An image-oriented generation model hidden watermarking method
By binarizing the noise of the image generation model into segments and adjusting for parity, and embedding encrypted watermark data, the problem of watermarks affecting image diversity in existing technologies is solved. This achieves efficient watermark embedding and extraction, ensuring the quality and diversity of generated images.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2026-03-17
AI Technical Summary
Existing implicit watermarking methods for image generation models significantly reduce the diversity of generated images when embedding watermarks, affecting the output fidelity and true representation of data in the image generation model.
By performing average segmentation and parity matching adjustments on the binarized array of the original noise, encrypted watermark data is embedded to ensure that the visual quality of the generated image is not degraded. The watermark is then effectively extracted and corrected by using the ChaCha20 stream cipher algorithm for encryption and decryption.
While ensuring the quality of the generated images, we maintain the output fidelity and diversity of the image generation model to ensure the effectiveness and robustness of the watermark information.
Smart Images

Figure CN120278867B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to implicit watermarking methods, and more particularly to an implicit watermarking method for image generation models. Background Technology
[0002] Image generation models are an important technology in the field of artificial intelligence, and have received widespread attention and application in recent years. By learning and modeling massive amounts of image data, image generation models can generate image data that is extremely close to real-world image data. Image decoders, based on this generated image data, can then generate images with very high similarity, and are widely used in image generation, image restoration, virtual reality, and other fields. Currently, there are two main types of common image generation models: those based on Generative Adversarial Networks (GANs) and those based on Diffusion Models.
[0003] With the increasing application of image generation models in industry and commerce, the protection of originality and copyright tracking of images generated from their data has become a critical issue. To address this, implicit watermarking technology has been gradually introduced into image generation models. Implicit watermarking is a method of embedding imperceptible information (i.e., watermark information) into an image without affecting its visual quality, but effectively tracing its origin and preventing unauthorized use. Therefore, designing effective implicit watermarking methods for image generation models is crucial, ensuring that the embedded watermark does not affect the quality of the generated image while maintaining high efficiency in tracking and copyright protection.
[0004] Currently, several implicit watermarking methods exist for image generation models. For example, implicit watermarking methods based on Gaussian noise mapping embed a unique watermark while generating the image by mapping the watermark onto Gaussian noise. This method has minimal impact on image quality while embedding the watermark, thus ensuring image quality. However, this method achieves watermark embedding by restricting the latent space to a fixed quadrant, but this fixed sampling method significantly reduces the diversity of the generated images. This problem negatively impacts the output fidelity and accurate data representation of the image generation model. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide an implicit watermarking method for image generation models that can effectively embed watermarks, ensure the quality of generated images, and also ensure the diversity of generated images without negatively affecting the output fidelity and true representation of data of the image generation model.
[0006] The technical solution adopted by this invention to solve the above-mentioned technical problems is as follows: a method for implicit watermarking oriented towards image generation models, including implicit watermark embedding operation and implicit watermark extraction operation. The specific process of the implicit watermark embedding operation is as follows: first, the original noise is expanded in one dimension and binarized to obtain a binarized array of the original noise. This binarized array of the original noise is a one-dimensional array. The binarized array of the original noise is then divided into segments of a fixed segment length, and the number of segments after segmentation is denoted as . The watermark information in binary data form is expanded to obtain a data bit length equal to The expanded watermark information is then encrypted to obtain encrypted watermark data, which is a one-dimensional array with a length equal to [missing information]. Based on the encrypted watermark data, the binarized array of the original noise is adjusted by parity matching to embed the encrypted watermark data, resulting in an adjusted binarized array of the original noise. This adjusted binarized array is then restored to obtain restored noise conforming to a Gaussian distribution. The statistical distribution characteristics of this restored noise are consistent with the original noise, while simultaneously preserving the watermark information. The restored noise is then reshaped according to the size of the original noise, resulting in reshaped noise. First, an image generation model is used to generate the reshaped noise data, and then an image decoder is used to generate an image containing the encrypted watermark data. The implicit... The specific process of watermark extraction is as follows: First, an image encoder is used to extract noise containing encrypted watermark data from the image containing encrypted watermark data. Then, the noise containing encrypted watermark data is expanded in one dimension and binarized to obtain a binarized noise array containing encrypted watermark data. The length of the binarized noise array containing encrypted watermark data is equal to the length of the binarized array of the original noise. Encrypted watermark data is extracted from the binarized noise array containing encrypted watermark data. Next, the extracted encrypted watermark data is decrypted to obtain the watermark data. Finally, the watermark data is corrected to obtain the watermark information.
