Generative AI ethical control and content authentic identification method

By dynamically adjusting the watermark embedding strategy, building game theory models, multimodal pseudo-evaluation analysis and blockchain rights confirmation, the problem of insufficient effectiveness of existing watermark technologies in generative AI content is solved, and efficient copyright protection and authenticity verification are achieved.

CN120068029AActive Publication Date: 2025-05-30北京思普艾斯科技有限公司

Patent Information

Application Number
CN202510257062.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-30
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

The existing watermarking technology faces great discounts in the effectiveness of complex generated content and adversarial attacks in generative AI content, lacks dynamic adjustment capabilities, resulting in insufficient robustness and adaptability, and single modal verification is difficult to cope with multimodal generated content.

Method used

By analyzing the characteristics of the generated content and predicting possible adversarial attack patterns, the watermark embedding strategy is dynamically adjusted, and the watermark robustness is enhanced by using redundant coding techniques. Build a game theory model between guardians and attackers and calculate the optimal watermark embedding strategy of guardians. The multimodal pseudo-authorization analyzer is used to verify the effectiveness of watermarks in combination with image, audio, and video data, and confirm the rights through blockchain technology, and use smart contracts to achieve automatic rights protection.

Benefits of technology

The adaptive adjustment of watermarks in different attack modes is realized, the robustness and attack resistance of watermarks are improved, the copyright protection and authenticity verification of multi-modal generated content is enhanced, and the efficiency and accuracy of copyright management are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068029A_ABST
    Figure CN120068029A_ABST
Patent Text Reader

Abstract

The invention relates to the field of generative artificial intelligence, and discloses a generative AI ethical control and content authentic identification method, which comprises the following steps: analyzing generated content characteristics and predicting an attack mode, dynamically adjusting a watermark embedding strategy, enhancing robustness by using redundant coding, optimizing watermark embedding through a game theory, guaranteeing watermark integrity, and improving the robustness of the generated content. Multi-mode authentic identification analysis verifies the validity of the watermark, and finally, automatic right protection of the copyright is realized through blockchain right confirmation and an intelligent contract; the invention further provides an ethical control and content authentic identification system of the generative AI. The ethical control and content authentic identification system comprises a content analysis module, a watermark embedding module and the like. According to the method, the optimal dynamic adjustment of the watermark embedding strategy is realized through a game model between a protector and an attacker, the watermark can be adaptively adjusted in different attack modes to ensure the effectiveness of the watermark, and the problem that the watermark is easily tampered or removed under adversarial attack is effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of generative artificial intelligence, and specifically to an ethical control and content authenticity verification method for generative AI. Background Art

[0002] With the rapid development of generative artificial intelligence (AI) technology, especially in the fields of image, text, audio, and video generation, the quality and personalization of generated content have been continuously improved. This has enabled generative AI to be widely used not only in the creative industry but also popularized in various social platforms and news dissemination. However, the content generated by generative AI faces increasingly serious copyright and authenticity problems, which directly affect the use and dissemination of content.

[0003] Traditional watermarking technology, as a means of content verification, is widely used in the copyright protection of digital content. By embedding unique identifiers in the content, watermarking technology can help copyright holders confirm the ownership of the content. However, existing watermarking technologies face many challenges in generative AI content, especially under complex generated content and adversarial attacks, the effectiveness of existing technologies is greatly reduced. Traditional watermark embedding methods usually adopt fixed watermark intensity and position, which makes the watermark easily removed or modified when facing attacks such as compression, denoising, or tampering. Existing watermarking technologies lack the ability of dynamic adjustment and cannot automatically optimize the watermark embedding strategy according to the characteristics of the generated content and potential attack patterns, resulting in insufficient robustness and adaptability.

[0004] In addition, most existing watermarking technologies rely on single-modal data for verification and usually only verify a certain form of image, audio, or video. With the progress of generative AI technology, the multi-modal characteristics of generated content have become more prominent. For example, generated content often contains various forms of data such as images, audio, and text, which makes traditional single-modal watermark verification methods difficult to handle complex generated content. Single-modal verification often cannot effectively detect the presence of watermarks, especially when the content encounters different types of forgery or tampering, the accuracy and reliability are relatively low. Therefore, those skilled in the art have proposed an ethical control and content authenticity verification method for generative AI to solve the above problems. Summary of the Invention

[0005] Aiming at the deficiencies of the prior art, the present invention provides an ethical control and content authenticity verification method for generative AI, which solves problems such as the lack of a dynamic adjustment mechanism in the existing watermark embedding method and the watermark verification method being only applicable to single-modal data.

[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: An ethical control and content authenticity verification method for generative AI, including the following steps: Analyze the characteristics of generated content and predict possible adversarial attack patterns; Based on the generated content characteristics and predicted attack patterns, the watermark embedding strategy is dynamically adjusted, and the robustness of the watermark is enhanced by using redundant coding technology; Construct a game theory model between the defender and the attacker, and calculate the defender's optimal watermark embedding strategy to keep the watermark as intact as possible when attacked; The watermark is verified through a multimodal counterfeit detector and image, audio and video data are combined to verify the validity of the watermark; The ownership of each piece of verified generated content is confirmed through blockchain technology, and smart contracts are used to automatically protect rights.

