A watermark attack method based on mapping space conversion angle improvement

By employing non-subsampled shear wave transform based on mapping space transformation and multi-scale geometric analysis, combined with convolutional neural network optimization of the restoration network for low-frequency and high-frequency subbands, the shortcomings of existing watermarking attack methods in terms of visual quality and attack capability are addressed, achieving efficient watermark information interference and restoration quality improvement.

CN120602595BActive Publication Date: 2025-11-28SHANDONG QINGCHENG DIGITAL TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511094520.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-28
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

Existing watermark attack methods struggle to effectively interfere with watermark information extraction while maintaining the visual quality of watermarked images. Furthermore, their simple network structure and insufficient spatial representation capabilities limit the attack capabilities of the models.

Method used

An improved method based on the mapping space transformation angle is adopted. The frequency domain coefficients predicted by the frequency domain coefficients are processed by non-subsampled shear wave transform to decompose the image into low-frequency and high-frequency sub-bands. The mapping space transformation is then performed by combining multi-scale geometric analysis and convolutional neural network to optimize the restoration network of low-frequency and high-frequency sub-bands, thereby realizing the mapping space transformation from frequency domain to spatial domain.

Benefits of technology

It significantly improves the restoration quality of watermarked images, effectively interfering with the extraction of watermark information while maintaining visual quality, thus enhancing the model's attack capability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602595B_ABST
    Figure CN120602595B_ABST
Patent Text Reader

Abstract

The application discloses a watermark attack method based on mapping space conversion angle improvement, and relates to the technical field of digital watermarking, characterized by comprising the following steps: S1: first, carrying out non-subsampled shearlet transform on a watermark-containing image to obtain a low-frequency subband and a plurality of high-frequency subbands; S2: inputting the low-frequency subband and the high-frequency subbands into convolutional neural networks with similar structures respectively to obtain mean square errors; S3: taking the mean square errors as loss functions, and respectively calculating errors between low-frequency and high-frequency subbands of output of low-frequency restoration networks and high-frequency restoration networks and target restored images; and S4: updating and optimizing parameters of the two networks through minimization of the loss functions and back propagation. The application aims to provide a watermark attack method based on mapping space conversion angle improvement, and to design a new attack method which meets the requirements of improving imperceptibility and reducing robustness, and to design and implement a watermark attack model based on mapping space conversion angle improvement.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of digital watermarking, in particular, to a watermark attack method based on mapping space conversion angle improvement. BACKGROUND

[0002] In the field of digital watermarking, the watermark method as the "defender" and the watermark attack method as the "attacker" are two main research directions. They restrict and promote each other, and develop and progress in the process of "offensive and defensive game". At present, the "defender" watermark method develops rapidly, while the development of the "attacker" watermark attack method lags far behind. In addition, the only watermark attack method at present will cause great loss to the visual quality of the watermarked image when interfering with the correct extraction of watermark information, so that the attack is easily detected.

[0003] At present, the research and development of watermark methods (defenders) at home and abroad are very rapid, while the research on watermark attack methods (attackers) has made little progress. Since 2002, few new watermark attack methods have been proposed, and there are only a few reports on watermark attack methods, but they only focus on the reclassification of traditional attack methods. Due to the rapid development of watermark methods, the watermarked image can be extracted with very low bit error rate or even lossless after being attacked, so that the watermark method cannot obtain objective and effective evaluation under the existing watermark attack evaluation system. The "offensive and defensive" balance has been lost, which will undoubtedly affect the healthy development of the field of digital watermarking. In addition, although the only watermark attack method at present will interfere with the correct extraction of watermark information, it will also cause great loss to the visual quality of the watermarked image. In the field of high-precision data requirements such as military, medical and remote sensing, these attack methods have lost their place. Therefore, the design of an attack method that can effectively interfere with the correct extraction of watermark information and maintain the visual quality of the watermarked image is imminent.

