Method for generating invisible watermark adversarial samples based on least significant bit modification

By using the basin jump improvement method combined with the lowest significant bit embedding algorithm in the adversarial sample generation method, embedding invisible watermarks as perturbation information, the problem that the adversarial sample generation method in the prior art cannot effectively embed practically meaningful perturbation information, and achieving high attack rate, good visual effect and strong robust adversarial sample generation.

CN114862647BActive Publication Date: 2025-06-24FUJIAN AGRI & FORESTRY UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210544556.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-19
Publication Date
2025-06-24
Estimated Expiration
2042-05-19

AI Technical Summary

Technical Problem

The existing adversarial sample generation method cannot effectively embed practical perturbation information in the original image, and the generated adversarial sample is distorted greatly, making it difficult to apply in actual production and life.

Method used

The invisible watermark adversarial sample generation method based on the least significant bit modification is adopted. The basin jump improvement method combines the least significant bit embedding algorithm to embed the invisible watermark as perturbation information, generate the adversarial sample, and save the position and size of the watermark in the channel of the last pixel.

Benefits of technology

It realizes the embedding of practical perturbation information in the original image, and the generated adversarial samples have good visual effects, high attack rate, strong robustness and good security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention provides an invisible watermark adversarial sample generation method based on least significant bit modification, including: during the execution of the basin hopping improvement method, embedding an invisible watermark as perturbation information through the least significant bit embedding algorithm to generate adversarial samples; during the execution, the channels of the last pixel of the adversarial sample respectively store the position where the watermark is embedded and the specific size of the watermark; during the watermark information extraction process, the entire watermark can be completely extracted according to the information stored in the channels of the last pixel of the adversarial sample. The adversarial samples generated by the above method not only have a good visual effect, but also have a high attack rate, and are suitable for further popularization and application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence security, and in particular to a method for generating imperceptible watermark adversarial samples based on least significant bit modification. Background Art

[0002] Artificial intelligence security is a very popular research field at present, and adversarial samples are an important branch of artificial intelligence security. Traditional adversarial sample generation methods (such as single-pixel attack, boundary attack, point-by-point attack, etc.) mainly focus on artificially adding imperceptible perturbation information to the original image. Therefore, the perturbation information in adversarial samples usually has no practical significance. Because the perturbation information has no practical significance, traditional adversarial sample generation methods cannot be applied to actual production and life. In recent years, some researchers have also proposed new adversarial sample generation methods. They generate adversarial samples by adding meaningful perturbation information to the original image. Although the perturbation information they embed in adversarial samples has practical significance, the adversarial samples generated based on their methods are highly distorted, and the difference between the adversarial samples and the original image is easily perceptible by the human eye. Therefore, it is difficult to be actually applied to actual production and life. At present, in the field of artificial intelligence security, no method has been proposed to add meaningful perturbation information to the original image and make the generated adversarial samples less distorted. Summary of the Invention

[0003] The present invention proposes a method for generating imperceptible watermark adversarial samples based on least significant bit modification, aiming to embed meaningful perturbation information into the original image and make the generated adversarial samples have good visual effects.

[0004] To solve the above problems, the present invention adopts the following technical solutions:

[0005] A method for generating imperceptible watermark adversarial samples based on least significant bit modification, comprising:

[0006] During the execution of the basin-hopping improvement method, an imperceptible watermark is embedded as perturbation information through the least significant bit embedding algorithm to generate adversarial samples;

[0007] The channels of the last pixel of the adversarial sample respectively store the position where the watermark is embedded and the specific size of the watermark.

[0008] Further, the basin-hopping improvement method is a combination of the basin-hopping algorithm and the least significant bit embedding algorithm.

[0009] The specific steps of the above method for generating imperceptible watermark adversarial samples based on least significant bit modification include:

[0010] S1: Determine the digital image into which the watermark is to be embedded;

[0011] S2: Convert the watermark, which is a digital image, into binary;

[0012] S3: Execute the basin-hopping improvement method six times to generate adversarial samples; among them, the differences in the six times of the basin-hopping improvement method lie in the number of iterations and the variation range of the watermark size.

