Pith. sign in

REVIEW 4 major objections 4 minor 89 references

Deep Data Hiding for ICAO-Compliant Face Images: A Survey

T0 review · 4 major / 4 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read Only a subset of deep data-hiding models meets ICAO face-image certification needs, the paper argues.

desk verdict A useful survey with a genuinely new ICAO lens, but Table 2 is too heterogeneous to support the strong conclusion that only a few methods qualify. read the letter →

arxiv 2508.19324 v1 pith:YGJNG3LU submitted 2025-08-26 cs.CV cs.AIcs.CRcs.LGeess.IV

classification cs.CVcs.AIcs.CRcs.LGeess.IV
keywords datahidingICAOfaceimagesdigitalwatermarkingsteganographyinvertibleneuralnetworkssemi-fragiletamperdetectionbiometriccertification
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

ICAO-standard face photos, used in e-passports and identity verification, remain vulnerable to morphing and deepfake manipulation after capture. This survey argues that embedding tamper-evident signals directly into the image is the natural complement to capture-time defenses. It reviews deep learning watermarking and steganography methods, maps them against ICAO constraints, and concludes that only a subset — chiefly invertible-neural-network and transformer-based semi-fragile methods — balance imperceptibility, selective robustness, and reliable blind decoding. If correct, this narrows the practical design space for persistent integrity verification of standardized biometric images.

What carries the argument

The organizing constraint is the ICAO portrait-quality specification: inter-eye distance, frontal neutral face, uniform background, JPEG/JPEG2000 formatting. Against that backdrop, the central identity is the fragility-robustness axis: fragile methods degrade under any alteration, semi-fragile methods absorb benign compression but break under semantic tampering, and robust methods are unsuitable because they would let morphing pass. The comparison uses reported PSNR, BER, payload, and JPEG-QF robustness to grade methods; invertible neural networks are highlighted as promising because they make concealment and reveal symmetric, reversible processes and give fine control over this fragility.

What would settle it

Run the methods graded 'High' and 'Low' on a single ICAO-compliant face dataset under identical conditions (same resolution, JPEG quality, and face-recognition pipeline), measuring PSNR, BER, and recognition accuracy; if the 'High' methods no longer separate from the 'Low' ones, the survey's central distinction collapses.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central claim is that deep learning-based fragile and semi-fragile data hiding, especially methods built on invertible neural networks, 'emerge as the most promising' for ICAO-compliant integrity verification. The survey establishes that robust, general-purpose watermarking is counterproductive for tamper detection because it tolerates exactly the semantic manipulations (face morphing, swapping) that certification must catch. Comparing thirteen methods on PSNR, bit-error rate, payload, and JPEG-compression robustness, it finds that only a subset simultaneously satisfies visual conformity, selective robustness to benign compression, and dependable message recover

Load-bearing premise

The paper's grades treat PSNR, BER, and payload numbers reported in each original paper as directly comparable, even though datasets, image resolutions, and payloads differ across methods; if those numbers are not commensurable, the conclusion about which methods are suitable is not robust.

Editorial extensions

If this is right

  • Practitioners building e-passport, digital travel credential, or KYC integrity systems should select semi-fragile, blind-extraction methods rather than robust copyright watermarks.
  • INN-based and transformer-based architectures, such as RIS and StegFormer, are the most promising candidates to test under real ICAO conditions.
  • The standard metrics (PSNR, BER, JPEG QF=90/50) are necessary but insufficient; security against steganalysis and impact on face-recognition accuracy need dedicated benchmarks.
  • The paper's qualitative grades give a preliminary selection tool for deployment, not a strict ranking.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The comparison conclusion is directly testable: running the shortlisted models on one ICAO-compliant face dataset, with identical resolution, compression, and a single face matcher, would likely reorder some grades.
  • The same fragile-vs-robust logic should extend to other standardized biometric images, such as fingerprints or iris, where predictable acquisition formats invite manipulation.
  • The paper's claim implies that even a very successful robust watermarker would fail morph detection; that is a falsifiable design choice, not a theorem.
  • Because the survey set of methods is not exhaustive, the identified 'subset' may not be the true frontier; a broader architecture search could uncover better semi-fragile designs.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper surveys deep learning-based data hiding (watermarking and steganography) for ICAO-compliant face images. It reviews ICAO portrait quality constraints and real-world applications, argues that PAD provides no post-capture protection, and positions fragile/semi-fragile data hiding as a complementary integrity mechanism. The core technical content is a taxonomy of deep architectures (encoder–decoder, GAN, transformer, invertible neural network, diffusion) and a comparative table (Table 2) of fourteen methods across imperceptibility, robustness, capacity, and a subjective overall grade. The central claim, stated in §5.2 and echoed in §6, is that only a subset of current models meet the combined requirements of visual conformity, selective robustness, and reliable decoding, and that INN-based methods are the most promising for ICAO-oriented integrity verification.