[0004] In the era of deep learning, deep neural networks and watermark attacks will undoubtedly collide to create new opportunities. Currently, researchers have made preliminary explorations of watermark attack methods based on deep neural networks. One watermark attack network points out that current watermark attack methods only interfere with watermarked images in isolation, ignoring the specific characteristics of watermark information, and cannot serve as a benchmark for testing the robustness of watermark methods. To this end, a network architecture based on residual dense blocks is proposed to learn the local and global features of watermarked images, and to make various watermark methods ineffective while protecting the quality of watermarked images from interference as much as possible. A robust hybrid watermarking technique can resist adversarial attacks based on convolutional neural networks. This technique uses an attack method based on convolutional neural networks and combines the idea of adversarial. First, it tests the robustness of image watermarking schemes based on discrete wavelet transform, discrete cosine transform, and singular value decomposition using a hybrid of existing attack methods. Then, a new watermark attack method based on a deep convolutional neural network autoencoder is proposed, which can represent the content of a watermarked image through low-dimensional projection in the middle layer of the network. A watermark real-time attack scheme based on a convolutional neural network. It points out that existing attack methods cannot balance the quality of watermarked images and the ability to destroy watermarks well, and proposes a removal attack method using a convolutional neural network. This method mainly attacks blind watermarking schemes with high robustness and does not require host images, and can preprocess watermarked images without any prior knowledge to interfere with watermark extraction; even in the case where the watermarking scheme is unknown, it can still use some common features of watermarked images to destroy the watermark.

[0005] The above shows that it is entirely feasible to construct new watermark attack methods based on deep neural networks, which can maintain the visual quality of watermarked images while interfering with the normal extraction of watermark information. However, according to our investigation, watermark attack techniques based on deep neural networks are still in the early stages of exploration and have not yet formed a mature system. Through in-depth analysis of related research on watermark attacks, the following problems still exist:

[0006] (1) Single optimization goal. Most current watermark attack methods aim to maintain the visual quality of watermarked images, ignoring the optimization of reducing watermark extraction quality, which cannot guarantee to effectively reduce the robustness of watermark methods.

[0007] (2) Simple network structure. Due to the small difference between watermarked images and target recovered images, the above watermark attack methods based on recovery use simple network structures, which cannot fully exploit effective features and limit the attack ability of the model.

[0008] (3) Insufficient spatial representation capability. Most methods perform watermark attacks in the spatial domain, and deep neural networks cannot fully capture important features of watermarked images, which also limits the attack ability of the model. SUMMARY

[0009] The technical problem to be solved by the present application is to provide a watermark attack method based on mapping space conversion angle improvement, aiming to design a new attack method that meets the requirements of improving imperceptibility and reducing robustness, and to design and implement a watermark attack model with improved mapping space conversion angle. Starting from the mapping space, the performance of the imperceptible watermark attack model is improved to maintain the visual quality of the attacked watermark image while destroying the embedded watermark information.

[0010] The technical scheme adopted by the present application to achieve the purpose of the application is as follows:

[0011] A watermark attack method based on mapping space conversion angle improvement, characterized by comprising the following steps:

[0012] S1: first perform non-subsampled shearlet transform on the watermark image to obtain a low-frequency subband and a plurality of high-frequency subbands;

[0013] S2: input the low-frequency subband and the high-frequency subband into a convolutional neural network with similar structure respectively to obtain a mean square error;

[0014] S3: take the mean square error as a loss function, and calculate the error between the low-frequency and high-frequency subbands of the output of the low-frequency and high-frequency restoration networks and the target restored image respectively;

[0015] S4: update and optimize the parameters of the two networks by minimizing the loss function and back propagation.

[0016] As a further limitation of the technical scheme, the non-subsampled shearlet transform is mainly divided into two parts: multi-scale decomposition and multi-direction decomposition. The multi-scale decomposition is realized by a non-subsampled pyramid filter set; and the multi-direction decomposition is realized by a shear filter set.

