arXiv:2409.04968cs.CVcs.CR2024-09中稿 · IEEE TIFS被引 8

通过神经元归因提升对抗隐写术的迁移能力,让隐藏信息更难被检测。

Natias: Neuron Attribution based Transferable Image Adversarial Steganography

  • 基于神经元贡献度识别通用特征,干扰多模型共用的关键特征
  • 在多个未见过的检测模型上实现更高欺骗成功率,转移性显著提升
  • 可无缝嵌入现有框架,适合隐私保护与对抗攻击场景

图像隐写术用于在数字图像中隐藏秘密信息,而隐写分析则旨在检测图像中是否存在隐藏信息。近年来,基于深度学习的隐写分析方法取得了优异的检测性能。作为应对措施,对抗隐写术因其能有效欺骗深度学习型隐写分析而受到广泛关注。然而,隐写分析师常使用未知的检测模型,因此对抗隐写术对非目标模型的欺骗能力(即迁移性)变得尤为重要。现有方法未考虑如何增强迁移性。为此,本文提出一种名为Natias的新对抗隐写方案:首先将目标中间层各神经元对隐写分析模型输出的贡献进行归因,识别出可能被多种模型采用的关键特征;随后破坏这些关键特征,从而提升对抗隐写术的迁移能力。该方法可无缝集成至现有对抗隐写框架。大量实验证明,相比以往方法,本方案在迁移性和重训练场景下的安全性均有显著提升。

原文摘要 · Abstract (English)

Image steganography is a technique to conceal secret messages within digital images. Steganalysis, on the contrary, aims to detect the presence of secret messages within images. Recently, deep-learning-based steganalysis methods have achieved excellent detection performance. As a countermeasure, adversarial steganography has garnered considerable attention due to its ability to effectively deceive deep-learning-based steganalysis. However, steganalysts often employ unknown steganalytic models for detection. Therefore, the ability of adversarial steganography to deceive non-target steganalytic models, known as transferability, becomes especially important. Nevertheless, existing adversarial steganographic methods do not consider how to enhance transferability. To address this issue, we propose a novel adversarial steganographic scheme named Natias. Specifically, we first attribute the output of a steganalytic model to each neuron in the target middle layer to identify critical features. Next, we corrupt these critical features that may be adopted by diverse steganalytic models. Consequently, it can promote the transferability of adversarial steganography. Our proposed method can be seamlessly integrated with existing adversarial steganography frameworks. Thorough experimental analyses affirm that our proposed technique possesses improved transferability when contrasted with former approaches, and it attains heightened security in retraining scenarios.

隐写术对抗样本迁移性神经归因

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。