[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118808-en":3,"doc-seo-118808-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118808,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","Steganographic Capacity of Selected Machine Learning and Deep Learning Models - Master of Science Project","Steganographic Capacity of Selected Machine Learning and Deep Learning Models by Lei Zhang evaluates how modern learning systems can be manipulated in steganography-based attack scenarios. The study measures the steganographic capacity of several classic machine learning and deep learning models by identifying the number of low-order bits in trained parameters that can be modified without significantly degrading model performance. Results show that learning models can exhibit unexpectedly high capacity, while performance typically drops sharply after a clear threshold.","San Jose State University  \nSJSU ScholarWorks  \n\n| Master's Projects | Master's Theses and Graduate Research |\n| --- | --- |\n| Spring 2023\u003Cbr>Steganographic Capacity of Selected Machine Learning and Deep Learning Models\u003Cbr>Lei Zhang\u003Cbr>San Jose State University\u003Cbr>Follow this and additional works at: [https://scholarworks.sjsu.edu/etd_projects](https://scholarworks.sjsu.edu/etd_projects)\u003Cbr> Part of the Artificial Intelligence and Robotics Commons, and the Information Security Commons |  |\n\nRecommended Citation  \nZhang, Lei, \"Steganographic Capacity of Selected Machine Learning and Deep Learning Models\" (2023) . Master 's Projects. 1271.  \nDOI: [https://doi.org/10.31979/etd.q6u5-n9x8](https://doi.org/10.31979/etd.q6u5-n9x8)  \n[https://scholarworks.sjsu.edu/etd_projects/1271](https://scholarworks.sjsu.edu/etd_projects/1271)  \nThis Master's Project is brought to you for free and open access by the Master's Theses and Graduate Research at SJSU ScholarWorks. It has been accepted for inclusion in Master's Projects by an authorized administrator of SJSU ScholarWorks. For more information, please contact [scholarworks@sjsu.edu](scholarworks@sjsu.edu).  \nSteganographic Capacity of Selected Machine Learning and Deep Learning Models  \nA Project  \nPresented to  \nThe Faculty of the Department of Computer Science San José State University  \nIn Partial Fulfillment  \nof the Requirements for the Degree  \nMaster of Science  \nby  \nLei Zhang  \nMay 2023  \n© 2023  \nLei Zhang  \nALL RIGHTS RESERVED  \nThe Designated Project Committee Approves the Project Titled  \nSteganographic Capacity of Selected Machine Learning and Deep Learning Models  \nby  \nLei Zhang  \nAPPROVED FOR THE DEPARTMENT OF COMPUTER SCIENCE  \nSAN JOSÉ STATE UNIVERSITY  \nMay 2023  \nDr. Mark Stamp  \nDr. Fabio Di Troia  \nDr. Genya Ishigaki  \nDepartment of Computer Science  \nDepartment of Computer Science  \nDepartment of Computer Science  \nABSTRACT  \nSteganographic Capacity of Selected Machine Learning and Deep Learning Models  \nby Lei Zhang  \nAs machine learning and deep learning models become ubiquitous, it is inevitable that there will be attempts to exploit such models in various attack scenarios. For example, in a steganographic based attack, information would be hidden in a learning model, which might then be used to gain unauthorized access to a computer, or for other malicious purposes. In this research, we determine the steganographic capacity of various classic machine learning and deep learning models. Specifically, we determine the number of low-order bits of the trained parameters of a given model that can be altered without significantly affecting the performance of the model. We find that thesteganographic capacity of learning models is surprisingly high, and that there tends to be a clear threshold after which model performance rapidly degrades.  \nACKNOWLEDGMENTS  \nI would like to take this opportunity to express my sincere gratitude to all those who have helped towards the completion of this project.  \nFirstly, I would like to thank my supervisor, Professor Mark Stamp, for the invaluable guidance and support throughout the whole research. Your expertise and insights have been instrumental in shaping the direction of this work, and I am truly grateful for your patience and encouragement.  \nI would also like to express my thanks to the members of my thesis committee, Professor Fabio Di Troia and Professor Genya Ishigaki, for their thoughtful feedback and constructive criticism. Their expertise and insights have been invaluable in helping me to refine my research and produce a high-quality thesis.  \nIn addition, I would like to extend my heartfelt thanks to my family for their unwavering support and encouragement. Their love, patience, and understanding have sustained me through the ups and downs of the research process, and I am truly grateful for their unwavering support.  \nFinally, I would like to thank all those who have contributed to this thesis in ways both large and s","cbCaiilJAAyoA9vp","https://ap.wps.com/l/cbCaiilJAAyoA9vp","pdf",2186081,1,60,"English","en",105,"# Chapter 1 Introduction\n# Chapter 2 Background\n## 2.1 Steganography\n## 2.2 Machine Learning\n## 2.3 Deep Learning\n# Chapter 3 Implementation\n## 3.1 Dataset\n## 3.2 Model Training\n# Chapter 4 Results\n## 4.1 SVMs\n## 4.2 Logistic Regression\n## 4.3 MLPs\n## 4.4 CNNs\n## 4.5 Transformers\n# Chapter 5 Conclusion","[{\"question\":\"What does the research measure regarding steganography and learning models?\",\"answer\":\"It determines the steganographic capacity by measuring how many low-order bits of trained parameters can be altered without significantly affecting model performance.\"},{\"question\":\"Why is this study relevant to security?\",\"answer\":\"The work addresses steganographic attacks where hidden information is embedded inside a learning model and then used for unauthorized access or other malicious purposes.\"},{\"question\":\"What pattern is observed in model performance after parameter modifications?\",\"answer\":\"The study finds an apparent threshold: model performance remains relatively stable up to a point, then degrades rapidly after the threshold is exceeded.\"}]","Steganographic Capacity of Selected Machine Learning and Deep Learning Models - Master of Science Project | PDF",1785720354,151,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"steganographic-capacity-of-selected-machine-learning-and-deep-learning-models-master-of-science-project","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/steganographic-capacity-of-selected-machine-learning-and-deep-learning-models-master-of-science-project/118808/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does the research measure regarding steganography and learning models?","Question",{"text":75,"@type":76},"It determines the steganographic capacity by measuring how many low-order bits of trained parameters can be altered without significantly affecting model performance.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why is this study relevant to security?",{"text":80,"@type":76},"The work addresses steganographic attacks where hidden information is embedded inside a learning model and then used for unauthorized access or other malicious purposes.",{"name":82,"@type":73,"acceptedAnswer":83},"What pattern is observed in model performance after parameter modifications?",{"text":84,"@type":76},"The study finds an apparent threshold: model performance remains relatively stable up to a point, then degrades rapidly after the threshold is exceeded.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":21,"slug":108},5,"Comic","comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]