Watermark embedding method and device, electronic device and storage medium
By embedding low-dimensional watermarks based on high-level semantic features into images and constructing a dual verification mechanism, the problem of insufficient robustness of existing watermarking technologies under malicious attacks is solved, enabling reliable differentiation between AI-generated content and real content and improving the security of image review.
Patent Information
- Application Number
- CN202511052988.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-11-25
AI Technical Summary
Existing watermarking technologies are not robust enough against malicious attacks and have difficulty distinguishing between AI-generated content and real content, resulting in low security for image review.
By extracting high-level semantic features from the image, an adapter network is used to project them into a low-dimensional watermark space to generate a target semantic watermark, which is then embedded into the image. A watermarked image is generated by combining a watermark encoder and a trained watermark decoder for decoding and comparison, thus constructing a dual watermark verification mechanism.
It effectively resists attacks such as watermark removal, forgery, and tampering, ensuring the semantic consistency and security of images and improving the security of image review.
Smart Images

Figure CN121010490A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of watermarking, and in particular to a watermark embedding method and device, an electronic device and a storage medium. BACKGROUND
[0002] With the rapid development of generative artificial intelligence (AI), AI-generated images have approached or even surpassed natural images in visual authenticity, resulting in a significant increase in the difficulty of distinguishing AI-generated content in content review scenarios.
[0003] In related technologies, digital watermarking is usually used to identify generated images; however, in malicious attack scenarios, the robustness of existing watermarking technology is insufficient, making it difficult to reliably distinguish AI-generated content and real content under watermark attacks. For example, an attacker may add perturbations to a watermark-free image to fake a specified watermark (i.e., a fake attack), or insert unrelated or harmful stickers in a watermarked image, while the original watermark signal may still be detected (i.e., a tampering attack). In addition, an attacker may also add perturbations to a watermarked image to remove watermark information (i.e., a removal attack). Therefore, the security of image review based on the above methods is low.
[0004] Currently, there is no effective solution to the problem of low security of image review in related technologies. SUMMARY
[0005] Embodiments of the present application provide a watermark embedding method, device, electronic device and storage medium to at least solve the problem of low security of image review in related technologies.
[0006] In a first aspect, embodiments of the present application provide a watermark embedding method, the method comprising:
[0007] obtaining a to-be-processed image;
[0008] extracting a target semantic feature in the to-be-processed image; inputting the target semantic feature into a trained adapter network, and using the adapter network to project the target semantic feature to a target dimension space to generate a target semantic watermark; the dimension of the target semantic feature is higher than the dimension of the target dimension space;
[0009] inputting the target semantic watermark and the to-be-processed image into a trained watermark encoder for encoding processing to generate a watermarked image; the dimension of the target dimension space matches the input dimension of the watermark encoder.
[0010] In some embodiments, after generating the watermarked image, the method further comprises:
[0011] obtaining a to-be-detected image;
[0012] performing semantic watermark extraction processing on the to-be-detected image to obtain a to-be-tested semantic watermark, and inputting the to-be-detected image into the trained watermark decoder to perform decoding processing to obtain a decoded watermark;
[0013] comparing the to-be-tested semantic watermark and the decoded watermark, and generating a target review result for the to-be-detected image according to a comparison result.
[0014] In some embodiments, the comparing the to-be-tested semantic watermark and the decoded watermark, and generating a target review result for the to-be-detected image according to a comparison result includes:
[0015] comparing consistency of the to-be-tested semantic watermark and the decoded watermark to obtain a bit consistency rate;
[0016] detecting whether the bit consistency rate exceeds a preset consistency rate threshold; if yes, generating a first target review result indicating that the to-be-detected image is an AI watermark image; otherwise, generating a second target review result indicating that the to-be-detected image is not the AI watermark image.
[0017] In some embodiments, the method further includes:
[0018] adding a preset first disturbance noise to the to-be-detected image to generate a noise image set;
[0019] performing semantic watermark extraction processing on each noise image in the noise image set to obtain a corresponding to-be-tested semantic watermark, and performing decoding processing based on the watermark decoder to obtain a decoded watermark;
[0020] comparing the to-be-tested semantic watermark corresponding to each noise image and the decoded watermark to obtain a corresponding noise consistency rate; and determining the bit consistency rate according to a statistical result of a plurality of noise consistency rates.
[0021] In some embodiments, the performing semantic watermark extraction processing on the to-be-detected image to obtain a to-be-tested semantic watermark includes:
[0022] extracting a to-be-tested semantic feature in the to-be-detected image; inputting the to-be-tested semantic feature into the adapter network, and using the adapter network to project the to-be-tested semantic feature to a target dimensional space to generate the to-be-tested semantic watermark.
