<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">55735</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2024.055735</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Digital Image Steganographer Identification: A Comprehensive Survey</article-title>
<alt-title alt-title-type="left-running-head">Digital Image Steganographer Identification: A Comprehensive Survey</alt-title>
<alt-title alt-title-type="right-running-head">Digital Image Steganographer Identification: A Comprehensive Survey</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Zhang</surname><given-names>Qianqian</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Zhang</surname><given-names>Yi</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Ma</surname><given-names>Yuanyuan</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Liu</surname><given-names>Yanmei</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-5" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Luo</surname><given-names>Xiangyang</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><xref ref-type="aff" rid="aff-2">2</xref><email>luoxy_ieu@sina.com</email></contrib>
<aff id="aff-1"><label>1</label><institution>Information Engineering University</institution>, <addr-line>Zhengzhou, 450001</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Key Laboratory of Cyberspace Situation Awareness of Henan Province</institution>, <addr-line>Zhengzhou, 450001</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>College of Computer and Information Engineering, Henan Normal University</institution>, <addr-line>Xinxiang, 453007</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Xiangyang Luo. Email: <email>luoxy_ieu@sina.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2024</year></pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>15</day>
<month>10</month>
<year>2024</year></pub-date>
<volume>81</volume>
<issue>1</issue>
<fpage>105</fpage>
<lpage>131</lpage>
<history>
<date date-type="received">
<day>05</day>
<month>7</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>05</day>
<month>9</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024 The Authors.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_55735.pdf"></self-uri>
<abstract>
<p>The rapid development of the internet and digital media has provided convenience while also posing a potential risk of steganography abuse. Identifying steganographer is essential in tracing secret information origins and preventing illicit covert communication online. Accurately discerning a steganographer from many normal users is challenging due to various factors, such as the complexity in obtaining the steganography algorithm, extracting highly separability features, and modeling the cover data. After extensive exploration, several methods have been proposed for steganographer identification. This paper presents a survey of existing studies. Firstly, we provide a concise introduction to the research background and outline the issue of steganographer identification. Secondly, we present fundamental concepts and techniques that establish a general framework for identifying steganographers. Within this framework, state-of-the-art methods are summarized from five key aspects: data acquisition, feature extraction, feature optimization, identification paradigm, and performance evaluation. Furthermore, theoretical and experimental analyses examine the advantages and limitations of these existing methods. Finally, the survey highlights outstanding issues in image steganographer identification that deserve further research.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Information hiding</kwd>
<kwd>steganalysis</kwd>
<kwd>steganographer identification</kwd>
<kwd>steganography</kwd>
<kwd>covert communication</kwd>
<kwd>survey</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Key Research and Development Program of China</funding-source>
<award-id>2022YFB3102900</award-id>
</award-group>
<award-group id="awg2">
<funding-source>National Natural Science Foundation of China</funding-source>
<award-id>62172435</award-id>
<award-id>62202495</award-id>
<award-id>62002103</award-id>
</award-group>
<award-group id="awg3">
<funding-source>Zhongyuan Science and Technology Innovation Leading Talent Project of China</funding-source>
<award-id>214200510019</award-id>
</award-group>
<award-group id="awg4">
<funding-source>Key Research and Development Project of Henan Province</funding-source>
<award-id>2211321200</award-id>
</award-group>
<award-group id="awg5">
<funding-source>Natural Science Foundation of Henan Province</funding-source>
<award-id>222300420058</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Steganography is the techniques of hiding secret information within various forms of digital media, such as images [<xref ref-type="bibr" rid="ref-1">1</xref>], audio [<xref ref-type="bibr" rid="ref-2">2</xref>], video [<xref ref-type="bibr" rid="ref-3">3</xref>], and text files [<xref ref-type="bibr" rid="ref-4">4</xref>], with the aim of achieving covert communication. Although it contributes to secure communications [<xref ref-type="bibr" rid="ref-5">5</xref>], there is still a risk that steganography can be illegal abuse [<xref ref-type="bibr" rid="ref-6">6</xref>&#x2013;<xref ref-type="bibr" rid="ref-8">8</xref>]. For example, in July 2019, a study by the cybersecurity company, Security Bull, found that nearly 8% of office workers in the UK had used online tools such as steganography or encryption to steal company information. In January 2016, the Russian antivirus company, Doctor Web, revealed that more than 60 games on Google Play could download and execute malicious code concealed within images, which allowed them to stealing user information. The illegal abuse of steganography poses a serious threat to the cyberspace security.</p>
<p>The art of steganalysis is an effective way to antagonize steganography. It detects steganography [<xref ref-type="bibr" rid="ref-9">9</xref>&#x2013;<xref ref-type="bibr" rid="ref-11">11</xref>], disrupts secret communication [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>], and extracts secret information [<xref ref-type="bibr" rid="ref-14">14</xref>]. In practice, steganalysis is considerably more challenging than steganography [<xref ref-type="bibr" rid="ref-15">15</xref>]. This is primarily due to the abundance of digital covers and the wide range of embedding methods that can be utilized in steganography, making the detection of secret information within this vast sea of digital media akin to locating a needle in a haystack. Especially with the rapid development of deep learning [<xref ref-type="bibr" rid="ref-16">16</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>], steganography is constantly evolving [<xref ref-type="bibr" rid="ref-19">19</xref>&#x2013;<xref ref-type="bibr" rid="ref-21">21</xref>], yet corresponding steganalysis methods are noticeably lagging behind. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> presents insights into the number of publications about steganography and steganalysis over the last nine years that have been surveyed. As can be seen in the figure, the number of research publications about steganography has been increasing since 2018, while the number of steganalysis has been decreasing. Furthermore, the ratio of steganography to steganalysis still has an elevated trend. Therefore, the development of steganalysis technology plays a vital role in reducing the harm caused by the abuse of illegal steganography and ensuring the security of the state, society and individuals.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Trend of the number of publications on steganography and steganalysis in the late nine years</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-1.tif"/>
</fig>
<p>The existing digital image steganalysis includes passive steganalysis [<xref ref-type="bibr" rid="ref-22">22</xref>], such as secret information detection [<xref ref-type="bibr" rid="ref-23">23</xref>], secret information extraction [<xref ref-type="bibr" rid="ref-24">24</xref>] and steganographer identification [<xref ref-type="bibr" rid="ref-25">25</xref>], and active steganalysis [<xref ref-type="bibr" rid="ref-26">26</xref>], such as secret information destroy [<xref ref-type="bibr" rid="ref-27">27</xref>,<xref ref-type="bibr" rid="ref-28">28</xref>]. Most of the existing research on steganalysis focuses on secret information detection. Its research methods include traditional supervised machine learning methods [<xref ref-type="bibr" rid="ref-29">29</xref>&#x2013;<xref ref-type="bibr" rid="ref-31">31</xref>] and deep learning methods such as XuNet [<xref ref-type="bibr" rid="ref-32">32</xref>], YeNet [<xref ref-type="bibr" rid="ref-33">33</xref>], and SRNet [<xref ref-type="bibr" rid="ref-34">34</xref>]. The development of steganalysis can provide reliable support for locating and extracting secret information. However, these methods only give a probabilistic decision on whether an image is a stego, making it difficult to accurately identify and track covert communication behaviors or activities.</p>
<p>In contrast, steganographer identification [<xref ref-type="bibr" rid="ref-35">35</xref>] is an effective passive steganalysis technique that to identify suspected image steganographers and discover illegal covert communication activities [<xref ref-type="bibr" rid="ref-35">35</xref>]. The problem was first posed in 2006. In 2013, Ker et al. [<xref ref-type="bibr" rid="ref-36">36</xref>] listed this problem as one of the &#x201C;moving steganography and steganalysis from the laboratory into the real world&#x201D;. In practice, steganographer identification technology can detect secret images and discover covert communication source. However, it is still in its early stages. While existing methods for detecting secret information in classical steganography have matured, research methods in this area provide limited references for steganographer identification. On one hand, it is often challenging to obtain information about the specific steganography techniques and payloads used by individuals since each user may employ different image acquisition devices and processing methods. This poses a significant challenge in terms of matching training and testing sets [<xref ref-type="bibr" rid="ref-37">37</xref>]. On the other hand, steganographers may also include cover images along with stego images to deceive steganalysis. In such cases, if information cannot be extracted from a single image alone, the detection result may not provide valuable insights. Therefore, there is an imperative need to develop robust methods for identifying steganographers in complex application scenarios.</p>
<p>With the development of steganalysis technology in the past decade, several surveys have been published [<xref ref-type="bibr" rid="ref-38">38</xref>,<xref ref-type="bibr" rid="ref-39">39</xref>]. For example, Ruan et al. [<xref ref-type="bibr" rid="ref-40">40</xref>] covered the application of deep learning to steganalysis. In 2022, Muralidharan et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] published the survey research &#x201C;Infinite Competition between Image Steganography and Steganalysis&#x201D;, which considered the interdependencies between steganography and steganalysis from new observations and insights. However, these still focus on steganalysis to detect secret information in images. Although these surveys provide references for steganographer identification, we must systematically sort out existing methods and point out problems in existing research and possible future research. Therefore, this manuscript describes the research in this field, which has served to steganalysis development. By summarizing the steganographer identification methods, the paper helps readers better analyze the current research progress in the field and better understand the current shortcomings and future research direction. The contributions of this paper can be highlighted as:
<list list-type="order">
<list-item>
<p>We conduct a comprehensive survey on digital image steganographer identification. Our study aims to systematically review, classify, and compare the performance of the existing methods for steganographer identification.</p></list-item>
<list-item>
<p>We present a general framework that summarizes the methods proposed in previous literature and evaluate their advantages and limitations based on performance comparisons using reported experimental results from the same datasets.</p></list-item>
<list-item>
<p>We review studies on various aspects of steganographer identification including data acquisition, feature optimization, identification paradigm, and performance evaluation. Furthermore, we discuss research problems that require further investigation based on our analysis.</p></list-item>
</list></p>
<p>The rest of this paper is organized as follows. <xref ref-type="sec" rid="s2">Section 2</xref> presents several primary concepts and techniques for steganographer identification. <xref ref-type="sec" rid="s3">Section 3</xref> proposes a general framework for steganographer identification and details the main steps. <xref ref-type="sec" rid="s4">Section 4</xref> compares the performance of the typical methods theoretically and experimentally. <xref ref-type="sec" rid="s5">Section 5</xref> discusses the critical research challenges that may need further attention based on the limitations of existing methods, and the last section concludes our work.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Primary Concepts and Techniques</title>
<sec id="s2_1">
<label>2.1</label>
<title>Batch Steganography and Pooled Steganalysis</title>
<p>The classic definition of steganography involves a steganographer aiming to communicate with a passive conspirator over an insecure channel, and an eavesdropper (or Warden) monitoring the channel. The Warden&#x2019;s aim is not to decode the hidden information but merely to deduce its presence. This is steganalysis for the single cover object, i.e., it assumes that each cover object is treated in isolation by both the steganographer and the eavesdropper. However, in practical applications involving considerably large payload, the steganographer should adopt a batch strategy to allocate payload to multiple covers properly.</p>
<p>Batch steganography aims to embed a large number of messages into multiple cover objects while maintaining a satisfactory level of undetectability. Reference [<xref ref-type="bibr" rid="ref-42">42</xref>] posed precisely the problem of batch steganography. In [<xref ref-type="bibr" rid="ref-43">43</xref>], batch schemes for content-adaptive steganography were first mathematically formulated. In specific, when allocating <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>P</mml:mi></mml:math></inline-formula> bits payload on a series of images <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>B</mml:mi><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula>, the steganographer tries to find an optimal payload-allocation which can minimize the total detectability:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:munder><mml:mrow><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>g</mml:mi><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow></mml:munder><mml:munderover><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>B</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>s</mml:mi><mml:mo>.</mml:mo><mml:mi>t</mml:mi><mml:mo>.</mml:mo><mml:mspace width="1em" /><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:munderover><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>b</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>B</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msup><mml:mi>R</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> denotes the desired payload length allocated to <italic>b</italic>-th cover image <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula>, and <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>b</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the expectation of steganalyzer&#x2019;s detection output for <italic>b</italic>-th stego image.</p>
