We propose adversarial embedding, a new steganography and watermarking\ntechnique that embeds secret information within images. The key idea of our\nmethod is to use deep neural networks for image classification and adversarial\nattacks to embed secret information within images. Thus, we use the attacks to\nembed an encoding of the message within images and the related deep neural\nnetwork outputs to extract it. The key properties of adversarial attacks\n(invisible perturbations, nontransferability, resilience to tampering) offer\nguarantees regarding the confidentiality and the integrity of the hidden\nmessages. We empirically evaluate adversarial embedding using more than 100\nmodels and 1,000 messages. Our results confirm that our embedding passes\nunnoticed by both humans and steganalysis methods, while at the same time\nimpedes illicit retrieval of the message (less than 13% recovery rate when the\ninterceptor has some knowledge about our model), and is resilient to soft and\n(to some extent) aggressive image tampering (up to 100% recovery rate under\njpeg compression). We further develop our method by proposing a new type of\nadversarial attack which improves the embedding density (amount of hidden\ninformation) of our method to up to 10 bits per pixel.\n