Blind watermark embedding and extracting method

By preprocessing high-resolution images and randomly selecting image blocks, blind watermarks are embedded and extracted, the problems of insufficient adaptability to high-resolution images and limited robustness in the prior art are solved, and higher adaptability and robustness are achieved, and file size increments are reduced.

CN120070144APending Publication Date: 2025-05-30BEIJING UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510243745.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing blind watermarking method is not adaptable when processing high-resolution images and has limited robustness to complex geometric attacks, limiting its application in actual scenarios.

Method used

By preprocessing the target image and randomly selecting multiple image blocks, a pre-trained encoder is used to embed the watermark message into each image block, and geometric transformation recovery and weighted voting processing are performed during the extraction process to extract the final watermark message.

Benefits of technology

Improves adaptability to arbitrary resolution images, enhances robustness to geometric attacks and composite attacks, improves the stability and accuracy of watermark information extraction, and reduces file size increments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120070144A_ABST
    Figure CN120070144A_ABST
Patent Text Reader

Abstract

The invention relates to a blind watermark embedding and extracting method, which comprises the following steps of: preprocessing a target image in which a blind watermark is to be embedded, and selecting a plurality of image blocks from the preprocessed target image; and embedding a blind watermark containing the watermark message into each image block by adopting a pre-trained encoder to obtain a target image embedded with the blind watermark. Preprocessing a target blind watermark image to be subjected to blind watermark extraction, and performing feature extraction and image matching on the preprocessed target blind watermark image to obtain a plurality of image blocks; carrying out geometric transformation recovery, and extracting a watermark message from each image block subjected to geometric transformation recovery by adopting a pre-trained decoder; and processing all the obtained watermark messages through weighted voting, and determining the extracted final watermark message according to a weighted voting result. The method can be suitable for images with any resolution, the robustness to geometric attacks and composite attacks is enhanced, the stability and accuracy of watermark information extraction are improved, and the file size increment is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and particularly to a method for blind watermark embedding and extraction. Background Art

[0002] As an important branch of digital watermarking, blind watermarking technology aims to embed copyright information or other identification information without affecting the visual quality of images or videos. Traditional blind watermarking methods are mainly divided into two categories: the spatial domain and the frequency domain. Spatial domain methods embed watermarks by directly modifying the least significant bit (LSB) of image pixels. Although simple to implement, they have poor robustness and are easily affected by non-geometric attacks such as noise and compression. Frequency domain methods transform the image into the frequency domain through transforms such as the discrete cosine transform (DCT), discrete Fourier transform (DFT), or discrete wavelet transform (DWT), and embed watermark information in the frequency domain coefficients. Compared with spatial domain methods, frequency domain methods show stronger robustness in resisting compression attacks and other aspects.

[0003] With the development of deep learning technology, blind watermarking methods have gradually shifted from traditional manual feature extraction to automatic feature learning. Blind watermarking methods based on deep learning usually adopt an autoencoder architecture, where the encoder is responsible for embedding watermark information into the image, and the decoder is responsible for extracting watermark information from the watermarked image. Through end-to-end training, deep learning methods can learn more effective watermark embedding and extraction strategies, significantly improving the robustness and invisibility of watermarks. For example, methods such as HiDDeN, MBRS, and TSDL proposed in recent years further enhance the practical applicability of blind watermarks by training the network to adapt to various attacks. However, existing methods still have problems such as insufficient adaptability to high-resolution images and limited robustness to complex geometric attacks (such as rotation and cropping), which limit their application in actual scenarios. Summary of the Invention

[0004] In view of the above problems, this application provides a method for blind watermark embedding and extraction, which solves the technical problems of insufficient adaptability to high-resolution images and limited robustness to complex geometric attacks in related technologies, and is limited in application in actual scenarios.

[0005] In a first aspect, this application provides a method for blind watermark embedding, the method comprising:

[0006] Preprocess the target image to which the blind watermark is to be embedded to obtain a preprocessed target image;

[0007] Select a plurality of image patches from the preprocessed target image according to a preset selection method;

[0008] Use a pre-trained encoder to embed a blind watermark containing a watermark message into each image block to obtain a target image with an embedded blind watermark.

