نوع مقاله : مقاله پژوهشی
عنوان مقاله English
نویسندگان English
Nowadays, detecting malware hidden within images via steganography has become a key challenge in cyber forensics and digital evidence analysis. This research presents a novel deep learning-based framework for the detection, localization, and classification of steganographic malware in images. Conventional steganalysis methods based on supervised learning, while performing acceptably in detecting known algorithms, face two fundamental shortcomings: first, a heavy reliance on the specific steganography algorithm used; and second, a significant performance drop at low embedding rates (below 0.1 bits per pixel). The present study aims to overcome these limitations by introducing an integrated framework named CONAFP (Adaptive One-Class Network with Adversarial Feature Refinement). The proposed framework comprises three main components: first, a reconstruction module based on Generative Adversarial Networks (GANs)—utilizing a U-Net architecture and a PatchGAN discriminator—reconstructs the input image into a clean version. Second, a feature extraction module highlights steganographic traces by calculating residuals and applying multi-scale transformations and cross-scale attention mechanisms. Third, a one-class detection module, employing the Deep SVDD method and trained solely on benign data (clean images), identifies any deviation from the normal pattern as an anomaly. To overcome the inherent instability of training GANs within hybrid architectures, a two-stage training strategy—comprising separate pre-training followed by end-to-end fine-tuning—has been employed. The study’s findings demonstrate that detecting malware hidden in images does not require identifying the specific steganography algorithm; instead, by modeling the concept of "normality" and decoupling it from the image reconstruction process, an anomaly detection system independent of the attacker's algorithm can be achieved. This represents a paradigm shift from "detecting traces of the crime" to "detecting deviations from normality," opening new horizons in cybersecurity and the mitigation of unknown threats. By presenting an integrated framework and distinguishing the roles of GANs and Deep SVDD, this research advances the paradigm shift in the design of future steganalysis systems.
کلیدواژهها English