Zhili Zhou 0001

dblp:91/3541-1 · DBLP profile ↗
← Back
68ranked-venue papers
24as first author
55since 2021 · last 2026
0000-0002-5641-7169ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 6 first-author · 16 since 2021Graphics, computer vision, multimedia, augmented reality and games · 19 · 5 first-author · 17 since 2021Artificial intelligence and machine learning · 12 · 5 first-author · 9 since 2021Computer networks · 8 · 4 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 5 first-author · 7 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Towards Provably Secure and Highly Robust Generative Image Steganography Leveraging Latent Diffusion Model
abstract
Generative image steganography has attracted significant attention for its exceptional resistance to steganalysis. However, current generative steganography methods still face limitations in terms of the lack of provable security guarantees under statistical analysis and vulnerability to real-world, unforeseen channel attacks. To address these issues, this paper proposes a novel generative image steganography framework that leverages the Latent Diffusion Model (LDM). Notably, we have uncover a consistent trend: regardless of whether an image has undergone attacks such as compression or noise addition, the sign pattern of values in its latent vector encoded by the LDM remains largely invariant. Capitalizing on this trend, we have devised an adaptive distribution-preserving mapping (ADPM) mechanism, capable of converting a secret message into a latent vector that follows standard normal distribution in an adjustable way. Since both the secret latent vector and the latent vector randomly generated during regular image generation follow the same distribution, satisfying the optimal input conditions for the diffusion model, the proposed method can achieve provable security. Experimental results demonstrate the outstanding performance of our approach in terms of robustness, security, and extraction accuracy.
Chengsheng Yuan 0001, Zhaonan Ji, Zhili Zhou 0001, Xinting Li, Zhihua Xia
AAAI4
2026 A cascaded border-aware network for visual tracking
Qun Li 0011, Haijun Zhang 0002, Kai Yang 0018, Zhili Zhou 0001
Eng. Appl. Artif. Intell.4
2026 A robust dual-pronged proactive defense framework against deepfakes via adversarial semi-fragile watermarking
Chengsheng Yuan 0001, Youqiang Cao, Zhili Zhou 0001, Zhangjie Fu 0001, Zhihua Xia, Q. M. Jonathan Wu
Expert Syst. Appl.3
2026 Large-Capacity Reversible Data Hiding Over Encrypted Images via Pixel Correlation Recovery
abstract
Cloud services have been commonly leveraged to store and manage the exponential growth of images, yet this also comes with critical data privacy concerns. Reversible data hiding over encrypted images (RDH-EI) techniques can embed data into encrypted images and support lossless recovery, which can provide an effective solution for securely managing private images in the cloud. However, existing schemes generally suffer from low embedding capacity. Moreover, most of them rely on a single cloud server, which introduces a single point of failure. In this paper, we first propose a pixel correlation recovery (PCR) technique for restoring the pixel correlation excessively disrupted during encryption. Using the PCR technique, we develop a secure (r, n)-threshold RDH-EI scheme with large embedding capacity and avoidance of single point of failure. In our scheme, a content owner encrypts a confidential image into n shares and distributes them across n independent cloud servers. We design a new encoding method enabling each cloud server to efficiently encode the share, preserving capacity for data embedding. An authorized receiver can later extract the embedded data and reconstruct the confidential image from r shares. Experiments demonstrate that our scheme achieves significantly larger embedding capacity over state-of-the-art schemes.
Zhongyun Hua, Jianhui Zou, Yifeng Zheng 0001, Zhili Zhou 0001, Fei Peng 0001, Qing Liao 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Proactive Image Manipulation Detection and Tracing in Fake News
abstract
The pervasive spread of fake news, particularly through manipulated images, presents a consequential negative impact on society. To prevent fake news images from misleading the public, existing methods focus on verifying the authenticity of news images but ignore source traceability, leaving a gap in creating a complete forensic chain for reliable fake news detection. To simultaneously achieve the goals of authenticity verification and source tracing, we propose a proactive image tagging approach based on a design of Disentangled Invertible Neural Networks (DINN). It can simultaneously embed the dual-tags,i.e., authenticable tag and traceable tag, into each news image prior to publication, allowing for separate extraction for authenticity verification and source tracing. Within the proposed DINN, we design a parallel Feature Aware Projection Module (FAPM) to assist DINN in preserving essential tag information, thereby improving extraction accuracy. In addition, we introduce a Distance Metric-Guided Module (DMGM) that learns asymmetric one-class representations, enabling the dual-tags to exhibit different robustness performances under malicious manipulations. Extensive experiments on diverse datasets and unseen manipulations demonstrate that the proposed tagging approach achieves promising performances on both authenticity verification and source tracing for reliable fake news detection and outperforms the prior works.
Ruohan Meng, Siyuan Yang 0001, Zhili Zhou 0001, Kwok-Yan Lam, Zengwei Zheng, Alex Chichung Kot
IEEE Trans. Dependable Secur. Comput.3
2026 Visually Meaningful Encryption via Image-to-Image Reversible Transformation
abstract
Image encryption techniques generally encrypt a secret image into a meaningless noise-like format, which could easily attract attention from attackers who then may try to crack it. On the other hand, image steganography typically embeds secret image data within a cover image, but it inevitably incurs a lot of distortion to the cover image. This makes the secret image data vulnerable to attacks by steganalysis tools. In light of the above, in this paper, we propose a Visually Meaningful Image Encryption (VMIE) scheme via image-to-image reversible transformation based on the Glow model. In this scheme, a secret image is encoded and compressed as a latent vector by the deep compression autoencoder. Then, the latent vector is scrambled and inputted into the Glow model to generate a visually meaningful encrypted image. Extensive experiments demonstrate that the proposed VMIE scheme not only provides desirable security against attacks, but also enables the reconstruction of the original images with negligible quality loss. Codes are available athttps://github.com/AIMS-Group-ZhiliZhou/VMEI.
Zhili Zhou 0001, Yuhuan Liu, Daizhi Liao, Yifeng Zheng 0001
IEEE Trans. Dependable Secur. Comput.2
2026 Zero-Knowledge Proof-Based IP Protection of Visual Large Models of Autonomous Driving
Chengsheng Yuan 0001, Lvyang Cao, Xinting Li, Zhili Zhou 0001, Zhihua Xia, Zhangjie Fu 0001
IEEE Trans. Inf. Forensics Secur.4
2025 STLC-KG: A Social Text Steganalysis Method Combining Large-Scale Language Models and Common-Sense Knowledge Graphs
abstract
Language steganography in social networks primarily focuses on embedding secret information into social media text efficiently to achieve covert communication. The misuse of such techniques could pose significant potential threats to public cyberspace, such as the spread of malicious code, commands, or viruses. Existing social text steganalysis techniques mainly focus on the analysis of individual social media texts. However, the information content in a single text is very limited, leading to poor detection performance in practical applications. To address this challenge, this paper proposes a social text steganalysis method that combines large-scale language models with common-sense knowledge graphs (STLC-KG). This method first uses knowledge graphs to expand the knowledge contained in the text under investigation, enriching its linguistic expression, and then utilizes large-scale language models to extract the linguistic features of the social text. The results of tests conducted on three mainstream social media platforms demonstrate that the proposed method significantly improves the performance of social text steganalysis.
Linna Zhou, Xuekai Chen, Zhili Zhou 0001, Zhongliang Yang
AAAI4
2025 DAEF-VS: An Efficient Universal VoIP Steganalysis Framework Based on Domain-Aware Knowledge
abstract
In recent years, research on information-hiding techniques based on network streaming media has focused on how to covertly embed secret information within real-time transmissions to achieve clandestine communication. The misuse of such technologies poses significant security risks, such as the dissemination of malicious codes, commands, viruses, and more. The existing methods for steganalysis of network voice streams generally face challenges in universality, exhibiting poor adaptability to steganographic detection scenarios with non-identity distributions. To address these issues, we introduce a framework named the Domain-Aware Enhanced Framework for VoIP Steganalysis (DAEF-VS), which harnesses the CutMix technology to enhance the shared steganographic domain features and employs the Domain-Aware Learning Model to fine-tune these features, thereby significantly improving generalization capabilities. Extensive experimental results demonstrate that our approach vastly surpasses existing advanced methods in terms of universality across a variety of steganographic detection scenarios.
Zhengyang Fang, Zhongliang Yang, Zhili Zhou 0001, Linna Zhou
ICASSP4
2025 SECC-Stega: Generative Linguistic Steganographic Framework Based on Error Correcting Codes
abstract
With the rise and maturation of neural network technology, generative text steganography based on language models is gradually becoming the mainstream technique in text steganography. However, homomorphic extraction attacks and text modification attacks from third parties pose serious threats to the usability of generative text steganography. To address this issue, this paper proposes a generative text steganography algorithm framework based on error correction codes. This framework enhances the robustness and security of steganography by encoding the secret information. Experimental results verify that the proposed framework achieves the expected outcomes and exhibits a certain degree of generality.