[0013] Furthermore, the number of iterations of the first basin-hopping improvement method is set to 100, the number of iterations of the second and third basin-hopping improvement methods is set to 60, and the number of iterations of the fourth, fifth, and sixth basin-hopping improvement methods is set to 30;

[0014] The variation range of the watermark size of the first basin-hopping improvement method is from 0.09 to 0.22, the variation range of the watermark size of the second and third basin-hopping improvement methods is from 0.18 to 0.22, and the variation range of the watermark size of the fourth, fifth, and sixth basin-hopping improvement methods is from 0.09 to 0.18.

[0015] Furthermore, the specific steps of S3 are as follows:

[0016] S3.1: For the first to fifth basin-hopping improvement methods, find the specific coordinates of the host image and the specific size of the watermark, embed the invisible watermark through the least significant bit technology to generate adversarial samples, retain the samples with adversarial properties, and the samples without adversarial properties enter the next basin-hopping improvement;

[0017] S3.2: For the sixth basin-hopping improvement method, find the specific coordinates of the host image and the specific size of the watermark, embed the invisible watermark to generate adversarial samples, retain the samples with adversarial properties, and also retain the samples without adversarial properties.

[0018] Based on the above solution, the present invention also provides a computer-readable storage medium, in which at least one instruction, at least one segment of program, code set or instruction set is stored, and the at least one instruction, at least one segment of program, code set or instruction set is loaded and executed by a processor to implement the above-mentioned method for generating adversarial samples of invisible watermark based on least significant bit modification.

[0019] Beneficial effects:

[0020] 1) The present invention has a high attack rate. The attack rate of our method is better than traditional black-box attack methods (such as spatial attack, boundary attack, single-pixel attack, etc.), and the highest attack rate of our method reaches 93.5%.

[0021] 2) The present invention has good visual effects. Compared with other methods for generating adversarial samples, the adversarial samples generated based on our method have good visual effects.

[0022] 3) The present invention has good robustness. Compared with other black-box attack methods, the generated adversarial examples are more robust.

[0023] 4) The present invention has good security. The generated adversarial examples are usually considered as the original images by people, thus avoiding the attack on the adversarial examples and being safer. Detailed implementation manners

[0024] The following further describes the present invention in detail in conjunction with embodiments. It should be specifically noted that the following embodiments are only used to illustrate the present invention, but do not limit the scope of the present invention. Similarly, the following embodiments are only partial embodiments of the present invention rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0025] The method for generating an imperceptible watermark adversarial example based on least significant bit modification provided in this embodiment embeds an imperceptible watermark based on the basin-hopping algorithm to generate an adversarial example. The goal is to minimize the confidence that the adversarial example belongs to a specific class, so that the classification model misclassifies, thereby achieving the purpose of fooling the classification model.

[0026] The above method for generating an imperceptible watermark adversarial example based on least significant bit modification includes:

[0027] During the execution of the improved basin-hopping method (BHI), an adversarial example is generated by embedding an imperceptible watermark as perturbation information. During the execution, the channels of the last pixel of the adversarial example respectively store the position where the watermark is embedded and the specific size of the watermark. During the subsequent watermark information extraction process, the entire watermark can be completely extracted according to the information stored in the channels of the last pixel of the adversarial example.

[0028] Among them, the improved basin-hopping method (BHI) combines the basin-hopping algorithm with the least significant bit embedding algorithm to realize generating an adversarial example by embedding an imperceptible watermark through the basin-hopping algorithm.

[0029] The method for generating an adversarial example by embedding an imperceptible watermark through BHI specifically includes the following steps:

[0030] S1: Determine the digital image for embedding the watermark, and only attack the images that are correctly classified under a specific classification model;

[0031] S2: Convert the watermark as a digital image into binary so as to embed the watermark into the host image subsequently.

[0032] S3: Execute the improved basin-hopping method six times to generate an adversarial example; among them, the processes of the six improved basin-hopping methods are similar, and the only difference lies in the number of iterations and the variation range of the watermark size.

