AIGC image watermarking method and system based on diffusion model generation path deflection

By introducing a key-guided path deflection mechanism in the diffusion model generation path, combining user private keys and timestamps to generate initialization noise, embed watermark signals, and realizing non-forgery verification of watermarks through DDIM inversion and initialization deviation calculation, the problem of insufficient reliability and attack resistance of watermarks in the existing technology is solved, and is suitable for copyright protection and tracking of AI content generation platforms and social media platforms.

CN120339030AActive Publication Date: 2025-07-18ZHEJIANG UNIV

Patent Information

Application Number
CN202510829783.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-18
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

The existing AIGC image watermarking technology has shortcomings in improving ownership verification reliability, enhancing attack resistance and supporting auditability. Especially without training and compatibility with mainstream diffusion models, it is difficult to take into account the semantic coupling, verification security and attack robustness of watermarks at the same time.

Method used

By introducing a key-guided path deflection mechanism in the diffusion model generation path, the initialization noise is generated in combination with the user's private key and timestamp, the watermark signal is embedded, and the non-forgery verification of the watermark is achieved through DDIM inversion and initialization deviation calculation in the verification stage.

Benefits of technology

It realizes watermark embedding without training in the diffusion model, is highly robust and non-forgery, supports measurable copyright protection and traceability, reduces system deployment costs, and is suitable for copyright confirmation and tracking of AI content generation platforms and social media platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120339030A_ABST
    Figure CN120339030A_ABST
Patent Text Reader

Abstract

The invention discloses an AIGC image watermarking method and system based on diffusion model generation path deflection. The method comprises the following steps: a server distributes a group of private key vectors for each user as a unique identity certificate; generating initial noise through an initial transformation function by combining a random salt value constructed by a user key and image generation time; in the first several steps of diffusion generation, generating path deflection according to key guidance, and embedding watermark semantics into image content in an implicit manner; after completion, publicly recording and generating a timestamp; in the verification stage, estimation noise is recovered through a reverse diffusion process and compared with reference noise reconstructed by a secret key and a timestamp, the mean square error of initialization deviation is calculated, and verification is passed if the mean square error is lower than a set threshold value. According to the AIGC image watermarking method and system based on the diffusion model generation path deflection, robust implantation and high-credibility verification of a copyright watermark can be realized, and the method and system are suitable for copyright confirmation and tracking scenes of an AIGC image generation platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of copyright protection for artificial intelligence-generated content, and in particular, to an AIGC image watermarking method and system based on the deflection of the generation path of a diffusion model. Background Art

[0002] With the rapid development of artificial intelligence-generated content (AIGC) technology, especially the wide application of diffusion models in the field of image generation, users can automatically generate high-quality image content based on text prompts or reference images. Such models as Stable Diffusion, DALL·E, and Midjourney have been widely adopted in multiple scenarios such as film and television production, digital art, and social media. However, with the increasing maturity of such generation technologies, the issues of copyright protection and attribution verification for AIGC images have become particularly prominent. On the one hand, ordinary users or creators hope that the images generated by AIGC can be clearly marked with attribution and protected by copyright; on the other hand, content service platforms need to bear compliance responsibilities to ensure the traceability and uniqueness of the owners of the generated images. These demands have promoted the rapid development of AIGC image watermarking technology.

[0003] Currently, image watermarking technologies are mainly divided into two categories: embedded watermarks and intrinsic watermarks. Embedded watermarking methods usually insert the watermark signal as a post-processing step into the image after image generation. Common methods include least significant bit (LSB) modulation in the spatial domain, frequency domain embedding (such as DCT, DWT), or neural network-based steganographic coding. The advantages of these methods are simple implementation and independent deployment, but since the watermark is added externally and has no direct association with the image generation process, it is easily affected by conventional image processing (such as compression, blurring, cropping) and targeted attacks (such as adversarial perturbations, reconstruction attacks). Although some methods introduce adversarial training to enhance robustness, this often results in high system overhead and poor migration.