Significance. If the comparative conclusion were robust, the paper would provide useful and timely guidance for deploying tamper-evident signals in e-passports, digital travel credentials, and KYC systems. The survey is genuinely novel in targeting ICAO-constrained face images rather than generic media, and it offers a clear problem formulation, a useful taxonomy, and a sensible discussion of why fragile/semi-fragile behavior is needed. The authors also deserve credit for being explicit that the comparison is qualitative and that ICAO-specific validation is still missing. However, the evidence base assembled in Table 2 does not support the strength of the central claim as currently worded. The cross-method comparison mixes self-reported metrics from heterogeneous datasets, resolutions, payloads, and embedding modalities, includes no JPEG2000 or face-recognition evaluation, and assigns grades without a transparent rubric. These issues are fixable by reframing the claims as qualitative tendencies or by adding a controlled ICAO-oriented benchmark, but they currently affect load-bearing conclusions.

major comments (4)
  1. [§5.2 / Table 2] The central finding that 'only a subset of models meet the combined requirements...' rests entirely on Table 2, but the metrics in that table are not commensurable. PSNR and BER are taken from original papers using different datasets (DIV2K, COCO, ImageNet, LFW, CelebA), resolutions (128–1024 px), payloads (0.00065–24 BPP), and task types (binary-string hiding vs. whole-image hiding). A 48 dB PSNR at 24 BPP on natural images is not comparable to 36 dB at 0.00065 BPP on faces. Moreover, ICAO logical storage uses JPEG2000 (Table 1), yet no row evaluates JPEG2000, and no row measures the impact of embedding on face recognition performance. The §6 call for future validation acknowledges this, but §5.2 still states the comparative result as a finding. Please either reframe the conclusion as a qualitative tendency with explicit caveats or add a controlled evaluation on ICAO-like face images wi
  2. [Table 2, 'Grade' column] The overall 'Grade' column (Low+, Medium, Medium-, High+, etc.) is assigned without a stated scoring rule or weighting. The text in §5.2 says it reflects 'a balanced assessment,' but the reader cannot see how imperceptibility, recovery fidelity, robustness behavior, and resolution compliance are combined. Many cells in the table are also missing (—), including JPEG-robustness values for several methods. Without a transparent rubric, the grades are not reproducible and cannot support the strong statement that certain methods are 'better aligned' with ICAO requirements. Please define the grading criteria or remove the grade column and restrict the discussion to the reported values.
  3. [§5.1 / §5.2] Section 5 opens by identifying security as one of the four core evaluation dimensions, but Table 2 contains no security metrics. The text mentions that 'most of the suitable methods report performance against generic steganalysis benchmarks... around 55% or less,' but no table rows, references, or per-method values support this statement. Because §3.2 lists security as desirable and §5.2's conclusion discusses combined requirements, omitting security from the comparison weakens the claim of a comprehensive suitability assessment. Either include the available security evaluations or explicitly bound the comparison to imperceptibility, robustness, and capacity.
  4. [§5.2, selective robustness] The paper's central threat model is morphing and semantic manipulation, but no method in Table 2 is evaluated under morphing. The only method with any semantic-manipulation test is FaceSigns (face swap), and that result is not reported in the table. Robustness to JPEG QF=90/50 is not the ICAO-relevant codec condition, since Table 1 specifies JPEG2000 for logical storage. Consequently, the 'selective robustness' component of the central claim is not actually established for the ICAO scenario. The authors should either present this as an open question or add the missing attack evaluations.
minor comments (4)
  1. [Figure 2 / Table 2] The caption of Figure 2 reports PSNR=45.813 and SSIM=0.9861 at 1 bpp for [76], while Table 2 lists Stegaformer [76] at 3 bpp with PSNR values 43.37/47.31. Similarly, Figure 2 reports PSNR=39.562 for [35] at 24 bpp, while Table 2 lists StegFormer [35] at ~24 bpp with PSNR 56.30/55.45 on DIV2K. Please harmonize the reported conditions and values.
  2. [References / author list] There is an orthographic inconsistency between 'StegFormer' [35] and 'Stegaformer' [76], which are easily confused. Also, the author list repeats 'Jefferson David Rodriguez Chivata' twice; please correct this.
  3. [Section 2, first paragraph] The sentence 'Section 2 revises the key biometric and technical specifications' should read 'reviews' rather than 'revises.'
  4. [Table 1 / Section 5.2] Table 1 correctly lists JPEG2000 as the logical-storage compression format, but the robustness discussion concentrates exclusively on JPEG compression. The manuscript would benefit from explicitly stating why JPEG2000 was not included in the comparison or from discussing its expected effect on the surveyed methods.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity: the survey's claims rest on external literature; the only self-citation is illustrative, not load-bearing.