<p>Pooled steganalysis, i.e., steganographer identification is a confrontation of batch steganography [<xref ref-type="bibr" rid="ref-44">44</xref>]. In batch steganography, the Warden&#x2019;s task is pooled steganalysis. Reference [<xref ref-type="bibr" rid="ref-43">43</xref>] formulated pooled steganalysis mathematically. Denoting the <italic>i</italic>-th image with <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>l</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> and its representation in the feature space as <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msup><mml:mi mathvariant="bold-italic">z</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, the steganographers generate a source of <italic>I</italic> images <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>I</mml:mi></mml:math></inline-formula> that are either all cover or all stego embedded with payloads <italic>R</italic><sub><italic>i</italic></sub>. The number of images is assumed to be arbitraily large. The Warden inspects a set of <italic>B</italic> images <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>B</mml:mi></mml:math></inline-formula> with a classifier trained with a high-dimensional feature set. Due to the way the features are built and the fact that the test statistic is a projection of high-dimensional features, the Warden&#x2019;s single-image detector output, denoted <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi mathvariant="bold-italic">z</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, is a sample from a Gaussian distribution <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
<p>Given <italic>B</italic> &#x2265; 1 images <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>B</mml:mi></mml:math></inline-formula>, in Warden&#x2019;s pooling bag, the Warden faces the following hypothes is testing problem:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>&#x003A;</mml:mo><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi mathvariant="normal">&#x2200;</mml:mi><mml:mi>i</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x003A;</mml:mo><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">N</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi mathvariant="normal">&#x2200;</mml:mi><mml:mi>i</mml:mi></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the expected shift of the detection statistic (over messages) when embedding payload size <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula>. In addition, if it does not impose any assumption on the steganographers&#x2019; payload spreading strategy, <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> can be different for each image.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Steganographer Identification</title>
<p>Steganographers often use batch images as covers for covert communication. A steganalyzer can analyze a user&#x2019;s image collection to determine their status as a steganographer by identifying at least one stego image in the collection. Therefore, the problem of identifying steganographers can be described as follows:</p>
<p>Steganographer identification problem formalization. A training set of <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>n</mml:mi></mml:math></inline-formula> users is defined as <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>U</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, where <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represents a user containing <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>m</mml:mi></mml:math></inline-formula> images. <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>y</mml:mi></mml:math></inline-formula> represents the label corresponding to the user, 0 is the normal user, and 1 is the steganographer. If all images of the user <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are cover images without secret information, he is a normal user, and his label <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>. If the user image set contains a stego image with secret information embedding, he is a steganographer with the label <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. In the test phase, the prediction label <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mn>1</mml:mn><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> is output for user <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, which contains multiple images.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Identification Paradigm</title>
<sec id="s2_3_1">
<label>2.3.1</label>
<title>Hierarchical Clustering</title>
<p>Clustering is gathering the more similar and less different samples according to the distance. The goal is to bring similar samples together and different samples separately. Hierarchical clustering is a clustering algorithm that creates a hierarchical nested clustering tree by calculating the similarity between data points of different categories. We introduce several distance measures below:</p>
<p>Let <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> for the distance between two objects <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mi>x</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mi>y</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mi>D</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> for the distance between two clusters <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>X</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>Y</mml:mi></mml:math></inline-formula>. The single linkage uses the distance between the nearest points in the two clusters:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>S</mml:mi><mml:mi>L</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>X</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>Y</mml:mi></mml:mrow></mml:munder><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>and the complete linkage uses the furthest points:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>L</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>X</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>Y</mml:mi></mml:mrow></mml:munder><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>The single linkage can cause long chains of clusters, whereas complete linkage prefers compact clusters; other agglomerative clustering algorithms are intermediate, including centroid clustering
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>E</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>X</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>Y</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>X</mml:mi></mml:mrow></mml:munder><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>Y</mml:mi></mml:mrow></mml:munder><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>and average linkage
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>A</mml:mi><mml:mi>L</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>X</mml:mi><mml:mo>&#x222A;</mml:mo><mml:mi>Y</mml:mi><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x222A;</mml:mo><mml:mi>Y</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>X</mml:mi><mml:mo>&#x222A;</mml:mo><mml:mi>Y</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>y</mml:mi></mml:mrow></mml:munder><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>The input to the basic agglomerative clustering is a distance matrix between objects. The output can be displayed in a dendrogram, a tree of the successive cluster agglomerations using &#x201C;height&#x201D; to indicate the distance between clusters being merged.</p>
</sec>
<sec id="s2_3_2">
<label>2.3.2</label>
<title>Local Outlier Factor</title>
<p>The local outlier factor (LOF) [<xref ref-type="bibr" rid="ref-45">45</xref>] is also a distance-based anomaly detection algorithm that can quantify the local deviation of each sample point. Whether the sample point <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>p</mml:mi></mml:math></inline-formula> is abnormal depends not on the local density of <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>p</mml:mi></mml:math></inline-formula> but on comparing the local density of <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>p</mml:mi></mml:math></inline-formula> and its neighbors. Specifically, the reachability distance of <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>p</mml:mi></mml:math></inline-formula> w.r.t. <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>o</mml:mi></mml:math></inline-formula> is defined as <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>h</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>d</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is <italic>k</italic>-th distance of sample point <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>p</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a distance between <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mi>p</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mi>o</mml:mi></mml:math></inline-formula>. The local reachability density of <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>p</mml:mi></mml:math></inline-formula> is
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>o</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:munder><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>h</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi>d</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula>where <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the number of elements in the <italic>k</italic>-th distance. Thus, the <italic>LOF</italic> value of <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>p</mml:mi></mml:math></inline-formula> is
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mi>L</mml:mi><mml:mi>O</mml:mi><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>o</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mfrac><mml:mrow><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>o</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>d</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>p</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>LOF can capture the degree of sample point <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>p</mml:mi></mml:math></inline-formula>, and the value provided by LOF are interpretable.</p>
</sec>
<sec id="s2_3_3">
<label>2.3.3</label>
<title>Graph Convolutional Network</title>
<p>The Graph Convolutional Network (GCN) [<xref ref-type="bibr" rid="ref-46">46</xref>] proposes a method to extract features from graph data by taking the feature matrix and adjacency matrix as input. The feature matrix contains the initial nodes in the graph, while the adjacency matrix represents their connection relationship. Aggregation operation and node feature updating are crucial in GCN, where low-dimension embeddings for each node are learned by convolving and aggregating information from its neighbors. During each layer&#x2019;s aggregation process, nodes gather information from their previous layer&#x2019;s neighborhood and update their own specific features accordingly.</p>
<p>In GCN, the network transmission from <italic>l</italic>-th layer to (<italic>l</italic> &#x002B; 1)-th layer is</p>
<p><disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:msup><mml:mi mathvariant="bold-italic">H</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>l</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi mathvariant="bold-italic">H</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>l</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi mathvariant="bold-italic">A</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi mathvariant="bold-italic">W</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>l</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:msup><mml:mi mathvariant="bold-italic">H</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>l</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> is the output of <italic>l</italic>-th layer, i.e., is the input of (<italic>l</italic> &#x002B; 1)-th layer. <bold><italic>A</italic></bold> is adjacency matrix. <bold><italic>H</italic></bold><sup>(<italic>l</italic> &#x002B; 1)</sup> is the output of (<italic>l</italic> &#x002B; 1)-th layer. <bold><italic>W</italic></bold><sup>(<italic>l</italic>)</sup> is the weight matrix that needs to be trained for the feature transformation. In particular, <bold><italic>H</italic></bold><sup>(0)</sup> is the 0-th layer, i.e., is the initial feature matrix.</p>
</sec>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Seganographer Identification Framework</title>
<p>The key to identifying steganographers lies in the distinguishable features of users. We categorize steganographer identification into two main methods: main channel-based and side channel-based, which are based on existing techniques for user feature design. The former distinguishes users by designing image features related to steganography embedding [<xref ref-type="bibr" rid="ref-47">47</xref>,<xref ref-type="bibr" rid="ref-48">48</xref>] in images, while the latter considers user behavioral features [<xref ref-type="bibr" rid="ref-49">49</xref>,<xref ref-type="bibr" rid="ref-50">50</xref>] along with image embedding. Based on this categorization, we propose a general framework for steganographer identification by summarizing the methods presented in existing literature depicted in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. It consists of five main steps: data acquisition, feature extraction, feature optimization, identification paradigm, and performance evaluation. The details are as follows:</p>
<p><list list-type="bullet">
<list-item>
<p>Dataset acquisition. Collect batch image data from multiple users, each with varying quantities and types of images.</p></list-item>
<list-item>
<p>Feature extraction. The key steps for accurately identify steganographers include image feature and side channel feature.</p></list-item>
<list-item>
<p>Feature optimization. The important means to improve steganographer identification accuracy include feature calibration, ensemble learning, and dimension reduction for optimized features.</p></list-item>
<list-item>
<p>Identification paradigm. Train a steganalyst to detect or identify steganographers using various learning approaches, including supervised, weakly supervised, unsupervised learning, and other identification paradigms.</p></list-item>
</list></p>

<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>General framework of main channel steganographer identification</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-2.tif"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Data Acquisition</title>
<p>In image steganographer identification, each user has a set of images. The inputs are acquired data, including user image data, user behaviour data, and analysis of user attributes, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. As mentioned, the main channel steganographer identification uses image features that can detect steganography embedding. Side channel steganographer identification is to identify steganographers according to user behaviour data. Of course, this all involves the analysis of user attributes.</p>
<p>It is common to simulate user data using image databases commonly used in steganalysis, such as BOSSBase-1.01 [<xref ref-type="bibr" rid="ref-51">51</xref>] and BOWs [<xref ref-type="bibr" rid="ref-52">52</xref>], to evaluate models. In addition, performance evaluation based on real-world datasets is more convincing. Therefore, the acquisition of the real-world datasets is essential for model implementation and performance evaluation. <xref ref-type="table" rid="table-1">Table 1</xref> lists the real-world user dataset used in existing literature.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Data source for steganographer identification</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Literature</th>
