Counterfeit image detection method and system based on identity watermark self-verification

By employing a self-verification mechanism that combines high-risk face screening with multi-scale identity feature watermark embedding, the generalization and overhead issues of Deepfake detection technology are resolved, achieving efficient and robust forged image detection.

CN122049641APending Publication Date: 2026-05-15HENAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HENAN NORMAL UNIV
Filing Date
2025-12-30
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing deepfake detection technologies are difficult to generalize to unknown attacks, and proactive forensic solutions have high computational and storage overhead and affect the original usability of images.

Method used

Employing a high-risk face screening, multi-scale identity feature watermark embedding, and self-verification mechanism, this method filters out easily forged images through a high-risk face quantitative evaluation system and embeds identity feature watermarks using a U-Net architecture identity watermark generator, encoder, and discriminator to self-verify and detect the authenticity of images.

Benefits of technology

It achieves a high detection rate against known and unknown Deepfake attacks, reduces computational and storage overhead, maintains image visual quality and robustness, and is suitable for large-scale deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122049641A_ABST
    Figure CN122049641A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of crossing of computer vision, digital watermarking and information security, in particular to a forged image detection method and system based on identity watermark self-verification, and the method comprises the steps: high-risk face screening: carrying out the risk assessment of an input image through a high-risk face quantitative assessment system; screening out a high-risk face image which is easily counterfeited at high quality; identity feature watermark embedding: for the screened high-risk face image, embedding the binarized identity features as watermark information into the image through a multi-scale identity feature watermark embedding network, and generating a watermark-containing image; and self-verification detection: carrying out watermark decoding on the to-be-detected image to obtain a recovered identity feature, calculating the cosine similarity between the recovered identity feature and the identity feature extracted by the to-be-detected image, and judging the authenticity of the image according to a similarity threshold. According to the method, high-precision and strong-generalization detection of known and unknown depth forgery attacks is realized, and meanwhile, the calculation and storage overhead is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the interdisciplinary fields of computer vision, digital watermarking, and information security, and in particular to a method and system for detecting forged images based on identity watermark self-verification. Background Technology

[0002] The deep penetration of AI technology into all sectors of society presents a distinct duality: while empowering society, it also makes information security a core issue in the digital age. With breakthroughs in technologies such as Generative Adversarial Networks (GANs), Deepfake technology has developed rapidly, significantly improving the realism of forged faces and greatly lowering the barrier to entry. However, Deepfake technology has been maliciously used to generate highly realistic fake content. This seriously infringes on individuals' portrait rights and reputation rights, exacerbates the spread of misinformation, and poses a threat to social stability. This situation places higher demands on the generalization, robustness, and practicality of Deepfake detection technology.

[0003] Existing deepfake defenses are mainly divided into two paradigms: passive detection and active defense. For example... Figure 1 As shown in Figure a, passive detection aims to identify forgery traces after the fact, but it heavily relies on the prior knowledge of a specific generative model and has insufficient generalization ability against unknown attacks. To address this challenge, active defense has emerged. Among them, interference-based schemes ( Figure 1 b) Disrupting the forgery process by adding adversarial perturbations, but this compromises the original usability of the image, hindering its application in legitimate creative scenarios. In contrast, watermark-based proactive forensics ( Figure 1 c) Image integrity is verified by embedding hidden identifiers, achieving detection and secure source tracing without affecting legitimate use. Blind watermarking is a technique that conceals additional information within valuable media without affecting its natural appearance, and its application in copyright protection and source tracing is becoming increasingly widespread. In recent years, in particular, deep learning-based blind watermarking technology has shown great potential in robustness and security due to its ability to verify without the original image. However, these advanced solutions still fail to address their fundamental efficiency bottleneck—the enormous computational and storage overhead of embedding watermarks into all data, hindering their large-scale deployment in real-world scenarios. Therefore, it is necessary to screen facial images with a high risk of forgery and implement targeted watermark protection, thereby significantly reducing system overhead while ensuring the effectiveness of evidence collection. Summary of the Invention

[0004] This invention addresses the challenges of existing passive detection methods, which struggle to generalize to unknown forgery techniques. It also addresses the high computational and storage costs associated with active forensics involving watermarking all images. The invention proposes a forged image detection method and system based on self-verification using identity watermarks. Through precise screening of high-risk faces, multi-scale identity feature watermark embedding, and a self-verification mechanism, it achieves a high detection rate against both known and unknown Deepfake attacks, while simultaneously maintaining low computational and storage costs, high visual quality, and strong watermark robustness.

