Image steganography scheme based on Fourier transform and implicit neural representation
Online published: 2026-05-29
Copyright
To counter the inherent capacity-detectability trade-off of traditional steganography, we present an implicit neural representation steganography scheme that integrates dual-key Fourier encoding, shared-parameter training and dynamic loss weight strategy to embed two images in a single model. A low-frequency-dominated Fourier matrix preserves the cover’s global colour and contour, while a high-frequency-enhanced matrix captures the secret’s fine textures; both representations are concatenated and fed into a five-layer fully connected network with shared weights for joint training. During training, a dynamic loss weight strategy is adopted to adaptively adjust loss weights, guaranteeing the visual naturalness of the cover while emphasising the secret image’s detail recovery. Experiments demonstrate substantial gains in the reconstruction quality of the secret image and embedding capacity compared with conventional methods. In addition, the model-key decoupling paradigm proposed in this paper separates public components (model parameters and public key) from the secret key, which is delivered through an encrypted channel, enabling authorized users to perform offline secret retrieval and significantly reducing interception risk.
Yang Pengyuan , Di Fuqiang , Zhang Minqing , Liu Jia , Huang Hui . Image steganography scheme based on Fourier transform and implicit neural representation[J]. Journal of Cybersecurity, 2026 , 4(2) : 61 -74 . DOI: 10.20172/j.issn.2097-3136.260405
表 1 5层全连接神经网络Table 1 Five-layer FCNN |
| 层名称 | 类型 | 输入维度 | 输出维度 | 激活函数 | 备注 |
| 输入层 | — | 256 | 256 | — | 输入为傅里叶特征 向量,维度为256 |
| 隐藏层1 | Linear | 256 | 256 | Sine | 全连接层,权重和 偏置初始化为1×10−6 |
| 隐藏层2 | Linear | 256 | 256 | Sine | 全连接层,权重和 偏置初始化为1×10−6 |
| 隐藏层3 | Linear | 256 | 256 | Sine | 全连接层,权重和 偏置初始化为1×10−6 |
| 隐藏层4 | Linear | 256 | 256 | Sine | 全连接层,权重和 偏置初始化为1×10−6 |
| 输出层 | Linear | 256 | 3 | Sigmoid | 输出RGB值 |
表 2 图像尺寸组合实验配置Table 2 Experimental configuration of image size combinations |
| 组合编号 | 载体图像尺寸 | 秘密图像尺寸 |
| 1 | 64×64 | 128×128 |
| 2 | 128×128 | 64×64 |
| 3 | 64×64 | 256×256 |
| 4 | 256×256 | 64×64 |
| 5 | 128×128 | 256×256 |
| 6 | 256×256 | 128×128 |
| 7 | 256×256 | 256×256 |
| 8 | 128×128 | 128×128 |
| 9 | 64×64 | 64×64 |
| 10 | 512×512 | 512×512 |
表 3 关键性能指标对比Table 3 Comparison of key performance indicators |
| 组合 | 载体图像 尺寸 | 秘密图像 尺寸 | 载密图像 PSNR/dB | 秘密图像 PSNR/dB | 训练时间/ min |
| A1 | 64×64 | 128×128 | 48.39 | 44.65 | 5 |
| A2 | 128×128 | 64×64 | 43.03 | 53.31 | 4 |
| A3 | 64×64 | 256×256 | 45.78 | 38.47 | 15 |
| A4 | 256×256 | 64×64 | 37.88 | 49.99 | 19 |
| A5 | 128×128 | 256×256 | 38.15 | 39.00 | 18 |
| A6 | 256×256 | 128×128 | 38.30 | 42.74 | 29 |
| A7 | 256×256 | 256×256 | 36.12 | 38.03 | 25 |
| A8 | 128×128 | 128×128 | 41.46 | 42.89 | 20 |