[0023] In some embodiments, the extracting a target semantic feature in the to-be-detected image includes:
[0024] The image to be processed is input into the trained image encoder for semantic extraction and the target semantic features are output.
[0025] In some embodiments, the training process of the adapter network includes:
[0026] Acquire the original training image and add a preset second perturbation noise to the original training image to generate a noisy training image;
[0027] The original training image and the noisy training image are respectively input into the image encoder for semantic extraction processing to obtain the corresponding original semantic features and noisy semantic features;
[0028] The original semantic features and the noisy semantic features are respectively input into the initial network for feature adaptation and compression, and then projected onto the target dimension space through the last fully connected layer of the initial network to obtain the original compressed features and the noisy compressed features.
[0029] The network parameters of the image encoder are fixed; a loss is constructed based on the difference between the original compression features and the noise compression features, and the initial network is iteratively trained based on the loss to generate the adapter network.
[0030] Secondly, embodiments of this application provide a watermark embedding device, comprising:
[0031] The acquisition module is used to acquire the image to be processed;
[0032] A watermark generation module is used to extract target semantic features from the image to be processed; input the target semantic features into a trained adapter network, and use the adapter network to project the target semantic features into a target dimension space to generate a target semantic watermark; the dimension of the target dimension space is lower than the dimension of the target semantic features.
[0033] The watermark embedding module is used to input the target semantic watermark and the image to be processed into the trained watermark encoder for encoding processing to generate a watermark image; the input dimension of the watermark encoder matches the dimension of the target dimension space.
[0034] Thirdly, embodiments of this application provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the watermark embedding method as described in the first aspect above.
[0035] Fourthly, embodiments of this application provide a storage medium storing a computer program that, when executed by a processor, implements the watermark embedding method as described in the first aspect above.
[0036] Compared to related technologies, the watermark embedding method, apparatus, electronic device, and storage medium provided in this application embodiment acquire an image to be processed; extract target semantic features from the image to be processed; input the target semantic features into a trained adapter network, and use the adapter network to project the target semantic features into a target dimension space to generate a target semantic watermark; the dimension of the target semantic features is higher than the dimension of the target dimension space; input the target semantic watermark and the image to be processed into a trained watermark encoder for encoding processing to generate a watermark image; the dimension of the target dimension space matches the input dimension of the watermark encoder.
[0037] Based on this, when an attacker attempts to tamper with the image content, it will inevitably lead to changes in semantic features, thus causing the watermark verification to fail. This watermarking mechanism, which deeply integrates with image semantics, ensures that any attack attempting to destroy the watermark will result in semantic distortion of the image. This semantic distortion will directly affect the understandability and usability of the image, thus effectively combating three types of attacks: watermark removal, watermark forgery, and watermark tampering. It constructs a triangular protection system of content, watermark, and security, avoiding the phenomenon of easy watermark removal, easy tampering, and insufficient security in traditional review mechanisms, and effectively solving the problem of low security in image review.
[0038] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0039] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0040] Figure 1 This is a hardware structure block diagram of a terminal for a watermark embedding method according to an embodiment of this application;
[0041] Figure 2 This is a flowchart of a watermark embedding method according to an embodiment of this application;
[0042] Figure 3 This is a flowchart of another watermark embedding method according to an embodiment of this application;
[0043] Figure 4 This is a structural block diagram of a watermark embedding device according to an embodiment of this application;
[0044] Figure 5 This is a structural block diagram of another watermark embedding device according to an embodiment of this application. Detailed Implementation
[0045] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application. Furthermore, it is understood that although the efforts made in such a development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, modifications to design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as insufficient disclosure of the content of this application.
[0046] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0047] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” “coupled,” and similar words used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. “Multiple” used in this application means two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. The terms “first,” “second,” “third,” etc., used in this application are merely to distinguish similar objects and do not represent a specific ordering of the objects.
[0048] The method embodiments provided in this example can be executed on a terminal, computer, or similar computing device. Taking running on a terminal as an example, Figure 1 This is a hardware structure block diagram of a terminal for a watermark embedding method according to an embodiment of this application. Figure 1 As shown, a terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. Optionally, the terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the terminal described above. For example, the terminal may also include components that are larger than... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0049] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the watermark embedding method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0050] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.
[0051] As mentioned in the background, existing watermarking technologies are vulnerable to forgery, tampering, and removal attacks, resulting in significant security deficiencies in real-world auditing scenarios. Furthermore, when faced with attacks exceeding the range of minute noise disturbances, traditional watermarking schemes either allow the watermark information to be forged under strong perturbations, leading to the detection of an unwanted watermark, or they fail to detect the watermark's presence even when the image semantics have been severely altered, failing to identify improper content modification. Therefore, there is an urgent need for an image watermarking technology that remains robust even under significant watermark forgery, semantic alteration, and watermark removal attacks.