[0009] In some embodiments, preprocessing the target image to which the blind watermark is to be embedded to obtain a preprocessed target image, including:

[0010] Perform normalization processing on the target image to which the blind watermark is to be embedded, convert the image pixel values from the range [0, 255] to the range [-1, 1], and obtain the preprocessed target image.

[0011] In some embodiments, selecting a plurality of image blocks from the preprocessed target image according to a preset selection method, including:

[0012] Randomly select a plurality of non-overlapping image blocks of a preset size from the preprocessed target image to obtain a plurality of image blocks.

[0013] In some embodiments, the preset size is an image block with a height h = 128 pixel values and a width w = 128 pixel values.

[0014] In some embodiments, using the pre-trained encoder to embed a blind watermark containing a watermark message into each image block to obtain a target image with an embedded blind watermark, including:

[0015] Use an encoder with a loss function of to embed a blind watermark containing a watermark message into each image block to obtain a target image with an embedded blind watermark;

[0016] where λ is the weight for balancing MSE and MSSIM, with a default value of 0.1, x co is the image block before embedding, and x en is the image block after embedding the blind watermark through the encoder.

[0017] In a second aspect, a method for extracting a blind watermark, the method includes:

[0018] Preprocess the target blind watermark image from which the blind watermark is to be extracted to obtain a preprocessed target blind watermark image;

[0019] Perform feature extraction and image matching on the preprocessed target blind watermark image to obtain a plurality of image blocks;

[0020] Perform geometric transformation recovery on the plurality of image blocks to obtain a plurality of image blocks after geometric transformation recovery;

[0021] Use a pre-trained decoder to extract the watermark message from each image block after geometric transformation recovery;

[0022] Process all the watermark messages obtained through weighted voting, and determine the final extracted watermark message according to the weighted voting result.

[0023] In some embodiments, preprocessing the target blind watermark image to be extracted to obtain a preprocessed target blind watermark image, including:

[0024] Perform denoising, normalization, and grayscale processing on the target blind watermark image to be extracted to obtain a preprocessed target blind watermark image.

[0025] In some embodiments, performing feature extraction and image matching on the preprocessed target blind watermark image to obtain multiple image blocks, including:

[0026] Use a convolutional neural network to extract high-level features from the preprocessed target blind watermark image;

[0027] Extract key points from the high-level features using the SIFT algorithm;

[0028] Perform image matching from the preprocessed target blind watermark image according to the feature descriptors of the regions around the key points to obtain multiple image blocks.

[0029] In some embodiments, performing geometric transformation recovery on the multiple image blocks to obtain multiple geometric transformation recovered image blocks, including:

[0030] Calculate geometric transformation parameters according to the feature point pairs in the multiple image blocks;

[0031] Determine the geometric transformation matrix using the RANSAC algorithm according to the feature point pairs in the multiple image blocks;

[0032] Perform geometric transformation recovery on each image block according to the geometric transformation parameters and the inverse matrix of the geometric transformation matrix to obtain multiple geometric transformation recovered image blocks.

[0033] In some embodiments, processing all the watermark messages obtained through weighted voting, and determining the final extracted watermark message according to the weighted voting result, including:

[0034] Calculate the confidence of each watermark message;

[0035] Calculate the weighted voting result according to the confidence of each watermark message;

[0036] According to the weighted voting result, perform binarization processing on the bit values of each watermark message, and fuse all the watermark messages with bit value 1 to obtain the final watermark message.

[0037] A blind watermark embedding and extraction method provided by this application includes: preprocessing a target image to be embedded with a blind watermark to obtain a preprocessed target image; selecting a plurality of image blocks from the preprocessed target image according to a preset selection method; using a pre-trained encoder to embed a blind watermark containing watermark information into each image block to obtain a target image with an embedded blind watermark. Preprocessing a target blind watermark image to be extracted with a blind watermark to obtain a preprocessed target blind watermark image; performing feature extraction and image matching on the preprocessed target blind watermark image to obtain a plurality of image blocks; performing geometric transformation recovery on the plurality of image blocks to obtain a plurality of image blocks after geometric transformation recovery; using a pre-trained decoder to extract watermark information from each image block after geometric transformation recovery; processing all the obtained watermark information through weighted voting, and determining the finally extracted watermark information according to the weighted voting result.

