Lightweight non-repudiation model fingerprint efficient tracing method

CN122024026BActive Publication Date: 2026-09-25GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610104283.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-26
Publication Date
2026-09-25
Estimated Expiration
2046-01-26

AI Technical Summary

Technical Problem

但现有的主动可持续检测方法仍存在着不足,一方面是其通信复杂度较高,另一方面是现有方法对模型指纹不可伪造性设计不够完善,难以有效抵御恶意篡改、伪造攻击,使得溯源结果的可靠性与权威性难以得到保障,无法充分满足实际应用中对生成式数据溯源的严格需求

Benefits of technology

[0049]所述存储器中存储有计算机程序,当所述计算机程序被所述处理器执行时,能够实现如前述所述的一种轻量级不可否认模型指纹高效溯源方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122024026B_ABST
    Figure CN122024026B_ABST
Patent Text Reader

Abstract

The application discloses a kind of lightweight undeniable model fingerprint efficient tracing method, belong to cryptography application, digital content tracing and other related technical fields.The specific steps include: inputting original image data set to computer system;Train learning lightweight encoder and decoder, encoder maps binary fingerprint and image to generate residual;Residual constraint is generated by Sigmoid function to generate fingerprint image, and the model is optimized by double loss;Generate PIT parameter binding salt value, commitment value metadata, and embed fingerprint in image;When detecting, load decoder to extract decoded fingerprint and binary through threshold function, realize double check by fingerprint polynomial comparison and commitment value verification.The application converts the fingerprint verification mode into polynomial verification by polynomial equivalence detection technology, reduces the communication complexity to sub-linear overhead, realizes lightweight efficient verification, and is suitable for efficient tracing and authenticity verification of deep fake images.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical fields of cryptography applications and digital content tracing, specifically involving a lightweight, non-repudiable model fingerprinting method for efficient tracing. Background Technology

[0002] With the rapid evolution of artificial intelligence technology, the continuous iteration of deep generative models, especially Generative Adversarial Networks (GANs), has provided core technical support for the maturity and widespread application of generative image technology. This technology can generate realistic image content, which has great application value in film and television production, virtual interaction, and other fields. However, the application of this technology has also given rise to the problem of deepfake detection. Fake image content has infiltrated every corner of real-world scenarios such as social media and news dissemination, raising strong concerns about the controllability of generative data and stimulating research on deepfake detection and tracing.

[0003] Currently, among methods for detecting and tracing deepfakes, proactive and sustainable detection methods have become the mainstream solution due to their advantages of early prevention and end-to-end tracking. However, existing proactive and sustainable detection methods still have shortcomings. On the one hand, their communication complexity is high; on the other hand, the existing methods do not have a perfect design for the unforgeability of model fingerprints, making it difficult to effectively resist malicious tampering and forgery attacks. This makes it difficult to guarantee the reliability and authority of the tracing results, and cannot fully meet the strict requirements for generative data tracing in practical applications.

[0004] In summary, there is an urgent need for an efficient, reliable, and practical deepfake tracing method that, while inheriting the core advantages of proactive and sustainable detection methods, effectively reduces communication complexity and strengthens the unforgeability of model fingerprints, thus providing a new solution for deepfake tracing. Summary of the Invention

[0005] The main objective of this invention is to provide a lightweight, non-repudiable model fingerprinting method for efficient source tracing. This method aims to transform fingerprint verification into multinomial verification through multinomial equivalence detection, reducing communication complexity to sublinear overhead and achieving lightweight, efficient verification. Furthermore, it utilizes encoder-decoder collaborative training and dual verification of PIT parameters and commitment values ​​to further reduce communication complexity, enhance fingerprint non-forgeability, and improve the efficiency and reliability of deepfake book source tracing.

[0006] Based on the first main aspect of the present invention, a lightweight, non-repudiable model fingerprinting efficient source tracing method is provided, comprising the following steps:

[0007] Input the raw image dataset into the computer system; the raw image dataset includes the number of image channels, image height, and image width;

[0008] Binary fingerprints are sampled for each batch, and an encoder and corresponding decoder are trained based on the original image dataset. The encoder maps the binary fingerprints to the original image dataset to obtain residuals.

