Online published: 2025-07-18
Copyright
Image steganography refers to hiding secret information in the cover image with an unconcealed way, thereby achieving covert communication. Under the framework of minimum distortion, the traditional steganography method modifies the low-order pixels of the cover image through the design of steganography cost functions and coding algorithms to embed secret information. In recent years, end-to-end image steganography has become a hot topic. In this direction, encoding and decoding networks were constructed to achieve information embedding and extraction through joint training. The capacity of steganography was enhanced by adopting a deep model. The steganography security was strengthened through the adversarial training of steganography and steganalysis. The robustness of the steganography was improved by adding a simulated noise layer in the training step. the end-to-end image steganography methods was described and analyzed, including end-to-end spatial domain image steganography and end-to-end frequency domain image steganography. Finally, the deficiencies existing in end-to-end steganography and future research directions were pointed out.
Key words: information hiding; end-to-end steganography; steganalysis
YANG Jianhua , ZOU Junjie , LI Shunguang , SHANG Fei , LIAO Xin , DING Liping , KANG Xiangui . Research on end-to-end image steganography[J]. Journal of Cybersecurity, 2025 , 3(2) : 28 -40 . DOI: 10.20172/j.issn.2097-3136.250203
表 1 端到端空域图像隐写算法对比Table 1 Comparison of end-to-end image steganographic algorithms in spatial domain |
| 代表性方法 | 主要思路 | 优点 | 缺点 |
HiDDeN[20] | 使用深度神经网络进行端到端的图像隐写,通过对抗训练和噪声层模拟真实失真 | 对多种攻击具有较好的鲁棒性 | 容量和安全性较低 |
| Baluja等[17] | 使用深度神经网络同时训练信息嵌入与提取过程,将一张彩色图像完整地隐藏到另一张同尺寸的图像中 | 可以成功隐藏全尺寸图像,且对载体图像的视觉质量影响较小 | 没有考虑鲁棒性与安全性 |
| StegNet[21] | 结合深度卷积神经网络,直接学习输入与输出之间的映射关系,隐藏相同尺寸的图像 | 图像隐藏容量高,达到了23.57 bpp | 安全效果不佳,对抗隐写分析能力有限 |
| StegnoGAN[22] | 基于生成对抗网络的大容量图像隐写,通过对抗训练优化隐藏图像的感知质量 | 实现了 4.4 bpp 的高容量隐藏,且具有较强的抗隐写分析能力 | 在大容量隐藏时图像质量略有下降 |
| ABDH[23] | 引入注意力机制,将秘密信息嵌入到人眼不敏感的区域;利用循环判别模型和不一致损失,在迭代训练过程中提升载密图像的质量 | 提高了载密图像的质量,具备一定程度的抵抗多种噪声攻击的鲁棒性 | 不能抵抗深度隐写分析器的检测 |
| UDH[25] | 将秘密图像的编码过程和载体图像分离,使编码的信息可以独立于载体图像进行分析 | 图像隐藏容量高,具备一定鲁棒性,可用于隐写、水印等应用场景 | 安全性有待提升,抗隐写分析检测能力不足 |
| Chat-GAN[27] | 提出基于通道注意力机制的 GAN 架构,通过通道注意力模块动态地调整特征图的通道权重 | 提高了载密图像的质量和信息提取准确率 | 对不同数据集的安全性需要进一步验证 |
表 2 端到端频域图像隐写算法对比Table 2 Comparison of end-to-end image steganographic algorithms in frequency domain |
| 代表方法 | 主要思路 | 优点 | 缺点 |
| HRJS[29] | 构建JPEG 域的端到端隐写框架,包含编码器、解码器、攻击模块、IDCT模块和判别器等模块 | 通过对抗训练让网络学会在攻击后正确恢复秘密信息 | 判别网络结构比较简单,隐写安全性不足 |
| HiNet[31] | 在可逆神经网络中引入图像小波变换,将秘密信息更多地隐藏在高频子带中 | 可嵌入整幅彩色图像,且生成的载密图像质量在42 dB以上 | 没有考虑鲁棒性 |