[0038] A blind watermark embedding and extraction method provided by this application has the following beneficial effects:

[0039] 1. Improve the adaptability to images of any resolution: The present invention aims to provide a blind watermark method that can adapt to images of any resolution (especially high-resolution images) to meet the diverse needs of image resolutions in practical applications.

[0040] 2. Enhance the robustness to geometric attacks and composite attacks: The present invention aims to improve the robustness of the blind watermark to geometric attacks (such as rotation, cropping, scaling, etc.) and composite attacks, ensuring that the watermark information can still be stably and accurately extracted after suffering these attacks.

[0041] 3. Improve the stability and accuracy of watermark information extraction: Through a decentralized embedding and information fusion strategy, the present invention aims to reduce the risk of watermark information loss, improve the stability and accuracy of information extraction, and ensure that watermark information can still be reliably extracted in a complex attack environment.

[0042] 4. Reduce the file size increment: The present invention aims to reduce the modification of the overall pixels of the image by only embedding watermark information in the local area of the image through a decentralized embedding scheme by selecting image blocks, thereby significantly reducing the file size increment of the watermark image. Especially in high-resolution images, the file size increment is controlled within 2.5%.

[0043] By solving the problems in the prior art, the present invention aims to provide a more practical and robust blind watermark embedding and extraction method that can adapt to high-resolution images, effectively cope with geometric attacks and composite attacks, and reduce the file size increment while ensuring visual quality. Description of the Drawings

[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the provided drawings.

[0045] Figure 1 It is a schematic flowchart of a blind watermark embedding method provided by an embodiment of the present application;

[0046] Figure 2 It is a schematic flowchart of a blind watermark extraction method provided by an embodiment of the present application. Specific embodiments

[0047] The following will detail the embodiments of the present application in conjunction with the drawings and embodiments, so as to fully understand how the present application uses technical means to solve technical problems and the implementation process of achieving corresponding technical effects and implement accordingly. The embodiments of the present application and each feature in the embodiments can be combined with each other on the premise of not conflicting, and the formed technical solutions are all within the protection scope of the present application.

[0048] Embodiment 1

[0049] Figure 1 It is a schematic flowchart of a blind watermark embedding method provided by an embodiment of the present application. As Figure 1 shown, this method includes:

[0050] S101. Preprocess the target image to be embedded with the blind watermark to obtain the preprocessed target image;

[0051] S102. Select a plurality of image blocks from the preprocessed target image according to a preset selection method;

[0052] S103. Use a pre-trained encoder to embed the blind watermark containing the watermark message into each image block to obtain the target image embedded with the blind watermark.

[0053] In some embodiments, the preprocessing of the target image to be embedded with the blind watermark to obtain the preprocessed target image includes:

[0054] Perform normalization processing on the target image to be embedded with the blind watermark, convert the image pixel values from the range [0, 255] to the range [-1, 1] to obtain the preprocessed target image.

[0055] It should be noted that the conversion of image pixel values is for the input requirements of the deep learning model. When selecting the target image to embed the blind watermark, try to select high-resolution images and ensure that the image size adapts to the requirements of the neural network. Specifically, padding or cropping can be selected for processing.

[0056] In some embodiments, selecting multiple image patches from the preprocessed target image according to a preset selection method includes:

[0057] Randomly select multiple non-overlapping image patches of a preset size from the preprocessed target image to obtain multiple image patches.

[0058] It should be noted that the traditional mode of watermark embedding, which operates uniformly or in fixed areas on the entire image, is broken, and multiple small-sized image patches are randomly selected from the target image. This randomly scattered selection method, on the one hand, greatly increases the uncertainty of the watermark embedding position, making it difficult for attackers to discover and remove the watermark through conventional means; on the other hand, compared with the overall embedding, it reduces the range of changes to the overall pixels of the image, effectively reducing the risk of image quality degradation caused by watermark embedding and ensuring the concealment of the watermark.

[0059] In some embodiments, the preset size is an image patch with a height h = 128 pixel values and a width w = 128 pixel values.

[0060] It should be noted that the total area ratio Q of the selected image patches is controlled (such as Q = 25%). This strict control of the ratio ensures the sparse distribution of the watermark in the image. The sparse watermark embedding method makes the watermark more difficult to detect. At the same time, due to the limited modification degree of the overall image, the increase in file size during storage and transmission is effectively controlled, improving the feasibility and efficiency of the watermark technology in practical applications.

