Production-grade steganography engine architected for imperceptible, high-fidelity data embedding. Combines adaptive spatial decomposition, metaheuristic pixel selection, and cryptographic payload protection. Engineered for threat intelligence operations, secure communications, and academic cryptanalysis.
macOS / Linux:
pipx install stegano-core
pipx ensurepathWindows (via WSL2):
wsl2
pipx install stegano-core
pipx ensurepathMinimum Requirements:
- Python 3.10 or later
- 200 MB available RAM
- Supported image format (PNG, BMP, TIFF, PGM, JPG)
STEGANO operates as a menu-driven terminal interface. The tool guides users through a structured workflow with real-time validation, progress indication, and visual diagnostics.
steganoLaunching stegano drops you into the Command Deck — a keyboard-navigable menu with four operations:
- Lock — Encrypt and embed a payload into a cover image
- Unlock — Extract and decrypt a hidden payload from a stego image
- Inspect — Generate a publication-ready visual comparison of cover vs. stego
- Help / Exit — Usage and contact/Exit
The Lock workflow guides you through each step with inline validation:
- Input Cover Image — Path to the original, untouched carrier (PNG recommended)
- Output Path — Destination for the stego image
- Password — Derives a 256-bit AES key via PBKDF2 (100 000 iterations)
- Embed — Paste text directly or reference a file path for binary payloads
- Parameters — Colony size, max iterations, min block size (defaults work well for most cases)
Embedding completes with spatial quality metrics printed to the console (PSNR, SSIM, MSE).
Unlock — Recovering Hidden Data
The Unlock workflow mirrors Lock in reverse:
- Stego Path — Path to the image containing the embedded payload
- Output Path — Where to write the recovered payload
- Password — Must match the password used at embed time
- Parameters — Replay the same colony / iteration settings used during embedding
On success, readable text content is optionally printed to stdout and the raw payload is saved to disk. The GCM authentication tag is verified before any data is returned — a corrupted or tampered image is rejected outright.
The Inspect operation accepts a cover / stego pair and writes a publication-ready PNG figure. Metrics reported:
| Metric | Description |
|---|---|
| PSNR (dB) | Peak Signal-to-Noise Ratio — higher is more imperceptible |
| SSIM | Structural Similarity Index — 1.0 = perceptually identical |
| MSE | Mean Squared Error — pixel-level distortion |
| Changed Pixels | Absolute count of modified pixels |
The generated figure displays four panels side by side: the original cover, the stego product, a ×20 amplified difference map, and the Quadtree pixel pool (yellow = selected safe pixels). This layout is suitable for direct inclusion in academic papers or security reports.
For scripted or non-interactive operation, use the stegano-product command directly.
Lock — embed a text message:
stegano-product lock -i cover.png -o stego.png -p "password" -m "secret message"Lock — embed a binary file:
stegano-product lock -i cover.png -o stego.png -p "password" -f path/to/secret.binUnlock — extract payload:
stegano-product unlock -i stego.png -o extracted.bin -p "password"Unlock — extract and print text to stdout:
stegano-product unlock -i stego.png -o extracted.bin -p "password" --printInspect — generate visual report:
stegano-product inspect --cover cover.png --stego stego.png --output report.png| Command | Flag | Description | Default |
|---|---|---|---|
lock |
-i / --input |
Cover image path | required |
lock |
-o / --output |
Output stego image path | required |
lock |
-p / --password |
AES-GCM encryption password | required |
lock |
-m / --message |
Text payload to embed | — |
lock |
-f / --file |
Binary file path to embed | — |
lock / unlock |
--colony-size |
D-ABC colony size | 30 |
lock / unlock |
--max-iter |
D-ABC max iterations | 50 |
lock / unlock |
--min-block |
Quadtree min block size | 4 |
lock / unlock / inspect |
--force |
Overwrite existing output | false |
unlock |
--print |
Print recovered text to stdout | false |
inspect |
--cover |
Original cover image path | required |
inspect |
--stego |
Stego image path | required |
inspect |
--output |
Output figure path | inspection_result.png |
Either
-mor-fmust be provided forlock, but not both. Interactive mode (stegano) is recommended for guided workflows and error recovery.
| Format | Grayscale | RGB | Recommended | Notes |
|---|---|---|---|---|
| PNG | Yes | Yes | Primary | Lossless; no data loss post-embedding |
| BMP | Yes | Yes | Yes | Uncompressed; large file size acceptable |
| TIFF | Yes | Yes | Yes | Flexible codec support |
| PGM | Yes | — | Grayscale-only | Raw/ASCII grayscale baseline |
| JPG/JPEG | Yes | Yes | Avoid | Lossy compression destroys LSB layer |
Use PNG or BMP for maximum imperceptibility and reproducibility. Deploy RGB over grayscale for 3× payload capacity. Avoid JPEG unless capacity takes priority over security margin.
- Grayscale: ~0.125 bits/pixel (single LSB layer, post-quadtree filtering)
- RGB: ~0.375 bits/pixel (LSB across 3 channels, post-quadtree filtering)
Exact capacity depends on image complexity and D-ABC parameter tuning.