[0033] In the first basin-hopping improvement method, the number of iterations is set to 100. However, in the second and third basin-hopping improvement methods, the number of iterations is set to 60. In the fourth, fifth, and sixth basin-hopping improvement methods, the number of iterations is set to 30. In the first basin-hopping improvement method, the size ranges from 0.09 to 0.22. However, in the second and third basin-hopping improvement methods, the size ranges from 0.18 to 0.22. In the fourth, fifth, and sixth basin-hopping improvement methods, the size ranges from 0.09 to 0.18.

[0034] Among them, the specific steps of S3 are as follows:

[0035] S3.1: The first to fifth basin-hopping improvement methods are all to find the specific coordinates of the host image and the specific size of the watermark, embed an invisible watermark through the least significant bit technology to generate adversarial samples, and retain the adversarial samples (the adversarial samples are the samples misclassified by the classification model). The samples without adversarial properties enter the next basin-hopping improvement;

[0036] S3.2: In the sixth basin-hopping improvement method, find the specific coordinates of the host image and the specific size of the watermark, embed an invisible watermark to generate adversarial samples, retain the adversarial samples, and also retain the samples without adversarial properties. Specifically, in this embodiment, the specific coordinates of the host image and the specific size of the watermark are found according to preset conditions.

[0037] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0038] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0039] The above are only some embodiments of the present invention, and thus do not limit the protection scope of the present invention. Any equivalent device or equivalent process transformation made by using the content of the specification of the present invention, or directly or indirectly applied in other related technical fields, shall similarly be included in the patent protection scope of the present invention.

Claims

1. An imperceptible watermark adversarial sample generation method based on least significant bit modification, characterized in that Including: During the execution of the improved basin-hopping method, an invisible watermark is embedded as perturbation information through the least significant bit embedding algorithm to generate adversarial samples. The improved basin-hopping method is the combination of the basin-hopping algorithm and the least significant bit embedding algorithm. The channels of the last pixel of the adversarial sample respectively store the position where the watermark is embedded and the specific size of the watermark. The method for generating an invisible watermark adversarial sample based on least significant bit modification specifically includes the following steps: S1: Determine the digital image into which the watermark is to be embedded. S2: Convert the watermark, which is a digital image, into binary. S3: Execute the improved basin-hopping method six times to generate adversarial samples. Among them, the differences in the six improved basin-hopping methods lie in the number of iterations and the variation range of the watermark size.

2. A method for generating an imperceptible watermark adversarial sample based on least significant bit modification according to claim 1, characterized in that, The number of iterations of the first improved basin-hopping method is set to 100, the number of iterations of the second and third improved basin-hopping methods is set to 60, and the number of iterations of the fourth, fifth, and sixth improved basin-hopping methods is set to 30. The variation range of the watermark size of the first improved basin-hopping method is from 0.09 to 0.22, the variation range of the watermark size of the second and third improved basin-hopping methods is from 0.18 to 0.22, and the variation range of the watermark size of the fourth, fifth, and sixth improved basin-hopping methods is from 0.09 to 0.

18.

3. A method for generating an invisible watermark adversarial sample based on least significant bit modification according to claim 1, characterized in that, The specific steps of S3 are as follows: S3.1: For the first to fifth improved basin-hopping methods, the specific coordinates of the host image and the specific size of the watermark are searched for, and an invisible watermark is embedded through the least significant bit technique to generate adversarial samples. The samples with adversarial properties are retained, and the samples without adversarial properties enter the next improved basin-hopping. S3.2: For the sixth improved basin-hopping method, the specific coordinates of the host image and the specific size of the watermark are searched for, an invisible watermark is embedded to generate adversarial samples, the samples with adversarial properties are retained, and the samples without adversarial properties are also retained.

4. A computer-readable storage medium, characterized in that: The storage medium stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, at least one program, a code set, or an instruction set is loaded and executed by a processor to implement the method for generating an invisible watermark adversarial sample based on least significant bit modification as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Confrontation sample generation method based on invisible watermark, application of confrontation sample generation method and storage medium

    CN114897095A