[0009] The residuals are constrained within an interval using the Haas-Sigmoid function to generate a fingerprint image. The decoder then extracts the fingerprints from this fingerprint image and calculates the binary cross-entropy loss. loss;

[0010] Load the encoder, weights, and parameters. If the batch of images are uniformly labeled, a fixed fingerprint is generated. Otherwise, the fingerprint is randomly sampled, PIT parameters are generated, the fingerprint is embedded into the image, and metadata is generated.

[0011] By binding the fingerprint with a salt value, the fingerprint is prevented from being tampered with, and the metadata is saved;

[0012] Load the decoder, input the image to be detected and the metadata, extract the decoded fingerprint and obtain the binary fingerprint through a threshold function;

[0013] The polynomial of the original fingerprint is compared with that of the binary fingerprint to verify the commitment value matching, determine whether the embedded fingerprint has been tampered with, and output the matching result and the tampering detection result.

[0014] Through the above technical solutions, this invention constructs a complete closed-loop technical process from training, embedding, detection, and verification. It reduces communication complexity based on lightweight model design and strengthens the unforgeability and tamper resistance of fingerprints by relying on dual verification mechanisms. It achieves efficient source tracing of fingerprint stealth embedding and deepfake images, balancing source tracing accuracy, image concealment, and execution efficiency.

[0015] As a further preferred embodiment, in the aforementioned method, the binary fingerprint specifically includes generation based on each image in the original image dataset;

[0016] The training and learning encoder and the corresponding encoder specifically include: through successive rounds of training, at the beginning of each round, shuffling the dataset to prevent model overfitting, and dividing the dataset into mini-batches for training.

[0017] The uniqueness of the traceability identifier is enhanced by using a unique binary fingerprint for each image. The small-batch training mode is adapted to the computing power of the computer system, breaking the original arrangement pattern of the data and avoiding the model from overlearning local features in the data during the training process, thereby preventing overfitting.

[0018] As a further preferred embodiment, in the aforementioned method, the Haas sigmoid function is:

[0019]

[0020] in, Let R represent the Haus number Sigmoid function, R represent the residual, and e represent the natural constant.

[0021] The interval range is Inside;

[0022] The binary cross-entropy loss is obtained by calculating the binary cross-entropy loss function. The loss constraint is based on the similarity between the fingerprint image and the original image, through... The loss function is obtained.

[0023] As a further preferred embodiment, in the aforementioned method, the binary cross-entropy loss function is:

[0024]

[0025] in, The loss function is binary cross-entropy, where j represents the sample index within the batch, and B represents the batch size. Represents fingerprints;

[0026] The The loss function is:

[0027]

[0028] in, express The loss function, where B represents the batch size and j represents the sample index within the batch. This indicates an image containing fingerprints.

[0029] The probability error of fingerprint extraction is precisely optimized by using binary cross-entropy loss, enabling the decoder to efficiently restore the original fingerprint. L2 loss strictly controls the distortion of the image and ensures the visual consistency of the fingerprint image.

[0030] Based on heavy loss collaborative optimization, not only is the accuracy of fingerprint embedding and extraction improved, but the practicality of the image is also ensured, providing technical support for the efficiency and reliability of the source tracing method.

[0031] As a further preferred embodiment, in the aforementioned method, the fingerprint embedding image includes the following steps:

[0032] The fingerprint is embedded into the image through residual calculation, and the pixel values ​​of the fingerprint-containing image are ensured to be within the range through Sigmoid activation and cropping.

[0033] The PIT parameters include prime numbers, random numbers, and fingerprint polynomial verification values.

[0034] The metadata includes the PIT parameters, the salt value, and the corresponding fingerprint commitment; the salt value is obtained by sampling each fingerprint.

[0035] The fingerprint commitment is calculated based on the corresponding salt value.

[0036] Specifically, invisible fingerprint embedding is achieved through residual computation embedding combined with sigmoid activation and pruning, avoiding image distortion. PIT parameters provide a standardized basis for subsequent fingerprint matching, the binding of salt value and fingerprint commitment forms an anti-tampering barrier, and the preservation of metadata provides complete and effective verification resources for the detection stage.

[0037] As a further preferred embodiment, in the aforementioned method, the threshold function is:

[0038]

[0039] The specific calculation logic of the threshold function is as follows: if the binary fingerprint... If the threshold function is 1, then the result of the binary fingerprint is 1. If the threshold function is applied, the result will be 0.

[0040] By employing threshold function binarization to unify the fingerprint format, the extracted fingerprint remains consistent with the original binary fingerprint, providing standardized input for subsequent fingerprint polynomial alignment and commitment value verification.

