Robust frequency domain watermark embedding and extracting method for resisting image processing attack
By adopting a robust frequency domain watermark embedding and extraction method based on reversible neural network in digital image watermark technology, the problem that the existing technology cannot take into account both concealment and robustness under image processing interference or attacks is solved, and efficient watermark embedding and extraction is achieved.
Patent Information
- Application Number
- CN202411713220.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-05-06
AI Technical Summary
In the face of image processing interference or attacks, existing digital image watermark technology cannot take into account the undetected watermark embedding and robust watermark extraction capabilities.
A robust frequency domain watermark embedding and extraction method based on reversible neural network is adopted to resist image processing attacks by gathering watermark information in the high-frequency interval of the encrypted image during the watermark embedding stage, and using interference cancellation network and information compensation network during the extraction stage.
It realizes the robust watermark extraction capability in image processing attack scenarios, while maintaining the concealment of watermark embedding, improving the robustness of image watermark embedding extraction.
Smart Images

Figure CN119941483A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a robust frequency domain watermark embedding and extraction method for resisting image processing attacks, belonging to the technical field of digital image watermark steganography. Background Art
[0002] The advancement of Internet technology and the popularity of smart communication devices such as mobile phones have promoted the development of multimedia social networks. People can use social networks to share, generate ideas and communicate anytime and anywhere. Among them, pictures are the most commonly used information carriers with the widest application range and the largest volume. For example, for mainstream social media software, thousands of pictures are uploaded or downloaded every second. However, the convenience of the Internet also brings security risks. People can easily copy, modify and forward pictures, leading to endless problems such as piracy, infringement and abuse. In addition, generative models such as DALL-E and Imagen can already generate pictures that are difficult to distinguish between true and false. While these models increase the efficiency of work for people in industries such as painting and design, they also facilitate the spread of false information and urgently need to be supervised. In order to solve the above problems, digital image watermarking technology came into being.
[0003] Existing digital image watermarking technologies can be divided into two categories: visible watermarks and invisible watermarks. Visible watermarks are added directly to images without extraction processes. They are simple to implement, but can be erased by image editing operations, causing them to become invalid. Invisible watermarks use embedding algorithms or neural network models to disperse watermarks into different areas of the image, and then use extraction algorithms or neural network models to extract watermarks. The process is hidden, so it has more applications. Existing invisible watermarking methods are not robust when encrypted images are interfered with or attacked by image processing, and cannot take into account both imperceptible watermark embedding and robust watermark extraction capabilities in interference scenarios. At present, the existing image steganography method HiNet based on reversible neural networks does not consider interference elimination and targeted information compensation in the watermark extraction process; the existing robust reversible image steganography method RIIS, although it considers interference scenarios, does not consider the concealment of encrypted images, and its training involves many components and the training process is complex.
[0004] Therefore, ensuring the concealment of the watermark embedding effect and improving the robust watermark extraction capability under image processing interference or attack scenarios have become urgent issues to be solved. Summary of the invention
[0005] The purpose of the present invention is to ensure the concealment of the watermark embedding effect and to improve the technical problem of robust watermark extraction capability under image processing interference or attack scenarios, and to propose a robust frequency domain watermark embedding and extraction method that resists image processing attacks.
[0006] The working principle of the present invention is:
[0007] In the watermarking stage, based on the imperceptible characteristics of watermark embedding in the high-frequency range of the image and the bidirectional encoding and decoding characteristics of the reversible neural network, the watermark information is driven to gather in the high-frequency range of the encrypted image; in the watermark extraction stage, an interference elimination network is designed to eliminate the interference or attack of image processing faced during the transmission of the encrypted image, and an information compensation network is designed to compensate for the watermark extraction process in a targeted manner. Finally, a robust frequency domain watermark embedding and extraction method that can resist image processing attacks is realized.
