Lightweight image-to-image Steganography Based on Improved Emd and Dual-domain Graph Convolutional Network
-
摘要: 针对现有单域图像隐写方法面临的难以同时兼顾隐蔽性、抗隐写分析能力与运行效率,以及高性能模型结构复杂、难以轻量化部署等问题,该文提出一种基于改进经验模态分解与双域图卷积的轻量化图像隐写网络模型。首先,利用改进的二维经验模态分解模块将秘密图像自适应分解为多尺度分量,以实现隐秘信息在不同形态组件中的自适应层级分散;其次,设计多尺度空频块,通过融合多分支扩张卷积、注意力机制与频域感知单元,实现空间域与频域特征的深度融合与协同优化,在增强抗检测能力的同时确保秘密信息的高保真提取;最后,引入改进的图特征神经网络作为瓶颈层,利用高效的稀疏图卷积操作显式建模远距离像素关联,在有效表征非连续纹理区修改模式的同时大幅降低模型计算复杂度。实验结果表明,该模型参数量仅为8.00 M,计算成本仅为7.88 GFLOPs,单幅图像推理时延低至76 ms,展现出显著的轻量化特征与高运行效率,更适用于资源受限的实际部署环境。Abstract:
Objective Image steganography embeds secret information into a cover image to achieve secure transmission, and it serves as an important technique in confidential communication and privacy protection. With the development of deep learning, learning-based steganography has notably improved embedding capacity and reconstruction quality. However, three requirements, namely high steganographic performance, strong resistance to steganalysis, and lightweight design, are difficult to satisfy simultaneously, and this trade-off has become the main bottleneck for practical deployment. Single-domain processing methods cannot balance the three objectives, whereas existing high-performance models are structurally complex and hard to deploy in resource-constrained environments. Moreover, mainstream dual-domain schemes usually assume that the embedding distortion follows a continuous distribution in both the spatial domain and the frequency domain, yet actual steganographic modifications tend to concentrate in the discontinuous and complex texture regions of the cover image. To address these problems, a lightweight image steganography network is designed in this study to jointly optimize the embedding and extraction paths, so that the stego-image quality and the anti-steganalysis ability are improved while a low computational cost and a low inference latency are maintained. Methods A lightweight steganographic network named GISNet is proposed, in which an encoder-decoder architecture with skip connections is adopted and the hiding network and the extraction network are made structurally symmetric without weight sharing. First, an Improved Bidimensional Empirical Mode Decomposition (IBEMD) module is applied, by which the secret image is adaptively decomposed into several intrinsic mode components and one residual component, so that the hidden information is dispersed hierarchically among components of different morphology. Gaussian blur is used to replace extremum interpolation for estimating the local mean envelope, the separability of the Gaussian kernel is exploited to reduce the computational complexity, and a parameter-binding mechanism is introduced to guarantee deterministic and reversible reconstruction. Next, a multi-scale spatial-frequency block (IMFB) is designed, in which multi-branch dilated convolutions, an attention mechanism, dynamic gating, and a frequency-domain perception unit are integrated, so that the spatial features and the frequency features are deeply fused, the anti-detection ability is enhanced, and the high-fidelity extraction of the secret information is ensured. Finally, an improved graph fusion neural network (GFNN) is employed as the bottleneck layer, in which a sparse graph is constructed in the feature space through the K-nearest-neighbor algorithm and messages are propagated only among non-local nodes with high similarity, so that the long-range pixel associations