[0007] Compared with existing technologies, the advantages of this invention lie in the following: First, the binary array of the original noise is divided into segments of a fixed length. Then, the watermark information in binary data form is expanded to a number of bits equal to the number of segments before encryption, resulting in encrypted watermark data. Next, based on the encrypted watermark data, the binary array of the original noise is adjusted using parity matching to embed the encrypted watermark data, resulting in an adjusted binary array of the original noise. When the adjusted binary array of the original noise is restored to Gaussian-distributed noise, the statistical distribution characteristics of the original noise are preserved. This process is achieved through mathematical transformation, ensuring that the restored noise of the input image generation model is not significantly different in characteristics from the original noise without watermark embedding. Therefore, the input received by the image generation model is consistent with the conventional generation process, and the final image generated by the image decoder will not suffer a decrease in visual quality due to watermark embedding, ensuring that the quality of the generated image remains unchanged. Simultaneously, during watermark (i.e., encrypted watermark data) embedding, limitations on noise sampling are avoided. This invention uses parity matching to adjust the binarized array of the original noise to embed encrypted watermark data. This involves only minor and dispersed local adjustments to the binarized array of the original noise, distributed throughout the entire reconstructed noise. This adjustment does not change the overall sampling range or distribution characteristics of the original noise and is statistically equivalent to the original noise. Therefore, the diversity of the reconstructed noise is preserved, ensuring the diversity of the generated images. Since the watermark embedding process does not alter the overall randomness and diversity of the original noise, the output fidelity of the image generation model (i.e., the similarity between the generated image and the expected output of the image generation model) is maintained. Simultaneously, the generated images still accurately reflect the distribution of the image data generated from the original noise, without any deviation or distortion caused by watermark embedding, thus guaranteeing the diversity and fidelity of the generated images. Therefore, this invention achieves effective watermark embedding, ensures the quality of the generated images, and also guarantees the diversity of the generated images, without negatively impacting the output fidelity and accurate data representation of the image generation model.
[0008] Furthermore, based on the encrypted watermark data, the binarized array of the original noise is adjusted by parity matching to embed the encrypted watermark data. The specific process of obtaining the adjusted binarized array of the original noise is as follows: Let the first... The first segment of data and the encrypted watermark data Bit element correspondence. Determine whether the sum of each data segment in the original noise binarization array and the corresponding element in the encrypted watermark data are both odd or both even. If they are, the data segment in the original noise binarization array remains unchanged. If not, flip the first element in the data segment in the original noise binarization array to adjust the original noise binarization array, thus obtaining the adjusted binarization array of the original noise.
[0009] Furthermore, the specific process for extracting the encrypted watermark data from the binarized noise array containing the encrypted watermark data is as follows: the binarized noise array containing the encrypted watermark data is divided into average segments, with the number of segments also being... The encrypted watermark data to be extracted is set as a one-dimensional array with a length of . The binarized noise array containing the watermark data The segment data and the encrypted watermark data to be extracted If the corresponding bit element of the binary array containing the watermark data is... If the sum of the data segments is odd, then the first segment of the encrypted watermark data to be extracted will be... If the bit element is assigned a value of 1, then the binarized noise array containing the watermark data has a bit element assigned a value of 1. If the sum of the data segments is even, then the first segment of the encrypted watermark data to be extracted will be... The bit element is assigned a value of 0, from which the length equal to 0 is extracted. It is also a one-dimensional array of encrypted watermark data.
[0010] Furthermore, the specific process of expanding the original noise in one dimension and performing binarization to obtain the binarized array of the original noise is as follows:
[0011] S1. Let the original noise be Z, the number of channels in the original noise Z be c, and the size of each channel of the original noise Z be h×w, where h represents the length and w represents the width. Flatten the two-dimensional array of each channel of the original noise Z into a one-dimensional array in row-major order. Then, concatenate all the one-dimensional arrays of all channels in channel order to form a one-dimensional array of length c×h×w, denoted as Z. f , will Z f Let the length be N, N = c × h × w, and define Z. f [i] represents Z f The i-th element in the array, where i = 1, 2, ..., N;
[0012] S2, convert the one-dimensional array Z f Each element is binarized to obtain the corresponding binary data, where the one-dimensional array Z... f The i-th element Z f The binarized data corresponding to [i] is denoted as B. z [i], a one-dimensional array Z f The i-th element Z f [i] Binarization is performed using formula (1) to obtain the corresponding binarized data B. z [i]:
[0013]
[0014] Where Φ(·) is the cumulative distribution function of the standard normal distribution;
[0015] S3. Using the one-dimensional array Z obtained in step S2 f The binarized data corresponding to each element constitutes the binarized array B of the original noise. z B z It is a one-dimensional array with length N and B. z The i-th element is B z [i].
[0016] Furthermore, the watermark information in binary data form is expanded to obtain a data bit length equal to... The specific process of obtaining the expanded watermark information and encrypting it to get the encrypted watermark data is as follows:
[0017] A1. Define a positive integer l that is divisible by N. w The original noise is binarized into an array B. z each l w Each bit element is used as a data segment, thus binarizing the original noise array B. z Average score Segment data,
[0018] A2. Let M be the binary data format of the watermark information, where M is a one-dimensional array. Let k be the length of the watermark information M.
[0019] A3, Judgment Is it an integer? If so, repeat the watermark information M. Next, the expanded watermark information M is formed. r , M d =M, If not, repeat the watermark information M. After that, fill in the end. The zeros form the expanded watermark information M. r , M p =M, for Bit element, where each bit is 0. Indicates the rounding up symbol;
[0020] A4. Preset the key Key, and use the ChaCha20 stream cipher algorithm to process the expanded watermark information M. r Encryption is performed, resulting in a length of encrypted watermark data M enc.
[0021] Furthermore, the specific process of restoring the original noise by adjusting the binarized array to obtain the restored noise conforming to a Gaussian distribution is as follows:
[0022] B1. Let B be the adjusted binarized array of the original noise. z ′, B z Let the i-th element of ′ be denoted as B. z [i], will B z The cumulative distribution function value of ′[i] is denoted as θ. i θ is calculated using formula (2). i :
[0023]
[0024] Among them, u i Let represent a random variable obtained by independently sampling from a uniform distribution defined on the closed interval [0, 0.5].