[0041] This avoids comparison errors caused by differences in fingerprint formats, improves the computational efficiency and verification accuracy of the detection stage, and ensures the coherence and consistency of the traceability logic.

[0042] As a further preferred embodiment, in the aforementioned method, the comparison of whether the polynomials of the original fingerprint and the binary fingerprint are consistent, and the verification of the commitment value matching specifically include a first verification and a second verification.

[0043] The first layer of verification specifically includes: comparing the polynomial of the original fingerprint with that of the binary fingerprint; if they are equal, the fingerprint is determined to match; if they are not equal, the fingerprint is determined to not match, and the second layer of verification is activated.

[0044] As a further preferred embodiment, in the aforementioned method, the second verification includes: when the first verification determines that the fingerprint does not match, opening the commitment for verification, calculating the reconstructed commitment, and based on the binary fingerprint and the salt value, reconstructing the commitment value through the commitment function and integrating them to form a set of commitment values ​​to be verified;

[0045] The fingerprint commitment in the metadata of the set of commitment values ​​to be verified is checked for consistency. If they are consistent, the embedded fingerprint has not been tampered with after embedding; if they are inconsistent, the embedded fingerprint has been tampered with.

[0046] By constructing a dual verification logic, the first layer of polynomial comparison quickly completes the fingerprint matching determination, improving the efficiency of traceability, while the second layer of commitment value verification accurately identifies tampering behavior in mismatch scenarios, strengthening the authority of traceability.

[0047] The dual verification logic ensures efficient traceability under normal conditions and can also cope with malicious tampering, thus improving the reliability and comprehensiveness of the traceability results.

[0048] According to a second key aspect of the present invention, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the processor;

[0049] The memory stores a computer program, which, when executed by the processor, enables a lightweight, non-repudiable model fingerprinting method for efficient tracing, as described above.

[0050] Based on a third key aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements a lightweight, non-repudiable model fingerprinting efficient tracing method as described above.

[0051] Compared to existing technologies, this invention addresses the technical pain points of high communication complexity and easy fingerprint tampering in deepfake image tracing. It utilizes a lightweight encoder and decoder for collaborative training, combined with the Haas sigmoid function to constrain residuals within a range to generate fingerprint-containing images. This simplifies model parameters and reduces model complexity when achieving invisible fingerprint embedding. Furthermore, it employs mini-batch training with shuffling the dataset in each round to prevent overfitting, improving the accuracy of fingerprint embedding and extraction. It also incorporates binary cross-entropy loss and... The joint optimization of loss ensures the accuracy of fingerprint extraction while constraining the similarity between the fingerprint-containing image and the original image.

[0052] Secondly, existing deepfake tracing solutions mostly only achieve fingerprint extraction, neglecting the critical requirements of fingerprint unforgeability and tamper-proof verification. To address this issue, this invention employs a dual verification scheme. First, it uses PIT parameters for fingerprint polynomial comparison verification, ensuring the uniqueness of fingerprint matching parameters. Second, it combines a commitment value and salt value binding mechanism to generate verifiable metadata. By opening the commitment value to verify its consistency, it accurately detects whether the fingerprint has been tampered with.

[0053] Finally, this invention designs an active defense scheme for non-repudiable and efficient model fingerprint attribution from the perspective of model developers. Starting from the training set of the generated model, it preprocesses the training images using artificial fingerprints. By verifying the transitivity of fingerprints from training images to the model and then to the generated images, it greatly simplifies deep fake image attribution to fingerprint detection and matching tasks. Cryptographic primitive commitments are incorporated into the model training and fingerprint embedding process to ensure the non-repudiation of the original fingerprints. A multinomial equivalence detection method is used to calculate the polynomial values ​​of the fingerprints, achieving lightweight and efficient verification by verifying the fingerprint polynomial. Attached Figure Description

[0054] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, obtaining other drawings based on these drawings without creative effort still falls within the scope of the present invention.

[0055] Figure 1 The following is an execution flowchart of a lightweight, non-repudiable model fingerprint efficient tracing method according to an embodiment of the present invention;

[0056] Figure 2 The diagram shows a comparison of the original image and the fingerprint image in an embodiment of the present invention, illustrating the differences between the original image and the fingerprint image in a lightweight, non-repudiable model fingerprint efficient tracing method. Detailed Implementation

[0057] The preferred embodiments of the present invention will be described in detail below to provide a clearer understanding of the purpose, features, and advantages of the invention. It should be understood that the following embodiments are not intended to limit the scope of the invention, but are merely illustrative of the essential spirit of the invention's technical solutions.

