Conversation Steganography: LLM-Based Hidden Message Research
Conversation Steganography is a research proof of concept that uses local AI-generated cover text to hide encrypted messages inside ordinary-looking conversations.
Key takeaways#
- Conversation Steganography is an educational proof of concept for hiding encrypted messages inside ordinary-looking chat text.
- The README says the cover text is generated by a local AI model and can be transported through normal messaging apps.
- The project includes a simulation mode so two local participants can test encoding, transport, and decoding on one device.
- Treat it as a security research resource, not a production recommendation. The author flags educational use only and warns that steganography detection techniques already exist.
What the project demonstrates#
Conversation Steganography combines encryption with language-model-generated cover text. A user enters a secret message, the tool encrypts it, and a local model generates innocent-looking text that carries the hidden payload. The receiving side decodes the cover text back into the original message when it has the shared context. The README lists common messaging apps as possible transport channels, but the project itself is about the local encoding and decoding workflow rather than a hosted messaging service.
How builders can use it#
For AI security teams, the repository is useful as a concrete example of why generated text can become a covert channel. For privacy researchers, it gives a hands-on system for thinking about detection, model choice, entropy, and operational risk. For product builders, it is a reminder that LLM features can create data exfiltration paths even when text looks harmless.
Setup notes#
The README shows a Go build flow: clone the repository, build the command under cmd/conversation-steganography, and run the resulting binary. On first run, the tool walks through setup, lets the user pick a local AI model, downloads the model, and creates a config file. The simulation command creates a two-person local conversation for testing the same protocol chain without requiring two devices.
Safety note#
OpenTools lists this as research and defensive education. Do not use it to bypass lawful monitoring or platform rules. The repository itself includes an educational-use-only caution and a warning that hidden-content detection is an active area.