[0005] To achieve the above objectives, the technical solution adopted is:

[0006] This invention provides a method for detecting forged images based on identity watermark self-verification, comprising the following steps:

[0007] High-risk face screening: The input images are assessed for risk through a high-risk face quantitative evaluation system, and high-risk face images that are easily forged with high quality are screened out;

[0008] Identity feature watermarking embedding: For the selected high-risk face images, the binarized identity features are embedded as watermark information into the image through a multi-scale identity feature watermarking embedding network to generate a watermarked image; the multi-scale identity feature watermarking embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder and a watermark discriminator.

[0009] Self-verification detection: Watermark decoding is performed on the image to be tested to obtain the restored identity features, the cosine similarity between the restored identity features and the identity features extracted from the image itself is calculated, and the authenticity of the image is determined based on the similarity threshold.

[0010] According to the forged image detection method based on identity watermark self-verification of the present invention, the risk assessment steps of the high-risk face quantitative assessment system further include:

[0011] Perform face detection and standardization on the input image, and extract the standardized face image;

[0012] Extract a set of fine-grained attributes from the standardized face image, the set of fine-grained attributes including a subset of image quality attributes and a subset of face structure attributes;

[0013] Based on the formal concept analysis method, a formal background K = (X, A, I) is constructed with standardized face images as objects and the set of fine-grained attributes as attributes. Here, X is the set of standardized face images, A is the union of image quality attributes and face structure attributes, and I is the association between the image and the attribute. Based on the formal background, a fine-grained concept C = (X', A') is generated using the Galois join operator. Here, A' represents the set of all attributes shared by a subset of objects; X' represents the set of all objects that satisfy a certain set of common attributes.

[0014] Based on predefined ideal high-risk attribute profiles and non-ideal attribute profiles, the susceptibility index of each fine-grained concept is calculated.

[0015] Granular computing is used to organize the fine-grained concept into granular levels with different extensional sizes, and to calculate the comprehensive susceptibility score for each granular level.

[0016] Based on the comprehensive susceptibility score, a high-risk granularity level is selected, and the standardized face image corresponding to this level is determined to be a high-risk face image.

[0017] According to the forged image detection method based on identity watermark self-verification of the present invention, the image quality attributes further include high brightness and high contrast, and the facial structure attributes include frontal pose, high symmetry and complete facial features.

[0018] According to the forged image detection method based on identity watermark self-verification of the present invention, the susceptibility index calculation formula for each fine-grained concept is further as follows:

[0019] S(C)=α|A'∩ITP|-β|A'∩NTP|

[0020] Where S(C) represents the susceptibility index of concept C, α represents the weight coefficient of ideal attribute matching, β represents the weight coefficient of non-ideal attribute matching, ITP represents the ideal high-risk attribute profile, and NTP represents the non-ideal attribute profile.

[0021] The particle size hierarchy L k The division formula is:

[0022]

[0023] Among them, L k Let C be the k-th granularity level, where k is the size of the concept extension, i.e., the number of images contained in the image subset X' of a single fine-grained concept, and C is a single fine-grained concept. It is the set of all fine-grained concepts;

[0024] The comprehensive susceptibility scoring formula for each granularity level is as follows:

[0025]

[0026] in, This represents the average susceptibility index for all concepts at this level. This indicates the total coverage of this level.

[0027] According to the forged image detection method based on identity watermark self-verification of the present invention, the implementation process of the identity watermark generator is further as follows: Principal component analysis is used to compress the 512-dimensional original face identity feature vector into a vector of length L, and binarization processing is performed through a STE-based residual autoencoder to obtain the binarized identity feature M. bin M is generated through a message generator. bin The data is expanded into a spatial feature map through linear layers, nearest neighbor interpolation, and convolution, which is then used for multi-scale fusion.

