Skip to content
Open access

Steganography and Probabilistic Risk Analysis: A Game Theoretical Framework for Quantifying Adversary Advantage and Impact

Dec 2024 · PeerJ Computer Science · Vol abs/2412.17950 · 0 citations · 170 references
Computer Science

TL;DR

A game-theoretic model of steganographic operations that captures the strategic interaction between a defender and an adversary through calibrated monetary primitives and nonlinear utility mappings is presented, and adversarial advantage can be translated into interpretable monetary risk estimates for assessing whether steganographic defences decrease, amplify, or only marginally affect organisational exposure.

Abstract

In environments where adversaries engage in active surveillance and covert communication, defenders face the dual challenge of when to deploy steganography and whether it yields measurable operational benefit. We present a game-theoretic model of steganographic operations that captures the strategic interaction between a defender and an adversary through calibrated monetary primitives and nonlinear utility mappings. The model derives mixed-strategy equilibria that determine conditional and unconditional success rates for hiding and detection, and introduces a time-varying adversarial advantage metric that quantifies when an attacker’s incentive exceeds the defender’s effective concealment or detection capability. By linking this advantage to a currency-unit risk measure, we extend the classical risk formulation into a decision-aware, monetised framework. The quantitative evaluation combines nonlinear equilibrium analysis, a Monte Carlo ensemble of 10,000 draws, and empirical calibration on Break Our Steganographic System database (BOSSbase) 1.01 using four spatial-domain adaptive steganographic methods: Wavelet Obtained Weights (WOW), Spatial Universal Wavelet Relative Distortion (S-UNIWARD), High-pass, Low-pass and Low-pass (HILL), and Minimising the Probability of Detection (MiPOD). The payloads are 0.100, 0.200, and 0.400 bits per pixel. Two lightweight convolutional neural-network steganalysis back-ends are used to estimate the defender signal, defined as 1 − TPR@FPR = 0.10. The aggregated trajectories show persistent positive adversarial advantage in most configurations, with mean normalised advantage reaching 0.22 and maximum normalised risk reaching 0.20. Lower-risk cases show average positive advantage of approximately 0.01, while higher-risk regimes reach approximately 0.18 to 0.19. In the monetary setting, the maximum epoch-level risk reaches £210,375, high-risk configurations produce mean risks close to £196,000, and the maximum observed security benefit is £11,250. Detector performance further shows best-epoch area under the curve (AUC) values of at least 0.95 for the more stable detector, while the more volatile detector produces defender-signal values spanning approximately 0.015 to 0.915. These results show that adversarial advantage can be translated into interpretable monetary risk estimates for assessing whether steganographic defences decrease, amplify, or only marginally affect organisational exposure.

Read PDF

Similar papers

Conference Aug 2026

Game-Theoretic Defense Against Hardware Trojans with Multi-Level Strategies

Hardware Trojans are malicious circuit modifications that can be covertly inserted during the design or fabrication of integrated circuits, enabling leakage, performance degradation, or mission failure after deployment. Because exhaustive testing against all Trojan classes and activation behaviors are prohibitively expensive, effective defense requires reasoning about the strategic interaction between an IC buyer/tester and a potentially malicious manufacturer. In this paper, we model Hardware Trojan insertion and testing as a two-player zero-sum security game with multi-level attacker and defender intensities. We first derive the Mixed-Strategy Nash Equilibrium (MSNE) under classical expected-utility assumptions and identify parameter regimes in which the game reduces to a smaller equilibrium over the remaining dominant strategies. Recognizing that real decision-makers exhibit bounded rationality, loss aversion, and distorted probability perceptionespecially under low-probability, high-impact threats-we then incorporate Prospect Theory to obtain a ProspectTheoretic MSNE (PT-MSNE) formulation. The resulting equilibrium conditions are nonlinear and are computed numerically under simplex constraints. Extensive simulations quantify how behavioral parameters reshape equilibrium mixing, shift the security-cost tradeoff, and alter defensive investment relative to the rational benchmark, providing actionable insights for designing robust and cost-effective Trojan testing policies under uncertainty and human bias.

