无需训练的防御方法,可有效清除扩散模型隐写恶意软件
Training-Free Color-Aware Adversarial Diffusion Sanitization for Diffusion Stegomalware Defense at Security Gateways
- 用预训练去噪器模拟隐写解码器,实现无训练防御
- 在极低视觉失真下使解码成功率接近零
- 适合安全网关部署,兼顾安全与图像可用性
生成式AI的快速发展使大规模合成媒体创作成为常态,催生了新型隐蔽通信方式。基于扩散模型的生成隐写技术可在不微调或使用辅助解码器的情况下嵌入高容量信息,对检测与修复构成重大挑战。由于其直接从秘密数据生成载体图像,覆盖无关的扩散隐写方法难以被传统依赖载体-隐写差异的检测器识别,攻击者可借此传递命令与控制指令、部署载荷或窃取数据。本文提出对抗扩散净化(ADS),一种适用于安全网关的无训练防御机制,通过中和隐藏载荷而非检测它来应对威胁。ADS采用现成预训练去噪器作为扩散解码器的可微代理,并引入颜色感知的四元数耦合更新规则,在严格失真限制下减少伪影。在实际威胁模型下评估显示,面对最先进的扩散隐写方法Pulsar,ADS将解码成功率降至接近零,且感知影响极小。结果表明,相比标准内容变换,ADS提供了更优的安全-效用权衡,是一种有效的扩散隐写对抗策略。
原文摘要 · Abstract (English)
The rapid expansion of generative AI has normalized large-scale synthetic media creation, enabling new forms of covert communication. Recent generative steganography methods, particularly those based on diffusion models, can embed high-capacity payloads without fine-tuning or auxiliary decoders, creating significant challenges for detection and remediation. Coverless diffusion-based techniques are difficult to counter because they generate image carriers directly from secret data, enabling attackers to deliver stegomalware for command-and-control, payload staging, and data exfiltration while bypassing detectors that rely on cover-stego discrepancies. This work introduces Adversarial Diffusion Sanitization (ADS), a training-free defense for security gateways that neutralizes hidden payloads rather than detecting them. ADS employs an off-the-shelf pretrained denoiser as a differentiable proxy for diffusion-based decoders and incorporates a color-aware, quaternion-coupled update rule to reduce artifacts under strict distortion limits. Under a practical threat model and in evaluation against the state-of-the-art diffusion steganography method Pulsar, ADS drives decoder success rates to near zero with minimal perceptual impact. Results demonstrate that ADS provides a favorable security-utility trade-off compared to standard content transformations, offering an effective mitigation strategy against diffusion-driven steganography.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。