| EFDR[33] | 通过细粒度DCT表示、子带特征增强模块和基于Transformer的可逆模块,直接在JPEG图像的量化DCT系数中嵌入和提取秘密图像,避免压缩和解压缩过程中的信息损失 | 提高了隐写和信息恢复的性能 | 在面对质量因子较低的情形时,恢复的秘密图像会出现一定程度的失真 |
| Lan等[35] | 利用INN直接在DCT系数中嵌入秘密信息,并通过互信息损失和双向融合模块减少信息损失 | 在不同JPEG压缩质量因子下展现出较强的鲁棒性 | 对JPEG压缩的模拟无法完全覆盖所有实际场景中的压缩情况 |
| Shang等[34] | 利用INN的双向过程在JPEG图像的量化DCT系数中嵌入和提取秘密信息,并模拟JPEG压缩攻击模块以提高鲁棒性 | 对JPEG压缩具有较强的鲁棒性,能够在不同质量因子下恢复秘密信息 | 在质量因子较低的情形下,恢复的秘密信息会有少量 错误 |
| Yin等[36] | 通过联合训练阶段和分离微调阶段解决端到端网络中舍入操作的非可微性问题,提高隐写的鲁棒性 | 有效解决了舍入操作导致的精度损失问题,提高了消息提取的准确性 | 信息提取率有待进一步提升 |
| Chen等[37] | 引入稀疏对抗攻击到JPEG隐写结构中,通过对抗训练提高隐写图像的安全性,并设计视觉感知损失函数以提高不可见性 | 提高了隐写图像对深度隐写分析模型的抵抗力 | 在高容量嵌入时,图像质量会受到一定影响 |
表 3 载体图像与载密图像在不同测试数据集上的图像质量对比Table 3 Comparison of image quality between cover images and stego images on different test dataset |
表 4 秘密图像恢复前后在不同测试数据集上的图像质量对比Table 4 Comparison of image quality before and after secret image restoration on different test datasets |
表 5 1 bpp嵌入容量下的提取误码率与隐写分析检测准确率对比Table 5 Comparison of extraction BER and steganalysis detection accuracy under 1 bpp embedding capacity |
| 1 |
FILLER T, JUDAS J, FRIDRICH J. Minimizing additive distortion in steganography using syndrome-trellis codes[J]. IEEE Transactions on Information Forensics and Security, 2011, 6 (3): 920- 935.
|
| 2 |
FILLER T, FRIDRICH J. Gibbs construction in steganography[J]. IEEE Transactions on Information Forensics and Security, 2010, 5 (4): 705- 720.
|
| 3 |
HOLUB V, FRIDRICH J, DENEMARK T. Universal distortion function for steganography in an arbitrary domain[J]. EURASIP Journal on Information Security, 2014, 2014, 1- 13.
|
| 4 |
LI B,WANG M,HUANG J,et al. A new cost function for spatial image steganography[C]//2014 IEEE International Conference on Image Processing (ICIP). IEEE,2014:4206-4210.
|
| 5 |
HOLUB V,FRIDRICH J. Designing steganographic distortion using directional filters[C]//2012 IEEE International Workshop on Information Forensics And Security (WIFS). IEEE,2012:234-239.
|
| 6 |
GUO L, NI J, SU W, et al. Using statistical image model for JPEG steganography: Uniform embedding revisited[J]. IEEE Transactions on Information Forensics and Security, 2015, 10 (12): 2669- 2680.
|
| 7 |
XU G, WU H Z, SHI Y Q. Structural design of convolutional neural networks for steganalysis[J]. IEEE Signal Processing Letters, 2016, 23 (5): 708- 712.
|
| 8 |
BOROUMAND M, CHEN M, FRIDRICH J. Deep residual network for steganalysis of digital images[J]. IEEE Transactions on Information Forensics and Security, 2018, 14 (5): 1181- 1193.
|
| 9 |
TANG W, TAN S, LI B, et al. Automatic steganographic distortion learning using a generative adversarial network[J]. IEEE Signal Processing Letters, 2017, 24 (10): 1547- 1551.
