Graphical passwords are an authentication method that uses pictures as passwords instead of using alphanumeric characters. We propose a graphical password method which is difficult to steal original pass-image by using characteristics of human vision system. In our method, we combine low frequency components of a decoy picture with high frequency components of a pass-image. It is easy for legitimate users to recognize the pass-image in the blended image. On the other hand, this task is difficult for attackers. We used discrete wavelet transform (DWT) to blend a decoy image and a pass-image. User studies are conducted to evaluate memorability and shoulder-surfing robustness of this method. We also compared our method with other existing methods in terms of the authentication time and the success ratio by the user test. The results show that our method is more usable and secure against shoulder-surfing.