Robust watermarking method for three-dimensional deformable grid model
Through the watermark embedding method of significant graph calculation and differentiated processing, the problem of insufficient invisibility and robustness of the three-dimensional deformable mesh watermark algorithm in the prior art is solved, and efficient copyright protection is achieved.
Patent Information
- Application Number
- CN202510457830.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-22
AI Technical Summary
The existing three-dimensional deformable mesh watermark algorithm based on deep learning usually uses the same strategy to punish the displacement of different vertices when embedding watermarks, limiting the invisibility and robustness of watermarks.
The significant graph calculation module is used to calculate the grid significant graph, and the watermark information encoding network and embedded network are used to differentiate the three-dimensional grid model, combining the attack network and the extraction network, adjust the watermark embedding strength and resist various attacks.
It significantly improves the invisibility and robustness of watermarks, achieves small embedding distortion, and effectively protects the copyright of the three-dimensional deformable model.
Smart Images

Figure CN120355559A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of robust watermarking, and in particular to a robust watermarking method for three-dimensional deformable mesh models. Background Art
[0002] With the development of computer graphics and advanced intelligent manufacturing, three-dimensional deformable models are widely used in industrial production, medicine, the film industry, the video game industry, computer-aided design, and other fields. A large number of three-dimensional models are exchanged and circulated on the Internet, which poses a huge challenge to the copyright protection of three-dimensional models. As an effective copyright protection measure, digital watermarking technology has been widely used, which can add copyright information to three-dimensional models in an invisible way. To effectively protect three-dimensional models, a watermarking method with both robustness and invisibility is achieved by using graph convolutional networks.
[0003] Three-dimensional deformable models are a special form of mesh with a shared template, that is, a fixed topology. This allows them to match different instances through deformation, such as human faces, bodies, hands, and animal movements. However, creating a three-dimensional deformable model dataset is not only time-consuming and costly, but also extremely easy to copy and spread in the digital age, which directly threatens the rights and interests of digital product owners. Therefore, it is particularly important to protect the copyright of three-dimensional deformable models.
[0004] For three-dimensional deformable robust watermarking, existing three-dimensional mesh watermarking algorithms based on deep learning usually use the same strategy to penalize the displacements of different vertices in the three-dimensional mesh when embedding watermarks, thus limiting their performance in terms of invisibility. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a robust watermarking method for three-dimensional deformable mesh models. The present invention adopts different strategies for the displacements of vertices with different saliencies in the mesh, thereby achieving high robustness and high invisibility.
[0006] The technical solution of the present invention is: a robust watermarking method for three-dimensional deformable mesh models, including the following steps:
[0007] S1), construct a saliency map calculation module, and use the saliency map calculation module to calculate the mesh saliency map of the three-dimensional mesh model;
[0008] S2), use the watermark information encoding network to encode the watermark information into a watermark vector through a fully connected layer,
[0009] and splice it with the original three-dimensional model to form a fused matrix vector;
[0010] S3), encode the matrix vectors obtained by fusing the watermark information and the 3D mesh model using the watermark embedding network, then calculate the saliency map for the vertices of the 3D mesh model, and fuse the watermark information with the vertices with low mesh saliency; calculate the mesh saliency map for the entire 3D mesh model in each iteration process in turn, and then complete the process of guiding watermark embedding; obtain the 3D mesh model with the watermark signal;
[0011] S4), use the attack network to simulate various attacks on the 3D mesh model with the embedded watermark;
[0012] S5), use the watermark extraction network to extract the watermark information from the 3D mesh models under various attacks.
[0013] Preferably, in step S1), construct a saliency map calculation module, and use the saliency map calculation module to calculate the mesh saliency map, which specifically includes the following steps:
[0014] S11), calculate the curvature K of each vertex of the 3D mesh model h , and determine the salient region by identifying the region that is significantly different from the surrounding environment;
[0015]
[0016] where A i is the area of the Voronoi region of vertex v i ; N i is the set of neighboring vertices of vertex v i ; v j is a neighboring vertex of v i ; w ij is the weight of the edge between vertex v i , v j ; n i is the normal vector of vertex v i ;
[0017] S12), use the search bounding box length to define the benchmark for different scale levels of the 3D mesh, and calculate the Gaussian weighted average G(K h (v), σ i ) of the average curvature at different scales;
[0018]
[0019] where σ i = {2∈, 3∈, 4∈,... | ∈ = L×0.003}, L is the border length of the 3D mesh model; N(v, σ i ) = {x|||x - v|| < σ i} represents the set of points whose Euclidean distance to vertex v is within σ iA set of points within; x represents the vertex element in the set;
[0020] S13) After normalizing and non-linearly mapping the Gaussian weighted average value, the saliency regions at different scales are accumulated to obtain the saliency map distribution of the three-dimensional mesh model.