[0025] B2. Use the probability distribution function of the standard normal distribution on θ. i By performing the mapping, we obtain the corresponding Gaussian distribution value, denoted as Z. f ′[i], as shown in formula (3):
[0026] Z f ′[i]=Φ -1 (θ i (3)
[0027] Where, Φ -1 (·) is the probability distribution function;
[0028] B3. The Gaussian distribution values obtained in step B2 are used to construct the restored one-dimensional Gaussian noise array Z. f ′, Z f The i-th element of ′ is Z f ′[i];For the restored one-dimensional Gaussian noise array Z f The original noise Z is reshaped according to its size to obtain the restored noise Z′ that conforms to a Gaussian distribution.
[0029] Furthermore, the extracted encrypted watermark data is decrypted to obtain the watermark data, and errors are corrected on the watermark data to obtain the watermark information. The specific process is as follows:
[0030] C1. Denote the extracted encrypted watermark data as M′ enc The ChaCha20 stream cipher algorithm and key Key are used to extract the encrypted watermark data M. e ′ nc Decryption is performed to obtain the watermark data, which is denoted as M. r′, watermark data M r The length of ′ is
[0031] C2. Set the extended parameter ratio Determine if Q is an integer. If it is, execute the full segment error correction process to obtain the watermark information M′. If Q is not an integer, execute the error correction process including truncation to obtain the watermark information M′.
[0032] The complete segment error correction process includes the following steps:
[0033] Step C2.1: Transfer the watermark data M r Each k-bit element of ' is divided into a data segment, resulting in Q data segments, each segment having a length of k.
[0034] Step C2.2: Calculate the watermark data M separately. r The number of times the j-th element in the Q-segment data is 1, where j = 1, 2, ..., k, if the watermark data M r The number of times the j-th element in the Q segment of data is 1 is greater than or equal to 1. Then set the j-th element of the watermark information M′ to 1, otherwise set it to 0;
[0035] The aforementioned error correction process with truncation includes the following steps:
[0036] Step C2.1: Set the maximum number of complete segments Indicates the floor function;
[0037] Step C2.2: Extract watermark data M′ r The first t*k elements are denoted as M″′. r , * is the multiplication operator;
[0038] Step C2.3, M r Each k bits of data in "′" is divided into segments, resulting in t segments of data;
[0039] Step C2.4, Statistical analysis of M″′ r The number of times the j-th element is 1 in the t-segment data, where j = 1, 2, ..., k, if M″ r The number of times the j-th element in segment t is 1 is greater than or equal to Then set the j-th element of the watermark information M′ to 1, otherwise set it to 0. Attached Figure Description
[0040] Figure 1 This is a flowchart of the watermark embedding process for the implicit watermarking method for image generation models according to the present invention.
[0041] Figure 2This is a flowchart of the watermark extraction process for the implicit watermarking method for image generation models of the present invention.
[0042] Figure 3 This is a diagram illustrating the architecture of the implicit watermarking method for image generation models according to the present invention.
[0043] Figure 4 This is an illustrative image example illustrating the distortion attack on the implicit watermarking method for image generation models of the present invention.
[0044] Figure 5 Box plots showing the accuracy of watermark extraction bits under different distortion attacks for the implicit watermarking method for image generation models of the present invention.
[0045] Figure 6 The image shows the average watermark bit accuracy of the implicit watermarking method for image generation models of this invention on social media platforms under different distortion attacks.
[0046] Figure 7 This is a comparative image quality and fidelity graph showing the image quality and fidelity of various watermarking algorithms under different distortion attacks using the implicit watermarking method for image generation models of this invention. Detailed Implementation
[0047] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0048] Example 1: As Figure 1 , Figure 2 and Figure 3 As shown, a method for implicit watermarking in image generation models includes implicit watermark embedding and implicit watermark extraction. The specific process of implicit watermark embedding is as follows: First, the original noise is expanded in one dimension and binarized to obtain a binarized array of the original noise. This binarized array of the original noise is a one-dimensional array. The binarized array of the original noise is then divided into segments of a fixed length, which is determined according to actual needs. The number of segments after segmentation is denoted as . The watermark information in binary data form is expanded to obtain a data bit length equal to The expanded watermark information is then encrypted to obtain encrypted watermark data, which is a one-dimensional array with a length equal to [missing information]. Based on the encrypted watermark data, the binarized array of the original noise is adjusted by parity matching to embed the encrypted watermark data, resulting in an adjusted binarized array of the original noise. This adjusted binarized array is then restored to obtain restored noise conforming to a Gaussian distribution. The statistical distribution characteristics of this restored noise are consistent with the original noise, while simultaneously preserving the watermark information. The restored noise is then reshaped according to the size of the original noise, resulting in reshaped noise. First, an image generation model is used to generate the reshaped noise data, and then an image decoder is used to generate an image containing the encrypted watermark data. This process also includes implicit watermark extraction. The specific process is as follows: First, the image encoder extracts the noise containing the encrypted watermark data from the image containing the encrypted watermark data. Then, the noise containing the encrypted watermark data is expanded in one dimension and binarized to obtain a binarized noise array containing the encrypted watermark data. The length of the binarized noise array containing the encrypted watermark data is equal to the length of the binarized array of the original noise. The encrypted watermark data is extracted from the binarized noise array containing the encrypted watermark data. Next, the extracted encrypted watermark data is decrypted to obtain the watermark data. Finally, the watermark data is corrected to obtain the watermark information.