full rationale

This is a survey, not a derivation. The central conclusion in §5.2 ('only a subset of models meet the combined requirements...') is an interpretation of Table 2, which compiles metrics (PSNR, BER, payload) reported in the original, largely external publications of the surveyed methods. No parameter is fitted to the conclusion, no equation is defined in terms of the target result, and no uniqueness theorem is invoked. The requirements in §3.2 (fragile/semi-fragile embedding mandatory, invertibility desired, etc.) are normative scoping choices, not circular reductions; they do not by themselves determine which specific methods are graded as suitable. The sole self-citation is [18] (Ghiani et al., same research group), used as an example for the threshold 'PSNR ≥35 dB and BER ≤0.3%' and as a motivation that steganography can act as fragile integrity markers. This citation is not load-bearing: Table 2's ranking would stand on the external papers' reported numbers, and the threshold is stated as indicative, not as the proof of the survey's comparative claim. The acknowledged 'qualitative nature' of Table 2 and the call for ICAO-specific validation in §6 are limitations of evidence, not circularity. Accordingly, the score is 2 due solely to the minor, non-load-bearing self-citation.

Assumptions & free parameters 1 free parameters · 3 assumptions · 0 invented entities

No new model parameters are proposed. The analysis depends on the authors' interpretation of ICAO requirements and on trusting reported metrics from prior papers.

free parameters (1)
  • ICAO imperceptibility threshold = 40 dB PSNR
    Authors classify methods as visually indistinguishable when PSNR > 40 dB, citing [53,58]; this threshold is adopted from prior work and is not fitted from ICAO data, but it directly affects which methods are deemed suitable.
assumptions (3)
  • domain assumption ICAO-compliant certification requires invisible embedding (PSNR above 40 dB), blind extraction, cover-based embedding, and fragile or semi-fragile behavior.
    Authors define these as mandatory in Section 3.2; this set of requirements drives the entire evaluation.
  • domain assumption Self-reported metrics from original papers are accurate and directly comparable across methods.
    Section 5.2 states all methods are analyzed using metrics from original publications; no independent verification or normalization for dataset or resolution differences.
  • ad hoc to paper The selected papers are representative of the state of the art in data hiding for ICAO images.
    No systematic search or inclusion criteria are described; selection appears subjective (Sections 4 and 5).

how reviews work

0 comments
Cite this review

Pith. "Pith review of Deep Data Hiding for ICAO-Compliant Face Images: A Survey." pith.science (2026). https://pith.science/paper/YGJNG3LU

@misc{pith2026250819324,
  author       = {Pith},
  title        = {Pith review of: Deep Data Hiding for ICAO-Compliant Face Images: A Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YGJNG3LU}},
  note         = {Machine review of arXiv:2508.19324}
}
read the original abstract

ICAO-compliant facial images, initially designed for secure biometric passports, are increasingly becoming central to identity verification in a wide range of application contexts, including border control, digital travel credentials, and financial services. While their standardization enables global interoperability, it also facilitates practices such as morphing and deepfakes, which can be exploited for harmful purposes like identity theft and illegal sharing of identity documents. Traditional countermeasures like Presentation Attack Detection (PAD) are limited to real-time capture and offer no post-capture protection. This survey paper investigates digital watermarking and steganography as complementary solutions that embed tamper-evident signals directly into the image, enabling persistent verification without compromising ICAO compliance. We provide the first comprehensive analysis of state-of-the-art techniques to evaluate the potential and drawbacks of the underlying approaches concerning the applications involving ICAO-compliant images and their suitability under standard constraints. We highlight key trade-offs, offering guidance for secure deployment in real-world identity systems.

Figures

Figures reproduced from arXiv: 2508.19324 by the authors.