[0007] Preferably, the adjustment of the watermark embedding strategy includes the following process: Based on the characteristics of the generated content and the security level assessment, the watermark strength, distribution area and encoding method are selected; According to the predicted adversarial attack pattern, the watermark redundancy is adaptively increased to enhance the watermark's anti-interference ability.

[0008] Preferably, the calculation of the game theory model includes the following contents: Define the defender utility function as: ; in: is the defender’s utility function; is the probability of successful watermark embedding; is the probability that an attacker successfully removes or tampered with the watermark; The attacker's utility function is defined as: ; in: is the attacker’s utility function; is the probability that an attacker successfully removes or tampered with the watermark; By solving the Nash equilibrium point in game theory, the optimal strategies of the defender and the attacker are obtained, so that the watermark embedding strategy can effectively resist adversarial attacks.

[0009] Preferably, the multimodal counterfeit identification analyzer uses deep learning technology, including the following process: Use pre-trained visual models, speech models, and language models to perform watermark verification on multimodal data such as images, audio, and video; The multimodal information is integrated to comprehensively judge the authenticity of the content and detect whether the watermark has been tampered with or lost.

[0010] Preferably, the blockchain confirmation includes the following steps: Bind the watermark information of each piece of verified generated content to the ownership record of the generated content, and generate an immutable proof of ownership through the blockchain; Preset copyright protection rules in the smart contract, and automatically initiate the rights protection process when detecting forged or infringing content.

[0011] Preferably, the redundancy coding technology includes increasing the redundancy of the watermark, and making the watermark information easier to recover during the modification process of the generated content through coding technology to ensure the integrity of the watermark information under denoising and compression attacks.

[0012] Preferably, the predicted adversarial attack mode generates adversarial samples based on deep learning algorithms and optimizes the watermark embedding strategy for the attack samples.

[0013] Preferably, the multi-modal forgery detection analyzer verifies each media form of the generated content separately and improves the accuracy of the system by fusing the forgery detection results of each media form with weights.

[0014] Preferably, for the generated content after confirmation of rights by the blockchain technology, the infringement handling procedure is automatically triggered through the smart contract, including automatically notifying the content owner and relevant law enforcement agencies, and taking down or deleting the generated content suspected of infringement.

[0015] The ethical control and content forgery detection system for generative AI includes: A content analysis module for analyzing the characteristics of the generated content and predicting possible adversarial attack modes; A watermark embedding module that dynamically adjusts the watermark embedding strategy according to the characteristics of the generated content and the predicted attack mode, and enhances the robustness of the watermark through redundancy coding technology; A game theory calculation module for calculating the optimal strategies of the defender and the attacker to ensure the integrity of the watermark when under attack; A multi-modal forgery detection module for verifying the effectiveness of the watermark through multi-modal data of images, audio, and video; A blockchain rights confirmation module for binding the watermark information of the generated content to its ownership record, ensuring the immutability of the ownership through the blockchain, and realizing automatic copyright rights protection through the smart contract.

[0016] The present invention provides an ethical control and content forgery detection method for generative AI. It has the following beneficial effects: 1. The present invention adopts a game theory model and an optimal strategy calculation technical solution. Through the game model between the protector and the attacker, it realizes the optimal dynamic adjustment of the watermark embedding strategy, achieving that the watermark can adaptively adjust to ensure its effectiveness under different attack modes. Compared with the single watermark embedding scheme in the prior art, this technical solution effectively avoids the problem that the watermark is easily tampered with or removed under adversarial attacks, and solves the deficiency that traditional methods cannot cope with complex attack types.

[0017] 2. The present invention adopts a multi-modal forgery identification analysis technical solution. Through the comprehensive verification of various data types such as images, audio, and video, it improves the accuracy of watermark verification, achieving that the existence of the watermark can be effectively confirmed under different modalities of the generated content, and avoiding the limitations of single-modal verification. Compared with the single image verification technology in the prior art, the present invention significantly enhances the system's resistance to diverse forgery means, especially performing better in complex content generation and attack environments.

[0018] 3. The present invention adopts a blockchain confirmation of rights and intelligent contract protection technical solution. It binds the watermark information of the generated content with the ownership record to ensure that the copyright information cannot be tampered with, and automatically executes copyright protection measures through intelligent contracts, achieving automated and seamless copyright management and rights protection, avoiding the cumbersome process and delays of manual intervention. Compared with the manual copyright management method in the prior art, the present invention effectively improves the efficiency and accuracy of rights protection, and solves the problem of imperfect copyright protection in the process of content generation and protection.

