
==== Front
Sci Rep
Sci Rep
Scientific Reports
2045-2322
Nature Publishing Group UK London

39266648
72693
10.1038/s41598-024-72693-5
Article
Vaccine for digital images against steganography
Li Xinran 1
Wang Zichi wangzichi@shu.edu.cn

2
1 https://ror.org/00ay9v204 grid.267139.8 0000 0000 9188 055X Business School, University of Shanghai for Science and Technology, Shanghai, 200093 China
2 https://ror.org/006teas31 grid.39436.3b 0000 0001 2323 5732 School of Communication and Information Engineering, Shanghai University, Shanghai, 200444 China
12 9 2024
12 9 2024
2024
14 2134026 3 2024
10 9 2024
© The Author(s) 2024
2024
https://creativecommons.org/licenses/by-nc-nd/4.0/ Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/.
Digital image steganography serves as a technology facilitating covert communication through digital images by subtly incorporating secret data into a cover image. This practice poses a potential threat, as criminals exploit steganography to transmit illicit content, thereby jeopardizing information security. Consequently, it becomes imperative to implement defensive strategies against steganographic techniques. This paper proposes a novel defense mechanism termed “image vaccine” to safeguard digital images from steganography. The process of “vaccinating” an image renders it immune to steganographic manipulation. Notably, when criminals attempt to embed secret data into vaccinated images, the presence of such hidden information can be detected with a 100% probability, ensuring the consistent identification of stego images. This proactive approach enables the interception of stego image transmission, thereby neutralizing covert communication channels.

Keywords

Digital image
Vaccine
Immunization
Steganography
Subject terms

Engineering
Mathematics and computing
Natural Science Foundation of China62376148 Wang Zichi the Chenguang Program of Shanghai Education Development Foundation and Shanghai Municipal Education Commission22CGA46 Wang Zichi issue-copyright-statement© Springer Nature Limited 2024
==== Body
pmcIntroduction

In the contemporary era, humanity has entered the epoch of social media1, a transformative landscape delineated by the widespread dissemination of digital images across platforms such as Twitter, Meta, and WeChat. The ubiquity of digital images has significantly enhanced the fabric of daily life, presenting opportunities and challenges alike2. Notably, the potential misuse of digital images by malicious actors for the transmission of illegal content through the covert technique of steganography introduces a complex dimension to this digital paradigm3. In the domain of digital images, steganography involves strategically embedding secret data into a cover image through inconspicuous modifications to the image content. The resultant stego image, bearing concealed information, is then discreetly transmitted via public channels without arousing suspicion. Upon reception, the recipient can extract the hidden data from the stego image4, exemplifying the dual nature of this technology. To mitigate the risk of illicit communication facilitated by steganography, it becomes imperative to implement defensive measures. Digital image steganalysis, operating as an adversarial counterpart, strives to ascertain the presence of secret data by scrutinizing the content of suspicious images5. Over the past decades, the domains of steganography and steganalysis for digital images have undergone significant development.

Contemporary steganography endeavors to reduce embedding distortion on a cover image through the utilization of user-defined distortion functions6. This objective is pursued through distortion minimization coding techniques, exemplified by methodologies such as STC (Syndrome Trellis Coding)7, SPC (Steganographic Polar Codes)8, and log-BPGD (Log-domain Belief Propagation Guided Decimation)9. Contemporary steganalysis utilizes supervised machine learning to explore variations in statistical models between cover and stego images10. Currently, the detection accuracy of steganalysis still has not steadily achieved a high level especially for small payload of steganography. For example, detection accuracy of the popular steganalytic tool SRNet11 is about 70% when detecting popular steganographic schemes with payload 0.1 bpp. For the feature extraction-based steganalytic tools such as TLBP12, detection accuracy is only about 60% when detecting popular steganographic schemes with payload 0.1 bpp. To intercept covert communication of steganography effectively, a new form of defense method against steganography is desirable.

This paper introduces a novel approach, termed the “image vaccine method”, designed to counteract steganography. Illustrated in Fig. 1, our method involves injecting a small quantity of vaccine data into an image intended for protection. Subsequently, the vaccinated image becomes impervious to steganographic manipulation. Consequently, when covert data is embedded into the vaccinated image, our method ensures a 100% probability of detecting the resulting stego images. This impeccable detection accuracy underscores the efficacy of our approach, making it possible to consistently intercept covert communication facilitated by vaccinated images. The proposed method leverages the inherent vulnerability of distortion minimization coding, a widely utilized technique in the realm of steganography. The vaccine data is intricately injected into a given image during the encoding process of distortion minimization coding. In instances where the vaccinated image contains no secret data, the vaccine data can be accurately extracted through the decoding process of distortion minimization coding. However, when secret data is embedded into the vaccinated image, the fragility of distortion minimization coding prevents the correct extraction of vaccine data. The decision regarding steganography is then based on the extraction error of vaccine data, providing a reliable indicator for detecting covert communication.Fig. 1 The idea of image vaccine against steganography.

It is an analogy between our method and previous reports on the subject. For previous reports on the subject, “vaccine” is the biological products used to prevent and control the occurrence and spread of infectious diseases. After vaccine injection, humans will be immune to infectious diseases. Similarily, in our method, “vaccine” is a defense mechanism to prevent and control the occurrence and spread of steganography. After vaccine injection, images will be immune to steganography. For this reason, we termed our method as “image vaccine”. There are some innovations about the terminology “vaccine” from previous reports to our method. Firstly, “vaccine” is biological products in previous reports and defense mechanism in our method; Secondly, “vaccine” is against infectious diseases in previous reports and against steganography in our method; Finally, “vaccine” is used for humans or animals in previous reports and for digital images in our method. The notable contributions of this paper can be outlined as follows: We introduce a novel defense mechanism against steganography named the “image vaccine”. Through our proposed method, achieving a detection accuracy of 100% on steganography is demonstrated, indicating that the presence of secret data can consistently be identified.

Our image vaccine method can be executed for both spatial (uncompressed) and JPEG images. For spatial images, the vaccine data is injected by modifying the values of pixel. For JPEG images, the DCT coefficients can be modified for vaccine injection.

The subsequent sections of this manuscript follow the outlined structure: Section "Related work" provides an overview of relevant literature, Section "Proposed method" elucidates our image vaccine methodology, Section "Experimental results" presents experimental results and their analysis, and Section "Conclusion" encapsulates the concluding remarks of this comprehensive paper.

Related work

In this section, we present an overview of related work, encompassing studies on both steganography and steganalysis specific to digital images.

