Watermark injection and detection method and device, storage medium and electronic equipment

By injecting watermarks into the spectrum of noisy images and generating images using a diffusion model, the robustness problem of watermark detection in image generation models is solved, and effective detection of edited images is achieved.

CN120807258APending Publication Date: 2025-10-17ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510779566.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

It is difficult for existing technologies to effectively inject watermarks into images generated by image generation models and improve the robustness of detection during detection.

Method used

The watermark image is injected into the spectrum of the noise image and the diffusion model is used to generate the image. During detection, the image to be detected is denoised and the watermark image is extracted from the spectrum for comparison and judgment.

Benefits of technology

Even if the image has been edited, the watermark can still be effectively detected, which significantly improves the robustness of watermark detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120807258A_ABST
    Figure CN120807258A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a watermark injection and watermark detection method, which comprises the following steps of: when a watermark is injected, converting a noise image on which an image is generated by a diffusion model into a spectrogram, injecting a first watermark image into the spectrogram, inversely transforming the first watermark image into a second noise image, inputting the second noise image into the diffusion model, and enabling the diffusion model to generate the image. The method comprises the following steps: when detecting whether an image has a watermark or not, firstly adding noise to a to-be-detected image to obtain a to-be-detected noise image, then extracting a first to-be-detected watermark image from a spectrogram of the to-be-detected noise image, and comparing the first to-be-detected watermark image with a preset first watermark image; and judging whether the to-be-detected image is generated by the diffusion model or not according to a comparison result. Through the method, even if the image to be detected is subjected to image editing, the watermark injected into the spectrogram of the noise image to be detected for generating the image to be detected can still be effectively detected during detection, so that the robustness of watermark detection can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a watermark injection and detection method, device, storage medium, and electronic device. Background Art

[0002] With the development of artificial intelligence (AI) technology, image generation services have been widely used in various fields, but this has brought with it issues such as copyright ownership and model abuse.

[0003] To address these issues, service providers need to employ technical means to prove whether an image was generated by their own image generation model. Therefore, injecting a watermark into images generated by the image generation model and then detecting whether the image contains the watermark has become a common method for proving this.

[0004] However, how to effectively inject watermarks into images so as to improve the robustness of watermark detection is an urgent problem to be solved. Summary of the Invention

[0005] The embodiments of this specification provide a watermark injection and detection method, device, storage medium, and electronic device to partially solve the problems existing in the above-mentioned prior art.

[0006] The embodiments of this specification adopt the following technical solutions:

[0007] This specification provides a watermark injection method, the method comprising:

[0008] Acquire a first noise image;

[0009] determining a frequency spectrum corresponding to the first noise image;

[0010] injecting a preset first watermark image into the spectrum graph;

[0011] determining a second noise image corresponding to the frequency spectrum injected into the first watermark image;

[0012] The second noisy image is input into a diffusion model, so that the diffusion model denoises the second noisy image to generate a desired image.

[0013] This specification provides a watermark detection method, the method comprising:

[0014] Obtain the image to be detected;

[0015] Noising the image to be detected using a noise adding method corresponding to a pre-trained diffusion model to obtain a noise image to be detected;

[0016] determine a frequency spectrum corresponding to the to-be-detected noise image;

[0017] extract a first to-be-detected watermark image in the frequency spectrum;

[0018] compare the extracted first to-be-detected watermark image with a preset first watermark image, and determine whether the to-be-detected image is an image generated by the diffusion model according to a comparison result.

[0019] The present specification provides a watermark injection device, the device comprising:

[0020] an acquisition module configured to acquire a first noise image;

[0021] a transformation module configured to determine a frequency spectrum corresponding to the first noise image;

[0022] an injection module configured to inject a preset first watermark image into the frequency spectrum;

[0023] an inverse transformation module configured to determine a second noise image corresponding to the frequency spectrum into which the first watermark image is injected;

[0024] a generation module configured to input the second noise image into a diffusion model, and make the diffusion model denoise the second noise image to generate a required image.

