Performance Comparison of Adversarial Example Attacks Against CNN-Based Image Steganalysis Models
Hyeonseong Kim, Hweerang Park, Youngho Cho · Electronics · 2025
A steganography technique hides a secret message stealthily within multimedia files such as images, videos, or even the skin image of an avatar in a metaverse environment. Conversely, a steganalysis technique detects steganographic files containing hidden messages. Recently, with the rapid advancement of Convolutional Neural Network (CNN) architectures, CNN-based image steganalysis models have been proposed to accurately detect steganography in image files. Meanwhile, Deep Learning (DL) models, including CNNs, are known to be vulnerable to evasion attacks such as adversarial example attacks, which can cause a CNN-based classifier to misclassify an input image according to the attacker’s intent. Given the lack of prior research in this domain, this paper investigates how effectively state-of-the-art adversarial example attack methods can evade three representative CNN-based image steganalysis ML models (XuNet, YeNet, and SRNet). Specifically, we first describe a system model consisting of three participating entities—a naïve attacker, a defender (Defender Lv. 1 and Defender Lv. 2), and an adversarial attacker. Next, we present experimental results comparing nine adversarial example attack methods against the three representative CNN models in terms of various metrics, including classification accuracy (CA), missed detection rate (MDR), attack success index (ASI), and adversarial example generation time (AEGT).