[0028] According to the forged image detection method based on identity watermark self-verification of the present invention, the watermark encoder is further configured to receive the high-risk face image and the corresponding binarized identity watermark information, and fuse features from the previous layer of the decoder, features from the corresponding skip connections of the encoder, and watermark information shaped and matched with the current scale at multiple scales during the upsampling process to generate a watermarked image; the skip connections of the watermark encoder are provided with a multi-scale fusion module, which uses multiple convolutional kernels of different sizes and combines spatial and channel attention mechanisms to fuse the multi-scale features from the encoder and then transmit them to the decoder;

[0029] The watermark discriminator is a PatchGAN-based discriminator used to distinguish the watermarked image from the original high-risk face image.

[0030] The watermark decoder is used to decode and recover binary identity watermark information from images that may be subject to noise attacks.

[0031] According to the forged image detection method based on identity watermark self-verification of the present invention, the method further includes a combined noise layer step used when training the multi-scale identity feature watermark embedding network, specifically including: creating a gradient-free copy of the watermarked image; applying a randomly selected noise operation to the gradient-free copy to obtain a noisy image and calculating the noise change amount; adding the noise change amount as a constant residual back to the original gradient-carrying watermarked image to obtain a noisy image for the input of the watermark decoder.

[0032] According to the forged image detection method based on identity watermark self-verification of the present invention, the total loss function of the multi-scale identity feature watermark embedding network is further defined as follows:

[0033]

[0034] Where λ1, λ2, and λ3 are weight parameters. For watermark encoder loss, For the loss of the watermark decoder, To combat the losses.

[0035] According to the forged image detection method based on identity watermark self-verification of the present invention, the specific judgment rule of the self-verification detection is as follows: set the cosine similarity threshold τ = 0.7, when the cosine similarity Sim between the recovered identity features and the identity features of the image to be tested is ≥ 0.7, the image is judged to be a real image; when Sim < 0.7, the image is judged to be a forged image.

[0036] Furthermore, the present invention also provides a forged image detection system based on identity watermark self-verification, for implementing the above method, the system comprising:

[0037] The high-risk face screening module is used to assess the risk of input images through a high-risk face quantitative evaluation system and screen out high-risk face images that are easily forged with high quality.

[0038] The identity feature watermarking embedding module is used to embed binarized identity features as watermark information into the selected high-risk face images through a multi-scale identity feature watermarking embedding network to generate a watermarked image. The multi-scale identity feature watermarking embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder, and a watermark discriminator.

[0039] The self-verification detection module is used to decode the watermark of the image under test, obtain the recovered identity features, calculate the cosine similarity between the recovered identity features and the identity features extracted from the image under test itself, and determine the authenticity of the image based on the similarity threshold.

[0040] The beneficial effects achieved by adopting the above technical solution are:

[0041] 1. Significantly reduces overall system overhead and adapts to large-scale deployment needs: Through a high-risk face quantification assessment system (HrFQA), "high-risk" faces easily forged with high quality are accurately screened from massive amounts of data. This allows defense resources to focus on core protection targets, avoiding the redundant operation of watermarking all data in traditional proactive forensics solutions, and significantly reducing the computational overhead of the watermarking stage. Simultaneously, the multi-scale identity feature watermarking embedding network uses target identity features as the core watermark content, eliminating the need for additional local storage of watermark information. This completely avoids the resource consumption problem caused by watermark storage in traditional solutions, achieving dual optimization of computational and storage overhead, and providing feasibility for large-scale deployment of proactive forensics technology in real-world scenarios.

[0042] 2. Overcoming the bottleneck of detection generalization and enhancing defense against unknown attacks: An innovative "self-verification" detection mechanism is adopted, abandoning the traditional semi-fragile watermark detection logic that relies on bit error rate. It determines authenticity by calculating the cosine similarity between the decoded identity features and the facial identity features of the person being tested. Since the core purpose of Deepfake attacks is to tamper with facial identities, regardless of whether they use known or unknown forgery techniques, they will disrupt the consistency of the original identity features. This mechanism precisely matches this attack essence, thus possessing a natural defensive advantage against various novel and unknown Deepfake attacks, effectively solving the core problem of insufficient generalization ability in traditional passive detection methods.

