Backpack: A Backpropagable Adversarial Embedding Scheme

Solène Bernard, Patrick Bas, John Klein, Tomáš Pevný · IEEE Transactions on Information Forensics and Security · 2022

A min max protocol offers a general method to automatically optimize steganographic algorithm against a wide class of steganalytic detectors. The quality of the resulting steganograhic algorithm depends on the ability to find an “adversarial” stego image undetectable by a set of detectors while communicating a given message. Despite min max protocol instantiated with ADV-EMB scheme leading to unexpectedly good results, we show it suffers a significant flaw and we present a theoretically sound solution called Backpack. Extensive experimental verification of min max protocol with Backpack shows superior performance to ADV-EMB, the generality of the tool by targeting a new JPEG QF100 compatibility attack and further improves the security of steganographic algorithms.

Read the paper · More papers on PaperTik