are explicitly modeled, the modification patterns in discontinuous texture regions are characterized, and the model complexity is substantially reduced. The hiding network and the extraction network are jointly optimized by a four-term loss function that combines the hiding loss, the restriction loss, the Laplacian pyramid loss, and the perceptual loss. Results and Discussions GISNet achieves the best overall image-hiding and recovery performance on DIV2K, COCO, and ImageNet, demonstrating high reconstruction quality and stable cross-dataset generalization ( 表1 ). On DIV2K, the PSNR values reach 58.07 dB for cover/stego image pairs and 60.10 dB for secret/recovered-secret image pairs. The cover and stego images are visually indistinguishable, and the residual maps remain nearly black after 30-fold magnification (图5 ). Ablation experiments show that replacing DWT with IBEMD improves the PSNR values by 8.04 dB and 5.57 dB, respectively (表2 ). The complete combination of IBEMD, IMFB, and GFNN provides the best results, confirming the complementary effects of hierarchical information dispersion, multiscale spatial-frequency mapping, and nonlocal feature association (表3 ). Multi-dilation-rate branches and joint spatial-frequency processing further improve hiding quality and recovery accuracy (表4 ,表5 ). The detection accuracies under four steganalysis methods range from 49.35% to 49.85%, indicating that the stego images are difficult to distinguish from natural cover images (表6 ). GISNet requires only 8.00 M parameters and 7.88 GFLOPs, with an inference time of 76 ms (表7 ). These results demonstrate that GISNet effectively balances visual quality, recovery accuracy, resistance to steganalysis, and computational efficiency.Conclusions A lightweight dual-domain graph convolutional network for image steganography, named GISNet, is proposed in this paper. The experimental results demonstrate the following. (1) The improved bidimensional empirical mode decomposition disperses the secret information hierarchically and supports deterministic and reversible reconstruction, by which a reliable basis is provided for high-quality hiding and recovery. (2) The multi-scale spatial-frequency block and the graph fusion neural network jointly improve the stego-image quality and the anti-steganalysis ability, so that the stego images can resist detection by multiple steganalysis tools. (3) The lightweight design, which is based on depth-wise separable convolutions and sparse graph construction, significantly reduces the model complexity and the computational cost, by which the model is made suitable for deployment in resource-constrained environments. Future work will focus on the robustness against channel interference and the extension to multi-image and cross-modal steganography, so that the security and applicability of the scheme are further enhanced. -
表 1 单图像隐藏结果,最佳结果以粗体显示,次优结果以下划线标出
方法 载体/载密图像对 DIV2K ( 1024 ×1024 )COCO (256 × 256) Imagenet (256 × 256) PSNR SSIM MAE RMSE PSNR SSIM MAE RMSE PSNR SSIM MAE RMSE HiDDeN[7] 32.48 0.9172 9.73 13.93 32.98 0.9137 9.66 13.39 32.95 0.9124 9.87 13.60 UDH[31] 44.68 0.8913 3.58 4.43 43.89 0.8988 3.79 4.65 43.87 0.9018 3.81 4.66 HiNet[3] 50.79 0.9926 1.46 2.06 45.98 0.9806 2.43 3.56 46.00 0.9853 2.49 3.55 DeepMIH[10] 43.73 0.9873 2.21 3.14 43.13 0.9721 2.83 3.91 43.29 0.9621 2.74 4.21 DAH-Net[29] 49.39 0.9896 1.72 2.79 46.15 0.9856 2.96 3.84 45.75 0.9857 2.98 3.78 