An Active Detection Method for Deepfakes Based on Blockchain and Robust Watermark Enhancement
By using blockchain and robust watermark technology in deep forgery detection, watermark information is embedded and extracted, and combined with image enhancement technology, the problems of insufficient accuracy and watermark storage security in the existing technology are solved, and efficient forgery traceability and responsibility traceability are achieved.
Patent Information
- Application Number
- CN202510083765.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-01-20
Smart Images

Figure CN119494764B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of image processing, and more specifically, to an active detection method for deepfake based on blockchain and robust watermark enhancement. Background Art
[0002] As a deep learning-based image and video generation technology, Deepfake has developed rapidly in recent years, showing a high degree of generation fidelity and broad application potential. Through a deep neural network, this technology can synthesize virtual images that are extremely similar to the original human face, and then achieve face replacement, action imitation, and expression reenactment, thus generating highly deceptive forged videos. These forged videos are not only visually extremely realistic but also can perfectly replicate the behaviors and emotional expressions of people, making it almost impossible to distinguish the forged content from real videos. With the popularization of Deepfake technology, the potential risks it brings are becoming increasingly apparent, especially in terms of data security, privacy protection, and social ethics.
[0003] To address this issue, researchers have proposed a variety of defense technologies, which can be mainly divided into two categories: passive detection and active defense. Passive detection focuses on post-event evidence collection, relying on features or traces in the video to identify whether it is forged. Current technical methods mostly rely on spatial domain features, frequency domain features, or forged traces left by the generation model. For example, classic neural networks such as Xception Net and Efficient Net are used to extract the features of video frames, while the F3-Net and SPSL methods enhance the detection accuracy by enhancing the frequency domain information. In addition, some methods use attention mechanisms to focus on the subtle forged traces in video frames, thereby further improving the detection accuracy, such as the Multi-Attention method. Although these passive detection technologies have made progress to a certain extent, due to the uneven quality of the datasets and the continuous upgrading of forgery technologies, the existing methods still face huge challenges, especially in the detection of high-quality forged videos, where the accuracy rate is still insufficient.
[0004] Unlike passive detection, active defense technology focuses more on taking preventive measures before forgery occurs. The basic idea is to embed secret information, such as watermarks or adversarial disturbances, into video content to prevent forgery or facilitate tracing the source of forgery. Active defense technology can be further divided into two types: active interference and active forensics. Active interference interferes with the training process of the generative model by adding noise or disturbances to the video data to prevent the generation of forged content. For example, defense methods based on adversarial attacks and data poisoning can effectively protect face data from forgery. Active forensics embeds imperceptible fingerprints or keys into face videos to facilitate forgery tracking and tracing. For example, a method of embedding artificial fingerprints in training data is used to trace forged images, and a decentralized attribute scheme based on user-specific keys is used to enable effective tracking after forgery occurs. Through these technologies, active defense can significantly reduce the risk of the spread of forged content and improve the overall protection effect.
[0005] Although existing Deepfake defense technologies have made some progress in some areas, they still face many key problems. For example, existing passive detection methods have obvious shortcomings when dealing with high-quality forged content, especially when facing new generation models (such as diffusion models), the robustness and accuracy of detection are significantly reduced. At the same time, although active defense technology can effectively prevent forgery, its implementation relies on embedding watermarks or perturbations in the image in advance, which may affect the quality of the video and is vulnerable to attacks by attackers. In addition, in the scenario of large-scale applications, how to balance data privacy protection and the performance of anti-counterfeiting technology remains a major challenge.
[0006] The prior art has the following deficiencies:
[0007] 1. How to embed and maintain imperceptible and highly robust watermark information in image generation, forgery, and subsequent image enhancement processing, so that it can resist various image processing operations and ensure that the watermark information can still be identified after multiple stages of operations, so as to track forgery behavior and trace the source;
[0008] 2. How to improve the visual quality of the image after embedding the watermark, avoid interference with the original image, and reduce the risk of being misjudged as a forged image by the deep fake detection system;
[0009] 3. How to securely store watermark information to prevent it from being tampered with or forged, ensure the security and credibility of image traceability data, and at the same time provide a transparent and reliable forged content responsibility tracing mechanism to enhance the credibility and verifiability of the anti-counterfeiting system. Summary of the invention
[0010] The technical problem to be solved by the present invention is to provide an active deepfake detection method based on blockchain and robust watermark enhancement. By embedding and extracting watermark information and combining blockchain technology, an efficient and reliable solution is provided for deepfake detection and traceability.