Digital image steganography

Within the domain of digital image steganography, the process of concealing secret data within a cover image entails nuanced modifications to the image content. In the initial phase, this covert integration positions secret data within the least significant bit (LSB) of the cover image, a strategic choice made to uphold optimal visual quality13. Throughout this stage, researchers have developed a suite of coding algorithms, such as MME (Modified Matrix Encoding)14, matrix embedding15, and BCHopt (BCH syndrome coding heuristic optimization)16, with the aim of minimizing the extent of modifications as rigorously as possible. Following this initial phase, researchers have come to recognize the critical importance of modification locations. In other words, the decrease of modifications cannot achieve satisfactory undetectability statistically.

In contemporary steganographic research, the primary objective is to mitigate embedding distortion within a cover image through the utilization of a user-defined distortion function. Various coding techniques geared towards distortion minimization, such as log-BPGD9, SPC8, and STC7, have been innovatively developed for this purpose. Simultaneously, researchers have introduced a multitude of distortion functions tailored for steganography applications, including WOW (Wavelet Obtained Weights)17, SUNIWARD (Spatial Universal Wavelet Relative Distortion)18, MiPOD (Minimizing the Power of Optimal Detector)19, HILL (High-pass, Low-pass, and Low-pass)20, and DFEI (Distortion Function for Enhanced Images)21 for spatial images. Additionally, for JPEG images, distortion functions such as JUNIWARD (JPEG Universal Wavelet Relative Distortion)18, UED (Uniform Embedding Distortion)22, UERD (Uniform Embedding Revisited Distortion)23, HDS (Hybrid Distortion Steganography)24, GUED (Generalized UED)25, and JSCS (JPEG Steganography with Content Similarity)26 have been specifically crafted and investigated.

In our image vaccine method, the fragility of distortion minimization coding used in modern steganography is employed. Vaccine data is injected into a given image using distortion minimization coding. Upon embedding secret data into the vaccinated image, the correct extraction of vaccine data is impeded by the fragility inherent in distortion minimization coding. Thus, the extraction error of vaccine data is the proof of the existence of secret data.

Digital image steganalysis

In the realm of digital image steganalysis, a countermeasure to the adversarial technique of digital image steganography, the application of supervised machine learning takes center stage. This approach delves into the examination of statistical model disparities between cover and stego images. A robust steganalytic classifier is trained through the extraction of features from an extensive dataset comprising both cover and stego images27. Notably, various feature extraction methodologies are explored, encompassing SPAM (Subtractive Pixel Adjacency Matrix)28, SRMQ1 (SRM with Single Quantization Step)29, PSRM (Projections of SRM)30, maxSRMd2 (Selection-Channel-Aware Variant of SRM)31, TLBP (Threshold Local Binary Pattern)12 tailored for spatial images, and ccJRM (Cartesian Calibrated JPEG Rich Model)32, DCTR (Discrete Cosine Transform Residual)33, GFR (Gabor Filters Residual)34, IGFR (Improved GFR)35, IPAF (Improved Phase-Aware Features)36, MDCFR (Maximum Diversity Cascade Filter Residuals)37 designed for JPEG images. The contemporary landscape of steganalysis adopts an ensemble classifier with low computational complexity38 to effectively train the steganalytic classifier.

In recent advancements, the integration of deep learning has gained prominence within the field of steganalysis, seamlessly combining feature extraction and classifier training processes. The effectiveness of steganalysis based on deep learning surpasses that of conventional handcrafted feature-based approaches, demonstrating enhanced detection accuracy. Specifically, in spatial steganalysis, YeNet39 has made substantial strides in enhancing detection accuracy through the utilization of multiple high-pass filters. Subsequently, SRNet11 further elevates detection accuracy by incorporating a residual structure within the steganalytic network, enabling the capture of intricate modification details introduced by steganography. In40, authors leverage a dual-attention mechanism to exploit image texture information in the spatial domain. Extending the scope to JPEG steganalysis, YeNet is adapted for images with low model complexity41. Another significant advancement in42 introduces a hybrid deep-learning network encompassing DCT kernels, quantization truncation, and a multi-subnetwork structure. The strategic incorporation of visual attention mechanisms for knowledge channel selection is explored in a seminal work43. Furthermore, a multi-perspective progressive structure is ingeniously devised for JPEG steganalysis across domains in a pivotal study44.

Currently, the detection accuracy of steganalysis still has not steadily achieved a high level especially for small payload of steganography. This paper introduces a novel defense methodology against steganography termed the “image vaccine”. In our method, the detection accuracy on steganography is 100%. That means the existence of secret data can be always discovered.

Proposed method

We aim to discover the utilization of steganography by injecting image vaccine in advance. To achieve this, the distortion minimization coding widely used in the field of steganography is employed. Any utilization of steganography on the vaccinated image can be detected due to the fragility of distortion minimization coding.

Application scenarios

Fig. 2 Application scenarios of the proposed method, (a) digital cameras; (b) social networks.

In our method, the vaccine data is injected into a given image before steganography. As shown in Fig. 2, there are two application scenarios of our method, directly. Initially, our method can be integrated into the imaging process of digital cameras. When most of the digital cameras are equipped our image vaccine method, the transmission of illegal content can be eradicated to a great extent. Any steganographic operations executed on the vaccinated image will be discovered since the detection accuracy on steganography of our method is 100%. Secondly, our method can be utilized by a social network user who is unwilling that his/her images are used for illegal communication. To prevent this, the user can inject vaccine data into his/her images before transmitting on social networks. Then, any illegal communication via his/her images can be intercepted. Specific details of our method will be described in the following subsections.

Image vaccine injection

In our approach, we leverage the widely utilized distortion minimization coding paradigm from the steganography domain for the purpose of vaccine injection. In the distortion minimization framework, a dedicated distortion function is formulated to assign costs to image elements. Here, a pixel is considered for spatial images, or a Discrete Cosine Transform (DCT) coefficient for JPEG images. In the context of an image X composed of n elements (pixels or DCT coefficients) {x(1),x(2),…,x(n)}, the costs affiliated with +1 and -1 modifications assigned to x(i) are denoted as ρ+(i) and ρ-(i), respectively, where i∈{1,2,…,n}. Subsequently, the theoretical minimal injection distortion D of the resulting vaccinated image, incorporating m bits of vaccine data6, is articulated as follows:1 D=∑i=1n[p+(i)ρ+(i)+p-(i)ρ-(i)],

where2 p+(i)=e-λρ+(i)1+e-λρ+(i)+e-λρ-(i),

and3 p-(i)=e-λρ-(i)1+e-λρ+(i)+e-λρ-(i).