|
| 10 |
YANG J, RUAN D, HUANG J, et al. An embedding cost learning framework using GAN[J]. IEEE Transactions on Information Forensics and Security, 2019, 15, 839- 851.
|
| 11 |
TANG W, LI B, BARNI M, et al. An automatic cost learning framework for image steganography using deep reinforcement learning[J]. IEEE Transactions on Information Forensics and Security, 2020, 16, 952- 967.
|
| 12 |
HUANG D, LUO W, LIU M, et al. Steganography embedding cost learning with generative multi-adversarial network[J]. IEEE Transactions on Information Forensics and Security, 2023, 19, 15- 29.
|
| 13 |
CUI Q, ZHOU Z, MENG R, et al. ARES: On adversarial robustness enhancement for image steganographic cost learning[J]. IEEE Transactions on Multimedia, 2024, 26, 6542- 6553.
|
| 14 |
YANG J,RUAN D,KANG X,et al. Towards automatic embedding cost learning for JPEG steganography[C]//Proceedings of the ACM workshop on Information Hiding and Multimedia Security. Association for Computing Machinery,2019,37-46.
|
| 15 |
TANG W, LI B, BARNI M, et al. Improving cost learning for JPEG steganography by exploiting JPEG domain knowledge[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2021, 32 (6): 4081- 4095.
|
| 16 |
YANG J, LIAO Y, SHANG F, et al. JPEG image steganography with automatic embedding cost learning[J]. International Journal of Intelligent Systems, 2025, 2025 (1): 5309734.
|
| 17 |
BALUJA S. Hiding images in plain sight:Deep steganography[J]. Advances in Neural Information Processing Systems,2017,30.
|
| 18 |
HAYES J,DANEZIS G. Generating steganographic images via adversarial training[C]// Proceedings of the 31st International Conference on Neural Information Processing Systems. 2017,1951-1960.
|
| 19 |
KUMAR A, RANI R, SINGH S. Encoder-decoder architecture for image steganography using skip connections[J]. Procedia Computer Science, 2023, 218, 1122- 1131.
|
| 20 |
ZHU J,KAPLAN R,JOHNSON J,et al. Hidden:Hiding data with deep networks[C]//Proceedings of the European Conference On Computer Vision (ECCV). 2018:657-672.
|
| 21 |
WU P, YANG Y, LI X. StegNet: Mega image steganography capacity with deep convolutional network[J]. Future Internet, 2018, 10 (6): 54.
|
| 22 |
ZHANG K A, CUESTA-INFANTE A, XU L, et al. SteganoGAN: High capacity image steganography with GANs[J]. arXiv preprint, arXiv:, 1901, 03892, 2019.
|
| 23 |
YU C. Attention based data hiding with generative adversarial networks[C]//Proceedings of the AAAI Conference on Artificial Intelligence. 2020,34(1):1120-1128.
|
| 24 |
ZHANG C, BENZ P, KARJAUV A, et al. UDH: Universal deep hiding for steganography, watermarking, and light field messaging[J]. Advances in Neural Information Processing Systems, 2020, 33, 10223- 10234.
|
| 25 |
LU S P,WANG R,ZHONG T,et al. Large-capacity image steganography based on invertible neural networks[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 2021:10816-10825.
|
| 26 |
PAN W, YIN Y, WANG X, et al. Seek-and-hide: Adversarial steganography via deep reinforcement learning[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2021, 44 (11): 7871- 7884.
|
| 27 |
TAN J, LIAO X, LIU J, et al. Channel attention image steganography with generative adversarial networks[J]. IEEE Transactions on Network Science and Engineering, 2021, 9 (2): 888- 903.
|
| 28 |
CUI Q, TANG W, ZHOU Z, et al. Meta security metric learning for secure deep image hiding[J]. IEEE Transactions on Dependable and Secure Computing, 2024, 21 (5): 4907- 4920.
|
| 29 |
YANG J, SHANG F, LIAO Y, et al. Toward high capacity and robust JPEG steganography based on adversarial training[J]. Security and Communication Networks, 2023, 2023 (1): 3813977.
|
| 30 |
TANCIK M,MILDENHALL B,NG R. StegaStamp:Invisible hyperlinks in physical photographs[C]//Proceedings of the IEEE/CVF Conference on Computer Vision And Pattern Recognition. 2020:2117-2126.