[0011] The present invention adopts the following technical solutions to achieve the invention purpose:
[0012] An active deepfake detection method based on blockchain and robust watermark enhancement, characterized by comprising the following steps:
[0013] S1: Train a watermark embedding and extraction network;
[0014] S2: Embed a 100-bit random binary bit watermark into the original face image through the watermark embedding model, and save the watermark information to the blockchain;
[0015] S3: Train a deepfake detector and enhance the watermark image;
[0016] S4: Perform deepfake on the enhanced watermark image, and then extract the watermark from the deepfake image;
[0017] S5: Compare and verify the watermark extracted from the deepfake image with the watermark stored in the blockchain.
[0018] As a further limitation of this technical solution, the specific steps of S1 are:
[0019] S11: Set a watermark embedding network model E with an encoder-decoder structure and a watermark extraction network model D with a decoder structure;
[0020] S12: The watermark embedding network model , where E is the watermark embedding network model, is a clean face image, is a binary watermark, is the face image with the embedded watermark. This model embeds a randomly generated 100-bit binary bit watermark into the clean face image , uses adversarial training, adds slight perturbations to the face image with the embedded watermark , and then inputs it into the deepfake model for malicious tampering. The watermark extraction network model , where D is the watermark extraction network model, is the face image with the embedded watermark (including the face image with only the embedded watermark, the watermark image with slight perturbations added, and the watermark image after malicious tampering), is the extracted binary watermark. The model extracts watermark information from the image. Both the watermark embedding network model and the watermark extraction network model are designed as convolutional neural networks, and their training objective is to minimize the following two loss functions, binary cross-entropy loss and mean square error loss :
[0021] (1)
[0022] where: and are the -th bits of the input watermark and the decoded watermark respectively;
[0023] n is the length of the watermark;
[0024] (2)
[0025] where: is the image after embedding the watermark through the watermark embedding network model;
[0026] is the original clean face image;
[0027] represents the L2 norm, i.e., the Euclidean distance;
[0028] S13: The final training objective is to minimize the weighted sum of the two:
[0029] (3)
[0030] where: is a hyperparameter used to balance the weights of these two loss terms.
[0031] As a further limitation of this technical solution, the specific steps of S2 are:
[0032] S21: The watermark information is mapped to a suitable size through a fully connected layer, prepared and fused with the clean face image ;
[0033] S22: Dynamically adjust the embedding strength of the watermark based on the local complexity of the image to ensure that the effect of the watermark embedded in the image can adapt to the changes in the image content;
[0034] Quantify the features of the image by calculating the local complexity of the input clean face image ;
[0035] Let the clean face image be a tensor of size where:
[0036] B is the batch size, C is the number of channels of the image, and H and W are the height and width of the image;
[0037] The local complexity of the image is calculated by the following formula:
[0038] (4)
[0039] Where: represents the variance calculation in the height and width directions;
[0040] and are the indices of the batch and channel respectively;
[0041] The adaptive embedding weight is calculated based on the local complexity of the image and the embedding strength embedding_strength. The local complexity is scaled by a Sigmoid function so that higher complexity values should have stronger embedding strength;
[0042] (5)
[0043] Where: represents the adaptive weight of each channel at each image position;
[0044] is the Sigmoid function;
[0045] Watermark information is adjusted according to the adaptive embedding weight. The watermark information is a tensor with the same size as the input clean face image, representing the secret information to be embedded. By the following formula, the embedding strength is adjusted to the adaptive weight:
[0046] (6)
[0047] S23: Use multiple convolutional layers and transposed convolutional layers to extract and restore image features. By gradually restoring the structural details of the image, the watermark information is embedded into the original image. At this stage, for each clean face image Assign a unique binary watermark , then, use the trained watermark embedding network model Convert each clean face image into a watermarked image to obtain the watermarked image ;
[0048] S24: Through the smart contract, store the watermark information in the blockchain.