Yuzhe Guo, Zhongliang Yang, Zhili Zhou 0001, Linna Zhou
ICASSP4
2025 SCF-Stega: Controllable Linguistic Steganography Based on Semantic Communications Framework
abstract
Linguistic steganography is a key information hiding technique but faces challenges like abrupt content shifts, detection risks, and high training resource demands. To address these, this paper introduces SCF-Stega, a controllable method based on Semantic Communications Framework. By using a knowledge graph to guide secret encoding and dynamically adjusting large language model outputs, SCF-Stega enhances text imperceptibility and semantic coherence. Experiments show improved text quality and strong resistance to steganalysis, without needing additional training data.
Yilin Long, Zhongliang Yang, Zhili Zhou 0001, Yongfeng Huang 0001, Linna Zhou
ICASSP4
2025 TGCA: A Transformer GNN-based Approach with Cross-Attention Mechanism for Steganographic Text Detection in Social Networks
abstract
Steganalysis aims to detect the presence of concealed information within seemingly normal carriers in network transmissions, playing a crucial role in maintaining cybersecurity. With the rapid development of social networks, steganalysis techniques targeting social network texts have attracted significant interest from researchers in recent years. However, existing steganalysis techniques for social texts generally focus on analyzing the statistical features of the text itself, neglecting the relational features between texts, thereby limiting their detection capabilities. In this paper, we propose a novel text steganalysis feature enhancement method—TGCA. This method considers the relational features between texts by introducing GNN, while utilizing Transformers to expand the receptive field of GNNs and incorporating a cross-attention mechanism to reduce the aggregation of noise, thus mitigating the inherent limitations of GNNs. As a result, TGCA more effectively extracts and integrates textual and topological features, enhancing the model's performance in detecting steganographic texts. Experimental results demonstrate that TGCA outperforms existing methods by better leveraging graph and textual features to identify malicious steganographic texts. Our code is available at https://github.com/PandaaKai/TGCA.
Junkai Lu, Zhongliang Yang, Kaibo Huang, Zhili Zhou 0001, Linna Zhou
ICASSP5
2025 Dual-Population Watermark Vaccine: Efficient and Imperceptible Adversarial Attack for Watermarked Image Protection
abstract
The current watermark-removal neural networks (WRNNs) can effectively remove the watermarks from watermarked images without damaging their host images, which poses a significant threat to image copyright protection. As one of the most effective technologies of preventing watermarks from being removed, the watermark vaccine generally attacks the WRNNs by generating and adding the adversarial perturbations to watermarked images. However, the existing watermark vaccine schemes perturb all the pixels of watermarked images, which makes it difficult to find a good trade-off between attack efficiency and imperceptibility. To address the above issues, we propose a Dual-Population Watermark Vaccine (DPWV) scheme. In this scheme, we formulate the task of adding adversarial perturbation as a bi-objective optimization problem, and address it by decoupling the space of adversarial perturbation addition to the Intensity Population (IP)-based and Position Population (PP)-based subspaces to search for the optimal solution. The extensive experiments demonstrate that the proposed scheme significantly outperforms the state-of-the-arts in the aspects of attack efficiency and imperceptibility, simultaneously, with the improvements of 45%-55% attack efficiency and 30%-40% attack imperceptibility.
Zhili Zhou 0001, Chunhui Zeng, Linna Zhou, Zhongliang Yang, Yujiang Li, Fei Peng 0001, Yong Xie 0003
ICASSP1
2025 Imperceptible and Robust Adversarial Perturbation: Attention-Guided Watermark Vaccine Against Watermark Removal
abstract
Visible watermarks are generally embedded into digital images to claim their ownership for copyright protection. Unfortunately, the watermark removal models based on Deep Neural Networks (DNNs) are able to remove the watermarks from watermarked images, posing a great threat to image copyright protection. To prevent the watermark from being removed, watermark vaccines, i.e., adversarial perturbations, are usually added to the watermarked images to attack the target models, making them unable to remove the watermarks. However, the existing approaches indiscriminately add the watermark vaccine to the whole image region, and have not considered the vaccine failure caused by image noises, thereby still suffering from the issues of low imperceptibility and robustness. To address the above issues, we propose an Attention-Guided Watermark Vaccine (AGWV) scheme. Specifically, we propose pixel-feature attention (PFA) to identify the proper region for adding watermark vaccine, so as to achieve high imperceptibility for the added watermark vaccine. Then, we adopt image noises to perturb the vaccinated images and further optimize the watermark vaccine to correct the attention bias caused by image noise, thereby enhancing the robustness of watermark vaccines. Moreover, we design a vaccine evaluation model to intuitively evaluate the protective performances of watermark vaccines. Extensive experiments demonstrate that the proposed AGWV outperforms the state-of-the-arts in the aspects of both imperceptibility and robustness for defending against watermark removal models. Supplementary Material is available at https://github.com/YujiangLi0v0/ICME25.git
Yujiang Li, Zhili Zhou 0001, Zhongliang Yang, Baowei Wang, Tao Qi 0001, Xiaohua Xie, Jiantao Zhou 0001
ICME2
2025 Zero Matrix guided Adaptive Image Vaccine against Diffusion Model-based Multitask
Yujiang Li, Zhili Zhou 0001, Ruohan Meng, Baowei Wang, Cheng Qiao, Jiantao Zhou 0001
ACM Multimedia2
2025 Beyond Statistical Estimation: Differentially Private Individual Computation via Shuffling
Shaowei Wang 0003, Changyu Dong, Xiangfu Song, Jin Li 0002, Zhili Zhou 0001, Di Wang 0015
USENIX Security Symposium5
2025 A trigger-perceivable backdoor attack framework driven by image steganography
Weixuan Tang 0002, Yuan Rao 0002, Zhili Zhou 0001, Fei Peng 0001
Pattern Recognit.4
2025 Compressed Domain Invariant Adversarial Representation Learning for Robust Audio Deepfake Detection
abstract
The primary aim of audio deepfake detection (ADD) is to thwart deception arising from forged audio generated through text-to-speech or voice conversion technologies. However, encoding speech signals using diverse compression algorithms introduces discrepancies that significantly impair the performance of existing countermeasure systems. To tackle these challenges, this letter proposes a robust audio deepfake detection method based on Compressed Domain Invariant Adversarial Representation Learning with Adaptive Token Pooling (DANet-ATP). This framework incorporates a Compression Codecs Discriminator (CCD) that, through adversarial learning in tandem with the backbone network, enhances the model's ability to extract more robust features across diverse compression codecs. Moreover, to efficiently prune redundant frame-level features while retaining vital spoofing cues, the letter designs a plug-and-play, parameter-free Adaptive Token Pooling module, significantly improving detection performance. Experimental results on the ASVspoof2021 DF dataset showcase the exceptional performance of the proposed model. Furthermore, a series of ablation experiments validate the validity and effectiveness of the proposed method.
Chengsheng Yuan 0001, Yifei Chen 0013, Zhili Zhou 0001, Zhihua Xia, Yongfeng Huang 0001
IEEE Signal Process. Lett.3
2025 DGADM-GIS: Deterministic Guided Additive Diffusion Model for Generative Image Steganography
abstract
In recent years, generative steganography has witnessed remarkable progress in the field of covert communication. It leverages techniques such as generative adversarial networks (GANs) or flow-based generative models (GLOW) to generate stego images. However, these approaches often grapple with the dilemma of achieving optimal steganographic capacity while ensuring the accurate extraction of hidden information. Additionally, the models occasionally still generate low-quality images that are highly vulnerable to detection by steganalysis tools. To tackle the aforementioned challenges and enhance the overall performance of generative image steganography, this paper proposes the deterministic guided additive diffusion model for generative image steganography (DGADM-GIS). Initially, we devise a reversible mapping function that is used for deterministic guided by a provided secret message, and then construct a secret latent Gaussian vector. Moreover, the proposed DGADM-GIS framework designs an additive sampling method based on the superposition principle of normal distribution to obtain a Gaussian vector that satisfies independent, random and obeys the standard normal distribution, which is transformed to a stego image in a way of maintaining the distribution by the diffusion model. Furthermore, we conduct error analysis experiments on our proposed scheme and derive methods to enhance the accuracy of secret information extraction. The experimental results show that our proposed steganographic method exhibits robust resistance to steganalysis. When embedding 3 bits of secret information per pixel, it achieves nearly 100% extraction accuracy.