[0049] In this embodiment, by restoring the adjusted binarized array of the original noise to noise conforming to a Gaussian distribution, the statistical characteristics of the original noise are preserved, thereby ensuring that the visual quality of the generated image is not affected by the watermark embedding. During the watermark (encrypted watermark data) embedding process, only small and dispersed local adjustments are made to the binarized array, without changing the overall distribution characteristics of the original noise, thus preserving the diversity of the image. Since the restored noise has the same statistical characteristics as the original noise, the watermark embedding does not affect the diversity of the output fidelity of the image generation model.
[0050] Example 2: This example is basically the same as Example 1, except that: In this example, based on the encrypted watermark data, the binary array of the original noise is adjusted by parity matching to embed the encrypted watermark data. The specific process of obtaining the adjusted binary array of the original noise is as follows: Let the first... The first segment of data and the encrypted watermark data Bit element correspondence. Determine whether the sum of each data segment in the original noise binarization array and the corresponding element in the encrypted watermark data are both odd or both even. If they are, the data segment in the original noise binarization array remains unchanged. If not, flip the first element in the data segment in the original noise binarization array to adjust the original noise binarization array, thus obtaining the adjusted binarization array of the original noise.
[0051] In this embodiment, when adjusting the binary array of the original noise through parity matching, each adjustment flips at most one bit, having a negligible impact on the overall binary array. This makes the embedded watermark (encrypted watermark data) difficult to perceive or detect. The image generation model is not sensitive to small changes in noise, and this fine-tuning can effectively preserve watermark information during image generation. Therefore, this watermark embedding method is simple to implement, has low computational complexity and cost, high embedding efficiency, and is suitable for large-scale applications.
[0052] Example 3: This example is basically the same as Example 2, except that: in this example, the specific process of extracting the encrypted watermark data from the binary noise array containing the encrypted watermark data is as follows: the binary noise array containing the encrypted watermark data is divided into average segments, and the number of segments is also [number missing]. The encrypted watermark data to be extracted is set as a one-dimensional array with a length of . The binarized noise array containing the watermark data The segment data and the encrypted watermark data to be extracted If the corresponding bit element of the binary array containing the watermark data is... If the sum of the data segments is odd, then the first segment of the encrypted watermark data to be extracted will be... If the bit element is assigned a value of 1, then the binarized noise array containing the watermark data has a bit element assigned a value of 1. If the sum of the data segments is even, then the first segment of the encrypted watermark data to be extracted will be... The bit element is assigned a value of 0, from which the length equal to 0 is extracted. It is also a one-dimensional array of encrypted watermark data.
[0053] In this embodiment, the watermark extraction logic and the watermark embedding logic strictly correspond, enabling lossless watermark recovery in the absence of external interference. Furthermore, during the watermark extraction process, it is only necessary to sum each segment of the binary noise array containing the watermark data and determine its parity, requiring no complex calculations, making it easy to implement and highly efficient.
[0054] Example 4: This example is basically the same as Example 3, except that: in this example, the original noise is expanded in one dimension and binarized to obtain the binarized array of the original noise. The specific process is as follows:
[0055] S1. Let the original noise be Z, the number of channels in the original noise Z be c, and the size of each channel of the original noise Z be h×w, where h represents the length and w represents the width. Flatten the two-dimensional array of each channel of the original noise Z into a one-dimensional array in row-major order. Then, concatenate all the one-dimensional arrays of all channels in channel order to form a one-dimensional array of length c×h×w, denoted as Z. f , will Z fLet the length be N, N = c × h × w, and define Z. f [i] represents Z f The i-th element in the array, where i = 1, 2, ..., N;
[0056] S2, convert the one-dimensional array Z f Each element is binarized to obtain the corresponding binary data, where the one-dimensional array Z... f The i-th element Z f The binarized data corresponding to [i] is denoted as B. z [i], a one-dimensional array Z f The i-th element Z f [i] Binarization is performed using formula (1) to obtain the corresponding binarized data B. z [i]:
[0057]
[0058] Where Φ(·) is the cumulative distribution function of the standard normal distribution;
[0059] S3. Using the one-dimensional array Z obtained in step S2 f The binarized data corresponding to each element constitutes the binarized array B of the original noise. z B z It is a one-dimensional array with length N and B. z The i-th element is B z [i].
[0060] In this embodiment, the original noise is expanded in one dimension and binarized to obtain a binarized array of the original noise. The binarization operation preserves the sign information of the noise, providing a basis for subsequent reconstruction. This process is simple, applicable to any Gaussian distributed noise, and has low implementation cost.
[0061] Example 5: This example is basically the same as Example 4, except that: in this example, the watermark information in binary data form is expanded to obtain a data bit length equal to The specific process of obtaining the expanded watermark information and encrypting it to get the encrypted watermark data is as follows:
[0062] A1. Define a positive integer l that is divisible by N. w (i.e., the number of segments, set according to actual needs), the binarized array B of the original noise. z each l w Each bit element is used as a data segment, thus binarizing the original noise array B. z Average score Segment data,
[0063] A2. Let M be the binary data format of the watermark information, where M is a one-dimensional array. Let k be the length of the watermark information M.