[0058] In the following description, certain specific details are set forth for the purpose of illustrating various disclosed embodiments in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the art will recognize that the embodiments may be practiced without one or more of these specific details. In other instances, well-known techniques associated with the invention may not have been shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.

[0059] Throughout this specification, references to "an embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Therefore, the appearance of "in an embodiment" or "an embodiment" in various places throughout the specification does not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic may be combined in any manner in one or more embodiments.

[0060] The specific meanings of the technical terms or English abbreviations that may be used in this invention are explained as follows:

[0061] Binary cross-entropy: A loss function specifically designed for binary classification tasks. Its core principle is to measure the accuracy of the prediction results by quantifying the difference in probability distribution between the true label and the model's predicted probability. The smaller the loss value, the higher the degree of fit between the predicted probability and the true label.

[0062] L2 loss: Euclidean loss, also known as squared loss, is a numerical loss function based on Euclidean distance. Its calculation logic is to first calculate the Euclidean distance between the true value and the predicted value of each sample, then sum the squared distances and take the average to quantify the overall fitting error.

[0063] Encoder: A technical module used for data transformation and feature extraction. Its core function is to map raw input data into output data in a specific format through a specific algorithm.

[0064] Decoder: A reverse conversion module that works with an encoder. Its core function is to restore the encoder's output data in a specific format to the original or target data format through inverse operations.

[0065] Binary fingerprints are fixed-length sequences of binary digits, possessing three core characteristics: uniqueness, non-replicability, and stability. Their generation principle involves using hash functions, random generation algorithms, or feature extraction algorithms to transform the core features of digital content into a 0-1 sequence. Identical content generates the same fingerprint, while different content generates different fingerprints.

[0066] Commitment value: In the field of cryptography, a commitment value is a unique digital identifier obtained by processing original data through a commitment function. It is the core credential for achieving data binding and verifiability. Its generation process involves inputting the original data and a random salt value into the commitment function, and then using cryptographic techniques such as hashing and encryption to generate a fixed-length string.

[0067] Salt value: A randomly generated string or number whose core function is to enhance data uniqueness and resist brute-force attacks. It works by combining the salt value with the original data, followed by hashing or encryption, so that the same original data produces different output results depending on the salt value.

[0068] Metadata: Data that describes the attributes, environment, and management information of raw data; in other words, data about data. Metadata does not directly contain the core content of the raw data, but rather records its key characteristics. Its core function is to assist in the management, parsing, querying, and verification of raw data.

[0069] Overfitting: A lack of generalization ability that occurs during the training of a machine learning model. It refers to the model overlearning random errors, outliers, and local features in the training data, resulting in minimal training error on the training set but extremely large testing error on an unseen test set.

[0070] Non-repudiation: One of the core characteristics of information security, it refers to ensuring that the sender or operator of data cannot deny the actions they have performed, i.e., the traceability and non-repudiation of actions. Its implementation principle is to generate unique digital evidence for actions using cryptographic techniques, and this evidence possesses integrity, authenticity, and relevance.

[0071] PIT parameters: are the core technology carrier for achieving lightweight fingerprint verification and efficient traceability in this invention. Essentially, it is a standardized set of parameters for fingerprint uniqueness identification and polynomial verification. Its core function is to transform fingerprint verification into polynomial verification, thereby reducing communication complexity to sublinear overhead and adapting to the high efficiency requirements of deepfake image traceability.

[0072] Combination Figure 1 As shown, in one embodiment of the present invention, a lightweight, non-repudiable model fingerprint efficient tracing method includes the following steps S110-S170:

[0073] S110, Input the original image dataset into the computer system; the original image dataset includes the number of image channels, image height, and image width;

[0074] S120, sample binary fingerprints for each batch, train and learn an encoder and a corresponding decoder based on the original image dataset, and the encoder maps the binary fingerprints to the original image dataset to obtain residuals;

[0075] S130, the residual is constrained within an interval using the Haas-Sigmoid function to generate a fingerprint image. The decoder extracts the fingerprint from the fingerprint image and then calculates the binary cross-entropy loss. loss;

[0076] S140, Load the encoder, weights and parameters; if the batch of images are uniformly labeled, generate a fixed fingerprint; otherwise, randomly sample the fingerprint, generate PIT parameters, embed the fingerprint into the image and generate metadata.