[0052] Based on this, this embodiment provides a watermark embedding method. Figure 2 This is a flowchart of a watermark embedding method according to an embodiment of this application, such as... Figure 2 As shown, the process includes the following steps:
[0053] Step S210: Obtain the image to be processed.
[0054] The image to be processed can be a natural image (such as a photograph taken by a camera) or an AI-generated image. To ensure compatibility between watermark embedding and detection, the input image must meet the following conditions: Format standardization: the image should be in RGB format, and the resolution is recommended to be no less than 224×224 (to adapt to the input requirements of the pre-trained model). If the image size does not match, it needs to be adjusted by bilinear interpolation or center cropping; Preprocessing: normalize the image (such as mean and standard deviation normalization) to eliminate interference factors such as lighting and contrast; Anomaly detection: filter out damaged or low-quality images (such as completely black / white images) to avoid affecting the accuracy of feature extraction.
[0055] The technical significance of the above steps lies in providing high-quality input data for subsequent semantic feature extraction and watermark embedding. For example, in content moderation scenarios, the system needs to process both natural images and AI-generated images simultaneously, thus requiring assurance of the input module's generalization ability. Furthermore, if the image originates from network transmission, decompression artifact removal may be necessary to retain more high-frequency information for semantic analysis.
[0056] Step S220: Extract target semantic features from the image to be processed; input the target semantic features into the trained adapter network, and use the adapter network to project the target semantic features into the target dimension space to generate a target semantic watermark; the dimension of the target semantic features is higher than the dimension of the target dimension space.
[0057] In this step, high-dimensional semantic features are first extracted from images using visual-language pre-training models such as Distillation with Implicit Neural Optimization (version 2, DINOv2) and Contrastive Language-Image Pre-training (CLIP). Taking DINOv2 as an example, its output feature vector has a dimension of 768 or 1024, containing high-level semantic information of the image (such as object category, scene layout, texture pattern, etc.). These features are obtained through self-supervised learning, are sensitive to semantic changes in image content, but robust to local perturbations (such as slight noise).
[0058] Next, the high-dimensional semantic features (i.e., the target semantic features extracted above) are compressed into a low-dimensional watermark space (i.e., the target dimension space mentioned above) through a trained adapter network; this low-dimensional watermark space is typically 30-dimensional. Specifically, the adapter uses a shallow feedforward neural network, such as a multi-layer perceptron (MLP) layer, with the dimension gradually halved at each layer (e.g., 768→384→192→30). Through a combination of fully connected layers and non-linear activation functions, such as a Gaussian Error Linear Unit (GELU) combined with a hyperbolic tangent (Tanh) function, the features are gradually projected onto the specified low-dimensional target space (e.g., 30-dimensional), ultimately generating a watermark representation that is strongly correlated with the original semantics and has been dimensionally compressed. The feature compression process must meet the following requirements: information preservation, which prevents the loss of semantic information through rectified linear unit (ReLU) activation and residual connections; stability, which ensures that the output is not sensitive to disturbances; and compatibility, which uses the Tanh function in the output layer to limit the values to the range of [-1,1] to adapt to the input requirements of watermark encoders such as StegaStamp.
[0059] Based on the above steps, watermark generation can be deeply bound to image semantics. For example, a semantic watermark generated from an image of a "cat" will contain its key features (such as ear shape and pupil color), while a tampered image will have inconsistent watermarks due to changes in semantic features, thus being identified by the detection system.
[0060] Step S230: Input the target semantic watermark and the image to be processed into the trained watermark encoder for encoding processing to generate a watermark image; the dimension of the target dimension space is matched with the input dimension of the watermark encoder.
[0061] Specifically, the target semantic watermark is embedded invisibly into the original image to generate a watermarked image. The low-dimensional target semantic watermark output by the adapter and the image to be processed are directly input into a pre-trained watermark encoder, such as StegaStamp's Convolutional Neural Network (CNN) encoder.
[0062] During the encoding process, the watermark encoder achieves watermark embedding through a multi-scale feature fusion mechanism. Specifically, the encoder can adopt an encoder-decoder structure similar to a U-Net, progressively extracting multi-level features of the image through downsampling during the encoding stage, while injecting watermark information into skip connections. To ensure the watermark's invisibility, the encoder can also dynamically adjust the watermark embedding strength using an attention mechanism, enhancing the watermark signal in smooth areas of the image and adaptively suppressing it in areas with complex textures. Furthermore, it should be understood that since the watermark encoder receives vectors derived from semantic features rather than random codes, the embedded data remains strongly correlated with the image content.
