提出噪声空间检测框架,揭示扩散模型隐写安全漏洞。
Rethinking Security of Diffusion-based Generative Steganography
- 从噪声空间出发,构建新型隐写分析方法
- 实验证明现有方法在复杂场景下易被检测
- 适合研究隐写安全与对抗攻击的学者
生成式图像隐写技术可在不依赖原始载体图像的情况下,将秘密信息嵌入生成图像中。近期基于扩散模型的生成式图像隐写(DM-GIS)方法有效抵御了传统隐写分析。本文识别出影响DM-GIS安全性的关键因素,重新审视现有方法的安全性。首先,我们梳理了当前DM-GIS的通用流程,发现扩散模型的噪声空间是主要嵌入域。进一步分析表明,任何破坏噪声分布的隐写操作都将损害DM-GIS安全性。基于此,我们提出一种基于噪声空间的扩散隐写分析器(NS-DSer),可在扩散模型噪声空间中有效检测DM-GIS生成图像。我们在日益复杂的检测场景下重新评估了现有方法的安全性。实验结果验证了理论分析,并证明了NS-DSer在多种场景下的有效性。
原文摘要 · Abstract (English)
Generative image steganography is a technique that conceals secret messages within generated images, without relying on pre-existing cover images. Recently, a number of diffusion model-based generative image steganography (DM-GIS) methods have been introduced, which effectively combat traditional steganalysis techniques. In this paper, we identify the key factors that influence DM-GIS security and revisit the security of existing methods. Specifically, we first provide an overview of the general pipelines of current DM-GIS methods, finding that the noise space of diffusion models serves as the primary embedding domain. Further, we analyze the relationship between DM-GIS security and noise distribution of diffusion models, theoretically demonstrating that any steganographic operation that disrupts the noise distribution compromise DM-GIS security. Building on this insight, we propose a Noise Space-based Diffusion Steganalyzer (NS-DSer)-a simple yet effective steganalysis framework allowing for detecting DM-GIS generated images in the diffusion model noise space. We reevaluate the security of existing DM-GIS methods using NS-DSer across increasingly challenging detection scenarios. Experimental results validate our theoretical analysis of DM-GIS security and show the effectiveness of NS-DSer across diverse detection scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。