[0021] Preferably, in step S1), the saliency loss function l of the saliency map calculation module saliency is:
[0022]
[0023] where, represents the saliency value of the i-th vertex; N represents the total number of vertices; V enc,i represents the i-th vertex after embedding the watermark, V in,i represents the i-th input vertex.
[0024] Preferably, in step S2), the watermark information encoding network uses a multi-layer perceptron and the Tanh activation function to map the watermark information into a coding vector.
[0025] W out = Tanh(W in , encoder)
[0026] where, encoder represents the fully connected layer, W in is the input watermark, and W out is the output watermark vector.
[0027] Preferably, in step S2), the watermark information is encoded into a watermark vector through the fully connected layer by using the watermark encoding network, which specifically includes the following steps:
[0028] S21) Input the watermark information into the fully connected layer network and output potential coding watermark vectors of different dimensions as training data;
[0029] S22) Iteratively train and adjust the parameters of the watermark embedding network so that the generated watermark coding vector can better represent the watermark information in the latent space.
[0030] Preferably, in step S3), the watermark information and the model are encoded by using the watermark embedding network to obtain a three-dimensional model with a watermark signal, which specifically includes the following steps:
[0031] S31) The watermark embedding network performs a downsampling operation on the fused matrix vector, fuses the mesh model and the watermark feature, and obtains a robust representation of the watermark information;
[0032] S32) Upsample the fused three-dimensional grid model and watermark features, and restore the three-dimensional grid model layer by layer; after upsampling, output the three-dimensional model with watermark information through a fully connected layer.
[0033] Preferably, in step S3), the above-mentioned upsampling and downsampling perform feature fusion through a graph attention mechanism.
[0034] Preferably, in step S3), the watermark embedding loss l of the watermark embedding network enc is:
[0035]
[0036] where N represents the total number of vertices, V enc represents the vertex after embedding the watermark, and V in represents the input vertex.
[0037] Preferably, in step S4), use the attack network to simulate various attacks on the three-dimensional model with the embedded watermark, specifically:
[0038] S41) Design a fully connected network as the parameter of the attack network;
[0039] S42) Use the three-dimensional grid model with the watermark as the input, and use the perturbation acting on the three-dimensional grid model as a simulated attack, and add it to the three-dimensional grid model with the watermark to simulate the attack in the real scenario.
[0040] Preferably, in step S5), the watermark extraction network uses a multi-level structure to generate an intermediate representation of the grid, and processes the output result through a multi-layer perceptron. The watermark extraction accuracy is used as the loss function of the watermark extraction network.
[0041] Preferably, in step S5), use the watermark extraction network to extract the watermark information from the three-dimensional grid model under various attacks, specifically:
[0042] S51) Design a multi-layer fully connected layer as the watermark extraction network;
[0043] S52) Use the three-dimensional grid model of various attacks as the input of the watermark extraction network, and extract the watermark features through the watermark extraction network;
[0044] S53) Input the watermark feature information into the activation layer to obtain the final watermark vector.
[0045] Preferably, in step S5), the watermark extraction loss l of the watermark extraction network dec is:
[0046]
[0047] Among them, λ att represents the attack loss; W att represents the watermark extracted after passing through the attack network; W out represents the watermark information output by the decoder; W in is the input watermark
[0048] Preferably, the overall loss function L is defined as:
[0049] L = λ enc l enc + λ saliency l saliency + λ dec l dec
[0050] Among them, λ enc represents the embedding loss hyperparameter; l enc represents the watermark embedding loss; λ saliency represents the saliency loss hyperparameter; l saliency represents the saliency loss function; λ dec represents the decoding loss hyperparameter;
[0051] l dec is the watermark extraction loss.