[0064] A3, Judgment Is it an integer? If so, repeat the watermark information M. Next, the expanded watermark information M is formed. r , M d =M, If not, repeat the watermark information M. After that, fill in the end. The zeros form the expanded watermark information M. r , M p =M, p=1,2,..., for Each element is 0. Indicates the rounding up symbol;
[0065] A4. Preset the key Key, and use the ChaCha20 stream cipher algorithm to process the expanded watermark information M. r Encryption is performed, resulting in a length of encrypted watermark data M enc .
[0066] In this embodiment, the extension mechanism adapts to binary arrays of different lengths, making it widely applicable. Furthermore, by repeatedly embedding watermark information, redundancy is increased, enhancing noise resistance. The ChaCha20 stream cipher algorithm is efficient and secure, preventing unauthorized access or tampering of the watermark.
[0067] Example 6: This example is basically the same as Example 5, except that: in this example, the specific process of restoring the adjusted binarized array of the original noise to obtain the restored noise that conforms to a Gaussian distribution is as follows:
[0068] B1. Let B be the adjusted binarized array of the original noise. z ′, B z Let the i-th element of ′ be denoted as B. z [i], will B z The cumulative distribution function value of ′[i] is denoted as θ. i θ is calculated using formula (2). i :
[0069]
[0070] Among them, u iLet represent a random variable obtained by independently sampling from a uniform distribution defined on the closed interval [0, 0.5].
[0071] B2. Use the probability distribution function of the standard normal distribution on θ. i By performing the mapping, we obtain the corresponding Gaussian distribution value, denoted as Z. f ′[i], as shown in formula (3):
[0072] Z f ′[i]=Φ -1 (θ i (3)
[0073] Where, Φ -1 (·) is the probability distribution function;
[0074] B3. The Gaussian distribution values obtained in step B2 are used to construct the restored one-dimensional Gaussian noise array Z. f ′, Z f The i-th element of ′ is Z f ′[i];For the restored one-dimensional Gaussian noise array Z f The original noise Z is reshaped according to its size to obtain the restored noise Z′ that conforms to a Gaussian distribution.
[0075] In this embodiment, the restored noise distribution is consistent with the statistical characteristics of the original noise, ensuring that the image generation model receives similar input. Through accurate CDF inverse mapping (i.e., mapping to the probability distribution function of the standard normal distribution), distribution bias is reduced, guaranteeing the quality and diversity of the generated images.
[0076] Example 7: This example is basically the same as Example 6, except that: in this example, the extracted encrypted watermark data is decrypted to obtain the watermark data, and the watermark data is corrected to obtain the watermark information. The specific process is as follows:
[0077] C1. Denote the extracted encrypted watermark data as M′ enc The ChaCha20 stream cipher algorithm and key Key are used to extract the encrypted watermark data M. e ′ nc Decryption is performed to obtain the watermark data, which is denoted as M. r ′, watermark data M r The length of ′ is
[0078] C2. Set the extended parameter ratio Determine if Q is an integer. If it is, execute the full segment error correction process to obtain the watermark information M′. If Q is not an integer, execute the error correction process including truncation to obtain the watermark information M′.
[0079] The complete paragraph correction process includes the following steps:
[0080] Step C2.1: Transfer the watermark data M r Each k-bit element of ' is divided into a data segment, resulting in Q data segments, each segment having a length of k.
[0081] Step C2.2: Calculate the watermark data M separately. r The number of times the j-th element in the Q-segment data is 1, where j = 1, 2, ..., k, if the watermark data M r The number of times the j-th element in the Q segment of data is 1 is greater than or equal to 1. Then set the j-th element of the watermark information M′ to 1, otherwise set it to 0;
[0082] The error correction process including truncation includes the following steps:
[0083] Step C2.1: Set the maximum number of complete segments Indicates the floor function;
[0084] Step C2.2: Extract watermark data M′ r The first t*k elements are denoted as M″. r , * is the multiplication operator;
[0085] Step C2.3, M″ r Each k bits of data is divided into segments, resulting in t segments of data;
[0086] Step C2.4, Statistical analysis of M″ r The number of times the j-th element is 1 in the t-segment data, where j = 1, 2, ..., k, if M″ r The number of times the j-th element in segment t is 1 is greater than or equal to Then set the j-th element of the watermark information M′ to 1, otherwise set it to 0.
[0087] In this embodiment, the majority voting mechanism can correct some errors, and the watermark can be recovered even if the data is damaged due to distortion attacks; the error correction process adapts to different extension situations to ensure the recovery effect; the combination of encryption and error correction ensures that the watermark is both secure and reliable.
[0088] To verify the performance of the implicit watermarking method for image generation models of this invention, the following experiments were conducted:
[0089] I. Experimental Setup:
[0090] This experiment uses Python code to implement the implicit watermarking method for image generation models of this invention in the following hardware and software environment: Hardware: NVIDIA GeForce RTX 4090 graphics card, Software: Ubuntu 22.04 operating system.