[0043] 3. Optimize watermark embedding performance, balancing visual quality and robustness: A customized multi-scale identity feature watermark embedding network embeds facial identity features as robust watermarks. The network adaptively allocates watermark energy through a multi-scale fusion module (MSF-block), ensuring both the imperceptibility of the watermark—the embedded image is visually almost indistinguishable from the original image, maintaining high definition and structural integrity—and strengthening the watermark's anti-interference ability. It can effectively resist benign distortions during image propagation (such as compression, scaling, noise interference, etc.) and attacks caused by various Deepfake tampering (such as identity replacement, attribute editing, facial replay, etc.), achieving the optimal balance between visual quality and robustness. Attached Figure Description

[0044] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments of the present invention will be briefly described below. The drawings are merely illustrative of some embodiments of the present invention and are not intended to limit the scope of the present invention to all embodiments.

[0045] Figure 1 This is a diagram showing the differences between existing solutions for dealing with Deepfake.

[0046] Figure 2 This is an overall architecture diagram of the forged image detection method based on identity watermark self-verification according to an embodiment of the present invention;

[0047] Figure 3 This is a diagram illustrating the architecture of a high-risk facial quantitative assessment system according to an embodiment of the present invention.

[0048] Figure 4 This is the cosine difference of identity features under different noise levels in this embodiment of the invention. The y-axis represents the cosine distance, defined as 1–sim.

[0049] Figure 5 This is an architecture diagram of a multi-scale identity feature watermarking embedding network according to an embodiment of the present invention. Detailed Implementation

[0050] The exemplary solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Unless otherwise defined, the technical or scientific terms used in this invention should have the ordinary meaning understood by one of ordinary skill in the art.

[0051] This invention discloses a forged image detection method based on identity watermark self-verification (referred to as S2-Mark), the overall architecture of which is as follows: Figure 2 As shown, its core is a sequential pipeline consisting of two stages: risk assessment and identity watermarking. First, in the risk assessment stage, a high-risk face quantification evaluation system is designed. By analyzing multiple dimensions of attributes such as facial structure and image quality, a "forgery risk" score is calculated for each input image to identify those targets most easily tampered with using high-quality methods. Second, only images judged to be high-risk are sent to the identity watermark embedding stage. In this stage, a multi-scale identity feature watermark embedding network is used to hide the target's identity information as watermark information. The core purpose of this multi-scale design is to adaptively distribute the watermark energy across image components of different frequencies, thereby maintaining extremely high visual fidelity while resisting mixed attacks such as compression, noise, and Deepfake. S2-Mark specifically includes the following steps:

[0052] Step S101, High-Risk Face Screening: The input images are assessed using the High-Risk Face Quantitative Assessment (HrFQA) system to screen out high-risk face images that are easily forged with high quality. The High-Risk Face Quantitative Assessment (HrFQA) system uses Formal Concept Analysis (FCA) to uncover potential risk patterns and combines it with Granular Computation (GrC) to organize risk patterns into different granular levels according to their universality. By assessing the comprehensive risk at each granular level, high-risk faces are accurately screened.

[0053] High-risk face images refer to images that are easily manipulated by Deepfake to produce high-quality fake faces. Research indicates that high-resolution, low-noise, and uniformly lit images provide richer texture information for models, making it easier to generate realistic forgeries. Simultaneously, it has been observed that the geometric and structural properties of the face are equally crucial for generating high-quality forgeries. Specifically, faces with a frontal view, low pose shift, and no occlusion are more easily manipulated with high quality, generating indistinguishable forgeries; conversely, faces with occlusion or irregular poses are more prone to visible artifacts during forgery due to the loss or blurring of some key features, leading to a decrease in forgery quality.