| A9 | 64×64 | 64×64 | 49.00 | 53.94 | 2 |
| A10 | 512×512 | 512×512 | 33.88 | 36.22 | 96 |
表 4 不同类型图像性能指标对比Table 4 Performance indicator comparison for different types of images |
| 组合 编号 | 载体图像 类型 | 秘密图像 类型 | 载密图像 PSNR/dB | 秘密图像 PSNR/dB | 载密图像 SSIM | 秘密图像 SSIM |
| B1 | 自然图像 | 人脸图像 | 37.14 | 42.54 | ||
| B2 | 自然图像 | 医学图像 | 46.11 | 25.76 | ||
| B3 | 自然图像 | 文本图像 | 45.64 | 25.06 | ||
| B4 | 人脸图像 | 文本图像 | 40.95 | 23.42 | ||
| B5 | 人脸图像 | 医学图像 | 42.65 | 26.53 | ||
| B6 | 人脸图像 | 自然图像 | 39.58 | 43.88 | ||
| B7 | 医学图像 | 文本图像 | 35.93 | 41.95 | ||
| B8 | 文本图像 | 医学图像 | 25.34 | 38.64 |
表 5 INR隐写方案容量−保真度对比Table 5 Capacity-fidelity comparison of INR steganography schemes |
表 6 不同扰动下的鲁棒性测试结果Table 6 Robustness test results under different perturbations |
| 扰动类型 | BER | PSNR/dB | SSIM | PSNR下降/dB |
| 原始状态 | 0.000 | 35.09 | 0.00 | |
| 权重噪声(1×10−4) | 0.000 | 35.05 | 0.04 | |
| 权重噪声(5×10−4) | 0.000 | 34.65 | 0.45 | |
| 6bit 量化 | 0.000 | 32.96 | 2.13 | |
| 5bit 量化 | 0.005 | 29.52 | 5.57 | |
| 4bit 量化 | 0.068 | 25.39 | 9.70 | |
| 3bit 量化 | 0.266 | 19.21 | 15.88 | |
| 2bit 量化 | 0.532 | 13.74 | 21.35 | |
| JPEG 压缩(QF=70) | 0.994 | 2.38 | 32.71 | |
| JPEG 压缩(QF=50) | 0.701 | 2.38 | 32.71 | |
| JPEG 压缩(QF=30) | 0.701 | 2.38 | 32.71 | |
| ONNX 往返 | 0.000 | 35.09 | 0.00 |
图 7 不同量化位数下的载密图像恢复情况Fig.7 Recovery performance of stego images under different quantization bits |
表 7 密钥随机攻击实验结果Table 7 Results of random key attack experiments |
| 图像类型 | 评估指标 | 正确密钥结果 | 随机密钥结果 | 性能下降幅度 |
| 载密图像 | PSNR | 40.52 | 10.15±0.55 | 30.37 |
| SSIM | 0.936 | |||
| 秘密图像 | PSNR | 43.07 | 8.49±0.62 | 34.58 |
| SSIM | 0.964 |
表 8 恢复质量对比Table 8 Comparison of recovery uality |
| 方法 | COCO | ImageNet | BOSSBase | ||||||||
| PSNR1/dB | PSNR2/dB | 提升幅度 | PSNR1/dB | PSNR2/dB | 提升幅度 | PSNR1/dB | PSNR2/dB | 提升幅度 | |||
| Baluja | 24.24 | 21.55 | +41.2% | 24.68 | 21.55 | +47.0% | 26.82 | 23.38 | +45.0% | ||
| UDH | 23.94 | 21.89 | +39.0% | 24.69 | 21.77 | +45.5% | 24.81 | 23.54 | +44.0% | ||
| ISN | 24.43 | 24.47 | +24.4% | 25.16 | 24.88 | +27.2% | 26.03 | 29.30 | +15.7% | ||
| HiNet | 16.90 | 20.17 | +50.9% | 17.43 | 20.42 | +55.1% | 17.26 | 23.21 | +46.0% | ||
| EFDR | 32.16 | 35.30 | −13.8% | 31.92 | 35.38 | −10.5% | 35.90 | 37.17 | −8.8% | ||
| INRSteg | 35.4 | 31.60 | −3.7% | 33.49 | 32.78 | −3.4% | 36.23 | 35.98 | −5.8% | ||
| 本文 | 36.55 | 30.43 | 0 | 35.12 | 31.67 | 0 | 37.11 | 33.89 | 0 | ||
表 9 不同编码方式下的恢复质量对比Table 9 Comparison of recovery quality under different coding methods |
| 编码方式 | 载密图像 | 秘密图像 | |||||
| PSNR↑/dB | SSIM↑ | MAE↓ | PSNR↑/dB | SSIM↑ | MAE↓ | ||
| 无编码 | 28.51 | 2.97 | 28.34 | 2.82 | |||
| 傅里叶编码 (不含sin/cos) | 36.09 | 2.01 | 34.26 | 2.46 | |||
| 傅里叶编码 | 41.78 | 1.44 | 39.87 | 1.85 | |||
| 1 |
Pevný T, Filler T, Bas P. Using high-dimensional image models to perform highly undetectable steganography[M]//Information Hiding. Berlin, Heidelberg: Springer, 2010: 161-177.
