Score
Design and implement algorithms and pipelines that embed and recover Gaussian-distributed secret attributes within cover content in a scene-independent way, enabling feed-forward encoding and decoding that generalize to previously unseen scenes without per-scene finetuning. Build and evaluate the encoders, decoders, and associated metrics for fidelity, robustness, capacity, and detectability of the steganographic Gaussian attributes.
This work proposes the first general-purpose steganographic framework tailored for 3D Gaussian Splatting (3DGS), designed to embed meaningful 3D scene content in a lossless and imperceptible manner. By formulating 3D steganography as a feedforward Gaussian embedding process, the authors introduce the GAS network to learn a scene-agnostic embedding function that directly injects secret Gaussian attributes into carrier scenes without requiring per-scene fine-tuning. The method strategically structures 3D Gaussian attributes to align with 2D learning paradigms, substantially enhancing generalization to unseen scenes. Experimental results demonstrate that the proposed framework achieves high visual fidelity across multiple datasets while outperforming existing approaches in both payload capacity and security.
Existing 3D Gaussian Splatting (3DGS) steganography methods struggle to balance imperceptibility and reconstruction fidelity, while suffering from suboptimal feature utilization and vulnerability to statistical detection. Method: We propose the first end-to-end, key-controllable 3DGS steganography framework. Contributions/Results: (1) A key-driven multi-secret embedding mechanism enables fine-grained access control and secure secret distribution; (2) We characterize the heterogeneous contributions of Gaussian ellipsoid parameters to steganographic distortion, guiding optimal feature-space selection; (3) We introduce the 3D-Sinkhorn distance to quantify geometric distribution perturbations in 3D space, establishing the first differentiable metric for 3D steganographic imperceptibility. Experiments demonstrate that our method achieves state-of-the-art reconstruction quality (PSNR/SSIM) while significantly enhancing robustness against statistical steganalysis—simultaneously ensuring high-fidelity cover reconstruction and high-accuracy secret recovery.
Existing diffusion model watermarking methods overlook practical deployment bottlenecks: cumbersome key management, variable user-defined generation parameters, and infeasible third-party verification. This paper proposes a robust, real-world-oriented watermarking framework. Methodologically, it (1) introduces a novel dual-channel architecture that decouples watermark embedding from verification; (2) models the generation-inversion process as an additive white Gaussian noise (AWGN) channel and designs a soft-decision decoder, significantly enhancing robustness across diverse sampling steps, schedulers, and inversion methods; and (3) integrates public-key digital signatures to enable open, forgery-resistant third-party verification without requiring access to the generative model. Experiments demonstrate that the method achieves zero degradation in image generation quality while fully supporting user-customizable parameters and trusted external verification—thereby overcoming critical barriers to real-world deployment.
Existing 3D Gaussian Splatting (3DGS)-based steganographic methods struggle to simultaneously achieve high capacity, strong security, and asset usability, while remaining vulnerable to structural perturbation attacks. This work proposes a rendering-agnostic unified steganographic framework that directly embeds 3D/4D information into the native 3DGS representation. By leveraging spherical harmonic frequency importance-aware encryption, hash-grid-guided opacity mapping, and a gradient-gated consistency loss, the method constructs a continuous and attack-resilient steganographic latent manifold. It preserves visual fidelity while improving message signal-to-noise ratio by 6.28 dB and accelerating rendering speed by 3×. The approach demonstrates robustness against structural attacks such as GSPure and generalizes effectively to both 2D images and dynamic 4D scenes.
To address the vulnerability of generative image watermarking—where watermarks are easily detectable and degrade image quality—this paper proposes the first theoretically provable undetectable watermarking scheme. Methodologically, it leverages pseudorandom error-correcting codes (PRCs) to modulate the initial latent variables of Stable Diffusion 2.1, enabling end-to-end embedding and extraction. Its core contributions are threefold: (1) computational indistinguishability—no efficient adversary can distinguish watermarked from unwatermarked images with non-negligible advantage; (2) strict zero-fidelity loss—no perceptual or measurable degradation in image quality; and (3) strong robustness—reliably encodes 512 bits under adversarial attacks and up to 2500 bits in benign conditions, while existing removal attacks induce severe visual distortion and thus fail. This work breaks the long-standing trade-off between robustness and fidelity in image watermarking.
This work addresses the security vulnerability of existing steganographic methods in large language models, which are often fully recoverable and thus prone to detection. To mitigate this risk, the authors propose a novel steganographic approach leveraging the geometric structure of the embedding space to significantly reduce message recoverability, and for the first time, utilize this structure to construct a covert communication channel. Additionally, they introduce an interpretability technique based on linear probing to effectively detect steganographic behavior in maliciously fine-tuned models. Experimental results on Llama-8B, Mistral-8B, and Llama-70B demonstrate that the proposed method substantially lowers the recoverability of hidden messages while improving detection accuracy by up to 33% over baseline approaches.
This work proposes a 3D steganographic method that embeds entire hidden 3D scenes into a single Instant-NGP model without modifying its architecture or increasing parameter count. By leveraging the hash encoding function as a key-controlled scene switcher, the approach interleaves neural representations of both cover and secret scenes within the same set of model weights, enabling steganography without requiring an external decoder. A multi-key assignment mechanism is introduced to substantially expand the key space and enhance robustness against partial key exposure. The method achieves high-capacity, highly imperceptible, and secure embedding of full 3D scenes while preserving the standard Instant-NGP framework and parameter efficiency.
This work addresses a critical security gap in existing generative AI watermarking techniques, which lack mechanisms for secure control over detection rights and are thus vulnerable to malicious removal, misuse, or exploitation for user profiling. To remedy this, the paper proposes the first undetectable watermarking scheme supporting fine-grained policy-based access control. The approach binds generated content to user attributes and restricts watermark verification to outputs that satisfy predefined policies through constrained use of detection keys. Built upon constrained pseudorandom functions, pseudorandom error-correcting codes, and a randomness-recovery mechanism, the system provides formal security guarantees within the generative model. Experimental results demonstrate that the scheme simultaneously achieves watermark validity, consistency, adaptive robustness, undetectability, and reliability, offering both practical utility and strong security assurances.
This work proposes a covert communication method for large language models (LLMs) that requires no modification to model weights, sampling logic, or output distributions. By exploiting the invertible mapping between pseudorandom number generator (PRNG) seeds and generated text under deterministic decoding, the approach encodes secret information into the PRNG seed and reconstructs the corresponding probability intervals from the output text to recover the seed. This study formally establishes the first fully non-intrusive steganographic channel in LLMs, challenging the assumption that unknown prompts guarantee security—even without prompt knowledge, secret information can be reliably retrieved. Experiments demonstrate that with a known prompt, a 32-bit seed is recovered with 100% accuracy within 300 tokens in approximately 35 seconds; under unknown prompts, near-perfect recovery is achieved within 600–800 tokens in about 12 seconds.
This work addresses the limitations of existing image steganalysis methods, which are predominantly confined to binary classification and rely on the assumption that training and test data share identical distributions, thereby struggling to detect reversible image hiding in real-world scenarios. To overcome these challenges, we propose the first zero-shot, interpretable steganalysis framework specifically designed for reversible image hiding. Our approach unifies hiding, recovery, and detection within a single architecture and incorporates a residual enhancement strategy to improve generalization across diverse datasets and model architectures. Notably, the method requires no target-domain training data and retains the capability to recover hidden messages. Extensive experiments on multiple benchmark datasets demonstrate its superior performance over state-of-the-art methods, confirming both its effectiveness and strong generalization ability.