<p>Cloud storage greatly facilitates large-scale image hosting but also exposes encrypted content to the risk of <i>visually plausible ciphertext-domain tampering</i> after decryption. Such a threat is particularly critical in secure cloud-based image storage and forensics, where the integrity of encrypted visual data must be reliably verified. To address this threat, we propose a dual-stage ciphertext-domain self-embedding fragile watermarking scheme based on Hamming codes, which enables lightweight user-side operation requiring only encryption. Specifically, the user encrypts the plaintext image with any secure algorithm and uploads the ciphertext to the cloud. Without decrypting, the cloud performs a two-stage Permutation Ordered Binary (POB) reversible compression, releasing about 4 bpp of embedding space while maintaining perfect reversibility. In this space, two types of watermarks are embedded: (i) distributed (7,4) Hamming-code-based parity bits across interleaved blocks for bit-level tamper localization and single-bit correction; and (ii) a keyed hash-assisted block authentication watermark (4 bits per <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(2\times 2\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mn>2</mn> <mo>×</mo> <mn>2</mn> </mrow> </math></EquationSource> </InlineEquation> block) for coarse-grained integrity verification. During detection, an adaptive mask-selection mechanism compares the reliability of pixel-level and block-level results and triggers a hybrid image recovery (IHR) process: sparse errors are corrected by Hamming decoding, whereas multi-bit conflicts are refined through prediction-based pixel recovery. Experimental results show that the proposed method outperforms existing schemes in both detection accuracy and reconstruction quality, achieving lossless recovery at <InlineEquation ID="IEq2"> <EquationSource Format="TEX">\(\gamma =6.25\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>γ</mi> <mo>=</mo> <mn>6.25</mn> <mo>%</mo> </mrow> </math></EquationSource> </InlineEquation> and improving PSNR by 7 to 12 dB over the representative ciphertext-domain watermarking method under moderate cropping attacks (<InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(\gamma =25\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>γ</mi> <mo>=</mo> <mn>25</mn> <mo>%</mo> </mrow> </math></EquationSource> </InlineEquation>).</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ciphertext-domain fragile watermarking using hamming codes for dual-stage tamper detection and recovery

  • Lingfeng Qu,
  • Xin Wang,
  • Jiayu Zhou,
  • Yuan Yuan,
  • Yaolin Yang,
  • Yao Xin

摘要

Cloud storage greatly facilitates large-scale image hosting but also exposes encrypted content to the risk of visually plausible ciphertext-domain tampering after decryption. Such a threat is particularly critical in secure cloud-based image storage and forensics, where the integrity of encrypted visual data must be reliably verified. To address this threat, we propose a dual-stage ciphertext-domain self-embedding fragile watermarking scheme based on Hamming codes, which enables lightweight user-side operation requiring only encryption. Specifically, the user encrypts the plaintext image with any secure algorithm and uploads the ciphertext to the cloud. Without decrypting, the cloud performs a two-stage Permutation Ordered Binary (POB) reversible compression, releasing about 4 bpp of embedding space while maintaining perfect reversibility. In this space, two types of watermarks are embedded: (i) distributed (7,4) Hamming-code-based parity bits across interleaved blocks for bit-level tamper localization and single-bit correction; and (ii) a keyed hash-assisted block authentication watermark (4 bits per \(2\times 2\) 2 × 2 block) for coarse-grained integrity verification. During detection, an adaptive mask-selection mechanism compares the reliability of pixel-level and block-level results and triggers a hybrid image recovery (IHR) process: sparse errors are corrected by Hamming decoding, whereas multi-bit conflicts are refined through prediction-based pixel recovery. Experimental results show that the proposed method outperforms existing schemes in both detection accuracy and reconstruction quality, achieving lossless recovery at \(\gamma =6.25\%\) γ = 6.25 % and improving PSNR by 7 to 12 dB over the representative ciphertext-domain watermarking method under moderate cropping attacks ( \(\gamma =25\%\) γ = 25 % ).