Meteor: Cryptographically Secure Steganography for Realistic Distributions
Gabriel Kaptchuk, Tushar M. Jois, Matthew Green, Aviel D. Rubin
Abstract
Despite a long history of research and wide-spread applications to censorship resistant systems, practical steganographic systems capable of embedding messages into realistic communication distributions, like text, do not exist. We identify two primary impediments to deploying universal steganography: (1) prior work leaves the difficult problem of finding samplers for non-trivial distributions unaddressed, and (2) prior constructions have impractical minimum entropy requirements. We investigate using generative models as steganographic samplers, as they represent the best known technique for approximating human communication. Additionally, we study methods to overcome the entropy requirement, including evaluating existing techniques and designing a new steganographic protocol, called Meteor. The resulting protocols are provably indistinguishable from honest model output and represent an important step towards practical steganographic communication for mundane communication channels. We implement Meteor and evaluate it on multiple computation environments with multiple generative models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e89be002-2093-4181-baf6-d315740eade0Cited by top-tier papers34
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- On the Reliability of Watermarks for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu et al.ICLR 2024 · 202 citations
- Secret Collusion among AI Agents: Multi-Agent Deception via SteganographySumeet Ramesh Motwani, Mikhail Baranchuk, Martin Strohmeier, Vijay Bolina et al.NeurIPS 2024 · 140 citations
- A Resilient and Accessible Distribution-Preserving Watermark for Large Language ModelsYihan Wu, Zhengmian Hu, Junfeng Guo, Hongyang Zhang et al.ICML 2024 · 50 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
Builds on4
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- Measuring the Deployment of Network Censorship Filters at Global ScaleRam Sundara Raman, Adrian Stoll, Jakub Dalek, Reethika Ramesh et al.NDSS 2020
Related papers
- Perfectly Secure Steganography Using Minimum Entropy CouplingChristian Schröder de Witt, Samuel Sokota, J. Zico Kolter, Jakob Nicolaus Foerster et al.ICLR 2023 · 12 citations
- Provably Robust and Secure Steganography in Asymmetric Resource ScenarioMinhao Bai, Jinshuai Yang, Kaiyi Pang, Xin Xu et al.S&P 2025
- Pulsar: Secure Steganography for Diffusion ModelsTushar M. Jois, Gabrielle Beck, Gabriel KaptchukCCS 2024 · 4 citations
- Discop: Provably Secure Steganography in Practice Based on "Distribution Copies"Jinyang Ding, Kejiang Chen, Yaofei Wang, Na Zhao et al.S&P 2023
- Efficient Provably Secure Linguistic Steganography via Range CodingRuiyi Yan, Yugo MurawakiACL 2026