[0019] 4. The present invention adopts a technical solution that combines redundant coding and watermark embedding. By increasing the redundancy of the watermark, the watermark can still be effectively restored when the generated content encounters various adversarial attacks such as compression and denoising, achieving the effect of retaining valid watermark information under various attack conditions. Compared with the vulnerability of the watermark after embedding in the prior art, the present invention significantly improves the robustness and anti-attack ability of the watermark, and solves the shortcoming that traditional watermark technologies are prone to failure when the content is modified. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 is a schematic flow chart of the method of the present invention; Figure 2 is a schematic diagram of the system architecture of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0022] Please refer to the attached Figure 1 , the embodiments of the present invention provide an ethical control and content forgery detection method for generative AI, including the following steps: S1. Analyze the characteristics of the generated content and predict possible adversarial attack patterns; Specifically, the core purpose of this step is to comprehensively analyze the content generated by generative AI and predict possible adversarial attack patterns. Through this process, it can provide guidance for optimizing the subsequent watermark embedding strategy. The generated content can cover various media forms such as images, texts, audios, or videos, which have different characteristics and thus need to be analyzed separately. The analysis results will provide a basis for the embedding strength, layout, and redundant coding of the watermark in the subsequent steps, thereby ensuring that the watermark remains effective when encountering attacks.

[0023] In this embodiment, first, the system extracts the characteristics of the generated content, specifically including a deep analysis of various features of the generated content. For image data, a convolutional neural network (CNN) is used to extract features such as pixels, textures, and color distributions; for text data, a Transformer-based model is used to extract syntactic structures, semantic relationships, and context information; for audio or video content, key features are extracted through spectral analysis and time-domain analysis. Through these feature extractions, the system can better understand the internal structure of the generated content and provide a detailed analysis basis for watermark embedding.

[0024] When extracting the features of the generated content, pre-trained models can be selected, especially pre-trained neural networks for specific content types (such as images, videos). Using these pre-trained models can improve the efficiency of feature extraction and help the system adapt to different types of generated content faster. These models are trained with a large amount of data, can effectively extract important information that may be contained in the content, and pay attention to important regions in the content.

[0025] Specifically, for generated image content, low-level features such as edges and textures of the image, as well as high-level features such as color distribution and illumination, can be extracted through a convolutional neural network (CNN) model. These features will contribute to the optimization of the subsequent watermark embedding strategy. For example, in an image, complex texture regions may become target regions for watermark embedding because these regions are difficult to detect and have high anti-attack capabilities.

[0026] The processing of text content may adopt models such as BERT or GPT. By analyzing the sentence structure, semantic understanding, and context information in the text through the model, the key regions for generating text can be provided. For audio or video content, time-domain and frequency-domain analysis methods are adopted. Through the short-time Fourier transform (STFT) or wavelet transform (WT), specific frequency ranges in the audio or video can be extracted, thus providing effective regions for subsequent watermark embedding.

[0027] In addition, after content feature extraction, the system needs to predict the possible types of attacks based on the characteristics of the content. This process is trained based on deep learning models for the generation of adversarial samples, specifically including generative adversarial network (GAN) models and other attack simulation models. The system predicts the possible attack patterns at this stage, such as image compression attacks, denoising attacks, image tampering attacks, text rewriting attacks, etc.

[0028] Generally, for image data, the most common attack means are watermark removal attacks and image compression attacks. Watermark removal attacks usually delete the watermark through image editing tools, and image compression may cause the loss of watermark information. For text data, text tampering or sentence rewriting may cause the change or deletion of watermark information. Therefore, the system needs to automatically adjust the watermark embedding method and redundancy according to the predicted attack methods. For example, if the system predicts that it may face an image watermark removal attack, it can embed the watermark in multiple regions of the image and adopt redundant coding technology to ensure the watermark recovery ability.

[0029] When it is predicted that audio or video content may encounter denoising attacks, the system can increase the strength and redundancy of the watermark to ensure that the watermark information can be effectively recovered in complex audio content. In this way, even when encountering attacks such as denoising or compression, the watermark can still be recovered to a certain extent.

[0030] Specifically, to improve the accuracy of prediction, the system may adopt a method based on the generative adversarial network (GAN) to train adversarial attack samples and optimize the watermark embedding strategy for the generated adversarial samples. Through generative adversarial training, the system can foresee different types of attack means and make targeted adjustments during the watermark embedding process, thereby maximizing the anti-attack ability of the watermark.

[0031] The data after generating content feature extraction will be input into the following formula to calculate the security level of the content and the predicted attack probability: ; Where: is the probability of successful attack; represents the characteristics of the generated content; is the parameter of the model; A function representing the probability of successful attack.

[0032] Through this formula, the system can evaluate the security level of the generated content and predict possible attack types, ultimately providing a basis for subsequent watermark embedding strategies.

[0033] The system can continuously optimize the attack prediction model by combining a training strategy based on reinforcement learning. The reinforcement learning model can further improve the prediction accuracy by adjusting the model parameters in multiple iterations, enabling the system to respond promptly to new types of adversarial attacks.