StegFormer[30] 56.30 0.9956 0.73 1.23 48.77 0.9884 1.41 2.48 48.79 0.9859 1.51 2.50 CamStegNet[32] 38.36 0.9798 / 3.26 40.05 0.9776 / 2.70 39.49 0.9774 / 2.88 Ours 58.07 0.9972 0.64 1.07 49.42 0.9911 1.03 2.35 48.96 0.9894 1.43 2.41 方法 秘密/恢复秘密图像对 DIV2K ( 1024 ×1024 )COCO (256 × 256) Imagenet (256 × 256) PSNR SSIM MAE RMSE PSNR SSIM MAE RMSE PSNR SSIM MAE RMSE HiDDeN[7] 39.24 0.9502 3.54 5.29 36.29 0.9235 5.32 8.01 36.02 0.9132 5.02 7.32 UDH[31] 42.02 0.9781 2.15 3.23 34.75 0.9175 4.82 7.79 34.62 0.9034 5.29 8.22 HiNet[3] 52.32 0.9936 0.88 1.28 47.06 0.9796 1.82 2.78 47.07 0.9764 1.95 2.86 DeepMIH[10] 47.92 0.9892 1.76 2.54 45.31 0.9698 2.83 3.53 45.83 0.9889 2.79 3.54 DAH-Net[29] 50.72 0.9896 1.54 1.98 47.46 0.9726 1.54 2.17 47.35 0.9834 2.07 2.95 StegFormer[30] 55.45 0.9964 0.73 1.08 49.21 0.9882 1.48 2.33 49.18 0.9851 1.62 2.41 CamStegNet[32] 31.94 0.9314 / 6.70 32.47 0.9273 / 6.30 31.95 0.9192 / 6.96 Ours 60.10 0.9964 0.72 0.97 53.43 0.9929 1.11 2.04 50.10 0.9907 1.51 2.17 注:’/’表示该对应指标未在原始出版物中报告,且该方法的源代码尚未公开发布。 表 2 不同分解方法的实验结果
分解方式 载体/载密图像对 秘密/恢复秘密图像对 PSNR(dB) SSIM MAE RMSE PSNR(dB) SSIM MAE RMSE DWT 50.03 0.9846 1.64 2.77 54.53 0.9914 0.96 0.97 IBEMD 58.07 0.9972 0.64 1.07 60.10 0.9964 0.72 0.97 表 3 IBEMD、IMFB和GFNN的消融实验结果
IBEMD IMFB GFNN 载体/载密图像对 秘密/恢复秘密图像对 PSNR(dB) SSIM MAE RMSE PSNR(dB) SSIM MAE RMSE × × × 30.83 0.9803 4.08 9.89 38.33 0.9814 2.29 2.19 × √ × 53.24 0.9930 0.90 1.55 52.17 0.9927 0.96 1.67 × × √ 51.50 0.9926 0.94 1.78 52.91 0.9931 0.99 1.88 × √ √ 54.31 0.9938 1.13 1.53 53.31 0.9949 0.84 1.20 √ × × 52.46 0.9914 0.91 1.48 51.28 0.9937 0.91 1.80 √ √ × 54.19 0.9937 0.81 1.23 56.78 0.9956 0.89 1.20 √ × √ 54.27 0.9942 0.79 1.37 56.34 0.9951 0.90 1.31 √ √ √ 58.07 0.9972 0.64 1.07 60.10 0.9964 0.72 0.97 表 4 膨胀卷积的消融实验结果
扩展分支 载体/载密图像对 秘密/恢复秘密图像对 PSNR(dB) SSIM MAE RMSE PSNR(dB) SSIM MAE RMSE × 52.96 0.9943 0.97 1.57 54.98 0.9950 0.90 1.57 √ 58.07 0.9972 0.64 1.07 60.10 0.9964 0.72 0.97 表 5 不同域的使用的实验结果
空域 频域 载体/载密图像对 秘密/恢复秘密图像对 PSNR(dB) SSIM MAE RMSE PSNR(dB) SSIM MAE RMSE × √ 51.78 0.9927 0.99 1.54 53.36 0.9929 1.12 2.01 √ × 52.43 0.9951 0.86 1.44 56.16 0.9950 0.88 1.53 √ √ 58.07 0.9972 0.64 1.07 60.10 0.9964 0.72 0.97 表 6 基于XuNet、ZhuNet、SiaStegNet和StegExpose的八种隐写方案的检测准确率
方法 XuNet
(%)ZhuNet
(%)SiaStegNet
(%)StegExpose
(%)Baluja[2] 72.21 87.32 77.34 / UDH[31] 75.61 78.37 76.38 / StegoPNet[33] 70.76 71.93 68.95 / HiNet[3] 59.64 56.45 53.45 / StegFormer[30] 58.96 55.54 55.49 / Ma[34] 51.80 59.70 / / CamStegNet[32] / / / 55.00 Ours 49.35 49.85 49.80 49.65 注:精度越接近50%,性能越好 -
[1] ZENG Kai, CHEN Kejiang, ZHANG Weiming, et al. Robust steganography for high quality images[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2023, 33(9): 4893–4906. doi: 10.1109/TCSVT.2023.3250750. [2] BALUJA S. Hiding images within images[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2020, 42(7): 1685–1697. doi: 10.1109/TPAMI.2019.2901877. [3] JING Junpeng, DENG Xin, XU Mai, et al. HiNet: Deep image hiding by invertible network[C]. Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), Montreal, Canada, 2021: 4713–4722. doi: 10.1109/ICCV48922.2021.00469. [4] ZHANG Jiansong, CHEN Kejiang, LI Weixiang, et al. Steganography with generated images: Leveraging volatility to enhance security[J]. IEEE Transactions on Dependable and Secure Computing, 2024, 21(4): 3994–4005. doi: 10.1109/TDSC.2023.3341427. [5] LUO Ting, ZHOU Yuhang, HE Zhouyan, et al. StegMamba: Distortion-free immune-cover for multi-image steganography with state space model[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2025, 35(5): 4576–4591. doi: 10.1109/TCSVT.2024.3515652. [6] ZHANG Le, LU Yao, LI Tong, et al. Joint adaptive robust steganography network[J]. IEEE Transactions on Industrial Informatics, 2024, 20(8): 10156–10166. doi: 10.1109/TII.2024.3388674. [7] ZHU Jiren, KAPLAN R, JOHNSON J, et al. HiDDeN: Hiding data with deep networks[C]. Proceedings of the 15th European Conference on Computer Vision (ECCV), Munich, Germany, 2018: 682–697. doi: 10.1007/978-3-030-01267-0_40. [8] CHEN Huajie, ZHU Tianqing, ZHAO Yuan, et al. Low-frequency image deep steganography: Manipulate the frequency distribution to hide secrets with tenacious robustness[EB/OL]. https://arxiv.org/abs/2303.13713, 2023. [9] 刘媛妮, 范飞, 赵宇洋, 等. 基于图像多重隐写的区块链隐蔽通信方案[J]. 电子与信息学报, 2025, 47(4): 1126–1139. doi: 10.11999/JEIT240798.LIU Yuanni, FAN Fei, ZHAO Yuyang, et al. A convert communication scheme of blockchain based on image multilevel steganography embedding[J]. Journal of Electronics & Information Technology, 2025, 47(4): 1126–1139. doi: 10.11999/JEIT240798. [10] GUAN Zhenyu, JING Junpeng, DENG Xin, et al. DeepMIH: Deep invertible network for multiple image hiding[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2023, 45(1): 372–390. doi: 10.1109/TPAMI.2022.3141725. [11] XU Zihao, XU Dawei, LI Zihan, et al. MDDM: Practical message-driven generative image steganography based on diffusion models[C]. Proceedings of the 42nd International Conference on Machine Learning, Vancouver, Canada, 2025: 69832–69848. [12] QI Yu’ang, CHEN Kejiang, ZHAO Na, et al. Provably secure robust image steganography via cross-modal error correction[C]. Proceedings of the 39th AAAI Conference on Artificial Intelligence, Philadelphia, USA, 2025: 26354–26362. doi: 10.1609/aaai.v39i25.34834. [13] YE Huayuan, ZHANG Shenzhuo, JIANG Shiqi, et al. Robust message embedding via attention flow-based steganography[C]. IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Nashville, USA, 2025: 12840–12849. doi: 10.1109/CVPR52734.2025.01198. [14] TANG Weixuan, YANG Haoyu, RAO Yuan, et al. Dig a hole and fill in sand: Adversary and hiding decoupled steganography[C]. Proceedings of the 32nd ACM International Conference on Multimedia, Melbourne, Australia, 2024: 10440–10448. doi: 10.1145/3664647.3681330. [15] LI Guobiao, LI Sheng, LUO Zicong, et al. Purified and unified steganographic network[C]. Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, USA, 2024: 27559–27568. doi: 10.1109/CVPR52733.2024.02603. [16] LI Xiao, CHEN Liquan, FU Tong, et al. Coverless image steganography based on semantic-controlled text-to-image generation[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2025, 35(8): 8391–8405. doi: 10.1109/TCSVT.2025.3545067. [17] LI Xiang, LI Xiaolong, HU Shaohai, et al. Steganography-enhanced prediction-error expansion: A novel reversible data hiding framework[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2025, 35(3): 2701–2711. doi: 10.1109/TCSVT.2024.3495673. [18] SU Wenkang, NI Jiangqun, and SUN Yiyan. StegaStyleGAN: Towards generic and practical generative image steganography[C]. Proceedings of the 38th AAAI Conference on Artificial Intelligence, Vancouver, Canada, 2024: 240–248. doi: 10.1609/aaai.v38i1.27776. [19] BOEHM B. StegExpose-A tool for detecting LSB steganography[EB/OL]. https://arxiv.org/abs/1410.6656v1, 2014. [20] XU Guanshuo, WU Hanzhou, and SHI Yunqing. Structural