<th>Data source</th>
</tr>
</thead>
<tbody>
<tr>
<td>Ker et al. [<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-53">53</xref>]</td>
<td>Oxford University</td>
</tr>
<tr>
<td>Li et al. [<xref ref-type="bibr" rid="ref-54">54</xref>]</td>
<td>Baidu</td>
</tr>
<tr>
<td>Li et al. [<xref ref-type="bibr" rid="ref-55">55</xref>,<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>Twitter</td>
</tr>
<tr>
<td>Zhang et al. [<xref ref-type="bibr" rid="ref-57">57</xref>,<xref ref-type="bibr" rid="ref-58">58</xref>]</td>
<td>Flickr</td>
</tr>
<tr>
<td>Wang et al. [<xref ref-type="bibr" rid="ref-49">49</xref>]</td>
<td>MNIST, CIFAR-10</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Ker et al. downloaded over 4 million publicly available JPEG images from real social media sites [<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-53">53</xref>]. The crawl was restricted to users who publicly identified themselves with the Oxford University network and the data was then anonymized. Following filtering, they selected a subset of images contributed by 4000 users, with each user providing 200 images. Consequently, they generated an experimental dataset comprising a total of 800,000 images.</p>
<p>Li et al. [<xref ref-type="bibr" rid="ref-54">54</xref>] collected social network image data from an image sharing website (<ext-link ext-link-type="uri" xlink:href="https://image.baidu.com">https://image.baidu.com</ext-link>, accessed on 31 August 2024). They downloaded a large quantity of JPEG images from the website and resized them to a size of 1024 &#x00D7; 1024. They recompressed the images using quality of the same factor (QF &#x003D; 80) to avoid the influence of different quantization matrices on the steganalysis features.</p>
<p>Li et al. [<xref ref-type="bibr" rid="ref-55">55</xref>,<xref ref-type="bibr" rid="ref-56">56</xref>] used Tweepy [<xref ref-type="bibr" rid="ref-59">59</xref>], a public API for Twitter developers, to crawl images from 3000 users on Twitter. And only JPEG images are left. Next, they cropped them to a size of 512 &#x00D7; 512 using center cropping and filtered out users with less than 100 images. Following preprocessing, there were 700 images remaining.</p>
<p>Zhang et al. [<xref ref-type="bibr" rid="ref-57">57</xref>,<xref ref-type="bibr" rid="ref-58">58</xref>] collected images from Flickr (<ext-link ext-link-type="uri" xlink:href="https://www.flickr.com">https://www.flickr.com</ext-link>,
accessed on 31 August 2024), which is a well-known online social media platform designed for photo management and sharing. They accessed public raw JPEG images by utilizing Flickr&#x2019;s public API, downloading over 400,000 images from 1000 users, with each user contributing between 100 and 600 images.</p>
<p>Wang et al. [<xref ref-type="bibr" rid="ref-49">49</xref>] proposed a method to identify abnormal users who use adversarial attacks among many normal users. The idea and method are similar to steganographer identification except for the identification object. Therefore, the real-world datasets they use also have reference significant for steganographer identification. They used the well-known MNIST [<xref ref-type="bibr" rid="ref-60">60</xref>] and CIFAR-10 [<xref ref-type="bibr" rid="ref-61">61</xref>] image datasets.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Feature Extraction Methods</title>
<p>The goal of feature extraction is to design features that can distinguish users with effect. Therefore, the separability feature is critical to identify the steganographers accurately. In this section, we introduce the feature extraction method for steganographer identification, and summarize these methods into two categories: main channel features and side channel features, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. The details are as follows.</p>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Main Channel-Based Feature</title>
<p>Image features that distinguish users belong to the main channel features. Both image steganography detection and steganographer identification need image statistical features to make decisions. The former uses the features to detect images, while the latter measures users based on these features. Additionally, the dimension of the features has a greater impact on steganographer identification compared to image steganalysis. Therefore, although there are many relatively mature steganalysis features [<xref ref-type="bibr" rid="ref-62">62</xref>&#x2013;<xref ref-type="bibr" rid="ref-64">64</xref>] for image classification, they are not suitable for steganographer identification.</p>
<p>We summarize existing image features for steganographer identification. They are categorized into two classes: domain knowledge-based and deep learningbased features. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows the framework of main channel steganographer identification, where image steganalysis feature extraction is divided into domain knowledge-based and deep learning-based methods. Steganalysis features are often designed on residual images because residual helps suppress image content and amplify steganography noise.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>General framework of main channel steganographer identification</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-3.tif"/>
</fig>
<sec id="s3_2_1_1">
<title>A. Domain Knowledge-Based Feature</title>
<p>In 2011, Ker et al. [<xref ref-type="bibr" rid="ref-65">65</xref>] initially proposed clustering-based steganographer identification paradigm using PEV-274 features. The method is more robust because the clustering does not need to train. The PEV-274 [<xref ref-type="bibr" rid="ref-66">66</xref>] was proposed initially for detecting JPEG image steganography. In 2012, Ker et al. [<xref ref-type="bibr" rid="ref-35">35</xref>] proposed a LOF-based steganographer identification method that also utilized this feature. In [<xref ref-type="bibr" rid="ref-54">54</xref>], Li et al. designed a higher-order joint feature with lower dimension and proposed a steganographer identification paradigm based on ensemble clustering [<xref ref-type="bibr" rid="ref-67">67</xref>] using this feature. The higher-order joint feature can effectively capture the modification of the DCT coefficient by JPEG steganography embedding. Due to the development of adaptive steganography [<xref ref-type="bibr" rid="ref-68">68</xref>,<xref ref-type="bibr" rid="ref-69">69</xref>], Li et al. [<xref ref-type="bibr" rid="ref-70">70</xref>] proposed a steganographer identification method using the reduced PEV feature, RPEV-155. This feature is mainly used to identify users who employ adaptive steganography. They sampled and reconstructed the image before extracting the feature, which captured the noise of adaptive steganography to a greater extent.</p>
</sec>
<sec id="s3_2_1_2">
<title>B. Deep Learning-Based Feature</title>
<p>In deep learning-based steganalysis, multiple convolutional layers extract features, followed by a fully connected layer for classification. Therefore, deep learning-based steganographer identification usually extracts features the network learns after multiple convolutional layers in the deep learning network, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>. It should be noted that the performance of these features is closely related to the design and training of the network.</p>

<p>In 2017, Zheng et al. [<xref ref-type="bibr" rid="ref-71">71</xref>] proposed a residual network steganographer identification method, RNSD, which applies deep learning features to steganographer identification for the first time. The backbone is deep residual steganalysis network [<xref ref-type="bibr" rid="ref-72">72</xref>]. To tackle the algorithm mismatch [<xref ref-type="bibr" rid="ref-73">73</xref>,<xref ref-type="bibr" rid="ref-74">74</xref>] in steganographer identification, Zheng et al. [<xref ref-type="bibr" rid="ref-75">75</xref>] proposed a multiclass deep neural network steganographer identification method, MDNNSD. In 2019, inspired by selecting channel-aware steganalysis methods [<xref ref-type="bibr" rid="ref-76">76</xref>], Zheng et al. proposed two embedded probability estimation deep network steganographer detection methods, EPEDN [<xref ref-type="bibr" rid="ref-77">77</xref>] and MEPESD [<xref ref-type="bibr" rid="ref-25">25</xref>], that learn more knowledge about steganography embedding. The difference lies in the embedded probability learning sub-network module. In EPEDN, FCN-8s [<xref ref-type="bibr" rid="ref-78">78</xref>], a fully convolutional network commonly used in image segmentation, is used as this sub-network module. MEPESD adopted the NLDF [<xref ref-type="bibr" rid="ref-79">79</xref>], which is commonly used in saliency detection as the sub-network module. Because labels are not always available in the real world, [<xref ref-type="bibr" rid="ref-80">80</xref>] proposed a Deep Clustering Network for steganographer identification (DCNSD).</p>
</sec>
<sec id="s3_2_1_3">
<title>C. Discussion</title>
<p>The main channel steganographer identification features are classified into two categories based on feature extraction method: domain knowledge-based features and deep learning-based features.</p>
<p>Through the research status of image feature extraction methods in steganographer identification, this paper analyzes and classifies some existing feature extraction methods, so as to help readers better evaluate feature extraction methods immediately. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> lists the current features of main channel-based steganographer identification research and their advantages and limitations. According to previous studies, no validity feature extraction method can be applied to all data sets, and no features is always better than other features. No matter how well a feature extraction method is designed, there will always be application scenarios that are not applicable. For example, the network we train to detect steganographers using J-UNIWARD may not be suitable for identifying users using other steganography, such as UED.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Advantages and limitations of main channel features</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-4.tif"/>
</fig>
</sec>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Side Channel-Based Feature</title>
<p>In this section, we introduce steganographer identification methods that use behavioral features in the existing literature. We categorize such methods as side channel-based steganographer identification. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows the framework of side channel steganographer identification. The key to side channel steganographer identification is to find behavioural features that effectively distinguish steganographers from normal users. This involves the analysis of the behavioural attributes of the steganographer. Compared with main channel steganographer identification, there is little research on side channel steganographer identification based on user behaviour characteristics analysis. Existing research includes image sequence and cover selection behavior, described as follows.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>General framework of side channel steganographer identification</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-5.tif"/>
</fig>
<sec id="s3_2_2_1">
<title>A. Image Sequence Behavior Anslysis</title>
<p>In 2018, Li et al. [<xref ref-type="bibr" rid="ref-55">55</xref>] proposed a behavioral separability feature, SIAM (subtractive images adjacent model), between normal users and steganographers. To our knowledge, this is the first research on identifying steganographers using features other than images. SIAM feature design is on the assumption that the images from normal users are usually of a certain sequence and relevance. In contrast, there is usually no such relationship between the images of steganographers because they are more likely to select images suitable for steganography to covert communication. At this point, we can define consistency to describe this sequential relationship of images, as follows:</p>
<p><disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mfrac></mml:math></disp-formula>where <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represents the steganographer&#x2019;s consistency level, <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represent the number of random images and total images per user, respectively.</p>
</sec>
<sec id="s3_2_2_2">
<title>B. Complex Cover Selection Behavior</title>
<p>Steganographers typically choose suitable covers to resist steganalysis attacks. For example, Reference [<xref ref-type="bibr" rid="ref-81">81</xref>] considered images with good visual quality as suitable covers, and some scholars consider the image content and choose images with high texture complexity as covers [<xref ref-type="bibr" rid="ref-50">50</xref>,<xref ref-type="bibr" rid="ref-82">82</xref>]. Based on this, Wang et al. [<xref ref-type="bibr" rid="ref-83">83</xref>] observed that the covers selected by existing cover selection methods [<xref ref-type="bibr" rid="ref-84">84</xref>,<xref ref-type="bibr" rid="ref-85">85</xref>] normally have different characteristics from normal ones, and proposed a steganalysis method to capture such differences. Although the cover selection behaviour is used for image steganalysis in [<xref ref-type="bibr" rid="ref-83">83</xref>], it is also pointed out that the detection results of the images using this method also help in user identification at the same time.</p>
</sec>
<sec id="s3_2_2_3">
<title>C. Discussion</title>
<p>Actually, there are many differences between steganographers and normal users in terms of behavior. At present, side channel steganographer identification is still in its beginning state, and there is much more to study and explore in this area in the future.</p>
</sec>
</sec>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Feature Optimization Methods</title>
<p>In this section, we introduce the typical feature optimization methods used in existing literature for image steganographer identification, including feature calibration, feature dimension reduction and high dimensional feature ensemble learning. The brief structure is illustrated in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>, and the details are as follows.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Feature optimization methods</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-6.tif"/>
</fig>
<sec id="s3_3_1">
<label>3.3.1</label>
<title>Feature Calibration</title>
<p>In 2020, Li et al. [<xref ref-type="bibr" rid="ref-56">56</xref>] proposed SIAM-C feature for steganographer identification, which are calibrated SIAM [<xref ref-type="bibr" rid="ref-55">55</xref>]. The feature calibration method [<xref ref-type="bibr" rid="ref-86">86</xref>,<xref ref-type="bibr" rid="ref-87">87</xref>] is commonly used in steganalysis to eliminate the differences between different images and noise interference to make the extracted steganalysis features more stable. In [<xref ref-type="bibr" rid="ref-56">56</xref>], an image with similar content to the user&#x2019;s image is selected as a reference image to calibrate the SIAM features.</p>
</sec>
<sec id="s3_3_2">
<label>3.3.2</label>
<title>Feature Dimension Reduction</title>
<p>Image steganalysis has been studied for a longer period as compared to steganographer identification. Several effective single-image steganalysis features have been born. However, these cannot be used for steganographer identification directly. For example, Reference [<xref ref-type="bibr" rid="ref-54">54</xref>] stated that it is nearly impossible to steganographer identification using high-dimensional features such as DCTR (Discrete Cosine Transform Residual) [<xref ref-type="bibr" rid="ref-88">88</xref>] and PHARM [<xref ref-type="bibr" rid="ref-89">89</xref>]. Although the two feature sets are conclusively more sensitive for supervised binary classification, these rich feature sets are formed by a lot of weak features. The weak features contain a large amount of noise, which leads to an inferior performance in steganographer identification. This phenomenon has also been demonstrated in [<xref ref-type="bibr" rid="ref-90">90</xref>]. Based on this, Ma et al. [<xref ref-type="bibr" rid="ref-91">91</xref>] explored a feature selection method for single-image steganalysis.</p>