[0061] In some embodiments, using a pre-trained encoder to embed the blind watermark containing the watermark message into each image patch to obtain the target image with the embedded blind watermark includes:

[0062] Using an encoder with a loss function of to embed the blind watermark containing the watermark message into each image patch to obtain the target image with the embedded blind watermark;

[0063] where λ is the weight balancing MSE and MSSIM, and its default value is 0.1, x co is the image patch before embedding, and x en is the image patch after embedding the blind watermark through the encoder.

[0064] It should be noted that the encoder is used to embed the watermark message into each image patch x coFor each image patch, an encoded patch x is generated accordingly. en In the loss function of the encoder, MSE measures the pixel-level difference between the encoded patch x en and the original image patch x co before processing. The calculation formula is as follows:

[0065]

[0066] where h×w is the size of the image patch (by default, h = w = 128).

[0067] It should be noted that MSE forces the image patch generated by the encoder to be as close as possible to the original patch in terms of pixel values, thus ensuring low distortion of the image after watermark embedding.

[0068] And MSSIM evaluates the structural similarity of image patches through multi-scale analysis. The calculation steps are as follows:

[0069] Multi-scale decomposition: The image patch is downsampled at multiple levels (e.g., taking 3 levels) to generate images at different scales (such as the original resolution, 1 / 2 resolution, 1 / 4 resolution).

[0070] Single-scale SSIM calculation: Calculate the structural similarity index (SSIM) at each scale. The formula is:

[0071]

[0072] where μ x , μ y are the means of image patches x and y, are the variances of image patches x and y, and σ xy is the covariance of image patches x and y.

[0073] C1 and C2 are stable constants to prevent the denominator from being zero (usually set as C 1 =(0.01×L) 2 , C 2 =(0.03×L) 2 , where L is the pixel value range, e.g., 1.0).

[0074] Multi-scale fusion: Perform weighted averaging on the SSIM values at different scales to generate the final MSSIM value:

[0075]

[0076] where K is the number of scales (by default, 3 levels), and α k is the weight of each scale (usually set as a uniform weight).

[0077] It should be noted that MSSIM focuses on the overall consistency of the structure, brightness, and contrast of image blocks, ensuring that the visually quality of the watermarked image does not degrade significantly and avoiding artificial traces.

[0078] Corresponding to the above blind watermark embedding method, as Figure 2 shown, the present application also provides a blind watermark extraction method, which includes:

[0079] S201. Preprocess the target blind watermark image to be extracted to obtain a preprocessed target blind watermark image;

[0080] S202. Extract features and perform image matching on the preprocessed target blind watermark image to obtain multiple image blocks;

[0081] S203. Perform geometric transformation recovery on the multiple image blocks to obtain multiple geometric transformation recovered image blocks;

[0082] S204. Use a pre-trained decoder to extract watermark messages from each geometric transformation recovered image block;

[0083] S205. Process all the obtained watermark messages through weighted voting, and determine the final extracted watermark message according to the weighted voting result.

[0084] In some embodiments, the preprocessing of the target blind watermark image to be extracted to obtain a preprocessed target blind watermark image includes:

[0085] Perform denoising, normalization, and grayscale processing on the target blind watermark image to be extracted to obtain a preprocessed target blind watermark image.

[0086] It should be noted that the target blind watermark image to be extracted can be either an unattacked image or an attacked image, and the present invention can handle both.

[0087] In some embodiments, the extracting features and performing image matching on the preprocessed target blind watermark image to obtain multiple image blocks includes:

[0088] Use a convolutional neural network to extract high-level features from the preprocessed target blind watermark image;

[0089] It should be noted that the convolutional neural network CNN model adopts the ResNet-50 architecture, is pre-trained on the ImageNet dataset, and is fine-tuned on the watermark task. High-level features refer to the abstract information extracted by the deep neural network in the deeper layers, such as the shape, texture, and structure of objects, etc. These features are more discriminative than the original pixel information and can be effectively used to identify and match specific patterns.

[0090] Extract key points from the said advanced features using the SIFT algorithm;

[0091] It should be noted that the SIFT parameters are set as follows: the Gaussian blur kernel size is 3, the key point detection threshold is 0.04, and the edge response threshold is 10. Key points refer to the significant points in the image, such as corner points, edge intersection points, or texture mutation regions, which are usually stable under changes such as scaling and rotation. For example, in a face image, the positions of the corners of the eyes and mouth may be recognized as key points.

