IJMSC Vol. 12, No. 3, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 2024KB)
PDF (2024KB), PP.65-80
Views: 0 Downloads: 0
Steganalysis, Process Mining, Behavioral Modeling, LSB Embedding, Digital Image Forensics, Localized Steganography
Steganography attempts to conceal messages in plain sight while steganalysis seeks to identify them or, more importantly, to extract the embedded data. Low-payload and spatially localized steganographic embedding is increasingly used to evade detection by classical steganalysis methods. While such strategies preserve global image statistics and remain visually imperceptible, they can disrupt natural pixel-level behavior. This work proposes a behavioral steganalysis framework inspired by process mining that detects image steganography by analyzing localized behavioral deviation using regional behavioral contrast and behavioral amplification. Experiments on lossless grayscale PNG images from the USC SIPI database and 10,000 images from the BOWS2 dataset using 1-bit LSB embedding show that the proposed framework reliably identifies steganographic embedding. On the USC SIPI dataset, conventional statistical detectors, including chi-square analysis and the StegExpose tool, showed limited detection capability under the evaluated localized embedding settings. Despite high perceptual quality of stego images (PSNR > 55 dB), significant behavioral deviation is consistently observed within embedded regions. These results demonstrate that the proposed process mining-inspired framework provides an interpretable and complementary direction for image steganalysis, particularly under low-payload and localized embedding scenarios.
Shikha Badhani, Vinita Verma, Manju Bhardwaj, Sakeena Shahid, Geetan Manchanda, "From Pixels to Processes: A Process Mining-Inspired Approach to Image Steganalysis", International Journal of Mathematical Sciences and Computing(IJMSC), Vol.12, No.3, pp. 65-80, 2026. DOI: 10.5815/ijmsc.2026.03.04
[1]F. A. P. Petitcolas, R. J. Anderson, and M. G. Kuhn, “Information hiding—A survey,” Proceedings of the IEEE, vol. 87, no. 7, pp. 1062–1078, 1999, doi: 10.1109/5.771065.
[2]C. E. Shannon, “Communication theory of secrecy systems,” Bell System Technical Journal, vol. 28, no. 4, pp. 656–715, 1949, doi: 10.1002/j.1538-7305.1949.tb00928.x.
[3]K. Karampidis, E. Kavallieratou, and G. Papadourakis, “A review of image steganalysis techniques for digital forensics,” Journal of Information Security and Applications, vol. 40, pp. 217–235, 2018, doi: 10.1016/j.jisa.2018.04.005.
[4]D. R. I. M. Etiadi, S. Rustad, P. N. Andono, et al., “Maximizing complex features to minimize the detectability of content-adaptive steganography,” Multimedia Tools and Applications, vol. 84, pp. 23813–23831, 2025, doi: 10.1007/s11042-024-20056-7.
[5]S. A. Naji, H. N. Mohaisen, Q. S. Alsaffar, and H. A. Jalab, “Automatic region selection method to enhance image-based steganography,” Periodicals of Engineering and Natural Sciences, vol. 8, no. 1, pp. 67–78, 2020.
[6]B. R. Ghosh, S. Banerjee, and J. K. Mandal, “A survey on LSB replacement-based statistical image steganalysis techniques,” in Advances in Data Science and Computing Technologies, Springer Nature Singapore, 2022, pp. 313–320.
[7]C. Ye and N. S. M., “Uncovering hidden data: A comparative study of statistical detection models for grayscale image steganography,” European Journal of AI, Computing & Informatics, vol. 1, no. 2, pp. 14–22, 2025.
[8]A. Amsaveni and P. T. Vanathi, “A comprehensive study on image steganography and steganalysis techniques,” International Journal of Information and Communication Technology, vol. 7, no. 4–5, pp. 406–424, 2015, doi: 10.1504/IJICT.2015.070300.
[9]W. M. P. van der Aalst, Process Mining: Data Science in Action, 2nd ed. Springer, 2016, doi: 10.1007/978-3-662-49851-4.
[10]F. Bezerra, J. Wainer, and W. M. P. van der Aalst, “Anomaly detection using process mining,” in Enterprise, Business-Process and Information Systems Modeling, T. Halpin et al., Eds., Springer, 2009, pp. 149–161, doi: 10.1007/978-3-642-01862-6_13.
[11]R. S. Mans, M. H. Schonenberg, M. Song, W. M. P. van der Aalst, and P. J. M. Bakker, “Process mining in health care,” in Proc. Int. Conf. on Health Informatics (HEALTHINF’08), Jan. 2008, pp. 118–125.
[12]A. Westfeld and A. Pfitzmann, “Attacks on steganographic systems,” in Proc. 3rd Int. Workshop on Information Hiding, LNCS vol. 1768, I. S. Moskowitz, Ed., Springer, 2000, pp. 61–76, doi: 10.1007/10719724_5.