Soraya Partow, Satyaki Nan · 0 citations
Preprint Jul 2026

Game of Coding under Computation-Dependent Adversarial Noise

The game of coding framework was introduced to extend coding-theoretic recovery beyond its traditional limit, under which the number of honest reports must exceed the number of adversarial or corrupted reports. It does so by exploiting the rational behavior of adversarial participants and their incentive to keep the system live. Existing game-of-coding formulations, however, assume that the adversarial-noise distribution is independent of the realized ground-truth computation. This assumption may be restrictive when an informed adversary can adapt its reports to the value being computed. In this paper, we study the game of coding with input-dependent adversarial noise. We introduce a unified multi-node, multidimensional formulation. For every family of conditional adversarial-noise distributions, we construct an input-independent joint noise distribution, and prove that this reduction exactly preserves the probability of acceptance and the accepted mean-squared estimation error. Consequently, the input-dependent and input-independent models have identical achievable performance regions, and the same equilibrium utilities.

Hanzaleh Akbari Nodehi, M. Maddah-ali · 0 citations
Preprint Jul 2026

The Power of Backdoor Absorption in Community Training

Backdoor attacks severely threaten large-scale AI models. When model owners delegate training to external compute providers within a decentralized training paradigm, adversaries can craft stealthy, low-frequency triggers to inject malicious behavior while evading standard audits. Traditionally, detecting these attacks requires a full re-computation of the training steps--a prohibitive overhead that directly contradicts the owner's resource constraints. To address this, we investigate the resilience of continuous optimization dynamics under Byzantine perturbations, where adversaries are forced to compete against a continuous influx of honest updates. Under a threat model where an adversary compromises f out of n total trainers, we quantify the minimum auditing overhead required by the model owner to probabilistically bound the attack success rate. We formalize this injection-absorption dynamic as a Discrete-Time Markov Chain (DTMC). Using this framework, we prove that the success probability of any bounded adversary asymptotically collapses to zero under a defense strategy combining natural absorption, a randomized scheduler, and lazy verification oracle. Empirical results demonstrate significant backdoor suppression with zero utility degradation even when invoking the verification oracle on merely 10% of the total training steps. This approach yields a provably sound and computationally efficient defense for safety-critical AI.

Issam Seddik, Sami Souihi, Mohamed Tamaazousti et al. · 0 citations
Open access 2026

HEbdMIA: Lightweight Logit Encryption for Membership Inference Defense

: Membership Inference Attacks (MIAs) pose a significant privacy risk in machine learning by enabling adversaries to infer whether specific data samples were used during training, particularly in sensitive domains such as social media and mental health analytics. To address this challenge, this paper proposes HEbdMIA, a lightweight homomorphic encryption-based defense that operates at the post-inference stage by encrypting model output logits without requiring retraining or architectural modifications. The proposed approach preserves the relative ordering of predictions while obscuring confidence patterns exploited by MIAs. Experimental evaluation on DepInferAttack and BotInferAttack demonstrates that HEbdMIA achieves a reduction in MIA success rates of 31.0% and 27.3%, respectively, with an associated accuracy decrease of 29.3% and 26.4%, reflecting a controlled privacy and utility trade off. Additional analysis using precision, recall, F1-score, and ROC-AUC confirms a substantial decline in adversarial inference capability. These findings indicate that HEbdMIA provides an effective, scalable, and deployment-friendly solution for enhancing privacy in real-world machine learning systems.

Akash Shah, M. A. Wani, R. Chaturvedi et al. · 0 citations
Conference Open access 2026

Adversarial Distance Metrics: A Threat to Fairness in Clustering-Based Decision Systems

An insider adversary manipulates the distance function to induce discriminatory clustering outcomes against demographic groups, exposing a gap in current fairness auditing practices and demonstrating the urgent need to expand the scope of the algorithmic audit to include distance-function verification.

Shahzad Ahmad, Stefan Rass, Enes Sovtic · 0 citations