STAD: Transferable Active Defense against Generative Image Steganography via Structural Feature Perturbations
Abstract
Generative image steganography (GIS) directly generates stego images from secret information, making conventional passive defense methods that rely on detecting modification traces difficult to apply. Most existing active defense methods disrupt covert communication through image degradation followed by reconstruction. However, these approaches are ineffective against GIS, where the carrier image is generated directly rather than modified to embed secret information. We propose Structure-guided Transferable Active Defense (STAD), which perturbs stego images using a single frozen encoder. Neither the hidden message nor the target decoder is required. STAD optimizes differences between neighboring features at several encoder layers, avoiding a loss tied to a specific message representation. It combines gradients from nearby images with edge weighting and multiscale smoothing, then constrains distortion in the quantized output. Tests on five SOTA GIS methods give the lowest bit extraction accuracy among the evaluated defenses and an average 8-bit message accuracy of 17.06%. The surrogate and optimization settings remain fixed across targets, and output PSNR stays at or above 30 dB. Experimental results demonstrate that the proposed STAD effectively defends against GIS methods while maintaining high visual quality.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.