Chengsheng Yuan 0001, Zhaonan Ji, Xinting Li, Zhili Zhou 0001, Zhihua Xia, Q. M. Jonathan Wu
IEEE Trans. Dependable Secur. Comput.4
2025 Google Map-Based Password Authentication Systems Using Tolerant Distance and Homomorphic Encryption
abstract
Passwords are widely used for authentication in Internet applications. Recently, users tend to adopt graphical passwords instead of traditional alphanumeric passwords, since it is much easier for humans to remember images than verbal representations. However, the existing graphical password authentication systems generally suffer from three main issues. 1) It is required to remember and perform complicated operations during the registration/login phases, which significantly limits the systems’ usability; 2) The users’ passwords are simply stored as plaintexts in servers, and thus the security is compromised; 3) The users need to register/login to each server separately when they are applied in multi-server environment. To address the above issues, we propose a user-friendly and secure Google map-based graphical password (FS-GMGP) system using tolerant distance and homomorphic encryption. By using a homomorphic encryption scheme, each user encrypts his password point and response point selected on Google map, while the servers compute and decrypt the distance between the two encrypted points and then compare the resulting value with a tolerant distance for authentication. Moreover, the FS-GMGP system is extended for multi-server environment. The evaluation results and security analysis show that the FS-GMGP and its extended version achieve desirable usability and security in single-server environment and multi-server environment, respectively.
Zhili Zhou 0001, Ching-Nung Yang, Shaowei Wang 0003, Guoshun Nan, Stelvio Cimato, Yifeng Zheng 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.1
2025 Side-Channel Attacks and New Principles in the Shuffle Model of Differential Privacy
abstract
The shuffle model employs a shuffler to anonymize and permute user messages, thereby enhancing privacy/utility trade-offs compared to the local model. Ideally, it assumes perfect message anonymity protection against adversaries, allowing each user to hide among a large population. However, in contexts like mobile/edge networks or in scenarios where the shuffler is curious, this assumption is frequently unrealistic. In this study, we demonstrate the vulnerability of the shuffle model to communication side-channel attacks, which substantially compromise privacy amplification via shuffling. We categorize side-channel information in the shuffle model into three types: (i) in-out information, revealing the victim user’s participation and timing, (ii) message-cardinality information, indicating the victim’s message count, and (iii) message-length information, disclosing the victim’s message length(s). Numerical results indicate these attacks increase privacy loss by 200% to 4100%, revealing secret value with probability more than 90%. After theoretically analyzing the remaining privacy amplification effects, we suggest several countermeasures and principles to alleviate degradation caused by these attacks: (a) appending padding bits to each message to counter message-length attacks, (b) maximizing query parallelization to elude in-out attacks and increase the population for privacy amplification, and (c) sending dummy messages to exchange communication costs for improved privacy amplification effects. The newly proposed paradigms and principles significantly save privacy budget in comparison to current models under attack.
Shaowei Wang 0003, Changyu Dong, Jin Li 0002, Zhili Zhou 0001, Di Wang 0015, Zikai Wen
IEEE Trans. Inf. Forensics Secur.5
2025 Efficient Streaming Voice Steganalysis in Challenging Detection Scenarios
abstract
In recent years, there has been an increasing number of information hiding techniques based on network streaming media, focusing on how to covertly and efficiently embed secret information into real-time transmitted network media signals to achieve concealed communication. The misuse of these techniques can lead to significant security risks, such as the spread of malicious code, commands, and viruses. Current steganalysis methods for network voice streams face two major challenges: efficient detection under low embedding rates and short duration conditions. These challenges arise because, with low embedding rates (e.g., as low as 10%) and short transmission durations (e.g., only 0.1s), detection models struggle to acquire sufficiently rich sample features, making effective steganalysis difficult. To address these challenges, this paper introduces a Dual-View VoIP Steganalysis Framework (DVSF). The framework first randomly obfuscates parts of the native steganographic descriptors in VoIP stream segments, making the steganographic features of hard-to-detect samples more pronounced and easier to learn. It then captures fine-grained local features related to steganography, building on the global features of VoIP. Specially constructed VoIP segment triplets further adjust the feature distances within the model. Ultimately, this method effectively address the detection difficulty in VoIP. Extensive experiments demonstrate that our method significantly improves the accuracy of streaming voice steganalysis in these challenging detection scenarios, surpassing existing state-of-the-art methods and offering superior near-real-time performance.
Zhengyang Fang, Zhongliang Yang, Zhili Zhou 0001, Linna Zhou
IEEE Trans. Inf. Forensics Secur.4
2025 EPREAR:An Efficient Attribute-Based Proxy Re-Encryption Scheme With Fast Revocation for Data Sharing in AIoT
abstract
The Artificial Intelligence of Things (AIoT) is driving human society from “information” to “intelligence”, and the information technology industry is undergoing tremendous changes. However, AIoT data faces security threats such as leakage and illegal access when assisted by third parties. Therefore, some scholars use attribute-based proxy re-encryption (ABPRE) for secure sharing of data. However, the existing ABPRE schemes suffer from high computational overhead and inefficient attribution revocation, which seriously hinders practical application. To solve these problems, in this paper, we propose an efficient attribute-based proxy re-encryption scheme with fast attribute revocation (EPREAR). We design a non-interactive zero-knowledge proof protocol based on blockchain to ensure the verifiability of the key during attribute revocation. Furthermore, we devise a boundless encryption and decryption mechanism to enable the system's encryption and decryption with a fixed computation overhead, regardless of the size of the attribute set. And EPREAR possesses the ability to add infinite attributes without re-initializing the system. Finally, we perform theoretical and experimental analyses that show EPREAR has excellent computational performance. As a consequence, it has better application value in AIoT.
Yong Xie 0003, Cong Peng 0005, Xiong Li 0002, Zhili Zhou 0001
IEEE Trans. Mob. Comput.6
2025 Progressive Generative Steganography via High-Resolution Image Generation for Covert Communication
abstract
Recently, as one of the most popular covert communication technologies, generative steganography has received ever-increasing attention due to its promising performance against sophisticated steganalysis tools. However, it is quite difficult for the existing generative steganographic approaches to find a good tradeoff between hiding capacity and extraction accuracy, mainly due to the small capacity of their hiding spaces. To overcome this shortcoming, a Progressive Generative Steganography (PGS) network architecture is proposed to hide a secret message during the progressive image generation process to realize secure covert communication. Specifically, we first propose a robust Secret-to-Noise (S2N) mapping method to encode the secret message as a set of noise maps. Then, guided by these noise maps, a set of corresponding images ranging from low resolution to high resolution are progressively generated by the Single Generative Adversarial Networks (SINGAN). Consequently, a large-sized secret message can be hidden in the finally generated high-resolution image, since a set of high-capacity hiding spaces can be provided by the process of progressive image generation. Moreover, to improve the quality of image generation and the accuracy of secret message extraction, a Dense Secret-Feature Connection (DSFC) strategy is designed and integrated into the proposed PGS network architecture. Extensive experiments demonstrate that the proposed PGS outperforms the existing approaches in the aspects of both hiding capacity and message extraction, while maintaining promising anti-detectability and imperceptibility for covert communication.
Zhili Zhou 0001, Wensheng Zhang 0002, Zhengdao Li, Huilin Ge, Bin Qiu, Fengjun Xiao, Yongfeng Huang 0001
ACM Trans. Multim. Comput. Commun. Appl.1
2024 Dig a Hole and Fill in Sand: Adversary and Hiding Decoupled Steganography
abstract
Deep steganography is a technique that imperceptibly hides secret information into image by neural networks. Existing networks consist of two components, including a hiding component for information hiding and an adversary component for countering against steganalyzers. However, these two components are two ends of the seesaw, and it is difficult to balance the tradeoff between message extraction accuracy and security performance by joint optimization. To address the issues, this paper proposes a steganographic method called AHDeS (Adversary-Hiding-Decoupled Steganography) under the Dig-and-Fill paradigm, wherein the adversary and hiding components can be decoupled into an optimization-based adversary module in the digging process and an INN-based hiding network in the filling process. Specfically in the training stage, the INN is first trained for acquiring the ability of message embedding. In the deployment stage, given the well-trained and fixed INN, the cover image is first iteratively optimized for enhancing the security performance against steganalyzers, followed by the actual message embedding by the INN. Owing to the reversibility of the INN, security performance can be enhanced without sacrificing message extraction accuracy. Experimental results show that AHDeS can achieve the state-of-the-art security performance and visual quality while maintaining satisfied message extraction accuracy.