The variables p+(i) and p-(i) represent the probabilities associated with modifying x(i) by +1 and -1, respectively. The introduction of the parameter λ(λ>0) in Equation (4) is employed to equalize the ternary information entropy of modifying probabilities to m.4 -∑i=1n{p+(i)log2p+(i)+p-(i)log2p-(i)+[1-p+(i)-p-(i)]log2[1-p+(i)-p-(i)]}=m.

To approach the theoretical bound D in Equation (1), a distortion minimization coding should be employed. In our method, we employed the representative ternary STC7 for vaccine injection. The ternary STC offers a practical scheme for approximating D. With the specified costs of +1 and -1 modification, the vaccine data can be injected into X using the encoding process of ternary STC. During the vaccine injection phase, the image elements {x(1),x(2),…,x(n)}, the costs {ρ+(1),ρ+(2),…,ρ+(n)} and {ρ-(1),ρ-(2),…,ρ-(n)}, and the vaccine data v=[v(1),v(2),…,v(m)]T∈{0,1}m are input into the ternary STC to produce the vaccinated image elements {y(1),y(2),…,y(n)}. Then the corresponding vaccinated image Y can be obtained. Without loss of generality, we describe the phase of vaccine injection of binary STC firstly. In binary STC, the LSBs xl=[xl(1),xl(2),…,xl(n)]T∈{0,1}n of X is used for carrying v, which can be obtained by modulo operation as:5 xl(i)=mod[x(i),2].

Specifically, v can be injected into xl using Equation (6), and then the obtained bits yl=[yl(1),yl(2),…,yl(n)]T∈{0,1}n are the LSBs of Y.6 yl=argminC(v)Ds(X,Y),

where7 Ds(X,Y)=∑i=1nρ+(i)t+(i)+ρ-(i)t-(i),

8 t+(i)=1,y(i)>x(i)0,otherwiset-(i)=1,x(i)>y(i)0,otherwise.

The practical distortion between the original and vaccinated image is denoted as C(v), defined as {z∈{0,1}n|Hz=v}, the matrix H∈{0,1}m×n is indicative of a low-density parity-check matrix, determined by the injection speed, injection efficiency, and the parameter m. All operations are conducted within the realm of binary arithmetic. In this context, the vector v can be effectively injected into xl by manipulating the elements in xl to adhere9 Hyl=v.

Where yl are the obtained bits after vaccine injection, xl are the LSBs of pixels of a spatial image or DCT coefficients of a JPEG image. This approach allows for the direct extraction of the vector v through matrix computations. Since all the candidates in C(v) are the solutions for Equation (9), the candidate corresponding to the minimum Ds(X,Y) is selected as the optimal solution. For ternary STC, the two layers of LSBs of X are used for data injection. In practical, binary STC is respectively executed on the LSBs and the second LSBs to achieve ternary STC7.

Thus, vaccine data v can be injected into original image X using Equation (6) with the costs {ρ+(1),ρ+(2),…,ρ+(n)} and {ρ-(1),ρ-(2),…,ρ-(n)}. It can be inferred from Equations (2) and (3) that a larger value of cost ρ+(i) or ρ-(i) results in smaller value of modification probability p+(i) or p-(i). It means that the cost value can be set as a larger value if it do not hope to modify the corresponding element. Specifically, for an element cannot be modified, the values of modification probabilities p+(i) and p-(i) should be set as zero. To achieve this, the costs ρ+(i) and ρ-(i) should be set as +∞. There are many algorithms to determine the cost values for steganography as described in Subsection "Digital image steganography". Among these algorithms, the basic idea is to avoid modifying the smooth areas that can be easily predicted. In our method, the cost values are set as constant, as shown in Equation (10).

10 ρ+(i)=ρ-(i)=1.

In this way, the modification locations will be uniformly distributed among the whole image, since the modification probabilities will be equal. In other words, image vaccine will be existed in the whole image, which is beneficial to enhance the immunity against steganography. Consequently, the alteration pattern introduced by steganography can be readily identified.Fig. 3 Comparison of computational complexity about cost calculation algorithms.

In addition, constant cost values are also beneficial to save the computational complexity of vaccine injection. To verify this, a series of experiments were undertaken on 1000 image randomly selected from the popular image set BOSSbase ver. 1.0145. 100, 200, 300, 400, and 500 bits of vaccine data were respectively injected into the 1000 images. Average running time of constant cost values and those of existing algorithms for cost calculation are shown in Fig. 3, which are tested on a server with 3.7 GHz CPU, 16 GB memory, and Windows 7. It clear that constant cost achieves the lowest computational complexity. For JPEG images, the cost values of nonzero AC coefficients are set as constant, and the others are set as infinity to avoid modifying the corresponding coefficients. In addition, the injected vaccine data should not affect the quality of original image. For this reason, distortion caused by the modifications of vaccine injection should be minimized as far as possible. In our vaccine method, the amplitude of +1 and -1 modifications is enough to inject the required vaccine data. Therefore, we do not consider larger modifications such as +2 and -2.

Steganography detection

Upon the injection of vaccine data into the original image, the resulting vaccinated image becomes impervious to steganography. The verification of steganographic utilization necessitates confirming the presence of vaccine data. For a vaccinated image without steganography, the vaccine data v in the vaccinated image Y can be directly extracted by a matrix computation, as shown in Equation (9). When steganography is executed on the vaccinated image, a part of the bits in yl will be modified. Denote the LSBs of the image after steganography executed as yls=[yls(1),yls(2),…,yls(n)]T∈{0,1}n, then the extracted bits vs=[vs(1),vs(2),…,vs(m)]T∈{0,1}m using the same matrix computation will be different with v, as shown in Equation (11). The elements yls are also the pixels of a spatial image or DCT coefficients of a JPEG image.11 Hyls=vs.

Therefore, when steganography is executed on the vaccinated image, the vaccine data cannot be correctly extracted due to the fragility of above matrix computation. Thus, the extraction error of vaccine data is the proof of the utilization of steganography. Based on this, to decide whether a vaccinated image has been executed steganography, the extracted bits vs are compared with the vaccine data v. The extraction error β can be calculated as,12 β=1m∑j=1m|v(j)-vs(j)|.

Finally, the decision on steganography detection can be made as: steganography has not been executed if β=0; Otherwise, steganography has been executed.

To assess the impact of alterations on images subjected to vaccination, a series of experiments were undertaken on four widely recognized test images, each sized 512×512, namely Lena, Man, Peppers, and Baboon. Subsequently, 100 bits of vaccine data were individually introduced into the four images. Following this, random modifications of +1 or -1 were systematically applied to the pixels of the resulting vaccinated images. The correlation between the quantity of modifications and the extraction error β associated with the vaccine data is elucidated in Fig. 4.Fig. 4 Relationship between the number of modifications and the extraction error of vaccine data.