[0077] S150, prevent the fingerprint from being tampered with by binding the fingerprint with the salt value, and save the metadata;

[0078] S160, Load the decoder, input the image to be detected and the metadata, extract the decoded fingerprint and obtain the binary fingerprint through a threshold function;

[0079] S170, compare the polynomials of the original fingerprint and the binary fingerprint to verify the commitment value matching, determine whether the embedded fingerprint has been tampered with, and output the matching result and the tampering detection result.

[0080] Among the following possible implementations, the following provides a detailed description of a lightweight, non-repudiable model fingerprinting-based efficient tracing method of the present invention:

[0081] During the training phase:

[0082] First, input the original image dataset. Each image

[0083] in, Indicates the number of image channels (e.g., RGB image). ), Indicates the image height (in pixels). Indicates the image width (in pixels).

[0084] Sample fingerprints for each batch , This indicates the batch size, where the binary fingerprints are randomly generated for each image. , This refers to the fingerprint length.

[0085] The encoder is trained based on the dataset. and the corresponding decoder By training in rounds, the dataset is shuffled at the beginning of each round to prevent the model from overfitting.

[0086] The dataset is divided into mini-batches for training; the encoder... fingerprints and images Mapped to residuals By activating the Sigmoid function = Limiting the residual to Internally, generate fingerprint images. = ,like Figure 2 As shown, this illustrates the difference between the original image and the image containing fingerprints.

[0087] decoder from Extracting fingerprints Calculate the binary cross-entropy loss to force the decoder to accurately predict the fingerprint:

[0088]

[0089] calculate Loss constraint includes the similarity between the fingerprint image and the original image:

[0090]

[0091] Calculate total loss Perform backpropagation and parameter update, where and These are the training parameters.

[0092] Finally, PIT metadata is generated, and prime numbers are generated for each fingerprint. and random sampling , For a finite field, compute the fingerprint polynomial value. For subsequent fingerprint verification:

[0093]

[0094] in, It is the first The first image in the original binary fingerprint The value of each bit is the same prime number used when verifying fingerprints in this invention. Different random numbers are used for different batches of fingerprints. .

[0095] Secondly, the fingerprint is embedded in the image invisibly, and verifiable metadata is generated.

[0096] Load the trained encoder Weights and parameters: if batch images are uniformly labeled, a fixed fingerprint is generated; otherwise, fingerprints are randomly sampled. .

[0097] First, perform residual calculation. Embed the fingerprint into the image, and ensure the image contains the fingerprint by using Sigmoid activation and clipping. The pixel values ​​are within the range.

[0098] Secondly, the generated PIT parameters include prime numbers. random numbers fingerprint polynomial verification value .

[0099]

[0100]

[0101]

[0102] in, It indicates a uniform distribution.

[0103] And generate the corresponding fingerprint commitment, randomly sampling the salt value for each fingerprint. Use the corresponding salt value Commitment to fingerprint computation :

[0104]

[0105]

[0106] By binding fingerprints with salt values ​​to prevent fingerprint tampering, and finally the metadata... The fingerprints are saved for verification during subsequent testing phases.

[0107] Finally, load the trained decoder. Input the image to be detected. And metadata, extract and decode fingerprints for output. Through the threshold function Obtain binary fingerprint .

[0108] Specifically, the threshold function :

[0109]

[0110] in, It is the decoder for the first The first image detected in the binary fingerprint The value of the bit is used to calculate the polynomial value of the detected binary fingerprint. :

[0111]

[0112] Comparing the original fingerprint polynomial and the detected fingerprint polynomial:

[0113]

[0114] If they are equal, the fingerprints match; otherwise, they do not match, and the commitment is opened for verification. The reconstructed commitment is then calculated.

[0115]

[0116] examine This is to detect whether the embedded original fingerprint has been tampered with.

[0117] The purpose of the detection phase is to extract fingerprints from fingerprint images and verify their authenticity through dual verification.

[0118] In the following possible implementations, the present invention also provides an electronic device for implementing a lightweight, non-repudiable model fingerprint efficient tracing method.

[0119] In one feasible embodiment, the electronic device provided by the present invention is suitable for terminal or server scenarios for tracing the source of deepfake images, and its hardware architecture includes at least a processor and a memory communicatively connected to the processor.