Weixuan Tang 0002, Yuan Rao 0002, Zhili Zhou 0001, Fei Peng 0001
ACM Multimedia4
2024 CLGuard: Presentation Attack Detection Model using Clean Labels for Copyright Protection
abstract
Presentation Attack Detection Model (PADM) plays a crucial role in biometric authentication, particularly in fingerprint Liveness Detection Model (FLDM). However, FLDM is susceptible to various unauthorized usage and dissemination threats, highlighting the urgent necessity to protect its Intellectual Property (IP). While previous backdoor watermarking techniques have been effective in authenticating the IP of FLDM, they unfortunately pose a risk to its performance. Thus, this paper presents a novel model watermarking strategy named CLGuard, leveraging robust fingerprint attributes to create authentic label watermarks, facilitating the verification of ownership for FLDM. Notably, these watermarks seamlessly integrate into both the input and output layers, minimizing any irreversible modifications to the feature space of FLDM, ensuring optimal performance. Initially, a selection of High Complexity Inputs (HCI) is chosen based on robust fingerprint attributes, and watermark data is embedded into the HCI set using imperceptible backdoor. Simultaneously, a coding network is deployed to conceal the watermark data within the background layer of the samples, mitigating any adverse impacts on the model's deep feature space. Subsequently, a mapping function is established between triggers and original labels, enabling the fine-tuning of the model with embedded watermarks on a diverse mixed dataset. Ultimately, IP is authenticated by leveraging trigger sets and original misidentification sets. Comprehensive experiments on multiple benchmark datasets demonstrate that CLGuard effectively authenticates suspicious PADM IP without introducing anomalous input-output pairs, thus preserving the original task performance. Furthermore, it withstands attacks such as fine-tuning, neuronal cleanse, and watermark removal, showcasing reliability, stealthiness, fidelity, and robustness.
Chengsheng Yuan 0001, Zhili Zhou 0001, Xinting Li, Zhangjie Fu 0001
MSN3
2024 FIL-FLD: Few-Shot Incremental Learning with EMD Metric for High Generalization Fingerprint Liveness Detection
Chengsheng Yuan 0001, Wenqian Qiu, Zhili Zhou 0001, Xinting Li, Xianyi Chen
PRCV (15)3
2024 Efficient object detector via dynamic prior and dynamic feature fusion
abstract
Abstract Sparse R-CNN is a new paradigm of object detection, which predicts objects in a sparse way. However, there are some limitations in Sparse R-CNN. One is the presence of weak prior information caused by fixed learnable proposal boxes and features across different images, necessitating excessive iterations for the model to refine its predictions; the other is the inadequate exploitation of multi-scale information, leading to the sub-optimal detection performance. Thus, building upon Sparse R-CNN, we propose an efficient detector that incorporates dynamic prior and dynamic feature fusion, called $D^{2}$-Det. In particular, for the dynamic prior part, a prior information generator module dynamically generates proposal features and boxes as the dynamic prior for different images to alleviate the inference-inefficient iterative refinement process of predictions, and we further propose the class scores decoupling method to reduce the computation overhead. Furthermore, for the dynamic feature fusion part, we develop a novel lightweight multi-scale feature fusion module, which dynamically aggregates features from all layers for each proposal box, enabling adaptive feature fusion and improving detection precision by nearly 2 AP. Experiments show that $D^{2}$-Det can achieve 46.6 AP on COCO 2017 with fewer computations for the backbone ResNet50, surpassing most of the state-of-the-art detectors.
Zhili Zhou 0001, Gaobo Yang, Q. M. Jonathan Wu
Comput. J.3
2024 Encrypted Domain Secret Medical-Image Sharing With Secure Outsourcing Computation in IoT Environment
abstract
In existing secret medical-image sharing (SMIS) schemes, to protect and manage secret medical-images (SMIs), the sharing and recovery of each SMI are implemented by local servers of medical institutions. However, since a lot of SMIs are produced by personal smart terminal devices in Internet of Things (IoT) environment, directly implementing the sharing and recovery processes will cause excessive communication and computing burden for those local servers, which makes the existing SMIS schemes not suitable for IoT environment. To address the above issue, we propose an encrypted domain SMIS (Enc-SMIS) scheme with secure outsourcing computation for protecting and managing medical images in IoT environment. In the proposed scheme, the medical images are first encrypted using fully homomorphic encryption (FHE) and then outsourced to a cloud server for generating a set of image shares. Subsequently, these shares are stored separately in different local servers of medical institutions. Furthermore, the recovery process is also outsourced to the cloud server when doctors need to observe the patients’ medical images. Compared with the existing SMIS schemes, the proposed Enc-SMIS scheme alleviates the computing and communication burden on local servers significantly with secure outsourcing computation in the semi-honest model, and thus supports the storage and management of medical images well in IoT environment.
Jingwang Huang, Zhili Zhou 0001, Keping Yu, Ching-Nung Yang, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2024 A statistical approach to secure health care services from DDoS attacks during COVID-19 pandemic
Zhili Zhou 0001, Akshat Gaurav, Brij B. Gupta, Hédi Hamdi, Nadia Nedjah
Neural Comput. Appl.1
2024 Generative Steganography Based on Long Readable Text Generation
abstract
Text steganography has received a lot of attention in the application of covert communication. How to ensure desirable capacity and imperceptibility has become a key issue in text steganography. There are two typical approaches, i.e., text-selection-based steganography and text-generation-based steganography. However, the text-selection-based approaches generally have the very low hidden capacity and are not applicable in practical scenarios. Although the text-generation-based approaches can embed secret messages with higher capacity during text generation, they are prone to semantic incoherence and semantic errors when generating long texts. To address the abovementioned issues, this article proposes a novel text steganography based on long readable text generation. It first determines the topic of the stego-text according to the scenarios of the communication parties. Then, the plug and play language model (PPLM) is explored to generate the long readable stego-text conforming to the topic with semantic coherency. A given secret message is hidden during text generation by selecting proper words in an established embeddable candidate word pool (ECWP). Establishing the ECWP prevents the language model (LM) from selecting words with low probability in the text generation, thereby avoiding the generation of low-quality or even grammatically incorrect stego-text. Experimental results show that the proposed approach significantly increases hidden capacity while maintaining good imperceptibility compared with the existing approaches.
Zhili Zhou 0001, Chinmay Chakraborty, Meimin Wang, Q. M. Jonathan Wu, Xingming Sun, Keping Yu
IEEE Trans. Comput. Soc. Syst.2
2024 Meta Security Metric Learning for Secure Deep Image Hiding
abstract
Deep Image Hiding (DIH) aims to imperceptibly hide images within image. To improve its security performance, some DIH methods design Security Metrics (SMs) to guide the learning of their hiding networks. However, these methods focus on optimizing their anti-steganalysis ability on specific SMs, resulting in inferior generalization ability. To overcome these limitations, in this paper, we introduce meta-learning into DIH and propose Meta Security Metric-based DIH (MSM-DIH). In the MSM-DIH, the Invertible Neural Network (INN)-based hiding network is learned under the guidance of a learnable meta SM generalized from multiple fixed source SMs, and each SM is composed of a metric network and a contrastive loss function. Specifically, MSM-DIH is trained with bi-level optimization. In the outer optimization, a meta SM is learned to assign higher security scores for more advanced stego images. Besides, the domain knowledge of steganalysis is transferred from the multiple pre-trained source metric networks to the meta metric network, so as to enhance the generalization ability of the meta SM. In the inner optimization, the hiding network is learned to generate more secure stego images according to the learned meta SM. Experimental results show that our MSM-DIH has achieved the best security performance in most cases.
Weixuan Tang 0004, Zhili Zhou 0001, Ruohan Meng, Guoshun Nan, Yun Q. Shi 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Joint Cost Learning and Payload Allocation With Image-Wise Attention for Batch Steganography
abstract
In recent years, although cost learning methods have made great progress in single-image steganography, its development in batch steganography is relatively slower, which is a more practical communication scenario in the real world. The difficulties are capturing the full view of the image batch and building connections between cost learning and payload allocation by neural networks. To address the issues, this paper proposes a cost learning framework for batch steganography called JoCoP (Joint Cost Learning and Payload Allocation), wherein the policy network is designed to learn the optimal embedding policies for a batch of images via the collaboration between a cost learning module and a payload allocation module. In specific layers of the policy network, in the cost learning module, the intermediate feature maps of embedding costs are extracted for different images independently, which are sent to the payload allocation module. In the payload allocation module, to implement implicit payload allocation, the feature maps corresponding to different images within the same batch are adjusted by an image-wise attention mechanism. Afterwards, these adjusted feature maps are returned to the cost learning module for subsequent feature extraction in the next layer. Owing to the collaboration between the two modules and the batch-level receptive field in the image-wise attention mechanism, the embedding costs and the payload allocation can be jointly optimized in an end-to-end manner. Experimental results show that the proposed JoCoP outperforms existing methods against both single-image steganalyzers and pooled steganalyzers based on feature extraction and convolutional neural networks.