[0052] The beneficial effects of the present invention are as follows:
[0053] 1. By introducing the saliency mapping of the three-dimensional mesh, the present invention can adjust the intensity of watermark embedding, significantly improving the invisibility of the watermark and at the same time being able to resist various attacks;
[0054] 2. The loss function designed by the present invention can effectively measure the overall impact of the deformation of different regions of the three-dimensional mesh on human visual perception and can also be used as an evaluation index for the degree of visual saliency modification;
[0055] 3. The present invention achieves high watermark robustness and small watermark embedding distortion, and can realize the copyright protection of three-dimensional deformable models. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 is a schematic flow chart of the robust watermark method of the present invention;
[0057] Figure 2 is a downsampling flow chart of the three-dimensional model watermark embedding network of the present invention;
[0058] Figure 3 is a schematic diagram of the watermark information encoding network of the present invention;
[0059] Figure 4This is the saliency distribution map of the 3D mesh model of the present invention;
[0060] Figure 5 This is the effect diagram of the 3D mesh model of the present invention when it is under different attacks. Detailed implementation manners
[0061] The following further describes the detailed implementation manners of the present invention with reference to the accompanying drawings:
[0062] As Figure 1 shown, this embodiment provides a robust watermarking method for a 3D deformable mesh model, including the following steps:
[0063] S1), construct a saliency map calculation module, and use the saliency map calculation module to calculate the mesh saliency map of the 3D mesh model; specifically including the following steps:
[0064] S11), calculate the curvature K of each vertex of the 3D mesh model h , and determine the saliency region by identifying the region that is significantly different from the surrounding environment;
[0065]
[0066] wherein, A i is the area of the Voronoi region of vertex v i ; N i is the set of neighboring vertices of vertex v i ; v j is a neighboring vertex of v i ; w ij is the weight of the edge between vertex v i , v j ; n i is the normal vector of vertex v i ;
[0067] S12), use the search bounding box length to define the benchmark of different scale levels of the 3D mesh, and calculate the Gaussian weighted average G(K h (v), σ i ) of the average curvature at different scales;
[0068]
[0069] wherein, σ i = {2∈, 3∈, 4∈,... | ∈ = L×0.003}, L is the border length of the 3D mesh model; N(v, σ i ) = {x|||x - v|| < σ i} represents the set of points whose Euclidean distance to vertex v is within σ i ; x represents the vertex element in the set;
[0070] S13), After normalizing and non-linearly mapping the Gaussian weighted average value, the saliency regions at different scales are accumulated to obtain the saliency map distribution of the three-dimensional mesh model, as Figure 4 shown.
[0071] In this embodiment, the saliency loss function l of the saliency map calculation module saliency is:
[0072]
[0073] where, represents the saliency value of the i-th vertex; N represents the total number of vertices; V enc,i represents the i-th vertex after embedding the watermark, V in,i represents the i-th input vertex.
[0074] S2), Use the watermark information encoding network to encode the watermark information into a watermark vector through a fully connected layer, and splice it with the original three-dimensional model to form a fused matrix vector;
[0075] The watermark information encoding network of this embodiment is as Figure 3 shown; The watermark information encoding network is used to map the input binary watermark information into a coded vector; In order to achieve efficient coding and accelerated convergence, the watermark information encoding network adopts a multi-layer perceptron and uses the Tanh activation function to map the watermark information into a coded vector, aligning the watermark information with the three-dimensional mesh model data so that it can be trained with the three-dimensional model in the same dimension.
[0076] W out = Tanh(W in , encoder)
[0077] where, encoder represents the fully connected layer, W in is the input watermark, and W out is the output watermark vector.
[0078] Encoding the watermark information into a watermark vector by using the watermark encoding network specifically includes the following steps:
[0079] S21), Input the watermark information into the fully connected layer network and output potential coded watermark vectors of different dimensions as training data;
[0080] S22), Iteratively train and adjust the parameters of the watermark embedding network so that the generated watermark coded vector can better represent the watermark information in the latent space.
[0081] S3). Encode the matrix vector obtained by fusing the watermark information and the 3D mesh model using the watermark embedding network, then calculate the saliency map for the vertices of the 3D mesh model, and fuse the watermark information with the vertices with low mesh saliency; calculate the mesh saliency map for the entire 3D mesh model in each iteration in turn, and then complete the process of guiding watermark embedding; obtain the 3D mesh model with the watermark signal; in this embodiment, the input includes the latent encoding and the vertices of the original mesh, where the vertex features only include spatial coordinates, and a five-level hierarchical structure with a sampling factor of 4 is adopted; specifically, it includes the following steps:
[0082] S31). The watermark embedding network performs downsampling on the fused matrix vector, fuses the mesh model and the watermark features, and obtains a robust representation of the watermark information; the process of downsampling is as Figure 2 shown;
[0083] S32). Perform upsampling on the fused 3D mesh model and the watermark features, and gradually recover the 3D mesh model; after upsampling, output the 3D mesh model with the watermark information through a fully connected layer.