[0091] The implicit watermarking method for image generation models of this invention was used to manipulate noisy data, generating 1000 RGB images of size 512×512. Each image embedded 64 bits of watermark information and was saved as a PNG image. Subsequently, various distortion attacks and transmission tests on social media platforms, including WeChat Moments, WeChat chat, Xiaohongshu, Weibo, Bilibili, Twitter, and Instagram, were applied to these images to evaluate the robustness of the watermark. In addition, to compare with existing methods, the Gaussian Shading (GS) method disclosed in reference [1] "Yang Z, Zeng K, Chen K, et al. Gaussian shading: Provable performance-lossless image watermarking for diffusion models [C] / / Proceedings of the IEEE / CVF Conference on Computer Vision and Pattern Recognition. 2024: 12162-12171." and the TreeRing Watermark (TR) method disclosed in reference [2] "Wen Y, Kirchenbauer J, Geiping J, et al. Tree-rings watermarks: Invisible fingerprints for diffusion images [J]. Advances in Neural Information Processing Systems, 2023, 36: 58047-58063." were used to operate on noisy data to generate 1000 RGB images of size 512×512, and their image fidelity and diversity were evaluated. The implementation of the two existing methods is also completed under the aforementioned hardware and software conditions.
[0092] II. Experimental Indicators:
[0093] The accuracy of watermark extraction is measured by bit accuracy, defined as the ratio of correctly extracted bits to the total number of bits. This metric ranges from 0% to 100%. A bit accuracy close to 100% indicates that the watermark information has been effectively extracted; a bit accuracy close to 50% indicates that the watermark information has not been extracted, approaching the level of random guessing; in extremely rare cases, if the bit accuracy is close to 0%, the watermark information can be recovered by inverting each bit, but this rarely occurs in practice. This experiment uses this metric to evaluate the robustness of the watermark after distortion attacks and transmission on social media.
[0094] To evaluate the visual quality and diversity of the generated images, the following metrics are used: FID (Fréchet Inception Distance): Measures the similarity between the distribution of the generated image and the reference image. A lower FID value indicates that the distribution of the generated image is closer to the reference distribution, and the watermark embedding has a smaller impact on image quality. CLIP-FID: Combines the CLIP model to evaluate the FID metric of the consistency between the generated image and the text prompt. A lower CLIP-FID value indicates a higher degree of matching between the image content and the prompt, and the watermark embedding has a smaller impact on image fidelity. KID (Kernel Inception Distance): Evaluates the difference between the distribution of the generated image and the reference image distribution. A lower KID value indicates that the distribution of the generated image is closer to the reference image, and the watermarking method has a smaller negative impact on image diversity.
[0095] III. Experimental Procedure:
[0096] 1. Distortion Attack Simulation: The following distortion attacks were applied to 1000 watermarked images generated by the implicit watermarking method of this invention and two existing methods, with different intensities for each attack: Gaussian noise, Gaussian blur, JPEG compression, image size reduction, random image cropping, random image loss, contrast enhancement, brightness enhancement, and image regeneration using a variational autoencoder (VAE). After these attacks, watermark extraction was performed on the images, and bit accuracy was calculated. Specific examples of the distortion attacks are shown below. Figure 4 As shown.
[0097] 2. Image fidelity and diversity test: To compare the image quality of the implicit watermarking method of the present invention for image generation model with the two existing methods, the following test groups were set up: Reference group (G1-No-W): 1000 512×512 RGB images without watermark. Control group (G2-No-W): 1000 512×512 RGB images without watermark. Method group of the present invention (G2-W-Ours): 1000 512×512 RGB images with 64-bit watermark. GS method group (G2-W-GS): 1000 512×512 RGB images with 64-bit watermark, using the Gaussian Shading method (reference [1]). TR method group (G2-W-TR): 1000 512×512 RGB images with 64-bit watermark, using the TreeRing Watermark method (reference [2]). Using FID, CLIP-FID, and KID indices, the differences in image distribution between the reference group (G1-No-W) and the control group (G2-No-W), as well as between the control group (G2-No-W) and each watermarking method group (G2-W-Ours, G2-W-GS, G2-W-TR), were calculated. To visually compare fidelity, four types of images (G2-No-W, G2-W-Ours, G2-W-GS, G2-W-TR) were generated using the same prompt (e.g., "natural scenery") for cross-sectional comparison.
[0098] 3. Social Media Platform Testing: Upload the watermarked images to social media platforms, download all uploaded images and extract the watermarks, then calculate the bit accuracy after watermark extraction.
[0099] IV. Analysis of Experimental Results:
[0100] 1. Distortion Attack Simulation: Under attack-free conditions, based on statistical results from 1000 test images, the watermark extraction bit accuracy of the implicit watermarking method for image generation models in this invention is 100%. In most distortion attacks, even with high attack strength, the bit accuracy remains above 90%, demonstrating good robustness. Only when the attack strength is extremely high (e.g., severely distorted images) does the bit accuracy drop to around 50%, at which point the image becomes unusable. Results are as follows... Figure 5 As shown. Analysis Figure 5 It can be seen that the implicit watermarking method for image generation models of the present invention maintains a stable watermark extraction accuracy under mild to moderate attacks, proving its excellent resistance to attacks.