Weixuan Tang 0004, Zhili Zhou 0001, Bin Li 0011, Kim-Kwang Raymond Choo, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.2
2024 Locally Private Set-Valued Data Analyses: Distribution and Heavy Hitters Estimation
abstract
In many mobile applications, user-generated data are presented as set-valued data. To tackle potential privacy threats in analyzing these valuable data, local differential privacy has been attracting substantial attention. However, existing approaches only provide sub-optimal utility and are expensive in computation and communication for set-valued data distribution estimation and heavy-hitter identification. In this paper, we propose a utility-optimal and efficient set-valued data publication method (i.e.,Wheel mechanism). On the user side, the computational complexity is only$O(\min \lbrace m\log m, m e^\epsilon \rbrace )$and communication costs are$O(\epsilon +\log m)$bits, where$m$is the number of items,$d$is the domain size and$\epsilon$is the privacy budget, while existing approaches usually depend on$O(d)$or$O(\log d)$($d \gg m$). Our theoretical analyses reveal the estimation errors have been reduced from the previously known$O(\frac{m^{2} d}{n\epsilon ^{2}})$to the optimal rate$O(\frac{m d}{n\epsilon ^{2}})$. Additionally, for heavy-hitter identification, we present a variant of the Wheel mechanism as an efficient frequency oracle, entailing only$O(\sqrt{n})$computational complexity. This heavy-hitter protocol achieves an identification bar of$\tilde{O}(\frac{1}{\epsilon }\sqrt{\frac{m}{n} \log d})$, reducing by a factor of$\sqrt{m}$relative to existing protocols. Extensive experiments demonstrate our methods are 3-100x faster than existing approaches and have optimized statistical efficiency.
Shaowei Wang 0003, Yuntong Li, Yusen Zhong, Kongyang Chen, Xianmin Wang, Zhili Zhou 0001, Fei Peng 0001, Yuqiu Qian, Jiachun Du, Wei Yang 0011
IEEE Trans. Mob. Comput.6
2024 ARES: On Adversarial Robustness Enhancement for Image Steganographic Cost Learning
abstract
Taking the steganalytic discriminators as the adversaries, the existing Generative Adversarial Networks (GAN)-based steganographic approaches learn the implicit cost functions to measure the embedding distortion for steganography. However, the steganalytic discriminators in these approaches are trained by the stego-samples with insufficient diversity, and their network structures offer very limited representational capacity. As a result, these steganalytic discriminators will not exhibit robustness to various steganographic patterns, which causes learning suboptimal cost functions, thus compromising the anti-steganalysis capability. To address this issue, we propose a novel GAN-based steganographic approach, in which the Diversified Inverse-Adversarial Training (DIAT) strategy and the Steganalytic Feature Attention (SteFA) structure are designed to train a robust steganalytic discriminator. Specifically, the DIAT strategy provides the steganalytic discriminator with an expanded feature space by generating diversified adversarial stego-samples; the SteFA structure enables the steganalytic discriminator to capture more various steganalytic features by employing the channel-attention mechanism on higher-order statistics. Consequently, the steganalytic discriminator can build a more precise decision boundary to make it more robust, which facilitates learning a superior steganographic cost function. Extensive experiments demonstrate that the proposed steganographic approach achieves promising anti-steganalysis capability over the state-of-the-arts under the same embedding payloads.
Zhili Zhou 0001, Ruohan Meng, Shaowei Wang 0003, Hongyang Yan, Q. M. Jonathan Wu
IEEE Trans. Multim.2
2024 Blockchain-Based Secure and Efficient Secret Image Sharing With Outsourcing Computation in Wireless Networks
abstract
Secret Image Sharing (SIS) is the technology that shares any given secret image by generating and distributing$n$shadow images in the way that any subset of$k$shadow images can restore the secret image. However, in the existing SIS schemes, the shadow images will be easily tampered and corrupted during the communication, which will pose serious security issues. Recently, blockchain has emerged as a promising paradigm in the field of data communication and information security. To securely communicate and effectively protect the secret image data in wireless networks, we propose a Blockchain-based Secure and Efficient Secret Image Sharing (BC-SESIS) scheme with outsourcing computation in wireless networks. In the proposed BC-SESIS scheme, the shadow images are encrypted and stored in the blockchain to prevent them from being tampered and corrupted. The identity authentication-enabled smart contract is deployed to achieve the$(k,n)$threshold for secret image restoring. Furthermore, to reduce the computational burden of smart contract and users, an efficient outsourcing computation method is designed to outsource the restoring task, which is securely implemented by agent miners in the encryption domain. Theoretical analysis and extensive experiments demonstrate that the BC-SESIS scheme can achieve desirable communication security and high computational efficiency in the wireless networks.
Zhili Zhou 0001, Yao Wan 0003, Keping Yu, Shahid Mumtaz, Ching-Nung Yang, Mohsen Guizani
IEEE Trans. Wirel. Commun.1
2023 Glow Model-Based Latent Vector Optimization for Generative Image Steganography in Edge and Cloud Computing Environment
abstract
In edge and cloud computing environments, to protect and manage secret information, the sharing and recovery of each secret image are implemented by local servers. However, since existing Generative Image Steganography(GIS) schemes face issues such as low-quality image generation and small hiding capacity. This necessitates the generation of a large number of stego-images to meet the demands of information transmission, thereby imposing a excessive computational burden for those local servers, the above reasons make the existing GIS schemes not suitable for edge and cloud computing environments. To address the above issue, we propose a Latent Vector Optimization(LVO) scheme for GIS with high-quality image generation and large hiding capacity. In the proposed scheme, we introduce the concept of latent vector optimization, wherein the hiding probability of each element within the latent vector is computed based on its expected influence on the quality of the resulting stego-image. Furthermore, our LVO scheme employs an adaptive approach to identify the optimal locations for embedding information while considering a predefined hiding capacity. This adaptation involves giving priority to modifying elements in dimensions characterized by a low latent vector hiding probability, as guided by the characteristics of natural images. Simultaneously, the scheme hides the secret message within elements associated with a high latent vector hiding probability, thus achieving a large hiding capacity while minimizing any adverse effects on the stego-image quality. Compared with the existing GIS schemes, the proposed LVO scheme enhances security, provides high-quality image generation, a large data hiding capacity, meeting the requirements with fewer stego-images. This significantly reduces the communication and computational burden on local servers.
Zhipeng Bao, Zhili Zhou 0001, Xutong Cui, Chengsheng Yuan 0001
ICPADS2
2023 Geometric correction code-based robust image watermarking
abstract
Abstract Digital image watermarking is one of the effective schemes to protect the copyrights of still images. However, the existing watermarking schemes are still not robust enough to the common geometric transformation attacks such as arbitrary rotation, scaling and shifting with desirable hiding capacity. To address this issue, we propose a robust watermarking scheme based on geometric correction codes (GCCs). In this scheme, the watermark and pre‐set GCCs are combined and embedded into a cover image to obtain the watermarked image. At the stage of watermark extraction, the watermarked image, under a variety of geometric transformation attacks, can be geometrically corrected by minimising the difference between the extracted and the original GCCs, then the watermark is extracted from the watermarked image. The experiments demonstrate that, compared to the typical watermarking schemes, the proposed scheme achieves much higher robustness to the common geometric transformation attacks and comparable invisibility with the same embedding capacity.
Zhili Zhou 0001, Jianyu Zhu, Yuecheng Su, Meimin Wang, Xingming Sun
IET Image Process.1
2023 Dual efficient reversible data hiding using Hamming code and OPAP
Cheonshik Kim, Ching-Nung Yang, Zhili Zhou 0001, Ki-Hyun Jung
J. Inf. Secur. Appl.3
2023 Siamese transformer network-based similarity metric learning for cross-source remote sensing image retrieval
Chun Ding, Meimin Wang, Zhili Zhou 0001, Teng Huang 0001, Xiaoliang Wang 0002, Jin Li 0002
Neural Comput. Appl.3
2023 Deepfake Fingerprint Detection Model Intellectual Property Protection via Ridge Texture Enhancement
abstract
In addition to relying on super computing power and professional domain knowledge, training a high-precision deepfake fingerprint detection model (DFDM) to authenticate the fingerprints also requires the support of massive private fingerprint data. To sum up, the DFDM should be deemed as intellectual property (IP) of the trainers, so it is crucial to protect IP. Currently, most watermarking-based IP protection schemes are implemented by introducing additional tasks, such as constructing trigger sets, fine-tuning model weights, etc., which severely impair the performance of the original task and increase the training cost. Inspired by the feature knowledge learned by the model, this letter proposes an IP protection (IPP) scheme for DFDM by verifying whether the suspect model contains the fingerprint ridge features learned by the victim model from another perspective based on the verifier. Firstly, the local binary pattern (LBP) is used to enhance the ridge texture on the fingerprint samples, so that DFDM can better learn the ridge features. Then, a DFDM lacking texture augmentation is employed as the adversarial model for training the meta-verifier without any alteration to the model parameters. Finally, the trained meta-verifier is used to determine whether the suspected model contains the ridge features in the victim model. The public fingerprint dataset (LivDet2017) was leveraged in the DFDM training process to validate our approach. Experimental results show that the proposed scheme can verify the IP of DFDM and is robust to some common attacks.