[0063] It is worth noting that the matching between the target dimensional space and the input dimension of the watermark encoder is crucial. If the watermark dimension exceeds the encoder's processing capacity, it will lead to information truncation or encoder overload; if the dimensions do not match, additional fully connected or convolutional layers are required for dimension adaptation, which may introduce parameter redundancy or destroy the semantic structure of the watermark. Therefore, during the system design phase, the semantic watermark output by the adapter network (such as a 30-dimensional vector) must strictly match the input dimension requirements of the watermark encoder (such as StegaStamp); this dimensional constraint ensures the integrity and coding efficiency of the watermark information during the embedding process. The final watermarked image retains the original visual content and embeds verifiable semantic information, providing a reliable carrier for subsequent applications such as watermark detection and copyright authentication.
[0064] In related technologies, watermarks typically use random codes unrelated to the image content, making them easily forged by attackers through perturbation. However, this application's embodiment, through the aforementioned watermark embedding method, captures high-level semantic features of the image during the feature extraction stage. These features include high-level semantic information such as object categories and spatial relationships, creating a deep semantic binding between the watermark and the image content. Semantic distillation is achieved through dimensional compression via an adapter network, generating a low-dimensional watermark that is more difficult to blindly detect while preserving key semantics. Furthermore, the dimensionality matches the input requirements of the watermark encoder, ensuring that no human intervention is introduced during the encoding process. Therefore, when an attacker attempts to tamper with the image content, it inevitably leads to changes in semantic features, causing watermark verification to fail. This watermark mechanism, deeply integrated with image semantics, ensures that any attack attempting to destroy the watermark will result in semantic distortion of the image. This semantic distortion directly affects the image's understandability and usability, effectively combating three types of attacks: watermark removal, watermark forgery, and watermark tampering. It constructs a triangular protection system of content, watermark, and security, avoiding the problems of easy watermark removal, easy tampering, and insufficient security in traditional review mechanisms, effectively solving the problem of low security in image review.
[0065] In some embodiments, after generating the watermarked image, the watermark embedding method may further include the following steps:
[0066] The process involves: acquiring the image to be detected; extracting the semantic watermark from the image to obtain the semantic watermark to be tested; inputting the image to be detected into the trained watermark decoder for decoding to obtain the decoded watermark; comparing the semantic watermark to be tested and the decoded watermark, and generating the target review result for the image to be detected based on the comparison result.
[0067] The image to be detected can be either an image containing a semantic watermark generated through the above method embodiments, or a natural image without an embedded watermark, or a forged / tampered image.
[0068] Specifically, the semantic watermark extraction process for the image to be detected, to obtain the semantic watermark to be tested, may include the following steps: extracting the semantic features to be tested from the image to be detected; inputting the semantic features to be tested into an adapter network, and using the adapter network to project the semantic features to be tested into the target dimension space to generate the semantic watermark to be tested. More specifically, when extracting the semantic watermark from the image to be detected, firstly, high-dimensional semantic features (e.g., 768-dimensional vectors) of the image are extracted through a pre-trained visual-language model (e.g., DINOv2). These features contain the core semantic information of the image (e.g., object category, scene layout, etc.); then, the high-dimensional features are input into a trained adapter network, which adopts a multilayer perceptron structure (e.g., 3-layer MLP, with dimensions gradually halved: 768→384→192→30). The dimensions are gradually reduced through fully connected layers and the ReLU activation function, and finally a 30-dimensional semantic watermark to be tested is output. The adapter network can also be optimized through noise enhancement training to ensure robustness to image perturbations (e.g., JPEG compression, Gaussian noise).
[0069] Simultaneously, a pre-trained watermark decoder, such as a CNN structure within the Hidden Digital Detection Network (HiDDeN) framework, is used to extract potential embedded watermarks from image pixels. For example, the watermark decoder extracts features through a 7-layer Convolutional-Batch Normalization-Activation (ConvBNReLU) module, and finally outputs a 30-dimensional decoded watermark through global average pooling and fully connected layers. The decoder's training incorporates adversarial examples, such as perturbed images generated by the Fast Gradient Sign Method (FGSM), making it resistant to removal attacks (such as noise overlay format conversion). If the image does not contain a watermark or the watermark is corrupted, the decoder output will appear as random noise or invalid data.
