通过分析隐空间向量长度分布,发现生成图像隐写存在可检测漏洞。
Targeted Pooled Latent-Space Steganalysis Applied to Generative Steganography, with a Fix
- 在隐空间建模向量长度分布,用似然比检测隐写痕迹。
- 原方案在图像空间不可检测,但在隐空间方差差异明显可被识破。
- 随机采样隐向量长度可让隐写在隐空间也难以被发现,适合安全通信。
针对基于潜空间扩散模型的隐写方案,本文提出在隐空间而非图像空间进行隐写分析。该方案由Hu等提出,具备鲁棒性且在图像空间中几乎无法被检测。本文发现:嵌入后,隐写向量分布于超球面,而原始向量为独立同分布高斯。通过将分析从图像空间转移到隐空间,可在覆盖与隐写假设下分别建模向量长度为不同方差的高斯分布,并据此构建似然比检验实现聚合隐写分析。同时研究了提示词知识及扩散步数的影响。此外,通过在生成前随机采样隐向量长度,可使原方案在隐空间亦不可检测。
原文摘要 · Abstract (English)
Steganographic schemes dedicated to generated images modify the seed vector in the latent space to embed a message. Whereas most steganalysis methods attempt to detect the embedding in the image space, this paper proposes to perform steganalysis in the latent space by modeling the statistical distribution of the norm of the latent vector. Specifically, we analyze the practical security of a scheme proposed by Hu et al. for latent diffusion models, which is both robust and practically undetectable when steganalysis is performed on generated images. We show that after embedding, the Stego (latent) vector is distributed on a hypersphere while the Cover vector is i.i.d. Gaussian. By going from the image space to the latent space, we show that it is possible to model the norm of the vector in the latent space under the Cover or Stego hypothesis as Gaussian distributions with different variances. A Likelihood Ratio Test is then derived to perform pooled steganalysis. The impact of the potential knowledge of the prompt and the number of diffusion steps is also studied. Additionally, we show how, by randomly sampling the norm of the latent vector before generation, the initial Stego scheme becomes undetectable in the latent space.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。