[0017] As a further limitation of the technical scheme, the frequency domain implementation algorithm process of the discrete shearlet transform is as follows:

[0018] S11: perform Laplace pyramid transform on the watermark image to decompose it into a low-frequency subband and a high-frequency subband ;

[0019] Assume that an N×N size watermark image contains a limited number of pixel values , where , for any image , let L represent the two-dimensional discrete Fourier transform; R represent the integral space, represent the integer set;

[0020] Calculation in the discrete domain , This represents a scale index. This represents the ordinate domain. This represents the horizontal coordinate domain. V Represents a function; at scale The Laplace pyramid algorithm is used above to... Decomposed into a low-frequency subband and high-frequency subband ,in ,and Then we can get:

[0021] (1);

[0022] S12: High-frequency subband Map from Cartesian coordinates to pseudopolar coordinates, and calculate its Fourier transform in pseudopolar coordinates. Generate matrix ;

[0023] To achieve directional localization of the shear wave transform, a pseudo-polar coordinate system is first defined. ,Will and Establish the following mapping relationship:

[0024] (2);

[0025] in: This represents a horizontal area. This represents a vertical region;

[0026] get ,when At that time, there were:

[0027] (3);

[0028] Where: W represents the translation window function; ;

[0029] For any , Represents the set of natural numbers. k Indicates direction index. m Indicates the position index. Z Let represent the set of integers. Therefore, the Fourier transform of the shear wave is represented as follows:

[0030] (4);

[0031] in: is a shear wave local part window function; m represents a position index, and respectively represent a horizontal coordinate and a vertical coordinate of the position index;

[0032] satisfy the following equation:

[0033] (5);

[0034] wherein: ;

[0035] ;

[0036] X represents a discrete shear transform distribution;

[0037] S13: band-pass filtering the matrix ;

[0038] Shear wave local profile window function is respectively shown as follows:

[0039] (6);

[0040] (7);

[0041] wherein: represents a discrete shear wave;

[0042] S14: reflecting the transformed coefficient from the pseudo polar coordinate system to the Cartesian coordinate system, and performing a two-dimensional inverse discrete Fourier transform to obtain a shear wave transform coefficient;

[0043] The calculation formula of the shear wave transform is shown as follows:

[0044] (8).

[0045] As a further limitation of the technical solution, through the two-level non-subsampled shear wave transform, the input watermark image is decomposed into a low-frequency subband and several high-frequency subbands of the same size at different scales; the Lena image two-level non-subsampled shear wave subband diagram obtains four direction high-frequency subbands at the second scale and the third scale respectively.

[0046] Compared with the related art, the watermark attack method based on mapping space conversion angle improvement provided by the application has the following beneficial effects:

[0047] The application converts a spatial pixel prediction problem into a frequency coefficient prediction problem through non-subsampled shearlet transform mapping space conversion. The low-frequency subband prediction network can restore the global topological structure of the watermark-free image, and the high-frequency subband prediction network can restore the high-frequency texture details of the watermark-free image. At the same time, the introduction of non-subsampled shearlet transform mapping space conversion belongs to a plug-and-play module, which is suitable for any convolutional neural network-based restoration model, and can solve the problem of over-smoothed restoration image, thereby significantly improving the restoration quality of the watermark image.

[0048] The application innovatively proposes a mapping space conversion method based on multi-scale geometric analysis. Specifically, by introducing non-subsampled shearlet transform (NSST) with excellent sparse representation capability, efficient mapping space conversion from spatial domain to frequency domain is realized. This conversion mechanism has the following significant advantages: first, it can deeply explore the potential differences between the watermark image and the restored image; second, through accurate regulation of frequency domain features, it can simultaneously meet the two core needs of watermark attack methods, namely, significantly improving imperceptibility and effectively reducing robustness. BRIEF DESCRIPTION OF DRAWINGS

[0049] Figure 1 Figure 1 is a diagram of the two-level non-subsampled shearlet decomposition structure of the application.