The findings suggest that the extraction error persists, even with the modification of a single pixel. This signifies that the accurate extraction of vaccine data is unattainable once the vaccinated image has undergone any form of modification. In Fig. 4, the amplitude of modification is 1, which accords with that of steganography. Let e(α) represent the embedding efficiency of steganography, signifying that e(α) bits of secret data can be embedded on average with the modification of a single pixel. Here, α=m/n denotes the payload of steganography, ranging from 0⩽α⩽1. The theoretical limit of steganography’s embedding efficiency46 is given by the expression13 e(α)⩽αH-1(α),

here, H-1(·) represents the inverse function of the binary-entropy function. Therefore, for a steganographic algorithm with a payload of α bits per pixel (bpp), the quantity k(α) of altered pixels is given by,14 k(α)=nαe(α)⩾nH-1(α).

Therefore, modifications are necessary to the data embedding process of steganography even for small payload. For this reason, our method is effective against steganography with small payload. Additional experimental outcomes are presented in Section "Experimental results".

Experimental results

In this section, a sequence of experiments is undertaken to validate the efficacy of our approach.

Experiment setup

Our investigations employed the widely acknowledged image dataset within the steganography domain, BOSSbase ver. 1.0145. This dataset encompasses 10,000 spatial images, each with dimensions of 512×512 (n=5122). In order to evaluate the influence of compression, all 10,000 images underwent JPEG compression at quality factors QF = 75 and QF = 95, respectively. These images served as the original images for the introduction of vaccine data. The quantity of vaccine data was specified as 100, 200, 300, 400, and 500 bits, respectively. Consequently, a total of 50,000 vaccinated spatial images and 100,000 vaccinated JPEG images were generated.

To verify the effectiveness of our method, steganography should be executed on the vaccinated images. For spatial images, the steganographic algorithms SUNIWARD, HILL, MiPOD, and DFEI were employed with payload 0.1, 0.2, 0.3, 0.4, and 0.5 bpp (bits per pixel). For JPEG images, the steganographic algorithms UED, UERD, and JUNIWARD were employed with payload 0.1, 0.2, 0.3, 0.4, and 0.5 bpnzac (bits per nonzero AC coefficient). After that, vaccine extraction was respectively executed on the obtained stego images and the extraction error β was calculated. According to the values of extraction error, decisions on steganography detection can be made as described in Subsection "Steganography detection".

For the sake of comparison, the previously mentioned steganographic algorithms were directly applied to the 10,000 spatial original images and 20,000 JPEG original images. Following this, steganalytic methodologies were employed to discern between the cover and stego images. Fifty percent of both the cover and stego images were designated for training, with the remaining half constituting the testing dataset. The benchmark for evaluating steganalysis performance is grounded in achieving minimal total error PE with identical priors on the testing sets, as articulated in Equation (15).15 PE=minPFAPFA+PMD2.

In this context, PFA and PMD represent the false alarm rate and missed detection rate, respectively. A reduced PE value indicates improved detection accuracy. The assessment of steganalytic results is performed by computing the average PE value over ten random tests. For spatial images, steganalytic methodologies such as SPAM, SRMQ1, maxSRMd2, and TLBP were employed. In the case of JPEG images, steganalytic approaches including ccJRM, DCTR, GFR, and MDCFR were applied.

Image quality

In our method, vaccine data is injected into the original image to defend steganography. Meanwhile, the operation of vaccine injection should not cause obvious image distortion. With regard to this, the quality of the vaccinated image is discussed in this subsection.

The vaccination procedure encompassed the application of all 10,000 images from BOSSbase ver. 1.01, along with the inclusion of four additional test images (Lena, Man, Peppers, and Baboon). Subsequently, the computation of Peak Signal-to-Noise Ratio (PSNR) and Structural Similarity Index Measurement (SSIM) values47 between the original and vaccinated images was undertaken. A higher PSNR or SSIM value signifies enhanced image quality, adhering to the ranges 0<PSNR⩽+∞ and 0⩽SSIM⩽1. The outcomes are meticulously presented in Table 1, with the “BOSSbase” rows articulating the average PSNR and SSIM values derived from the 10,000 image pairs associated with BOSSbase ver. 1.01. The observed numerical fluctuations are attributed to the intrinsic variability in the bits of the vaccine data.Table 1 PSNR and SSIM values of vaccinated images.

	Images	Number of vaccine data (bits)	
100	200	300	400	500	
PSNR (db)	Lena	92.3	89.3	87.8	86.4	85.5	
Man	92.3	89.3	87.8	86.4	85.6	
Peppers	92.3	89.8	87.5	86.5	85.7	
Baboon	92.3	89.3	87.5	86.4	85.4	
BOSSbase	92.3	89.3	87.6	86.4	85.5	
SSIM	Lena	1.0	1.0	1.0	1.0	0.9999	
Man	1.0	1.0	1.0	1.0	0.9999	
Peppers	1.0	1.0	1.0	1.0	1.0	
Baboon	1.0	1.0	1.0	1.0	1.0	
BOSSbase	0.9999	0.9999	0.9999	0.9999	0.9999	

It can be seen from Table 1 that the image quality is excellent since SSIM values are close to 1.0 which is the theoretical bound. PSNR values are also large enough which corresponding to tiny modifications. Since PSNR is defined as16 PSNR=10log102552MSE,

where MSE denotes the mean squared error between the original and vaccinated images. Consequently, the quantity of altered pixels L is calculated as,17 L=n×MSE=65025n10PSNR10.

For the smallest PSNR value 85.4 dB in Table 1, there are about only 49 pixels are +1 or -1 modified for an image size 512×512. Therefore, the modifications made on the original image by our method is tiny. The quality of vaccinated image is hardly lossless.

Detection accuracy

Our methodology is crafted with the primary objective of identifying instances of steganographic utilization. The pivotal metric for assessing our method’s performance revolves around the accuracy of steganography detection. All 10,000 images from BOSSbase ver. 1.01 served as the base images for the injection of vaccine data. Subsequently, steganographic algorithms, namely SUNIWARD, HILL, MiPOD, and DFEI, were applied to embed confidential data into the vaccinated images, each with varying payload capacities set at 0.1, 0.2, 0.3, 0.4, and 0.5 bits per pixel (bpp). The discernment of steganographic utilization was executed by our method, and the resulting detection accuracies (indicating the proportion of correct decisions) are itemized in Table 2. Each accuracy assessment was computed by comparing 10,000 vaccinated images devoid of secret data (cover images) with their corresponding 10,000 counterparts containing concealed information (stego images).Table 2 Detection accuracy on steganography (%).