<p>In main channel steganographer identification, Zhang et al. [<xref ref-type="bibr" rid="ref-92">92</xref>] proposed a steganographer identification method based on steganalysis feature dimension reduction without trying to extracting new image feature. In <xref ref-type="sec" rid="s3_2">Section 3.2</xref>, we present the experiments of feature dimension reduction methods in steganographer identification.</p>
</sec>
<sec id="s3_3_3">
<label>3.3.3</label>
<title>Feature Ensemble Learning</title>
<p>For the same reasons, Wu [<xref ref-type="bibr" rid="ref-93">93</xref>] proposed a steganographer identification method based on feature bagging [<xref ref-type="bibr" rid="ref-94">94</xref>]. This method can deal with samples with high dimensional features without dimension reduction. Feature bagging randomly extracts subsets from the original high-dimensional feature space and trains multiple feature subspaces using an identification algorithm.</p>
<p>Finally, the prediction results of each sub feature space are integrated.</p>
</sec>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Identification Paradigms and Performance Evaluation</title>
<p>Performance evaluation is aiming to evaluate the performance of the steganographer identification algorithm. In this section, we introduce the typical evaluation metrics that widely used in existing literature for steganographer identification.</p>
<sec id="s3_4_1">
<label>3.4.1</label>
<title>Performance Evaluation</title>
<p><italic>A. Maximum Mean Difference</italic>. Each user corresponds to a set of images and the similarity between users is often evaluated using Maximum Mean Difference (<italic>MMD</italic>) [<xref ref-type="bibr" rid="ref-65">65</xref>]. The <italic>MMD</italic> distance can be described as follows:</p>
<p>Given two users, <italic>X</italic> and <italic>Y</italic>, and each containing <italic>n</italic> images. The standardized feature sets for <italic>X</italic> and <italic>Y</italic> are denoted as <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, respectively. The <italic>MMD</italic> distance between <italic>X</italic> and <italic>Y</italic> can be represented as follows:<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mi>M</mml:mi><mml:mi>M</mml:mi><mml:mi>D</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>X</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>Y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>2</mml:mn><mml:mrow><mml:mi>n</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mo>[</mml:mo><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <italic>k</italic>(<italic>x</italic>, <italic>y</italic>) is a kernel function which is pre-defined. The most effective kernel functions are the Linear kernel<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup><mml:mi>y</mml:mi></mml:math></disp-formula>and the Gaussian kernel<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mi>k</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>y</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:msup><mml:mrow><mml:mo symmetric="true">&#x2016;</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>y</mml:mi><mml:mo symmetric="true">&#x2016;</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where parameter <italic>&#x03B3;</italic> is the inverse kernel width.</p>
<p><italic>B. Identification Accuracy Rate</italic>. Identification accuracy rate <italic>AR</italic> [<xref ref-type="bibr" rid="ref-54">54</xref>] is calculated as the number of correctly detected steganographic users over the selected total number of steganographic users, i.e.,<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:mi>A</mml:mi><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mfrac><mml:mo>&#x00D7;</mml:mo><mml:mn>100</mml:mn><mml:mi mathvariant="normal">&#x0025;</mml:mi></mml:math></disp-formula>where <italic>N</italic><sub><italic>correct</italic></sub> is the number of correctly detected steganographers, and <italic>N</italic><sub><italic>total</italic></sub> represents the selected total number of steganographers.</p>
<p><italic>C. Vote Score</italic>. The total vote score (<italic>V</italic>) [<xref ref-type="bibr" rid="ref-56">56</xref>] of actor <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> can be obtained by</p>
<p><disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:mi>V</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>m</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>M</mml:mi></mml:mrow></mml:munderover><mml:mi>v</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>m</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi></mml:math></disp-formula>where <italic>M</italic> is the number of images per user, and <italic>N</italic> is the number of users under investigation, <italic>v</italic>(<italic>m</italic>) represents the ensemble votes yielded by the ensemble classifier.</p>
</sec>
<sec id="s3_4_2">
<label>3.4.2</label>
<title>Hierarchical Clustering-Based Approach</title>
<p>The difference between a steganographer and a normal user is larger than two normal users. Based on this, Ker et al. [<xref ref-type="bibr" rid="ref-65">65</xref>] first proposed a hierarchical clustering-based steganographer identification method in 2011, and the <italic>MMD</italic> distance was used to measure the distance between users. After several rounds of iterations, the remaining individual in the last iteration is determined to be the steganographer. The hierarchical clustering methods have been used in subsequent steganographer identification studies [<xref ref-type="bibr" rid="ref-71">71</xref>,<xref ref-type="bibr" rid="ref-75">75</xref>,<xref ref-type="bibr" rid="ref-54">54</xref>]. Among them, Li et al. [<xref ref-type="bibr" rid="ref-54">54</xref>] proposed a clustering ensemble-based steganographer identification method for optimal decisions.</p>
</sec>
<sec id="s3_4_3">
<label>3.4.3</label>
<title>LOF-Based Approach</title>
<p>Reference [<xref ref-type="bibr" rid="ref-53">53</xref>] was the earliest research that utilized local outlier factor (LOF) to measure steganographers. In contrast to hierarchical clustering, the LOF-based method can use an abnormal value to weigh the user. For a detailed description and analysis of the LOF, we refer to the original article [<xref ref-type="bibr" rid="ref-45">45</xref>]. The LOF-based identification paradigm provided new ideas for subsequent research [<xref ref-type="bibr" rid="ref-53">53</xref>,<xref ref-type="bibr" rid="ref-56">56</xref>,<xref ref-type="bibr" rid="ref-70">70</xref>,<xref ref-type="bibr" rid="ref-77">77</xref>,<xref ref-type="bibr" rid="ref-95">95</xref>]. For instance, Ker et al. [<xref ref-type="bibr" rid="ref-53">53</xref>] mainly did research on realistic large-scale steganalysis and pointed out that the steganographer is the Outlier. In the content-adaptive selective identification scheme [<xref ref-type="bibr" rid="ref-77">77</xref>], LOF is employed to capture the value of anomaly for each user.</p>
</sec>
<sec id="s3_4_4">
<label>3.4.4</label>
<title>Graph Neural Network-Based Approach</title>
<p>Different from the traditional machine learning-based identification paradigm, such as hierarchical clustering and LOF, in 2020, Zhang et al. [<xref ref-type="bibr" rid="ref-57">57</xref>] first proposed a network learning-based method for steganographer identification. The network learning-based method first constructs the users as graphs using the similarity of the images. Then, the graphs as input and the user labels as output are used to train the steganographer identification model based on Graph Convolutional Neural Network (GNN). GNN is an extension of deep learning methods from structured data to unstructured data, and its core components are aggregation operations and node feature updates. For a detailed description and analysis of the GNN, we refer to the original article [<xref ref-type="bibr" rid="ref-46">46</xref>]. Since then, many network learning-based methods [<xref ref-type="bibr" rid="ref-58">58</xref>,<xref ref-type="bibr" rid="ref-92">92</xref>] have been researched for steganographer identification.</p>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Methods Comparison</title>
<p>In this section, we offer a comparative analysis of the representative methods. The details are shown in <xref ref-type="table" rid="table-2">Table 2</xref>. As can be seen from the table, both steganographer identification and steganalysis all require to extract features. However, in addition to extracting image features, steganographer identification can also extract side channel feature, which is different from steganalysis. This is because the goals are different. Steganalysis mainly focuses on the image itself, aiming to detect whether there is steganography embedding in the image. Steganographer identification focuses on the identity of the user behind the steganography, aiming to determine the subject hiding information in the image. Of course, the features that can effectively identify steganographers, especially the behavior features of users, is still in its infancy and requires further research and improvement.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison of representative approaches for steganographer identification</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Method</th>
<th>Year</th>
<th>Dataset</th>
<th>Type</th>
<th>Feature extraction</th>
<th>Feature optimization</th>
<th>Identification paradigm</th>
</tr>
</thead>
<tbody>
<tr>
<td>PEV_HC [<xref ref-type="bibr" rid="ref-65">65</xref>]</td>
<td>2011</td>
<td>RAW photos</td>
<td>JPEG</td>
<td rowspan="5">DK-based feature</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>PEV_SD [<xref ref-type="bibr" rid="ref-53">53</xref>]</td>
<td>2014</td>
<td>Social network site (Oxford University network)</td>
<td>JPEG</td>
<td>None</td>
<td>LOF</td>
</tr>
<tr>
<td>HOJ_SD [<xref ref-type="bibr" rid="ref-54">54</xref>]</td>
<td>2016</td>
<td>Social network site (<ext-link ext-link-type="uri" xlink:href="http://image.baidu.com">http://image.baidu.com</ext-link>)</td>
<td>JPEG</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>RPEV_SD [<xref ref-type="bibr" rid="ref-70">70</xref>]</td>
<td>2017</td>
<td>Social network site (<ext-link ext-link-type="uri" xlink:href="http://image.baidu.com">http://image.baidu.com</ext-link>) (<ext-link ext-link-type="uri" xlink:href="http://images.google.com">http://images.google.com</ext-link>)</td>
<td>JPEG</td>
<td>Dimension reduction</td>
<td>LOF</td>
</tr>
<tr>
<td>FSGCN [<xref ref-type="bibr" rid="ref-92">92</xref>]</td>
<td>2023</td>
<td>BOSSBase-1.01/Bows</td>
<td>JPEG</td>
<td>Dimension reduction</td>
<td>GNN</td>
</tr>
<tr>
<td>RNSD [<xref ref-type="bibr" rid="ref-71">71</xref>]</td>
<td>2017</td>
<td>BOSSBase-1.01</td>
<td>Spatial</td>
<td rowspan="8">DL-based feature</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>MDNNSD [<xref ref-type="bibr" rid="ref-75">75</xref>]</td>
<td>2018</td>
<td>BOSSBase-1.01</td>
<td>Spatial</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>EPEDN [<xref ref-type="bibr" rid="ref-77">77</xref>]</td>
<td>2019</td>
<td>BOSSBase-1.01</td>
<td>Spatial</td>
<td>Feature fusion</td>
<td>LOF</td>
</tr>
<tr>
<td>MEPESD [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>2019</td>
<td>BOSSBase-1.01</td>
<td>Spatial/JPEG</td>
<td>None</td>
<td>Gaussian vote</td>
</tr>
<tr>
<td>EGCN [<xref ref-type="bibr" rid="ref-57">57</xref>]</td>
<td>2020</td>
<td>BOSSBase-1.01/Flick</td>
<td>Spatial/JPEG</td>
<td>None</td>
<td>GNN</td>
</tr>
<tr>
<td>SAGCN [<xref ref-type="bibr" rid="ref-58">58</xref>]</td>
<td>2021</td>
<td>BOSSBase-1.01/Flick</td>
<td>Spatial/JPEG</td>
<td>None</td>
<td>GNN</td>
</tr>
<tr>
<td>MSCNN [<xref ref-type="bibr" rid="ref-95">95</xref>]</td>
<td>2021</td>
<td>BOSSBase-1.01</td>
<td>Spatial</td>
<td>None</td>
<td>LOF</td>
</tr>
<tr>
<td>DCNSD [<xref ref-type="bibr" rid="ref-80">80</xref>]</td>
<td>2023</td>
<td>BOSSBase-1.01</td>
<td>Spatial</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>SIAM_SD [<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>2018</td>
<td>Twitte</td>
<td>JPEG</td>
<td rowspan="3">SC-based feature</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>PSRM [<xref ref-type="bibr" rid="ref-93">93</xref>]</td>
<td>2019</td>
<td>BOSSBase-1.01/UCID</td>
<td>Spatial</td>
<td>None</td>
<td>Clustering</td>
</tr>
<tr>
<td>SIAM-C_SD [<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>2020</td>
<td>Twitte</td>
<td>JPEG</td>
<td>Feature calibration</td>
<td>LOF</td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn><p>Note: The hyperlinks in <xref ref-type="table" rid="table-2">Table 2</xref> were accessed on 31 August 2024; DK-based feature: Domain knowledge-based feature; DL-based feature: Deep learning-based feature; SC-based feature: Side channel-based feature.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p>The experimental comparisons and analysis of the performance of existing steganographer identification methods, including clustering-based, reduced feature dimension, and graph-based methods, are shown below. It is important to note that, all experiments were performed on the standard dataset BOSSBase1.01, where the frequency domain dataset was compressed using QF &#x003D; 80. In the training stage, we construct 200 normal users and 200 steganographers, each with a sample of 50 images. The normal user images are cover images, while the steganographer images are stego images. Random sampling with replacement is used as the sampling strategy. In the testing stage, we set 99 normal users and 1 steganographer among a total of 100 users to simulate real-world scenarios. Each user has 50 images.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Clustering-Based Methods Comparison</title>
<p>Most of the steganographer identification methods use a hierarchical clustering based paradigm. Clustering utilizes the distance or similarity between samples to cluster more similar and less different samples into one class. Hierarchical clustering is a type of clustering algorithm that creates a hierarchical nested clustering tree by calculating the similarity between data points of different categories, aiming to cluster similar samples together and separate different samples.</p>
<p>In clustering-based methods, the performance is closely related to the effectiveness of extracted image features. <xref ref-type="fig" rid="fig-7">Fig. 7</xref> describes spatial image steganographer identification comparisons based on clustering according to the experimental results reported in [<xref ref-type="bibr" rid="ref-75">75</xref>] and [<xref ref-type="bibr" rid="ref-71">71</xref>], include the SRMQ1_SD, XuNet_SD, ANSD, RNSD [<xref ref-type="bibr" rid="ref-71">71</xref>], and MDNNSD [<xref ref-type="bibr" rid="ref-75">75</xref>]. Where SRMQ1_SD is the clustering-based steganographer identification method via SRMQ1 [<xref ref-type="bibr" rid="ref-62">62</xref>], which is a well-known spatial rich model with a single quantization step. XuNet_SD is the abbreviation of the clustering-based steganographer identification method based on the network proposed by Xu et al. [<xref ref-type="bibr" rid="ref-32">32</xref>]. ANSD is the clustering-based steganographer identification method via a well-known deep CNN architecture AlexNet [<xref ref-type="bibr" rid="ref-96">96</xref>]. It should be noted that the experiment shows the identification results of steganographers using S-UNIWARD steganography and even embedding strategy.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Performance comparison on clustering-based methods</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-7.tif"/>
