Deep Sub-Image Sampling Based Defense Against Spatial-Domain Adversarial Steganography

Xinyu Huang, Yuwen Cao, Tomoaki Otsuki Ohtsuki · 2024

Deep steganalyzer combined with neural networks has achieved great success in image classification over recent years. However, it suffers from the following persistent challenges: i) Deep steganalyzer is extremely vulnerable and has the risk of being attacked via adversarial steganography when performing the image classification tasks; ii) Pre-processing based methods aiming to remove adversarial perturbations from cover images jeopardize the accuracy performance, as the involved steganographic signal will be wiped off as well. In this context, to defend against adversarial attacks by an adversary, we propose an adversarial steganography detection scheme based on the pre-processing and feature migration. In brief, sub-images are sampled to obtain the dimensionality of the extracted features, which are usually used to expand them while reducing the effect brought by adversarial perturbations. In particular, by computing statistical features together with normalizing the features, our approach can improve the classification accuracy of the samples. Our experimental results show that the proposed approach is capable of detecting adversarial steganographic image with an accuracy gain of up to 35.9% over the state-of-the-art methods.

Read the paper · More papers on PaperTik