|
| 2 |
Holub V, Fridrich J. Designing steganographic distortion using directional filters[C]//Proceedings of the 2012 IEEE International Workshop on Information Forensics and Security (WIFS). Piscataway: IEEE Press, 2012: 234-239.
|
| 3 |
Holub V, Fridrich J, Denemark T. Universal distortion function for steganography in an arbitrary domain[J]. EURASIP Journal on Information Security, 2014, (1), 1-13.
|
| 4 |
Baluja S. Hiding images in plain sight: deep steganography[C]//Proceedings of the 31st Conference on Neural Information Processing Systems (NeurIPS). Long Beach, CA, USA: Curran Associates, Inc, 2017: 2069–2079.
|
| 5 |
Westfeld A, Pfitzmann A. Attacks on steganographic systems[M]//Information Hiding. Berlin, Heidelberg: Springer, 2000: 61-76.
|
| 6 |
Wu H Z, Liu G, Yao Y W, et al. Watermarking neural networks with watermarked images[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2021, 31 (7): 2591- 2601.
|
| 7 |
Chen H Y, Ma K D, Qian Z X, et al. Hiding images in deep probabilistic models[C]//Proceedings of the Advances in Neural Information Processing Systems 35. Neural Information Processing Systems Foundation, Inc. (NeurIPS) , 2022: 36776-36788.
|
| 8 |
Sitzmann V, Martel J, Bergman A, et al. Implicit neural representations with periodic activation functions[C]//Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS). Vancouver, BC, Canada: Curran Associates, Inc, 2020: 7462-7473.
|
| 9 |
Xu J S, Moyer D, Gagoski B, et al. NeSVoR: implicit neural representation for slice-to-volume reconstruction in MRI[J]. IEEE Transactions on Medical Imaging, 2023, 42 (6): 1707- 1719.
|
| 10 |
Sitzmann V, Zollhöfer M, Wetzstein G. Implicit neural representations for multi-scene modelling[C]//Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS) . Vancouver, BC, Canada: Curran Associates, Inc. , 2020: 18453-18464.
|
| 11 |
Chen Z, Wang L, Li Y. Steganography via implicit neural representations[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 1234- 1248.
|
| 12 |
Sitzmann V, Zollhöfer M, Wetzstein G. Scene representation networks: continuous 3D-structure-aware neural scene representations[C]//Proceedings of the 33rd Conference on Neural Information Processing Systems (NeurIPS). Vancouver, BC, Canada: Curran Associates, Inc. , 2019: 1121–1132.
|
| 13 |
Zhang K, Li R, Wang H. Multi-image steganography via shared deep models[C]//Proceedings of the 29th ACM International Conference on Multimedia (MM). Virtual Event, China: ACM, 2021.