[0050] Figure 2 Figure 2 is a non-subsampled shearlet decomposition subband diagram of the watermark image of the application, Figure 2 (a) represents a watermark image, Figure 2 (b) represents a low-frequency subband image, Figure 2 (c) represents four high-frequency subbands in the first scale, Figure 2 (d) represents four high-frequency subbands in the second scale.

[0051] Figure 3 Figure 3 is a watermark image restoration method based on non-subsampled shearlet transform of the application. DETAILED DESCRIPTION

[0052] The application will be further described below in conjunction with the drawings and embodiments.

[0053] The imperceptible watermark method based on watermark image restoration fully utilizes the image restoration technology, takes the original watermark-free image as the optimization target of the watermark attack model, and maps the watermark image back to the watermark-free image to remove the watermark information embedded in the watermark image. For most digital image watermarking methods, the imperceptibility of the watermark is an important evaluation index. There is no significant visual difference between the watermark image obtained by the watermark technology and the original watermark-free image. Therefore, for the imperceptible watermark attack model, taking the original watermark-free image as the optimization target of the watermark image restoration is a simple and effective training method, which has three reasons: (1) The training process does not require prior knowledge, i.e., it does not need to know the specific strategy of watermark embedding and extraction in the watermark method in advance, so it has the advantages of universality and simple optimization process; (2) The trained watermark attack model converts the watermark image into a watermark-free image, removes the content changes in the watermark image due to watermark embedding, and causes the watermark extractor to be unable to effectively extract the watermark information; (3) The attack watermark image output by the trained watermark attack model, the original watermark image and the watermark-free image have high visual similarity, which meets the imperceptible requirement of watermark attack.

[0054] In the image restoration task, most methods based on convolutional neural networks take the to-be-restored image and the target image as the input and output of the network, respectively, and learn the mapping relationship between the images in the spatial domain by the strong learning ability of the convolutional neural network. This spatial domain restoration method is easy to cause the restored image to be too smooth, resulting in the loss of important high-frequency details (such as structured texture details) in the output image. In order to solve this problem, many image restoration methods consider combining multi-scale geometric analysis methods with convolutional neural networks to effectively capture high-frequency details and improve the restoration ability of the model. During the training and optimization of the restoration model, the multi-scale geometric analysis method is used to convert the spatial domain pixels into frequency domain coefficients, and then the convolutional neural network is used to learn the mapping relationship between the frequency domain coefficients of the to-be-restored image and the target image, realizing the mapping space conversion from the spatial domain to the frequency domain in the learning process. This kind of restoration method has the characteristics of universality and belongs to the plug-and-play module. After converting the spatial domain to the frequency domain by the multi-scale geometric analysis method, it can be combined with any convolutional neural network-based model to significantly improve the restoration ability of the model.

[0055] The image restoration method combining multi-scale geometric analysis and convolutional neural network also has some shortcomings. For two-dimensional images, the wavelet transform fits the singularity of "line" through "point", the curvelet transform combines multiple wavelet basis functions to fit the singularity of "surface" through multiple "curves", and the contourlet transform has insufficient directional feature representation ability and reduces the sparse representation ability. These image restoration models combining multi-scale geometric analysis methods realize the conversion of the mapping space through discrete wavelet transform, curvelet transform or contourlet transform, and cannot optimally sparsely represent the high-frequency features in the image frequency domain, thus affecting the performance of the image restoration model to some extent. Therefore, combining the multi-scale geometric analysis method with stronger sparse representation ability with the convolutional neural network is an effective solution to improve the restoration ability of the model.

[0056] A watermark attack method based on improved mapping space conversion angle, comprising the following steps:

[0057] S1: first, perform non-subsampled shearlet transform on the watermark-containing image to obtain a low-frequency subband and a plurality of high-frequency subbands;

[0058] S2: input the low-frequency subband and the high-frequency subbands into convolutional neural networks with similar structures, respectively, to obtain mean square errors;

[0059] S3: taking the mean square errors as loss functions, respectively calculate the errors between the outputs of the low-frequency restoration network and the high-frequency restoration network and the low-frequency and high-frequency subbands of the target restored image;

[0060] S4: update and optimize the parameters of the two networks by minimizing the loss function and back propagation.