</fig>
<p>As seen from <xref ref-type="fig" rid="fig-7">Fig. 7</xref>, although all of these methods use the clustering paradigm, the identification performance is significantly different when the user uses different payloads of steganography based on various image features. However, in general, the performance of low-dimensional features significantly outperforms that of high-dimension features in steganographer identification. We found that SRMQ1 features have the highest dimension and the worst identification performances. Based on this, we analyze the effect of feature dimension on identification performance, as shown in the following subsection.</p>

</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Feature Dimension Reduction Comparison</title>
<p>This section focuses on showing the effect of feature dimensions on identification performance. <xref ref-type="fig" rid="fig-8">Fig. 8</xref> shows the identification accuracy of feature selection in different dimensions of CCPEV [<xref ref-type="bibr" rid="ref-87">87</xref>] steganalysis feature. In this case, steganographer use the UED steganography commonly used in the JPEG domain. We select the <italic>k</italic>-dimension feature components from CCPEV with the highest separability [<xref ref-type="bibr" rid="ref-92">92</xref>] in order of feature separability (<italic>k</italic> is 50, 100, 150, 200, and 250). The five feature dimensionality reduction of the steganalysis features, together with the 274-D Pev and 548-D CCPev features [<xref ref-type="bibr" rid="ref-87">87</xref>], a total of seven dimensions are used as image features based on the graph neural network as the results of the steganographer identification experiments. The influence of feature dimensions on identification performance is clearly illustrated in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Performance comparison on dimension reduction (The CCPEV features as an example)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-8.tif"/>
</fig>
<p>Compared to Pev-274 and CCPev steganalysis features, satisfactory identification accuracy is achieved based on the selected low-dimensional features. It is easy to calculate that the dataset is reduced to less than one-tenth of the original, and the complexity of the training set is low, which improves the speed of the classification algorithm and the identification accuracy. At the same time, the selected feature components are quantified in terms of their contribution to classification, perhaps with better readability and interpretability.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Graph Neural Network-Based Methods Comparison</title>
<p>The experimental results show that the features of different dimensions of steganalysis not only have significant differences in time and space complexity but directly affect the accuracy of model identification. Of course, the key is the effectiveness of the feature selection method at this time.</p>
<p>The previous section demonstrates the method&#x2019;s performance regarding image feature extraction methods, feature dimensions, etc. In addition, the model&#x2019;s design is also crucial for the identification accuracy. The clustering method is used in steganographer identification. On the one hand, it only uses user image statistical feature differences to distinguish users, which leads to a decrease in identification accuracy when the differences between users are minor. On the other hand, the unsupervised learning method is more susceptible to noise, which leads to the instability of the recognition results. The state-of-the-art steganographer identification method uses a geometric deep-learning architecture approach (graph neural network) to represent and recognize steganographers. This work provided new ideas for research in the field of steganographer identification.</p>
<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> presents the comparative results of conventional clustering-based and GNN-based methods, respectively. <xref ref-type="fig" rid="fig-9">Fig. 9a</xref> is the result of user utilizing S-UNIWARD steganography, and <xref ref-type="fig" rid="fig-9">Fig. 9b</xref> shows the result of user utilizing J-UNIWARD steganographer identification. In the spatial domain, the comparisons in the experiments include the SRMQ1 [<xref ref-type="bibr" rid="ref-62">62</xref>] with hierarchical clustering for steganographer identification (SRMQ1SD), the MDNNSD [<xref ref-type="bibr" rid="ref-75">75</xref>] method, the GCN-based [<xref ref-type="bibr" rid="ref-46">46</xref>] method, SAGCN [<xref ref-type="bibr" rid="ref-58">58</xref>] method, and MILGCN [<xref ref-type="bibr" rid="ref-97">97</xref>]. In the JPEG domain, the comparisons include the JRM [<xref ref-type="bibr" rid="ref-98">98</xref>] with hierarchical clustering for steganographer identification (JRM_SD), the PEV [<xref ref-type="bibr" rid="ref-66">66</xref>] with hierarchical clustering for steganographer identification (PEV_SD), the GCN-based [<xref ref-type="bibr" rid="ref-46">46</xref>] method, EGCN [<xref ref-type="bibr" rid="ref-57">57</xref>] method, and FSGCN method [<xref ref-type="bibr" rid="ref-92">92</xref>]. According to the experimental results reported in [<xref ref-type="bibr" rid="ref-57">57</xref>] and [<xref ref-type="bibr" rid="ref-58">58</xref>], the graph neural network-methods are obviously superior to the traditional clustering-based method.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Performance comparison on GNN-based methods. (a) The result of user utilizing S-UNIWARD steganography; (b) The result of user utilizing J-UNIWARD steganography</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-9.tif"/>
</fig>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Typical Identification Methods Comparison in Frequency Domain</title>
<p>Based on the experimental results reported in the literature, we further present a comprehensive analysis of the typical identification methods in the frequency domain. <xref ref-type="fig" rid="fig-10">Fig. 10</xref> shows the experimental results of different methods for identifying steganographers using nsF5 and UED, respectively. Among them, <xref ref-type="fig" rid="fig-10">Fig. 10a</xref> is the experimental results of users utilizing nsF5 steganography, and <xref ref-type="fig" rid="fig-10">Fig. 10a</xref> represents the experimental results of users utilizing UED steganography. It should be noted that, the JPEG version of BOSSbase1.01 is utilized to evaluate the proposed method in frequency domain. The comparisons include the PEV [<xref ref-type="bibr" rid="ref-66">66</xref>] with hierarchical clustering for steganographer identification (PEV_Cluster), the PEV [<xref ref-type="bibr" rid="ref-66">66</xref>] with LOF for steganographer identification (PEV_LoF), the GCN-based [<xref ref-type="bibr" rid="ref-46">46</xref>] method (GCN), SAGCN [<xref ref-type="bibr" rid="ref-58">58</xref>], MILGCN [<xref ref-type="bibr" rid="ref-97">97</xref>].</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Performance comparison in frequency domain. (a) The results of users utilizing nsF5 steganography; (b) The results of users utilizing UED steganography</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_55735-fig-10.tif"/>
</fig>
<p>From <xref ref-type="fig" rid="fig-10">Fig. 10</xref>, we can see that graph-based approaches outperform the conventional method that solely relies on statistical features of the image. On one hand, we analyzed that the graph-based method may increase inter-class difference by fusing image features and structural information. On the other hand, multi-layer graph convolutional neural networks possess powerful learning abilities to automatically capture differences between various user types.</p>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Discusstion</title>
<p>The problem of steganographer identification was first addressed by Ker et al. in 2011. They employed two unsupervised learning methods for steganographer identification, i.e., clustering-based detection and LOF-based detection. It can be said that most of the advanced works reported in the literature are based on them. Unsupervised learning methods do not depend on prior information or labels but instead, distinguish steganographers from normal users by establishing correlations or similarities between data. However, unsupervised learning is highly susceptible to the influence of noise, which can impact its accuracy and reliability. For example, the LOF-based method is incompatible with rich features containing many weak features because the weak features include lots of noise (caused by cover content), resulting in inferior performance.</p>
<p>In contrast, the state-of-the-art GNN-based identification method has good generalization ability, which can somewhat alleviate the problem of cover mismatch. However, the method is still in its infancy. For example, these frameworks are designed for users sharing the same number of images. If the number of images users share is significantly different, upsampling or downsampling is required so that the sampling strategy directly affects the model. Therefore, more questions will likely arise as the study of steganographer identification moves ahead.</p>
<p>In addition to that, it has been shown that the methods of feature processing, such as dimension reduction, can improve the identification performance. In steganographer identification, there are two main reasons for not using high-dimension features. First, the high-dimension feature is usually composed of many weak features that contain a large amount of noise, resulting in inferior performance. Secondly, high-dimension features will affect the distance measurement, making the distance between users smaller, thus affecting the identification accuracy. Feature dimension reduction can exploit salient features and eliminate irrelevant feature fluctuations by representing the discriminative information in a lower dimensional manifold. However, it is crucial to analyze the redundancy of feature components in this method.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Future Issues and Open Challenges</title>
<p>This review summarises the recent research on steganographer identification. Although the before-mentioned efforts have yielded substantial results, due to the diversity of available steganography and the the complexity of the social network, there are still several problems that deserve further research.</p>
<p><bold>1. Research on multi-modal features fusion methods for improving classification performance.</bold></p>
<p>In complex and diverse application scenarios, steganographer identification faces increasingly severe challenges. Existing research often relies on single-modal features, which have certain limitations. Strongly representative features can facilitate models in discover patterns and rules in data, thereby improving performance and generalization ability. One of the main challenges we encounter is performing multi-modal feature fusion to obtain richer feature representation for distinguish users. Research on this technique can further advance the development of steganographer identification.</p>
<p><bold>2. Extraction of distinguishable side channel feature.</bold></p>
<p>Steganographers in social networks often exhibit distinct behavioral features compared to normal users, which can used as a side channel. Further exploration of individual behavioral features based on specific application scenarios, such as posting behavior, social interaction patterns, and topic preferences, etc. is recommended. Additionally, combining user behavior with image features for multi-modal information fusion shows promise for future developments in this field. It is important to note that as the number of available features and information increases, the time required for model training and tuning will also increase. Therefore, investigating methods to simplify models while maintaining high performance is essential.</p>
<p><bold>3. Construction of models with strong generalization ability.</bold></p>
<p>The practical challenges in identifying steganographers include time-consuming classification of each user due to the wide variety of media types. Therefore, it is necessary to explore methods for improving model efficiency. Additionally, the diversity of image sources poses an impossible challenge in steganographer identification, leading to a mismatch problem. Hence, future research should focus on Transfer Learning, Domain-Adaptive techniques, and other methods that establish connections between images from different sources to enhance the model&#x2019;s generalization ability and identification accuracy.</p>
<p><bold>4. Active defense of AIGC steganography in social networks.</bold></p>
<p>The development of artificial intelligence has led to the emergence of AI Generated Content (AIGC), which encompasses text, image, audio, and video. However, as AIGC applications become more widespread, concerns regarding privacy and security arise. Malicious user attacks pose a significant threat to the data security of AIGC. These users can manipulate the AIGC model by injecting false data samples to generate misleading or harmful outcomes in the content it produces. They may also exploit generative steganography techniques for covert communication and illegal activities, posing risks to individual privacy and network security. Therefore, researching active defense techniques in steganography is crucial for preventing covert communication failures and tracing AIGC on social networks.</p>
<p>Nowadays, image steganographer identification is still challenging in many aspects, and we highlight some future research directions as follows:</p>
<p><bold>1. Looking for new methods of user feature fusion.</bold></p>
<p>The existing methods often rely on a single type of user data for training and prediction. In the future, it is worth considering fusing and aligning different modal information from users to enhance model performance using multiple modalities.</p>
<p><bold>2. Designing robust identification model.</bold></p>
<p>Although most of the advanced works in the literature are based on two general frameworks for steganographer identification, i.e., clustering-based detection and outlier-based detection, there are significant issues of data imbalance and scarce labels in real-world scenario. In future research, more efforts can be made to address these problems and improve the reliability of identification models.</p>
<p><bold>3. Researching cross-domain covert communication defense.</bold></p>
<p>The potential applications of steganographer identification technology can be explored in various disciplines, enhancing its practical value and effectiveness when combined with cyberspace security, digital forensics, antifraud, and other fields.</p>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion</title>
<p>This survey has extensively reviewed steganographer identification, a pivotal security technique that can provide comprehensive security protection by defending against malicious covert communication. First, we introduce the research background and outline the issue of steganographer identification. Then, a general framework for steganographer identification is introduced, and the existing methods are presented in detail based on this framework. Besides that, the advantages and limitations of these methods are uncovered by comparing them experimentally and theoretically. We find that feature extraction strategies, such as image features or behavioral features, affect the accuracy of identification results, which means that proper feature extraction approaches may lead to better identification performance. Moreover, the latest identification models based on graph neural network perform better. We also find that, in main channel steganographer identification, the dimension of image features significantly affects the identification performance. Therefore, a suitable feature dimension reduction method can obtain good performance. At last, we discuss the possible future issues of steganographer identification, and demonstrate the potential research directions.</p>