[0004] In contrast, the emerging internal watermarking methods in recent years embed watermark signals during the generation process of diffusion models, attempting to achieve a deep binding between the watermark and the image semantics through interventions in the initial noise or generation path. Such methods do not rely on dedicated embedding or extraction modules and can achieve invisible and non-removable watermark effects without modifying the original generation model, thus having more advantages in terms of practicality and theoretical consistency. However, existing internal methods still face key technical bottlenecks. On the one hand, most of them use static vectors or explicit messages as watermark identifiers, and the verification process usually relies on the restoration of specific content or similarity scoring, making it difficult to cope with semantic-level forgeries or targeted attacks. On the other hand, recent research has shown that even if internal watermarking methods have strong robustness, attackers can still use means such as diffusion model inversion and gradient optimization to forge or erase watermarks with the help of open-source alternative models, and only need minimal image modification to bypass verification. More importantly, most existing methods do not essentially distinguish between "watermark removal attacks" and "watermark forgery attacks", often treating all attack behaviors as unified perturbations, thus ignoring the structural differences presented by different attack intentions in the latent space, which will seriously limit their interpretability and traceability capabilities in the real world.

[0005] In summary, the current AIGC image watermarking technology still has obvious deficiencies in improving the reliability of ownership verification, enhancing anti-attack capabilities, and supporting auditability. Existing methods are still unable to simultaneously take into account the semantic coupling of watermarks, that is, the tightness of the mutual association and integration between the watermark and the semantic content of the image during the generation process, verification security, and attack robustness without training and being compatible with mainstream diffusion models. Therefore, there is an urgent need for a new type of internal watermark mechanism that is more complete in theory and more robust in practice, which can achieve low-intervention implantation in the diffusion path, measurable verification, and non-forgeable identity binding, and fundamentally solve the copyright protection and traceability problems of AIGC images. Summary of the Invention

[0006] The purpose of the present invention is to provide an AIGC image watermarking method and system based on the deflection of the generation path of the diffusion model to solve the problems existing in the above-mentioned background technology.

[0007] To achieve the above purpose, the present invention provides an AIGC image watermarking method based on the deflection of the generation path of the diffusion model, including the following steps: The server assigns a group of private key vectors to the user; Combining the user's private key and a random salt value to generate initial noise; During the generation process of the diffusion model, embed the watermark signal into the semantic process generated by diffusion; After the diffusion process ends, output the finally generated image with a watermark, and embed the timestamp information during generation into the image metadata for public release; In the verification stage, the image to be verified, the user's private key, and the timestamp are received, the corresponding initial noise is reconstructed, and compared with the reference noise generated based on the private key and the timestamp; The deviation intensity is calculated based on the estimated noise and the reference noise. When the statistic of the deviation is less than the preset threshold, it is determined that the image is generated by the corresponding private key, thus completing the ownership verification.

[0008] Preferably, for the initial transformation function used as the starting point for diffusion model sampling, a salt value generated by combining the private key and the timestamp is used to construct standard normal distribution noise through the Box-Muller transformation: ;

[0009] where is the cumulative distribution function of the standard normal distribution.

[0010] Preferably, in the first several steps of the diffusion model, the user's private key is used to deflect the diffusion path. Specifically: ; where the deflection function is: ; where represents the time step; in the diffusion model, represents the noise retention coefficient at the th step, and is the cumulative noise retention ratio from the first step to the th step, which is used to measure the signal retention degree from the initial state to the current step; is the denoising prediction network of the diffusion model at step ; is a deflection function is a hyperparameter that controls the deflection intensity.

[0011] Preferably, the deflection process is performed within the first N steps of diffusion, and the deflection intensity is controlled by a constant . The product of in the deflection function and the image content constitutes the dynamic perturbation of the sampling path, realizing the deep coupling of the watermark and the image semantics.

[0012] Preferably, in the verification stage, given the image to be verified , the key and the timestamp , based on the DDIM inversion technology, the inverse deflection function is used to restore the noise . The inverse deflection function is expressed as: ; ;

[0013] And calculate the initial deviation, expressed as: ; Wherein, is the deflection inverse function; the initialization function and the noise after inversion The difference between them constitutes the verification deviation, and the mean square error is used as all verification indicators.

[0014] Preferably, calculate the deviation intensity according to the difference between the estimated noise and the reference noise. If its second moment satisfies: ; Then confirm that the image belongs to the legitimate owner corresponding to the user key . The threshold is set according to the hypothesis testing framework. Under the condition of non-watermarked images or key forgery, the probability that the initialization deviation exceeds does not exceed the set significance level .