[0008] The objective of the present invention is achieved through the following technical solutions:
[0009] A robust frequency domain watermark embedding and extraction method for resisting image processing attacks of the present invention applies encrypted image watermark embedding and extraction scenarios, and includes the following steps:
[0010] Step 1: Construct an encrypted image watermark embedding and extraction model, and set and initialize the parameters of the encrypted image watermark embedding and extraction model;
[0011] Step 1.1: Construct an encrypted image watermark embedding extraction model. The encrypted image watermark embedding extraction model is further composed of a reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli It consists of three sub-network models;
[0012] Step 1.1.1: Construct a reversible neural network model N for image watermark embedding and extraction processing INN ;
[0013] Step 1.1.2: Construct an information supplement network model N for information enhancement processing in image watermark extraction Inf ;
[0014] Step 1.1.3: Construct an interference elimination network model N for eliminating interference factors in image transmission Eli ;
[0015] Step 1.2: Set and initialize the parameters of the encrypted image watermark embedding and extraction model;
[0016] Step 1.2.1: Set the parameters of the encrypted image watermark embedding extraction model; further settings is the image processing attack method, DWT, IWT represents the transformation algorithm from spatial domain to frequency domain and from frequency domain to spatial domain; set I as the carrier image, W as the watermark image, I em To encrypt pictures, The encrypted image after image processing attack, I″ em is the encrypted image after interference elimination, Ire To restore the extracted carrier image, W re To restore the extracted watermark image, M is the watermark embedding information compensation matrix, To extract information from watermark, we need to make up the matrix; set L img is the loss function for calculating the spatial image difference, L LL is the loss function for calculating the difference of low-frequency images; set D as the data set to be selected;
[0017] Step 1.2.2: Initialize the parameters of the encrypted image watermark embedding and extraction model; further initialize the iteration round E to 0; the upper limit of Gaussian noise attack strength is σ; the upper limit of JPEG compression attack strength is Q;
[0018] Step 2: Reversible neural network model N INN and information compensation network model N Inf Conduct training;
[0019] Step 2.1: Reversible neural network model N INN Perform the predetermined forward propagation to obtain the encrypted image I em ; Encrypt image I em Input to the information compensation network model N Inf Obtain watermark extraction information compensation matrix Extract watermark information to make up the matrix and encrypted image I em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0020] Step 2.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Respectively for the reversible neural network model N INN and information compensation network model N Inf Perform parameter optimization and increase the number of iterations E;
[0021] Step 2.3: Iterate steps 3.1 to 3.2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Freeze parameters.
[0022] Step 3: Eliminate the interference network model N Eli Conduct training;
[0023] Step 3.1: Reversible neural network model N INN Perform a second predetermined forward propagation to obtain the encrypted image Iem ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em ; The encrypted image I" after eliminating interference em Secondary input to the information compensation network model N Inf The watermark extraction information compensation matrix is obtained Extract watermark information to make up the matrix And the encrypted image I″ after interference elimination em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0024] Step 3.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E;
[0025] Step 3.3: Iterate steps 4.1 to 4.2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Enable the parameters;
[0026] Step 4: Reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Conduct training; and then obtain a trained encrypted image watermark embedding and extraction model;
[0027] Step 4.1: Reversible neural network model N INN Perform three predetermined forward propagations to obtain the encrypted image I em ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform secondary interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em; The encrypted image I" after eliminating interference em Three inputs to the information compensation network model N Inf The watermark extraction information compensation matrix is obtained Extract watermark information to make up the matrix And the encrypted image I″ after interference elimination em Secondary input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0028] Step 4.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL For the reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E;
[0029] Step 4.3: loop iterate step 4.1 to step 4.2, when the number of iterations reaches the threshold, stop iterative update to obtain the trained encrypted image watermark embedding extraction model;
[0030] Step 5: Input the carrier image I and the watermark image W into the trained encrypted image watermark embedding and extraction model to complete the watermark embedding of the carrier image and the anti-interference extraction processing of the watermark image W; thereby improving the robustness of the image watermark embedding and extraction.
[0031] Beneficial effects:
[0032] Compared with the prior art, the present invention has the following effects:
[0033] 1. The method of embedding watermarks into carrier images of the present invention is more covert, and allows different special types of images to be embedded as watermark images, and the method is highly practical.
[0034] 2. The present invention can extract watermarked images with higher image quality when the encrypted images are subjected to severe image processing attacks, and the method has good robustness.
[0035] 3. The present invention uses a single reversible neural network to embed and extract watermarks, the training process involves fewer components, and adopts a three-stage training method, so the training process is more stable. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a schematic diagram of the process of the present invention;
[0037] Figure 2 It is a schematic diagram of the reversible neural network structure;
[0038] Figure 3 It is a schematic diagram of the information compensation network and interference elimination network architecture. DETAILED DESCRIPTION
[0039] In order to better illustrate the purpose and advantages of the present invention, the invention is further described below in conjunction with the accompanying drawings and examples. It should be noted that the implementation of the present invention is not limited to the following embodiments, and any form of modification or change made to the present invention will fall within the protection scope of the present invention.