[0070] During the target review result generation stage, the system performs a dimension-by-dimensional numerical comparison between the semantic watermark (30-dimensional vector) output by the adapter network and the decoded watermark (30-dimensional vector) extracted by the watermark decoder. The final review conclusion is output based on preset threshold judgment rules (e.g., Hamming distance < 3 and cosine similarity > 0.85). If the two match within the tolerance range, it is marked as "certified AI-generated content"; if there are significant differences but the decoded watermark is valid, it is judged as "suspected tampering"; if the decoded watermark is invalid or completely deviates from the semantic watermark, it is classified as "uncertified content". This process achieves millisecond-level response through a parallel computing acceleration module, and can also generate an interpretable report containing a confidence score (range 0-1) and the location of the difference dimensions.
[0071] Through the above embodiments, a defense-in-depth system is constructed using dual watermark verification. The semantic watermark extraction channel ensures semantic awareness of content tampering, while the decoding watermark channel provides an independent verification path, forming a cross-verification closed loop. Even if an attacker attempts to disrupt the watermark of a single channel through partial modification, the other channel can still detect the tampering through semantic association or independent decoding. This design effectively resists cut-and-paste attacks, splicing attacks, and protocol analysis attacks that are vulnerable to traditional watermarking systems, significantly improving the security of image content authentication.
[0072] In some embodiments, the comparison of the semantic watermark to be tested and the decoded watermark, and the generation of a target review result for the image to be detected based on the comparison result, may further include the following steps:
[0073] The consistency between the semantic watermark to be tested and the decoded watermark is compared to obtain the bit consistency rate; it is then checked whether the bit consistency rate exceeds the preset consistency rate threshold; if so, a first target review result indicating that the image to be tested is an AI watermarked image is generated; otherwise, a second target review result indicating that the image to be tested is not an AI watermarked image is generated.
[0074] Specifically, in the final review and judgment stage, the matching degree between the semantic watermark to be tested (a 30-dimensional vector generated by the adapter network) and the decoded watermark (a 30-dimensional vector extracted by the watermark decoder) is quantitatively analyzed. The bit consistency rate (such as Hamming distance or bit-by-bit matching ratio) of the two is calculated and compared with a preset consistency rate threshold (such as 90%). If the bit consistency rate exceeds the consistency rate threshold, it indicates that the watermark signal and the semantic features of the image are highly consistent, and the system generates a judgment result that the image to be detected is an AI-generated image with a semantic watermark (i.e., the aforementioned AI watermarked image). If it is lower than the threshold, the image is judged to have failed the watermark verification (it may be a natural image, forged or tampered with). It should also be understood that the consistency rate threshold setting can be based on the statistical analysis of large-scale test data (such as the bit consistency rate distribution of legitimate AI images in the dataset).
[0075] On the other hand, the bit consistency rate (such as Hamming distance) and semantic similarity (such as cosine similarity) between the semantic watermark to be tested and the decoded watermark can also be calculated, and a dual threshold judgment can be set: if the bit consistency rate is >90% and the cosine similarity is >0.85, it is judged as "legitimate AI-generated image"; if the semantic similarity is <0.6 but the decoded watermark is valid, it is indicated that "the content has been tampered with"; if the decoded watermark is noise or does not match the semantic watermark at all (bit consistency rate <30%), it is marked as "forged image".
[0076] The above embodiments achieve semantic binding defense against forgery. Attackers need to simultaneously forge image content and semantic features (such as generating specific objects), which is extremely costly. At the same time, tampering will cause changes in semantic features, and even if the original watermark is retained, it will be exposed due to consistency failure. Therefore, dual verification can also be achieved to identify tampering.
[0077] In some embodiments, the watermark embedding method described above may further include the following steps:
[0078] A preset first disturbance noise is added to the image to be detected to generate a set of noisy images; semantic watermark extraction is performed sequentially from each noisy image in the set to obtain the corresponding semantic watermark to be tested, and decoding is performed based on the watermark decoder to obtain the decoded watermark; the semantic watermark to be tested and the decoded watermark corresponding to each noisy image are compared to obtain the corresponding noise consistency rate; the bit consistency rate is determined based on the statistical results of multiple noise consistency rates.
[0079] Specifically, in the robustness verification stage, N sets of noise samples (e.g., N=5 sets) are first generated from the image to be detected using a preset first perturbation noise (e.g., Gaussian noise σ=0.05), forming a set of noisy images. Then, a dual extraction is performed in parallel on each noisy image in the set: high-dimensional semantic features are extracted using a visual-language model (DINOv2), and the semantic watermark to be tested is generated by dimensionality reduction using a trained adapter network. At the same time, the embedded watermark is decoded from the pixels using a watermark decoder (e.g., the HiDDeN framework). Next, the semantic watermark to be tested and the decoded watermark of each set of noisy images are compared bit-by-bit (e.g., Hamming distance calculation) to obtain N noise consistency rates. Finally, median aggregation is used to eliminate local tampering interference, the comprehensive bit consistency rate is determined, and the image detection judgment result is output based on the comprehensive bit consistency rate.