[0084] In this embodiment, the above upsampling and downsampling perform feature fusion through the graph attention mechanism.
[0085] In this embodiment, the watermark embedding loss l enc of the watermark embedding network is:
[0086]
[0087] where N represents the total number of vertices, V enc represents the vertices after embedding the watermark, and V in represents the input vertices.
[0088] S4). Use the attack network to simulate various attacks on the 3D mesh model with the embedded watermark; specifically:
[0089] S41). Design a fully connected network as the parameters of the attack network;
[0090] S42). Use the 3D mesh model with the watermark as the input, and use the perturbation acting on the 3D mesh model as the simulated attack, and add it to the 3D mesh model with the watermark to simulate the attack in the real scenario. As Figure 5 shown. The attacks in this embodiment include affine transformation, Gaussian noise, cropping, smoothing, and simplification attacks, etc., to enable more robust watermark extraction for the subsequent extraction network.
[0091] S5). Use the watermark extraction network to extract the watermark information from the 3D mesh models under various attacks, specifically:
[0092] S51), designing a multi-layer fully-connected layer as the watermark extraction network;
[0093] S52), using 3D mesh models of various attacks as the input of the watermark extraction network, and extracting watermark features through the watermark extraction network;
[0094] S53), inputting the watermark feature information into the activation layer to obtain the final watermark vector.
[0095] The described watermark extraction network uses a multi-level structure to generate an intermediate representation of the mesh and processes the output result through a multi-layer perceptron. The watermark extraction accuracy is used as the loss function of the watermark extraction network. The watermark extraction loss l dec is:
[0096]
[0097] where λ att represents the attack loss; W att represents the watermark extracted after passing through the attack network; W out represents the watermark information output by the decoder; W in is the input watermark
[0098] Finally, the overall loss function L is defined as:
[0099] L = λ emc l enc + λ saliency l saliency + λ dec l dec
[0100] where λ enc represents the embedding loss hyperparameter; l enc represents the watermark embedding loss; λ salienct represents the saliency loss hyperparameter; l saliency represents the saliency loss function; λ dec represents the decoding loss hyperparameter;
[0101] l dec is the watermark extraction loss.
[0102] The above embodiments and descriptions in the specification only illustrate the principles and the best embodiments of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.
Claims
1. A robust watermarking method for three-dimensional deformable mesh models, characterized in that, It includes the following steps: S1), construct a saliency map calculation module, and use the saliency map calculation module to calculate the grid saliency map of the three-dimensional mesh model; S2), use the watermark information encoding network to encode the watermark information into a watermark vector through a fully connected layer, and splice it with the original three-dimensional model to form a fused matrix vector; S3), use the watermark embedding network to encode the fused matrix vector of the watermark information and the three-dimensional mesh model, then calculate the saliency map for the vertices of the three-dimensional mesh model, and fuse the watermark information with the vertices with small grid saliency; calculate the grid saliency map for the entire three-dimensional mesh model in each iteration process in turn, and then complete the process of guiding watermark embedding; Obtain a three-dimensional mesh model with a watermark signal; S4), use the attack network to simulate various attacks on the three-dimensional mesh model embedded with the watermark; S5), use the watermark extraction network to extract the watermark information from the three-dimensional mesh models under various attacks.
2. The robust watermarking method for a three-dimensional deformable mesh model according to claim 1, characterized in that: In step S1), construct a saliency map calculation module, and use the saliency map calculation module to calculate the grid saliency map, which specifically includes the following steps: S11), calculating the curvature K of each vertex of the three-dimensional mesh model h , and determining the significant region by identifying the region that is significantly different from the surrounding environment; S12), using the search bounding box length as a benchmark for defining different scale levels of the three-dimensional grid, calculate the Gaussian weighted average G(K h (v), σ i ) S13), after normalizing and non-linearly mapping the Gaussian weighted average value, accumulate the saliency regions at different scales to obtain the saliency map distribution of the three-dimensional mesh model.