[0054] High-quality face forgery is not determined by a single attribute, but rather by the complex synergistic effect of multiple fine-grained attributes (such as image quality, facial structural features, etc.). Mainstream methods face a fundamental limitation in addressing the problem of "quantifying the synergistic effect of multiple attributes": Supervised learning (such as logistic regression / SVM): These methods require a large-scale, pre-labeled "high / low risk" training dataset. In the context of social networks, such labeled data is difficult to obtain, and the task of this invention must be completed in an unsupervised environment. While weighted scoring functions are simple, their linear "additive" logic cannot capture the nonlinear synergistic effects between attributes. For example, a high score on one attribute (such as high resolution) can easily "compensate" for a low score on another attribute (such as extreme poses). Standard unsupervised methods, tools like K-Means, are unsuitable because they are based on statistical distance, identifying "clusters" rather than "logical rules." The "high-risk" profile of this invention is not a cluster in vector space, but rather a logical connection of attributes. In contrast, Formal Concept Analysis (FCA) is a mathematical tool derived from lattices specifically designed for theoretical relationships in "object-attribute" binary models.

[0055] To systematically model the relationships among these multiple attributes and their combined impact on susceptibility to forgery, this invention proposes a high-risk face quantification assessment system (HrFQA). For example... Figure 3 As shown, the system first uses formal concept analysis (FCA) to discover all potential risk patterns, and then uses granular computation (GrC) to organize these patterns into different "granularity levels" according to their universality. By evaluating the comprehensive risk of these granularities, the system ultimately achieves the goal of accurately screening high-risk faces from massive images.

[0056] (1) Face Standardization: Face tampering operations mainly target the facial region, and accurate face localization is a prerequisite for subsequent fine-grained analysis. To balance accuracy and time efficiency, the MediaPipe face detection framework is introduced to standardize the target image I. o Face detection is performed to detect faces within 2 meters, and false detection results with a confidence level of less than 50% are filtered out. The relative boundaries of the face are obtained through model inference, the face bounding box is expanded, and finally a standardized face image X is cropped out.

[0057] (2) Attribute Construction: A series of fine-grained attributes are extracted from standardized face images. These attributes are divided into two main categories: a subset of image quality attributes Q = {q1,q2,...,q...} m The data includes quantifiable image quality features such as high brightness and high contrast, as well as a subset of facial structural attributes F = {f1, f2, ..., f...} n It includes features related to facial structure such as frontal pose, high symmetry, and complete facial features.

[0058] (3) Risk Modeling Based on Conceptual Analysis: To capture the synergistic effects between different attributes, this approach introduces Formal Conceptual Analysis (FCA), a mathematical tool specifically designed to uncover strong correlation patterns in object-attribute binary relationships, to discover the "synergistic effects" between image attributes under unsupervised conditions. First, a formal background K = (X, A, I) is constructed, where X = {x1, x2, ..., x...}. N} represents a standardized set of face images; A = Q∪F is a set of fine-grained attributes composed of image quality attributes and face structure attributes; To standardize the association between images and attributes, a binary decision table M∈{0,1} is constructed. N×(m+n) The decision table M is a two-dimensional matrix, where rows correspond to objects x∈X (i.e., each image), columns correspond to attributes a∈A (such as frontal pose, high resolution, etc.), and the element M(x,a) indicates whether object x has attribute a; M(x,a) = 1 if and only if x∈X and has a∈A, otherwise it is 0;

[0059] Based on the formal context K, a fine-grained concept C = (X', A') is generated using the Galois join operator, for any subset of objects. Its attribute set is as follows:

[0060]

[0061] The formula takes a subset of objects X' (a set of face images) as input and outputs a set of all attributes shared by these images, X'. ↑ The goal is to find the common attributes of a certain set of images.

[0062] For attribute subsets Its object set is:

[0063]

[0064] The formula takes a subset of attributes A' (e.g., {front view, high resolution}) as input and outputs a set of images A' that simultaneously possess all of these attributes. ↓ The goal is to find all images that have a certain combination of attributes.