[0080] Through the above embodiments, by adding multiple sets of preset first perturbation noise to the image to be detected, a set of noisy images is generated, simulating removal attacks that attackers may carry out (such as noise overlay and format conversion), thereby realizing the multi-perturbation noise enhancement and statistical aggregation strategy, which significantly improves the robustness and accuracy of watermark detection under adversarial attacks.
[0081] In some embodiments, the above extraction of target semantic features from the image to be processed may further include the following steps:
[0082] The image to be processed is input into a trained image encoder for semantic extraction, and the target semantic features are output. In the semantic feature extraction stage, the image first undergoes standardization preprocessing (e.g., adjusting the resolution to 224×224 and normalizing the RGB channels), and then is input into a pre-trained image encoder (e.g., DINOv2 based on a vision-language model). This encoder extracts multi-level semantic features of the image through a self-attention network (Transformer) architecture; for example, shallow convolutions capture local textures (e.g., edges, color distribution), and deep attention mechanisms aggregate global semantics (e.g., object categories, scene layout), ultimately outputting a high-dimensional feature vector. This vector not only contains visual content information of the image but also aligns with the language modality through self-supervised learning, enabling it to distinguish the semantic differences between "AI-generated" and "natural images," such as the CLIP feature distribution shift of images generated by the Stable Diffusion model. This provides a robust and interpretable semantic representation for subsequent adapter network dimensionality reduction and watermark generation. Through these steps, leveraging the zero-shot capability of the pre-trained model, the output characteristics of different generation models can be adapted without fine-tuning.
[0083] In some embodiments, the training process of the adapter network includes the following steps:
[0084] The original training image is acquired, and a preset second perturbation noise is added to the original training image to generate a noisy training image. The original training image and the noisy training image are respectively input into the image encoder for semantic extraction processing to obtain the corresponding original semantic features and noisy semantic features. The original semantic features and noisy semantic features are respectively input into the initial network for feature adaptation and compression, and the features are projected to the target dimension space through the last fully connected layer of the initial network to obtain the original compressed features and the noisy compressed features. The network parameters of the image encoder are fixed. A loss is constructed based on the difference between the original compressed features and the noisy compressed features, and the initial network is iteratively trained based on the loss to generate the adapter network.
[0085] Specifically, during the training phase, the original training image is first acquired and a pre-defined second perturbation noise (such as Gaussian noise or JPEG compression artifacts) is added to generate a noisy training image. Then, a pre-trained image encoder (such as DINOv2 50) is used to extract high-dimensional semantic features (such as 768-dimensional vectors) from the original image and the noisy image, respectively. These features contain global semantic information of the image (such as object categories and scene layout). Next, the two types of features are input into the initial adapter network (usually a multi-layer perceptron structure, such as a 768→384→192→30-dimensional fully connected layer). Low-dimensional compressed features (such as 30-dimensional) are generated through progressive dimensionality reduction and ReLU activation function. The last fully connected layer constrains the output range ([-1,1]) through the Tanh function to ensure compatibility with the input dimension of the watermark encoder. During training, the image encoder parameters are fixed, and only the adapter network is optimized. Backpropagation is performed by calculating the loss (minimizing the difference) between the original compressed features and the noisy compressed features, forcing the adapter to still output stable semantic features under noise perturbation, and finally generating a robust adapter network.
[0086] As can be seen from the above embodiments, in order to address the instability of watermarks under different image perturbations, Gaussian noise is added to the input image during the training phase, and the output of the adapter network is guided to be consistent with the original features. Thus, the noise-enhanced training significantly improves the watermark's resistance to adversarial attacks and effectively enhances the stability of the watermark.
[0087] The present application will now be described in detail with reference to specific embodiments. Figure 3 This is a flowchart of another watermark embedding method according to an embodiment of this application, such as... Figure 3 As shown, the process includes the following steps:
[0088] Step S301: Input a clean image (i.e., the image to be processed mentioned above).
[0089] Step S302, semantic feature extraction; semantic features are extracted from the clean image by the image encoder to obtain a high-dimensional semantic vector (i.e., the target semantic features mentioned above).
[0090] Step S303, Feature adaptation compression: The high-dimensional semantic vector is converted into a low-dimensional semantic watermark through an adapter network.
[0091] Step S304, watermark embedding; embed the semantic watermark into the original clean image to generate a watermarked image.
[0092] Step S305, watermark extraction; extract the watermark from the input clean image and re-extract the semantic watermark.