[0040] The dataset used in this embodiment is DiffusionDB, which consists of realistic artificial intelligence-generated pictures generated by the Stable Diffusion model based on user descriptions, which is in line with the application scenarios of today's digital media. 800 pictures are randomly selected to form a training set, and another 100 pictures are randomly selected to form a test set. Before training, all pictures are uniformly cropped to 256*256 size; the experimental environment is PyTorch; it runs in the GPU, and the GPU version is NVIDIAGeForce RTX 3090.
[0041] The reversible neural network used in this embodiment is a classic reversible neural network with 12 identical reversible blocks, denoted as N INN , the information compensation network and the interference elimination network are both composed of convolutional neural networks using dense blocks, denoted by N Inf and N Eli , the input and output dimensions of all networks are 256*256. The Adam optimization algorithm is used for training the above networks, the initial learning rate is 1e-5, and the data size of each batch of images is 16. img and L LL All use l 2 Norm implementation.
[0042] Example
[0043] like Figure 1 As shown, a robust frequency domain watermark embedding and extraction method for resisting image processing attacks in this embodiment is specifically implemented as follows:
[0044] Step 1: Construct an encrypted image watermark embedding and extraction model, and set and initialize the parameters of the encrypted image watermark embedding and extraction model;
[0045] Step 1.1: Construct an encrypted image watermark embedding extraction model. The encrypted image watermark embedding extraction model is further composed of a reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli It consists of three sub-network models;
[0046] Step 1.1.1: Construct a reversible neural network model N for image watermark embedding and extraction processing INN ;
[0047] Step 1.1.2: Construct an information supplement network model N for information enhancement processing in image watermark extraction Inf ;
[0048] Step 1.1.3: Construct an interference elimination network model N for eliminating interference factors in image transmission Eli ;
[0049] Step 1.2: Set and initialize the parameters of the encrypted image watermark embedding and extraction model;
[0050] Step 1.2.1: Set the parameters of the encrypted image watermark embedding extraction model; further settings is the image processing attack method, DWT, IWT represents the transformation algorithm from spatial domain to frequency domain and from frequency domain to spatial domain; set I as the carrier image, W as the watermark image, I em To encrypt pictures, The encrypted image after image processing attack, I″ em is the encrypted image after interference elimination, I re To restore the extracted carrier image, W re To restore the extracted watermark image, M is the watermark embedding information compensation matrix, To extract information from watermark, we need to make up the matrix; set L img is the loss function for calculating the spatial image difference, L LL is the loss function for calculating the difference of low-frequency images; set D as the data set to be selected;
[0051] Step 1.2.2: Initialize the parameters of the encrypted image watermark embedding and extraction model; further initialize the iteration round E to 0; the upper limit of Gaussian noise attack strength is σ; the upper limit of JPEG compression attack strength is Q;
[0052] In the embodiment, the upper limit of Gaussian noise attack strength σ=10, the upper limit of JPEG compression attack strength Q=80, and γ 1 ,γ 2 ,γ 3 is the loss weight; E 1 ,E 2 ,E 3 is the iteration threshold of each stage; γ 1 =1,γ 2 =2,γ 3 =1,E 1 =2000,E 2 =2000,E 3 =2000.img Calculate L between image pixels 2 Loss, L LL Calculate L in the low-frequency subband of the image frequency domain 2 loss.
[0053] Step 2: Reversible neural network model N INN and information compensation network model N Inf Conduct training;
[0054] Step 2.1: Reversible neural network model N INN Perform the predetermined forward propagation to obtain the encrypted image I em ; Encrypt image I em Input to the information compensation network model N Inf Obtain watermark extraction information compensation matrix Extract watermark information to make up the matrix and encrypted image I em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0055] Step 2.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Respectively for the reversible neural network model N INN and information compensation network model N Inf Perform parameter optimization and increase the number of iterations E;
[0056] Step 2.3: Iterate steps 3.1 to 3.2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Freeze parameters.
