以秘密-隐写图像的差异性为设计轴:基于扩散模型的可逆无载体图像隐写术
Secret-Stego Dissimilarity as a Design Axis: Invertible Coverless Image Steganography with Diffusion Models
- Zhejiang University of Technology(浙江工业大学)
- Zhejiang University(浙江大学)
- UC Berkeley(加州大学伯克利分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
该研究提出InvCISD可逆扩散框架,耦合秘密与参考图像潜在表示,降低秘密-隐写图像视觉相似性,提升隐写质量,为CIS抗隐写分析研究提供方向。
AI中文摘要:
无载体图像隐写术(Coverless Image Steganography,CIS)通过合成隐写图像而非修改现有载体图像,使授权接收方可从隐写图像中重构原始秘密图像。现有基于扩散模型的CIS方法能生成自然的隐写图像,但与秘密图像保留了大量视觉相似性,这种相似性可能暴露结构和语义线索,产生仅通过恢复保真度无法评估的安全漏洞。在不损害隐写图像质量和秘密恢复保真度的前提下,实现秘密图像与隐写图像间的显著视觉差异性仍是一项挑战。为解决该问题,本文提出InvCISD,一种可逆扩散框架,其通过名为LIMNet的可逆网络将秘密图像与无关参考图像的潜在表示耦合。我们首先在扩散潜在空间中训练LIMNet,随后对整个网络进行端到端微调,即整合了扩散逆变换与生成模块的LIMNet。实验表明,所提方法大幅降低了秘密-隐写图像的视觉相似性,提升了隐写图像质量,并保留了令人满意的秘密恢复质量。我们的进一步研究显示,所有被评估的方法均可被面向CIS的隐写分析模型高度检测,这表明针对目标隐写分析的抗性是未来CIS研究的关键方向。
英文摘要:
Coverless image steganography (CIS) synthesizes a stego image rather than modifying an existing cover image, enabling authorized recipients to reconstruct the original secret image from the stego. Existing diffusion-based CIS methods can generate natural-looking stego images but preserve substantial visual similarity to the secret image. This resemblance risks exposing structural and semantic cues, giving rise to security vulnerabilities that cannot be evaluated solely via recovery fidelity. Achieving substantial visual dissimilarity between the secret and stego images without compromising stego quality and recovery fidelity remains challenging. To address this issue, we propose InvCISD, an invertible diffusion framework that couples the latent representations of the secret and an irrelevant reference image with an invertible network called LIMNet. We first train LIMNet in diffusion latent space, followed by end-to-end fine-tuning of the entire network, i.e., LIMNet integrated diffusion inversion and generation modules. Experiments demonstrate that the proposed method substantially reduces secret-stego visual similarity, improves stego quality, and retains satisfactory secret reconstruction quality. Our further investigation shows that all evaluated methods are highly detectable by the CIS-oriented steganalysis model, indicating that resistance against targeted steganalysis constitutes a critical direction for future CIS research.