Chengsheng Yuan 0001, Zhili Zhou 0001, Zhangjie Fu 0001, Zhihua Xia
IEEE Signal Process. Lett.3
2023 Secret-to-Image Reversible Transformation for Generative Steganography
abstract
Recently, generative steganography that transforms secret information to a generated image has been a promising technique to resist steganalysis detection. However, due to the inefficiency and irreversibility of the secret-to-image transformation, it is hard to find a good trade-off between the information hiding capacity and extraction accuracy. To address this issue, we propose a secret-to-image reversible transformation (S2IRT) scheme for generative steganography. The proposed S2IRT scheme is based on a generative model, i.e., Glow model, which enables a bijective-mapping between latent space with multivariate Gaussian distribution and image space with a complex distribution. In the process of S2I transformation, guided by a given secret message, we construct a latent vector and then map it to a generated image by the Glow model, so that the secret message is finally transformed to the generated image. Owing to good efficiency and reversibility of S2IRT scheme, the proposed steganographic approach achieves both high hiding capacity and accurate extraction of secret message from generated image. Furthermore, a separate encoding-based S2IRT (SE-S2IRT) scheme is also proposed to improve the robustness to common image attacks. The experiments demonstrate the proposed steganographic approaches can achieve high hiding capacity (up to 4bpp) and accurate information extraction (almost 100% accuracy rate) simultaneously, while maintaining desirable anti-detectability and imperceptibility.
Zhili Zhou 0001, Yuecheng Su, Jin Li 0002, Keping Yu, Q. M. Jonathan Wu, Zhangjie Fu 0001, Yun Q. Shi 0001
IEEE Trans. Dependable Secur. Comput.1
2023 Generative Steganography via Auto-Generation of Semantic Object Contours
abstract
As a promising technique of resisting steganalysis detection, generative steganography usually generates a new image driven by secret information as the stego-image. However, it generally encodes secret information as entangled features in a non-distribution-preserving manner for the stego-image generation, which leads to two common issues: 1) limited accuracy of information extraction, and 2) low security in feature-domain. To address the above issues, we propose a generative steganographic framework via auto-generation of semantic object contours, in which a given secret message is encoded as the disentangled features,i.e., object-contours, in a distribution-preserving manner for the stego-image generation. In this framework, we propose a contour generative adversarial nets (CtrGAN) consisting of a contour-generator and a contour-discriminator, which are adversarially trained with reinforcement learning. To realize the generative steganography, by using the contour-generator of the trained CtrGAN, a contour point selection (CPS)-based encoding strategy is designed to encode the secret message as the contours. Then, the BicycleGAN is employed to transform the generated contours to the corresponding stego-image. Extensive experiments demonstrate the proposed steganographic approach achieves superior performance in the aspects of information extraction accuracy, especially under common image attacks, and feature-domain security, compared to the state-of-the-arts.
Zhili Zhou 0001, Xiaohua Dong, Ruohan Meng, Meimin Wang, Hongyang Yan, Keping Yu, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.1
2023 Sequential Order-Aware Coding-Based Robust Subspace Clustering for Human Action Recognition in Untrimmed Videos
abstract
Human action recognition (HAR) is one of most important tasks in video analysis. Since video clips distributed on networks are usually untrimmed, it is required to accurately segment a given untrimmed video into a set of action segments for HAR. As an unsupervised temporal segmentation technology, subspace clustering learns the codes from each video to construct an affinity graph, and then cuts the affinity graph to cluster the video into a set of action segments. However, most of the existing subspace clustering schemes not only ignore the sequential information of frames in code learning, but also the negative effects of noises when cutting the affinity graph, which lead to inferior performance. To address these issues, we propose a sequential order-aware coding-based robust subspace clustering (SOAC-RSC) scheme for HAR. By feeding the motion features of video frames into multi-layer neural networks, two expressive code matrices are learned in a sequential order-aware manner from unconstrained and constrained videos, respectively, to construct the corresponding affinity graphs. Then, with the consideration of the existence of noise effects, a simple yet robust cutting algorithm is proposed to cut the constructed affinity graphs to accurately obtain the action segments for HAR. The extensive experiments demonstrate the proposed SOAC-RSC scheme achieves the state-of-the-art performance on the datasets of Keck Gesture and Weizmann, and provides competitive performance on the other 6 public datasets such as UCF101 and URADL for HAR task, compared to the recent related approaches.
Zhili Zhou 0001, Chun Ding, Jin Li 0002, Eman Mohammadi, Guangcan Liu, Yimin Yang 0001, Q. M. Jonathan Wu
IEEE Trans. Image Process.1
2022 Coverless Information Hiding Based on Probability Graph Learning for Secure Communication in IoT Environment
abstract
To securely transmit secret data between Internet of Things (IoT) nodes, it is required to the implement information hiding technique for secure communication in the IoT environment. The traditional information hiding approaches generally select a multimedia file, such as texts, images, and video clips as the cover, and then embed secret information into the cover by slight modification. However, it is not feasible to directly apply these approaches in the IoT environment for the following reasons. First, it is hard for some IoT nodes to effectively and efficiently process and transmit the complex multimedia data. Second, the modification trace left in the cover will cause the presence of hidden secret information to be easily exposed by steganalysis tools. To address the above issues, we propose a coverless information hiding scheme based on probability graph learning for secure communication in the IoT environment. Instead of modifying an existing multimedia cover, we conceal secret information in a generated sequence of IoT data to realize secure communication between different nodes in the IoT environment. According to the node-data interaction relationships, we first learn the transition probability graph (TPG) to describe the transition probabilities between IoT data elements. Then, guided by a given secret message that needs to be hidden, we sequentially select a set of highly correlated data elements from the TPG to generate the sequence. The experimental results and theoretical analysis demonstrate that the proposed information hiding scheme can achieve high hiding capacity with desirable imperceptibility and security performances in the IoT environment.
Zhili Zhou 0001, Yuecheng Su, Yulan Zhang, Zhihua Xia, Shan Du 0001, Brij B. Gupta, Lianyong Qi
IEEE Internet Things J.1
2022 Improving Generalization by Commonality Learning in Face Forgery Detection
abstract
This paper proposes a commonality learning strategy for face video forgery detection to improve the generalization. Considering various face forgery methods could leave certain similar forgery traces in videos, we attempt to learn the common forgery features from different forgery databases, so as to achieve better generalization in the detection of unknown forgery methods. Firstly, the Specific Forgery Feature Extractors (SFFExtractors) are trained separately for each of given forgery methods. We utilize the U-net structure and consider the triplet loss, location loss, classification loss, and automatic weighted loss to ensure the detection ability of SFFExtractors on the corresponding forgery methods. Next, the Common Forgery Feature Extractor (CFFExtractor) is trained under the supervision of SFFExtractors to explore the commonality of the forgery traces caused by different forgery methods. The extracted common forgery feature is expected to have a good generalization. The experimental results on FaceForensic++ show that the SFFExtractors outperform many state-of-the-arts in face forgery detection. The generalization performance of the CFFExtractor is verified on FaceForensic++, DFDC, and CelebDF. It is proved that commonality learning can be an effective strategy to improve generalization.
Peipeng Yu, Jianwei Fei, Zhihua Xia, Zhili Zhou 0001, Jian Weng 0001
IEEE Trans. Inf. Forensics Secur.4
2022 Spatio-Temporal Feature Encoding for Traffic Accident Detection in VANET Environment
abstract
In the Vehicular Ad hoc Networks (VANET) environment, recognizing traffic accident events in the driving videos captured by vehicle-mounted cameras is an essential task. Generally, traffic accidents have a short duration in driving videos, and the backgrounds of driving videos are dynamic and complex. These make traffic accident detection quite challenging. To effectively and efficiently detect accidents from the driving videos, we propose an accident detection approach based on spatio–temporal feature encoding with a multilayer neural network. Specifically, the multilayer neural network is used to encode the temporal features of video for clustering the video frames. From the obtained frame clusters, we detect the border frames as the potential accident frames. Then, we capture and encode the spatial relationships of the objects detected from these potential accident frames to confirm whether these frames are accident frames. The extensive experiments demonstrate that the proposed approach achieves promising detection accuracy and efficiency for traffic accident detection, and meets the real-time detection requirement in the VANET environment.