[0101] 2. Horizontal comparison with GS and TR methods:
[0102] Fidelity comparison: Images generated using the same prompt words are compared side-by-side, and the results are as follows. Figure 6 As shown. Analysis Figure 6 It can be seen that the image (G2-W-Ours) generated by the implicit watermarking method for image generation model of the present invention has a high degree of visual consistency with the control group (G2-No-W), while the images generated by the two existing methods are significantly different from the control group, proving that the implicit watermarking method for image generation model of the present invention has a significant advantage in fidelity.
[0103] Diversity comparison: The results were evaluated using FID, CLIP-FID and KID indicators, and are shown in Table 1. G1-No-W is the watermark-free reference group and G2-No-W is the watermark-free control group.
[0104] Table 1: Comparison of Image Diversity Indicators
[0105] Dataset FID↓ CLIP-FID↓ KID↓ G1-No-W vsG2-No-W 24.46 1.012 0.00058 G1-No-W vsW-TR 41.37 3.269 0.01978 G1-No-W vsW-GS 38.97 3.001 0.01389 G1-No-W vsW-Ours 24.98 0.958 0.00037
[0106] As shown in Table 1, the FID, CLIP-FID, and KID values of the method of this invention (G2-W-Ours) are close to those of the control group (G2-No-W), and are much lower than those of the GS and TR methods, indicating that the watermark embedding has the least impact on image diversity and is superior to existing methods.
[0107] 3. Social Media Platform Testing: Test results on social media platforms, such as... Figure 7 As shown. Figure 7 The figure shows the average accuracy of the watermark bit across different platforms, expressed as a percentage. Figure 7 Test results show that after uploading and downloading images on social media platforms, the bit accuracy of the watermark information remains above 99%, demonstrating extremely high robustness and effectiveness. Particularly on common platforms such as WeChat and Weibo, the watermark bit accuracy approaches 100%, indicating almost no loss of watermark information on these platforms. Overall, all test platforms demonstrate the high accuracy and stability of the implicit watermarking method based on image generation models of this invention in extracting watermark information on real-world social media platforms, verifying the effectiveness of the implicit watermarking method based on image generation models in practical applications.
[0108] In summary, the implicit watermarking method for image generation models of the present invention can effectively embed watermarks, ensure the quality of generated images, and also guarantee the diversity of generated images. It will not negatively affect the output fidelity and data authenticity of the image generation model, and has broad application prospects for the protection of the originality and copyright tracking of images generated by the image generation model.
Claims
1. An image-oriented model-embedded watermarking method comprising an embedded watermarking embedding operation and an embedded watermarking extracting operation, characterized in that: The specific process of the hidden watermark embedding operation is as follows: first, the original noise is one-dimensionally unfolded and binarized to obtain a binarized array of the original noise, the binarized array of the original noise being a one-dimensional array; the binarized array of the original noise is evenly segmented according to a fixed segment length, and the number of the segmented segments is denoted as ; the watermark information in the form of binary data is expanded to obtain expanded watermark information with a data bit number equal to ; the expanded watermark information is encrypted to obtain encrypted watermark data, the encrypted watermark data being a one-dimensional array and having a length equal to ; based on the encrypted watermark data, the binarized array of the original noise is adjusted through parity matching to embed the encrypted watermark data, to obtain an adjusted binarized array of the original noise; the adjusted binarized array of the original noise is restored to obtain restored noise conforming to a Gaussian distribution, the statistical distribution characteristics of the restored noise being consistent with those of the original noise and the watermark information being retained at the same time; the restored noise is reshaped according to the size of the original noise to obtain reshaped noise; the reshaped noise data is generated using an image generation model, and the reshaped noise data is subjected to image generation using an image decoder to generate an image containing the encrypted watermark data; the specific process of the hidden watermark extraction is as follows: first, the image containing the encrypted watermark data is subjected to image encoding using an image encoder to extract noise containing the encrypted watermark data; then, the noise containing the encrypted watermark data is one-dimensionally unfolded and binarized to obtain a binarized noise array containing the encrypted watermark data, the length of the binarized noise array containing the encrypted watermark data being equal to that of the binarized array of the original noise; the encrypted watermark data is extracted from the binarized noise array containing the encrypted watermark data; then, the extracted encrypted watermark data is decrypted to obtain watermark data; finally, the watermark data is subjected to error correction to obtain watermark information.
2. The image-oriented, model-generated, hidden watermarking method according to claim 1, characterized in that Based on the encrypted watermark data, the binary array of the original noise is adjusted to embed the encrypted watermark data through parity matching, and the specific process of obtaining the adjusted binary array of the original noise is as follows: let the first element of the binary array of the original noise be x , the first element of the encrypted watermark data be y , and the sum of each segment of the binary array of the original noise be s , and the element corresponding to the segment data in the encrypted watermark data be t , respectively, determine whether the sum of each segment of the binary array of the original noise and the element corresponding to the segment data in the encrypted watermark data are both odd or both even, if yes, the segment data of the binary array of the original noise remains unchanged, if not, the first element in the segment data of the binary array of the original noise is flipped, the binary array of the original noise is adjusted, and thus the adjusted binary array of the original noise is obtained.