[0034] S2. Dynamically adjust the watermark embedding strategy based on the characteristics of the generated content and the predicted attack patterns, and use redundant coding technology to enhance the robustness of the watermark. Specifically, in step S1, the characteristics of the generated content are successfully extracted, and potential attack patterns are predicted. Based on this information, the system will enter the watermark embedding stage. In this stage, the system will select a suitable watermark embedding strategy and use redundant coding technology to enhance the robustness of the watermark. The goal of watermark embedding is to make the watermark have good concealment in the generated content while ensuring its effective recovery when encountering adversarial attacks. Through this stage, the system not only embeds the watermark but also improves the anti-attack ability of the watermark through redundant design, providing technical support for subsequent verification and copyright protection.

[0035] In this embodiment, the watermark embedding strategy is dynamically selected according to the content characteristics and attack prediction results extracted in step S1. For example, for image content, the system may choose to embed the watermark in the texture area of the image because these areas are more complex and less likely to be noticed. For text content, the system can select a suitable location for watermark embedding according to the context structure to maximize the anti-interference ability of the watermark.

[0036] Specifically, watermark embedding first needs to determine the type of the generated content and the expected attack pattern. For example, when generating an image, the system may use an algorithm based on a convolutional neural network (CNN) to determine which areas in the image have a high texture complexity, and these areas are usually preferred areas for embedding the watermark. Selecting low-frequency areas or areas with rich details in the image as embedding points can effectively improve the concealment of the watermark and reduce the loss of the watermark under attacks.

[0037] During the process of generating text, the system will analyze the syntactic structure and semantic information, and select those core sentences or important grammar positions to embed the watermark. For example, select specific morphological changes of verbs, nouns, or keywords as the carrier of the watermark. Through these technical means, the loss of the watermark in attacks such as text content rewriting and forgery can be minimized.

[0038] The watermark embedding of audio content can be based on the characteristics of the time domain and frequency domain. Select the "hidden" area in the spectrum to embed the watermark. By using methods such as Fourier transform, the watermark information is embedded into the high-frequency area of the audio. These areas have less impact on the human ear but are very important for the digital processing of audio, so they will not be easily removed.

[0039] The strength and distribution method of the watermark will be dynamically adjusted according to the complexity of the generated content and the attack mode. If it is predicted that the content will encounter a watermark removal attack, the system can increase the redundancy of the watermark. For example, by increasing the repeated embedding of the watermark in multiple areas, so that even if some watermark areas are attacked and removed, there are still other redundant watermark areas that can ensure the integrity of the watermark information.

[0040] To further enhance the stability of the watermark in the attack environment, the system uses redundant coding technology. This redundant coding can not only improve the recovery ability of the watermark information, but also make the watermark remain effective when encountering attacks such as compression and denoising.

[0041] Specifically, the redundant coding technology embeds the watermark information into multiple different parts by adding extra information, thus avoiding the loss of watermark information during the content processing. For example, use Huffman coding, RS code or other information redundancy coding methods to encode the watermark data. These coding methods can increase the redundancy of the watermark information, so that the watermark can still be recovered when the content is compressed or tampered with.

[0042] The redundant coding technology can select different coding schemes for different types of generated content. For example, in audio watermark embedding, use block coding technology to disperse the watermark information into different time periods of the audio signal. In image watermarking, a coding method based on the discrete cosine transform (DCT) can be used to embed redundant watermark data in the frequency domain of the image.

[0043] The redundant coding method ensures that even under various attacks such as high compression, denoising, and distortion, the watermark information can still be recovered to a certain extent. Therefore, this redundant coding method greatly enhances the robustness of the watermark and improves the security of the generated content under complex attacks.

[0044] The redundant coding technology can be combined with machine learning methods to automatically optimize the embedding position and redundancy of the watermark. By training a deep neural network, the system can learn how to select the best watermark embedding position in the content and adjust the redundant information according to the attack mode, thereby further improving the anti-attack ability of the watermark.

[0045] In this embodiment, the embedding of the watermark and the redundant coding work together, significantly enhancing the concealment and anti-attack ability of the watermark in the generated content. Through watermark embedding and redundant design, the system ensures that the watermark information is not only hidden during the content generation stage, but also can be quickly restored when encountering different types of adversarial attacks, guaranteeing the authenticity of the generated content and copyright protection.

[0046] The redundancy of the watermark information can be quantitatively evaluated by the following formula: ; Where: represents the probability of successful watermark embedding; represents the characteristics of the generated content; represents the watermark information; represents the redundancy of the redundant coding; represents the watermark embedding function, and the system maximizes the probability of successful watermark embedding by dynamically adjusting the redundancy .

[0047] S3. Construct a game theory model for the defender and the attacker, and calculate the optimal watermark embedding strategy for the defender to keep the watermark as intact as possible when under attack; Specifically, in the aforementioned step S2, the generated content has been analyzed in detail and the watermark has been embedded, and the redundant coding technology has also been applied to enhance the robustness of the watermark. Next, the core task of this step is to calculate the optimal strategies for the defender and the attacker based on the game theory model. Through the framework of game theory, the interaction relationship between the defender and the attacker is modeled as a game. The goal of the defender is to ensure that the watermark information remains undamaged in the content, while the attacker tries to remove or tamper with the watermark information.