Steganographic algorithms	Payload	Number of vaccine data (bits)	
(bpp)	100	200	300	400	500	
DFEI	0.5	100.0	100.0	100.0	100.0	100.0	
0.4	100.0	100.0	100.0	100.0	100.0	
0.3	100.0	100.0	100.0	100.0	100.0	
0.2	100.0	100.0	100.0	100.0	100.0	
0.1	100.0	100.0	100.0	100.0	100.0	
MiPOD	0.5	100.0	100.0	100.0	100.0	100.0	
0.4	100.0	100.0	100.0	100.0	100.0	
0.3	100.0	100.0	100.0	100.0	100.0	
0.2	100.0	100.0	100.0	100.0	100.0	
0.1	100.0	100.0	100.0	100.0	100.0	
HILL	0.5	100.0	100.0	100.0	100.0	100.0	
0.4	100.0	100.0	100.0	100.0	100.0	
0.3	100.0	100.0	100.0	100.0	100.0	
0.2	100.0	100.0	100.0	100.0	100.0	
0.1	100.0	100.0	100.0	100.0	100.0	
SUNIWARD	0.5	100.0	100.0	100.0	100.0	100.0	
0.4	100.0	100.0	100.0	100.0	100.0	
0.3	100.0	100.0	100.0	100.0	100.0	
0.2	100.0	100.0	100.0	100.0	100.0	
0.1	100.0	100.0	100.0	100.0	100.0	

As expected, the detection accuracy on steganography of our method is 100% for all cases, as shown in Table 2. That means for a given image, the decision on the utilization of steganography can be always correctly made by our method as long as the vaccine data is injected beforehand. In other words, the cover images and stego images can be always correctly classified by our method. The result is reasonable since the extraction error of vaccine data is not equal to zero even if only one pixel is modified, as shown in Fig. 4. The vaccine data cannot be correctly extracted as long as the vaccinated image has been modified. On the other hand, modifications are necessary to the data embedding process of steganography even for small payload. Therefore, our method is effective to detect the utilization of steganography by capturing the trace of modification. We achieve a remarkable improvement on the accuracy on steganography detection with a quite small price (tiny modifications). Comparisons with existing steganalytic tools will be discussed in the next subsection.

Comparison with steganalysis

Steganalysis is the main technique against steganography at present. In this subsection, we compare our method with spatial steganalytic schemes SPAM, SRMQ1, maxSRMd2, TLBP and JPEG steganalytic schemes ccJRM, DCTR, GFR, MDCFR. All the 10,000 images in BOSSbase ver. 1.01 were used as cover images for steganography. Then, steganalytic schemes were used to distinguish the cover and stego images. The performance was evaluated by PE as shown in Equation (15). For our method, vaccine data of 100 bits was injected into cover images beforehand. The comparisons of PE for our method and spatial steganalytic schemes were shown in Fig. 5 and Fig. 6.Fig. 5 Comparisons of our method and spatial steganalytic schemes against (a) DFEI and (b) MiPOD.

Fig. 6 Comparisons of our method and spatial steganalytic schemes against (a) HILL and (b) SUNIWARD.

It is clear in Figs. 5 and 6 that the PE values of our method are much smaller than other steganalytic schemes in all cases. Specifically, the values of PE for our method are always equal to zero. It is reasonable since the detection accuracy on steganography of our method is 100% for all cases, as listed in Table 2. The results of PE again verified that the cover images and stego images can be always correctly classified by our method, while detection errors are always existed in steganalytic schemes. As mentioned in Section , the detection accuracy of steganalysis still has not steadily achieved a high level especially for small payload of steganography. For example, the values of PE for steganalysis are around 0.4 for the cases of payload 0.1 bpp (the bound of PE is 0.5). That means steganalysis is not able to classify cover images and stego images for the case of small payload. By injecting vaccine data beforehand, our method achieve a qualitative improvement on defending steganography compared with steganalysis. Using our method, the detection error on steganography can be decreased to zero.

For JPEG images, comparisons of PE for our method and JPEG steganalytic schemes were shown in Figs. 7∼9. The results for JPEG images also accord with those for spatial images. The values of PE for our method on JPEG images are always equal to zero, while detection errors are always existed in JPEG steganalytic schemes. Usually, a smaller payload results in a larger PE, since it means few modifications are made on cover image, and it is hard to capture the modification trace. For JPEG images, a larger quality factor QF also results in a larger PE. This is because that a larger QF means few information are lost during the process of JPEG compression. The redundancy of content is advantageous to steganography. Therefore, the performance of steganalysis depends on many aspects. For our method, the values of PE are always zero no matter of payload and quality factor. In addition, it can be observed that the detection performance of JPEG steganalysis on UED is closer to that of our method compared with the cases on JUNIWARD and UERD. The reason is that the steganographic algorithms JUNIWARD and UERD are better than UED, and so it is more difficult to detect JUNIWARD and UERD. For this reason, steganalysis is not good at detecting advanced steganographic algorithms especially for small payload of steganography. Thus, our method has an advantage of detecting the state-of-the-art steganographic algorithms.Fig. 7 Comparisons of our method and JPEG steganalytic schemes against JUNIWARD with (a) QF=75 and (b) QF=95.

Fig. 8 Comparisons of our method and JPEG steganalytic schemes against UERD with (a) QF=75 and (b) QF=95.

Fig. 9 Comparisons of our method and JPEG steganalytic schemes against UED with (a) QF=75 and (b) QF=95.

To substantiate the effectiveness of our methodology, a series of experiments was conducted to compare our approach with steganalysis based on deep learning. The complete collection of 10,000 images from BOSSbase ver. 1.01 served as cover images for steganographic embedding. The steganalytic networks, namely YeNet and SRNet, were then applied to distinguish between the cover and stego images. The evaluation of performance was carried out utilizing the Probability of Error (PE), as delineated in Table 3.Table 3 Comparison of PE between proposed method and deep learning-based steganalysis.