[0025] The present specification provides a watermark detection device, the device comprising:

[0026] an acquisition module configured to acquire a to-be-detected image;

[0027] a restoration module configured to add noise to the to-be-detected image using a noise adding method corresponding to a pre-trained diffusion model to obtain a to-be-detected noise image;

[0028] a transformation module configured to determine a frequency spectrum corresponding to the to-be-detected noise image;

[0029] an extraction module configured to extract a first to-be-detected watermark image in the frequency spectrum;

[0030] a determination module configured to compare the extracted first to-be-detected watermark image with a preset first watermark image, and determine whether the to-be-detected image is an image generated by the diffusion model according to a comparison result.

[0031] The present specification provides a computer readable storage medium, the storage medium storing a computer program, the computer program being executed by a processor to implement the above watermark injection and watermark detection methods.

[0032] The electronic device provided in the specification comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the watermark injection and watermark detection methods described above when executing the program.

[0033] The above at least one technical solution adopted by the embodiments of the specification can achieve the following beneficial effects:

[0034] The embodiments of the specification disclose a watermark injection and watermark detection method. When injecting a watermark, the method converts a noise image based on which a diffusion model generates an image into a frequency spectrum image, injects a first watermark image into the frequency spectrum image, and inversely transforms the frequency spectrum image into which the first watermark image is injected into a second noise image to input the diffusion model to generate an image. Correspondingly, when detecting whether an image is provided with a watermark, the method first adds noise to the image to be detected to obtain a noise image to be detected, then extracts a first watermark image to be detected from a frequency spectrum image of the noise image to be detected, and compares the first watermark image to be detected with a preset first watermark image, and judges whether the image to be detected is generated by the diffusion model according to a comparison result. Through the above method, even if the image to be detected is edited, the watermark injected in the frequency spectrum image of the noise image to be detected used to generate the image to be detected can be effectively detected when detecting, so that the robustness of detecting the watermark can be significantly improved. BRIEF DESCRIPTION OF DRAWINGS

[0035] The accompanying drawings described herein are used to provide further understanding of the specification, constitute a part of the specification, and the illustrative embodiments of the specification and the description thereof are used to explain the specification, and do not constitute an improper limitation on the specification. In the drawings:

[0036] Figure 1 A watermark injection method flowchart provided for the embodiments of the specification;

[0037] Figure 2 A watermark detection method flowchart provided for the embodiments of the specification;

[0038] Figure 3 A watermark injection device schematic diagram provided for the embodiments of the specification;

[0039] Figure 4 A watermark detection device schematic diagram provided for the embodiments of the specification;

[0040] Figure 5 A structure schematic diagram of an electronic device provided for the embodiments of the specification. DETAILED DESCRIPTION

[0041] For the purposes of the present description, the technical solutions and advantages thereof, the technical solutions provided by the embodiments of the present description will be described in detail below in conjunction with the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present description, rather than all the embodiments. Based on the embodiments in the present description, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the scope of protection of the present description.

[0042] The technical solutions provided by the embodiments of the present description will be described in detail below in conjunction with the drawings.

[0043] Figure 1 The watermark injection method flowchart provided by the embodiments of the present description specifically includes the following steps:

[0044] S100: Obtain a first noise image.

[0045] In the embodiments of the present description, the method for generating an image and injecting a watermark as shown in Figure 1 The main body that generates an image and injects a watermark in the method shown in

[0046] Since the server needs to generate a required image using a pre-trained diffusion model subsequently, and the diffusion model needs to repeatedly denoise a noise image to generate a required image when generating the required image, the server first obtains a noise image to be denoised when the diffusion model generates a required image, which is referred to as a first noise image in the present description. The first noise image can be any random noise image, such as a white noise image, a Gaussian noise image, etc.

[0047] S102: Determine a frequency spectrum corresponding to the first noise image.

[0048] After the server obtains the first noise image based on which the diffusion model generates a required image, the server can determine a frequency spectrum corresponding to the first noise image. Specifically, the server can perform Fourier transform, such as fast Fourier transform, on the first noise image to obtain a frequency spectrum corresponding to the first noise image.