[0057] In the embodiment, Figure 2 As shown in Figure 1, the selected reversible neural network is composed of 12 reversible blocks of the same structure connected in series. Each reversible block has two inputs and two outputs, and the input and output sizes are the same. When the reversible neural network is scheduled to propagate forward, its input is the carrier image I and the watermark image W, and the output is the encrypted image I em and watermark embedding information to make up the matrix M; when the reversible neural network is scheduled to back propagate, its input is the encrypted image I em And watermark extraction information complement matrix The output is the recovered extracted carrier image I re And restore the extracted watermark image W re The size of each input and output image is 256*256*3. Figure 3 As shown in Figure 2, the selected information compensation network contains a total of 8 intermediate layers, and its input is an encrypted image I with a size of 256*256*3 em , the output is a watermark extraction information compensation matrix with a size of 256*256*3
[0058] Step 3: Eliminate the interference network model N Eli Conduct training;
[0059] Step 3.1: Reversible neural network model N INN Perform a second predetermined forward propagation to obtain the encrypted image I em ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em ; The encrypted image I" after eliminating interference em Secondary input to the information compensation network model N Inf The watermark embedding information compensation matrix is obtained Embed the watermark into the information matrix And the encrypted image I″ after interference elimination em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0060] Step 3.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E;
[0061] Step 3.3: Iterate steps 4.1 to 4.2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Enable the parameters;
[0062] In the embodiment, Figure 3 As shown in Figure 1, the selected interference elimination network contains 8 intermediate layers. The input of the interference elimination network is the encrypted image I′ after the image processing attack with a size of 256*256*3. em, the output is the encrypted image I″ with a size of 256*256*3 after interference elimination em In this stage, the input of the information compensation network is the interference-eliminated encrypted image I″ with a size of 256*256*3 em , the output is a watermark extraction information compensation matrix with a size of 256*256*3 The Gaussian noise attack intensity applied to the image is uniformly sampled as integers between 0 and 10 (the upper limit of the Gaussian noise attack intensity σ=10), and the JPEG compression attack intensity applied to the image is uniformly sampled between 100, 95, 90, 85, and 80 (the upper limit of the JPEG compression attack intensity Q=80).
[0063] Step 4: Reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Conduct training; and then obtain a trained encrypted image watermark embedding and extraction model;
[0064] Step 4.1: Reversible neural network model N INN Perform three predetermined forward propagations to obtain the encrypted image I em ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform secondary interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em ; The encrypted image I" after eliminating interference em Three inputs to the information compensation network model N Inf The watermark embedding information compensation matrix is obtained Embed the watermark into the information matrix And the encrypted image I″ after interference elimination em Secondary input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ;
[0065] Step 4.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL For the reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E;
[0066] Step 4.3: loop iterate step 4.1 to step 4.2, when the number of iterations reaches the threshold, stop iterative update to obtain the trained encrypted image watermark embedding extraction model;
[0067] Step 5: Input the carrier image I and the watermark image W into the trained encrypted image watermark embedding and extraction model to complete the watermark embedding of the carrier image and the anti-interference extraction processing of the watermark image W; thereby improving the robustness of the image watermark embedding and extraction;
[0068] In the embodiment, the test set images containing 100 images selected from the DiffusionDB data set are combined in pairs to form 50 pairs of carrier images and watermark images. The Peak Signal-to-Noise Ratio (PSNR) is used as the image quality evaluation index to compare the watermark image and the restored and extracted watermark image, and the average PSNR measurement results of the 50 groups of images are recorded.
[0069] To further verify the effectiveness of the present invention, based on the same experimental environment, using the same test image correspondence relationship and the original configuration parameters of other methods in the embodiment, the present invention is compared with the two deep learning image steganography methods HiNet and RIIS mentioned in the background technology and the traditional image steganography method 4bit-LSB;
[0070] Table 1 Comparison of watermark image extraction effects of different image steganography methods under image processing attacks of different intensities
[0071]
[0072] As shown in Table 1, under different intensities of image processing attacks, the watermark image extraction quality of the present invention is better than other comparison methods, which shows that the present invention has better robustness against image processing attacks. Further, the structural similarity (SSIM) is used to measure the image difference between the carrier image and the secret image. Under the highest interference settings of Gaussian noise σ=10 and JPEG compression Q=80 in Table 1, SSIM reaches 0.8832 and 0.8612 respectively, which shows that the watermark embedding of the present invention has concealment and can ensure that the image is not distorted.
[0073] The specific description above further illustrates the purpose, technical solutions and beneficial effects of the invention in detail. It should be understood that the above is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A robust frequency domain watermark embedding and extraction method to resist image processing attacks, characterized by: The following steps are included: Step 1: Construct an encrypted image watermark embedding and extraction model, and set and initialize the parameters of the encrypted image watermark embedding and extraction model; Step 2: Reversible neural network model N INN and information compensation network model N Inf Conduct training; Step 2.1: Reversible neural network model N INN Perform the predetermined forward propagation to obtain the encrypted image I em ; Encrypt image I em Input to the information compensation network model N Inf Obtain watermark extraction information compensation matrix Extract watermark information to make up the matrix and encrypted image I em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ; Step 2.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Respectively for the reversible neural network model N INN and information compensation network model N Inf Perform parameter optimization and increase the number of iterations E; Step 2.3: Iterate steps 3.1 to 3.