- Base overhead: ~50 MB
- Per-operation peak (1024×1024): 150–200 MB
opencv-python >=4.8.0 Image I/O and basic CV operations
numpy >=1.24.0 Numerical arrays and linear algebra
scikit-image >=0.21.0 SSIM, MSE, and image metrics
rich >=13.5.2 Terminal UI, colors, progress rendering
psutil >=5.9.5 Process monitoring and resource tracking
cryptography >=41.0.3 AES-256-GCM encryption and key derivation
matplotlib >=3.7.2 Visualization and figure generation
questionary >=2.0.0 Interactive terminal prompts and menus
System Requirements: Python 3.10+, Linux (x86_64, ARM64), macOS (Intel, Apple Silicon), Windows via WSL2. Rust optional — pre-compiled wheels provided for common platforms.
--colony-size [int, default: 30] Number of bees in optimization colony
Quality ↑ exponentially; runtime ↑ linearly
Recommended range: 20–60
--max-iter [int, default: 50] Maximum optimization iterations
Convergence ↑; time ↑ linearly
Recommended range: 20–100; diminishing returns >100
--min-block [int, default: 4] Minimum quadtree leaf block size
Safe pixels ↑; complexity ↓
Recommended range: 4–8
Image regions exhibit heterogeneous statistical properties. The adaptive quadtree partitions the spatial domain into blocks of varying granularity, selecting only complex regions (high variance) as candidates for payload embedding.
Algorithm:
- Initialize: Recursively divide image into quadrants
- Compute variance σ²(B) for each candidate block B
- If σ²(B) > threshold T and block dimensions > min_block: subdivide into 4 child quadrants; repeat
- Else if σ²(B) > T and dimensions ≤ min_block: mark all pixels in block as "safe"
- Else: discard block (insufficient complexity)
Result: Sparse coordinate matrix of safe pixels exploitable for embedding without detectability risk.
- Variance threshold T balances capacity vs. imperceptibility
- Minimum block size min_block prevents over-granular partitioning
- Complexity O(N log N) where N = image dimensions
Pixel selection in a discrete combinatorial space requires stochastic exploration. The discrete ABC algorithm treats safe-pixel subset selection as an optimization problem, minimizing detectability while maximizing fidelity preservation.
Algorithm Phases:
- Initialization: Generate random L-subsets of the K safe-pixel pool, initializing food sources
- Employed Bee Phase: Each employed bee explores via single-element swaps; retain improvements, increment failure counter otherwise
- Onlooker Bee Phase: Roulette-wheel selection based on fitness distribution; high-fitness solutions selected with higher probability
- Scout Phase: Discard exhausted food sources (stagnated for
limititerations); discover new random L-subsets - Global Best Tracking: Maintain archive of best solution across all generations
Fitness Function:
f(indices) = Σ image_intensity[j] for j ∈ selected_pixels
Higher-intensity pixels tolerate LSB modification with lower detectability.
Convergence: O(colony_size × max_iter × L) per image; typical runtime 2–3 seconds on modern hardware.
Embedding Protocol:
- Serialize payload (message or file binary)
- Derive 256-bit AES key via PBKDF2(password, salt, 100 000 iterations)
- Encrypt payload using AES-256-GCM; produces ciphertext + authentication tag
- For each safe pixel selected by D-ABC: replace LSB with next payload bit — distortion per pixel ≤ 1
Extraction Protocol:
- Recover bitstream from stego image via selected pixel LSB extraction
- Decrypt ciphertext using derived key and embedded nonce
- Verify authentication tag; abort if corrupted
- Return plaintext or binary payload
Security Properties:
- AES-256-GCM ensures semantic security (IND-CCA2)
- Authentication prevents tampering and confirms integrity
- LSB modifications undetectable to human vision
- Requires cryptanalysis in complement to steganalysis for compromise
STEGANO provides defense against passive observation and standard frequency-domain detection methods. Assumes:
- Attacker has access to stego image but not cover image
- Attacker lacks knowledge of embedding parameters
- Authentication is maintained separately from stego channel
- Semantic Security: AES-256-GCM encryption prevents payload reconstruction without key
- Imperceptibility: Quadtree + D-ABC minimize perceptual detectability in safe regions
- Integrity: GCM authentication tag prevents tampering
- Reproducibility: Deterministic embedding with fixed parameters yields identical stego images
- Fridrich, J., Goljan, M., & Hogea, D. (2003). "Steganalysis of LSB embedding in grayscale images." IEEE Trans. on Signal Processing, 51(5), 1413–1422.
- Holub, V., Fridrich, J., & Denemark, T. (2014). "Universal Distortion Function for Steganography in an Arbitrary Domain." EURASIP Journal on Information Security.
- Karaboga, D., & Basturk, B. (2007). "A powerful and efficient algorithm for numerical function optimization: Artificial Bee Colony (ABC) algorithm." Journal of Global Optimization, 39(3), 459–471.
- Finkel, R. A., & Bentley, J. L. (1974). "Quad Trees: A Data Structure for Retrieval on Composite Keys." Acta Informatica, 4(1), 1–9.
Berkay Bayramoğlu · Betül Göksu · Gülnur Durukan · İsmail Erol
Contributions are solicited for algorithm refinement, platform expansion, and cryptanalytic hardening.
- Open an issue for architectural proposals before implementing changes
- Benchmark impact on embedding speed and imperceptibility metrics
- Provide test coverage for new functionality
- Follow Rust/Python style standards outlined in CONTRIBUTING.md
Released under the MIT License. See LICENSE for complete terms.
Version 0.2.0 — Production Ready
Adaptive Quadtree + Discrete ABC + LSB-Matching
Rust-accelerated. Python-compatible. Cryptographically-sound.