Figure 1
Figure 1. General scheme of a data hiding system. breaches [49, 54]. Similarly, financial institutions manag￾ing biometric databases for identity verification represent attractive targets for cyberattacks if proper security mea￾sures are not enforced [38, 59]. Therefore, this combination of acquisition predictability, mass distribution, and extended operational validity under￾scores the need for protection mechanisms that per… view at source ↗
Figure 2
Figure 2. Comparison between: a) original input image; b) water [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

89 extracted references · 78 canonical work pages

  1. [35]

    X. Ke, H. Wu, and W. Guo. Stegformer: Rebuilding the glory of autoencoder-based steganography. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 38, pages 2723–2731, 2024

  2. [76]

    G. Yu, Q. Xuchong, and Y . Zihan. Effective message hiding with order-preserving mechanisms. arXiv preprint arXiv:2402.19160, 2024

  3. [1]

    Information technology — Biometric data interchange for- mats — Part 5: Face image data, 2011

  4. [2]

    Information technology — Extensible biometric data inter- change formats — Part 5: Face image data, 2019

  5. [3]

    Abdelnabi and M

    S. Abdelnabi and M. Fritz. Adversarial watermarking trans- former: Towards tracing text provenance with data hiding. In 2021 IEEE Symposium on Security and Privacy (SP) , pages 121–140. IEEE, 2021

  6. [4]

    S. Baluja. Hiding images in plain sight: Deep steganogra- phy. Advances in neural information processing systems, 30, 2017

  7. [5]

    Beuve, W

    N. Beuve, W. Hamidouche, and O. D ´eforges. Waterlo: Pro- tect images from deepfakes using localized semi-fragile wa- termark. In Proceedings of the IEEE/CVF international con- ference on computer vision, pages 393–402, 2023

  8. [6]

    Boroumand, M

    M. Boroumand, M. Chen, and J. Fridrich. Deep residual network for steganalysis of digital images. IEEE Transac- tions on Information Forensics and Security , 14(5):1181– 1193, 2018

Show all 89 references
  1. [7]

    C. Busch. Challenges for automated face recognition sys- tems. Nature Reviews Electrical Engineering , 1(11):748– 757, 2024

  2. [8]

    Capasso, G

    P. Capasso, G. Cattaneo, and M. De Marsico. A comprehen- sive survey on methods for image integrity. ACM Transac- tions on Multimedia Computing, Communications and Ap- plications, 20(11):1–34, 2024

  3. [9]

    Chan and L.-M

    C.-K. Chan and L.-M. Cheng. Hiding data in images by simple lsb substitution. Pattern recognition, 37(3):469–474, 2004

  4. [10]

    Coatrieux, W

    G. Coatrieux, W. Pan, N. Cuppens-Boulahia, F. Cuppens, and C. Roux. Reversible watermarking based on invari- ant image classification and dynamic histogram shifting. IEEE Transactions on information forensics and security , 8(1):111–120, 2012

  5. [11]

    I. Cox, M. Miller, J. Bloom, J. Fridrich, and T. Kalker. Dig- ital watermarking and steganography . Morgan kaufmann, 2007

  6. [12]

    I. J. Cox, J. Kilian, T. Leighton, and T. Shamoon. Secure spread spectrum watermarking for images, audio and video. In Proceedings of 3rd IEEE international conference on im- age processing, volume 3, pages 243–246. IEEE, 1996

  7. [13]

    Di Domenico, G

    N. Di Domenico, G. Borghi, A. Franco, and D. Mal- toni. Onot: a high-quality icao-compliant synthetic mugshot dataset. In 2024 IEEE 18th International Conference on Automatic Face and Gesture Recognition (FG), pages 1–10. IEEE, 2024

  8. [14]

    Erdogmus and S

    N. Erdogmus and S. Marcel. Spoofing face recognition with 3d masks. IEEE transactions on information forensics and security, 9(7):1084–1097, 2014

  9. [15]

    H. Fang, K. Chen, Y . Qiu, Z. Ma, W. Zhang, and E.-C. Chang. Dero: Diffusion-model-erasure robust watermark- ing. In Proceedings of the 32nd ACM International Confer- ence on Multimedia, pages 2973–2981, 2024

  10. [16]

    Ferrara, A

    M. Ferrara, A. Franco, and D. Maltoni. The magic passport. In IEEE International Joint Conference on Biometrics, pages 1–7, 2014

  11. [17]

    L. Geng, W. Zhang, H. Chen, H. Fang, and N. Yu. Real- time attacks on robust watermarking tools in the wild by cnn. Journal of Real-Time Image Processing, 17:631–641, 2020

  12. [18]