</sec>
</body>
<back>
<ack><p>The authors would like to express our sincere gratitude and appreciation to each other for our combined efforts and contributions throughout the course of this research paper.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This work is supported by the National Key Research and Development Program of China (No. 2022YFB3102900), the National Natural Science Foundation of China (Nos. 62172435, 62202495 and 62002103), Zhongyuan Science and Technology Innovation Leading Talent Project of China (No. 214200510019), Key Research and Development Project of Henan Province (No. 2211321200), the Natural Science Foundation of Henan Province (No. 222300420058).</p>
</sec>
<sec><title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: study conception and design: Qiangqian Zhang, Yi Zhang and Xiangyang Luo; data collection and analysis: Qianqian Zhang, Yuanyuan Ma and Yanmei Liu; draft manuscript preparation: Qianqian Zhang. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>In the study, we used the Bossbase1.01 and Bows2 datasets, which are publicly available and can be accessed via the citation links in the paper.</p>
</sec>
<sec><title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p></sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Quaternary quantized gaussian modulation with optimal polarity map selection for JPEG steganography</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensics Secur.</source>, vol. <volume>18</volume>, pp. <fpage>5026</fpage>&#x2013;<lpage>5040</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2023.3303715</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Luo</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Fang</surname></string-name></person-group>, &#x201C;<article-title>Audio steganography based on iterative adversarial attacks against convolutional neural networks</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensics Secur.</source>, vol. <volume>15</volume>, pp. <fpage>2282</fpage>&#x2013;<lpage>2294</lpage>, <year>Apr. 2020</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2019.2963764</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Fan</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Zhao</surname></string-name></person-group>, &#x201C;<article-title>Adaptive QIM with minimum embedding cost for robust video steganography on social networks</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>17</volume>, pp. <fpage>3801</fpage>&#x2013;<lpage>3815</lpage>, <year>Apr. 2022</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2022.3215901</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Bao</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Huang</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Jiao</surname></string-name></person-group>, &#x201C;<article-title>Linguistic steganalysis via densely connected LSTM with feature pyramid</article-title>,&#x201D; in <conf-name>Proc. IH&#x0026;MMSec</conf-name>, <publisher-loc>Denver, CO, USA</publisher-loc>, <year>2020</year>, pp. <fpage>2282</fpage>&#x2013;<lpage>2294</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. V.</given-names> <surname>Desai</surname></string-name></person-group>, &#x201C;<article-title>Steganography, cryptography, watermarking: A comparative study</article-title>,&#x201D; <source>J. Glob. Res. Comput. Sci.</source>, vol. <volume>3</volume>, no. <issue>12</issue>, pp. <fpage>33</fpage>&#x2013;<lpage>35</lpage>, <year>Apr. 2012</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Wiseman</surname></string-name></person-group>, &#x201C;<chapter-title>Stegware&#x2013;Using steganography for malicious purposes</chapter-title>,&#x201D; in <source>Technical Report DS-2017-4</source>. <publisher-loc>Malvern, UK</publisher-loc>: <publisher-name>Everfox</publisher-name>, <year>2017</year>.doi: <pub-id pub-id-type="doi">10.13140/RG.2.2.15283.53289</pub-id></mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Bak</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Bieniasz</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Krzemi&#x0144;ski</surname></string-name>, and <string-name><given-names>K.</given-names> <surname>Szczypiorski</surname></string-name></person-group>, &#x201C;<article-title>Application of perfectly undetectable network steganography method for malware hidden communication</article-title>,&#x201D; in <conf-name>Proc. Int. Conf. Front. Signal Process. (ICFSP)</conf-name>, <publisher-loc>Poitiers, France</publisher-loc>, <year>2018</year>, pp. <fpage>34</fpage>&#x2013;<lpage>38</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Zou</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Tu</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>Linguistic steganalysis toward social network</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>18</volume>, pp. <fpage>859</fpage>&#x2013;<lpage>871</lpage>, <year>Apr. 2022</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2022.3226909</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Qiao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Xu</surname></string-name>, and <string-name><given-names>Z.</given-names> <surname>Qian</surname></string-name></person-group>, &#x201C;<article-title>Adaptive steganalysis based on statistical model of quantized DCT coefficients for JPEG images</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>18</volume>, no. <issue>6</issue>, pp. <fpage>2736</fpage>&#x2013;<lpage>2751</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2019.2962672</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Xue</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Kong</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Peng</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Zhong</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Wen</surname></string-name></person-group>, &#x201C;<article-title>An effective linguistic steganalysis framework based on hierarchical mutual learning</article-title>,&#x201D; <source>Inf. Sci.</source>, vol. <volume>586</volume>, pp. <fpage>140</fpage>&#x2013;<lpage>154</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ins.2021.11.086</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Xiong</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Fu</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>A universal audio steganalysis scheme based on multiscale spectrograms and DeepResNet</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, pp. <fpage>665</fpage>&#x2013;<lpage>679</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2022.3141121</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tan</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>Universal deep network for steganalysis of color image based on channel representation</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>17</volume>, pp. <fpage>3022</fpage>&#x2013;<lpage>3036</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2022.3196265</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Jung</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Bae</surname></string-name>, <string-name><given-names>H. -S.</given-names> <surname>Choi</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Yoon</surname></string-name></person-group>, &#x201C;<article-title>PixelSteganalysis: Pixel-wise hidden information removal with low visual degradation</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, pp. <fpage>331</fpage>&#x2013;<lpage>342</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2021.3132987</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Yang</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Extracting embedded messages using adaptive steganography based on optimal syndrome-trellis decoding paths</article-title>,&#x201D; <source>Digit. Commun. Netw.</source>, vol. <volume>8</volume>, pp. <fpage>455</fpage>&#x2013;<lpage>465</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1016/j.dcan.2021.09.005</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Shuo</surname></string-name></person-group>, &#x201C;<article-title>Recent advances in image-based steganalysis research</article-title>,&#x201D; (in Chinese), <source>Chin. J. Comput.</source>, vol. <volume>32</volume>, no. <issue>7</issue>, pp. <fpage>1247</fpage>&#x2013;<lpage>1263</lpage>, <year>Apr. 2009</year>. doi: <pub-id pub-id-type="doi">10.3724/SP.J.1016.2009.01247</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Zhong</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Qian</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Batch steganography via generative network</article-title>,&#x201D; <source>IEEE Trans. Circuits Syst. Video Technol.</source>, vol. <volume>31</volume>, no. <issue>1</issue>, pp. <fpage>88</fpage>&#x2013;<lpage>97</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TCSVT.2020.2974884</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Sewak</surname></string-name></person-group>, &#x201C;<article-title>Introduction to deep learning</article-title>,&#x201D; <source>Adv. Deep Learn. Eng. Sci.</source>, vol. <volume>5</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1007/978-3-030-66519-7_1</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>Cover reproducible steganography via deep generative models</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, pp. <fpage>3787</fpage>&#x2013;<lpage>3798</lpage>, <year>Apr. 2022</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2022.3217569</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Barni</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>An automatic cost learning framework for image steganography using deep reinforcement learning</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>16</volume>, pp. <fpage>952</fpage>&#x2013;<lpage>967</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2020.3025438</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Mou</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Song</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Ghanem</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Large-capacity and flexible video steganography via invertible neural network</article-title>,&#x201D; in <conf-name>Proc. IEEE/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)</conf-name>, <publisher-loc>Vancouver, BC, Canada</publisher-loc>, <year>2023</year>, pp. <fpage>22606</fpage>&#x2013;<lpage>22615</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Tang</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>Steganography embedding cost learning with generative multi-adversarial network</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>19</volume>, pp. <fpage>15</fpage>&#x2013;<lpage>29</lpage>, <year>Apr. 2024</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2023.3318939</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Zhu</surname></string-name></person-group>, &#x201C;<article-title>Passive defense against 3D adversarial point clouds through the lens of 3D steganalysis</article-title>,&#x201D; <comment>2022, <italic>arXiv:2205.08738v1</italic></comment>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Liu</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Adaptive feature selection for image steganalysis based on classification metrics</article-title>,&#x201D; <source>Inf. Sci.</source>, vol. <volume>644</volume>, <year>Apr. 2023, Art. no. 118973</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ins.2023.118973</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Du</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>X. Y.</given-names> <surname>Luo</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Extraction method of secret message based on optimal hypothesis test</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, pp. <fpage>5265</fpage>&#x2013;<lpage>5277</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2023.3243907</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Wu</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection via multi-scale embedding probability estimation</article-title>,&#x201D; <source>ACM Trans. Multim. Comput. Commun. Appl.</source>, vol. <volume>15</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>23</lpage>, <year>Apr. 2020</year>. doi: <pub-id pub-id-type="doi">10.1145/3352691</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Francis-Christie</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Lo</surname></string-name></person-group>, &#x201C;<article-title>A combination of active and passive video steganalysis to fight sensitive data exfiltration through online video</article-title>,&#x201D; in <conf-name>Proc. IEEE Annu. Comput. Softw. Appl. Conf.</conf-name>, <publisher-loc>Atlanta, GA, USA</publisher-loc>, <year>2016</year>, pp. <fpage>371</fpage>&#x2013;<lpage>376</lpage>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Qian</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Destroying robust steganography in online social networks</article-title>,&#x201D; <source>Inf. Sci.</source>, vol. <volume>581</volume>, pp. <fpage>605</fpage>&#x2013;<lpage>619</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ins.2021.10.023</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Qian</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Image sanitization in online social networks: A general framework for breaking robust information hiding</article-title>,&#x201D; <source>IEEE Trans. Circuits Syst. Video Technol.</source>, vol. <volume>33</volume>, pp. <fpage>3017</fpage>&#x2013;<lpage>3029</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TCSVT.2022.3224243</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Feng</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Qian</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Diversity-based cascade filters for JPEG steganalysis</article-title>,&#x201D; <source>IEEE Trans. Circuits Syst. Video Technol.</source>, vol. <volume>30</volume>, pp. <fpage>376</fpage>&#x2013;<lpage>386</lpage>, <year>Apr. 2020</year>. doi: <pub-id pub-id-type="doi">10.1109/TCSVT.2019.2891778</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Sachnev</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Sundararajan</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Suresh</surname></string-name></person-group>, &#x201C;<article-title>A new approach for JPEG steganalysis with a cognitive evolving ensembler and robust feature selection</article-title>,&#x201D; <source>Cogn. Comput.</source>, vol. <volume>15</volume>, no. <issue>2</issue>, pp. <fpage>751</fpage>&#x2013;<lpage>764</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1007/s12559-022-10087-3</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Chhikara</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>Information theoretic steganalysis of processed image LSB steganography</article-title>,&#x201D; <source>Multim. Tools Appl.</source>, vol. <volume>82</volume>, no. <issue>9</issue>, pp. <fpage>13595</fpage>&#x2013;<lpage>13615</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1007/s11042-022-13931-8</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Wu</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Shi</surname></string-name></person-group>, &#x201C;<article-title>Structural design of convolutional neural networks for steganalysis</article-title>,&#x201D; <source>IEEE Signal Process. Lett.