[13]J. Fridrich, M. Goljan, and R. Du, “Reliable detection of LSB steganography in color and grayscale images,” in Proc. ACM Workshop on Multimedia and Security, 2001, pp. 27–30, doi: 10.1145/1232454.1232466.
[14]X. Yu, T. Tan, and Y. Wang, “Extended optimization method of LSB steganalysis,” in Proc. IEEE Int. Conf. on Image Processing, vol. 2, 2005, pp. II-1102–II-1105, doi: 10.1109/ICIP.2005.1530252.
[15]K. Sullivan, U. Madhow, S. Chandrasekaran, and B. S. Manjunath, “Steganalysis for Markov cover data with applications to images,” IEEE Transactions on Signal Processing, vol. 54, no. 2, pp. 225–236, 2006, doi: 10.1109/TSP.2005.861882.
[16]Y. Q. Shi, C. Chen, and W. Chen, “A Markov process based approach to effective attacking JPEG steganography,” in Proc. 9th Int. Workshop on Information Hiding (IH 2007), Lecture Notes in Computer Science, vol. 4567, Springer, Berlin, Heidelberg, 2007, pp. 249–264, doi: 10.1007/978-3-540-74124-4_17.
[17]T. Pevný, P. Bas, and J. Fridrich, “Steganalysis by subtractive pixel adjacency matrix,” IEEE Transactions on Information Forensics and Security, vol. 5, no. 2, pp. 215–224, 2010, doi: 10.1109/TIFS.2010.2045842.
[18]J. Kodovský, J. Fridrich, and T. Holotyak, “Ensemble classifiers for steganalysis of digital media,” IEEE Transactions on Information Forensics and Security, vol. 7, no. 2, pp. 432–444, 2012, doi: 10.1109/TIFS.2011.2170809.
[19]Y. Qian, J. Dong, W. Wang, and T. Tan, “Deep learning for steganalysis via convolutional neural networks,” in Media Watermarking, Security, and Forensics 2015, vol. 9409, p. 94090J, 2015, doi: 10.1117/12.2083479.
[20]J. Ye, J. Ni, and Y. Yi, “Deep learning hierarchical representations for image steganalysis,” IEEE Transactions on Information Forensics and Security, vol. 12, no. 11, pp. 2545–2557, 2017, doi: 10.1109/TIFS.2017.2710946.
[21]M. Boroumand, M. Chen, and J. Fridrich, “Deep residual network for steganalysis of digital images,” IEEE Transactions on Information Forensics and Security, vol. 14, no. 5, pp. 1181–1193, 2019, doi: 10.1109/TIFS.2018.2871749.
[22]S. Agarwal and K.-H. Jung, “Digital image steganalysis using entropy driven deep neural network,” Journal of Information Security and Applications, vol. 84, Art. no. 103799, 2024, doi: 10.1016/j.jisa.2024.103799.
[23]H. Chen, Q. Han, Q. Li, et al., “Image steganalysis with multi-scale residual network,” Multimedia Tools and Applications, vol. 82, no. 15, pp. 22009–22031, 2023, doi: 10.1007/s11042-021-11611-7.
[24]T. Fu, L. Chen, Y. Jiang, J. Jia, and Z. Fu, “Image steganalysis based on dual-path enhancement and fractal downsampling,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 1–16, 2025, doi: 10.1109/TIFS.2024.3493615.
[25]R. Yang, Y. Yang, L. Zhou, and X. Meng, “A steganalysis method based on relationship mining,” Electronics, vol. 14, no. 21, Art. no. 4347, 2025, doi: 10.3390/electronics14214347.
[26]Z. He, R. Wu, and X. Wang, “Image steganalysis based on an adaptive attention mechanism and lightweight DenseNet,” Computers, Materials & Continua, vol. 85, no. 1, pp. 1631–1651, 2025, doi: 10.32604/cmc.2025.067252.
[27]W. M. P. van der Aalst and S. Dustdar, “Process mining put into context,” IEEE Internet Computing, vol. 16, no. 1, pp. 82–86, 2012, doi: 10.1109/MIC.2012.12.
[28]J. Fridrich and J. Kodovský, “Rich models for steganalysis of digital images,” IEEE Transactions on Information Forensics and Security, vol. 7, no. 3, pp. 868–882, 2012, doi: 10.1109/TIFS.2012.2190402.
[29]A. Gupta, “BOWS2,” Mendeley Data, V1, 2023, doi: 10.17632/kb3ngxfmjw.1.
[30]P. Bas and T. Furon, “BOWS-2 Contest (Break Our Watermarking System),” 2007–2008.
[31]B. Boehm, “StegExpose: A tool for detecting LSB steganography,” arXiv:1410.6656, 2014. [Online]. Available: http://arxiv.org/abs/1410.6656