[0049] As a further limitation of this technical solution, the specific steps of S3 are as follows:
[0050] S31: Select face images from the dataset as positive examples, and take the following steps to generate negative samples to train the CNN model;
[0051] Detect faces in the original image, use the dlib package to extract the face region, align the face to multiple scales, randomly select one scale, and then smooth it through Gaussian blur with a kernel size of 5×5. The smoothed face is affine distorted back to the same size as the original face to simulate the generation process of DeepFake;
[0052] Take the region of interest as the input of the CNN model network. Since the goal is to expose the artifacts between the fake face region and the surrounding area, select RoIs as rectangular regions containing the face and the surrounding area;
[0053] S32: Generate adversarial perturbations through the fast gradient sign method. Set the watermarked image as , and classify the image through the neural network model In the fast gradient sign method, the perturbation is generated by calculating the gradient of the image on the deepfake detector. The formula is as follows:
[0054] (7)
[0055] Where: is the size of the perturbation;
[0056] is the loss function;
[0057] is the output of the deepfake detection model for the watermarked image ;
[0058] is the true label,
[0059] is the gradient with respect to the input image;
[0060] After adding the adversarial perturbation, generate the adversarial sample , that is, the image enhanced by the perturbation:
[0061] (8)
[0062] Calculate the loss of the image generated by the adversarial perturbation:
[0063] (9)
[0064] Wherein: represents the output score of the deepfake detection model for the watermarked image after perturbation enhancement, i.e., the adversarial sample ;
[0065] is the loss function that makes the model judge the image as a fake image.
[0066] As a further limitation of the present technical solution, the specific steps of S4 are as follows:
[0067] Use the deepfake generation model to process the enhanced watermarked image to obtain a forged image ;
[0068] (10)
[0069] Input the forged image into the watermark extraction model for watermark extraction;
[0070] (11)
[0071] Wherein: is the watermark extraction model;
[0072] Extract the watermark information from the forged image ;
[0073] As a further limitation of the present technical solution, the specific steps of S5 are as follows:
[0074] Use the bit error rate to measure the difference between the extracted watermark information and the original watermark information :
[0075] (12)
[0076] Wherein: is the number of bits of the watermark information;
[0077] and are the th bits of the original watermark and the extracted watermark respectively.
[0078] Compared with the prior art, the advantages and positive effects of the present invention are:
[0079] The present invention proposes a robust watermark embedding and extraction method. By embedding imperceptible watermark information in an image, it ensures that even during image forgery or subsequent image enhancement processes, the watermark information can still maintain its recognizability. This watermark has high robustness and can effectively resist various image processing operations, ensuring effective traceability and tracking of forgery behaviors at all stages of image generation. The present invention combines image enhancement technology to perform enhancement processing on the image with the embedded watermark. This enhancement processing aims to improve the visual quality of the image and, while maintaining the integrity of the image, cleverly avoid the risk of being misjudged as a forged image by a deep forgery detection system. Through this enhancement technology, the interference of the generated watermark embedding model on the original image can be effectively reduced, and the authenticity of the watermark image can be improved. The present invention further combines the watermark with blockchain technology and uses the decentralized and immutable characteristics of the blockchain to encrypt and store the watermark information. This not only ensures the security and immutability of the watermark data but also provides a transparent and trustworthy evidence chain for image traceability. Through blockchain technology, the responsibility for forged content can be traced, effectively preventing forgers from tampering with or forging the original image data, thereby enhancing the credibility and verifiability of the entire defense system. This method not only conducts forgery traceability by embedding imperceptible watermarks but also combines image enhancement technology to reduce the risk of being recognized by a forgery detection system. The watermark information is encrypted and stored through the blockchain to ensure its immutability and high security, providing a reliable means of traceability for forged content. This method can effectively address the challenges brought by complex generation models, ensure the quality of video images, and provide a transparent and trustworthy evidence chain for the traceability and responsibility tracing of deep forged content. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] Figure 1 is the overall structure diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0081] The following will describe in detail a specific embodiment of the present invention with reference to the accompanying drawings. It should be understood that the protection scope of the present invention is not limited by the specific embodiment.
[0082] The present invention embeds a 100-bit random binary bit watermark into the original face image, and then improves the concealment of the watermark through an image enhancement network to reduce the risk of being detected as a fake image. The enhanced image is sent to a deep forgery model for face swapping operations. In the face-swapped image, the watermark extraction network extracts the watermark information, and these information are then compared with the original watermark information stored in the blockchain to verify the authenticity of the image. The entire process combines deep learning, image processing, and blockchain technology to achieve effective detection and traceability of deep forged content. The overall flowchart is as Figure 1 shown. It includes the following steps:
[0083] S1: Train a watermark embedding and extraction network.