[0092] Perform image matching on the preprocessed target blind watermark image according to the feature descriptors of the regions around the said key points to obtain multiple image patches.

[0093] It should be noted that specifically, FLANN (Fast Library for Approximate Nearest Neighbors) can be used for feature point matching, and the matching threshold is set to 0.7. Feature descriptors are numerical descriptions of the regions around key points, enabling the comparison of the same key points in different images. SIFT uses a 128-dimensional vector to describe the local information (such as the gradient direction distribution) of key points, and then performs efficient matching through FLANN to improve the accuracy of image recognition.

[0094] In some embodiments, the geometric transformation recovery of the said multiple image patches to obtain multiple geometric transformation recovered image patches includes:

[0095] Calculate geometric transformation parameters according to the pairs of feature points in the said multiple image patches;

[0096] It should be noted that according to the pairs of feature points matched by SIFT+FLANN above, the transformation relationship is estimated using the least squares method to calculate parameters such as the rotation angle, scaling factor, and translation amount. Since the true matching feature points may be interfered by noise and mis-matched feature points, directly using all matching feature points to calculate the transformation matrix may lead to large errors, so a robust estimation method is required.

[0097] Determine the geometric transformation matrix according to the pairs of feature points in the said multiple image patches using the RANSAC algorithm;

[0098] It should be noted that RANSAC (Random Sample Consensus) is a robust estimation method that can eliminate mis-matched feature points in the set of matching feature points to obtain accurate transformation parameters.

[0099] The specific process is as follows:

[0100] Randomly select the minimum number of pairs of matching feature points (generally at least 4 pairs of points are required to estimate the affine transformation or perspective transformation).

[0101] Calculate the hypothetical transformation matrix (e.g., perspective transformation matrix or affine transformation matrix).

[0102] Calculate the error of all matching feature points and determine which points conform to the transformation model (i.e., "inliers"). The error is defined as the Euclidean distance between the transformed point and the actual matching feature point. If it is less than the set threshold (5.0 in this solution), it is regarded as an inlier.

[0103] Iterative optimization: Repeat the above process 1000 times (the set maximum number of iterations), and select the transformation model with the most inliers as the final geometric transformation matrix.

[0104] Perform geometric transformation restoration on each image block according to the geometric transformation parameters and the inverse matrix of the geometric transformation matrix to obtain multiple image blocks after geometric transformation restoration.

[0105] It should be noted that specifically applying the inverse transformation to the watermark image, that is:

[0106] x syn =T -1 (x)

[0107] where T -1 is the inverse matrix of the obtained geometric transformation matrix, x is the image block before geometric transformation restoration, and x syn is the image block after geometric transformation restoration.

[0108] This process usually uses bilinear interpolation or nearest neighbor interpolation to calculate the pixel values after the inverse transformation, so as to obtain the corrected image block synchronized with the original image.

[0109] Finally, through the above geometric transformation restoration steps, the rotation, scaling, translation and other transformations of the image can be effectively corrected, so that the watermark information can be accurately extracted.

[0110] In some embodiments, processing all the obtained watermark messages through weighted voting and determining the final extracted watermark message according to the weighted voting result includes:

[0111] Calculate the confidence of each watermark message;

[0112] Calculate the weighted voting result according to the confidence of each watermark message;

[0113] According to the weighted voting result, perform binarization processing on the bit values of each watermark message, and fuse all the watermark messages with bit value 1 to obtain the final watermark message.

[0114] It should be noted that after the geometric transformation is restored, the extracted image patches may be affected by noise, compression distortion, etc., resulting in slight differences in the watermark messages of different image patches. To improve the accuracy of blind watermark extraction, this application adopts a weighted voting strategy to fuse the decoded messages of all image patches after geometric transformation restoration, so as to obtain a more robust final watermark message. This process includes the following steps:

[0115] 1. Decode the message:

[0116] Use the decoder to extract the watermark message M′ from each image patch x after geometric transformation restoration syn in i .

[0117] Since the image may be affected by rotation, scaling, noise, etc., there may be certain errors in the watermark of each image patch after geometric transformation restoration. Therefore, subsequent steps are needed to improve the accuracy.