    Ghiani, J

    D. Ghiani, J. D. R. Chivata, S. Lilliu, S. M. La Cava, M. Micheletto, G. Orr`u, F. Lama, and G. L. Marcialis. Frag- ile watermarking for image certification using deep stegano- graphic embedding. arXiv preprint arXiv:2504.13759, 2025

  13. [19]

    Dutch participation in eu- ropean dtc pilot

    Government of the Netherlands. Dutch participation in eu- ropean dtc pilot. https://www.government.nl/ documents / publications / 2023 / 02 / 23 / dtc,

  14. [20]

    Z. Guan, J. Jing, X. Deng, M. Xu, L. Jiang, Z. Zhang, and Y . Li. Deepmih: Deep invertible network for multiple image hiding. IEEE Transactions on Pattern Analysis and Machine Intelligence, 45(1):372–390, 2022

  15. [21]

    Guo and N

    G. Guo and N. Zhang. A survey on deep learning based face recognition. Computer vision and image understanding, 189:102805, 2019

  16. [22]

    Guo and Z

    Y . Guo and Z. Liu. Coverless steganography for face recog- nition based on diffusion model. IEEE Access, 2024

  17. [23]

    Hamidi, M

    M. Hamidi, M. E. Haziti, H. Cherifi, and M. E. Hassouni. Hybrid blind robust image watermarking technique based on dft-dct and arnold transform. Multimedia Tools and Applica- tions, 77:27181–27214, 2018

  18. [24]

    Hayata, K

    J. Hayata, K. Nomura, Y . Takata, H. Kumagai, M. Kami- zono, T. Kono, Y . Maeda, and N. Fukuda. A trust service model adaptable to various assurance levels by linking digi- tal ids and certificates. In 2024 8th International Conference on Cryptography, Security and Privacy (CS...

  19. [25]

    Hernandez-Ortega, J

    J. Hernandez-Ortega, J. Fierrez, A. Morales, and J. Gal- bally. Introduction to presentation attack detection in face biometrics and recent advances. Handbook of Biometric Anti-Spoofing: Presentation Attack Detection and Vulnera- bility Assessment, pages 203–230, 2023

  20. [26]

    Hidayat, U

    F. Hidayat, U. Elviani, G. B. G. Situmorang, M. Z. Ramad- han, F. A. Alunjati, and R. F. Sucipto. Face recognition for automatic border control: a systematic literature review. IEEE Access, 12:37288–37309, 2024

  21. [27]

    Hore and D

    A. Hore and D. Ziou. Image quality metrics: Psnr vs. ssim. In 2010 20th international conference on pattern recognition , pages 2366–2369. IEEE, 2010

  22. [28]

    X. Hu, Z. Fu, X. Zhang, and Y . Chen. Invisible and steganalysis-resistant deep image hiding based on one-way adversarial invertible networks. IEEE Transactions on Cir- cuits and Systems for Video Technology , 34(7):6128–6143, 2023

  23. [29]

    Huang, Y

    H. Huang, Y . Wang, Z. Chen, Y . Zhang, Y . Li, Z. Tang, W. Chu, J. Chen, W. Lin, and K.-K. Ma. Cmua-watermark: A cross-model universal adversarial watermark for combat- ing deepfakes. In Proceedings of the AAAI conference on artificial intelligence, volume 36, pages 989–997, 2022

  24. [30]

    Huang, T

    J. Huang, T. Luo, L. Li, G. Yang, H. Xu, and C.-C. Chang. Arwgan: Attention-guided robust image watermark- ing model based on gan. IEEE Transactions on Instrumen- tation and Measurement, 72:1–17, 2023

  25. [31]

    Machine readable travel documents: Part 9 – deployment of biometric identi- fication and electronic storage of data in mrtds

    International Civil Aviation Organization. Machine readable travel documents: Part 9 – deployment of biometric identi- fication and electronic storage of data in mrtds. Technical Report Doc 9303, Part 9, International Civil Aviation Orga- nization (ICAO), Montr´eal, Canada, 2021

  26. [32]

    Z. Jia, H. Fang, and W. Zhang. Mbrs: Enhancing robustness of dnn-based watermarking by mini-batch of real and sim- ulated jpeg compression. In Proceedings of the 29th ACM international conference on multimedia, pages 41–49, 2021

  27. [33]

    Jiang, M

    Z. Jiang, M. Guo, Y . Hu, J. Jia, and N. Z. Gong. Certifi- ably robust image watermark. In European Conference on Computer Vision, pages 427–443. Springer, 2024