[0093] Step S306, consistency determination: compare whether the extracted watermark is consistent with the semantic watermark.
[0094] Step S307: Output the determination result, determining whether the image is an AI image with a watermark.
[0095] Through the above embodiments, the deep binding of watermarks with image semantic content can effectively enhance robustness against large-scale disturbances, and the above method can be applied to both content review and copyright protection. Furthermore, by combining semantically aware watermarks with adversarial training and random smoothing, the watermark's resistance to forgery attacks, tampering attacks, and removal attacks is comprehensively improved.
[0096] It should be noted that the steps shown in the above process or in the flowchart of the accompanying figures can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0097] This embodiment also provides a watermark embedding device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the terms "module," "unit," "subunit," etc., can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0098] Figure 4 This is a structural block diagram of a watermark embedding device according to an embodiment of this application, such as... Figure 4 As shown, the device includes: an acquisition module 41, a watermark generation module 42, and a watermark embedding module 43; wherein:
[0099] The acquisition module 41 is used to acquire the image to be processed; the watermark generation module 42 is used to extract the target semantic features from the image to be processed; the target semantic features are input into the trained adapter network, and the adapter network is used to project the target semantic features into the target dimension space to generate the target semantic watermark; the dimension of the target dimension space is lower than the dimension of the target semantic features; the watermark embedding module 43 is used to input the target semantic watermark and the image to be processed into the trained watermark encoder for encoding processing to generate the watermark image; the input dimension of the watermark encoder matches the dimension of the target dimension space.
[0100] Figure 5 This is a structural block diagram of another watermark embedding device according to an embodiment of this application, such as... Figure 5 As shown, the device includes Figure 4In addition to all the modules shown, a detection module 51 is also included; the detection module 51 is used to acquire the image to be detected; the detection module 51 is also used to perform semantic watermark extraction processing on the image to be detected, and to input the image to be detected into the trained watermark decoder for decoding processing to obtain the decoded watermark; the detection module 51 is also used to compare the semantic watermark to be detected and the decoded watermark, and to generate the target review result for the image to be detected based on the comparison result.
[0101] In some embodiments, the detection module 51 is further configured to compare the consistency between the semantic watermark to be tested and the decoded watermark to obtain a bit consistency rate; detect whether the bit consistency rate exceeds a preset consistency rate threshold; if so, generate a first target review result indicating that the image to be tested is an AI watermark image; otherwise, generate a second target review result indicating that the image to be tested is not an AI watermark image.
[0102] In some embodiments, the detection module 51 is further configured to add a preset first disturbance noise to the image to be detected to generate a set of noise images; sequentially extract semantic watermarks from each noise image in the set of noise images to obtain the corresponding semantic watermark to be tested, and perform decoding processing based on the watermark decoder to obtain the decoded watermark; compare the semantic watermark to be tested and the decoded watermark corresponding to each noise image to obtain the corresponding noise consistency rate; and determine the bit consistency rate based on the statistical results of multiple noise consistency rates.
[0103] In some embodiments, the detection module 51 is further configured to extract the semantic features to be tested from the image to be detected; input the semantic features to be tested into the adapter network; and use the adapter network to project the semantic features to be tested into the target dimension space to generate the semantic watermark to be tested.
[0104] In some embodiments, the watermark generation module 42 is further configured to input the image to be processed into a trained image encoder for semantic extraction processing and output the target semantic features.
[0105] In some embodiments, the watermark embedding device further includes a training module; the training module is used to acquire the original training image and add a preset second perturbation noise to the original training image to generate a noisy training image; the training module is also used to input the original training image and the noisy training image into the image encoder for semantic extraction processing to obtain the corresponding original semantic features and noisy semantic features; the training module is also used to input the original semantic features and the noisy semantic features into the initial network for feature adaptation compression, and project the features to the target dimension space through the last fully connected layer of the initial network to obtain the original compressed features and the noisy compressed features; the training module is also used to fix the network parameters of the image encoder; construct a loss based on the difference between the original compressed features and the noisy compressed features, and iteratively train the initial network based on the loss to generate an adapter network.
[0106] It should be noted that the above modules can be functional modules or program modules, and can be implemented by software or hardware. For modules implemented by hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination. Specific examples in this embodiment can be found in the examples described in the above embodiments and optional implementations, and will not be repeated in this embodiment.
[0107] This embodiment also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0108] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0109] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0110] S1, Obtain the image to be processed.
[0111] S2, extract the target semantic features from the image to be processed; input the target semantic features into the trained adapter network, and use the adapter network to project the target semantic features into the target dimension space to generate the target semantic watermark; the dimension of the target semantic features is higher than the dimension of the target dimension space.