[0118] 2. Calculate the confidence:

[0119] To measure the reliability of each decoded watermark message M′ i , calculate its confidence C i , and the formula is as follows:

[0120]

[0121] where L is the length of the watermark message, that is, the number of bits of the watermark.

[0122] M′ i [j] is the j-th bit value of the i-th decoded message, usually 0 or 1.

[0123] It should be noted that if M′ i [j] is far from 0.5 (i.e., close to 0 or 1), it means that the decoded bit value is relatively certain and the confidence is high;

[0124] If M′ i [j] is close to 0.5, it means that there is a large uncertainty in the decoding and the confidence is low.

[0125] 3. Weighted voting:

[0126] Since there may be certain errors in the watermark messages in different image patches after geometric transformation restoration, we adopt a weighted voting mechanism to assign weights according to the confidence of each decoded message and calculate the final weighted voting result.

[0127] For each bit value j, calculate the weighted voting result V j :

[0128]

[0129] Among them, N = i is the number of decoded watermark messages (i.e., the number of image blocks after geometric transformation restoration).

[0130] W i is the weight calculated based on the confidence C i and is usually defined as:

[0131]

[0132] 4. Determine the final watermark message:

[0133] After obtaining the weighted voting result V of each bit value j we perform binarization according to the threshold 0.5 to determine the final watermark message M:

[0134]

[0135] It should be noted that if the weighted voting result V of a certain bit value j is greater than or equal to 0.5, it means that most of the credible image blocks think that this bit value should be 1, so finally take 1;

[0136] If V j is less than 0.5, then take 0.

[0137] Finally, we fuse the watermark information with a value of 1 to obtain the fused watermark information, which is more stable and accurate than the decoding results of individual image blocks.

[0138] It should be noted that this weighted voting method of the present application makes full use of the effective information in multiple decoding results, and improves the accuracy and robustness of watermark information extraction by comprehensively considering the credibility of different messages. Even when the watermark is attacked by various means and some decoding results are deviated, the original watermark information can be accurately restored.

[0139] In summary, the embodiments of the present application provide a blind watermark embedding and extraction method, including: preprocessing a target image to be embedded with a blind watermark to obtain a preprocessed target image; selecting a plurality of image blocks from the preprocessed target image according to a preset selection method; using a pre-trained encoder to embed a blind watermark containing a watermark message into each image block to obtain a target image with an embedded blind watermark; preprocessing a target blind watermark image to be extracted with a blind watermark to obtain a preprocessed target blind watermark image; performing feature extraction and image matching on the preprocessed target blind watermark image to obtain a plurality of image blocks; performing geometric transformation recovery on the plurality of image blocks to obtain a plurality of image blocks after geometric transformation recovery; using a pre-trained decoder to extract the watermark message from each image block after geometric transformation recovery; processing all the obtained watermark messages through weighted voting, and determining the final extracted watermark message according to the weighted voting result.

[0140] The blind watermark embedding and extraction method provided by the present application has the following beneficial effects:

[0141] 1. Improve the adaptability to images of any resolution: The present invention aims to provide a blind watermark method that can adapt to images of any resolution (especially high-resolution images) to meet the diverse needs of image resolutions in practical applications.

[0142] 2. Enhance the robustness to geometric attacks and composite attacks: The present invention aims to improve the robustness of the blind watermark to geometric attacks (such as rotation, cropping, scaling, etc.) and composite attacks, ensuring that the watermark information can still be stably and accurately extracted after suffering these attacks.

[0143] 3. Improve the stability and accuracy of watermark information extraction: Through a decentralized embedding and information fusion strategy, the present invention aims to reduce the risk of watermark information loss, improve the stability and accuracy of information extraction, and ensure that the watermark information can still be reliably extracted in a complex attack environment.

[0144] 4. Reduce the file size increment: The present invention aims to reduce the modification of the overall pixels of the image by only embedding watermark information in the local area of the image through a decentralized embedding scheme by selecting image blocks, thereby significantly reducing the file size increment of the watermark image. Especially in high-resolution images, the file size increment is controlled within 2.5%.

[0145] By solving the problems in the prior art, the present invention aims to provide a more practical and robust blind watermark embedding and extraction method that can adapt to high-resolution images, effectively cope with geometric attacks and composite attacks, and reduce the file size increment while ensuring visual quality.