Algorithms	Detection	Payload (bpp)	
0.1	0.2	0.3	0.4	0.5	
HILL	Proposed	0.0	0.0	0.0	0.0	0.0	
SRNet	0.301	0.216	0.164	0.129	0.103	
YeNet	0.338	0.254	0.195	0.171	0.131	
SUNIWARD	Proposed	0.0	0.0	0.0	0.0	0.0	
SRNet	0.297	0.192	0.131	0.094	0.067	
YeNet	0.322	0.222	0.150	0.128	0.100	

In a broader context, the experimental findings provide additional affirmation of the efficacy of our proposed method, introducing the concept of image vaccination. Upon comparing Table 3 with Figs. 5∼6, it becomes evident that the detection performance of deep learning-based steganalysis surpasses that of handcrafted feature-based steganalysis. However, it remains a considerable distance from achieving PE values approaching zero. In contrast, the PEvalues attained by our method have already reached zero. Consequently, our approach holds significance for the realms of steganography and steganalysis.

Conclusion

This study introduces a novel defensive approach against steganography referred to as “image vaccination”. The methodology involves the incorporation of a limited quantity of vaccine data during the encoding process utilizing distortion minimization coding to safeguard an image. The resultant vaccinated image demonstrates immunity to steganographic attempts. In instances where covert data is embedded within the vaccinated image, the fragility inherent in distortion minimization coding prevents the extraction of vaccine data. Consequently, any extraction error in the vaccine data serves as conclusive evidence of the presence of secret data. Empirical findings validate the efficacy of our approach, showcasing a 100% detection accuracy for steganography. In essence, our method consistently identifies stego images generated through steganographic techniques. Hence, our approach holds significant utility in curbing the application of steganography. In our method, an image owner sends the original image to a vaccine provider for vaccine injection. In this case, content of original image is overt to the vaccine provider. In future work, it is interesting to develop a vaccine scheme for encrypted image. It is because that the image owner and vaccine provider are not the same person in some cases. For privacy protection, the image owner hopes that the vaccine provider can inject vaccine data into the original image without knowing the image content.

Acknowledgements

This work was supported in part by Natural Science Foundation of China under Grant 62376148, and supported in part by the Chenguang Program of Shanghai Education Development Foundation and Shanghai Municipal Education Commission under Grant 22CGA46.

Author contributions

All authors contributed extensively to the work presented in this paper. Xinran Li conceived the study and designed the image vaccine scheme. Zichi Wang performed the experiments and wrote the paper.

Data availability 

The datasets generated and/or analysed during the current study are available in the [SUNY Binghamton] repository, [http://agents.fel.cvut.cz/stegodata/]

Declarations

Competing interests

The authors declare no competing interests.