</source>, vol. <volume>23</volume>, no. <issue>5</issue>, pp. <fpage>708</fpage>&#x2013;<lpage>712</lpage>, <year>Apr. 2016</year>. doi: <pub-id pub-id-type="doi">10.1109/LSP.2016.2548421</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Ye</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ni</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Yi</surname></string-name></person-group>, &#x201C;<article-title>Deep learning hierarchical representations for image steganalysis</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>12</volume>, pp. <fpage>2545</fpage>&#x2013;<lpage>2557</lpage>, <year>2017</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2017.2710946</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Boroumand</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>J. J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Deep residual network for steganalysis of digital images</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>14</volume>, pp. <fpage>1181</fpage>&#x2013;<lpage>1193</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2018.2871749</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ker</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name></person-group>, &#x201C;<article-title>Identifying a steganographer in realistic and heterogeneous data sets</article-title>,&#x201D; in <conf-name>Proc. Med. Watermarking, Secur., Forensic.</conf-name>, <publisher-loc>Burlingame, CA, USA</publisher-loc>, <year>2012</year>, <fpage>83030N</fpage>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ker</surname></string-name> <etal>et al.</etal></person-group>, &#x201C;<article-title>Moving steganography and steganalysis from the laboratory into the real world</article-title>,&#x201D; in <conf-name>Proc. IH&#x0026;MMSec</conf-name>, <publisher-loc>Montpellier, France</publisher-loc>, <year>2013</year>, pp. <fpage>45</fpage>&#x2013;<lpage>58</lpage>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Zakaria</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Chaumont</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Subsol</surname></string-name></person-group>, &#x201C;<article-title>Pooled steganalysis in JPEG: How to deal with the spreading strategy</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Workshop Inform. Forensic. Secur. (WIFS)</conf-name>, <publisher-loc>Delft, Netherlands</publisher-loc>, <year>2019</year>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Karampidis</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Kavallieratou</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Papadourakis</surname></string-name></person-group>, &#x201C;<article-title>A review of image steganalysis techniques for digital forensics</article-title>,&#x201D; <source>J. Inf. Secur. Appl.</source>, vol. <volume>40</volume>, pp. <fpage>217</fpage>&#x2013;<lpage>235</lpage>, <year>Apr. 2018</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jisa.2018.04.005</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Selvaraj</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Ezhilarasan</surname></string-name>, <string-name><given-names>S. L. J.</given-names> <surname>Wellington</surname></string-name>, and <string-name><given-names>A. R.</given-names> <surname>Sam</surname></string-name></person-group>, &#x201C;<article-title>Digital image steganalysis: A survey on paradigm shift from machine learning to deep learning-based techniques</article-title>,&#x201D; <source>IET Image Process</source>, vol. <volume>15</volume>, no. <issue>2</issue>, pp. <fpage>504</fpage>&#x2013;<lpage>522</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1049/ipr2.12043</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Ruan</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wan</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Qi</surname></string-name></person-group>, &#x201C;<article-title>Deep learning for real-time image steganalysis: A survey</article-title>,&#x201D; <source>J. Real Time Image Process</source>, vol. <volume>17</volume>, no. <issue>1</issue>, pp. <fpage>149</fpage>&#x2013;<lpage>160</lpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.1007/s11554-019-00915-5</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Muralidharan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Cohen</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Cohen</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Nissim</surname></string-name></person-group>, &#x201C;<article-title>The infinite race between steganography and steganalysis in images</article-title>,&#x201D; <source>Signal Process</source>, vol. <volume>201</volume>, <year>Apr. 2022, Art. no. 108711</year>. doi: <pub-id pub-id-type="doi">10.1016/j.sigpro.2022.108711</pub-id>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ker</surname></string-name></person-group>, &#x201C;<article-title>Batch steganography and pooled steganalysis</article-title>,&#x201D; in <conf-name>Proc. Int. Workshop Inform. Hiding</conf-name>, <publisher-loc>Alexandria, VA, USA</publisher-loc>, <year>2006</year>, pp. <fpage>265</fpage>&#x2013;<lpage>281</lpage>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Cogranne</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Sedighi</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Practical strategies for content-adaptive batch steganography and pooled steganalysis</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. Acoust., Speech Signal Process. (ICASSP)</conf-name>, <publisher-loc>New Orleans, LA, USA</publisher-loc>, <year>2017</year>, pp. <fpage>2122</fpage>&#x2013;<lpage>2126</lpage>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Qin</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhou</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>Adversarial batch image steganography against CNN-based pooled steganalysis</article-title>,&#x201D; <source>Signal Process</source>, vol. <volume>181</volume>, <year>Apr. 2021, Art. no. 107920</year>. doi: <pub-id pub-id-type="doi">10.1016/j.sigpro.2020.107920</pub-id>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. M.</given-names> <surname>Breunig</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Kriegel</surname></string-name>, <string-name><given-names>R. T.</given-names> <surname>Ng</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Sander</surname></string-name></person-group>, &#x201C;<article-title>LOF: Identifying density-based local outliers</article-title>,&#x201D; in <conf-name>Proc. ACM SIGMOD Conf. Int. Conf. Manage. Data</conf-name>, <publisher-loc>Dallas, TX, USA</publisher-loc>, <year>2000</year>, pp. <fpage>93</fpage>&#x2013;<lpage>104</lpage>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Kipf</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Welling</surname></string-name></person-group>, &#x201C;<article-title>Semi-supervised classification with graph convolutional networks</article-title>,&#x201D; <comment>2016, <italic>arXiv:1609.02907</italic></comment>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Barni</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>CNN-based adversarial embedding for image steganography</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>14</volume>, no. <issue>8</issue>, pp. <fpage>2074</fpage>&#x2013;<lpage>2087</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2019.2891237</pub-id>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ni</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>Efficient JPEG batch steganography using intrinsic energy of image contents</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>16</volume>, pp. <fpage>4544</fpage>&#x2013;<lpage>4558</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2021.3109464</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Feng</surname></string-name></person-group>, &#x201C;<article-title>Exploring abnormal behavior in swarm: Identify user using adversarial examples</article-title>,&#x201D; <source>IEEE Trans. Emerg. Top. Comput. Intell.</source>, vol. <volume>7</volume>, no. <issue>1</issue>, pp. <fpage>250</fpage>&#x2013;<lpage>260</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TETCI.2022.3201294</pub-id>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Subhedar</surname></string-name> and <string-name><given-names>V.</given-names> <surname>Mankar</surname></string-name></person-group>, &#x201C;<article-title>Curvelet transform and cover selection for secure steganography</article-title>,&#x201D; <source>Multim. Tools Appl.</source>, vol. <volume>77</volume>, no. <issue>7</issue>, pp. <fpage>8115</fpage>&#x2013;<lpage>8138</lpage>, <year>Apr. 2018</year>. doi: <pub-id pub-id-type="doi">10.1007/s11042-017-4706-x</pub-id>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Bas</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Filler</surname></string-name>, and <string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name></person-group>, &#x201C;<article-title>Break our steganographic system: The ins and outs of organizing boss</article-title>,&#x201D; in <conf-name>Proc. Inform. Hiding</conf-name>, <publisher-loc>Prague, Czech Republic</publisher-loc>, <year>2011</year>. doi: <pub-id pub-id-type="doi">10.1007/978-3-642-24178-9_5</pub-id>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Piva</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Barni</surname></string-name></person-group>, &#x201C;<article-title>The first bows contest: Break our watermarking system</article-title>,&#x201D; in <conf-name>Proc. Secur., Steganograp., Watermarking Multimed. Contents IX</conf-name>, <publisher-loc>San Jose, CA, USA</publisher-loc>, <year>2007</year>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. D.</given-names> <surname>Ker</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name></person-group>, &#x201C;<article-title>The steganographer is the outlier: Realistic large-scale steganalysis</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>9</volume>, no. <issue>9</issue>, pp. <fpage>1424</fpage>&#x2013;<lpage>1435</lpage>, <year>Apr. 2014</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2014.2336380</pub-id>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Lei</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Wen</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Bi</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Gu</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis over large-scale social networks with high-order joint features and clustering ensembles</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>11</volume>, no. <issue>2</issue>, pp. <fpage>344</fpage>&#x2013;<lpage>357</lpage>, <year>Apr. 2016</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2015.2496910</pub-id>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zha</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>Side channel steganalysis: When behavior is considered in steganographer detection</article-title>,&#x201D; <source>Multim. Tools Appl.</source>, vol. <volume>78</volume>, no. <issue>7</issue>, pp. <fpage>8041</fpage>&#x2013;<lpage>8055</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1007/s11042-018-6582-4</pub-id>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>Steganographic security analysis from side channel steganalysis and its complementary attacks</article-title>,&#x201D; <source>IEEE Trans. Multim.</source>, vol. <volume>22</volume>, no. <issue>10</issue>, pp. <fpage>2526</fpage>&#x2013;<lpage>2536</lpage>, <year>Apr. 2020</year>. doi: <pub-id pub-id-type="doi">10.1109/TMM.2019.2959909</pub-id>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hua Zhong</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection via enhancement-aware graph convolutional network</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. Multimed. Expo</conf-name>, <publisher-loc>London, UK</publisher-loc>, <year>2020</year>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection via a similarity accumulation graph convolutional network</article-title>,&#x201D; <source>Neural Netw.</source>, vol. <volume>136</volume>, pp. <fpage>97</fpage>&#x2013;<lpage>111</lpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1016/j.neunet.2020.12.026</pub-id>; <pub-id pub-id-type="pmid">33472131</pub-id></mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>M. A.</given-names> <surname>Russell</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Klassen</surname></string-name></person-group>, &#x201C;<source>Mining the Social Web: Data Mining Facebook, Twitter, LinkedIn, Google+, GitHub, and More</source>, <edition>2nd ed</edition>. <publisher-loc>Sebastopol, USA</publisher-loc>: <publisher-name>O&#x2019;Reilly Media Press</publisher-name>, <year>2013</year>, pp. <fpage>137</fpage>&#x2013;<lpage>138</lpage>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>The MNIST database of handwritten digit images for machine learning research</article-title>,&#x201D; <source>IEEE Signal Process. Mag.</source>, vol. <volume>29</volume>, no. <issue>6</issue>, pp. <fpage>141</fpage>&#x2013;<lpage>142</lpage>, <year>Apr. 2012</year>. doi: <pub-id pub-id-type="doi">10.1109/MSP.2012.2211477</pub-id>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Krizhevsky</surname></string-name></person-group>, &#x201C;<article-title>Learning multiple layers of features from tiny images</article-title>,&#x201D; <year>2009</year>. Accessed: Aug. 31, 2024. [Online]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.cs.utoronto.ca/~kriz/learning-features-2009-TR.pdf">https://www.cs.utoronto.ca/~kriz/learning-features-2009-TR.pdf</ext-link></mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J. J.</given-names> <surname>Fridrich</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Kodovsky</surname></string-name></person-group>, &#x201C;<article-title>Rich models for steganalysis of digital images</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>7</volume>, no. <issue>3</issue>, pp. <fpage>868</fpage>&#x2013;<lpage>882</lpage>, <year>Apr. 2012</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2012.2190402</pub-id>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Song</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis of adaptive JPEG steganography using 2D Gabor filters</article-title>,&#x201D; in <conf-name>Proc. ACM Workshop Inform. Hiding Multimed. Secur.</conf-name>, <publisher-loc>Portland, OR, USA</publisher-loc>, <year>2015</year>, pp. <fpage>15</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Qin</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>Distribution-preserving-based automatic data augmentation for deep image steganalysis</article-title>,&#x201D; <source>IEEE Trans. Multim.</source>, vol. <volume>24</volume>, pp. <fpage>4538</fpage>&#x2013;<lpage>4550</lpage>, <year>Apr. 2022</year>. doi: <pub-id pub-id-type="doi">10.1109/TMM.2021.3119994</pub-id>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A. D.</given-names> <surname>Ker</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name></person-group>, &#x201C;<article-title>A new paradigm for steganalysis via clustering</article-title>,&#x201D; in <conf-name>Proc. Med. Forensic. Secur. III</conf-name>, <publisher-loc>San Francisco, CA, USA</publisher-loc>, <year>2011</year>.</mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Multiclass detector of current steganographic methods for JPEG format</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>3</volume>, no. <issue>4</issue>, pp. <fpage>635</fpage>&#x2013;<lpage>650</lpage>, <year>Apr. 2008</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2008.2002936</pub-id>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Mauri</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Apolloni</surname></string-name>, and <string-name><given-names>E.</given-names> <surname>Damiani</surname></string-name></person-group>, &#x201C;<article-title>Robust ML model ensembles via riskdriven anti-clustering of training data</article-title>,&#x201D; <source>Inf. Sci.</source>, vol. <volume>633</volume>, pp. <fpage>122</fpage>&#x2013;<lpage>140</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ins.2023.03.085</pub-id>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Sedighi</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Cogranne</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Content-adaptive steganography by minimizing statistical detectability</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>11</volume>, no. <issue>2</issue>, pp. <fpage>221</fpage>&#x2013;<lpage>234</lpage>, <year>Apr. 2016</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2015.2486744</pub-id>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name></person-group>, &#x201C;<article-title>A new rule for cost reassignment in adaptive steganography</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>12</volume>, pp. <fpage>2654</fpage>&#x2013;<lpage>2667</lpage>, <year>Apr. 2017</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2017.2718480</pub-id>.</mixed-citation></ref>
