Aug 2026· International Conference on Digital Image Processing· Vol 14351, pp. 143510I - 143510I-15· 0 citations· 20 references
Engineering
TL;DR
A novel, integrated security frame- work that forges robust and persistent cryptographic link by embedding a patient’s encrypted fingerprint data directly into their medical images, thereby pre- serving the clinical reliability of the scan.
Abstract
The integrity and authenticity of digital medical images are paramount for diagnostic accuracy and patient safety. Existing security measures often fail to create a persistent link between the identity of a patient and their medical scans, leaving decrypted data vulnerable. This paper introduces a novel, integrated security frame- work that forges robust and persistent cryptographic link by embedding a patient’s encrypted fingerprint data directly into their medical images. Our end-to-end system synergistically integrates robust biometric processing with a deep learning-based watermarking model. First, a specialized pipeline preprocesses a patient’s fingerprint using binarization, Zhang-Suen thinning, and minutiae extraction. These biometric features are then secured using AES-GCM (Advanced Encryption Standard with Galois/Counter Mode) and a Fuzzy Vault scheme, generating a compact, encrypted payload. Concurrently, the medical image (DICOM) undergoes modality-specific preprocessing to prepare it for embedding. Crucially, the centerpiece of our framework is a jointly trained embedder-extractor neural network that hides this payload with high imperceptibility, ensuring the watermark remains imperceptible to human eyes and designed to be undetectable by diagnostic algorithms, thereby pre- serving the clinical reliability of the scan. Extensive experiments confirm the method’s efficacy, achieving an outstanding mean Peak Signal-to-Noise Ratio (PSNR) of 41.37 dB, a Structural Similarity Index (SSIM) of 0.9804, and a near-perfect Bit Error Rate (BER) of 0.0020 in a no-attack scenario. Furthermore, the framework demonstrates notable resilience against common signal processing attacks, including noise addition and JPEG compression, proving its potential for deployment in secure clinical environments without compromising medical image quality.
The integrity of medical imaging data is essential to trust diagnostically accurate results and make correct decisions about patient treatment. However, recent advances in deep learning-based image manipulation have revealed critical vulnerabilities in existing medical image workflows. In particular, volumetric (3D) medical images, which are stored as DICOM files, are vulnerable to undetectable (invisible to the naked eye) tampering, which will not be recognizable to a human or passively detectable by any means. This paper describes an active fragile authentication method for 3D medical images, using a valid 3D Discrete Wavelet Transform (DWT). The proposed technique embeds a cryptographically seeded fragile watermark within selected high-frequency volumetric sub-bands, thus providing sensitive detection of content-based tampering while preserving the diagnostic quality of the image. Unlike slice-wise or metadata-based techniques, the proposed method works directly on all 3D volumetric images as one unified volume, which promotes spatial integrity across slices and protects against format-based tampering. Authentication is performed using a block-based correlation analysis method that enables sensitive detection of voxel-level changes, even if the changes are slight. The evaluation results demonstrate that the proposed technique provides very high levels of invisibility (i.e., peak signal-to-noise ratios of greater than 56 dB), while still maintaining very effective authentication capabilities in the presence of noise-based tampering. These results indicate that the proposed method provides an effective and practical solution for safeguarding the integrity of 3D medical imagery in clinical environments.
In the context of medical image storage, cloud-based exchange of digital images, and telemedicine transmission, the medical image watermarking technique is a crucial tool for verifying ownership, integrity, and authenticity. Most medical watermarking schemes currently in existence have its drawbacks, such as fixed-strength embedding, weak protection for important diagnostic regions, weak geometric robustness, and poor implementation reproducibility. In this paper, FLOPBONS-Net is proposed as an ROI-preserved hybrid watermarking framework, which is based on fuzzy logic, flower pollination optimization, DWT-DCT-SVD transform embedding, BCH/CRC payload protection, and attack-aware convolutional neural network decoder. The proposed method classifies ROI and NROI domain and calculates texture, edge, contrast and ROI-risk maps, and finally applies a fuzzy inference system to assign clinically safe embedding strength. A flower pollination optimizer is used to find optimal candidate blocks, embedding gains and transform coefficients with a multi-objective cost function, that optimally minimizes global distortion, ROI distortion, extraction error and maximizes payload and robustness. The watermark payload is scrambled and protected using BCH error correction and CRC verification. Noise, compression, cropping, rotation, blur, filtering, resizing, gamma correction and histogram equalization are used to train an attack-aware CNN decoder. Under major attacks, PSNR more than 50 dB, SSIM more than 0.99, and normalized correlation more than 0.91 are achieved in the evaluation of public chest radiography datasets. The manuscript contains links to datasets of Manusia, implementation architecture, formal equations, numbered algorithms, real-image figure slots with image identification command, visual attack panels, ablation analysis, statistical validation, runtime/memory analysis, scalability, and security metrics. Therefore, the proposed framework will be appropriate for secure radiology image exchange for both authentication and diagnostic quality.