Publisher’s note

Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
==== Refs
References

1. Shivakumara P A new language-independent deep cnn for scene text detection and style transfer in social media images IEEE Transactions on Image Processing 2023 32 3552 3566 10.1109/TIP.2023.3287038 37342944
Shivakumara, P. et al. A new language-independent deep cnn for scene text detection and style transfer in social media images. IEEE Transactions on Image Processing 32, 3552–3566 (2023).37342944 10.1109/TIP.2023.3287038
2. Priya S Abirami S Arunkumar B Mishachandar B Super-resolution deep neural network (srdnn) based multi-image steganography for highly secured lossless image transmission Scientific Reports 2024 14 6104 10.1038/s41598-024-54839-7 38480860
Priya, S., Abirami, S., Arunkumar, B. & Mishachandar, B. Super-resolution deep neural network (srdnn) based multi-image steganography for highly secured lossless image transmission. Scientific Reports 14, 6104 (2024).38480860 10.1038/s41598-024-54839-7
3. Luo J Zhou R-G Luo G Li Y Liu G Traceable quantum steganography scheme based on pixel value differencing Scientific reports 2019 9 15134 10.1038/s41598-019-51598-8 31641209
Luo, J., Zhou, R.-G., Luo, G., Li, Y. & Liu, G. Traceable quantum steganography scheme based on pixel value differencing. Scientific reports 9, 15134 (2019).31641209 10.1038/s41598-019-51598-8
4. Wang Z Feng G Shen L Zhang X Cover selection for steganography using image similarity IEEE Transactions on Dependable and Secure Computing 2023 20 2328 2340
Wang, Z., Feng, G., Shen, L. & Zhang, X. Cover selection for steganography using image similarity. IEEE Transactions on Dependable and Secure Computing 20, 2328–2340 (2023).
5. Shankar DD Azhakath AS Random embedded calibrated statistical blind steganalysis using cross validated support vector machine and support vector machine with particle swarm optimization Scientific Reports 2023 13 2359 10.1038/s41598-023-29453-8 36759703
Shankar, D. D. & Azhakath, A. S. Random embedded calibrated statistical blind steganalysis using cross validated support vector machine and support vector machine with particle swarm optimization. Scientific Reports 13, 2359 (2023).36759703 10.1038/s41598-023-29453-8
6. Fridrich, J. & Filler, T. Practical methods for minimizing embedding impact in steganography. In Security, Steganography, and Watermarking of Multimedia Contents IX, vol. 6505, 650502 (International Society for Optics and Photonics, 2007).
7. Filler T Judas J Fridrich J Minimizing additive distortion in steganography using syndrome-trellis codes IEEE Transactions on Information Forensics and Security 2011 6 920 935 10.1109/TIFS.2011.2134094
Filler, T., Judas, J. & Fridrich, J. Minimizing additive distortion in steganography using syndrome-trellis codes. IEEE Transactions on Information Forensics and Security 6, 920–935 (2011).10.1109/TIFS.2011.2134094
8. Li W Zhang W Li L Zhou H Yu N Designing near-optimal steganographic codes in practice based on polar codes IEEE Transactions on Communications 2020 68 3948 3962 10.1109/TCOMM.2020.2982624
Li, W., Zhang, W., Li, L., Zhou, H. & Yu, N. Designing near-optimal steganographic codes in practice based on polar codes. IEEE Transactions on Communications 68, 3948–3962 (2020).10.1109/TCOMM.2020.2982624
9. Yao, Q., Zhang, W., Chen, K. & Yu, N. Ldgm codes based near-optimal coding for adaptive steganography. IEEE Transactions on Communications (2023, 10.1109/TCOMM.2023.3342247.).
10. Li Q Feng G Ren Y Zhang X Embedding probability guided network for image steganalysis IEEE Signal Processing Letters 2021 28 1095 1099 10.1109/LSP.2021.3083546
Li, Q., Feng, G., Ren, Y. & Zhang, X. Embedding probability guided network for image steganalysis. IEEE Signal Processing Letters 28, 1095–1099 (2021).10.1109/LSP.2021.3083546
11. Boroumand M Chen M Fridrich J Deep residual network for steganalysis of digital images IEEE Transactions on Information Forensics and Security 2019 14 1181 1193 10.1109/TIFS.2018.2871749
Boroumand, M., Chen, M. & Fridrich, J. Deep residual network for steganalysis of digital images. IEEE Transactions on Information Forensics and Security 14, 1181–1193 (2019).10.1109/TIFS.2018.2871749
12. Li B Li Z Zhou S Tan S Zhang X New steganalytic features for spatial image steganography based on derivative filters and threshold lbp operator IEEE Transactions on Information Forensics and Security 2017 13 1242 1257 10.1109/TIFS.2017.2780805
Li, B., Li, Z., Zhou, S., Tan, S. & Zhang, X. New steganalytic features for spatial image steganography based on derivative filters and threshold lbp operator. IEEE Transactions on Information Forensics and Security 13, 1242–1257 (2017).10.1109/TIFS.2017.2780805
13. Westfeld, A. F5—a steganographic algorithm. In International workshop on information hiding, 289–302 (Springer, 2001).
14. Kim, Y., Duric, Z. & Richards, D. Modified matrix encoding technique for minimal distortion steganography. In International Workshop on Information Hiding, 314–327 (Springer, 2006).
15. Fridrich J Soukal D Matrix embedding for large payloads IEEE Transactions on Information Forensics and Security 2006 1 390 395 10.1109/TIFS.2006.879281
Fridrich, J. & Soukal, D. Matrix embedding for large payloads. IEEE Transactions on Information Forensics and Security 1, 390–395 (2006).10.1109/TIFS.2006.879281
16. Sachnev, V., Kim, H. J. & Zhang, R. Less detectable jpeg steganography method based on heuristic optimization and bch syndrome coding. In Proceedings of the 11th ACM Workshop on Multimedia and Security, 131–140 (2009).
17. Holub, V. & Fridrich, J. J. Designing steganographic distortion using directional filters. In Information Forensics and Security (WIFS), 2012 IEEE International Workshop on, 234–239 (2012).
18. Holub V Fridrich J Denemark T Universal distortion function for steganography in an arbitrary domain EURASIP Journal on Information Security 2014 2014 1 10.1186/1687-417X-2014-1
Holub, V., Fridrich, J. & Denemark, T. Universal distortion function for steganography in an arbitrary domain. EURASIP Journal on Information Security 2014, 1 (2014).10.1186/1687-417X-2014-1
19. Sedighi V Cogranne R Fridrich J Content-adaptive steganography by minimizing statistical detectability IEEE Transactions on Information Forensics and Security 2015 11 221 234 10.1109/TIFS.2015.2486744
Sedighi, V., Cogranne, R. & Fridrich, J. Content-adaptive steganography by minimizing statistical detectability. IEEE Transactions on Information Forensics and Security 11, 221–234 (2015).10.1109/TIFS.2015.2486744
20. Li, B., Wang, M., Huang, J. & Li, X. A new cost function for spatial image steganography. In Image Processing (ICIP), 2014 IEEE International Conference on, 4206–4210 (IEEE, 2014).
21. Wang, Z., Feng, G. & Zhang, X. Steganographic distortion function for enhanced images. In Digital Forensics and Watermarking: 19th International Workshop, IWDW 2020, Melbourne, VIC, Australia, November 25–27, 2020, Revised Selected Papers 19, 31–40 (Springer, 2021).
22. Guo L Ni J Shi YQ Uniform embedding for efficient jpeg steganography IEEE transactions on Information Forensics and Security 2014 9 814 825 10.1109/TIFS.2014.2312817
Guo, L., Ni, J. & Shi, Y. Q. Uniform embedding for efficient jpeg steganography. IEEE transactions on Information Forensics and Security 9, 814–825 (2014).10.1109/TIFS.2014.2312817
23. Guo L Ni J Su W Tang C Shi Y-Q Using statistical image model for jpeg steganography: uniform embedding revisited IEEE Transactions on Information Forensics and Security 2015 10 2669 2680 10.1109/TIFS.2015.2473815
Guo, L., Ni, J., Su, W., Tang, C. & Shi, Y.-Q. Using statistical image model for jpeg steganography: uniform embedding revisited. IEEE Transactions on Information Forensics and Security 10, 2669–2680 (2015).10.1109/TIFS.2015.2473815
24. Wang Z Zhang X Yin Z Hybrid distortion function for jpeg steganography Journal of Electronic Imaging 2016 25 050501 10.1117/1.JEI.25.5.050501
