{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T08:59:48Z","timestamp":1765357188189,"version":"build-2065373602"},"reference-count":43,"publisher":"MDPI AG","issue":"17","license":[{"start":{"date-parts":[[2022,8,29]],"date-time":"2022-08-29T00:00:00Z","timestamp":1661731200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"],"award-info":[{"award-number":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Defense Industrial Technology Development Program","award":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"],"award-info":[{"award-number":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"]}]},{"name":"Key Research and Development Program","award":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"],"award-info":[{"award-number":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"]}]},{"name":"Sichuan Provincial Science and Technology Department Project","award":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"],"award-info":[{"award-number":["62102379","61902262","JCKY2019602B013","2019QY0706","2020YFG0461"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Internet has become the main channel of information communication, which contains a large amount of secret information. Although network communication provides a convenient channel for human communication, there is also a risk of information leakage. Traditional image steganography algorithms use manually crafted steganographic algorithms or custom models for steganography, while our approach uses ordinary OCR models for information embedding and extraction. Even if our OCR models for steganography are intercepted, it is difficult to find their relevance to steganography. We propose a novel steganography method for character-level text images based on adversarial attacks. We exploit the complexity and uniqueness of neural network boundaries and use neural networks as a tool for information embedding and extraction. We use an adversarial attack to embed the steganographic information into the character region of the image. To avoid detection by other OCR models, we optimize the generation of the adversarial samples and use a verification model to filter the generated steganographic images, which, in turn, ensures that the embedded information can only be recognized by our local model. The decoupling experiments show that the strategies we adopt to weaken the transferability can reduce the possibility of other OCR models recognizing the embedded information while ensuring the success rate of information embedding. Meanwhile, the perturbations we add to embed the information are acceptable. Finally, we explored the impact of different parameters on the algorithm with the potential of our steganography algorithm through parameter selection experiments. We also verify the effectiveness of our validation model to select the best steganographic images. The experiments show that our algorithm can achieve a 100% information embedding rate and more than 95% steganography success rate under the set condition of 3 samples per group. In addition, our embedded information can be hardly detected by other OCR models.<\/jats:p>","DOI":"10.3390\/s22176497","type":"journal-article","created":{"date-parts":[[2022,8,30]],"date-time":"2022-08-30T01:37:55Z","timestamp":1661823475000},"page":"6497","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["A Novel Steganography Method for Character-Level Text Image Based on Adversarial Attacks"],"prefix":"10.3390","volume":"22","author":[{"given":"Kangyi","family":"Ding","sequence":"first","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"},{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8624-0210","authenticated-orcid":false,"given":"Teng","family":"Hu","sequence":"additional","affiliation":[{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3235-3463","authenticated-orcid":false,"given":"Weina","family":"Niu","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8510-4025","authenticated-orcid":false,"given":"Xiaolei","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junpeng","family":"He","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingyong","family":"Yin","sequence":"additional","affiliation":[{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaosong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,8,29]]},"reference":[{"key":"ref_1","unstructured":"Upham, D. (2016, January 06). Jpeg-Jsteg-V4. Available online: http:\/\/www.funet.fi\/pub\/crypt\/steganography\/jpeg-jsteg-v4.diff.gz."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Sharp, T. (2001). An implementation of key-based digital signal steganography. International Workshop on Information Hiding, Springer.","DOI":"10.1007\/3-540-45496-9_2"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1109\/LSP.2006.870357","article-title":"LSB matching revisited","volume":"13","author":"Mielikainen","year":"2006","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_4","unstructured":"Kim, Y., Duric, Z., and Richards, D. (2006). Modified matrix encoding technique for minimal distortion steganography. International Workshop on Information Hiding, Springer."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Nguyen, B.C., Yoon, S.M., and Lee, H.K. (2006). Multi bit plane image steganography. International Workshop on Digital Watermarking, Springer.","DOI":"10.1007\/11922841_6"},{"key":"ref_6","first-page":"38","article-title":"Minimizing embedding impact in steganography using trellis-coded quantization","volume":"Volume 7541","author":"Filler","year":"2010","journal-title":"Media Forensics and Security II"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"920","DOI":"10.1109\/TIFS.2011.2134094","article-title":"Minimizing additive distortion in steganography using syndrome-trellis codes","volume":"6","author":"Filler","year":"2011","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/1687-417X-2014-1","article-title":"Universal distortion function for steganography in an arbitrary domain","volume":"2014","author":"Holub","year":"2014","journal-title":"EURASIP J. Inf. Secur."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"814","DOI":"10.1109\/TIFS.2014.2312817","article-title":"Uniform embedding for efficient JPEG steganography","volume":"9","author":"Guo","year":"2014","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_10","unstructured":"Volkhonskiy, D., Borisenko, B., and Burnaev, E. (2016, January 24\u201326). Generative adversarial networks for image steganography. Proceedings of the ICLR 2017, Toulon, France."},{"key":"ref_11","unstructured":"Shi, H., Dong, J., Wang, W., Qian, Y., and Zhang, X. (2017). SSGAN: Secure steganography based on generative adversarial networks. Pacific Rim Conference on Multimedia, Springer."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"8559","DOI":"10.1007\/s11042-018-6951-z","article-title":"Invisible steganography via generative adversarial networks","volume":"78","author":"Zhang","year":"2019","journal-title":"Multimed. Tools Appl."