[0048] In this embodiment, first, the system constructs utility functions for the defender and the attacker through the game theory model. The defender's utility function and the attacker's utility function respectively represent the success rate of watermark embedding and the success rate of the attacker removing the watermark. By optimizing these utility functions, the system can calculate the optimal watermark embedding strategy for the defender and ensure that the watermark can remain intact under various attacks.

[0049] Specifically, in this step, the defender's utility function mainly considers the relationship between the probability of successful watermark embedding and the probability of the attacker removing the watermark. The defender's utility function can be expressed as: ; Where: represents the probability of successful watermark embedding; represents the probability that the attacker successfully removes or tampers with the watermark; is the defender's utility function.

[0050] The goal of the protector is to maximize , that is, to maximize the probability of successful watermark embedding and minimize the probability of successful watermark removal by the attacker as much as possible.

[0051] Attacker utility function is mainly related to the probability of successful watermark removal by the attacker. The goal of the attacker is to maximize its utility function , that is, to maximize the probability of successful watermark removal as much as possible. The attacker utility function is expressed as: ; where: is the attacker utility function; is the probability of the attacker successfully removing or tampering with the watermark.

[0052] In this step, the strategy choices of the protector and the attacker are solved through the Nash equilibrium in game theory. The Nash equilibrium means that during the game process, both the protector and the attacker reach a stable state, that is, neither party can obtain higher utility by changing its own strategy. In this case, the strategies of the protector and the attacker are respectively and , and these two strategies are optimal.

[0053] The optimal strategy of the protector is to select the most suitable watermark embedding method for the current generated content and attack pattern. This means that the protector will dynamically adjust the strength, layout, and redundancy of the watermark according to the type, characteristics of the generated content, and the predicted attack pattern. In this way, the protector can ensure the integrity of the watermark under different attack conditions.

[0054] To further improve the practicality of the game model, the system can train and optimize the game strategy through reinforcement learning according to the diversity of attack patterns. Reinforcement learning can help the system adaptively adjust the watermark embedding strategy and still effectively respond when encountering unknown or complex attack methods.

[0055] Specifically, the solution steps of the game theory model include: optimizing the utility functions of the attacker and the protector through adversarial training and learning of historical data to ensure flexible adjustment according to the attacker's behavior during actual application. In addition, the system can also consider multiple factors, such as the selection of the watermark embedding area, the allocation of redundancy, and the adjustment of watermark strength, to comprehensively deal with various types of adversarial attacks.

[0056] The watermark embedding strategy of the protector can be further optimized based on models such as generative adversarial networks (GANs). Through GANs, the protector and the attacker can iterate continuously in a simulated environment to obtain a more accurate and efficient watermark embedding strategy. In this way, after multiple trainings, the system can obtain the optimal watermark embedding scheme applicable to various generated contents and attack patterns.

[0057] The system can adopt a multi-dimensional game model, not limited to a single watermark embedding strategy. It can also design multiple protection measures according to the changes in the generated content and the changes in the attacker's strategy. For example, the protector not only selects the embedding strength of the watermark but also considers multiple watermark positions and multiple redundant coding methods to establish multi-level protection in complex generated content.

[0058] Through the application of the game theory model, the system can not only ensure the successful embedding of the watermark in the generated content but also guarantee the optimality of the watermark strategy in practical applications through Nash equilibrium. Through this process, the protector can automatically adjust the watermark embedding strategy based on the characteristics of the generated content and the possible attack methods to ensure the authenticity of the generated content and the copyright protection is not affected.

[0059] In addition, the probability of successful attack and the probability of successful watermark embedding will be updated in real time according to the characteristics of the generated content and the training results of the model. By optimizing these parameters, the system can continuously improve the success rate of the watermark under complex attacks and optimize the watermark embedding strategy of the protector.

[0060] S4. Verify the watermark through a multi-modal forgery analyzer, and verify the effectiveness of the watermark by combining image, audio, and video data; Specifically, in the aforementioned step S3, the game theory model provides an optimal strategy for watermark embedding and ensures that the protector can make dynamic adjustments according to the characteristics of the generated content and the attack pattern. Next, the core task of step S4 is to verify the watermark information in the generated content through multi-modal forgery analysis. The purpose of this step is to verify the embedded watermark through different types of data (such as images, audio, videos, etc.) to ensure its effectiveness and authenticity. This process can further ensure that in complex generated content and diverse attack environments, the watermark can be effectively recovered and maintain its integrity.

[0061] In this embodiment, first, the system uses a multi-modal forgery detection analyzer to detect the generated content. According to the watermark embedding strategy in the aforementioned step S2, the watermark may be embedded in different regions or different modalities of the content. Therefore, it is necessary to analyze from multiple dimensions. The image content may be embedded in the color, texture, or detail regions. The audio content may have a watermark in the frequency domain, while the video content requires synchronous verification by combining image and audio information.