  28. [34]

    J. Jing, X. Deng, M. Xu, J. Wang, and Z. Guan. Hinet: Deep image hiding by invertible network. In Proceedings of the IEEE/CVF international conference on computer vision, pages 4733–4742, 2021

  29. [36]

    Khalifa and A

    A. Khalifa and A. Guzman. Imperceptible image steganogra- phy using symmetry-adapted deep learning techniques.Sym- metry, 14(7):1325, 2022

  30. [37]

    S. M. La Cava, G. Orr `u, M. Drahansky, G. L. Marcialis, and F. Roli. 3d face reconstruction: the road to forensics. ACM Computing Surveys, 56(3):1–38, 2023

  31. [38]

    Laishram, M

    L. Laishram, M. Shaheryar, J. T. Lee, and S. K. Jung. Toward a privacy-preserving face recognition system: A survey of leakages and solutions. ACM Computing Surveys, 57(6):1– 38, 2025

  32. [39]

    Y . Lan, F. Shang, J. Yang, X. Kang, and E. Li. Robust image steganography: hiding messages in frequency coefficients. In Proceedings of the AAAI conference on artificial intelli- gence, volume 37, pages 14955–14963, 2023

  33. [40]

    G. Li, S. Li, Z. Qian, and X. Zhang. Cover-separable fixed neural network steganography via deep generative models. In Proceedings of the 32nd ACM International Conference on Multimedia, pages 10238–10247, 2024

  34. [41]

    Y . Liu, M. Guo, J. Zhang, Y . Zhu, and X. Xie. A novel two- stage separable deep learning framework for practical blind watermarking. In Proceedings of the 27th ACM International conference on multimedia, pages 1509–1517, 2019

  35. [42]

    S.-P. Lu, R. Wang, T. Zhong, and P. L. Rosin. Large-capacity image steganography based on invertible neural networks. In Proceedings of the IEEE/CVF conference on computer vi- sion and pattern recognition, pages 10816–10825, 2021

  36. [43]

    T. Luo, J. Wu, Z. He, H. Xu, G. Jiang, and C.-C. Chang. Wformer: A transformer-based soft fusion model for robust image watermarking. IEEE Transactions on Emerging Top- ics in Computational Intelligence, 2024

  37. [44]

    McAteer, A

    I. McAteer, A. Ibrahim, G. Zheng, W. Yang, and C. Valli. In- tegration of biometrics and steganography: a comprehensive review. Technologies, 7(2):34, 2019

  38. [45]

    A. V . Nadimpalli and A. Rattani. Social media authenti- cation and combating deepfakes using semi-fragile invisible image watermarking. Digital Threats: Research and Prac- tice, 5(4):1–30, 2024

  39. [46]

    Neekhara, S

    P. Neekhara, S. Hussain, X. Zhang, K. Huang, J. McAuley, and F. Koushanfar. Facesigns: semi-fragile neural water- marks for media authentication and countering deepfakes. arXiv preprint arXiv:2204.01960, 2022

  40. [47]

    Palaghias, L

    N. Palaghias, L. Chondromatidou, J. Calapez, M. Krecek, G. Kouzas, D. Kassimis, J. Zaras, P. Orfanoudakis, I. Cru- cianu, and D. Oniga. Seamless identity verification at water and land borders. In 2024 5th International Conference in Electronic Engineering, Information Technol...

  41. [48]

    Panzino, S

    A. Panzino, S. M. La Cava, G. Orr `u, and G. L. Mar- cialis. Evaluating the integration of morph attack detection in automated face recognition systems. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 3827–3836, 2024

  42. [49]

    K. K. Prakasha and U. Sumalatha. Privacy-preserving tech- niques in biometric systems: Approaches and challenges. IEEE Access, 2025

  43. [50]

    Radutoiu, A

    A.-T. Radutoiu, A. Bassit, R. Veldhuis, and C. Busch. A study on the next generation of digital travel credentials. In 2024 International Conference of the Biometrics Special In- terest Group (BIOSIG), pages 1–6. IEEE, 2024

  44. [51]

    Rawat and B

    S. Rawat and B. Raman. A blind watermarking algorithm based on fractional fourier transform and visual cryptogra- phy. Signal Processing, 92(6):1480–1491, 2012

  45. [52]

    M. K. Rusia and D. K. Singh. A comprehensive survey on techniques to handle face identity threats: challenges and op- portunities. Multimedia Tools and Applications, 82(2):1669– 1748, 2023