Zhili Zhou 0001, Xiaohua Dong, Zhetao Li, Keping Yu, Chun Ding, Yimin Yang 0001
IEEE Trans. Intell. Transp. Syst.1
2022 An Efficient and Secure Identity-Based Signature System for Underwater Green Transport System
abstract
The smart ocean has aroused the interest of government, business, and academia because of the wealth of marine resources. It has been suggested to use underwater Internet of Things (IoT) frameworks to collect a variety of data from smart seas that can aid in the underwater green transport system, ecological sustainability, military intelligence gathering, and a variety of other operations. Because of the limited resources accessible to IoT devices regarding communication overhead, processing expenses, and battery capacity, security and privacy concerns in underwater green transport systems have lately been a critical source of worry. In this context, We presented a unique identity-based authentication mechanism for underwater green transport systems. Our suggested solution uses lightweight authentication mechanisms that prove secure communication between different elements of the green transport system.
Zhili Zhou 0001, Brij B. Gupta, Akshat Gaurav, Yujiang Li, Miltiadis D. Lytras, Nadia Nedjah
IEEE Trans. Intell. Transp. Syst.1
2022 A Fine-Grained Access Control and Security Approach for Intelligent Vehicular Transport in 6G Communication System
abstract
The area of intelligent transport systems (ITS) is attracting growing attention because of the integration of the smart IoT with vehicles that improve user safety and overall travel experience. Vehicular ad hoc network (VANET) is the part of ITS; that deals with the routing protocols and security of smart vehicles. However, due to the rapid increase in the number of smart vehicles, the existing network technology’s resources unable to handle the traffic load. It expects that the 6G communication system has the ability to fulfill the requirements of VANETs. Only a few studies explore this area, but they also overlooked the security aspect of VANETs in 6G communications networks. In this paper, we present an approach to address authentication and security issues for vehicles in VANET. By authenticating cars in the VANET and identifying various cyber assaults such as DDoS, our method significantly contributes to the intelligent transport communication network. Our approach uses the concepts of identity-based encryption to provide access control to the vehicles and deep learning-based techniques for filtering malicious packets. Our identity-based encryption technique is IND-sID-CCA secure, and a state-of-the-art deep learning algorithm detects malicious packets with an accuracy of 99.72%. These results emphasize the validity of our proposed approach for VANETs in 6G communication systems.
Zhili Zhou 0001, Akshat Gaurav, Brij B. Gupta, Miltiadis D. Lytras, Muhammad Imran Razzak
IEEE Trans. Intell. Transp. Syst.1
2022 Blockchain in Big Data Security for Intelligent Transportation With 6G
abstract
The purposes are to investigate how blockchain can solve the security problems in Intelligent Autonomous Transport System (IATS) and intelligentize the logistics transportation development. Regarding the scarcity of trust and concentration of rights caused by the centralized structure of traditional logistics information systems, a blockchain-based IATS is proposed. The system employs Ethereum as the underlying blockchain to record sensitive information, such as system orders, cargos, and personnel information on the blockchain, ensuring the non-tampering and credibility of data. Simultaneously, an order management module, a warehouse management module, a transportation management module, a transaction management module, and a system management module are established. In the meantime, the Light Gradient Boosting Machine (LightGBM) algorithm is utilized to recommend vehicle and cargo matching during transportation. Finally, the constructed algorithm model is simulated to analyze its performance. Results demonstrate that the security prediction accuracy of the proposed algorithm reaches 88.72%; moreover, the security prediction precision, recall, and F1 of the proposed algorithm are considerably better than those of other algorithms. Furthermore, the actual effect of each algorithm is analyzed. The LightGBM algorithm outperforms other algorithms and unused algorithms in click rate, conversion rate, turnover rate, and average response time. Therefore, the constructed blockchain-based IATS has excellent security performance and prediction accuracy, which provides an experimental basis for the later intelligent logistics transportation development.
Zhili Zhou 0001, Meimin Wang, Jingwang Huang, Shengliang Lin 0001, Zhihan Lyu
IEEE Trans. Intell. Transp. Syst.1
2021 Blockchain-based decentralized reputation system in E-commerce environment
Zhili Zhou 0001, Meimin Wang, Ching-Nung Yang, Zhangjie Fu 0001, Xingming Sun, Q. M. Jonathan Wu
Future Gener. Comput. Syst.1
2021 Geometric rectification-based neural network architecture for image manipulation detection
abstract
Determination of image authenticity usually requires the identification and localization of the manipulated regions of images. Hence, image manipulation detection has become one of the most important tasks in the field of multimedia forensics. Recently, Convolutional Neural Networks (CNNs) have achieved promising performance in image manipulation detection. However, it is hard for the existing CNN-based manipulation detection approaches to accurately identify and localize the manipulated regions that have undergone geometric transformations, since CNNs are limited by their inability to be geometrically invariant. To address this issue, we propose a geometric rectification-based neural network architecture for image manipulation detection. In this type of network architecture, following the detection of a set of potential manipulated regions (PMRs) using Region Proposal Network, the Spatial Transformer Network is employed to geometrically rectify the convolutional feature maps (CFMs) of these regions to obtain the geometrically rectified CFMs (GR-CFMs). Subsequently, the residual feature maps (RFMs) are computed to capture the characteristic inconsistency between the CFMs and GR-CFMs of each PMR. Finally, the computed RFMs are automatically integrated with the GR-CFMs by a designed attention module to determine whether each PMR is a manipulated region and to localize the manipulated part at the pixel-level. Extensive experiments on the public data set as well as on our challenging data set demonstrate that the proposed network architecture achieves desirable performance in identifying and localizing regions with common tampering artifacts, which involve geometric transformations.
Zhili Zhou 0001, Wenyan Pan, Q. M. Jonathan Wu, Ching-Nung Yang, Zhihan Lyu
Int. J. Intell. Syst.1
2021 Residual visualization-guided explainable copy-relationship learning for image copy detection in social networks
Zhili Zhou 0001, Yujiang Li, Yulan Zhang, Lianyong Qi, Rui Ma 0020
Knowl. Based Syst.1
2021 Improved CNN-Based Hashing for Encrypted Image Retrieval
abstract
As more and more image data are stored in the encrypted form in the cloud computing environment, it has become an urgent problem that how to efficiently retrieve images on the encryption domain. Recently, Convolutional Neural Network (CNN) features have achieved promising performance in the field of image retrieval, but the high dimension of CNN features will cause low retrieval efficiency. Also, it is not suitable to directly apply them for image retrieval on the encryption domain. To solve the above issues, this paper proposes an improved CNN-based hashing method for encrypted image retrieval. First, the image size is increased and inputted into the CNN to improve the representation ability. Then, a lightweight module is introduced to replace a part of modules in the CNN to reduce the parameters and computational cost. Finally, a hash layer is added to generate a compact binary hash code. In the retrieval process, the hash code is used for encrypted image retrieval, which greatly improves the retrieval efficiency. The experimental results show that the scheme allows an effective and efficient retrieval of encrypted images.
Wenyan Pan, Meimin Wang, Jiaohua Qin, Zhili Zhou 0001
Secur. Commun. Networks4
2021 Multiple Distance-Based Coding: Toward Scalable Feature Matching for Large-Scale Web Image Search
abstract
For scalable feature matching in large-scale web image search, the bag-of-visual-words-based (BOW) approaches generally code local features as visual words to construct an inverted index file to match features efficiently. Both the popular feature coding techniques, i.e., K-means-based vector quantization and scalar quantization, directly quantize features to generate visual words. K-means-based vector quantization requires expensive visual codebook training, whereas scalar quantization leads to the miss of many matches due to the low stability of individual components of feature vectors. To address the above issues, we demonstrate that the corresponding sub-vectors of similar features generally have similar distances to multiple reference points in feature subspace and propose a multiple distance-based feature coding scheme for scalable feature matching. Specifically, based on the distances between the sub-vectors and multiple distinct reference points, we transform each feature to a set of feature codes, where one code is treated as a visual word required to construct the inverted index file whereas the others are embedded into the index file to further verify the feature matching based on the visual words. The proposed coding scheme does not need visual codebook training and shows desirable stability and discriminability. Moreover, in the matching verification, a feature-distance estimation method is proposed to estimate the Euclidean distances between features for an accurate matching verification. Extensive experimental results demonstrate the superiority of the proposed approach in comparison to the other approaches using recent feature quantization methods for large-scale web image search.