[0062] Specifically, the system will process different forms of data through multiple deep learning models to ensure the consistency and effectiveness of the watermark information in each modality. For example, image data will be processed through a pre-trained convolutional neural network (CNN) to extract the features where the watermark is located and compare them with the embedded watermark information; text data may use a Transformer-based model to verify the watermark information; audio and video data use time-domain and frequency-domain analysis techniques to extract the position and intensity of the watermark in the sound or image frames. These models are combined to ensure that the watermark information can be effectively verified in various types of content.

[0063] The multi-modal forgery detection adopts a fusion strategy, that is, combining information from different modalities such as images, audio, and video, and generating a final verification result through methods such as weighted averaging. This method can improve the accuracy of the system when facing complex generated content. For example, some watermarks may not be easily visually verified due to noise, compression, or other image transformations. However, by combining the auxiliary information in the audio or video with the watermark verification result in the image, it can effectively supplement the missing information of the watermark in the image.

[0064] In the verification of audio content, the system can adopt time-frequency analysis techniques such as wavelet transform or Fourier transform to extract the spectral information in the audio signal and identify the embedded watermark information. In video data, the system not only analyzes each frame of the image but also needs to consider the temporal relationship between video frames to ensure that the watermark information can be consistent in consecutive frames. This multi-dimensional verification method can enhance the accuracy of watermark forgery detection, especially when facing editing, cropping, or other forgery methods.

[0065] Specifically, to improve the verification accuracy, the system combines traditional image processing techniques and modern deep learning methods. For example, in the image verification process, the system extracts the feature region of the watermark through a convolutional neural network (CNN) and combines an adversarial sample generation model to simulate different attack situations to enhance the generalization ability of the model. Through training the model, the system can detect that even after relatively complex image operations (such as high compression, color adjustment, rotation, etc.), the watermark can still be effectively recovered.

[0066] In the multi-modal data of audio and video, the system conducts watermark verification through dual analysis of frequency-domain and time-domain features, avoiding the problems of missed detection or false detection that may occur in a single mode. For example, the system can process the audio signal through Fourier transform, convert the audio signal into a frequency-domain representation, and then compare the similarity between the spectrum information and the watermark features through a trained model to determine whether the watermark is successfully embedded.

[0067] The output result of the multi-modal verification system is the final judgment obtained through comprehensive weights. For the detection results of images, watermarks, audio, and video, the results of each data type will be assigned different weights according to their importance and credibility. For example, for the verification of image watermarks, the information provided by the image content itself is more credible than other modalities, so a higher weight can be assigned; for audio data, although audio can be used as a supplementary verification method, the image may still be the main verification channel, so the weight of audio data will be relatively low during comprehensive verification.

[0068] Under this multi-modal fusion scheme, the system not only improves the accuracy of watermark forgery detection but also enhances the resistance to complex forgery methods. The multi-modal forgery detection analyzer can perform verification from multiple angles and multiple modalities, improving the overall robustness and security.

[0069] During the watermark verification process, the goal of the verification model is to calculate the verification success probability of each modality and finally comprehensively obtain the total success probability of the watermark For example, considering the verification results of images, audio, and video comprehensively, the system can obtain the overall verification result through weighted average: ; where: represents the watermark verification success probability of the th modality; is the weight of this modality; is the total number of modalities; is the total success probability of the watermark finally obtained comprehensively.

[0070] In some complex scenarios, the system can use the deep reinforcement learning method to dynamically adjust the weight of each modality. Through the training process, the system can automatically identify which modalities are more important for the verification of the current content and adjust the weights accordingly, thereby further improving the verification accuracy.

[0071] 5. Confirm the rights of each verified generated content through blockchain technology and use smart contracts to achieve automatic rights protection.

[0072] Specifically, in the aforementioned step S4, through multimodal forgery detection and analysis, the watermark of the generated content has been successfully embedded and verified through multiple dimensions. With the completion of the verification, the next step is to ensure the immutability of the copyright of the generated content and the watermark information. The key task in step S5 is to bind the watermark information to the ownership record of the generated content, use blockchain technology to achieve the confirmation of the watermark rights, and perform automatic rights protection operations through smart contracts. Through this process, the system can effectively provide strong copyright protection for content creators and ensure that the watermark information is legally recognized in the generated content.

[0073] In this embodiment, first, the watermark information of the generated content and the corresponding ownership information are recorded on the blockchain. The blockchain technology acts as a "distributed ledger" here, and its immutability ensures that the watermark information of the generated content can be stored and traced in a long-term and stable manner. Through this technology, any piece of generated content and its corresponding watermark information will form a unique and immutable record in the blockchain, ensuring the legality and copyright ownership of the content.