[0015] Preferably, the verification security satisfies the following limit relationship: ; Wherein, represents the forged key; represents the legitimate key; represents the initialization deviation obtained by inversion; represents the deviation under the legitimate key; Even if the forged key infinitely approaches the legitimate key, the deviation is still greater than the deviation corresponding to the correct key, ensuring verification uniqueness.

[0016] Preferably, the initialization deviation has the following analytical form: ; ; ; ;

[0017] Wherein, the deflection coefficient , . When and infinitely approach, there is: ; Wherein, represents the noise retention coefficient of the i-th step; is ; denote ; and respectively denote the error terms at each step under the legal key and the forged key; denotes using the forged key through the initial transformation function to calculate the verification starting point; in the DDIM inversion, denotes the noisy image obtained using the legal key at time, while denotes the noisy image obtained using the forged key at time.

[0018] Preferably, it is thus proved that the deviation is uniquely bound to the user key, ensuring that the diffusion trajectory can only be generated by a unique key, thereby forming the basis for the non-forgeability of watermark verification.

[0019] The present invention also provides an AIGC image watermarking system based on the deflection of the generation path of the diffusion model, including a key registration module, a watermark image generation module, and an ownership verification module; The key registration module is used to generate and allocate a unique user private key for each user, and this key is used to bind the image generation path in the subsequent watermark embedding and verification processes; The watermark image generation module includes: an initialization noise generation unit, which is used to combine the user key and the random salt value based on the generation time, and generate initialization noise obeying the standard normal distribution through the Box-Muller transformation; a semantic deflection injection unit, which is used to deflect the generation path with key guidance in the initial stage of sampling of the diffusion model; an image output unit, which is used to write the finally generated image and the generation timestamp into the image metadata and then output; The ownership verification module includes: a diffusion inversion unit, which is used to inversely map the input image back to the estimated initialization noise through the inverse deflection algorithm of the watermark image generation module; an initialization reconstruction unit, which is used to reconstruct the standard initialization noise through the key and the timestamp; a deviation calculation and determination unit, which is used to calculate the initialization deviation and compare its second-order moment with a preset threshold. If the deviation is less than the threshold, it is verified that the image is generated by a legitimate user.

[0020] The present invention adopts the above-mentioned AIGC image watermarking method and system based on the deflection of the generation path of the diffusion model, and has remarkable technical effects: First of all, the present invention completes watermark injection in the generation process of the diffusion model, without any structural modification or retraining of the original model, and has the general deployment ability of "plug and play". Compared with the traditional embedded watermark method, the present invention does not rely on image post-processing, nor does it require training an additional embedding network and decoder, significantly reducing the system deployment cost and maintenance complexity.

[0021] Secondly, the two-stage watermark embedding mechanism (initialization + path deflection) proposed by the present invention can achieve the deep integration of the watermark and the semantic structure of the image while ensuring the quality of the generated image. Since this mechanism not only intervenes in the initial sampling points but also guides the diffusion path to be biased, the watermark information is globally propagated and embedded during the image generation process, thus having stronger robustness and being difficult to be removed by means of reconstruction or perturbation.

[0022] Thirdly, the present invention adopts a statistical test method based on initialization deviation to replace the traditional information extraction method. By calculating the difference between the DDIM inversion result of the watermarked image and the initialization result of the legitimate key, an ownership verification mechanism without message embedding is realized. This verification method not only does not require decoding the watermark information, avoiding vulnerability problems such as decoder failure, but also supports setting security levels in different scenarios through threshold regulation.

[0023] Finally, the present invention also provides a structured mathematical model, theoretically deduces and empirically verifies the distinguishability between the legitimate key and the forged key in the initialization deviation space, constructs a verifiable security boundary, and thus realizes the unforgeability of watermark verification. This security guarantee mechanism provides a basic support for subsequent use in high-reliability application scenarios such as judiciary and copyright disputes.