  46. [53]

    M. M. Sadek, A. S. Khalifa, and M. G. Mostafa. Robust video steganography algorithm using adaptive skin-tone de- tection. Multimedia Tools and Applications, 76:3065–3085, 2017

  47. [54]

    S. L. Sanna, D. Soi, D. Maiorca, G. Fumera, and G. Giacinto. A risk estimation study of native code vulnerabilities in an- droid applications. Journal of Cybersecurity, 10(1):tyae015, 2024

  48. [55]

    Shaheed, P

    K. Shaheed, P. Szczuko, M. Kumar, I. Qureshi, Q. Abbas, and I. Ullah. Deep learning techniques for biometric se- curity: A systematic review of presentation attack detection systems. Engineering Applications of Artificial Intelligence, 129:107569, 2024

  49. [56]

    Sharma and A

    D. Sharma and A. Selwal. A survey on face presentation at- tack detection mechanisms: hitherto and future perspectives. Multimedia Systems, 29(3):1527–1577, 2023

  50. [57]

    Sumalatha, K

    U. Sumalatha, K. K. Prakasha, S. Prabhu, and V . C. Nayak. A comprehensive review of unimodal and multimodal finger- print biometric authentication systems: Fusion, attacks, and template protection. IEEE Access, 2024

  51. [58]

    J. Sun, Z. Yang, Y . Zhang, T. Li, and S. Wang. High-capacity data hiding method based on two subgroup pixels-value ad- justment using encoding function. Security and Communi- cation Networks, 2022(1):4336526, 2022

  52. [59]

    Tabassum, S

    Z. Tabassum, S. Arsheen, K. Ahmad, and G. Ozdemir. Blockchain-based secure e-kyc solution for banking system. In 2024 IEEE 16th International Conference on Computa- tional Intelligence and Communication Networks (CICN) , pages 565–571. IEEE, 2024

  53. [60]

    J. Tan, X. Liao, J. Liu, Y . Cao, and H. Jiang. Channel at- tention image steganography with generative adversarial net- works. IEEE transactions on network science and engineer- ing, 9(2):888–903, 2021

  54. [61]

    Tavares, A

    M. Tavares, A. Guerreiro, C. Coutinho, F. Veiga, and A. Campos. Wallid: Secure your id in an ethereum wal- let. In 2018 International Conference on Intelligent Systems (IS), pages 714–721. IEEE, 2018

  55. [62]

    Dtc border control faster and smoother

    The Finnish Border Guard. Dtc border control faster and smoother. https://raja.fi/en/dtc , 2024. Ac- cessed: 2025-04-03

  56. [63]

    Wang and Y

    B. Wang and Y . Wu. Staged adaptive blind watermarking scheme. In Proceedings of the Asian conference on computer vision, pages 1812–1827, 2022

  57. [64]

    B. Wang, Y . Wu, and G. Wang. Adaptor: Improving the ro- bustness and imperceptibility of watermarking by the adap- tive strength factor. IEEE Transactions on Circuits and Sys- tems for Video Technology, 33(11):6260–6272, 2023

  58. [65]

    J. Wang, H. Wang, J. Zhang, H. Wu, X. Luo, and B. Ma. Invisible adversarial watermarking: A novel security mech- anism for enhancing copyright protection. ACM Transac- tions on Multimedia Computing, Communications and Ap- plications, 21(2):1–22, 2024

  59. [66]

    R. Wang, F. Juefei-Xu, M. Luo, Y . Liu, and L. Wang. Fake- tagger: Robust safeguards against deepfake dissemination via provenance tracking. In Proceedings of the 29th ACM international conference on multimedia , pages 3546–3555, 2021

  60. [67]

    T. Wang, M. Huang, H. Cheng, X. Zhang, and Z. Shen. Lampmark: Proactive deepfake detection via training-free landmark perceptual watermarks. In Proceedings of the 32nd ACM International Conference on Multimedia , pages 10515–10524, 2024

  61. [68]

    Z. Wang, O. Byrnes, H. Wang, R. Sun, C. Ma, H. Chen, Q. Wu, and M. Xue. Data hiding with deep learning: A sur- vey unifying digital watermarking and steganography. IEEE Transactions on Computational Social Systems, 10(6):2985– 2999, 2023

  62. [69]

    A. Wolf. Icao: Portrait quality (reference facial images for mrtd), version 1.0. standard. International Civil Aviation Or- ganization, 2018

  63. [70]