Zhili Zhou 0001, Q. M. Jonathan Wu, Xingming Sun
IEEE Trans. Big Data1
2020 Privacy-aware Cold-Start Recommendation based on Collaborative Filtering and Enhanced Trust
abstract
The ever-increasing popularity of the recommender system provides a convenient way for users to find their interesting items among plenty of candidate services. However, on account of the enhancement of user privacy protection consciousness in recent years, users tend to conceal their evaluation information from the public. Thus, a large number of users with little explicit rating information are generated (i.e., cold-start users), which makes it challenging to implement high-quality recommendations. It has become a serious barrier to further and broader applications of the recommender system. In response to this issue, we take social network information into account and first propose TeCF (Trust-enhanced Collaborative Filtering). Our proposal integrates user-based, item-based, and trust-based collaborative filtering methods harmoniously and achieves a good trade-off between privacy preservation and service recommendation accuracy. A case study is conducted to validate the feasibility and comprehensiveness of our research.
Fan Wang 0020, Weiyi Zhong, Xiaolong Xu 0001, Wajid Rafique, Zhili Zhou 0001, Lianyong Qi
DSAA5
2020 Region-Level Visual Consistency Verification for Large-Scale Partial-Duplicate Image Search
abstract
Most recent large-scale image search approaches build on a bag-of-visual-words model, in which local features are quantized and then efficiently matched between images. However, the limited discriminability of local features and the BOW quantization errors cause a lot of mismatches between images, which limit search accuracy. To improve the accuracy, geometric verification is popularly adopted to identify geometrically consistent local matches for image search, but it is hard to directly use these matches to distinguish partial-duplicate images from non-partial-duplicate images. To address this issue, instead of simply identifying geometrically consistent matches, we propose a region-level visual consistency verification scheme to confirm whether there are visually consistent region (VCR) pairs between images for partial-duplicate search. Specifically, after the local feature matching, the potential VCRs are constructed via mapping the regions segmented from candidate images to a query image by utilizing the properties of the matched local features. Then, the compact gradient descriptor and convolutional neural network descriptor are extracted and matched between the potential VCRs to verify their visual consistency to determine whether they are VCRs. Moreover, two fast pruning algorithms are proposed to further improve efficiency. Extensive experiments demonstrate the proposed approach achieves higher accuracy than the state of the art and provide comparable efficiency for large-scale partial-duplicate search tasks.
Zhili Zhou 0001, Q. M. Jonathan Wu, Yimin Yang 0001, Xingming Sun
ACM Trans. Multim. Comput. Commun. Appl.1
2020 Minimizing Redundancy to Satisfy Reliability Requirement for a Parallel Application on Heterogeneous Service-Oriented Systems
abstract
Reliability is widely identified as an increasingly relevant issue in heterogeneous service-oriented systems because processor failure affects the quality of service to users. Replication-based fault-tolerance is a common approach to satisfy application's reliability requirement. This study solves the problem of minimizing redundancy to satisfy reliability requirement for a directed acyclic graph (DAG)-based parallel application on heterogeneous service-oriented systems. We first propose the enough replication for redundancy minimization (ERRM) algorithm to satisfy application's reliability requirement, and then propose heuristic replication for redundancy minimization (HRRM) to satisfy application's reliability requirement with low time complexity. Experimental results on real and randomly generated parallel applications at different scales, parallelism, and heterogeneity verify that ERRM can generate least redundancy followed by HRRM, and the state-of-the-art MaxRe and RR algorithm. In addition, HRRM implements approximate minimum redundancy with a short computation time.
Guoqi Xie, Yuekun Chen, Yang Bai 0007, Zhili Zhou 0001, Renfa Li, Keqin Li 0001
IEEE Trans. Serv. Comput.5
2019 Intrusion Detection and Prevention in Cloud, Fog, and Internet of Things
abstract
We are pleased to announce the publication of the special issue focusing on intrusion detection and prevention in cloud, fog, and Internet of Things (IoT).Internet of Things (IoT), cloud, and fog computing paradigms are as a whole provision a powerful large-scale computing infrastructure for many data and computation intensive applications.Specifically, the IoT technologies and deployment can widely perceive our physical world at a fine granularity and generate sensing data for further insight extraction.The fog computing facilities can provide computing power near the IoT devices where data are generated, aiming to achieve fast data processing for time critical applications or save the amount of data transmitted into cloud for storage or further processing.The cloud computing platforms can offer big data storage and large-scale processing services for cheap long-term storage or data intensive analytics with more advanced data mining models.Hence, it can be seen that the IoT/fog/cloud computing infrastructures can support the whole lifecycle of large-scale applications where big data collection, transmission, storage, processing, and mining can be seamlessly integrated.However, these state-of-the-art computing infrastructures still suffer from severe security and privacy threats because of their built-in properties such as the ubiquitous-access and multitenancy features of
Xuyun Zhang, Yuan Yuan 0004, Zhili Zhou 0001, Shancang Li, Lianyong Qi, Deepak Puthal
Secur. Commun. Networks3
2019 Coverless image steganography using partial-duplicate image retrieval
Zhili Zhou 0001, Yan Mu, Q. M. Jonathan Wu
Soft Comput.1
2018 MCRS: A course recommendation system for MOOCs
Hao Zhang 0066, Tao Huang 0017, Zhihan Lyu, Sanya Liu, Zhili Zhou 0001
Multim. Tools Appl.5
2018 Encoding multiple contextual clues for partial-duplicate image retrieval
Zhili Zhou 0001, Q. M. Jonathan Wu, Xingming Sun
Pattern Recognit. Lett.1
2018 Hybrid computation offloading for smart home automation in mobile cloud computing
Jie Zhang 0053, Zhili Zhou 0001, Leilei Gan, Xuyun Zhang, Lianyong Qi, Xiaolong Xu 0001, Wan-Chun Dou
Pers. Ubiquitous Comput.2
2017 An optimized design of CAN FD for automotive cyber-physical systems
Yong Xie 0003, Ryo Kurachi, Guoqi Xie, Yong Dou, Zhili Zhou 0001
J. Syst. Archit.6
2017 Effective and Efficient Global Context Verification for Image Copy Detection
abstract
To detect illegal copies of copyrighted images, recent copy detection methods mostly rely on the bag-of-visual-words (BOW) model, in which local features are quantized into visual words for image matching. However, both the limited discriminability of local features and the BOW quantization errors will lead to many false local matches, which make it hard to distinguish similar images from copies. Geometric consistency verification is a popular technology for reducing the false matches, but it neglects global context information of local features and thus cannot solve this problem well. To address this problem, this paper proposes a global context verification scheme to filter false matches for copy detection. More specifically, after obtaining initial scale invariant feature transform (SIFT) matches between images based on the BOW quantization, the overlapping region-based global context descriptor (OR-GCD) is proposed for the verification of these matches to filter false matches. The OR-GCD not only encodes relatively rich global context information of SIFT features but also has good robustness and efficiency. Thus, it allows an effective and efficient verification. Furthermore, a fast image similarity measurement based on random verification is proposed to efficiently implement copy detection. In addition, we also extend the proposed method for partial-duplicate image detection. Extensive experiments demonstrate that our method achieves higher accuracy than the state-of-the-art methods, and has comparable efficiency to the baseline method based on the BOW quantization.
Zhili Zhou 0001, Yunlong Wang 0006, Q. M. Jonathan Wu, Ching-Nung Yang, Xingming Sun
IEEE Trans. Inf. Forensics Secur.1
2014 Combination of SIFT Feature and Convex Region-Based Global Context Feature for Image Copy Detection
Zhili Zhou 0001, Xingming Sun, Yunlong Wang 0006, Zhangjie Fu 0001, Yun Q. Shi 0001
IWDW1
2014 A novel signature based on the combination of global and local signatures for image copy detection
abstract
ABSTRACT To prevent digital image from unauthorized use, image copy detection is an important technique in the field of copyright protection. The conventional methods of image copy detection concentrate on extracting global or local signatures to resist various kinds of copy attacks. However, the global signatures are sensitive to some geometric transformations, such as rotation and cropping, while the local signatures are not discriminative enough to identify copies from similar images. Considering both the robustness and discriminability, a novel image signature based on the combination of global and local signatures is proposed for image copy detection. Firstly, the interest points are detected from a given image by using the Hessian–Affine detector. Secondly, the image is divided into some circle tracks, and thus the interest points are distributed into these tracks. Finally, to combine the advantages of the circle‐track‐based global signature and the interest points, the global distribution characteristics of interest points based on circle tracks are used to generate our image signature. Experimental results demonstrate the effectiveness of our proposed method in the aspects of both robustness and discriminability. Copyright © 2013 John Wiley & Sons, Ltd.
Zhili Zhou 0001, Xingming Sun, Xianyi Chen, Zhangjie Fu 0001
Secur. Commun. Networks1
2013 Reversible watermarking method based on asymmetric-histogram shifting of prediction errors
Xianyi Chen, Xingming Sun, Huiyu Sun, Zhili Zhou 0001, Jianjun Zhang 0005
J. Syst. Softw.4