[0024] In summary, the present invention realizes an image watermarking method that is untrained, invisible, unforgeable, and verifiable by introducing a key-based direction deflection mechanism into the diffusion model generation path, having broad practical application prospects and industrial transformation value, and being particularly suitable for copyright confirmation and tracking scenarios of AI content generation platforms, social media platforms, and digital art works. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0026] Figure 1 is a flow schematic diagram of the method of the present invention; Figure 2 is an overall schematic diagram of the system of the present invention; Figure 3 is a comparison diagram of watermark verifiable results of the method of the present invention, where (a) is compression, (b) is noise, (c) is blurring, (d) is brightness, and (e) is average; Figure 4It is a schematic diagram of the overall structure of the method of the present invention. Detailed implementation mode

[0027] The following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts belong to the scope of protection of the present invention.

[0028] Embodiment 1: As Figure 1 shown, an AIGC image watermarking method based on generating path deflection by a diffusion model, by introducing a diffusion path deflection mechanism guided by a key, innovatively embeds the image watermark into the generation process itself, and has the following remarkable features and advantages: First, the proposed initialization noise function maintains the sampling assumption of the diffusion model for the standard normal distribution, ensuring that the generation quality is not affected, achieving zero modification and zero training overhead for the original model, and having good versatility and deployability; Second, by introducing path deflection controlled by a key in the first several steps, the present invention realizes the deep coupling of the watermark and the image semantics, making the watermark have strong robustness, and still being effective even under complex threats such as reconstruction, denoising or adversarial attacks; Third, the proposed verification mechanism based on initialization deviation does not rely on traditional explicit message embedding and decoding processes, and directly verifies the existence and uniqueness of the watermark through statistical distance measurement, effectively avoiding the decoder vulnerability problem. Through the above technical means, the present invention solves the core bottleneck problems of current AIGC image watermarking technology in terms of verifiability, anti-attack ability and deployment cost, and provides a theoretically provable, safe and efficient, and easy-to-implement solution for the copyright protection and liability traceability of generative AI content. It includes the following steps: Step S100, the server assigns a private key vector that follows the standard normal distribution to each user as the only identity credential, including the following steps: In this embodiment, when a user registers or first accesses, the server generates and assigns a private key vector to each user, the dimension of which is the same as the initial noise used by the diffusion model (such as in StableDiffusion), and the value of each dimension follows the standard normal distribution, that is

[0029] Step S200: Combine the user's private key with a random salt value generated based on the image generation time, and generate initialization noise that conforms to the standard normal distribution through an initial transformation function as the starting point for diffusion model sampling, including the following steps: In this embodiment, when the user initiates an image generation request, the system first obtains the current generation time , and generates a random salt value vector that is consistent with the dimension of the private key as a variable to enhance generation diversity and ensure that the watermark is not uniquely reproduced. Subsequently, the system calls the initialization function to calculate the initialization noise: ; where is the mapping of the cumulative distribution function (CDF) of the normal distribution of , and the result ensures that obeys the standard normal distribution . This noise is used as the starting point input for the diffusion model to start image generation.

[0030] Step S300: During the generation process of the diffusion model, in the first several time steps, deflect the diffusion path according to the user's private key, so as to embed the watermark signal into the semantic process generated by diffusion, including the following steps: During the generation process of the diffusion model, the system performs a key-guided path deflection operation in the first N time steps (e.g., N = 5) to implicitly embed the watermark signal into the image semantic structure. Specifically, at each time step , update the sampling path as follows: ; where the deflection function is defined as: ; where is a hyperparameter that controls the deflection intensity (e.g., ), is the denoising prediction network of the diffusion model at step t. The above operations will introduce key-bound perturbations in the semantic space to form an implicit path watermark. At each remaining time step , use the standard DDIM sampling process.

[0031] Step S400: After the diffusion process ends, output the finally generated image with a watermark, and embed the timestamp information at the time of generation into the metadata of the image and return it to the user, including the following steps: After completing the diffusion process, the system outputs the finally generated image 。Meanwhile, embed the timestamp T corresponding to the image generation as metadata into the image, or save it separately to the accompanying log / database to support subsequent watermark verification operations. This timestamp and the user key together constitute the necessary inputs for the initialization function to ensure subsequent verification consistency.