[0146] In several embodiments provided by the embodiments of the present application, it should be understood that the disclosed method can also be implemented in other ways. The method embodiments described above are only illustrative.

[0147] It should be noted that in this document, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of another identical element in the process, method, article or device including the element.

[0148] Although the embodiments disclosed in the present application are as above, the above content is only an embodiment adopted for the convenience of understanding the present application, and is not intended to limit the present application. Any person skilled in the art within the technical field to which the present application pertains may make any modifications and changes in the form of implementation and details without departing from the spirit and scope disclosed in the present application. However, the scope of patent protection of the present application shall still be subject to the scope defined by the appended claims.

Claims

1. A blind watermark embedding method, characterized in that: The method comprises: Preprocessing the target image to be embedded with the blind watermark to obtain a preprocessed target image; Selecting a plurality of image blocks from the preprocessed target image according to a preset selection method; A pre-trained encoder is used to embed a blind watermark containing a watermark message into each image block to obtain a target image embedded with a blind watermark.

2. The method according to claim 1, characterized in that The preprocessing of the target image to be embedded with the blind watermark to obtain the preprocessed target image includes: The target image to be embedded with the blind watermark is normalized, and the image pixel values ​​are converted from the range of [0, 255] to the range of [-1, 1] to obtain the preprocessed target image.

3. The method according to claim 1, characterized in that The step of selecting a plurality of image blocks from the preprocessed target image according to a preset selection method includes: A plurality of non-overlapping image blocks of preset sizes are randomly selected from the preprocessed target image to obtain a plurality of image blocks.

4. The method according to claim 3, characterized in that The preset size is an image block with a height h=128 pixels and a width w=128 pixels.

5. The method according to claim 1, characterized in that The method of using a pre-trained encoder to embed a blind watermark containing a watermark message into each image block to obtain a target image embedded with the blind watermark includes: The loss function is adopted as The encoder embeds the blind watermark containing the watermark message into each image block to obtain a target image embedded with the blind watermark; Among them, λ is the weight for balancing MSE and MSSIM, and its default value is 0.1, x co is the image block before embedding, x en is the image block after the encoder embeds the blind watermark.

6. A blind watermark extraction method, characterized in that: The method comprises: Preprocessing the target blind watermark image to be extracted with the blind watermark to obtain the preprocessed target blind watermark image; Performing feature extraction and image matching on the preprocessed target blind watermark image to obtain multiple image blocks; Performing geometric transformation restoration on the multiple image blocks to obtain multiple geometrically transformed restored image blocks; A pre-trained decoder is used to extract the watermark message from each geometrically restored image block; All the obtained watermark messages are processed by weighted voting, and the final watermark message extracted is determined according to the weighted voting result.

7. The method according to claim 6, characterized in that The preprocessing of the target blind watermark image to be extracted blind watermark to obtain the preprocessed target blind watermark image includes: The target blind watermark image to be extracted is subjected to denoising, standardization and grayscale processing to obtain a preprocessed target blind watermark image.

8. The method according to claim 6, characterized in that The preprocessed target blind watermark image is subjected to feature extraction and image matching to obtain a plurality of image blocks, including: Extracting high-level features from the preprocessed target blind watermark image using a convolutional neural network; Extract key points from the advanced features using SIFT algorithm; Image matching is performed on the preprocessed target blind watermark image according to the feature descriptors of the area around the key point to obtain multiple image blocks.

9. The method according to claim 6, characterized in that The performing geometric transformation restoration on the multiple image blocks to obtain multiple geometrically transformed restored image blocks includes: Calculating geometric transformation parameters according to the feature point pairs in the plurality of image blocks; Determine a geometric transformation matrix using a RANSAC algorithm according to the feature point pairs in the plurality of image blocks; Perform geometric transformation restoration on each image block according to the geometric transformation parameters and the inverse matrix of the geometric transformation matrix to obtain a plurality of geometrically transformed restored image blocks.

10. The method according to claim 6, characterized in that The step of processing all watermark messages obtained by weighted voting and determining the final watermark message to be extracted according to the weighted voting result includes: Calculate the confidence of each watermark message; Calculate a weighted voting result according to the confidence of each watermark message; According to the weighted voting result, the bit value of each watermark message is binarized, and all watermark messages with bit values ​​of 1 are merged to obtain a final watermark message.