},{"key":"ref_13","unstructured":"Rahim, R., Nadeem, S., and ul Hussain, S. (2018, January 8\u201314). End-to-end trained CNN encoder-decoder networks for image steganography. Proceedings of the European Conference on Computer Vision (ECCV) Workshops, Munich, Germany."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"38303","DOI":"10.1109\/ACCESS.2018.2852771","article-title":"A novel image steganography method via deep convolutional generative adversarial networks","volume":"6","author":"Hu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Zhang, W., Chen, K., Liu, J., Liu, Y., and Yu, N. (2018, January 20\u201322). Adversarial examples against deep neural network based steganalysis. Proceedings of the 6th ACM Workshop on Information Hiding and Multimedia Security, Innsbruck, Austria.","DOI":"10.1145\/3206004.3206012"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2074","DOI":"10.1109\/TIFS.2019.2891237","article-title":"CNN-based adversarial embedding for image steganography","volume":"14","author":"Tang","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_17","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J. (2018, January 18\u201322). Boosting adversarial attacks with momentum. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"107102","DOI":"10.1016\/j.knosys.2021.107102","article-title":"A low-query black-box adversarial attack based on transferability","volume":"226","author":"Ding","year":"2021","journal-title":"Knowl.-Based Syst."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Liu, X., Du, X., Zhang, X., Zhu, Q., Wang, H., and Guizani, M. (2019). Adversarial samples on android malware detection systems for IoT systems. Sensors, 19.","DOI":"10.3390\/s19040974"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Liu, X., Wan, K., Ding, Y., Zhang, X., and Zhu, Q. (2020, January 7\u201312). Weighted-sampling audio adversarial example attack. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.","DOI":"10.1609\/aaai.v34i04.5928"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Niu, W., Luo, Y., Ding, K., Zhang, X., Wang, Y., and Li, B. (2021). A Novel Generation Method for Diverse Privacy Image Based on Machine Learning. Comput. J., bxab176.","DOI":"10.1093\/comjnl\/bxab176"},{"key":"ref_25","unstructured":"Song, C., and Shmatikov, V. (2018). Fooling OCR systems with adversarial text images. arXiv."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Chen, L., Sun, J., and Xu, W. (2020). FAWA: Fast adversarial watermark attack on optical character recognition (OCR) systems. Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Springer.","DOI":"10.1007\/978-3-030-67664-3_33"},{"key":"ref_27","unstructured":"Liu, Y., Chen, X., Liu, C., and Song, D. (2016). Delving into transferable adversarial examples and black-box attacks. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Dong, Y., Pang, T., Su, H., and Zhu, J. (2019, January 16\u201317). Evading defenses to transferable adversarial examples by translation-invariant attacks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Gao, L., Zhang, Q., Song, J., Liu, X., and Shen, H.T. (2020). Patch-wise attack for fooling deep neural network. European Conference on Computer Vision, Springer.","DOI":"10.1007\/978-3-030-58604-1_19"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Wang, X., and He, K. (2021, January 29\u201325). Enhancing the transferability of adversarial attacks through variance tuning. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref_31","first-page":"1384","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1547","DOI":"10.1109\/LSP.2017.2745572","article-title":"Automatic steganographic distortion learning using a generative adversarial network","volume":"24","author":"Tang","year":"2017","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_33","unstructured":"Yang, J., Liu, K., Kang, X., Wong, E.K., and Shi, Y.Q. (2018). Spatial image steganography based on generative adversarial network. arXiv."},{"key":"ref_34","unstructured":"Zhang, K.A., Cuesta-Infante, A., Xu, L., and Veeramachaneni, K. (2019). SteganoGAN: High capacity image steganography with GANs. arXiv."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Liu, J., Zhou, T., Zhang, Z., Ke, Y., Lei, Y., and Zhang, M. (2018, January 8\u201310). Digital cardan grille: A modern approach for information hiding. Proceedings of the 2018 2nd International Conference on Computer Science and Artificial Intelligence, Shanghai, China.","DOI":"10.1145\/3297156.3297255"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"90815","DOI":"10.1109\/ACCESS.2019.2913895","article-title":"Image steganography based on foreground object generation by generative adversarial networks in mobile edge computing with Internet of Things","volume":"7","author":"Cui","year":"2019","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"2298","DOI":"10.1109\/TPAMI.2016.2646371","article-title":"An end-to-end trainable neural network for image-based sequence recognition and its application to scene text recognition","volume":"39","author":"Shi","year":"2016","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Graves, A., Fern\u00e1ndez, S., Gomez, F., and Schmidhuber, J. (2006, January 25\u201329). Connectionist temporal classification: Labelling unsegmented sequence data with recurrent neural networks. Proceedings of the 23rd International Conference on Machine Learning, Pittsburgh, PA, USA.","DOI":"10.1145\/1143844.1143891"},{"key":"ref_39","unstructured":"Wang, X., Ren, J., Lin, S., Zhu, X., Wang, Y., and Zhang, Q. (2020). A unified approach to interpreting and boosting adversarial transferability. arXiv."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Gupta, A., Vedaldi, A., and Zisserman, A. (2016, January 27\u201330). Synthetic data for text localisation in natural images. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.254"},{"key":"ref_41","unstructured":"Fu, Y. (1988). Development of Modern Chinese Commonly Used Character List\u2014Appendix: Commonly Used Characters, Subcommonly Used Characters. Language Development, Merrill."},{"key":"ref_42","unstructured":"Huang, Z., Xu, W., and Yu, K. (2015). Bidirectional LSTM-CRF models for sequence tagging. arXiv."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"1181","DOI":"10.1109\/TIFS.2018.2871749","article-title":"Deep residual network for steganalysis of digital images","volume":"14","author":"Boroumand","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/17\/6497\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:19:43Z","timestamp":1760141983000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/17\/6497"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,29]]},"references-count":43,"journal-issue":{"issue":"17","published-online":{"date-parts":[[2022,9]]}},"alternative-id":["s22176497"],"URL":"https:\/\/doi.org\/10.3390\/s22176497","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2022,8,29]]}}}