|
| 31 |
JING J,DENG X,XU M,et al. HiNet:Deep image hiding by invertible network[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision. 2021:4733-4742.
|
| 32 |
GUAN Z, JING J, DENG X, et al. DeepMIH: Deep invertible network for multiple image hiding[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2022, 45 (1): 372- 390.
|
| 33 |
YANG J,LIAO X. Exploiting fine-grained DCT representations for hiding image-level messages within JPEG images[C]//Proceedings of the 31st ACM International Conference on Multimedia. 2023:7373-7382.
|
| 34 |
SHANG F, LAN Y, YANG J, et al. Robust data hiding for JPEG images with invertible neural network[J]. Neural Networks, 2023, 163, 219- 232.
|
| 35 |
LAN Y,SHANG F,YANG J,et al. Robust image steganography:Hiding messages in frequency coefficients[C]//Proceedings of the AAAI Conference on Artificial Intelligence. 2023,37(12):14955-14963.
|
| 36 |
YIN X, WU S, WANG K, et al. Anti-rounding image steganography with separable fine-tuned network[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2023, 33 (11): 7066- 7079.
|
| 37 |
CHEN B, NIE Y, YANG J. Toward high imperceptibility deep JPEG steganography based on sparse adversarial attack[J]. Journal of Visual Communication and Image Representation, 2023, 97, 103977.
|
| 38 |
WEI K, LUO W, TAN S, et al. Universal deep network for steganalysis of color image based on channel representation[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 3022- 3036.
|
| 39 |
YAO Y, WANG J, CHANG Q, et al. High invisibility image steganography with wavelet transform and generative adversarial network[J]. Expert Systems with Applications, 2024, 249, 123540.
|
| 40 |
TANG W ,YANG H ,RAO Y ,et al. Dig a hole and fill in sand:Adversary and hiding decoupled steganography[C]//Proceedings of the 32nd ACM International Conference on Multimedia. 2024:10440-10 448.
|
| 41 |
SHANG F,ZHAO W,WEN J,et al. INN-based robust JPEG steganography through cover coefficient selection[C]//IEEE 9th International Conference on Data Science in Cyberspace . IEEE,2024:406-413.
|
| 42 |
LI F,SHENG Y,WU K,et al. LiDiNet:A lightweight deep invertible network for image-in-image steganography[J]. IEEE Transactions on Information Forensics and Security,2024:8817-8831.
|
| 43 |
COGRANNE R,GIBOULOT É,BAS P. ALASKA #2:Challenging academic research on steganalysis with realistic images[C]//2020 IEEE International Workshop on Information Forensics and Security (WIFS). IEEE,2020:1-5.
|
| 44 |
LIN T Y,MAIRE M,BELONGIE S,et al. Microsoft COCO:Common objects in context[C]//Computer vision-ECCV 2014:13th European conference. Springer International Publishing,2014:740-755.
|
| 45 |
RUSSAKOVSKY O, DENG J, SU H, et al. Imagenet large scale visual recognition challenge[J]. International Journal of Computer Vision, 2015, 115, 211- 252.
|
| 46 |
SHANG F,ZHAO W,KANG X,et al. INN-based secure steganography using lost information as adversarial perturbations[C]//ICASSP 2025-2025 IEEE International Conference on Acoustics,Speech and Signal Processing (ICASSP). IEEE,2025:1-5.
|
| 47 |
DENG X,CHEN B,LUO W,et al. Fast and effective global covariance pooling network for image steganalysis[C]//Proceedings of the ACM workshop on information hiding and multimedia security. 2019:230-234.
|
| 48 |
YE J, NI J, YI Y. Deep learning hierarchical representations for image steganalysis[J]. IEEE Transactions on Information Forensics and Security, 2017, 12 (11): 2545- 2557.
|
| 49 |
ROMBACH R,BLATTMANN A,LORENZ D,et al. High-resolution image synthesis with latent diffusion models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision And Pattern Recognition. 2022:10684-10695.
|
/
| 〈 |
|
〉 |