[0065] (4) Granularity Stratification and Screening: To assess the susceptibility of each concept, an objective "Ideal High-Risk Attribute Profile" (ITP) was defined, consisting of a set of attributes most conducive to high-quality tampering. Simultaneously, its opposite was defined as the "Non-Ideal Attribute Profile." The susceptibility index S(C) of concept C was defined as the net match score between its intension A' and the ITP:

[0066] S(C)=α|A'∩ITP|-β|A'∩NTP|(3)

[0067] Where S(C) represents the susceptibility index of concept C, α represents the weighting coefficient of ideal attribute matching, β represents the weighting coefficient of non-ideal attribute matching, ITP represents the ideal high-risk attribute profile, and NTP represents the non-ideal attribute profile. |A'∩ITP| is the number of "ideal" attributes matched by concept C, and |A'∩NTP| is the number of "non-ideal" attributes matched by concept C.

[0068] In tamper susceptibility analysis, granular computation (GrC) is used to organize these concepts into a hierarchical structure. Let the set of all concepts be . Granularity levels are defined according to the size of the extension:

[0069]

[0070] Among them, L k Let C be the k-th granularity level, where k is the size of the concept extension, i.e., the number of images contained in the image subset X' of a single fine-grained concept, and C is a single fine-grained concept. Let X' be the set of all fine-grained concepts. |X'| is the cardinality of the concept extension, i.e., the number of images contained in the image subset X'.

[0071] Includes concept granularity levels L with an extension size of k. k The overall susceptibility score S(L) k ) is defined as:

[0072]

[0073] in, This represents the average susceptibility index for all concepts at this level. This indicates the total coverage of this level.

[0074] Ultimately, based on S(L) k The high-risk granularity level selected is the set of concepts corresponding to this level, which are the images most easily forged with high quality.

[0075] Step S102, Identity Feature Watermark Embedding: For the selected high-risk face images, the binarized identity features are embedded as watermark information into the image through a multi-scale identity feature watermark embedding network to generate a watermarked image; the multi-scale identity feature watermark embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder and a watermark discriminator.

[0076] For the high-risk images selected in step S101, this invention designs a multi-scale identity feature watermarking embedding network to achieve proactive forensics. The core motivation of this scheme stems from a key observation (such as...). Figure 4As shown: Malicious tampering such as Deepfake (e.g., SimSwap) can cause irreversible and significant damage to the deep identity features of a face, while conventional benign operations (e.g., JPEG compression) have negligible impact on these features. Utilizing this significant statistical difference, this paper innovatively embeds the "facial identity features" themselves as watermark information into the image. During the detection phase, the original watermark is no longer needed; instead, the authenticity is determined by calculating the cosine similarity between the identity features of the image under test and the decoded and recovered identity features. This "self-verification" mechanism greatly reduces the storage overhead of the watermarking system.

[0077] To achieve the aforementioned "self-verification" mechanism and balance imperceptibility with robustness, multi-scale identity feature watermarking is embedded in networks (such as...). Figure 5 The image shown is designed as an adversarial autoencoder, aiming to resolve the core contradiction between robustness and imperceptibility. The architecture comprises five key components: an identity watermark generator, a watermark encoder, a watermark decoder, a combined noise layer, and a watermark discriminator. The watermark encoder receives a batch of filtered high-risk face images. And the corresponding identity features encoded into watermark information M bin ∈{0,1} B×L The watermark information is embedded in the image, and the watermarked image I is output. en The watermark discriminator is used to distinguish I en with I co Does the image contain a watermark to enhance its imperceptibility? During training, combined random noise is selected, and the watermark image I... en Noisy image I is generated by a selected noise attack. no Watermark decoder from I no Extract and restore watermark information M rec Finally, compare M rec The decoded identity features are compared with the identity features of the image under test to determine forgery.

[0078] (1) Identity Watermark Generator

[0079] Original facial identity features are continuous high-dimensional floating-point vectors, making it difficult to fully embed them into an image without compromising visual quality. Furthermore, even minor perturbations can alter these features, making them unsuitable for direct use as robust watermarks. To address this issue, the original 512-dimensional continuous features are learned and compressed into a compact, robust binary representation M. bin .