Wang, Z., Zhang, X. & Yin, Z. Hybrid distortion function for jpeg steganography. Journal of Electronic Imaging 25, 050501 (2016).10.1117/1.JEI.25.5.050501
25. Su W Ni J Li X Shi Y-Q A new distortion function design for jpeg steganography using the generalized uniform embedding strategy IEEE Transactions on Circuits and Systems for Video Technology 2018 28 3545 3549 10.1109/TCSVT.2018.2865537
Su, W., Ni, J., Li, X. & Shi, Y.-Q. A new distortion function design for jpeg steganography using the generalized uniform embedding strategy. IEEE Transactions on Circuits and Systems for Video Technology 28, 3545–3549 (2018).10.1109/TCSVT.2018.2865537
26. Wang Z Feng G Qian Z Zhang X Jpeg steganography with content similarity evaluation IEEE Transactions on Cybernetics 2023 53 5082 5093 10.1109/TCYB.2022.3155732 35580096
Wang, Z., Feng, G., Qian, Z. & Zhang, X. Jpeg steganography with content similarity evaluation. IEEE Transactions on Cybernetics 53, 5082–5093 (2023).35580096 10.1109/TCYB.2022.3155732
27. Qiao T Luo X Wu T Xu M Qian Z Adaptive steganalysis based on statistical model of quantized dct coefficients for jpeg images IEEE Transactions on Dependable and Secure Computing 2021 18 2736 2751 10.1109/TDSC.2019.2962672
Qiao, T., Luo, X., Wu, T., Xu, M. & Qian, Z. Adaptive steganalysis based on statistical model of quantized dct coefficients for jpeg images. IEEE Transactions on Dependable and Secure Computing 18, 2736–2751 (2021).10.1109/TDSC.2019.2962672
28. Pevnỳ, T., Bas, P. & Fridrich, J. Steganalysis by subtractive pixel adjacency matrix. In Proceedings of the 11th ACM workshop on Multimedia and security, 75–84 (2009).
29. Fridrich J Kodovsky J Rich models for steganalysis of digital images IEEE Transactions on Information Forensics and Security 2012 7 868 882 10.1109/TIFS.2012.2190402
Fridrich, J. & Kodovsky, J. Rich models for steganalysis of digital images. IEEE Transactions on Information Forensics and Security 7, 868–882 (2012).10.1109/TIFS.2012.2190402
30. Holub V Fridrich J Random projections of residuals for digital image steganalysis IEEE Transactions on Information Forensics and Security 2013 8 1996 2006 10.1109/TIFS.2013.2286682
Holub, V. & Fridrich, J. Random projections of residuals for digital image steganalysis. IEEE Transactions on Information Forensics and Security 8, 1996–2006 (2013).10.1109/TIFS.2013.2286682
31. Denemark, T., Sedighi, V., Holub, V., Cogranne, R. & Fridrich, J. Selection-channel-aware rich model for steganalysis of digital images. In Information Forensics and Security (WIFS), 2014 IEEE International Workshop on, 48–53 (IEEE, 2014).
32. Kodovskỳ, J. & Fridrich, J. Steganalysis of jpeg images using rich models. In Media Watermarking, Security, and Forensics 2012, 81–93. International Society for Optics and Photonics (SPIE, 2012).
33. Holub V Fridrich J Low-complexity features for jpeg steganalysis using undecimated dct IEEE Transactions on Information Forensics and Security 2015 10 219 228 10.1109/TIFS.2014.2364918
Holub, V. & Fridrich, J. Low-complexity features for jpeg steganalysis using undecimated dct. IEEE Transactions on Information Forensics and Security 10, 219–228 (2015).10.1109/TIFS.2014.2364918
34. Song, X., Liu, F., Yang, C., Luo, X. & Zhang, Y. Steganalysis of adaptive jpeg steganography using 2d gabor filters. In Proceedings of the 3rd ACM Workshop on Information Hiding and Multimedia Security, 15–23 (Association for Computing Machinery, 2015).
35. Xia, C., Guan, Q., Zhao, X., Xu, Z. & Ma, Y. Improving gfr steganalysis features by using gabor symmetry and weighted histograms. In Proceedings of the 5th ACM Workshop on Information Hiding and Multimedia Security, 55–66 (2017).
36. Xia C Guan Q Zhao X Wu K Improved jpeg phase-aware steganalysis features using multiple filter sizes and difference images IEEE Transactions on Circuits and Systems for Video Technology 2020 30 4100 4113 10.1109/TCSVT.2019.2954041
Xia, C., Guan, Q., Zhao, X. & Wu, K. Improved jpeg phase-aware steganalysis features using multiple filter sizes and difference images. IEEE Transactions on Circuits and Systems for Video Technology 30, 4100–4113 (2020).10.1109/TCSVT.2019.2954041
37. Feng G Zhang X Ren Y Qian Z Li S Diversity-based cascade filters for jpeg steganalysis IEEE Transactions on circuits and systems for video technology 2020 30 376 386 10.1109/TCSVT.2019.2891778
Feng, G., Zhang, X., Ren, Y., Qian, Z. & Li, S. Diversity-based cascade filters for jpeg steganalysis. IEEE Transactions on circuits and systems for video technology 30, 376–386 (2020).10.1109/TCSVT.2019.2891778
38. Kodovskỳ J Fridrich J Holub V Ensemble classifiers for steganalysis of digital media IEEE Transactions on Information Forensics and Security 2012 7 432 444 10.1109/TIFS.2011.2175919
Kodovskỳ, J., Fridrich, J. & Holub, V. Ensemble classifiers for steganalysis of digital media. IEEE Transactions on Information Forensics and Security 7, 432–444 (2012).10.1109/TIFS.2011.2175919
39. Ye J Ni J Yi Y Deep learning hierarchical representations for image steganalysis IEEE Transactions on Information Forensics and Security 2017 12 2545 2557 10.1109/TIFS.2017.2710946
Ye, J., Ni, J. & Yi, Y. Deep learning hierarchical representations for image steganalysis. IEEE Transactions on Information Forensics and Security 12, 2545–2557 (2017).10.1109/TIFS.2017.2710946
40. Zhang X Zhang X Feng G Image steganalysis network based on dual-attention mechanism IEEE Signal Processing Letters 2023 30 1287 1291 10.1109/LSP.2023.3313517
Zhang, X., Zhang, X. & Feng, G. Image steganalysis network based on dual-attention mechanism. IEEE Signal Processing Letters 30, 1287–1291 (2023).10.1109/LSP.2023.3313517
41. Huang, J., Ni, J., Wan, L. & Yan, J. A customized convolutional neural network with low model complexity for jpeg steganalysis. In Proceedings of the ACM workshop on information hiding and multimedia security, 198–203 (2019).
42. Zeng J Tan S Li B Huang J Large-scale jpeg image steganalysis using hybrid deep-learning framework IEEE Transactions on Information Forensics and Security 2018 13 1200 1214 10.1109/TIFS.2017.2779446
Zeng, J., Tan, S., Li, B. & Huang, J. Large-scale jpeg image steganalysis using hybrid deep-learning framework. IEEE Transactions on Information Forensics and Security 13, 1200–1214 (2018).10.1109/TIFS.2017.2779446
43. Hu D Digital image steganalysis based on visual attention and deep reinforcement learning IEEE Access 2019 7 25924 25935 10.1109/ACCESS.2019.2900076
Hu, D. et al. Digital image steganalysis based on visual attention and deep reinforcement learning. IEEE Access 7, 25924–25935 (2019).10.1109/ACCESS.2019.2900076
44. Jia J Luo M Liu J Ren W Wang L Multiperspective progressive structure adaptation for jpeg steganography detection across domains IEEE Transactions on Neural Networks and Learning Systems 2022 33 3660 3674 10.1109/TNNLS.2021.3054045 33560992
Jia, J., Luo, M., Liu, J., Ren, W. & Wang, L. Multiperspective progressive structure adaptation for jpeg steganography detection across domains. IEEE Transactions on Neural Networks and Learning Systems 33, 3660–3674 (2022).33560992 10.1109/TNNLS.2021.3054045
45. Bas, P., Filler, T. & Pevnỳ, T. Break our steganographic system: the ins and outs of organizing boss. In International Workshop on Information Hiding, 59–70 (Springer, 2011).
46. Zhang W Zhu X Improving the embedding efficiency of wet paper codes by paper folding IEEE Signal Processing Letters 2009 16 794 797 10.1109/LSP.2009.2024807
Zhang, W. & Zhu, X. Improving the embedding efficiency of wet paper codes by paper folding. IEEE Signal Processing Letters 16, 794–797 (2009).10.1109/LSP.2009.2024807
47. Wang Z Bovik AC A universal image quality index IEEE signal processing letters 2002 9 81 84 10.1109/97.995823
Wang, Z. & Bovik, A. C. A universal image quality index. IEEE signal processing letters 9, 81–84 (2002).10.1109/97.995823