[0112] S3 inputs the target semantic watermark and the image to be processed into the trained watermark encoder for encoding to generate the watermark image; the dimension of the target dimension space is matched with the input dimension of the watermark encoder.
[0113] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated here.
[0114] Furthermore, in conjunction with the watermark embedding methods in the above embodiments, this application embodiment can provide a storage medium for implementation. This storage medium stores a computer program; when executed by a processor, the computer program implements any of the watermark embedding methods in the above embodiments.
[0115] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0116] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0117] Those skilled in the art should understand that the technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0118] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A watermark embedding method, characterized in that, The method includes: Obtain the image to be processed; Extract target semantic features from the image to be processed; input the target semantic features into a trained adapter network, and use the adapter network to project the target semantic features into a target dimension space to generate a target semantic watermark; the dimension of the target semantic features is higher than the dimension of the target dimension space; The target semantic watermark and the image to be processed are input into the trained watermark encoder for encoding to generate a watermark image; the dimension of the target dimension space is matched with the input dimension of the watermark encoder.
2. The watermark embedding method according to claim 1, characterized in that, After generating the watermarked image, the method further includes: Acquire the image to be detected; The image to be detected is subjected to semantic watermark extraction processing to obtain the semantic watermark to be detected; and the image to be detected is input into the trained watermark decoder for decoding processing to obtain the decoded watermark. The semantic watermark to be tested and the decoded watermark are compared, and a target review result for the image to be tested is generated based on the comparison result.
3. The watermark embedding method according to claim 2, characterized in that, The comparison of the semantic watermark to be tested and the decoded watermark, and the generation of the target review result for the image to be detected based on the comparison result, include: The bit consistency rate is obtained by comparing the consistency between the semantic watermark to be tested and the decoded watermark. The system detects whether the bit consistency rate exceeds a preset consistency rate threshold; if so, it generates a first target review result indicating that the image to be detected is an AI watermarked image; otherwise, it generates a second target review result indicating that the image to be detected is not an AI watermarked image.
4. The watermark embedding method according to claim 3, characterized in that, The method further includes: A preset first disturbance noise is added to the image to be detected to generate a set of noisy images; Semantic watermark extraction is performed sequentially from each noisy image in the noisy image set to obtain the corresponding semantic watermark to be tested, and decoding is performed based on the watermark decoder to obtain the decoded watermark; By comparing the semantic watermark to be tested and the decoded watermark corresponding to each of the noise images, the corresponding noise consistency rate is obtained; based on the statistical results of multiple noise consistency rates, the bit consistency rate is determined.
5. The watermark embedding method according to claim 2, characterized in that, The step of extracting a semantic watermark from the image to be detected to obtain the semantic watermark to be tested includes: Extract the semantic features to be tested from the image to be detected; input the semantic features to be tested into the adapter network, and use the adapter network to project the semantic features to be tested into the target dimension space to generate the semantic watermark to be tested.
6. The watermark embedding method according to any one of claims 1 to 5, characterized in that, The extraction of target semantic features from the image to be processed includes: The image to be processed is input into the trained image encoder for semantic extraction and the target semantic features are output.
7. The watermark embedding method according to claim 6, characterized in that, The training process of the adapter network includes: Acquire the original training image and add a preset second perturbation noise to the original training image to generate a noisy training image; The original training image and the noisy training image are respectively input into the image encoder for semantic extraction processing to obtain the corresponding original semantic features and noisy semantic features; The original semantic features and the noisy semantic features are respectively input into the initial network for feature adaptation and compression, and then projected onto the target dimension space through the last fully connected layer of the initial network to obtain the original compressed features and the noisy compressed features. The network parameters of the image encoder are fixed; a loss is constructed based on the difference between the original compression features and the noise compression features, and the initial network is iteratively trained based on the loss to generate the adapter network.
8. A watermark embedding device, characterized in that, include: The acquisition module is used to acquire the image to be processed; The watermark generation module is used to extract target semantic features from the image to be processed; The target semantic features are input into the trained adapter network, and the adapter network is used to project the target semantic features into the target dimension space to generate a target semantic watermark; the dimension of the target dimension space is lower than the dimension of the target semantic features. The watermark embedding module is used to input the target semantic watermark and the image to be processed into the trained watermark encoder for encoding processing to generate a watermark image; the input dimension of the watermark encoder matches the dimension of the target dimension space.
9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to perform the watermark embedding method according to any one of claims 1 to 7.
10. A storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the watermark embedding method according to any one of claims 1 to 7 when it runs.
Citation Information
Cited By
Watermark generation detection method based on stochastic smoothing testible robust large language model
CN121351045A