[0080] This scheme first employs Principal Component Analysis (PCA) to compress the original 512-dimensional face identity feature vector into a vector of length L, achieving efficient compression while retaining most of the identity information. Subsequently, binarization is performed using the encoder portion of a STE-based residual autoencoder to obtain the binarized identity features M.bin Residual connections can effectively prevent gradient vanishing in deep MLPs, while pass-through estimators solve the zero-gradient problem during binarization. The autoencoder minimizes the reconstruction loss, enabling the L-dimensional binary representation to carry key information of the original identity features, thus achieving identity vector binarization and recovery.

[0081] To effectively inject M into a multi-scale encoder bin This binary identity watermark needs to be expanded and shaped. This scheme uses a simple "message generator" to expand the watermark information of length L into a spatial feature map through linear layers, nearest neighbor interpolation, and convolution, so that it can be fused at different scales of the encoder.

[0082] (2) Watermark encoder

[0083] The core challenge in watermark embedding lies in the balance between robustness and visual quality. Watermark information needs to be embedded sufficiently "deeply" into image features to resist attacks such as compression, scaling, and noise; however, it must also be "shallow" enough to avoid artifacts visible to the human eye. Therefore, the watermark signal needs to be embedded dispersedly across multiple scales and frequency bands of the image.

[0084] To achieve the above goals, U-Net was chosen as the backbone architecture of the watermark encoder. In the downsampling stage, a Conv-In-LeakyReLu (CIL) block with a stride of 2 is used to halve the image spatial dimension, and then a Double Conv (two CIL blocks) is used to double the channel features. Four downsampling steps progressively extract multi-level features from fine texture to abstract semantics, providing ideal "anchor points" for embedding watermarks at different frequency bands and semantic levels. The skip connections in U-Net are key to ensuring high visual quality; this is not a simple identity mapping, but rather achieved through a multi-scale fusion module MSF (see...). Figure 5 b) Processing is performed to reduce the processing pressure on the residual blocks of subsequent attention. The MSF module uses a variety of convolutional kernels of different sizes (3×3, 5×5, 7×7) and combines spatial and channel attention to pre-fuse multi-scale contextual information before the features are passed to the upsampling stage, which greatly enhances the representational ability of the features passed by the skip connections.

[0085] Traditional methods typically inject watermarks once at the network input or bottleneck layer. A drawback of this design is that the watermark information may be diluted during deep propagation or covered by shallow image features during reconstruction, making it difficult to balance visual appeal and robustness. In this scheme, watermark information is actively and explicitly re-injected at each scale of encoder upsampling. Specifically, each upsampling fuses information from three different sources: 1. Image features from the previous layer of the decoder, which are first doubled in spatial dimension using nearest neighbor interpolation before being input into the CIL block; 2. Skip connection features from the corresponding layer of the encoder, carrying high-resolution, multi-scale original image details; 3. A message matrix shaped by the message generator, molded to the scale of the current feature map. These three information streams are concatenated along the channel dimension and fed into a residual block containing attention (see...). Figure 5 c) The network adaptively learns how to optimally integrate these three types of information. At the end of the watermark encoder, a 1×1 convolution outputs a three-channel watermark image.

[0086] (3) Combined noise layer

[0087] Images on social networks undergo various complex and unpredictable distortions during propagation. To enable watermarking models to learn robustness against benign distortions and deepfake attacks, the model must be fully exposed to both types of noise during training. Benign distortions (such as Gaussian Blur) are typically differentiable and can be seamlessly integrated into training. However, malicious deepfake noise (such as SimSwap and StarGAN) is highly complex, multi-stage, and non-differentiable. If the watermark encoder I is directly... en The output of the encoder is fed into Deepfake noise, which interrupts the gradient flow during backpropagation, causing the encoder to be unable to receive the loss signal from the decoder.