[0074] Specifically, whenever the generated content and its watermark are verified, the system will automatically write this information into the blockchain through an encryption algorithm. The unique identifier of the generated content (such as a hash value) and its corresponding watermark information and copyright information will be submitted as transaction data to the blockchain network. This process not only ensures the authenticity of the generated content but also provides an immutable copyright certificate, preventing anyone from infringing on the copyright through tampering or forgery.

[0075] The blockchain record includes not only the watermark information but also the creator information of the content, the generation timestamp, any modification records of the content, etc. Through these information, the blockchain system can clearly record the generation and modification process of each piece of generated content. These records, as the basis for copyright confirmation, can effectively prevent subsequent infringement acts.

[0076] The system can adopt smart contract technology to conduct copyright protection on the basis of the blockchain. A smart contract is a computer program that automatically executes the terms of a contract. When the blockchain records the copyright information of the generated content, the smart contract can automatically perform corresponding operations according to the preset rules. For example, when the system detects that a certain piece of generated content is suspected of infringement, the smart contract can automatically trigger the rights protection process, including but not limited to notifying the content creator, initiating a request to take down the content, and starting legal prosecution procedures. The automated feature of this process greatly improves the efficiency of copyright protection and avoids the delays and omissions caused by manual intervention.

[0077] Specifically, when the watermark of the content is verified and successfully recorded on the blockchain, the smart contract generates a copyright certificate for the content according to the predefined rules and binds it to the identity of the generator. When the content is uploaded to any platform, the relevant blockchain information will be uploaded as the copyright certificate together, ensuring that the platform can automatically identify and protect the copyright of the content. Once an infringement occurs, the smart contract will automatically execute a series of rights protection actions according to the set terms, including notifying the copyright holder, restricting or deleting the infringing content, and claiming compensation, etc.

[0078] The application of smart contracts is not limited to copyright confirmation. It can also perform more flexible operations according to the needs of copyright protection. For example, the smart contract can automatically calculate the copyright fees according to the commercial use authorization terms of the generated content and automatically allocate and settle them during the use of the generated content. This automated payment and authorization system based on smart contracts greatly simplifies the management work of content creators and provides more efficient and reliable copyright protection.

[0079] In addition, to further enhance the ability of copyright protection, blockchain rights confirmation and smart contracts can also be used in combination with other data protection technologies. For example, by combining digital signature technology and encryption technology, the system can ensure the uniqueness and authenticity of the generated content and its watermark information, thereby strengthening the ability to resist forgery and tampering. Digital signature technology is used to verify the source of the generated content and watermark information, while encryption technology can ensure the security of information transmission during the process and prevent it from being tampered with midway.

[0080] In this embodiment, through the combination of blockchain rights confirmation and smart contracts, it is ensured that the copyright of the generated content is comprehensively protected. As the proof of content ownership, the watermark information not only ensures the authenticity of the content but also reduces the complexity and cost of manual intervention through the automated mechanism of the smart contract, greatly improving the efficiency of copyright management.

[0081] To ensure the synchronization of the watermark information with the ownership record in the blockchain, the system uses the following formula to confirm the watermark information and content ownership: ; Where: represents the ownership information of the generated content; is the generated content and the watermark information 's hash value; is the signature information of the watermark and the generated content, ensuring that the watermark information and ownership data are correctly recorded and cannot be tampered with in the blockchain.

[0082] The privacy and security of blockchain records can be ensured by combining public-private key encryption systems. The public key serves as the identifier of the content generator, while the private key guarantees the uniqueness of the generator's identity and the encryption protection of the data, further strengthening the copyright protection of the content.

[0083] The ethical control and content authentication system of generative AI described below can be mutually corresponding and referential to the ethical control and content authentication method of generative AI described above.

[0084] Please refer to the attached Figure 2 , the ethical control and content authentication system of generative AI, including: A content analysis module for analyzing the characteristics of the generated content and predicting possible adversarial attack patterns; A watermark embedding module that dynamically adjusts the watermark embedding strategy according to the characteristics of the generated content and the predicted attack patterns, and enhances the robustness of the watermark through redundant coding technology; A game theory calculation module for calculating the optimal strategies of the defender and the attacker to ensure the integrity of the watermark when under attack; A multi-modal authentication module for verifying the effectiveness of the watermark through multi-modal data such as images, audio, and video; A blockchain rights confirmation module for binding the watermark information of the generated content to its ownership record, ensuring the immutability of ownership through the blockchain, and realizing automatic copyright protection through smart contracts.

[0085] Specifically, the main task of the content analysis module is to conduct a detailed characteristic analysis of the generated content and predict possible adversarial attack patterns. By extracting various features of the generated content (such as images, audio, video, text, etc.), the system can accurately evaluate the security of the content and provide a technical basis for watermark embedding.

[0086] The watermark embedding module dynamically selects the best watermark embedding strategy based on the information provided by the content analysis module, and uses redundant coding technology to enhance the robustness of the watermark in the content. This module ensures the authenticity of the generated content by accurately embedding the watermark and enhances its anti-attack ability.