[0032] Step S500, in the verification phase, receive the image to be verified, the user's private key, and the timestamp, and reconstruct the corresponding initialization noise through a denoising inversion mechanism and compare it with the reference noise generated based on the private key and the timestamp, including the following steps: In the ownership verification phase, the user or the platform submits the image to be verified , the user key and the timestamp . Among them, the timestamp is obtained from the metadata of the image to be verified. The system first performs the DDIM inversion process, performs a reverse diffusion operation on the image, and inversely deduces the corresponding estimated initialization noise . During the inversion process, the system uses the deflection inverse function to gradually restore the diffusion path, and the specific expression is: ; Finally, the estimated noise is obtained.

[0033] Step S600, calculate the deviation intensity based on the difference between the estimated noise and the reference noise. When the statistic of this deviation is less than the preset threshold, determine that the image is generated by the corresponding private key, thereby completing the ownership verification, including the following steps: The system uses the initialization function again to calculate the reference noise , and subtract it from the estimated noise to obtain the initialization deviation: ; Then the system calculates its second moment (i.e., the mean square error) , and compares it with the preset threshold . If the deviation intensity is less than the threshold, it is determined that the image is generated by this user key, and the verification passes; otherwise, it is judged as illegally generated or forged watermark, and the verification is rejected.

[0034] In order to make a reliable judgment on the verification deviation in practice, in this example, a statistical hypothesis testing framework is adopted to determine the deviation intensity . Set up the null hypothesis : The image is not generated by a legal key. The system determines the deviation threshold at a significance level (such as ) so that: ; That is, on the premise of non-watermark image or forged key input, the probability that the initialization deviation is less than the threshold does not exceed . Threshold can be set by statistically analyzing a large number of initialization deviation samples of non-watermark images or incorrect keys in the verification system and using the quantile of their distribution, so as to achieve a high-confidence rejection of illegal samples. In the experimental settings, we adopt a significance level , and obtain the corresponding threshold as . This threshold can not only effectively exclude illegal keys, but also ensure that legitimate users can stably pass the verification under normal generation conditions.

[0035] In addition, the watermark verification mechanism proposed in the present invention makes a judgment based on the statistic of the initialization deviation . Its core security lies in that even if an attacker has a legitimate watermark image and attempts to forge a legitimate user key through optimization or imitation, etc., it is impossible to bypass the deviation test. For this reason, we theoretically prove that even if the forged key infinitely approaches the legitimate key , that is, under the assumption of the strongest attack , the mean square error of the obtained initialization deviation is still greater than the deviation under the legitimate key . Specifically, the following limit inequality holds: ; In the derivation, we define the deflection coefficient as , , and combine the inverse error propagation model to obtain the following form of error expression: ; ; ; ;

[0036] where and respectively represent the error terms at each step under the legitimate and forged keys, and they have a consistent directional distribution on the neural network estimation residuals. Therefore, when and infinitely approach, we have: ; means that the mean square error of the attacker is always higher than that of the legitimate user, thus ensuring the uniqueness and non-forgeability of the ownership verification.

[0037] Verification experiments were conducted on the application scenarios of the image watermarking method provided in this embodiment for image generation under unconditional and text control. In the verification experiments, two models, DDIM and StableDiffusion v2.1, pre-trained on the CelebAHQ dataset were selected. For copyright protection in the text-to-image scenario, we used the text in the COCO and CelebAHQ datasets as input. In this embodiment, watermarked image generation and verification were respectively carried out in the above two application scenarios, and the experimental results are shown in Table 1: Table 1 Comparison table of experimental results ;

[0038] The results show that this technical solution can always perform better than other related technologies in the two application scenarios, confirming the high quality and verifiability of the watermarked images of the present invention, the visual and semantic consistency between the generated watermarked images and the watermark-free images, and at the same time being able to accurately verify the user's copyright.

[0039] In this embodiment, the advantages of the image watermarking method over the existing related image watermarking methods in realistic interference scenarios were further verified. The implemented realistic interferences include compression, noise, blur, and brightness adjustment. The interference level is 3 levels, and as the level increases, the interference intensity increases. The experimental results are as Figure 3 shown, confirming that the image watermarking method based on semantic deflection has better robustness by strongly binding the user identity and the image generation process, and is less likely to be eliminated by attacks.