3. The image-oriented model-based method for embedding a watermark according to claim 2, characterized in that The specific process of extracting the encrypted watermark data from the binary noise array containing the encrypted watermark data is as follows: the binary noise array containing the encrypted watermark data is evenly segmented, and the number of segments is also , the encrypted watermark data to be extracted is a one-dimensional array, and the length is , the data of the first segment of the binary noise array containing the encrypted watermark data is corresponded to the first element of the encrypted watermark data to be extracted, if the sum of the data of the first segment of the binary noise array containing the encrypted watermark data is odd, the first element of the encrypted watermark data to be extracted is assigned as 1, if the sum of the data of the first segment of the binary noise array containing the encrypted watermark data is even, the first element of the encrypted watermark data to be extracted is assigned as 0, thus the encrypted watermark data with the length equal to and being a one-dimensional array is extracted.
4. The image-oriented model-based method for embedding a watermark according to claim 3, characterized in that The specific process of one-dimensional expansion and binaryzation of the original noise to obtain the binary array of the original noise is as follows: S1, let the original noise be , let the original noise be , let the number of channels contained be , let the original noise be , let the size of each channel of the original noise be , wherein h represents length, w represents width, let the original noise be , and let the two-dimensional array of each channel of the original noise be flattened into a one-dimensional array in row priority order respectively, then let the one-dimensional arrays of all channels be spliced in channel order successively to form a one-dimensional array with a length of , denoted as , let the length of be , = , and let be the th element in , wherein ; S2, binarizing each element of the one-dimensional array to obtain corresponding binarized data, wherein the first element of the one-dimensional array corresponding binarized data is denoted as , and the first element of the one-dimensional array is binarized by formula (1) to obtain corresponding binarized data : wherein is the cumulative distribution function of the standard normal distribution; S3. Using the one-dimensional array obtained in step S2 The binarized data corresponding to each element constitutes the binarized array of the original noise. ,in It is a one-dimensional array with length . , The The bit element is .
5. The image-oriented model-based method for embedding a watermark according to claim 4, characterized in that The watermark information in binary data form is expanded to obtain expanded watermark information with data bits equal to The specific process of encrypting the expanded watermark information to obtain encrypted watermark data is as follows: A1, set a positive integer that can be divided by the number of the original noise binary array , each bit element of the original noise binary array as a piece of data, so that the original noise binary array is divided into pieces of data, , ; A2, the watermark information in the form of binary data is denoted as , is a one-dimensional array, the length of the watermark information is denoted as , wherein ; A3, judge whether it is an integer, if yes, then the watermark information repeat times, forming the extended watermark information , =M1M2… , M d = , d=1,2,… ; if not, then the watermark information repeat times, and then fill in the end bit , forming the extended watermark information , =M1M2… , M p = , p=1,2,… , is bit elements, each bit element is 0, indicates the upward rounding symbol; A4. Preset Key The ChaCha20 stream cipher algorithm was used to process the expanded watermark information. Encryption is performed, resulting in a length of encrypted watermark data .
6. The image-oriented model-based method for embedding a watermark according to claim 5, characterized in that The specific process of restoring the adjusted binary array of the original noise to obtain the restored noise conforming to the Gaussian distribution is as follows: B1, the adjusted binarization array of the original noise is denoted as , the first bit element of is denoted as , and the cumulative distribution function value of is denoted as , and the value of is calculated by using formula (2): wherein denotes a random variable obtained by independently sampling from a uniform distribution defined on the closed interval [0, 1]. B2, mapping the probability distribution function of the standard normal distribution to obtain the corresponding Gaussian distribution value, denoted as As shown in equation (3): wherein is a probability distribution function; B3. The Gaussian distribution values obtained in step B2 are used to construct the restored one-dimensional Gaussian noise array. , The The bit element is ; for the restored one-dimensional Gaussian noise array Based on the original noise The dimensions are reshaped to obtain a restored noise that conforms to a Gaussian distribution. .
7. The image-oriented model-based method for embedding a watermark according to claim 6, characterized in that The specific process of decrypting the extracted encrypted watermark data to obtain the watermark data, correcting the watermark data, and obtaining the watermark information is as follows: C1, the extracted encrypted watermark data is denoted as , using the ChaCha20 stream cipher algorithm and the key to decrypt the extracted encrypted watermark data , to obtain watermark data, which is denoted as , the length of the watermark data is ; C2, set the expansion parameter ratio , determine whether it is an integer, if so, execute the complete segment error correction process to obtain the watermark information ; if it is not an integer, execute the error correction process with truncation to obtain the watermark information ; The complete segment error correction process includes the following steps: Step C2.1: Transfer the watermark data each The bit element is divided into a segment of data, resulting in Segment data, each segment has a length of [length missing]. ; Step C2.2, count the watermark data the number of elements in the segment data j with value 1, wherein if the watermark data the number of elements in the segment data j with value 1 is greater than or equal to then let the element at position of the watermark information j be 1, otherwise 0; The error correction process with truncation includes the following steps: The complete segment error correction process includes the following steps: Step C2.
1. Set maximum number of complete segments , denotes the floor symbol. Step C2.
2. Truncating watermark data of the preceding bit element, denoted bit element, denoted , denotes a multiplication operator; Step C2.3, divide each of the data of the bit into a piece of data, to obtain pieces of data ; Step C2.4, Statistics the number of elements in the segment data whose bit is 1, wherein j if the number of elements in the segment data whose bit is 1 is greater than or equal to , then the bit element of the watermark information j is 1, otherwise 0. j