    X. Wu, X. Liao, and B. Ou. Sepmark: Deep separable wa- termarking for unified source tracing and deepfake detection. In Proceedings of the 31st ACM International Conference on Multimedia, pages 1190–1201, 2023

  64. [71]

    Xu, H.-Z

    G. Xu, H.-Z. Wu, and Y .-Q. Shi. Structural design of convo- lutional neural networks for steganalysis. IEEE Signal Pro- cessing Letters, 23(5):708–712, 2016

  65. [72]

    W. Xu, D. He, L. Qiu, and X. Liang. Stegdiff: Content- adaptive image steganography with denoising diffusion probabilistic models. In Advances in Neural Information Processing Systems (NeurIPS), 2023

  66. [73]

    Y . Xu, C. Mou, Y . Hu, J. Xie, and J. Zhang. Robust invertible image steganography. In Proceedings of the IEEE/CVF con- ference on computer vision and pattern recognition , pages 7875–7884, 2022

  67. [74]

    Y . Yang, Z. Liu, J. Jia, Z. Gao, Y . Li, W. Sun, X. Liu, and G. Zhai. Diffstega: towards universal training-free coverless image steganography with diffusion models. arXiv preprint arXiv:2407.10459, 2024

  68. [75]

    C. Yu. Attention based data hiding with generative adver- sarial networks. In Proceedings of the AAAI conference on artificial intelligence, volume 34, pages 1120–1128, 2020

  69. [77]

    J. Yu, X. Zhang, Y . Xu, and J. Zhang. Cross: Diffusion model makes controllable, robust and secure image steganogra- phy. Advances in Neural Information Processing Systems , 36:80730–80743, 2023

  70. [78]

    P. Yu, Z. Xia, J. Fei, and Y . Lu. A survey on deepfake video detection. Iet Biometrics, 10(6):607–624, 2021

  71. [79]

    Zhang, P

    C. Zhang, P. Benz, A. Karjauv, G. Sun, and I. S. Kweon. Udh: Universal deep hiding for steganography, watermark- ing, and light field messaging. Advances in Neural Informa- tion Processing Systems, 33:10223–10234, 2020

  72. [80]

    K. A. Zhang, A. Cuesta-Infante, L. Xu, and K. Veeramacha- neni. Steganogan: High capacity image steganography with gans. arXiv preprint arXiv:1901.03892, 2019

  73. [81]

    Zhang, S

    R. Zhang, S. Dong, and J. Liu. Invisible steganography via generative adversarial networks. Multimedia tools and ap- plications, 78(7):8559–8575, 2019

  74. [82]

    Zhang, P

    R. Zhang, P. Isola, A. A. Efros, E. Shechtman, and O. Wang. The unreasonable effectiveness of deep features as a percep- tual metric. In Proceedings of the IEEE conference on com- puter vision and pattern recognition, pages 586–595, 2018

  75. [83]

    Zhang, K

    R. Zhang, K. Zhu, H. Zhang, and X. Zhang. Robust deep image steganography with steganalysis adaptive adversarial learning. In Proceedings of the 27th ACM International Con- ference on Multimedia, pages 2099–2107, 2019

  76. [84]

    Zhang, R

    X. Zhang, R. Li, J. Yu, Y . Xu, W. Li, and J. Zhang. Editguard: Versatile image watermarking for tamper localization and copyright protection. In Proceedings of the IEEE/CVF con- ference on computer vision and pattern recognition , pages 11964–11974, 2024

  77. [85]

    Zhang, D

    Y . Zhang, D. Ye, C. Xie, L. Tang, X. Liao, Z. Liu, C. Chen, and J. Deng. Dual defense: Adversarial, traceable, and in- visible robust watermarking against face swapping. IEEE Transactions on Information Forensics and Security, 2024

  78. [86]

    Y . Zhao, B. Liu, M. Ding, B. Liu, T. Zhu, and X. Yu. Proac- tive deepfake defence via identity watermarking. InProceed- ings of the IEEE/CVF winter conference on applications of computer vision, pages 4602–4611, 2023

  79. [87]

    J. Zhu, R. Kaplan, J. Johnson, and L. Fei-Fei. Hidden: Hid- ing data with deep networks. In Proceedings of the Euro- pean conference on computer vision (ECCV) , pages 657– 672, 2018

  80. [88]

    J. Zhu, Y . Zhang, and L. Fei-Fei. Stegformer: Content- adaptive steganography with transformers. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pat- tern Recognition (CVPR), pages 20606–20615, 2022

  81. [2023]

    Accessed: 2025-04-03

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.