[0061] In actual application, the watermark-containing image is input into the trained watermark attack model to output the low-frequency subband and the high-frequency subband after attack, and the watermark-containing image after attack can be obtained by inverse non-subsampled shearlet transform reconstruction using these subbands.

[0062] Compared with other multi-scale geometric analysis methods, the nonsubsampled shearlet transform not only has good multi-directionality and shift invariance, but also realizes better two-dimensional image feature description ability through the shearlet basis function constructed by scale, direction and shift parameters. The nonsubsampled shearlet transform mainly includes multi-scale decomposition and multi-directional decomposition. The multi-scale decomposition is realized by the nonsubsampled pyramid filter set, which ensures the shift invariance and suppresses the pseudo Gibbs phenomenon. The directional localization decomposition is realized by the shear filter set. After the image is decomposed by the k-level nonsubsampled pyramid filter, 1 low-frequency and k high-frequency subband images from fine to coarse are obtained, and each subband image has the same size as the original image. The multi-directional decomposition is realized by the shear filter set. The standard shear filter is mapped from the pseudo polarized network system to the Cartesian coordinate system, so that the downsampling operation is abandoned and the shift invariance is realized.

[0063] The frequency domain implementation algorithm process of the discrete shearlet transform is as follows:

[0064] S11: performing Laplace pyramid transform on the watermarked image to decompose the watermarked image into one low-frequency subband and one high-frequency subband .

[0065] Suppose that an N×N size watermarked image contains a limited number of pixel values , wherein , for any image , let denote the two-dimensional discrete Fourier transform; L denote the space that can be integrated, R denote the integer set;

[0066] In the discrete domain, calculate , denotes the scale index, denotes the longitudinal coordinate domain, denotes the transverse coordinate domain, V denotes the function; in the scale , the Laplace pyramid algorithm is used to decompose into one low-frequency subband and one high-frequency subband , wherein , and , that is, the following equation can be obtained:

[0067] (1);

[0068] S12: mapping the high-frequency subband from the Cartesian coordinate system to the pseudo polar coordinate system, and calculating the Fourier transform of the high-frequency subband in the pseudo polar coordinate system , generating matrix ;

[0069] To realize the direction localization of shear wave transform, first define the pseudo polar coordinate system , and with The mapping relationship is established as follows:

[0070] (2);

[0071] Wherein: Indicates the horizontal region, Indicates the vertical region;

[0072] Get When , there is:

[0073] (3);

[0074] Wherein: W indicates the translation window function; ;

[0075] From the above public can be seen that the use of window function simple translation can obtain different direction of shear wave coefficient;

[0076] For any , Indicates the natural number set, k Indicates the direction index, m Indicates the position index, Z Indicates the integer set, therefore, for the Fourier transform of shear wave is expressed as follows:

[0077] (4);

[0078] Wherein: Is the shear wave local part window function; m Indicates the position index, And Indicate the horizontal and vertical coordinates of the position index respectively;

[0079] Satisfy the following equation:

[0080] (5);

[0081] Wherein: ;

[0082] ;

[0083] X indicates the discrete shear transform distribution;

[0084] S13: performing band-pass filtering on the matrix performing band-pass filtering on the matrix

[0085] Shear wave local partition window function respectively as shown in the following formula:

[0086] (6);

[0087] (7);

[0088] wherein: represents discrete shear wave;

[0089] S14: reflecting the transformed coefficient from the pseudo polar coordinate system to the Cartesian coordinate system, and performing two-dimensional inverse discrete Fourier transform to obtain shear wave transform coefficient;

[0090] The calculation formula of the shear wave transform is as follows:

[0091] (8).