[0049] S104: Inject a preset first watermark image into the frequency spectrum.

[0050] In the embodiments of the present description, in order to improve the robustness of subsequent watermark detection, a watermark can be injected in the frequency domain of a noise image. That is, after the server obtains the frequency spectrum of the first noise image through step S102, the server can inject a preset first watermark image into the frequency spectrum.

[0051] Specifically, the server can determine an injection region in the spectrum map, determine a target region in the first watermark image with the same size as the injection region, directly replace elements in the injection region in the spectrum map with elements of the target region in the first watermark image, and use the spectrum map after the replacement as the spectrum map for injecting the first watermark image.

[0052] That is, the server can determine the spectrum map for injecting the first watermark image through the following formula (1).

[0053] Formula (1): <z> _{f}= <z>M + w_f * (1 - M); where:

[0054] z represents a first noise image;

[0055] <z>a first noise image corresponding to a first noise image;

[0056] <z>f represents a frequency spectrum map of the first watermark image injected;

[0057] w_f is the first watermark image, and <z>are of the same size;

[0058] M is a mask matrix, and <z>The size of the first watermark image is the same as that of the first noise image, and the element value of M at the corresponding position in the injection area is 0, and the element value of M at the corresponding position in the non-injection area is 1.

[0059] S106: Determine the second noise image corresponding to the spectrum graph of the first watermark image injected.

[0060] After injecting the first watermark image into the spectrum graph of the first noise image, the server can perform inverse Fourier transform on the spectrum graph injected with the first watermark image to convert the spectrum graph with the first watermark image back to the time-space domain, and obtain the second noise image corresponding to the spectrum graph injected with the first watermark image.

[0061] S108: Input the second noise image into the diffusion model, and make the diffusion model denoise the second noise image to generate the required image.

[0062] After obtaining the second noise image, the server can input the second noise image into the pre-trained diffusion model, and make the diffusion model denoise the second noise image to generate the required image.

[0063] The above method injects the watermark into the frequency domain of the noise image. Even if the user performs image editing such as rotation and translation on the image in the time-space domain, the watermark injected in the frequency domain will not be affected, so that the watermark can still be extracted from the spectrum graph during subsequent watermark detection, improving the robustness of watermark detection.

[0064] Further, in addition to adding a watermark in the frequency domain of the noise image in the specification, a watermark can also be added in the time-space domain of the noise image. Specifically, in the above step S100, the first noise image obtained by the server can be a noise image that has already injected a watermark image in the time-space domain.

[0065] Specifically, the server can first obtain a third noise image, which can be any random noise image, such as a white noise image, a Gaussian noise image, etc. The server first injects a preset second watermark image into the third noise image, and then takes the third noise image injected with the second watermark image as the first noise image, and continues to execute the subsequent steps S102-S108.

[0066] The size of the second watermark image and the size of the third noise image can be the same. The server can inject the second watermark image into the third noise image by taking each element in the third noise image as a processing element, and updating the sign of each processing element according to the value of the element in the second watermark image that has the same position as the processing element. Finally, the third noise image after updating the sign of each processing element is the third noise image in which the second watermark image is injected.

[0067] Specifically, the server can use the following formula (2) to inject the second watermark image into the third noise image.

[0068] Formula (2): Z_s = abs(Z)*(2w-1); where:

[0069] Z represents the third noise image;

[0070] Z_s represents the third noise image in which the second watermark image is injected;

[0071] abs(Z) represents the absolute value of each processing element in the third noise image;

[0072] w is the second watermark image, and the value of each watermark element in w is 0 or 1, i.e., for each processing element in Z, when the value of the watermark element in w that has the same position as the processing element is 0, the absolute value of the processing element remains unchanged, and the sign is negative; when the value of the watermark element in w that has the same position as the processing element is 1, the absolute value of the processing element remains unchanged, and the sign is positive.

[0073] After obtaining the third noise image Z_s in which the second watermark image is injected by using the above formula (2), the third noise image Z_s can be used as the first noise image z in formula (1).

[0074] Further, when injecting the first watermark image into the frequency spectrum of the first noise image, the server can also use the second watermark image injected in the time-space domain to generate the first watermark image injected in the frequency domain. Specifically, the server can generate a Gaussian distribution corresponding to the second watermark image according to the second watermark image, determine a frequency spectrum corresponding to the Gaussian distribution as the first watermark image to be injected in the frequency domain, and inject the frequency spectrum into the frequency spectrum corresponding to the first noise image. Wherein, the server can generate a random Gaussian distribution as the Gaussian distribution corresponding to the second watermark image by taking the second watermark image as a random seed, and after injecting the frequency spectrum corresponding to the Gaussian distribution into the frequency spectrum corresponding to the first noise image, inverse Fourier transform the frequency spectrum injected with the first watermark image to obtain a second noise image in the time-space domain, and then input the second noise image into the pre-trained diffusion model to make the diffusion model repeatedly denoise the second noise image for multiple times to generate the required image.

[0075] After injecting the first watermark image and the second watermark image by the above method, the server can store the first watermark image and the second watermark image, and subsequently detect an unknown image. If the first watermark image and the second watermark image are detected from the unknown image, it means that the unknown image is generated by the diffusion model as described above, as shown in Figure 2

[0076] Figure 2 A watermark detection method flowchart provided by an embodiment of the present specification specifically includes the following steps:

[0077] S200: Obtain an image to be detected.

[0078] In the embodiment of the present specification, the device for performing watermark detection as shown in Figure 2 may also be any electronic device. The electronic device can be the same as or different from the device for performing watermark injection as shown in Figure 1 . The following still takes a server as an example for illustration.

[0079] The server first obtains an image to be detected. The image to be detected is an image of unknown generation source, i.e., it is currently unknown whether the image to be detected is generated by the above diffusion model.

[0080] S202: Use a noise adding method corresponding to the pre-trained diffusion model to add noise to the image to be detected to obtain a noise image to be detected.

[0081] ​If the to-be-detected image is generated by the diffusion model, since the principle of generating an image by the diffusion model is to predict the distribution of the noise added in the input noise image, and then to perform noise sampling and denoising according to the predicted noise distribution by the denoising diffusion implicit model (DDIM) corresponding to the diffusion model, therefore, in the embodiments of the present specification, the server can adopt the DDIM Inversion, i.e., the DDIM inversion method, corresponding to the diffusion model to perform an accurate inverse process (adding noise) on the process (denoising) of generating the to-be-detected image by the diffusion model, so as to restore the to-be-detected image to the noise image input into the diffusion model (hereinafter referred to as the to-be-detected noise image).

[0082] It should be noted that since DDIM depends on the noise distribution defined and predicted by the trained diffusion model, if the to-be-detected image is generated by the diffusion model, then the DDIM corresponding to the diffusion model can certainly restore the process of generating the to-be-detected image by the diffusion model in reverse, restore the repeated denoising process in the image generation process to the repeated noise adding process of the to-be-detected image, and obtain the original noise image input into the diffusion model, i.e., the to-be-detected noise image. If the to-be-detected image is not generated by the diffusion model, then the noise adding process performed by the DDIM corresponding to the diffusion model is certainly not the inverse process of generating the to-be-detected image, and the noise image obtained by adding noise is not the noise image based on which the to-be-detected image is generated.

[0083] S204: Determine the frequency spectrum corresponding to the to-be-detected noise image.

[0084] Similarly to step S104, the server can also perform Fourier transform on the to-be-detected noise image to convert the to-be-detected noise image in the time-space domain to the frequency domain to obtain the corresponding frequency spectrum.

[0085] S206: Extract a first to-be-detected watermark image in the frequency spectrum.

[0086] After obtaining the frequency spectrum corresponding to the to-be-detected noise image, the server can determine Figure 1 The server can directly extract the elements in the injection region of the first watermark image in the frequency spectrum of the to-be-detected noise image as the first to-be-detected watermark image.

[0087] S208: Compare the extracted first to-be-detected watermark image with the preset first watermark image, and determine whether the to-be-detected image is an image generated by the diffusion model according to the comparison result.

[0088] If the to-be-detected image is an image generated by the diffusion model, the DDIM Inversion corresponding to the diffusion model adopted in step S202 can accurately restore the noise image input to the diffusion model when the to-be-detected image is generated, and the frequency domain image of the noise image will also have the first watermark image injected in the method shown in the description of step S202, so the server extracts, through step S206, the elements in the injection area in the same position of the frequency spectrum of the to-be-detected noise image as the frequency spectrum of the first noise image, and takes the extracted first to-be-detected watermark image as the first to-be-detected watermark image. Figure 1 After the first to-be-detected watermark image is determined, the server compares the first to-be-detected watermark image with the first watermark image injected in step S202, to determine the difference between the first to-be-detected watermark image and the first watermark image. Figure 1 Figure 1

[0089] If the difference is less than a preset threshold, it indicates that step S202 accurately restores the noise image input to the diffusion model when the to-be-detected image is generated, and the restored noise image has the first watermark image injected in the method shown in the description of step S202. Figure 1 The first watermark image injected in the frequency domain in the method shown in the description of step S202 can determine that the to-be-detected image is an image generated by the diffusion model.

[0090] If the difference is not less than the preset threshold, it indicates that either step S202 does not accurately restore the noise image input to the diffusion model when the to-be-detected image is generated, or the restored noise image does not have the first watermark image injected in the method shown in the description of step S202. Figure 1 The first watermark image injected in the frequency domain in the method shown in the description of step S202, so that it can be determined that the to-be-detected image is not an image generated by the diffusion model.

[0091] Further, in the process shown in the description of step S202, the server can first inject the second watermark image into the first noise image in the time-space domain, and then inject the first watermark image into the frequency spectrum of the first noise image in the frequency domain, so correspondingly, in the watermark detection process shown in the description of step S206, the server can extract the first to-be-detected watermark image from the frequency spectrum of the to-be-detected noise image in the frequency domain, and also can extract the second to-be-detected watermark image from the to-be-detected noise image in the time-space domain, and compare the extracted second to-be-detected watermark image with the preset second watermark image. Figure 1 Figure 2 Since the server injects the second watermark image in the time-space domain by updating the signs of the first noise image according to the element values of the second watermark image, when the server extracts the second to-be-detected watermark image from the to-be-detected noise image, it can extract the second to-be-detected watermark image according to the signs of each element in the to-be-detected noise image.

[0092] ​​​The server can determine whether the to-be-detected image is generated by the diffusion model according to the first comparison result of the first to-be-detected watermark image and the preset first watermark image and the second comparison result of the second to-be-detected watermark image and the second watermark image.

[0093] Specifically, the first comparison result includes the difference between the first to-be-detected watermark image and the preset first watermark image, and the first comparison result can be represented by the second moment of the element difference at the same position of the first to-be-detected watermark image and the first watermark image, such as r_f = -||[w]_f-w_f||, where r_f is the first comparison result, [w]_f is the first to-be-detected watermark image, and w_f is the preset first watermark image.

[0094] The second comparison result includes the difference between the second to-be-detected watermark image and the second watermark image, and the second comparison result can also be represented by the second moment of the element difference at the same position of the second to-be-detected watermark image and the second watermark image, such as r_s = -||[w]-w||, where r_s is the second comparison result, [w] is the second to-be-detected watermark image, and w is the preset second watermark image.

[0095] After obtaining the two comparison results, the server can directly weight the two comparison results to obtain a comprehensive comparison result, and determine whether the to-be-detected image is generated by the diffusion model according to the comprehensive comparison result.

[0096] To further improve the detection accuracy, the server can also input the two comparison results into a pre-trained evaluation model, fuse the two comparison results through the evaluation model, and determine whether the to-be-detected image is generated by the diffusion model according to the fusion result.

[0097] Specifically, the evaluation model can be a multi-layer perception (MLP), and a plurality of watermark-injected images can be obtained as sample images by the method shown in FIG. 11, and some images without watermark injection can also be added to the sample images. Figure 1 For each sample image, the two comparison results (i.e., the first comparison result and the second comparison result) corresponding to the sample image can be obtained by the method shown in FIG. 12, and then the two comparison results are input into the evaluation model. Figure 2 The evaluation model outputs a judgment result of whether the sample image is generated by the diffusion model, and the difference between the judgment result and the label of the sample image is minimized as a training target, and the model parameters of the evaluation model are adjusted to obtain a trained evaluation model.

[0098] Through the above extraction and detection of the watermark image injected in the frequency domain, the robustness of watermark detection can be effectively improved. Even if the image is edited in the time and space domain, such as rotation and translation, the watermark injected in the frequency domain will not be affected, and the server can still accurately extract the watermark from the frequency domain and detect it.

[0099] The above is a watermark injection and watermark detection method provided by the embodiment of the present specification. Based on the same idea, the present specification also provides corresponding devices, storage media and electronic equipment.

[0100] Figure 3 The watermark injection device provided by the embodiment of the present specification is shown in the schematic diagram, and the device comprises:

[0101] The acquisition module 301 is configured to acquire a first noise image.

[0102] The transformation module 302 is configured to determine a frequency spectrum corresponding to the first noise image.

[0103] The injection module 303 is configured to inject a preset first watermark image into the frequency spectrum.

[0104] The inverse transformation module 304 is configured to determine a second noise image corresponding to the frequency spectrum into which the first watermark image is injected.

[0105] The generation module 305 is configured to input the second noise image into a diffusion model, and make the diffusion model denoise the second noise image to generate a required image.

[0106] Optionally, the acquisition module 301 is specifically configured to acquire a third noise image; inject a preset second watermark image into the third noise image; and take the third noise image into which the second watermark image is injected as the first noise image.

[0107] Optionally, the size of the second watermark image is the same as the size of the third noise image.

[0108] The acquisition module 301 is specifically configured to, for each to-be-processed element in the third noise image, update the sign of the to-be-processed element according to the value of the watermark element in the second watermark image that has the same position as the to-be-processed element; and take the third noise image after updating the sign of each to-be-processed element as the third noise image into which the second watermark image is injected.

[0109] Optionally, the injection module 303 is specifically configured to generate a Gaussian distribution corresponding to the second watermark image according to the second watermark image; determine a frequency spectrum corresponding to the Gaussian distribution as a preset first watermark image; and inject the first watermark image into the frequency spectrum corresponding to the first noise image.

[0110] The above is a watermark injection and watermark detection method provided by the embodiment of the present specification. Based on the same idea, the present specification also provides corresponding devices, storage media and electronic equipment.​​​​​​​​​​​​​​​​​​​​​​​​Optionally, the injection module 303 is specifically configured to generate a random Gaussian distribution as the Gaussian distribution corresponding to the second watermark image, taking the second watermark image as a random seed.

[0111] Optionally, the injection module 303 is specifically configured to determine an injection region in the spectrum graph and determine a target region in the first watermark image with the same size as the injection region; replace elements in the injection region in the spectrum graph with elements in the target region in the first watermark image; and take the spectrum graph after the replacement as the spectrum graph of the first watermark image.

[0112] Optionally, the transformation module 302 is specifically configured to perform Fourier transform on the first noise image to obtain a spectrum graph corresponding to the first noise image.

[0113] The inverse transformation module 304 is specifically configured to perform inverse Fourier transform on the spectrum graph of the first watermark image to obtain a second noise image corresponding to the spectrum graph of the first watermark image.

[0114] Figure 4 The watermark detection device provided by the embodiment of the present specification is shown in the schematic diagram, and the device comprises:

[0115] The acquisition module 401 is configured to acquire a to-be-detected image.

[0116] The restoration module 402 is configured to use a noise adding method corresponding to a pre-trained diffusion model to add noise to the to-be-detected image to obtain a to-be-detected noise image.

[0117] The transformation module 403 is configured to determine a spectrum graph corresponding to the to-be-detected noise image.

[0118] The extraction module 404 is configured to extract a first to-be-detected watermark image in the spectrum graph.

[0119] The judgment module 405 is configured to compare the extracted first to-be-detected watermark image with a preset first watermark image, and judge whether the to-be-detected image is an image generated by the diffusion model according to a comparison result.

[0120] Optionally, the restoration module 402 is specifically configured to use a denoising diffusion implicit model (DDIM) reverse method corresponding to a pre-trained diffusion model to add noise to the to-be-detected image.

[0121] Optionally, the extraction module 404 is specifically configured to determine a preset injection region in the spectrum graph; and extract elements in the injection region in the spectrum graph as a first to-be-detected watermark image.

[0122] Optionally, the extraction module 404 is further configured to extract a second to-be-detected watermark image from the to-be-detected noise image before the determination module 405 determines whether the to-be-detected image is generated by the diffusion model according to the comparison result; and compare the extracted second to-be-detected watermark image with a preset second watermark image.

[0123] The determination module 405 is specifically configured to determine whether the to-be-detected image is generated by the diffusion model according to a first comparison result of the first to-be-detected watermark image and a preset first watermark image, and a second comparison result of the second to-be-detected watermark image and the second watermark image.

[0124] Optionally, the first comparison result includes a difference between the first to-be-detected watermark image and the preset first watermark image.

[0125] The second comparison result includes a difference between the second to-be-detected watermark image and the second watermark image.

[0126] The determination module 405 is specifically configured to input the first comparison result and the second comparison result into a pre-trained evaluation model, and determine whether the to-be-detected image is generated by the diffusion model through the evaluation model.

[0127] The present specification also provides a computer-readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the watermark injection method and the watermark detection method provided above.

[0128] Based on the watermark injection method and the watermark detection method shown above, Figure 1 the present specification provides an electronic device shown in Figure 2 the present specification provides an electronic device shown in Figure 5 the present specification provides an electronic device shown in Figure 5 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course can also include other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs to implement the watermark injection method and the watermark detection method described above.

[0129] The above only describes the embodiments of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present specification shall be included in the scope of claims of the present specification.< / z> < / z> < / z> < / z> < / z> < / z>

Claims

1. A watermark injection method, comprising: Acquire a first noise image; determining a frequency spectrum corresponding to the first noise image; injecting a preset first watermark image into the spectrum graph; determining a second noise image corresponding to the frequency spectrum injected into the first watermark image; The second noisy image is input into a diffusion model, so that the diffusion model denoises the second noisy image to generate a desired image.

2. The method according to claim 1, wherein obtaining the first noise image comprises: acquiring a third noise image; injecting a preset second watermark image into the third noise image; The third noise image injected into the second watermark image is used as the first noise image.

3. The method according to claim 2, wherein the size of the second watermark image is the same as the size of the third noise image; Injecting a preset second watermark image into the third noise image specifically includes: For each element to be processed in the third noise image, updating the sign of the element to be processed according to the value of the watermark element in the second watermark image at the same position as the element to be processed; The third noise image after updating the positive and negative signs of each element to be processed is used as the third noise image injected into the second watermark image.

4. The method according to claim 2, wherein injecting a preset first watermark image into the spectrum graph comprises: generating a Gaussian distribution corresponding to the second watermark image according to the second watermark image; Determine a frequency spectrum corresponding to the Gaussian distribution as a preset first watermark image; The first watermark image is injected into the frequency spectrum corresponding to the first noise image.

5. The method according to claim 4, wherein generating a Gaussian distribution corresponding to the second watermark image according to the second watermark image comprises: The second watermark image is used as a random seed to generate a random Gaussian distribution as the Gaussian distribution corresponding to the second watermark image.

6. The method according to claim 1, wherein injecting a preset first watermark image into the spectrum graph comprises: Determining an injection area in the spectrum diagram, and determining a target area having the same size as the injection area in the first watermark image; Replacing the elements in the injected region of the spectrum graph with the elements in the target region of the first watermark image; The spectrum graph after element replacement is used as the spectrum graph injected into the first watermark image.

7. The method according to claim 1, wherein determining the frequency spectrum corresponding to the first noise image comprises: Performing Fourier transform on the first noise image to obtain a frequency spectrum corresponding to the first noise image; Determining a second noise image corresponding to the frequency spectrum injected into the first watermark image specifically includes: Perform an inverse Fourier transform on the frequency spectrum injected into the first watermark image to obtain a second noise image corresponding to the frequency spectrum injected into the first watermark image.

8. A watermark detection method, the method comprising: Obtain the image to be detected; Noising the image to be detected using a noise adding method corresponding to a pre-trained diffusion model to obtain a noise image to be detected; Determine a frequency spectrum corresponding to the noise image to be detected; Extracting a first watermark image to be detected from the spectrum graph; The extracted first watermark image to be detected is compared with a preset first watermark image, and it is determined whether the image to be detected is an image generated by the diffusion model according to the comparison result.

9. The method according to claim 8, further comprising: adding noise to the image to be detected using a noise adding method corresponding to a pre-trained diffusion model; The image to be detected is denoised using a denoising diffusion implicit model (DDIM) inversion method corresponding to a pre-trained diffusion model.

10. The method according to claim 8, wherein extracting the first watermark image to be detected from the spectrum graph comprises: Determining a preset injection area in the spectrum graph; The elements in the injected area of ​​the spectrum are extracted as the first watermark image to be detected.

11. The method according to claim 8, before determining whether the image to be detected is an image generated by the diffusion model based on the comparison result, the method further comprises: Extracting a second watermark image to be detected from the noise image to be detected; comparing the extracted second watermark image to be detected with a preset second watermark image; Determining whether the image to be detected is an image generated by the diffusion model according to the comparison result specifically includes: According to a first comparison result between the first watermark image to be detected and a preset first watermark image, and a second comparison result between the second watermark image to be detected and the second watermark image, it is determined whether the image to be detected is an image generated by the diffusion model.

12. The method according to claim 11, wherein the first comparison result comprises a difference between the first watermark image to be detected and a preset first watermark image; The second comparison result includes a difference between the second watermark image to be detected and the second watermark image; Determining whether the image to be detected is an image generated by the diffusion model according to a first comparison result between the first watermark image to be detected and a preset first watermark image, and a second comparison result between the second watermark image to be detected and the second watermark image, specifically includes: The first comparison result and the second comparison result are input into a pre-trained evaluation model, and the evaluation model is used to determine whether the image to be detected is an image generated by the diffusion model.

13. A watermark injection device, comprising: An acquisition module, configured to acquire a first noise image; a transform module, configured to determine a frequency spectrum corresponding to the first noise image; An injection module, configured to inject a preset first watermark image into the spectrum graph; an inverse transformation module, configured to determine a second noise image corresponding to the frequency spectrum injected into the first watermark image; The generating module is configured to input the second noise image into a diffusion model, so that the diffusion model denoises the second noise image to generate a desired image.

14. A watermark detection device, comprising: An acquisition module, used for acquiring an image to be detected; A restoration module, configured to add noise to the image to be detected using a noise adding method corresponding to a pre-trained diffusion model to obtain a noise image to be detected; A transformation module, configured to determine a frequency spectrum corresponding to the noise image to be detected; An extraction module, configured to extract a first watermark image to be detected from the spectrum graph; The judgment module is used to compare the extracted first watermark image to be detected with a preset first watermark image, and judge whether the image to be detected is an image generated by the diffusion model according to the comparison result.

15. A computer-readable storage medium storing a computer program, wherein the computer program implements the method according to any one of claims 1 to 12 when executed by a processor.

16. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 12 when executing the program.