[0084] The specific steps of S1 are as follows:
[0085] S11: Set a watermark embedding network model E with an encoder-decoder structure and a watermark extraction network model D with a decoder structure;
[0086] S12: The watermark embedding network model , where E is the watermark embedding network model, is a clean face image, is a binary watermark, is a face image with the embedded watermark. This model embeds a randomly generated 100-bit binary watermark into the clean face image . Using adversarial training, the face image with the embedded watermark is slightly perturbed and then input into the deepfake model for malicious tampering. The watermark extraction network model , where D is the watermark extraction network model, is a face image with the embedded watermark (including the face image with only the embedded watermark, the watermark image with slight perturbation, and the maliciously tampered watermark image), is the extracted binary watermark. This model extracts the watermark information from the image. Both the watermark embedding network model and the watermark extraction network model are designed as convolutional neural networks, and their training objective is to minimize the following two loss functions, binary cross-entropy loss and mean square error loss :
[0087] (1)
[0088] Where: and are the th bits of the input watermark and the decoded watermark respectively;
[0089] n is the length of the watermark;
[0090] (2)
[0091] Where: is the image after embedding the watermark through the watermark embedding network model;
[0092] is the original clean face image;
[0093] represents the L2 norm, i.e., the Euclidean distance;
[0094] S13: The final training objective is to minimize the weighted sum of the two:
[0095] (3)
[0096] Where: is a hyperparameter used to balance the weights of these two loss terms.
[0097] S2: Embed a 100-bit random binary bit watermark into the original face image through the watermark embedding model, and save the watermark information to the blockchain.
[0098] The specific steps of S2 are as follows:
[0099] The embedding process of the watermark information (i.e., 100-bit binary bits) is realized through an encoder-decoder structure.
[0100] S21: Map the watermark information to an appropriate size through a fully connected layer, and prepare to fuse it with the clean face image for fusion;
[0101] S22: Dynamically adjust the embedding strength of the watermark based on the local complexity of the image to ensure that the effect of the watermark embedded in the image can adapt to the changes in the image content;
[0102] Quantify the features of the image by calculating the local complexity of the input clean face image ;
[0103] Let the clean face image be a tensor of size , where:
[0104] B is the batch size, C is the number of channels of the image, and H and W are the height and width of the image;
[0105] The local complexity of the image is calculated by the following formula:
[0106] (4)
[0107] Where: represents the variance calculation in the height and width directions; after calculation, it is necessary to know which batch and which channel these variance values belong to. That is, each channel in each batch will have a calculated local complexity value;
[0108] and are the indices of the batch and the channel respectively;
[0109] The adaptive embedding weight is calculated based on the local complexity of the image and the embedding strength embedding_strength. The local complexity is scaled by a Sigmoid function so that higher complexity values correspond to stronger embedding strengths.
[0110] (5)
[0111] Among them: represents the adaptive weight for each channel at each image position;
[0112] is the Sigmoid function;
[0113] watermark information is adjusted according to the adaptive embedding weight. The watermark information is a tensor of the same size as the input clean face image, representing the secret information to be embedded. Through the following formula, the embedding strength is adjusted to the adaptive weight:
[0114] (6)
[0115] S23: Use multiple convolutional layers and transposed convolutional layers to extract and restore image features. By gradually restoring the structural details of the image, the watermark information is embedded into the original image. At this stage, for each clean face image assign a unique binary watermark , then, use the trained watermark embedding network model to convert each clean face image into a watermarked image, obtaining the watermarked image ;
[0116] S24: Through the smart contract, store the watermark information in the blockchain.
[0117] S3: Train a deepfake detector and perform image enhancement on the watermarked image.