3. A robust watermarking method for three-dimensional deformable mesh models according to claim 2, characterized in that: In step S11), the curvature K of each vertex h is calculated by the following expression: Among them, A i is the area of the Voronoi region of vertex v i ; N i is the set of neighboring vertices of vertex v i ; v j is a neighboring vertex of v i ; w ij is the weight of the edge between vertices v i , v j ; n i is the normal vector of vertex v i ; In step S12), the Gaussian weighted average value G(K h (v), σ i ) is calculated by the following formula: Among them, σ i ={2∈, 3∈, 4∈, …|∈ = L×0.003}, where L is the border length of the three-dimensional grid model; N(v, σ i )={x|||x - v|| < σ i} represents the set of points whose Euclidean distance to vertex v is within σ i ; x represents the vertex element in the set.
4. A robust watermarking method for a three-dimensional deformable mesh model according to claim 1, characterized in that: In step S2), the watermark information encoding network uses a multi-layer perceptron and the Tanh activation function to map the watermark information into an encoded vector. W out = Tanh(W in , encoder) Among them, encoder represents a fully connected layer, and W in is the input watermark, and W out is the output watermark vector.
5. A robust watermarking method for a three-dimensional deformable mesh model according to claim 4, characterized in that: In step S2), use the watermark encoding network to encode the watermark information into a watermark vector through a fully connected layer, which specifically includes the following steps: S21), input the watermark information into the fully connected layer network, and output potential encoded watermark vectors of different dimensions as training data; S22), iteratively train and adjust the parameters of the watermark embedding network to make the generated watermark encoding vector better represent the watermark information in the latent space.
6. A robust watermarking method for a three-dimensional deformable mesh model according to claim 1, characterized in that: In step S3), use the watermark embedding network to encode the watermark information and the model to obtain a three-dimensional model with a watermark signal, which specifically includes the following steps: S31), the watermark embedding network performs a downsampling operation on the fused matrix vector, fuses the mesh model and the watermark features, and obtains a robust representation of the watermark information; S32), perform an upsampling operation on the fused three-dimensional mesh model and the watermark features, and layer by layer restore the three-dimensional mesh model; after upsampling, output a three-dimensional model with watermark information through a fully connected layer.
7. A robust watermarking method for three-dimensional deformable mesh models according to claim 1, characterized in that: In step S4), use the attack network to simulate various attacks on the three-dimensional model embedded with the watermark, specifically: S41), design a fully connected network as the parameters of the attack network; S42), use the three-dimensional mesh model with the watermark as the input, and use the perturbation acting on the three-dimensional mesh model as a simulated attack, and add it to the three-dimensional mesh model with the watermark to simulate the attack in the real scenario.
8. A robust watermarking method for three-dimensional deformable mesh models according to claim 1, characterized in that: In step S5), use the watermark extraction network to extract the watermark information from the three-dimensional mesh models under various attacks, specifically: S51), design a multi-layer fully connected layer as the watermark extraction network; S52), use the three-dimensional mesh models of various attacks as the input of the watermark extraction network, and extract the watermark features through the watermark extraction network; S53), input the watermark feature information into the activation layer to obtain the final watermark vector.
9. A robust watermarking method for a three-dimensional deformable mesh model according to claim 1, characterized in that: The overall loss function L of the method is defined as: L = λ enc l enc + λ saliency l saliency + λ dec l dec Among them, λ enc represents the embedding loss hyperparameter; λ saliency represents the saliency loss hyperparameter; λ dec represents the decoding loss hyperparameter; l enc represents the watermark embedding loss; l saliency represents the saliency loss function; l dec is the loss of watermark extraction.
10. A robust watermarking method for a three-dimensional deformable mesh model according to claim 9, characterized in that: The significance loss function l of the described significant graph calculation module saliency is as follows: Among them, represents the significance value of the i-th vertex; N represents the total number of vertices; V enc,i represents the i-th vertex after embedding the watermark, and V in,i represents the i-th input vertex;; The watermark embedding loss l of the watermark embedding network described above enc is as follows: where N represents the total number of vertices, and V enc represents the vertices after embedding the watermark, and V in represents the input vertices; The watermark extraction loss l of the described watermark extraction network dec is as follows: Among them, λ att represents the attack loss; W att represents the watermark extracted after passing through the attack network; W out represents the watermark information output by the decoder; W in is the input watermark.
Citation Information
Patent Citations
Three-dimensional visible physical watermark copyright anti-counterfeit marking method for 3D printed model
CN108830776A
Reversible robust watermark embedding and extracting model construction method capable of resisting image attack
CN116452401A
Anti-counterfeiting watermark information embedding method, device, equipment and medium
CN118799158A