[0040] The overall structural diagram of the AIGC image watermarking method based on the deflection of the diffusion model generation path is as Figure 4 shown.

[0041] Embodiment 2: As Figure 2 shown, an AIGC image watermarking system based on the deflection of the diffusion model generation path includes a key registration module 100, a watermarked image generation module 200, and an ownership verification module 300; The key registration module 100 is used to generate and assign a unique user private key for each user, and this key is used to bind the image generation path in the subsequent watermark embedding and verification processes; The watermarked image generation module 200 includes: an initialization noise generation unit, which is used to combine the user key and a random salt value based on the generation time to generate initialization noise obeying the standard normal distribution through the Box-Muller transformation; a semantic deflection injection unit, which is used to deflect the generation path by key guidance in the initial stage of sampling of the diffusion model; an image output unit, which is used to write the finally generated image and the generation timestamp into the image metadata and then output; The ownership verification module 300 includes: a diffusion inversion unit for reversely mapping an input image back to an estimated initial noise through an inverse deflection algorithm of a watermark image generation module; an initialization reconstruction unit for reconstructing a standard initial noise through a key and a timestamp; a deviation calculation and determination unit for calculating an initialization deviation and comparing its second moment with a preset threshold, and if the deviation is less than the threshold, verifying that the image is generated by a legitimate user.

[0042] All changes and variations made without departing from the spirit and scope of the present invention, and all equivalent technical solutions also fall within the scope of the present invention.

[0043] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.

[0044] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0045] The present invention is described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0046] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0047] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide for implementing the process Figure 1 one process or multiple processes and / or blocks Figure 1 steps for the functions specified in one block or multiple blocks.

[0048] It should be noted that: The "one embodiment" or "embodiment" mentioned in the specification means that the specific features, structures or characteristics described in connection with the embodiment are included in at least one embodiment of the present invention. Therefore, the phrases "one embodiment" or "embodiment" that appear throughout the specification do not necessarily all refer to the same embodiment.

[0049] In addition, it should be noted that for the specific embodiments described in this specification, the shapes, names of the components, etc. can be different. Any equivalent or simple changes made according to the structure, features and principles described in the inventive concept of the present invention are included in the protection scope of the present invention. Those skilled in the art to which the present invention pertains can make various modifications or supplements to the described specific embodiments or use similar ways to replace them, as long as they do not deviate from the structure of the present invention or exceed the scope defined by this claim, they should fall within the protection scope of the present invention.

Claims

1. An AIGC image watermarking method for generating path deflection based on a diffusion model, characterized in that, The steps are as follows: The server allocates a group of private key vectors for the user; Combining the user's private key with a random salt value to generate initial noise; During the generation process of the diffusion model, embed the watermark signal into the semantic process generated by diffusion; After the diffusion process ends, output the finally generated image with a watermark, and embed the timestamp information during generation into the image metadata for public release; In the verification stage, receive the image to be verified, the user's private key, and the timestamp, reconstruct the corresponding initial noise, and compare it with the reference noise generated based on the private key and the timestamp; Calculate the deviation intensity based on the estimated noise and the reference noise. When the statistic of this deviation is less than the preset threshold, determine that the image is generated by the corresponding private key, thus completing the ownership verification.

2. The AIGC image watermarking method for generating path deflection based on a diffusion model according to claim 1, wherein, For the initial transformation function for the starting point of diffusion model sampling, combined with the private key The salt value generated with the timestamp , construct a standard normal distribution noise through the Box-Muller transformation: ; wherein, is the cumulative distribution function of the standard normal distribution.

3. An AIGC image watermarking method for generating path deflection based on a diffusion model according to claim 2, characterized in that, In the first several steps of the diffusion model, use the user's private key to deflect the diffusion path. Specifically: ; Where the deflection function is: ; Among them, represents the time step; in the diffusion model, represents the noise retention coefficient at the t-th step, and is the cumulative noise retention ratio from the 1st step to the t-th step, which is used to measure the signal retention degree from the initial state to the current step; is the denoising prediction network of the diffusion model at step ; is a deflection function; is a hyperparameter for controlling the deflection intensity.