[0118] The specific steps of S3 are as follows:
[0119] S31: Select face images from the dataset as positive examples. Since the purpose here is to detect the artifacts introduced by the affine face deformation step in deepfake production, the negative example generation process is simplified by directly simulating the affine face deformation step. The following steps are taken to generate negative samples for training the CNN model;
[0120] Specifically, detect faces in the original image, extract the face regions using the dlib package, align the faces to multiple scales, randomly select one scale, and then smooth them through Gaussian blur with a kernel size of 5×5, which can better simulate the different resolutions introduced in the affine deformation surface; the smoothed face is affine distorted back to the same size as the original face to simulate the generation process of DeepFake;
[0121] Take the region of interest (RoI) as the input of the CNN model. Since the goal is to expose the artifacts between the fake face region and the surrounding regions, select the RoIs as rectangular regions that include the face and the surrounding regions;
[0122] Specifically, use facial landmarks to determine the RoIs, such as ;
[0123] where: represents the smallest bounding box that can cover all facial landmarks except the cheek contours;
[0124] The variable is randomly valued within the interval and where h and w are the height and width of the dataset images respectively;
[0125] The regions of interest (RoIs) are resized to 224×224 for training the convolutional neural network (CNN) model. A CNN model ResNet 50 is trained using the training data, and then the predictions of all RoIs are averaged to obtain the final fake probability;
[0126] S32: Generate adversarial perturbations through the fast gradient sign method. Set the watermarked image as , and classify the image through the neural network model . In the fast gradient sign method, the perturbation is generated by calculating the gradient of the image on the deepfake detector, and the formula is as follows:
[0127] (7)
[0128] where: is the size of the perturbation;
[0129] is the loss function;
[0130] is the output of the deepfake detection model for the watermarked image ;
[0131] is the true label,
[0132] is the gradient of the input image;
[0133] After adding adversarial perturbations, an adversarial example is generated , that is, the image enhanced by perturbations:
[0134] (8)
[0135] Calculate the loss of the image generated by the adversarial perturbation :
[0136] (9)
[0137] Where: represents the output score of the deepfake detection model for the watermarked image enhanced by perturbations, that is, the adversarial example ;
[0138] is the loss function that makes the model judge the image as a fake image.
[0139] It is hoped that this loss is as low as possible, that is as close to 0 (real image) as possible. It is necessary to maximize the possibility of being a real image, thereby reducing the probability that the deepfake detection model judges the image as a forged image.
[0140] S4: Deepfake the enhanced watermarked image, and then extract the watermark from the deepfake image.
[0141] The specific steps of the said S4 are:
[0142] Use the deepfake generation model to process the enhanced watermarked image to obtain a forged image ;
[0143] (10)
[0144] Input the forged image into the watermark extraction model for watermark extraction;
[0145] (11)
[0146] Where: is the watermark extraction model;
[0147] Extract the watermark information from the forged image ;
[0148] The specific steps of the said S5 are:
[0149] Measure the extracted watermark information using the bit error rate and the original watermark information The difference between:
[0150] (12)
[0151] Where: is the number of bits of the watermark information;
[0152] and are the bits of the original watermark and the extracted watermark respectively.
[0153] The lower the bit error rate, the more accurate the extracted watermark.
[0154] The present invention significantly improves the detection ability of deepfake content by embedding a robust watermark, combining image enhancement technology, and blockchain encrypted storage. First, the embedding of the robust watermark ensures that the watermark remains recognizable even during image forgery or enhancement, thus effectively tracing and tracking forgery behavior. Second, the image for watermark embedding is optimized through image enhancement technology, which avoids misjudging as a forged image while maintaining visual quality, ensuring the generation quality of the watermark embedding model. More importantly, the present invention combines blockchain technology with watermark information, and uses the decentralization and immutability of blockchain to ensure the security of watermark information, while providing a transparent and credible evidence chain for image tracing. This invention not only effectively improves the detection ability of deepfakes, but also increases the credibility and verifiability of the detection system.
[0155] The specific embodiments of the present invention disclosed above are only for illustration, but the present invention is not limited thereto. Any changes that can be thought of by those skilled in the art should fall within the protection scope of the present invention.
Claims
1. A deep forgery active detection method based on blockchain and robust watermark enhancement, characterized in that: The following steps are involved: S1: Train a watermark embedding extraction network; S2: embed a 100-bit random binary bit watermark into the original face image through the watermark embedding model, and save the watermark information to the blockchain; S3: Train a deep fake detector and perform image enhancement on the watermarked image; S4: Deep forging the enhanced watermark image, and then extracting the watermark from the deep forged image; S5: Compare and verify the watermark extracted from the deep fake image with the watermark stored in the blockchain; The specific steps of S3 are: S31: Select face images from the dataset as positive examples and take the following steps to generate negative samples to train the CNN model; Detect faces in the original image and extract face regions using the software package dlib. Align faces to multiple scales and randomly select one scale before smoothing them using a Gaussian blur with a kernel size of 5×5. The smoothed face is affine-warped back to the same size of the original face to simulate the DeepFake generation process. The region of interest is used as the input of the CNN model network. Since the goal is to reveal the artifacts between the pseudo face region and the surrounding area, the RoIs are selected as the rectangular region containing the face and the surrounding area; S32: Generate adversarial perturbations through the fast gradient sign method, setting the watermarked image to , and through the neural network model To classify images, in the fast gradient sign method, perturb It is generated by calculating the gradient of the image on the deep fake detector, the formula is as follows: (7) in: is the size of the disturbance; is the loss function; The deep fake detection model for the watermarked image is Output: is the true label, is the gradient with respect to the input image; After adding adversarial perturbations, adversarial samples are generated , that is, the image enhanced by disturbance: (8) Compute the image generated by adversarial perturbation Loss: (9) in: Denotes the deep fake detection model for the perturbation-enhanced watermark image, i.e., the adversarial sample The output score of It is the loss function that makes the model judge the image as a fake image.