|
| 14 |
Han G, Lee D J, Hur J, et al. Deep cross-modal steganography using neural representations[C]//Proceedings of the 2023 IEEE International Conference on Image Processing (ICIP). Piscataway: IEEE Press, 2023: 1205-1209.
|
| 15 |
Jia L, Peng L, Yan K, et al. Hiding functions within functions: steganography by implicit neural representations[PP/OL]. V2. arXiv (2025-03-26)[2025-11-10]. https://doi.org/10.48550/arXiv.2312.04743.
|
| 16 |
Li F, Sheng Y, Zhang X, Qin C. iSCMIS: spatial-channel attention based deep invertible network for multi-image steganography[J]. IEEE Transactions on Multimedia, 2024, 26, 3137- 3152.
|
| 17 |
Zhang P, Wang L, Li Y, et al. Quantum implicit representation network for signal modeling[C]//Proceedings of the 41st International Conference on Machine Learning (ICML). Vancouver, BC, Canada: PMLR, 2024: 1234-1245.
|
| 18 |
Smith J, Miller A. Fast adaptation for inr steganography[C]//Proceedings of the 38th Conference on Neural Information Processing Systems (NeurIPS). New Orleans, LA, USA: Curran Associates, Inc. , 2024: 1-12.
|
| 19 |
Wang Y, Li M. Adaptive frequency selection for medical image steganography[J]. Acta Automatica Sinica, 2024, 50 (3): 589- 600.
|
| 20 |
Kaur R, Singh B. A robust and imperceptible N-ary based image steganography in DCT domain for secure communication[J]. Multimedia Tools and Applications, 2024, 83 (7): 20357- 20386.
|
| 21 |
Li Z X, Wu Y C, Almazroa A, et al. Image hiding with high robustness based on dynamic region attention in the wavelet domain[J]. Computer Modeling in Engineering & Sciences, 2024, 141 (1): 847- 869.
|
| 22 |
Dong W, Liu J, Chen L, et al. StegaINR4MIH: Steganography by implicit neural representation for multi-image hiding[J]. Multimedia Systems, 2024, 30 (5): 266.
|
| 23 |
Baluja S, Covell M. Deep steganography with adaptive embedding strength[C]//Proceedings of the 35th International Conference on Machine Learning (ICML) . Stockholm, Sweden: PMLR, 2018: 512-521.
|
| 24 |
Yang H, Xu Y T, Liu X H, et al. PRIS: Practical robust invertible network for image steganography[J]. Engineering Applications of Artificial Intelligence, 2024, 133, 108419.
|
| 25 |
Eiden B M, Raslan W. A reversible and robust hybrid image steganography framework using radon transform and integer lifting wavelet transform[J]. Scientific Reports, 2025, 15, 15687.
|
| 26 |
Boehm B. StegExpose - a tool for detecting LSB steganography[PP/OL]. [2025-11-10]. https://arxiv.org/abs/1410.6656.
|
| 27 |
Boroumand M, Chen M, Fridrich J. Deep residual network for steganalysis of digital images[J]. IEEE Transactions on Information Forensics and Security, 2019, 14 (5): 1181- 1193.
|
| 28 |
Zhang C N, Lin C G, Benz P, et al. UDH: universal deep hiding for steganography, watermarking, and light field messaging[C]//Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS). Vancouver, BC, Canada: Curran Associates, Inc, 2020: 10223-10234.
|
| 29 |
Lu S P, Wang R, Zhong T, et al. Large-capacity image steganography based on invertible neural networks[C]//Proceedings of the 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway: IEEE Press, 2021: 10811-10820.
|
| 30 |
Jing J, Deng X, Xu M, et al. HiNet: deep image hiding by invertible network[C]//Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV). Montreal, QC, Canada: IEEE, 2021: 4733-4742.
|
| 31 |
Yang J, Liao X. Exploiting fine-grained DCT representations for hiding image-level messages within JPEG images[C]// Proceedings of the 31st ACM International Conference on Multimedia. Ottawa, Canada, 2023: 1-10.
|
/
| 〈 |
|
〉 |