[0092] Through the two-level non-subsampled shear wave transform, the input watermarked image is decomposed into a low-frequency subband and several high-frequency subbands of the same size on different scales; Figure 2 The two-level non-subsampled shear wave subband diagram of the Lena image is given, and four high-frequency subbands in different directions can be obtained on the second scale and the third scale. It can be seen that the low-frequency subband is the approximate subband of the input image, and the high-frequency subbands on each scale capture important high-frequency features of the image in different directions.

[0093] The above only describes the embodiments of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent flow transformation obtained by utilizing the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A watermarking attack method based on mapping space conversion angle improvement, characterized in that, The method comprises the following steps: S1: first, the watermarked image is subjected to non-subsampled shearlet transform to obtain a low-frequency subband and a plurality of high-frequency subbands; S2: the low-frequency subband and the high-frequency subbands are respectively input into convolutional neural networks with similar structures to obtain mean square errors; S3: the mean square errors are taken as loss functions to respectively calculate errors between outputs of low-frequency and high-frequency restoration networks and low-frequency and high-frequency subbands of a target restored image; S4: the low-frequency and high-frequency restoration networks are updated and optimized through minimization of the loss functions and back propagation; The frequency domain implementation algorithm process of the discrete shearlet transform is as follows: S11: performing Laplacian pyramid transform on the watermarked image to decompose it into a low frequency subband and a high frequency subband ; Let us assume that a Q x Q size watermarked image contains a finite number of pixel values where for any image Let denote the two-dimensional discrete Fourier transform; L denote the space of integrals, R denote the set of integers; In the discrete domain, the calculation is , is the scale index, is the ordinate domain, is the abscissa domain, V is the function; in the scale , the Laplacian pyramid algorithm is used to decompose into a low-frequency subband and a high-frequency subband , where , and , so that (1); S12: mapping the high-frequency sub-band mapping from the Cartesian coordinate system to the pseudo-polar coordinate system and calculating the Fourier transform in the pseudo-polar coordinate system generating a matrix ; To realize the direction localization of shear wave transform, first define the pseudo polar coordinate system , and , and establish the following mapping relationship: (2); wherein: represents a horizontal region, represents a vertical region; obtained when there is: (3); wherein: W represents a translation window function; ; For any , denotes a set of natural numbers, k denotes a direction index, m denotes a position index, Z denotes a set of integers, for which the Fourier transform of the shear wave is represented as follows: (4); wherein: is a shear wave local part window function; and denote the horizontal and vertical coordinates of the position index, respectively. satisfies the following equation: (5); wherein: ; ; X represents a discrete shearlet transform distribution; S13: band-pass filtering the matrix ; Shear wave local partitioning window function respectively as follows: (6); (7); wherein: represents a discrete shear wave; S14: the transformed coefficients are reflected from the pseudo-polar coordinate system to the Cartesian coordinate system, and are subjected to two-dimensional inverse discrete Fourier transform to obtain shearlet transform coefficients; The calculation formula of the shearlet transform is as follows: (8)。 2. The watermarking attack method based on mapping space conversion angle improvement according to claim 1, characterized in that: The non-subsampled shearlet transform is mainly divided into two parts of multi-scale decomposition and multi-direction decomposition, the multi-scale decomposition is realized by a non-subsampled pyramid filter set; and the multi-direction decomposition is realized by a shear filter set.

3. The watermarking attack method based on mapping space conversion angle improvement according to claim 2, characterized in that: Through two-stage non-subsampled shearlet transform, the input watermarked image is decomposed into a low-frequency subband and a plurality of high-frequency subbands with the same size at different scales; the Lena image two-stage non-subsampled shearlet subband diagram obtains four high-frequency subbands in four directions at the second scale and the third scale.

Citation Information

Patent Citations

  • An NSST domain robust image watermarking method based on multivariate BKF parameter correction

    CN109727178A

  • Remote sensing image copyright protection method based on double chaotic mapping

    CN117372233A