy implemented on the JPEG coefficients of the recompressed test image, we can find a “proper” randomly perturbed ratio. For different images, this universal “proper” ratio will generate a dynamically changed threshold, which can be utilized to discriminate the singly compressed image and doubly compressed image. Furthermore, our method has the potential to detect triple JPEG compression, four times JPEG compression, etc. Fangjun Huang, Jiwu Huang, Yun Q. Shi 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Edge adaptive image steganography based on LSB matching revisitedabstractThe least-significant-bit (LSB)-based approach is a popular type of steganographic algorithms in the spatial domain. However, we find that in most existing approaches, the choice of embedding positions within a cover image mainly depends on a pseudorandom number generator without considering the relationship between the image content itself and the size of the secret message. Thus the smooth/flat regions in the cover images will inevitably be contaminated after data hiding even at a low embedding rate, and this will lead to poor visual quality and low security based on our analysis and extensive experiments, especially for those images with many smooth regions. In this paper, we expand the LSB matching revisited image steganography and propose an edge adaptive scheme which can select the embedding regions according to the size of secret message and the difference between two consecutive pixels in the cover image. For lower embedding rates, only sharper edge regions are used while keeping the other smoother regions as they are. When the embedding rate increases, more edge regions can be released adaptively for data hiding by adjusting just a few parameters. The experimental results evaluated on 6000 natural images with three specific and four universal steganalytic algorithms show that the new scheme can enhance the security significantly compared with typical LSB-based approaches as well as their edge adaptive ones, such as pixel-value-differencing-based approaches, while preserving higher visual quality of stego images at the same time. Weiqi Luo 0001, Fangjun Huang, Jiwu Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2009 | Calibration based universal JPEG steganalysis
Fangjun Huang, Jiwu Huang |
Sci. China Ser. F Inf. Sci. | 1 |
| 2008 | Universal JPEG steganalysis based on microscopic and macroscopic calibrationabstractIn this paper, we present a new universal steganalysis scheme to effectively attack some recently proposed JPEG steganography. Different from the other steganalyzers, not only the magnitude but also the sign dependencies existed in intra-block and inter-block quantized DCT (discrete cosine transform) coefficients are exploited by the Markov empirical transition matrices. Moreover, a new microscopic and macroscopic calibration method is proposed to calibrate the local and global distribution of the quantized DCT coefficients of the test image, thus improve the detecting performance. Experimental results demonstrate that our proposed scheme outperforms some existing steganalyzers in attacking the advanced JPEG steganography such as F5, MB1 and Outguess. Fangjun Huang, Bin Li 0011, Jiwu Huang |
ICIP | 1 |
| 2008 | A study on security performance of YASSabstractYASS (Yet another steganographic scheme) is a newly developed JPEG steganographic method. Through embedding data in the randomized 8×8 blocks which do not coincide with the 8×8 grid used in JPEG compression, it effectively disables the self-calibration process popularly used in today’s JPEG steganalyzers. However, with YASS’ complicated embedding procedure, the intra- and inter-block dependency among the quantized DCT coefficients belonging to the original image is disturbed after the secret message embedding. Furthermore, because of the randomly selection of an 8×8 block within a large block and the necessary utilization of error correction code, the amount of information that YASS can embed is largely reduced. In this paper a study on security performance of YASS is reported. Our experimental results have demonstrated that 1) the steganalyzers which utilizes intra- and/or inter-block correlation of JPEG coefficients can break YASS, 2) with embedding the same amount of information bits, the security of YASS is not stronger than that of MB1 when some today’s blind JPEG steganalyzers are used. Fangjun Huang, Yun Q. Shi 0001, Jiwu Huang |
ICIP | 1 |
| 2007 | Attack LSB Matching Steganography by Counting Alteration Rate of the Number of Neighbourhood Gray LevelsabstractIn this paper, we propose a new method for attacking the LSB (least significant bit) matching based steganography. Different from the LSB substitution, the least two or more significant bit-planes of the cover image would be changed during the embedding in LSB matching steganography and thus the pairs of values do not exist in stego image. In our proposed method, we get an image by combining the least two significant bit-planes and divide it into 3x3 overlapped subimages. The subimages are grouped into four types, i.e.T1,T2,T3andT4according to the count of gray levels. Via embedding a random sequence by LSB matching and then computing the alteration rate of the number of elements inT1, we find that normally the alteration rate is higher in cover image than in the corresponding stego image. This new finding is used as the discrimination rule in our method. Experimental results demonstrate that the proposed algorithm is efficient to detect the LSB matching stegonagraphy on uncompressed gray scale images. Fangjun Huang, Bin Li 0011, Jiwu Huang |
ICIP (1) | 1 |
| 2007 | Steganalysis of LSB Greedy Embedding Algorithm for JPEG Images using Coefficient SymmetryabstractA recently developed LSB greedy embedding algorithm for JPEG images is capable of resisting the chi-square attack. By carefully studying the quantized DCT (discrete cosine transform) coefficients of the cover and stego images, we find that the embedding algorithm does not preserve the histogram of the DCT coefficients well. In this paper, we define a new chi-square statistic which is used to measure whether the image under scrutiny is like the cover or the stego. Our proposed steganalytic method is based on the symmetry property of the DCT coefficients in JPEG images. It can also be used in the scenario where the cover images are double JPEG compressed. The reliability of this specific steganalytic scheme depends on the embedding rate and it is influenced by the JPEG quality factor. Experimental results show that when the embedding rate exceeds half of the maximal embedding capacity, the steganographic algorithm is detectable with a very low false negative rate, whatever the quality factor is. Bin Li 0011, Fangjun Huang, Jiwu Huang |
ICIP (1) | 2 |
| 2007 | Effect of Different Coding Patterns on Compressed Frequency Domain Based Universal JPEG Steganalysis
Bin Li 0011, Fangjun Huang, Shunquan Tan, Jiwu Huang, Yun Q. Shi 0001 |
IWDW | 2 |
| 2004 | A hybrid SVD-DCT watermarking method based on LPSNR
Fangjun Huang, Zhi-Hong Guan |
Pattern Recognit. Lett. | 1 |