Barkha Sahu, N. Rathore, Abhishek Bansal· International journal of com...· 0 citations
Current optical image watermarking methods are mostly robust techniques aimed at image copyright protection, and the few existing optical fragile watermarking methods for image tamper detection are almost exclusively designed for natural images. To address these issues, this paper proposes an optical fragile zero-watermarking (ZW) method specifically for medical image tamper detection. In the proposed method, the two-dimensional discrete wavelet transform is first utilized to extract the high-frequency polarity features of the medical host image, which are then combined with the SHA-256 hash algorithm to generate chaotic initial state values. Secondly, these initial values are used to dynamically initialize a novel three-dimensional chaotic system (3D-CCSLM) to generate a chaotic sequence, realizing a ‘one-image-one-key’ security mechanism. Subsequently, a cascaded dual-phase mask architecture is introduced during the watermark’s optical encryption stage, where the original watermark sequentially undergoes double Fresnel diffraction and phase truncation operations to form an optical ciphertext; this ciphertext is then diffused by the chaotic sequence and XORed with the host features to generate a ZW certificate to be stored in the database. Extensive experimental results demonstrate that the proposed scheme achieves complete recovery of the copyright watermark under ideal, attack-free conditions and possesses high algorithmic execution efficiency. By integrating the hash avalanche effect with a cascaded optical encryption architecture, the scheme achieves acute fragility against localized tampering, enabling highly sensitive integrity alarms. Furthermore, the noise-like distribution of the generated ZW effectively neutralizes statistical attacks. Ultimately, this zero-distortion approach provides a highly secure and reliable solution for the authentication and integrity verification of sensitive medical imagery.
The outsourced storage of massive medical images in cloud environments carries significant vulnerabilities regarding privacy leakage and data integrity. Existing solutions predominantly utilize conventional cryptography, which struggles to protect the large-area zero-value regions typical of medical images. Furthermore, the lack of high-speed ciphertext retrieval and verification mechanisms hinders the secure interaction of clinical data. To address these dilemmas, this paper proposes an end-to-end secure storage framework based on the zero-trust principle of ‘encrypt-before-outsourcing’. The framework incorporates a thumbnail-based dual-track encryption and authentication protocol, enabling visual pre-screening of images without requiring full decryption while inherently intercepting malicious tampering. At the foundational cryptographic layer, we propose a strongly coupled encryption scheme integrating a two-dimensional high-complexity chaotic map, ciphertext feedback chain scrambling, and hash-adaptive recursive diffusion. Leveraging SHA-256 to extract plaintext features, this scheme dynamically perturbs the chaotic parameters to drive a full-link feedback mechanism. This effectively circumvents the ‘diffusion failure’ induced by large-area zero-value regions, fundamentally thwarting known-plaintext attacks and chosen-plaintext attacks. For cloud interaction, the proposed framework integrates hash trapdoors and the hash-based message authentication code mechanism. This effectively decouples retrieval semantics from the target ciphertexts, thereby enabling O(1) ultra-fast blind search and strict integrity self-checking within the cloud. Experimental results demonstrate that the equivalent key space reaches 2256, and the information entropy approaches the theoretical maximum of 8. Additionally, the number of pixels change rate and unified average changing intensity metrics stabilize at approximately 99.6094% and 33.4635%, respectively. These findings comprehensively guarantee the robust confidentiality of outsourced medical images, providing highly reliable technical support for sharing sensitive clinical data in untrusted public clouds.
Biometric cryptosystems designed with revocability and session-level renewability must preserve template privacy and maintain reliable authentication despite the inherent variability of biometric data. A key unresolved issue in deep biometric protection is how the embedding should be formed from a network’s final representation for secure cryptographic key binding. This study presents a privacy-preserving face biometric framework in which deep embeddings are transformed into binary revocable templates and bound on the fly to cryptographic keys using a fuzzy commitment scheme with error-correcting codes. This work focuses on revocability and session-level renewability; achieving full ISO/IEC 24745 cancelability (specifically unlinkability and irreversibility) requires a keyed transform and salted-hashed storage, which we identify as essential future work. Holding the trained network and the binding pipeline fixed, three feature-aggregation strategies applied to the final representation are systematically compared, namely Global Average Pooling, Smoothed Flattening, and a dedicated Dense Feature Layer. The resulting templates are combined with Reed–Solomon and Extended Hamming coding schemes to analyse the trade-offs among discriminability, error tolerance, key length, and computational cost. Experiments conducted on the FEI Face Database show that the Dense Feature Layer (a learned non-linear projection) provides a markedly more suitable representation for secure key binding than the non-learned spatial-aggregation alternatives, achieving the best authentication performance among the tested alternatives. At the selected operating point under controlled-acquisition, frontal-face conditions, the protected system achieves a 0% false acceptance rate (95% confidence interval [0%, 0.92%], n = 400) with a 1360-bit bound key while maintaining a genuine acceptance rate of 91.0% with Reed–Solomon coding and 89.75% with Extended Hamming coding in the structurally secure independent-segment configuration, which eliminates key-reuse leakage. On the deployment side, mobile-side binding completes in well under a millisecond for both codes, whereas cloud-side decoding differs sharply: Reed–Solomon requires 15.056 ms per attempt against 0.042 ms for Extended Hamming, a≈ 350 × gap that dominates one-to-many scalability. The results further show that Reed–Solomon coding is preferable for high-security low-scale verification, whereas Extended Hamming coding offers substantially lower cloud-side decoding cost and better scalability for one-to-many identification. Consequently, the relative ranking of the three strategies, rather than the absolute error rates, is the primary transferable finding. Overall, the study provides practical design guidance for jointly selecting CNN feature representations and cryptographic binding mechanisms in secure and privacy-preserving biometric authentication systems.
Atef Bentahar, M. C. Ghanem, R. Saidi et al.· Cybersecurity· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.