2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Freeze parameters. Step 3: Eliminate the interference network model N Eli Conduct training; Step 3.1: Reversible neural network model N INN Perform a second predetermined forward propagation to obtain the encrypted image I em ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em ; The encrypted image I" after eliminating interference em Secondary input to the information compensation network model N Inf The watermark extraction information compensation matrix is obtained Extract watermark information to make up the matrix And the encrypted image I″ after interference elimination em Input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ; Step 3.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL Interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E; Step 3.3: Iterate steps 4.1 to 4.
2. When the number of iterations reaches the threshold, stop iterative updating and update the reversible neural network model N. INN and information compensation network model N Inf Enable the parameters; Step 4: Reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Conduct training; and then obtain a trained encrypted image watermark embedding and extraction model; Step 4.1: Reversible neural network model N INN Perform three predetermined forward propagations to obtain the encrypted image I em ; Attack method via image processing Gaussian noise attack and JPEG compression attack on encrypted image I em Perform secondary interference processing to obtain the encrypted image I′ after image processing attack em ; will I′ em Input to the interference cancellation network model N Eli The encrypted image I″ after interference elimination is obtained em ; The encrypted image I" after eliminating interference em Three inputs to the information compensation network model N Inf The watermark extraction information compensation matrix is obtained Extract watermark information to make up the matrix And the encrypted image I″ after interference elimination em Secondary input to the reversible neural network model N INN Perform predetermined reverse propagation in order to recover the extracted watermark image W re ; Step 4.2: Use the loss function L to calculate the spatial image difference img And the loss function L that calculates the difference between low-frequency images LL For the reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli Perform parameter optimization and increase the number of iterations E; Step 4.3: loop iterate step 4.1 to step 4.2, when the number of iterations reaches the threshold, stop iterative update to obtain the trained encrypted image watermark embedding extraction model; Step 5: Input the carrier image I and the watermark image W into the trained encrypted image watermark embedding and extraction model to complete the watermark embedding of the carrier image and the anti-interference extraction processing of the watermark image W; thereby improving the robustness of the image watermark embedding and extraction.
2. A robust frequency domain watermark embedding and extraction method for resisting image processing attacks as claimed in claim 1, characterized in that: Step 1 is implemented as follows: Step 1.1: Construct an encrypted image watermark embedding extraction model. The encrypted image watermark embedding extraction model is further composed of a reversible neural network model N INN , Information Compensation Network Model N Inf and interference cancellation network model N Eli It consists of three sub-network models; Step 1.2: Set and initialize the parameters of the encrypted image watermark embedding and extraction model.
3. A robust frequency domain watermark embedding and extraction method for resisting image processing attacks as claimed in claim 2, characterized in that: Step 1.1 is implemented as follows: Step 1.1.1: Construct a reversible neural network model N for image watermark embedding and extraction processing INN ; Step 1.1.2: Construct an information supplement network model N for information enhancement processing in image watermark extraction Inf ; Step 1.1.3: Construct an interference elimination network model N for eliminating interference factors in image transmission Eli .
4. A robust frequency domain watermark embedding and extraction method for resisting image processing attacks as claimed in claim 2, characterized in that: Step 1.2 is implemented as follows: Step 1.2.1: Set the parameters of the encrypted image watermark embedding extraction model; further settings is the image processing attack method, DWT, IWT represents the transformation algorithm from spatial domain to frequency domain and from frequency domain to spatial domain; set I as the carrier image, W as the watermark image, I em To encrypt pictures, The encrypted image after image processing attack, I″ em is the encrypted image after interference elimination, I re To restore the extracted carrier image, W re To restore the extracted watermark image, M is the watermark embedding information compensation matrix, To extract information from watermark, we need to make up the matrix; set L img To calculate the loss function of spatial image differences, L LL is the loss function for calculating the difference of low-frequency images; set D as the data set to be selected; Step 1.2.2: Initialize the parameters of the encrypted image watermark embedding and extraction model; further initialize the iteration round E to 0; the upper limit of the Gaussian noise attack strength is σ; the upper limit of the JPEG compression attack strength is Q.