<ref id="ref-70"><label>[70]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Wen</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Lei</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Ren</surname></string-name></person-group>, &#x201C;<article-title>Efficient steganographer detection over social networks with sampling reconstruction</article-title>,&#x201D; <source>Peer-to-Peer Netw. Appl.</source>, vol. <volume>11</volume>, no. <issue>5</issue>, pp. <fpage>924</fpage>&#x2013;<lpage>939</lpage>, <year>Apr. 2018</year>. doi: <pub-id pub-id-type="doi">10.1007/s12083-017-0603-3</pub-id>.</mixed-citation></ref>
<ref id="ref-71"><label>[71]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wu</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Jiang</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection via deep residual network</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. Multimed. Expo</conf-name>, <publisher-loc>Hong Kong, China</publisher-loc>, <year>2017</year>, pp. <fpage>235</fpage>&#x2013;<lpage>240</lpage>.</mixed-citation></ref>
<ref id="ref-72"><label>[72]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis via deep residual network</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. Parallel Distrib. Syst. (ICPADS)</conf-name>, <publisher-loc>Wuhan, China</publisher-loc>, <year>2016</year>, pp. <fpage>1233</fpage>&#x2013;<lpage>1236</lpage>.</mixed-citation></ref>
<ref id="ref-73"><label>[73]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Kong</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Feng</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Guo</surname></string-name></person-group>, &#x201C;<article-title>Iterative multi-order feature alignment for JPEG mismatched steganalysis</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>214</volume>, pp. <fpage>458</fpage>&#x2013;<lpage>470</lpage>, <year>Apr. 2016</year>. doi: <pub-id pub-id-type="doi">10.1016/j.neucom.2016.06.037</pub-id>.</mixed-citation></ref>
<ref id="ref-74"><label>[74]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Meg&#x2019;ias</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Lerch-Hostalot</surname></string-name></person-group>, &#x201C;<article-title>Subsequent embedding in targeted image steganalysis: Theoretical framework and practical applications</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, no. <issue>2</issue>, pp. <fpage>1403</fpage>&#x2013;<lpage>1421</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2022.3154967</pub-id>.</mixed-citation></ref>
<ref id="ref-75"><label>[75]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hua Zhong</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wu</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Jiang</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection based on multiclass dilated residual networks</article-title>,&#x201D; in <conf-name>Proc. ACM Int. Conf. Multimed. Retr.</conf-name>, <publisher-loc>Yokohama, Japan</publisher-loc>, <year>2018</year>, pp. <fpage>300</fpage>&#x2013;<lpage>308</lpage>.</mixed-citation></ref>
<ref id="ref-76"><label>[76]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Denemark</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Boroumand</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis features for content-adaptive JPEG steganography</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>11</volume>, pp. <fpage>1736</fpage>&#x2013;<lpage>1746</lpage>, <year>Apr. 2016</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2016.2555281</pub-id>.</mixed-citation></ref>
<ref id="ref-77"><label>[77]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Zheng</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Jiang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name>, and <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Content-adaptive selective steganographer detection via embedding probability estimation deep networks</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>365</volume>, pp. <fpage>336</fpage>&#x2013;<lpage>348</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1016/j.neucom.2019.07.068</pub-id>.</mixed-citation></ref>
<ref id="ref-78"><label>[78]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>E.</given-names> <surname>Shelhamer</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Long</surname></string-name>, and <string-name><given-names>T.</given-names> <surname>Darrell</surname></string-name></person-group>, &#x201C;<article-title>Fully convolutional networks for semantic segmentation</article-title>,&#x201D; in <conf-name>Proc. IEEE Conf. Comput. Vis. Pattern Recognit.</conf-name>, <publisher-loc>Boston, MA, USA</publisher-loc>, <year>2014</year>, pp. <fpage>3431</fpage>&#x2013;<lpage>3440</lpage>.</mixed-citation></ref>
<ref id="ref-79"><label>[79]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Luo</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Mishra</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Achkar</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Eichel</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Jodoin</surname></string-name></person-group>, &#x201C;<article-title>Non-local deep features for salient object detection</article-title>,&#x201D; in <conf-name>Proc. IEEE Conf. Comput. Vis. Pattern Recognit.</conf-name>, <publisher-loc>Honolulu, HI, USA</publisher-loc>, <year>2017</year>, pp. <fpage>6593</fpage>&#x2013;<lpage>6601</lpage>.</mixed-citation></ref>
<ref id="ref-80"><label>[80]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E.</given-names> <surname>Amrutha</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Arivazhagan</surname></string-name>, and <string-name><given-names>W.</given-names> <surname>Jebarani</surname></string-name></person-group>, &#x201C;<article-title>Deep clustering network for steganographer detection using latent features extracted from a novel convolutional autoencoder</article-title>,&#x201D; <source>Neural Process. Lett.</source>, vol. <volume>55</volume>, no. <issue>3</issue>, pp. <fpage>2953</fpage>&#x2013;<lpage>2964</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1007/s11063-022-10992-6</pub-id>.</mixed-citation></ref>
<ref id="ref-81"><label>[81]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O.</given-names> <surname>Evsutin</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Kokurina</surname></string-name>, and <string-name><given-names>R.</given-names> <surname>Meshcheryakov</surname></string-name></person-group>, &#x201C;<article-title>Approach to the selection of the best cover image for information embedding in JPEG images based on the principles of the optimality</article-title>,&#x201D; <source>J. Decis. Syst.</source>, vol. <volume>27</volume>, pp. <fpage>256</fpage>&#x2013;<lpage>264</lpage>, <year>Apr. 2018</year>. doi: <pub-id pub-id-type="doi">10.1080/12460125.2018.1460163</pub-id>.</mixed-citation></ref>
<ref id="ref-82"><label>[82]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Sajedi</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Jamzad</surname></string-name></person-group>, &#x201C;<article-title>Cover selection steganography method based on similarity of image blocks</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Conf. Comput. Inform. Technol. Workshops</conf-name>, <publisher-loc>Sydney, Australia</publisher-loc>, <year>2008</year>, pp. <fpage>379</fpage>&#x2013;<lpage>384</lpage>.</mixed-citation></ref>
<ref id="ref-83"><label>[83]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Li</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Towards improved steganalysis: When cover selection is used in steganography</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, pp. <fpage>168914</fpage>&#x2013;<lpage>168921</lpage>, <year>Apr. 2019</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2019.2955113</pub-id>.</mixed-citation></ref>
<ref id="ref-84"><label>[84]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Kharrazi</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Sencar</surname></string-name>, and <string-name><given-names>N.</given-names> <surname>Memon</surname></string-name></person-group>, &#x201C;<article-title>Cover selection for steganographic embedding</article-title>,&#x201D; in <conf-name>Proc. Int. Conf. Image Process.</conf-name>, <publisher-loc>Atlanta, GA, USA</publisher-loc>, <year>2006</year>, pp. <fpage>117</fpage>&#x2013;<lpage>120</lpage>.</mixed-citation></ref>
<ref id="ref-85"><label>[85]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Feng</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Shen</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Cover selection for steganography using image similarity</article-title>,&#x201D; <source>IEEE Trans. Dependable Secur. Comput.</source>, vol. <volume>20</volume>, no. <issue>3</issue>, pp. <fpage>2328</fpage>&#x2013;<lpage>2340</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.1109/TDSC.2022.3181039</pub-id>.</mixed-citation></ref>
<ref id="ref-86"><label>[86]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Goljan</surname></string-name>, and <string-name><given-names>D.</given-names> <surname>Hogea</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis of JPEG images: Breaking the F5 algorithm</article-title>,&#x201D; in <conf-name>Proc. Inform. Hiding</conf-name>, <publisher-loc>Noordwijkerhout, Netherlands</publisher-loc>, <year>2002</year>, pp. <fpage>310</fpage>&#x2013;<lpage>323</lpage>.</mixed-citation></ref>
<ref id="ref-87"><label>[87]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Kodovsky</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Calibration revisited</article-title>,&#x201D; in <conf-name>Proc. Workshop Multimed. Secur.</conf-name>, <publisher-loc>Princeton, NJ, USA</publisher-loc>, <year>2009</year>, pp. <fpage>63</fpage>&#x2013;<lpage>74</lpage>.</mixed-citation></ref>
<ref id="ref-88"><label>[88]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Holub</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Low-complexity features for JPEG steganalysis using undecimated DCT</article-title>,&#x201D; <source>IEEE Trans. Inf. Forensic. Secur.</source>, vol. <volume>10</volume>, no. <issue>2</issue>, pp. <fpage>219</fpage>&#x2013;<lpage>228</lpage>, <year>Apr. 2015</year>. doi: <pub-id pub-id-type="doi">10.1109/TIFS.2014.2364918</pub-id>.</mixed-citation></ref>
<ref id="ref-89"><label>[89]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Holub</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Fridrich</surname></string-name></person-group>, &#x201C;<article-title>Phase-aware projection model for steganalysis of JPEG images</article-title>,&#x201D; in <conf-name>Proc. Med. Watermarking, Secur., Forensic.</conf-name>, <publisher-loc>San Francisco, CA, USA</publisher-loc>, <year>2015</year>, pp. <fpage>259</fpage>&#x2013;<lpage>269</lpage>.</mixed-citation></ref>
<ref id="ref-90"><label>[90]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Ker</surname></string-name></person-group>, &#x201C;<article-title>The challenges of rich features in universal steganalysis</article-title>,&#x201D; in <conf-name>Proc. Med. Watermarking, Secur., Forensic.</conf-name>, <publisher-loc>Burlingame, CA, USA</publisher-loc>, <year>2013</year>, pp. <fpage>203</fpage>&#x2013; <lpage>217</lpage>.</mixed-citation></ref>
<ref id="ref-91"><label>[91]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Zhang</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name></person-group>, &#x201C;<article-title>Steganalysis feature selection with multidimensional evaluation &#x0026; dynamic threshold allocation</article-title>,&#x201D; <source>IEEE Trans. Circuits Syst. Video Technol.</source>, vol. <volume>34</volume>, no. <issue>3</issue>, pp. <fpage>1954</fpage>&#x2013;<lpage>1969</lpage>, <year>Apr. 2024</year>. doi: <pub-id pub-id-type="doi">10.1109/TCSVT.2023.3295364</pub-id>.</mixed-citation></ref>
<ref id="ref-92"><label>[92]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Ma</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Luo</surname></string-name></person-group>, &#x201C;<article-title>Steganographer identification of JPEG image based on feature selection and graph convolutional representation</article-title>,&#x201D; (in Chinese), <source>J. Commun.</source>, vol. <volume>44</volume>, no. <issue>7</issue>, pp. <fpage>218</fpage>&#x2013;<lpage>229</lpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.11959/j.issn.1000</pub-id>.</mixed-citation></ref>
<ref id="ref-93"><label>[93]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Wu</surname></string-name></person-group>, &#x201C;<article-title>Feature bagging for steganographer identification</article-title>,&#x201D; <comment>2018, <italic>arXiv:1810.11973</italic></comment>.</mixed-citation></ref>
<ref id="ref-94"><label>[94]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Lazarevic</surname></string-name> and <string-name><given-names>V.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>Feature bagging for outlier detection</article-title>,&#x201D; in <conf-name>Proc. Knowl. Discov. Data Min.</conf-name>, <publisher-loc>Chicago, MI, USA</publisher-loc>, <year>2005</year>, pp. <fpage>157</fpage>&#x2013;<lpage>166</lpage>.</mixed-citation></ref>
<ref id="ref-95"><label>[95]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Dong</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Lei</surname></string-name>, and <string-name><given-names>X.</given-names> <surname>Bai</surname></string-name></person-group>, &#x201C;<article-title>MSCNN: Steganographer detection based on multi-scale convolutional neural networks</article-title>,&#x201D; in <conf-name>Proc. Wireless Algorithms, Syst., Appl.</conf-name>, <publisher-loc>Nanjing, China</publisher-loc>, <year>2021</year>, pp. <fpage>215</fpage>&#x2013;<lpage>226</lpage>.</mixed-citation></ref>
<ref id="ref-96"><label>[96]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Krizhevsky</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Sutskever</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Hinton</surname></string-name></person-group>, &#x201C;<article-title>ImageNet classification with deep convolutional neural networks</article-title>,&#x201D; in <conf-name>Proc. Neural Inform. Process. Syst.</conf-name>, <publisher-loc>Lake Tahoe, CA, USA</publisher-loc>, <year>2012</year>, pp. <fpage>84</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation></ref>
<ref id="ref-97"><label>[97]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Zhong</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Steganographer detection via multiple-instance learning graph convolutional networks</article-title>,&#x201D; (in Chinese), <source>Acta Automatica Sinica</source>, vol. <volume>50</volume>, no. <issue>4</issue>, pp. <fpage>771</fpage>&#x2013;<lpage>789</lpage>, <year>Apr. 2024</year>. doi: <pub-id pub-id-type="doi">10.1145/3065386</pub-id>.</mixed-citation></ref>
<ref id="ref-98"><label>[98]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Pevny</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Nikolaev</surname></string-name></person-group>, &#x201C;<article-title>Optimizing pooling function for pooled steganalysis</article-title>,&#x201D; in <conf-name>Proc. IEEE Int. Workshop Inform. Forensic. Secur.</conf-name>, <publisher-loc>Roma, Italy</publisher-loc>, <year>2015</year>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
</ref-list>
</back></article>