Steganalysis of neural networks based on parameter statistical bias |
| |
Authors: | Yi Yin Weiming Zhang Nenghai Yu Kejiang Chen |
| |
Institution: | School of Cyber Science and Technology, University of Science and Technology of China, Hefei 230029, China |
| |
Abstract: | Many pretrained deep learning models have been released to help engineers and researchers develop deep learning-based systems or conduct research with minimall effort. Previous work has shown that at secret message can be embedded in neural network parameters without compromising the accuracy of the model. Malicious developers can, therefore, hide malware or other baneful information in pretrained models, causing harm to society. Hence, reliable detection of these vicious pretrained models is urgently needed. We analyze existing approaches for hiding messages and find that they will ineluctably cause biases in the parameter statistics. Therefore, we propose steganalysis methods for steganography on neural network parameters that extract statistics from benign and malicious models and build classifiers based on the extracted statistics. To the best of our knowledge, this is the first study on neural network steganalysis. The experimental results reveal that our proposed algorithm can effectively detect a model with an embedded message. Notably, our detection methods are still valid in cases where the payload of the stego model is low. |
| |
Keywords: | neural network steganography steganalysis |
|
| 点击此处可从《中国科学技术大学学报》浏览原始摘要信息 |
| 点击此处可从《中国科学技术大学学报》下载免费的PDF全文 |