arXiv:2507.08343cs.CV2025-07

用多范围特征对抗生成,让隐藏图像几乎无法被察觉。

Towards Imperceptible JPEG Image Hiding: Multi-range Representations-driven Adversarial Stego Generation

  • 结合卷积与Transformer,同时捕捉局部和全局特征
  • 在视觉和检测上均达到当前最佳隐蔽效果
  • 适合需要高隐蔽性的图像隐写场景

图像隐写利用深度学习模型的隐藏潜力,将信息嵌入载体图像中,通过解密载体图像实现隐蔽通信。现有方法因局限于空间域载体、单一范围特征提取与攻击方式,以及不足的损失约束,易被肉眼或隐写分析器发现。为此,本文提出多范围表征驱动的对抗隐写生成框架MRAG,用于JPEG图像隐写。该设计基于隐写分析器通常融合局部与全局信息以捕捉隐藏痕迹的事实。具体而言,MRAG结合卷积的局部特征与Transformer的全局建模能力,并设计特征角度-范数解耦损失,基于代理隐写分析器分类前最后一层全连接层的特征计算对抗损失。在角度与范数双重约束下,能精细编码载体与秘密的拼接为与隐写分析相关的局部和全局范围细微扰动。因此生成的隐写图像在视觉和隐写分析上均难以察觉。此外,引入粗粒度与细粒度频率分解操作以转换输入,增加多粒度信息。大量实验表明,MRAG性能达到当前最优。

原文摘要 · Abstract (English)

Image hiding fully explores the hidden potential of deep learning-based models, aiming to conceal image-level messages within cover images and reveal them from stego images to achieve covert communication. Existing hiding schemes are easily detected by the naked eyes or steganalyzers due to the cover type confined to the spatial domain, single-range feature extraction and attacks, and insufficient loss constraints. To address these issues, we propose a multi-range representations-driven adversarial stego generation framework called MRAG for JPEG image hiding. This design stems from the fact that steganalyzers typically combine local-range and global-range information to better capture hidden traces. Specifically, MRAG integrates the local-range characteristic of the convolution and the global-range modeling of the transformer. Meanwhile, a features angle-norm disentanglement loss is designed to launch multi-range representations-driven feature-level adversarial attacks. It computes the adversarial loss between covers and stegos based on the surrogate steganalyzer's classified features, i.e., the features before the last fully connected layer. Under the dual constraints of features angle and norm, MRAG can delicately encode the concatenation of cover and secret into subtle adversarial perturbations from local and global ranges relevant to steganalysis. Therefore, the resulting stego can achieve visual and steganalysis imperceptibility. Moreover, coarse-grained and fine-grained frequency decomposition operations are devised to transform the input, introducing multi-grained information. Extensive experiments demonstrate that MRAG can achieve state-of-the-art performance.

图像隐写对抗生成多范围特征JPEG

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。