[0120] The processor is a central processing unit (CPU), but other hardware components with data processing capabilities can also be selected. The memory includes random access memory (RAM), read-only memory (ROM), and flash memory. Both the CPU and RAM interact with the processor through a data bus and a control bus to ensure efficient data and program transmission.

[0121] The computer program stored in the memory is executable code that implements a lightweight, non-repudiable model fingerprint efficient tracing method. It is divided into multiple functional modules, including a data input module, a model training module, a fingerprint embedding module, and a detection and verification module.

[0122] The data input module receives the raw image dataset and parses parameters such as the number of channels, height, and width of the images. The model training module contains the network structure code for the encoder and decoder, as well as the logic code for batch processing and loss calculation.

[0123] When the processor executes the computer program, it first acquires the original image dataset through the data input module and caches it in the RAM area of ​​the memory.

[0124] Subsequently, the model training module is invoked, and the processor computing power is scheduled to perform mini-batch training round by round. Before each round of training, the order of the dataset is shuffled, and the fingerprint and image are mapped by the encoder to generate residuals. After processing by the Haas sigmoid function, fingerprint images are generated. At the same time, the decoder extracts fingerprints and calculates binary cross-entropy loss and L2 loss. The processor optimizes the model parameters in reverse based on the loss results and stores the updated weights in random access memory (RAM), read-only memory (ROM), and flash memory.

[0125] During the fingerprint embedding stage, the processor loads the trained encoder parameters, generates fixed or random fingerprints according to the batch labeling requirements, calculates the PIT parameters and binds salt values ​​to generate metadata, and stores the metadata in the memory.

[0126] During the detection phase, the processor receives the image to be detected and metadata, calls the detection and verification module, extracts the fingerprint through the decoder and binarizes it through the threshold function, then completes the fingerprint polynomial comparison and commitment value verification, and finally outputs the matching result and tamper detection result.

[0127] The electronic device provided by this invention can be deployed in scenarios such as content review platforms and digital media management terminals to meet the needs of real-time or batch deepfake image tracing.

[0128] In the following possible implementations, the present invention also provides a computer-readable storage medium for implementing a lightweight, non-repudiable model fingerprint efficient tracing method.

[0129] In one feasible embodiment, the present invention provides a computer-readable storage medium that carries a computer program for a lightweight, non-repudiable model fingerprinting efficiency tracing method. This type of storage medium includes, but is not limited to, portable storage devices, optical storage media, solid-state storage media, and network storage media. This computer-readable storage medium is connected to the aforementioned processor via a network interface, ensuring stable access to the program data.

[0130] The computer program stored on the computer-readable storage medium provided by this invention corresponds to the complete execution logic of a lightweight, non-repudiable model fingerprinting efficient tracing method, and its code is organized in a modular form:

[0131] The training subroutine includes code for data shuffling, batch partitioning, encoder mapping fingerprints and image generating residuals, and decoder extracting fingerprints to complete the model training.

[0132] The loss calculation subroutine integrates the calculation logic of binary cross-entropy loss and L2 loss to achieve loss optimization.

[0133] The detection subroutine includes functional units for threshold function binarization, fingerprint machine polynomial comparison, and commitment value verification.

[0134] When the storage medium is connected to a computer device, the computer device's processor reads the calculation program from the medium through the storage interface and loads it into the device's memory. The processor then executes the program sequentially according to the program logic.

[0135] First, the data input code is called to obtain the original image dataset. Then, the training subroutine is executed to complete the training of the encoder and decoder. Next, the loss is optimized through the loss calculation subroutine, and fingerprint images and metadata are generated and stored.

[0136] Finally, when the fingerprint is to be detected, the processor calls the detection subroutine, inputs the image to be detected and metadata, completes fingerprint extraction, verification and outputs the results.

[0137] The various subroutine modules are connected to form a complete link, enabling efficient tracing of lightweight, non-repudiable model fingerprints.

[0138] The computer-readable medium provided by this invention has good portability and reusability. It does not require the separate development of corresponding program code in different traceability systems. It can quickly deploy a lightweight, non-repudiable model fingerprint efficient traceability function simply by reading the program in the storage medium.

[0139] The technical terms, principles, or means related to the technical solutions of the present invention mentioned in the above embodiments, which are not described in detail above, are all well-known technologies or common practices that are known to those skilled in the art.

