节点文献
基于多载体和新载体的隐写方法研究
Research on Steganography of Multiple Covers and New Covers
【作者】 李莉;
【导师】 张卫明;
【作者基本信息】 中国科学技术大学 , 网络空间安全, 2022, 博士
【摘要】 近年来,互联网的普及使得信息可以方便地通过网络进行传输,但同时很多与军事、政治、商业等重要领域相关的敏感信息也暴露在网络中。因此,保障敏感信息在网络传输中的安全具有重要意义。为了实现安全的网络通信,密码术采用加密的方式将信息编码为一串无意义的随机码字,保护信息的内容安全。但这种发送无意义码字的方式泄露了“秘密通信”的行为,容易引起针对性的监测与攻击。为了进一步隐藏“秘密通信”行为,隐写术先将加密后的消息隐藏在常见的多媒体数据中,再通过社交平台等公共信道进行传输,从而保护通信的行为安全。实际应用中,隐写通常会面临隐写分析的风险,不仅包括单图隐写分析的风险,还包括以用户为单位的隐写者检测的风险。因此,安全的隐写不仅要求载体载密不可区分,还要求隐写者的行为符合社交场景。以多张图像承载消息的多载体隐写在图像数量上符合社交用户的行为,但现有方法主要关注消息分配的问题而忽略了隐写者的其他行为特征,导致隐写者在行为分析下仍会暴露自己。同时,基于深度学习的隐写者检测也对多载体隐写算法提出了更高的安全要求。因此,本文首先从对抗隐写分析的角度研究了如何提升多载体隐写的安全性,然后利用当前网络环境下衍生出的的新型载体数据设计隐写算法,增加隐写算法的多样性。本文的主要工作与创新点如下:1.行为安全的载体选择方法针对现有的隐写载体选择方法行为安全不足的问题,本文首先设计了基于侧信道隐写分析和互补攻击的行为安全判别器,以提高隐写者的行为安全。侧信道分析的作用是区分随机图像序列和内容相关的图像序列。由于社交用户通常连续发送一些内容相关的图像,采用侧信道分析选择具有相关内容的图像序列作为载体,可以使得隐写者与正常用户行为一致。此外,本文进一步发现利用内容相关的图像作为边信息可以提升隐写分析的准确性,与侧信道分析构成互补攻击,使得隐写者发送过多的内容相关的图像也是不安全的。实验结果表明,隐写者发送的内容相关的图像比例应该在一个安全区间内,既不能发送过多的随机图,也不能发送过多的相关图。2.多载体对抗隐写方法为了对抗基于深度学习的隐写者检测,本文借鉴计算机视觉中对抗样本的思想,提出了多载体对抗隐写方法。该方法首先针对隐写者检测算法采用无监督分类方式的特点设计代价函数;然后利用其反向传播得到的梯度调整传统隐写失真,使得在调整后的失真下,隐写的修改方向能够最小化隐写者与正常用户的隐写分析特征的距离,从而减小隐写者被发现的风险;最后将图像间自适应消息分配策略和失真调整策略相结合,提升现有隐写方法的安全性。实验结果表明,该方法不仅可以抵抗基于多张图像的隐写者检测,而且也在一定程度上降低了有监督的单图隐写分析的检测准确性,提升了隐写的算法安全。3.基于图像风格迁移的隐写方法当前网络环境下,传输风格化的图像成为一种普遍的现象,因此,以风格化图像为载体的隐写符合当前社交用户的行为。本文提出了一种基于图像风格迁移的隐写方法,将图像风格迁移过程与消息嵌入过程融合,使得生成的载密图与风格化图像难以区分,从而提升隐写的安全性。通过修改风格迁移网络的中间层,将秘密消息和网络浅层特征拼接,并作为下一个网络层的输入,从而将消息嵌入与风格迁移进行融合,实现风格迁移中的隐写。为了保证消息可以被正确提取,在网络末端加入消息提取网络一起训练。同时采用对抗训练的思想,以隐写分析网络作为判别器进行对抗训练,以提升载密的安全性。实验结果表明,该方法可以实现大容量的隐写,并且可以抵抗传统隐写分析的检测。4.基于深度神经网络的新型隐写方法随着深度学习模型开源平台的普及,在网络中共享深度神经网络成为一种普遍的用户行为,使得深度神经网络成为一种理想的隐写载体。因此,本文提出了两种以深度神经网络为载体的隐写方法:基于神经网络的隐蔽任务隐写和基于神经网络的黑盒鲁棒隐写方法。隐蔽任务隐写通过修改网络训练过程,使得网络在原始任务之外还学习到一个隐蔽任务,并将隐蔽任务结果作为秘密消息隐藏在原始任务输出中,同时不影响原始任务性能。黑盒的鲁棒隐写方法通过向训练损失中加入正则项约束,使得网络输出具有特定的与密钥和消息相关的偏差,从而将秘密消息隐藏到网络输出中。实验结果表明,所提两种方法可以在不影响网络性能的同时,分别提取出隐藏在输出中的隐蔽任务结果和隐秘消息,并且基于神经网络的黑盒鲁棒隐写方法对于网络的微调和剪枝具有鲁棒性。
【Abstract】 In recent years,the popularization of the Internet has promoted the efficient transmission of information.However,sensitive information related to military,political,commercial,and other important fields is also exposed on the network,so the security of the sensitive information transmitted on the Internet should be protected.To this end,classical cryptography encodes the information to a series of meaningless and random codewords to hide the information content,thereby protecting the content security of sensitive information.However,the behavior of "secret communication" is divulged by the way of sending such meaningless codewords,which may arouse targeted monitoring and attack.In order to hide the "secret communication" behavior,steganography hides the encrypted messages in the common multimedia,and then transmits them through public channels such as social platforms,in such a way the "secret communication" is covered up by the normal social behavior,thereby the behavior security of communication is protected.In practice,steganography usually faces the risk of steganalysis,including single image steganalysis and steganographer detection based on users.A secure steganography algorithm not only requires the concealment of the modification but also expects the steganographer’s behavior conforms to the social scene.Batch steganography conforms to the behavior of social users in terms of the number of images,since the messages are hiding in multiple images.But existing research on batch steganography mainly focuses on the problem of payload distribution but ignores other behavior characteristics of the steganographer,thereby the steganographer is still liable to expose herself under behavior analysis.Additionally,deep learning-based steganographer detection brings new challenges to batch steganography.Therefore,this dissertation first studies how to improve the security of multi-cover-based batch steganography,and then makes use of the new covers brought by deep learning to design steganography algorithms.The main work and innovations of this dissertation are as follows:1.Behavioral Secure Cover Selection Method for Batch Steganography To improve the behavior security of the steganographer,two discriminators are designed,namely discriminators based on side-channel steganalysis and complementary attack.The side-channel analysis is