[0087] The game theory calculation module is used to calculate the optimal strategies between the defender and the attacker. By establishing a game model between the defender and the attacker, it ensures that the system can optimize the watermark embedding method and protection measures when encountering adversarial attacks.

[0088] The multi-modal authentication module verifies the watermark of the generated content through multi-modal data such as images, audio, and video, ensures that the embedded watermark information is not tampered with, and confirms the authenticity of the generated content.

[0089] The blockchain rights confirmation module is responsible for binding the watermark information of the generated content to its ownership record, ensuring the immutability of the content's ownership through blockchain technology, and realizing automatic copyright protection through smart contracts.

[0090] The system of this embodiment can be used to execute the above method embodiment, and its principle and technical effect are similar, so they will not be elaborated here.

[0091] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. Ethical control and content authentication method of generative AI, characterized by: The following steps are involved: Analyze the characteristics of generated content and predict possible adversarial attack patterns; Based on the generated content characteristics and predicted attack patterns, the watermark embedding strategy is dynamically adjusted, and the robustness of the watermark is enhanced by using redundant coding technology; Construct a game theory model between the defender and the attacker, and calculate the defender's optimal watermark embedding strategy to keep the watermark as intact as possible when attacked; The watermark is verified through a multimodal counterfeit detector and image, audio and video data are combined to verify the validity of the watermark; The ownership of each piece of verified generated content is confirmed through blockchain technology, and smart contracts are used to automatically protect rights.

2. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The adjustment of the watermark embedding strategy includes the following processes: Based on the characteristics of the generated content and the security level assessment, the watermark strength, distribution area and encoding method are selected; According to the predicted adversarial attack pattern, the watermark redundancy is adaptively increased to enhance the watermark's anti-interference ability.

3. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The calculation of the game theory model includes the following: Define the defender utility function as: ; in: is the defender’s utility function; is the probability of successful watermark embedding; is the probability that an attacker successfully removes or tampered with the watermark; The attacker's utility function is defined as: ; in: is the attacker’s utility function; is the probability that an attacker successfully removes or tampered with the watermark; By solving the Nash equilibrium point in game theory, the optimal strategies of the defender and the attacker are obtained, so that the watermark embedding strategy can effectively resist adversarial attacks.

4. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The multi-modal counterfeit detection analyzer uses deep learning technology and includes the following processes: Use pre-trained visual models, speech models, and language models to perform watermark verification on multimodal data such as images, audio, and video; The multimodal information is integrated to comprehensively judge the authenticity of the content and detect whether the watermark has been tampered with or lost.

5. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The blockchain confirmation process includes the following steps: Bind the watermark information of each verified generated content to the ownership record of the generated content, and generate an unalterable proof of ownership through the blockchain; Copyright protection rules are preset in the smart contract, and the rights protection process is automatically initiated when counterfeit or infringing content is detected.

6. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The redundant coding technology includes increasing the redundancy of the watermark, and through the coding technology, the watermark information can be more easily restored during the modification process of the generated content, ensuring the integrity of the watermark information under denoising and compression attacks.

7. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The predicted adversarial attack pattern generates adversarial samples based on a deep learning algorithm, and optimizes a watermark embedding strategy for the attack samples.

8. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The multimodal authentication analyzer improves the accuracy of the system by individually verifying each media form of the generated content and fusing the authentication results of each media form through weights.

9. The method for ethical control and content authentication of generative AI according to claim 1, characterized in that: The generated content after the ownership is confirmed by the blockchain technology will automatically trigger the infringement handling procedure through the smart contract, including automatic notification of the content owner and relevant law enforcement agencies, and the removal or deletion of the generated content suspected of infringement.

10. A generative AI ethical control and content authentication system, applied to a generative AI ethical control and content authentication method as claimed in any one of claims 1 to 9, characterized in that: include: A content analysis module to analyze the characteristics of generated content and predict possible adversarial attack patterns; The watermark embedding module dynamically adjusts the watermark embedding strategy according to the generated content characteristics and predicted attack patterns, and enhances the robustness of the watermark through redundant coding technology; Game theory calculation module, used to calculate the optimal strategy of the defender and the attacker to ensure that the watermark remains intact when attacked; Multimodal authentication module, used to verify the validity of watermarks through image, audio, and video multimodal data; The blockchain title confirmation module is used to bind the watermark information of the generated content to its ownership record, ensure that the ownership cannot be tampered with through the blockchain, and realize automatic copyright protection through smart contracts.

Citation Information

Patent Citations

  • Cross-modal image-watermark joint generation and detection device and method

    CN117057969A

  • Anti-watermark generation method and device, computer equipment and storage medium

    CN119107219A

  • Dark watermark generation system and generation method thereof

    CN119293764A

  • Methods and systems for implementing secure and trustworthy artificial intelligence

    WO2025042692A1

Cited By

  • Watermark embedding method and device, storage medium and computer readable storage medium

    CN120805114A

  • Medical ethical analysis report generation method based on multi-model game

    CN121148723A