[0140] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A lightweight, non-repudiable model fingerprinting method for efficient source tracing, characterized in that, Includes the following steps: Input the raw image dataset into the computer system; the raw image dataset includes the number of image channels, image height, and image width; Binary fingerprints are sampled for each batch, and an encoder and corresponding decoder are trained based on the original image dataset. The encoder maps the binary fingerprints to the original image dataset to obtain residuals. The residuals are constrained within an interval using the Haas-Sigmoid function to generate a fingerprint image. The decoder then extracts the fingerprints from this fingerprint image and calculates the binary cross-entropy loss. loss; The encoder is loaded. If the batch of images are uniformly labeled, a fixed fingerprint is generated. Otherwise, the fingerprint is randomly sampled, PIT parameters are generated, the fingerprint is embedded into the image, and metadata is generated. By binding the fingerprint with a salt value, the fingerprint is prevented from being tampered with, and the metadata is saved; Load the decoder, input the image to be detected and the metadata, extract the decoded fingerprint and obtain the binary fingerprint through a threshold function; Compare the polynomials of the original fingerprint and the binary fingerprint to verify the commitment value matching, determine whether the embedded fingerprint has been tampered with, and output the matching result and tampering detection result; The fingerprint embedding image includes the following steps: The fingerprint is embedded into the image through residual calculation, and the pixel values ​​of the fingerprint-containing image are ensured to be within the range through Sigmoid activation and cropping. The PIT parameters include prime numbers, random numbers, and fingerprint polynomial verification values. The metadata includes the PIT parameters, the salt value, and the corresponding fingerprint commitment; the salt value is obtained by sampling each fingerprint. The fingerprint commitment is calculated based on the corresponding salt value.

2. The lightweight, non-repudiable model fingerprinting efficient tracing method according to claim 1, characterized in that, The binary fingerprint specifically includes one generated based on each image in the original image dataset; The training and learning encoder and the corresponding encoder specifically include: through successive rounds of training, at the beginning of each round, shuffling the dataset to prevent model overfitting, and dividing the dataset into mini-batches for training.

3. The lightweight, non-repudiable model fingerprinting efficient tracing method according to claim 1, characterized in that, The Sigmoid function is: in, Let R represent the Haus number Sigmoid function, R represent the residual, and e represent the natural constant. The interval range is Inside; The binary cross-entropy loss is obtained by calculating the binary cross-entropy loss function. The loss constraint is based on the similarity between the fingerprint image and the original image, through... The loss function is obtained.

4. The lightweight, non-repudiable model fingerprinting efficient tracing method according to claim 3, characterized in that, The binary cross-entropy loss function is: in, The loss function is binary cross-entropy, where j represents the sample index within the batch, and B represents the batch size. Represents fingerprints; The The loss function is: in, express The loss function, where B represents the batch size and j represents the sample index within the batch. This indicates an image containing fingerprints.

5. The lightweight, non-repudiable model fingerprinting efficient tracing method according to claim 1, characterized in that, The comparison of the polynomials of the original fingerprint and the binary fingerprint to verify the matching of the commitment value specifically includes a first verification and a second verification. The first layer of verification specifically includes: comparing the polynomial of the original fingerprint with that of the binary fingerprint; if they are equal, the fingerprint is determined to match; if they are not equal, the fingerprint is determined to not match, and the second layer of verification is activated.

6. The lightweight, non-repudiable model fingerprinting efficient tracing method according to claim 5, characterized in that, The second layer of verification includes: When the first verification determines that the fingerprint does not match, the commitment is opened for verification, the commitment is reconstructed, and the commitment value is reconstructed and integrated based on the binary fingerprint and the salt value to form a set of commitment values ​​to be verified. The fingerprint commitment in the metadata of the set of commitment values ​​to be verified is checked for consistency. If they are consistent, the embedded fingerprint has not been tampered with after embedding; if they are inconsistent, the embedded fingerprint has been tampered with.

7. An electronic device, characterized in that, include: At least one processor; The memory is communicatively connected to the processor; The memory stores a computer program, which, when executed by the processor, enables a lightweight, non-repudiable model fingerprinting efficient tracing method as described in any one of claims 1-6.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements a lightweight, non-repudiable model fingerprinting efficient tracing method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Generated image traceability method based on model fingerprints

    CN113988180A

  • Related method and related device for training set images

    CN115830723A