used to distinguish random image sequences from content-related image sequences.Because social users usually send images with similar content continuously,selecting the image sequence with related content as the cover by using side-channel analysis helps the steganographer to behave consistently with the social user.It is further found that content-related images could be used as side information to improve the accuracy of steganalysis,which forms a complementary attack with side-channel analysis.Therefore,the steganographer should not send too many content-related images.Experimental results demonstrate that the number of content-relative images should be in a secure interval,neither totally random covers nor totally relative covers are secure.2.Batch Adversarial Steganography Against Deep-learning Based Steganographer DetectionTo improve the security of batch steganography under deep learning-based steganographer detection,this dissertation proposes batch adversarial steganography against unsupervised steganographer detection.The proposed approach is based on the idea of the adversarial example in computer vision.a novel cost function is designed regarding the unsupervised classification approach of steganographer detection,then the gradient obtained by its back-propagation is used to adjust the traditional steganography distortion in such a way that the modification direction of steganography could minimize the distance between the steganographer and the normal user,thereby reducing the risk of steganographer being found.Finally,the strategy is implemented to distribute the payload between images.Experimental results demonstrate that the proposed method increases the detection errors of the attacked steganographer detection and single image steganalysis,thereby improving the security of the steganographic algorithm.3.Image Steganography Based on Style TransferCurrently,it is a common phenomenon to share stylized images on the Internet,and hiding information with stylized images can achieve covert communication.This dissertation proposes a steganography method based on image style transfer.It integrates the image style transfer process with the message embedding process to generate stages that are difficult to distinguish from the stylized image,thereby improving the security of steganography.To implement the message embedding and style transfer at the same time,the proposed method concat the secret message and the shallow feature map of a style transfer network.To correctly extract the embedded messages,a message extraction network is added at the end of the message embedding network.Moreover,we adopt the idea of adversarial training and use a steganalysis network as the discriminator to improve the security of generated stegos.Experimental results demonstrate that this method can achieve high-capacity steganography and the generated stegos are difficult to distinguish from stylized images.4.Steganography Based on Deep Neural NetworksWith the popularity of open-source platforms of deep learning models,sharing deep neural networks in the network has become a common social behavior.Therefore,the deep neural network becomes an ideal cover for steganography.This dissertation proposes two steganography methods based on deep neural networks:the covert task steganography method and the Black-box robust steganography method.In covert task steganography,the network training process is modified to force the network to learn a hidden task in addition to the primary task,and hides the hidden task result as a secret message in the output of the primary task.In black-box robust steganography.The output of the network is related to the secret message by a key sequence.By adding a regular term to the training loss,the output of the primary task is forced to have a specific deviation,which is related to the secret message and key.The receiver can directly extract the secret message from the network output by using the key.The experimental results verified the efficiency of the two proposed methods,the hidden task results and the hidden message could be extracted accurately respectively,without affecting the performance of the original task.
【Key words】 Steganography; Deep Neural Network; Batch steganography; Steganographer detection; Behavioral security;