ICASSP 2022accepted0 citations

Patch Steganalysis: A Sampling Based Defense Against Adversarial Steganography

Chuan Qin, Na Zhao, Weiming Zhang, Nenghai Yu

Abstract

In recent years, the classification accuracy of CNN (convolutional neural network) steganalyzers has rapidly improved. However, as general CNN classifiers will misclassify adversarial samples, CNN steganalyzers can hardly detect adversarial steganography, which combines adversarial samples and steganography. Adversarial training and preprocessing are two effective methods to defend against adversarial samples. But literature shows adversarial training is ineffective for adversarial steganography. Steganographic modifications will also be destroyed by preprocessing, which aims to wipe out adversarial perturbations. In this paper, we propose a novel sampling based defense method for steganalysis. Specifically, by sampling image patches, CNN steganalyzers can bypass the sparse adversarial perturbations and extract effective features. Additionally, by calculating statistical vectors and regrouping deep features, the impact on the classification accuracy of common samples is effectively compressed. The experiments show that the proposed method can significantly improve the robustness against adversarial steganography without adversarial training.

BibTeX
@inproceedings{icassp2022_patchsteganalysi,
  title = {Patch Steganalysis: A Sampling Based Defense Against Adversarial Steganography},
  author = {Chuan Qin and Na Zhao and Weiming Zhang and Nenghai Yu},
  booktitle = {ICASSP 2022},
  year = {2022}
}
Patch Steganalysis: A Sampling Based Defense Against Adversarial Steganography · ICASSP 2022