2. According to claim 1, the deep forgery active detection method based on blockchain and robust watermark enhancement is characterized in that: The specific steps of S1 are: S11: Setting a watermark embedding network model E with an encoder-decoder structure and a watermark extraction network model D with a decoder structure; S12: Watermark Embedding Network Model , where E is the watermark embedding network model, For a clean face image, is a binary watermark, To embed a watermarked face image, the model uses a randomly generated 100-bit binary watermark Embedded into clean face image In this paper, adversarial training is used to embed watermarked face images. Add slight disturbances, then input the deep fake model for malicious tampering, and extract the network model with watermarks , where D is the watermark extraction network model, For a face image with embedded watermark, To extract the binary watermark, the model extracts the watermark information from the image. Both the watermark embedding network model and the watermark extraction network model are designed as convolutional neural networks. The training goal is to minimize the following two loss functions: binary cross entropy loss And mean square error loss : (1) in: and are the first Bit; n is the length of the watermark; (2) in: It is the image after watermarking through the watermark embedding network model; is the original clean face image; represents the L2 norm, i.e., the Euclidean distance; S13: The final training goal is to minimize the weighted sum of the two: (3) in: is a hyperparameter used to balance the weights of these two loss terms.
3. The deep forgery active detection method based on blockchain and robust watermark enhancement according to claim 1 is characterized by: The specific steps of S2 are: S21: The watermark information is mapped to a suitable size through a fully connected layer and prepared and compared with the clean face image to integrate; S22: Dynamically adjust the embedding strength of the watermark based on the local complexity of the image to ensure that the effect of the watermark embedded in the image can adapt to changes in the image content; By calculating the input clean face image The local complexity of the image is used to quantify the characteristics of the image; Set a clean face image For a size of A tensor of , where: B is the batch size, C is the number of channels of the image, H and W are the height and width of the image; The local complexity of an image is calculated using the following formula: (4); in: Indicates the variance calculation in the height and width directions; and are the indices of batch and channel respectively; The adaptive embedding weight is calculated based on the local complexity of the image and the embedding strength embedding_strength. The local complexity is scaled by a Sigmoid function so that higher complexity values correspond to stronger embedding strength. (5) in: represents the adaptive weight of each channel at each image position; is the Sigmoid function; Watermark information According to the adaptive embedding weight, the watermark information It is a tensor of the same size as the input clean face image, representing the secret information to be embedded. The embedding strength is adjusted to an adaptive weight through the following formula: (6) S23: Use multiple convolutional layers and deconvolutional layers to extract and restore image features, and gradually restore the structural details of the image to embed the watermark information into the original image. In this stage, for each clean face image Assign a unique binary watermark Then, use the trained watermark to embed the network model Each clean face image Convert to watermark image and get the image embedded with watermark ; S24: The watermark information is stored in the blockchain through smart contracts.
4. The deep forgery active detection method based on blockchain and robust watermark enhancement according to claim 3 is characterized by: The specific steps of S4 are: Generate models using deepfakes For the enhanced watermark image Processing to obtain a forged image ; (10) The forged image is input into the watermark extraction model to extract the watermark; (11) in: Extract the model for watermark; From the forged image Extract the watermark information.
5. The deep forgery active detection method based on blockchain and robust watermark enhancement according to claim 3 is characterized by: The specific steps of S5 are: Use bit error rate to measure the extracted watermark information and original watermark information The difference between: (12) in: is the number of bits of watermark information; and They are the original watermark and the extracted watermark. Bit.
Citation Information
Patent Citations
Deep forgery active evidence obtaining method based on separable perceptual hash enhancement
CN118587568A