design of convolutional neural networks for steganalysis[J]. IEEE Signal Processing Letters, 2016, 23(5): 708–712. doi: 10.1109/LSP.2016.2548421. [21] YOU Weike, ZHANG Hong, and ZHAO Xianfeng. A Siamese CNN for image steganalysis[J]. IEEE Transactions on Information Forensics and Security, 2021, 16: 291–306. doi: 10.1109/TIFS.2020.3013204. [22] ZHANG Ru, ZHU Feng, LIU Jianyi, et al. Depth-wise separable convolutions and multi-level pooling for an efficient spatial CNN-based steganalysis[J]. IEEE Transactions on Information Forensics and Security, 2020, 15: 1138–1150. doi: 10.1109/TIFS.2019.2936913. [23] HUANG N E, SHEN Zheng, LONG S R, et al. The empirical mode decomposition and the Hilbert spectrum for nonlinear and non-stationary time series analysis[J]. Proceedings of the Royal Society of London. Series A: Mathematical, Physical and Engineering Sciences, 1998, 454(1971): 903–995. doi: 10.1098/rspa.1998.0193. [24] WU Zhaohua and HUANG N E. Ensemble empirical mode decomposition: A noise-assisted data analysis method[J]. Advances in Adaptive Data Analysis, 2009, 1(1): 1–41. doi: 10.1142/S1793536909000047. [25] NUNES J C, BOUAOUNE Y, DELECHELLE E, et al. Image analysis by bidimensional empirical mode decomposition[J]. Image and Vision Computing, 2003, 21(12): 1019–1026. doi: 10.1016/S0262-8856(03)00094-5. [26] TIMOFTE R, AGUSTSSON E, VAN GOOL L, et al. NTIRE 2017 challenge on single image super-resolution: Methods and results[C]. 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), Honolulu, USA, 2017: 1110–1121. doi: 10.1109/CVPRW.2017.149. [27] RUSSAKOVSKY O, DENG Jia, SU Hao, et al. ImageNet large scale visual recognition challenge[J]. International Journal of Computer Vision, 2015, 115(3): 211–252. doi: 10.1007/s11263-015-0816-y. [28] LIN T Y, MAIRE M, BELONGIE S, et al. Microsoft COCO: Common objects in context[C]. Proceedings of the 13th European Conference on Computer Vision (ECCV), Zurich, Switzerland, 2014: 740–755. doi: 10.1007/978-3-319-10602-1_48. [29] ZHANG Le, LU Yao, LI Jinxing, et al. Deep adaptive hiding network for image hiding using attentive frequency extraction and gradual depth extraction[J]. Neural Computing and Applications, 2023, 35(15): 10909–10927. doi: 10.1007/s00521-023-08274-w. [30] KE Xiao, WU Huanqi, and GUO Wenzhong. StegFormer: Rebuilding the glory of autoencoder-based steganography[C]. Proceedings of the 38th AAAI Conference on Artificial Intelligence, Vancouver, Canada, 2024: 2723–2731. doi: 10.1609/aaai.v38i3.28051. [31] ZHANG Chaoning, BENZ P, KARJAUV A, et al. UDH: Universal deep hiding for steganography, watermarking, and light field messaging[C]. Proceedings of the 34th International Conference on Neural Information Processing Systems, Vancouver, Canada, 2020: 857. [32] MAO Le, TAN Yun, QIN Jiaohua, et al. CamStegNet: A robust image steganography method based on camouflage model[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2025, 35(10): 10599–10611. doi: 10.1109/TCSVT.2025.3570725. [33] DUAN Xintao, WANG Wenxin, LIU Nao, et al. StegoPNet: Image steganography with generalization ability based on pyramid pooling module[J]. IEEE Access, 2020, 8: 195253–195262. doi: 10.1109/ACCESS.2020.3033895. [34] MA Bin, WANG Haocheng, XU Jian, et al. Color image high-capacity differential steganography algorithm based on multiple adversarial networks[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2025, 35(4): 3907–3920. doi: 10.1109/TCSVT.2024.3508849. -
下载: