Method and system for localization of trusted watermark embedding and tracing of generative ai output
The domestically developed trusted watermark embedding and traceability system, which utilizes generative AI output, solves the problem that existing watermarking technologies struggle to balance robustness, invisibility, and traceability. It achieves precise adaptation between watermarks and content and reliable traceability, adapts to the diversity of content output by generative AI, and provides a domestically developed, independently controllable, and trusted traceability solution.
Patent Information
- Application Number
- CN202511339652.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-09-19
AI Technical Summary
Existing generative AI watermarking technologies struggle to balance robustness, invisibility, and traceability, and their reliance on foreign technologies results in low levels of domestic production, failing to meet domestic demands for credible traceability of generative AI output content.
This system provides a domestically developed, reliable watermark embedding and traceability system with generative AI output. It establishes a reliable watermark configuration database through an acquisition module, sets watermark embedding targets, performs watermark impact analysis and parameter-oriented embedding, and constructs traceability paths to achieve efficient watermark embedding and reliable traceability.
It achieves precise matching between watermark and content, ensuring that the watermark does not affect the quality during content processing and can accurately trace the source, adapting to the diversity of generative AI output content, and providing a domestic, independent and controllable reliable traceability solution.
Smart Images

Figure CN120832661B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of generative AI watermark technology, in particular to a localization and traceability method and system for generative AI output. BACKGROUND
[0002] With the rapid development of generative AI technology, its application in text creation, image generation, video production, audio synthesis and other fields is becoming more and more widespread, bringing great convenience to production and life. However, the rapid growth of generative AI output content has also brought a series of problems, among which the unclear content ownership, frequent falsification and tampering, and difficult traceability are particularly prominent. In the field of news media, some unscrupulous people use generative AI to produce fake news and fake interview videos. If these contents lack effective traceability means, they can easily spread rapidly on the network, mislead public cognition, and disrupt public opinion order; in the field of digital copyright, creative works such as paintings and scripts generated by generative AI often appear to be randomly used and reproduced without clear original creators, which damages the legal rights and interests of the creators; in the field of government office and enterprise document management, important policy documents and business reports may be spread after being tampered with by generative AI, which not only may leak sensitive information, but also may cause decision-making errors and cause serious losses.
[0003] To solve the above problems, watermark technology is widely used in the traceability and protection of generative AI output content, but the existing watermark technology still has many shortcomings. On the one hand, the existing watermark technology is difficult to balance the robustness, invisibility and traceability association. Some technologies pursue watermark robustness by embedding more watermark information in the content, which enhances the visibility of the watermark, destroys the visual and quality of the original content, and affects the user experience; some technologies excessively focus on invisibility, greatly reduce the watermark strength, so that the watermark is easily lost or damaged when facing common content processing operations (such as image compression, cropping, filtering, text format conversion, paragraph adjustment, etc.), and cannot realize effective traceability. On the other hand, the traceability association ability of the existing watermark technology is weak, most watermarks can only exist as simple identifiers, cannot establish deep association with the original data, generation parameters, and propagation path of the generative AI output content, and it is difficult to accurately locate the generation source and propagation node of the content in the traceability process, resulting in a lack of persuasiveness of the traceability result.
[0004] Currently, most mainstream watermarking technologies and tools rely heavily on foreign research and development, resulting in a low degree of domestic production. These technologies not only suffer from a lack of transparency in their technical principles and the undisclosed nature of their core algorithms, but also risk data theft, tampering, or even watermark malfunction due to foreign technological restrictions or security vulnerabilities. With the increasing urgency for data security and technological self-sufficiency, watermarking solutions relying on foreign technologies cannot meet domestic requirements for credible traceability of generative AI output content. They are also ill-suited to the personalized needs of different industries and scenarios in China, hindering the compliant and secure promotion and application of generative AI technology domestically. Furthermore, existing technologies lack specific designs tailored to the characteristics of generative AI output content. Generative AI content is diverse in type and complex in structure, making it difficult for conventional watermarking technologies to accurately adapt to its features. This leads to low watermark embedding efficiency, unstable traceability success rates, and an inability to form a complete and reliable watermark traceability system. Summary of the Invention
[0005] The purpose of this invention is to provide a domestically developed trusted watermark embedding and traceability system for generative AI output, so as to solve the problems mentioned in the background art.
[0006] To achieve the above objectives, this invention provides a domestically developed trusted watermark embedding and traceability system based on generative AI output, the system comprising:
[0007] The acquisition module is used to acquire the raw content data of the generative AI output and establish a trusted watermark configuration database that maps to the raw content data.
[0008] The watermark target setting module is used to configure watermark embedding targets according to the trusted watermark configuration database. The watermark embedding targets include watermark robustness optimization, watermark invisibility optimization, and watermark source tracing and association optimization.
[0009] The watermark classification identifier module is used to determine the target classification identifier in the watermark embedding target. The target classification identifier includes the main watermark target, the auxiliary watermark target, and the baseline preservation target.
[0010] The watermark impact analysis module is used to perform watermark embedding target impact analysis of key watermark parameters after selecting key watermark parameters using the main watermark target and auxiliary watermark targets.
[0011] The watermark tracing module is used to establish watermark optimization constraints based on the watermark embedding target impact analysis results, then perform watermark parameter directional embedding, and use the watermark parameter directional embedding results to complete the domestically produced reliable watermark embedding of generative AI output.
[0012] The source tracing path construction module is used to generate watermark source tracing paths based on the watermark parameter directional embedding results, and generate source tracing verification results.
[0013] Preferably, the watermark impact analysis module selects key watermark parameters using the main watermark target and auxiliary watermark targets, and then performs watermark embedding target impact analysis on the key watermark parameters, including:
[0014] Obtain the set of adjustable parameters for watermark embedding;
[0015] Quantitative mapping of the influence of adjustable parameter sets on the main watermark target and auxiliary watermark targets;
[0016] Construct a target influence matrix for all watermark targets in the watermark embedding target. The target influence matrix represents the interrelationship between different watermark targets, including positive cooperative relationships and negative conflict relationships.
[0017] Sensitivity coefficients of the adjustable parameter set are calculated based on the quantization mapping of the degree of influence and the target influence matrix.
[0018] The results of the watermark embedding target impact analysis were established based on the sensitivity coefficient calculation results.
[0019] Preferably, the watermark tracing module performs targeted embedding of watermark parameters, including:
[0020] After establishing the control range of the watermark parameters, an initial watermark solution set is created based on the original content data;
[0021] After performing fitness evaluation of the solutions within the initial watermark solution set, the embedding direction and embedding step size are established based on the watermark optimization constraints and fitness evaluation results.
[0022] The initial watermark solution set is iteratively updated using the embedding direction and embedding step size.
[0023] The watermark parameters are embedded in a targeted manner based on the iterative update results.
[0024] Preferably, the watermark tracing module uses the embedding direction and embedding step size to iteratively update the initial watermark unpacking set, including:
[0025] An iterative trajectory is established for each watermark solution, and the iterative trajectory is identified by the fitness value of the solution in each iteration.
[0026] Configure an iterative evaluation interval, identify the update status of the iterative trajectory within the iterative evaluation interval, and generate an evaluation classification, which includes a good solution evaluation classification, an exploration evaluation classification, and a poor solution evaluation classification.
[0027] Search self-optimization management that iteratively updates based on evaluation categories.
[0028] Preferably, the watermark tracing module performs iterative updates and self-optimization management based on evaluation classification, including:
[0029] In the optimal solution evaluation classification configuration, a local proxy model is used to predict the improvement trend and generate the first reference embedding direction.
[0030] In the inferior solution evaluation classification configuration, a penalty optimization identification layer is configured, and the penalty optimization identification layer is used to identify the wrong embedding direction and establish window embedding taboos;
[0031] The watermarked solution within the optimal solution evaluation category is fine-tuned and iteratively updated using the first reference embedding direction and window embedding taboo. The watermarked solution within the inferior solution evaluation category is then iteratively updated using a hybrid exploration evaluation category using the first reference embedding direction and window embedding taboo. A random factor is configured to perform the iterative update of the watermarked solution within the inferior solution evaluation category.
[0032] Preferably, the watermark tracing module performs targeted embedding of watermark parameters, and further includes:
[0033] Establish a security evaluation function for watermark parameters; establish a balance-fit function based on the security evaluation function and the watermark quality evaluation function; select embedding schemes for targeted embedding of watermark parameters based on the balance-fit function, and output the embedding scheme selection results as the targeted embedding results of watermark parameters.
[0034] Preferably, the configuration metrics of the trusted watermark configuration database include watermark robustness metrics, watermark invisibility metrics, and watermark traceability and correlation metrics.
[0035] Preferably, the source tracing path construction module generates a watermark source tracing path based on the watermark parameter directional embedding result, including:
[0036] The watermark feature data in the watermark parameter directional embedding result is parsed; a traceability node sequence is constructed based on the watermark feature data; a traceability chain tree structure is generated based on the traceability node sequence; and the traceability verification result is output using the traceability chain tree structure.
[0037] Preferably, the source tracing path construction module generates a source tracing chain tree structure based on the source tracing node sequence, including:
[0038] Filter key nodes in the traceability node sequence; establish a root node set based on the key nodes; construct a multi-level traceability tree using the root node set; generate traceability verification results through the multi-level traceability tree.
[0039] Preferably, the present invention also includes a domestically produced trusted watermark embedding and traceability method for generative AI output, which includes all modules and method flows of the aforementioned domestically produced trusted watermark embedding and traceability system for generative AI output.
[0040] Compared with the prior art, the beneficial effects of the present invention are:
[0041] This domestically developed, trustworthy watermark embedding and traceability system, based on generative AI output, acquires the original content data output by the generative AI through an acquisition module and establishes a trustworthy watermark configuration database that maps to the original content data. This enables deep binding between the original content data and watermark configuration information, ensuring that each watermark operation accurately corresponds to the characteristics of the original content and avoiding watermark-content mismatch issues caused by data fragmentation. The establishment of this data mapping relationship provides clear original data support for subsequent operations such as watermark target setting and parameter selection, ensuring the adaptability of the watermark embedding process to the original content and avoiding any incongruity or functional conflicts between the embedded watermark and the content.
[0042] The watermark target setting module configures watermark embedding targets based on a trusted watermark configuration database, incorporating watermark robustness optimization, watermark invisibility optimization, and watermark traceability optimization into the target system, breaking the limitations of single-target optimization in existing technologies. In practical application scenarios, different types of generative AI content have different watermark requirements. For example, generated artistic images need to prioritize invisibility to maintain visual aesthetics, while government documents need to focus on strengthening traceability to ensure source verifiability. This module can flexibly set multi-dimensional targets that meet the needs of the scenario based on the original content information in the configuration database, enabling the watermark to simultaneously possess the ability to handle content processing operations, the characteristic of not affecting the content experience, and the function of supporting accurate traceability.
[0043] The watermark classification and identification module identifies the primary watermarking objective, secondary watermarking objectives, and baseline preservation objectives, clarifying the priority of each objective during multi-objective optimization. When potential conflicts exist between different watermarking objectives, the primary objective can be prioritized based on the classification and identification, while secondary objectives are optimized without affecting the primary objective, ensuring that the baseline preservation objective is not compromised. For example, in generative AI video content, if robustness is set as the primary objective, the watermark can be prevented from being lost even during video editing and format conversion; if invisibility is set as a secondary objective, the impact of the watermark on video quality can be minimized while ensuring robustness; and if content integrity is set as the baseline preservation objective, critical video information should not be destroyed to embed the watermark. This classification design makes watermark embedding more targeted, reduces resource waste, and improves watermark performance.
[0044] The watermarking impact analysis module, after selecting key watermarking parameters based on primary and secondary watermarking targets, performs an impact analysis on these parameters' effects on the watermark embedding targets, enabling early prediction of the key parameters' effectiveness. By analyzing the correlation between parameters and various targets, parameters that significantly promote the primary target while having minimal negative impacts on secondary targets can be selected, avoiding substandard watermarking performance caused by blindly selecting parameters. For example, when selecting the key parameter of watermark embedding strength, impact analysis can clarify the degree of influence of this parameter on invisibility while improving robustness, thereby determining a suitable parameter range, reducing the trial-and-error costs of parameter tuning, and improving the efficiency and accuracy of watermark embedding.
[0045] The watermark tracing module establishes watermark optimization constraints based on impact analysis results, performs targeted watermark parameter embedding, and completes the embedding of a domestically developed and reliable watermark. This module relies on domestically developed technology to build the watermark system, eliminating dependence on foreign technologies. From watermark algorithm design to parameter embedding processes, everything is independently controllable, avoiding potential security vulnerabilities or usage limitations of foreign technologies, ensuring the security and reliability of the entire watermark process from embedding to extraction. Simultaneously, the targeted embedding design allows watermark parameters to be precisely embedded in specific locations within the original content, reducing the impact of external interference on the watermark and ensuring its integrity during content dissemination and processing, providing a reliable foundation for subsequent tracing.
[0046] The source tracing path construction module generates source tracing paths based on the targeted embedding results of watermark parameters, obtaining source tracing verification results and forming a complete closed loop from watermark embedding to source tracing verification. The generated source tracing path clearly presents the key nodes from content generation to dissemination, including generation device information, initial dissemination channels, and content processing records, making the source tracing process traceable and verifiable. In cases of disputed content ownership or instances of tampering or forgery, the source tracing path can quickly identify the responsible party, protecting the legitimate rights and interests of content creators and users. Furthermore, the system adapts to the diversity and complexity of generative AI output content, functioning stably in source tracing of different types of content such as text, images, and videos, providing assurance for the compliant application of generative AI technology and promoting the healthy development of the digital content field. Attached Figure Description
[0047] Figure 1 This is a timing diagram of the domestically developed trusted watermark embedding and traceability system for generative AI output described in this invention.
[0048] Figure 2 This is a flowchart of the watermark impact analysis module.
[0049] Figure 3 Workflow diagram for targeted embedding of watermark parameters;
[0050] Figure 4 A flowchart of the workflow for targeted embedding of another watermark parameter. Detailed Implementation
[0051] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0052] Please see Figure 1 This invention provides a domestically developed, trusted watermark embedding and tracing method and system for generative AI output, the system comprising:
[0053] The system acquires raw content data from the generative AI output through an acquisition module and establishes a trusted watermark configuration database mapped to the raw content data. The watermark target setting module configures watermark embedding targets based on the trusted watermark configuration database, including watermark robustness optimization, watermark invisibility optimization, and watermark source tracing association optimization. The watermark classification and identification module determines the target classification identifiers in the watermark embedding targets, including primary watermark targets, auxiliary watermark targets, and baseline preservation targets. The watermark impact analysis module selects key watermark parameters using the primary and auxiliary watermark targets and then performs an impact analysis of the key watermark parameters on the watermark embedding targets. The watermark source tracing module establishes watermark optimization constraints based on the watermark embedding target impact analysis results, performs targeted watermark parameter embedding, and uses the targeted watermark parameter embedding results to complete the embedded domestic trusted watermark of the generative AI output. The source tracing path construction module generates watermark source tracing paths based on the targeted watermark parameter embedding results, generating source tracing verification results. All modules in the system work collaboratively to achieve efficient watermark embedding and reliable source tracing.
[0054] Example 1: See Figure 2 The implementation of the watermark impact analysis module involves a series of rigorous calculations and mapping processes. The core task is to systematically evaluate the impact of selected key watermark parameters on the preset watermark target. This process begins with obtaining a set of adjustable parameters for watermark embedding. This set is not fixed but dynamically generated based on the characteristics of the original content data. For example, when processing AI-generated text, adjustable parameters might include character encoding offsets, the probability of replacing specific words, and the intensity of fine-tuning syntactic structures. For image content, parameters might involve frequency domain transformation coefficients, pixel block perturbation amplitudes, or color channel adjustment thresholds. The completeness of this set directly determines the scope and accuracy of subsequent analysis; therefore, automated methods are needed to extract all possible parameter variables from the trusted watermark configuration database and eliminate obviously invalid or redundant parameters.
[0055] The system quantifies and maps the influence of adjustable parameter sets on the primary and secondary watermark targets. This is a step that transforms abstract goals into concrete numerical relationships. The primary watermark target is typically watermark robustness optimization, requiring the watermark to remain detectable even after content compression, cropping, or format conversion. Secondary watermark targets may include watermark invisibility optimization, requiring the watermark embedding to not affect the visual or auditory quality of the content, and watermark source association optimization, requiring the watermark to effectively carry source information. During quantization, the system establishes influence weights between each parameter and each target. For example, increasing the embedding strength parameter of a text watermark may have a positive, high-weighted impact on the robustness target, but may simultaneously have a negative, medium-weighted impact on the invisibility target. This mapping relationship is determined through a combination of a predefined rule base and a machine learning model. The rule base provides prior knowledge, while the machine learning model continuously adjusts the weight precision based on historical embedding data.
[0056] After completing the quantization mapping, the system constructs a target influence matrix for all watermark targets within the watermark embedding target. This matrix is a mathematical tool used to characterize the intrinsic relationships between different watermark targets. The rows and columns of the matrix represent different watermark targets, and the values of the matrix elements represent the relationships between targets. Positive cooperative relationships are represented by positive elements; for example, robustness optimization and source tracing association optimization may be synergistic, as a stronger watermark often carries more source tracing data. Negative conflict relationships are represented by negative elements; for example, adjusting parameters to improve robustness often reduces invisibility, and there is a trade-off between the two. Constructing this matrix requires integrating domain knowledge and multi-objective optimization theory; the accuracy of the matrix directly affects the reliability of subsequent parameter sensitivity analysis.
[0057] The system calculates the sensitivity coefficients of the adjustable parameter set based on the influence degree quantification mapping and the target influence matrix. The sensitivity coefficient measures the magnitude of the impact of a change in a single parameter on the overall goal achievement. The calculation process involves complex multivariate analysis; the sensitivity coefficient of each parameter is a comprehensive function of its influence weights on each goal, while also considering the interrelationships between goals. For example, a frequency domain coefficient parameter might have a high positive impact on robustness and a moderate negative impact on invisibility. Since robustness and invisibility exhibit a negative conflict in the target influence matrix, the final sensitivity coefficient of this parameter needs to integrate these mutually constraining factors. The calculation typically employs gradient-based methods or analysis of variance, outputting a sensitivity score for each parameter.
[0058] The system establishes watermark embedding target impact analysis results based on sensitivity coefficient calculations. These results are presented in a structured data format, typically including a parameter sensitivity ranking list, a parameter-target correlation graph, and trade-off suggestions for conflicting targets. For example, the analysis might show that the text embedding intensity parameter has the highest sensitivity, followed by the frequency domain transform depth parameter, while the color space offset parameter has lower sensitivity. These results not only identify key watermarking parameters but also reveal potential inter-target conflicts that may arise when adjusting parameters. The entire watermark embedding target impact analysis process, through systematic calculation and mapping, transforms watermark embedding from an experience-driven operation into a data-driven, precise decision-making process.
[0059] Example 2: See Figure 3 In the domestically developed, trustworthy watermark embedding and traceability system based on generative AI output, the process of targeted watermark parameter embedding by the watermark traceability module is a fine-grained operation based on iterative optimization. This process begins with establishing a control range for the watermark parameters. This range defines the legal value range of each adjustable parameter. For example, for image watermarks, the quantization coefficients of the discrete cosine transform may be limited to a specific frequency range, while the character replacement probability of text watermarks is constrained to between zero and one. Setting the control range must ensure the effectiveness of the watermark while preventing excessive modification that could degrade content quality. Based on the original content data, the system creates an initial watermark solution set through random sampling or a heuristic method based on historical best solutions. Each solution represents a complete set of watermark parameter combinations, which collectively determine the watermark embedding method and characteristics.
[0060] After the initial watermark solution set is created, the system performs a solution fitness evaluation. This step comprehensively evaluates each solution using a watermark quality evaluation function, which considers multiple dimensions such as watermark robustness, invisibility, and source attribution. For example, for watermark embedding in video content, the fitness evaluation simulates common video processing operations (such as transcoding and cropping) to detect watermark survival rate, measures watermark concealment through visual quality evaluation metrics, and also verifies the integrity of the source attribution information carried by the watermark. The fitness value of each solution reflects the overall performance of that parameter combination under multiple objectives.
[0061] Based on watermark optimization constraints and fitness evaluation results, the system establishes an embedding direction and an embedding step size. The embedding direction indicates the optimization direction of parameter adjustment, and its determination depends on the estimation of the fitness function gradient or by comparing the performance differences of different solutions. For example, if increasing the value of a certain frequency coefficient is observed to improve robustness while only slightly affecting invisibility, then the embedding direction in that parameter dimension is positive. The embedding step size defines the magnitude of parameter adjustment; a larger step size facilitates rapid exploration of the parameter space, while a smaller step size is beneficial for fine-tuning local parameters. The step size is usually related to the sensitivity of the parameter; highly sensitive parameters use smaller step sizes to achieve precise control.
[0062] By utilizing the embedding direction and embedding step size, the system iteratively updates the initial watermark solution set. This process employs evolutionary computation or gradient optimization, gradually improving the solution quality through multiple iterations. In each iteration, the system establishes a detailed iterative trajectory for each watermark solution, recording the historical changes in parameter values and corresponding fitness values. These trajectories are identified using timestamps and version numbers, forming a complete optimization history archive. By analyzing the iterative trajectories, the system can gain insights into the evolutionary trends and potential problems of each solution.
[0063] The system configures an iterative evaluation interval, which defines the time window or range of iterations for evaluation. Within this interval, the system updates the state of the iterative trajectory and generates three evaluation categories. The "excellent solution" category refers to solutions whose fitness values continuously improve and have reached a high level; these solutions are typically located in the promising region of the parameter space. The "exploratory solution" category includes solutions with fluctuating fitness values but exhibiting innovative characteristics; these solutions may be exploring new parameter combinations. The "inferior solution" category covers solutions with persistently low or significantly degraded fitness values; these solutions are often trapped in local optima or have chosen the wrong parameter adjustment direction.
[0064] Based on the evaluation and classification results, the system implements search self-optimization management. This management mechanism dynamically adjusts the optimization strategy, adopting differentiated update methods for different types of solutions. For solutions in the excellent solution evaluation category, the system adopts a conservative update strategy, continuing to fine-tune along the existing optimization direction with small steps. For solutions in the exploratory evaluation category, the system introduces a certain degree of randomness while maintaining the main optimization direction to balance the relationship between exploration and utilization. For solutions in the inferior solution evaluation category, the system may adopt strategies such as re-initialization or significant adjustments to help them escape their current unfavorable state.
[0065] Throughout the iterative update process, the system maintains a diverse population of solution sets to avoid premature convergence to local optima. After each iteration, the classification state of the solutions is reassessed, and the update strategy is adjusted accordingly. This dynamic and adaptive optimization method effectively addresses the complex trade-offs between multiple competing objectives in watermark embedding. After multiple iterations, when the overall quality of the solution set stabilizes or reaches a preset termination condition, the system outputs the final watermark parameter-oriented embedding result. This result represents the near-optimal parameter combination found under given constraints, achieving an optimal balance between multiple objectives such as watermark robustness, invisibility, and source attribution. The final watermark parameter-oriented embedding result is passed to subsequent modules to perform the actual watermark embedding operation, and the relevant metadata is recorded in the trusted watermark configuration database, providing reference and guidance for future watermark embedding tasks. The entire watermark parameter-oriented embedding process demonstrates the system's ability to finely control watermark embedding quality and optimize multiple objectives, ensuring the effectiveness and reliability of watermark embedding through a systematic iterative update mechanism.
[0066] Example 3: See Figure 4 The watermark tracing module's iterative update of search self-optimization management based on evaluation classification is a multi-layered, adaptive process. In the optimal solution evaluation classification, the system configures a local surrogate model to assist in optimization decisions. The local surrogate model is a simplified mathematical model built based on sampling points within the neighborhood of the current optimal solution; it can simulate the behavioral characteristics of the real fitness function with low computational cost. Using this model, the system performs improvement trend prediction, generating a first reference embedding direction by analyzing gradient information and historical optimization paths in the parameter space. This direction indicates the parameter adjustment vector most likely to achieve performance improvement near the current optimal solution.
[0067] In the inferior solution evaluation and classification, the system employs a penalty optimization identification layer to handle poorly performing solutions. This layer identifies erroneous embedding directions that lead to performance degradation by analyzing the iteration history and behavioral patterns of the solutions. These directions may stem from conflicting parameter configurations or inappropriate step size adjustments. The identification results are used to establish window embedding taboos, a dynamically maintained list of taboos that records parameter adjustment directions proven invalid or harmful in recent iterations, preventing the algorithm from repeatedly exploring known bad regions.
[0068] The system integrates the first reference embedding direction and window embedding taboo information to implement differentiated update strategies for solutions in different categories. For watermarked solutions within the excellent solution evaluation category, the system performs fine-tuning iterative updates, using small step sizes to finely adjust along the reference direction while strictly adhering to taboo constraints to avoid performance degradation. For solutions in the exploratory evaluation category, the system implements hybrid exploratory iterative updates, combining the reference direction with random exploration elements to maintain population diversity while preserving the optimization trend. For watermarked solutions within the inferior solution evaluation category, the system configures a random factor for iterative updates, introducing controllable random perturbations to help solutions escape local optima while utilizing window embedding taboos to avoid repeating the same mistakes.
[0069] The watermark tracing module's targeted embedding of watermark parameters also includes establishing a security evaluation function for the watermark parameters. This function assesses the watermark scheme's ability to resist malicious attacks, considering factors such as resistance to detection, removal, and forgery. The security evaluation function is constructed based on information theory and cryptography principles, quantifying the watermark's survival probability and information preservation level under various attack scenarios. Simultaneously, the system maintains a watermark quality evaluation function to assess the content fidelity and visual / audio quality after watermark embedding.
[0070] Based on the security evaluation function and the watermark quality evaluation function, the system establishes a balanced adaptive function to guide parameter optimization. This function employs a multi-objective optimization framework to coordinate the trade-off between security and quality. One possible expression of the balanced adaptive function is:
[0071]
[0072] in: This represents the watermark parameter vector, which contains all adjustable watermark embedding parameters. This represents the output value of the safety evaluation function, with a value range of [0,1]. The higher the value, the stronger the safety. This represents the output value of the watermark quality evaluation function, with a value range of [0,1]. The higher the value, the better the content quality is maintained. It is a safety weighting coefficient used to adjust the importance of safety relative to quality, and its value is a non-negative real number.
[0073] Based on the equilibrium fitness function, the system performs embedding scheme selection for watermark parameter-oriented embedding. The selection process compares the equilibrium fitness values of different parameter combinations to identify the embedding scheme that achieves the optimal balance between security and quality. The system employs an elitist retention strategy to ensure that the optimal solution in each generation is not replaced by a degraded solution, while maintaining population diversity to prevent premature convergence. The embedding scheme selection result, as the final output of watermark parameter-oriented embedding, represents the optimal watermark configuration scheme achievable under current technological conditions.
[0074] By establishing a dedicated security evaluation system and quality assessment mechanism, and combining it with intelligent optimization algorithms, the system can automatically discover parameter configuration schemes that both ensure watermark security and maximize content quality. This systematic approach provides reliable technical support for the embedding of watermarks in generative AI output, ensuring that the watermark is difficult to remove or forge maliciously, while also not significantly affecting the quality of the original content.
[0075] Example 4: The construction and maintenance of a trusted watermark configuration database is a fundamental step in achieving effective watermark management. This database adopts a layered architecture design, comprising three main parts: a metadata layer, an indicator layer, and a configuration layer. The metadata layer records basic information about the original content, such as content type, generation time, and source identifier; the indicator layer stores the specific values and calculation rules of various watermark evaluation indicators; and the configuration layer stores the parameter settings and strategy selections related to watermark embedding.
[0076] The database configuration metrics mainly fall into three categories: watermark robustness metrics, watermark invisibility metrics, and watermark source association metrics. Watermark robustness metrics measure the watermark's ability to resist external interference, including sub-metrics such as resistance to compression, resistance to cropping, and resistance to noise interference. Each sub-metric has corresponding measurement methods and threshold ranges. For example, resistance to compression is assessed by detecting the watermark survival rate under different compression ratios, while resistance to cropping tests the detectability of the watermark after different degrees of cropping. Watermark invisibility metrics assess the impact of watermark embedding on the quality of the original content, including dimensions such as visual fidelity, auditory quality retention, and text readability. These metrics are quantified through a combination of objective measurement and subjective evaluation. For example, structural similarity index is used to assess the visual impact of image watermarks, and voice quality perception is used to measure the auditory effect of audio watermarks. Watermark source association metrics mainly examine the binding strength and information integrity between the watermark and source information, including elements such as information embedding capacity, error correction capability, and decoding reliability. These metrics ensure that watermarks can effectively carry and protect traceability information, and that key traceability data can still be recovered even after the content has been modified or damaged to a certain extent.
[0077] The indicator data in the database is stored and managed in a structured manner. See Table 1 for a sample of indicator configuration.
[0078] Table 1: Watermark Configuration Indicators.
[0079]
[0080] The database update mechanism employs version control, generating a new version record for each indicator adjustment or parameter modification, facilitating the tracking of configuration change history. The system also establishes an indicator association rule base, recording the interrelationships between different indicators. For example, improving robustness indicators may negatively impact invisibility indicators; these association rules play a crucial constraining role in watermark parameter optimization. The database query interface provides multi-condition combined search functionality, supporting data retrieval by content type, indicator type, time range, and other dimensions. For instance, users can query watermark invisibility indicator data for all image content within the past month, or obtain the historical trend of a specific robustness indicator. These query results provide data support for adjusting and optimizing watermark strategies. The database security mechanism employs a multi-layered protection strategy, including encrypted data storage, access control, and operation log auditing. Sensitive indicator data, such as security keys and encryption parameters, are stored separately with encrypted encryption. Access permissions are finely controlled based on different user roles, and all database operations are logged in detail for auditing purposes.
[0081] The database is integrated with other modules of the system through standardized API interfaces. The watermark target setting module can obtain current indicator configuration information through the interface, the watermark impact analysis module can query the correlation rules between indicators, and the watermark tracing module can use historical data in the database for parameter optimization reference. This highly integrated design makes the database the core data hub of the entire watermarking system.
[0082] Database maintenance includes routine operations such as regular backups, performance optimization, and data cleanup. The backup strategy combines full and incremental backups to ensure data security while improving backup efficiency. Performance optimization primarily focuses on index optimization and query plan tuning for large-volume queries. Data cleanup involves periodically archiving or deleting historical data according to a preset retention policy to maintain database operating efficiency.
[0083] Through this systematic design and management, the trusted watermark configuration database provides comprehensive, accurate, and reliable indicator data support for watermark embedding and traceability, ensuring that the watermarking system maintains stable performance and reliable results in various application scenarios. The database's flexibility and scalability also enable it to adapt to different types of content and watermarking needs, providing a solid data foundation for watermark protection based on generative AI output.
[0084] Example 5: The source tracing path construction module generates a watermark source tracing path based on the watermark parameter-oriented embedding results. This process begins with a deep analysis of the watermark parameter-oriented embedding results to extract watermark feature data. This feature data includes various parameter information generated during the watermark embedding process, such as embedding strength coefficients, frequency domain distribution characteristics, timestamp sequences, content identifiers, and version information. The analysis process employs feature extraction algorithms, using pattern recognition and data mining techniques to identify key data elements with source tracing value from the complex parameter set.
[0085] Based on the extracted watermark feature data, the system constructs a sequence of tracing nodes. Each node represents a significant event or state transition in the watermark's lifecycle, and nodes are interconnected through temporal sequence and logical relationships. Node content includes multi-dimensional information such as event type, occurrence time, operation parameters, and content state. For example, one node might record the specific parameter configuration for the initial watermark embedding, while another node might record the watermark state changes after transcoding. The construction of the node sequence follows strict temporal logic to ensure the continuity and integrity of the tracing path. Based on the tracing node sequence, the system generates a tracing chain tree structure. This tree-like data structure effectively expresses the multi-branch paths of watermark propagation and evolution. The root node of the tree structure represents the initial watermark embedding event, while child nodes represent subsequent operations or derived content. Each node contains rich metadata, recording the operation details and environmental information corresponding to that node. The tree structure is constructed using a bottom-up approach, starting with leaf nodes for identification and gradually building parent-child relationships upwards, ultimately forming a complete tree-shaped tracing path.
[0086] In constructing the traceability chain tree structure, the system filters key nodes in the traceability node sequence. Key node identification is based on a node importance score, which comprehensively considers factors such as the event type, time span, and impact of the operation. For example, the initial watermark embedding node typically has the highest importance score, while nodes involved in significant modification operations also have high importance. The system automatically identifies these key nodes by setting thresholds, ensuring that the tree structure contains necessary details while maintaining structural simplicity.
[0087] Based on the identified key nodes, the system establishes a set of root nodes. This set contains the starting points of all possible tracing paths, with each root node representing the starting point of an independent tracing branch. In multi-version content scenarios, there may be multiple root nodes corresponding to different versions of watermark embedding events.
[0088] Using a set of root nodes, the system constructs a multi-level tracing tree. This tree employs a hierarchical structure, with the first level being the root node and subsequent levels containing its child nodes. Each node contains a reference to its parent node and pointers to its child nodes, forming a bidirectional tree structure. The depth and breadth of the tree are dynamically adjusted according to actual tracing needs, allowing for both the display of the overall tracing context and a deep dive into specific technical details. During construction, the system uses a breadth-first search algorithm to traverse and connect each node, ensuring the integrity and consistency of the tree structure. Through the multi-level tracing tree, the system generates the final tracing verification result. This result is presented in a structured report format, containing key data such as the watermark's source information, propagation path, and modification history. The verification result not only displays the current state of the watermark but also recreates its complete historical evolution, providing comprehensive evidence supporting the watermark's authenticity and integrity. The system also provides multiple output formats, including visual graphs, structured data files, and natural language reports, to meet the query and understanding needs of different users.
[0089] The entire source tracing process demonstrates the system's comprehensiveness and meticulousness in managing the watermark lifecycle. From the initial feature data analysis to the final verification result output, each step emphasizes data accuracy and logical rigor. Through the systematic construction of source tracing paths, the origin and development of watermarks can be effectively tracked, providing a reliable technical means for copyright protection and source verification of generative AI outputs.
[0090] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0091] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A domestically developed trusted watermark embedding and traceability system based on generative AI output, characterized in that, The system includes: The acquisition module is used to acquire the raw content data of the generative AI output and establish a trusted watermark configuration database that maps to the raw content data. The watermark target setting module is used to configure watermark embedding targets according to the trusted watermark configuration database. The watermark embedding targets include watermark robustness optimization, watermark invisibility optimization, and watermark source tracing and association optimization. The watermark classification identifier module is used to determine the target classification identifier in the watermark embedding target. The target classification identifier includes the main watermark target, the auxiliary watermark target, and the baseline preservation target. The watermark impact analysis module is used to perform watermark embedding target impact analysis of key watermark parameters after selecting key watermark parameters using the main watermark target and auxiliary watermark targets. The watermark tracing module is used to establish watermark optimization constraints based on the watermark embedding target impact analysis results, then perform watermark parameter directional embedding, and use the watermark parameter directional embedding results to complete the domestically produced reliable watermark embedding of generative AI output. The source tracing path construction module is used to generate watermark source tracing paths based on the watermark parameter directional embedding results, and generate source tracing verification results. The watermark impact analysis module selects key watermark parameters using the primary watermark target and auxiliary watermark targets, and then performs watermark embedding target impact analysis on the key watermark parameters, including: Obtain the set of adjustable parameters for watermark embedding; Quantitative mapping of the influence of adjustable parameter sets on the main watermark target and auxiliary watermark targets; Construct a target influence matrix for all watermark targets in the watermark embedding target. The target influence matrix represents the interrelationship between different watermark targets, including positive cooperative relationships and negative conflict relationships. Sensitivity coefficients of the adjustable parameter set are calculated based on the quantization mapping of the degree of influence and the target influence matrix. Based on the sensitivity coefficient calculation results, an analysis of the impact of watermark embedding on the target was established. The sensitivity coefficient is an indicator that measures the impact of changes in a single parameter on the overall achievement of the goal. The watermark tracing module performs targeted embedding of watermark parameters, including: After establishing the control range of the watermark parameters, an initial watermark solution set is created based on the original content data; After performing fitness evaluation of the solutions within the initial watermark solution set, the embedding direction and embedding step size are established based on the watermark optimization constraints and fitness evaluation results. The initial watermark solution set is iteratively updated using the embedding direction and embedding step size. The watermark parameters are embedded in a targeted manner based on the iterative update results.
2. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 1, characterized in that, The watermark tracing module uses the embedding direction and embedding step size to iteratively update the initial watermark solution set, including: An iterative trajectory is established for each watermark solution, and the iterative trajectory is identified by the fitness value of the solution in each iteration. Configure an iterative evaluation interval, identify the update status of the iterative trajectory within the iterative evaluation interval, and generate an evaluation classification, which includes a good solution evaluation classification, an exploration evaluation classification, and a poor solution evaluation classification. Search self-optimization management that iteratively updates based on evaluation categories.
3. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 2, characterized in that, The watermark tracing module performs iterative updates and self-optimization management based on evaluation classification, including: In the optimal solution evaluation classification configuration, a local proxy model is used to predict the improvement trend and generate the first reference embedding direction. In the inferior solution evaluation classification configuration, a penalty optimization identification layer is configured, and the penalty optimization identification layer is used to identify the wrong embedding direction and establish window embedding taboos; The watermarked solution within the optimal solution evaluation category is fine-tuned and iteratively updated using the first reference embedding direction and window embedding taboo. The watermarked solution within the inferior solution evaluation category is then iteratively updated using a hybrid exploration evaluation category using the first reference embedding direction and window embedding taboo. A random factor is configured to perform the iterative update of the watermarked solution within the inferior solution evaluation category.
4. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 1, characterized in that, The watermark tracing module performs targeted embedding of watermark parameters and also includes: Establish a security evaluation function for watermark parameters; establish a balance-fit function based on the security evaluation function and the watermark quality evaluation function; select embedding schemes for targeted embedding of watermark parameters based on the balance-fit function, and output the embedding scheme selection results as the targeted embedding results of watermark parameters.
5. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 1, characterized in that, The configuration metrics of the trusted watermark configuration database include watermark robustness metrics, watermark invisibility metrics, and watermark traceability and correlation metrics.
6. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 1, characterized in that, The source tracing path construction module generates a watermark source tracing path based on the watermark parameter directional embedding result, including: The watermark feature data in the watermark parameter directional embedding result is parsed; a traceability node sequence is constructed based on the watermark feature data; a traceability chain tree structure is generated based on the traceability node sequence; and the traceability verification result is output using the traceability chain tree structure.
7. The domestically developed trusted watermark embedding and traceability system for generative AI output as described in claim 6, characterized in that, The source tracing path construction module generates a source tracing chain tree structure based on the source tracing node sequence, including: Filter key nodes in the traceability node sequence; establish a root node set based on the key nodes; construct a multi-level traceability tree using the root node set; generate traceability verification results through the multi-level traceability tree.
8. A domestically developed trusted watermark embedding and traceability method for generative AI output, characterized in that, It includes all modules and method flows of the domestically produced trusted watermark embedding and traceability system for generative AI output as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Adaptive amplitude modulation screening digital watermark optimization method and system
CN119006259A
Watermarking method based on mutual information screening and IGWO optimization
CN119312298A