4. The AIGC image watermarking method for generating path deflection based on a diffusion model according to claim 3, wherein: The deflection process is performed within N steps before diffusion, and the deflection intensity is controlled by , and the product of the deflection function and the image content in constitutes a dynamic perturbation of the sampling path, realizing the deep coupling of the watermark and the image semantics.

5. The AIGC image watermarking method for generating path deflection based on the diffusion model according to claim 3, wherein, In the verification stage, given the image to be verified , the private key and the timestamp , based on the denoising inversion technique, the inverse deflection function is used to recover the noise , and the inverse deflection function is expressed as: ; ; And calculate the initial deviation, expressed as: ; Among them, is the deflection inverse function; the initialization function and the noise after inversion The difference between them constitutes the verification deviation, and the mean square error is used as all verification indicators.

6. The AIGC image watermarking method for generating path deflection based on a diffusion model according to claim 1, wherein Calculate the deviation intensity according to the difference between the estimated noise and the reference noise. If its second moment satisfies: ; Then confirm that the image belongs to the user's private key The corresponding legitimate owner; the threshold Set according to the hypothesis testing framework. Under the conditions of non-watermarked images or key forgery, the probability that the initialization deviation exceeds does not exceed the set significance level .

7. A method for generating an AIGC image watermark with path deflection based on a diffusion model according to claim 1, characterized in that, Verify that the security satisfies the following limit relationship: ; Among them, represents a forged key; represents a legitimate key; represents the inversion-derived initialization deviation; represents the deviation under a legitimate key; Even if the forged key infinitely approaches the legitimate key, the deviation is still greater than the deviation corresponding to the correct key, ensuring the uniqueness of verification.

8. A method for generating path deflection of AIGC image watermark based on diffusion model according to claim 7, characterized in that, The initial deviation has the following analytical form: ; ; ; ; Among them, the deflection coefficient , , when and approach infinitely, it is transformed into: ; Among them, represents the noise retention coefficient at the th step; is ; and respectively represent the error terms at each step under the legal key and the forged key; represents the verification starting point calculated by using the forged key through the initial transformation function ; is ; represents the noisy image obtained by using the legal key at the moment; represents the noisy image obtained by using the forged key at the moment.

9. The AIGC image watermarking method for generating path deflection based on the diffusion model according to claim 8, characterized in that: The deviation is uniquely bound to the user key, ensuring that the diffusion trajectory is generated by a unique key, thus constituting the basis for the non-forgeability of watermark verification.

10. An AIGC image watermarking system for generating path deflection based on a diffusion model, which is applied to an AIGC image watermarking method for generating path deflection based on a diffusion model according to any one of claims 1-9, characterized in that, It includes a key registration module, a watermark image generation module, and an ownership verification module; The key registration module is used to generate and allocate a unique user private key for each user, and this key is used to bind the image generation path during subsequent watermark embedding and verification; The watermark image generation module includes: an initial noise generation unit, which is used to combine the user key with a random salt value based on the generation time, and generate initial noise that follows a standard normal distribution through the Box-Muller transform; a semantic deflection injection unit, which is used to deflect the generation path by key guidance at the initial stage of sampling in the diffusion model; an image output unit, which is used to write the finally generated image and the generation timestamp into the image metadata and then output; The ownership verification module includes: a diffusion inversion unit, which is used to inversely map the input image back to the estimated initial noise through the inverse deflection algorithm of the watermark image generation module; an initial reconstruction unit, which is used to reconstruct the standard initial noise through the key and the timestamp; a deviation calculation and determination unit, which is used to calculate the initial deviation and compare its second moment with the preset threshold. If the deviation is less than the threshold, verify that the image is generated by a legitimate user.

Citation Information

Patent Citations

  • Neural network watermark embedding method and device, electronic equipment and storage medium

    CN114359011A

  • Watermark disturbance-based adversarial sample generation method and device, equipment and medium

    CN115619616A

  • Image invisible watermark embedding detection processing method and device based on diffusion model

    CN117911230A

  • Image copyright protection method based on diffusion model

    CN118152996A

  • Double-copyright protection method based on diffusion model and zero watermark

    CN118735761A

Cited By

  • Deep learning model watermarking method and system based on private key embedding response

    CN122451866A

  • Deep learning model watermarking method and system based on private key embedded response

    CN122451866B