AQI-HNS: A Security-Aware Hybrid Framework for Quantum-Inspired Image Encryption and Neural Image Hiding with Cross-Dataset Evaluation
Mahmoud Gad, Nehal A. Sakr, Noha A. Hikal, Khalid M. HosnyDigital-image protection often requires two safeguards at once: the content must remain unintelligible to an unauthorized reader, and the communication itself should not be conspicuous. We introduce AQI-HNS, an encryption-first framework that couples a reversible four-dimensional fractional-map cipher with a security-aware neural hiding channel. Session material is derived from a uniformly generated 256-bit master key and a public 96-bit nonce through HKDF-HMAC-SHA3-512. The encryption stage combines stable chaotic permutation, pre- and post-whitening, and a six-round SHAKE256 wide-block Feistel transformation. Evaluation on 100 Kodak and category-balanced USC-SIPI images at 256 × 256 RGB resolution produced byte-exact decryption in every case. Mean ciphertext entropy was 7.9991 bits per byte, adjacent-byte correlations were close to zero, mean fixed-session NPCR was 99.6098%, and mean UACI was 33.4599%. Across 559 one-byte plaintext perturbations, mean NPCR was 99.6094% and mean UACI was 33.4616%. A coarse timing-dependence screen produced maximum absolute Spearman correlations of 0.0905 for encryption and 0.2206 for decryption; these are empirical diagnostics rather than security proofs. The hiding stage uses attention-guided residual embedding, straight-through 8-bit quantization, independent steganalysis, and a multi-scale blind decoder. All neural development and checkpoint selection were confined to DIV2K. At 0.25 bits per pixel, the selected internal checkpoint achieved a mean BER of 0.0190, a P95 BER of 0.0798, and a mean PSNR of 37.35 dB. Frozen external evaluation yielded a mean BER of 0.0625 on 500 COCO images and 0.0597 on 500 ImageNet validation images, confirming a cross-domain recovery weakness. Two learned residual-domain detectors trained only on DIV2K transferred strongly: SRNet AUCs were 0.9967 internally, 0.9910 on COCO, and 0.9988 on ImageNet, while XuNet-style AUCs were 0.9891, 0.9458, and 0.9775, respectively. Finally, a 196,608-byte v6 ciphertext was transported across 385 covers at 0.25 bpp; the recovered ciphertext BER was 0.0284, only 2 of 385 blocks were exact, and the hash/integrity checks failed. The present uncoded neural channel therefore does not provide reliable byte-exact ciphertext transport, and the learned-steganalysis results rule out any claim of undetectability under the tested detectors.