[0088] To address the aforementioned issues, this solution introduces a gradient bypass strategy. First, a copy of the encoder output I is created. en Gradient-free replica I en ', Performing a randomly selected noisy operation on a gradient-free replica yields I. no This operation will not be included in the gradient calculation. Then, the actual change caused by non-differentiable noise, noise = I, is calculated. no '-I en ' Finally, this noise residual, which is treated as a constant, is added back to the original image tensor I carrying the gradient. no =I en+noise. In this way, the encoder is successfully optimized based on the results of non-differentiable deepfake attacks, while ensuring the smooth gradient path of the end-to-end training process, thus achieving stable joint training.

[0089] (4) Competitive training

[0090] To achieve a high degree of imperceptibility, this invention employs an adversarial training strategy. Specifically, this invention introduces a Markov discriminator (PatchGAN). Unlike traditional single-value discriminators, PatchGAN uses a fully convolutional approach to output an N×N feature map, where each element evaluates the realism of a local region (patch) in the input image. This design forces the encoder to not only focus on global visual consistency but also ensure that no perceptible artifacts are generated in any local region, thereby generating a watermarked image with extremely high visual fidelity. Its loss function is as follows:

[0091]

[0092] in, To combat loss, MSE is the mean squared error, Dis is the watermark discriminator, and θ dis I is the parameter set of the watermark discriminator. co For the original overlay image, I en For the image with the watermark embedded, mean is the mean calculation function, 1 is the target value of the first part of the MSE loss, and we hope that Dis(θ) dis ,I co )-mean(I en The result of Dis(θ) should be as close to 1 as possible to ensure that the watermark discriminator can accurately identify the original real image; 0 is the target value of the second part of the MSE loss, which is to be the value of Dis(θ). dis ,I en )-mean(I co The result is made as close to 0 as possible, forcing the watermark encoder to generate a visually highly fidelity watermarked image that is enough to confuse the watermark discriminator.

[0093] (5) Network total loss function

[0094] The watermark encoder and decoder are trained jointly. The watermark discriminator is updated after the parameters of the current watermark encoder and decoder are frozen. The overall loss function is:

[0095]

[0096] Where λ1, λ2, and λ3 are weight parameters. For watermark encoder loss, For the loss of the watermark decoder, To combat the losses.

[0097] The training objective of the watermark encoder is to update the parameters θ e Make I co with I en The l2 paradigm is minimized, and LPIPS loss is used to ensure good visual performance:

[0098]

[0099] Where En is the encoder function, and the parameter is θ e LPIPS is a learning-aware image patch similarity algorithm, α L These are the weighting coefficients. The first term on the right-hand side of the equation ensures minimal variation in pixel values, while the second term ensures visual similarity.

[0100] The watermark decoder uses a U-Net structure similar to the watermark encoder. However, unlike the encoder which uses nearest-neighbor interpolation to inject discrete, blocky digital signals, the decoder extracts the watermark signal, processing image features; therefore, smoothness and continuity are crucial. During the upsampling phase, bilinear interpolation is employed to extract smooth, natural watermark information. The training objective of the watermark decoder is to update the parameters θ... d , making M bin With M rec The l2 normal form is minimized.

[0101]

[0102] Step S104, Self-verification detection: Decode the watermark of the image to be tested, obtain the recovered identity features, calculate the cosine similarity between the recovered identity features and the identity features extracted from the image to be tested, and determine the authenticity of the image based on the similarity threshold.

[0103] Specifically, the image to be verified is input into the watermark decoder; the watermark decoder extracts the recovered binary watermark information from the image to be verified, denoted as M. rec ; M rec The input is the decoder part of the "STE-based residual autoencoder", which is responsible for converting the binarized M... rec Reconstruct a continuous vector that is consistent with the original identity feature vector space, denoted as F. rec (That is, the decoded and recovered identity feature vector). Simultaneously, a pre-trained face recognition model is used to directly extract the identity feature vector of the image to be verified, denoted as F. det ; Calculate F rec With F det Cosine similarity between Sim(F) rec ,F detThe similarity is compared with a preset threshold (e.g., 0.7) to determine the authenticity of the image: if Sim≥threshold, the image is considered real or only benignly distorted and the identity remains unchanged; if Sim<threshold, the image is considered to have been maliciously tampered with, such as deepfake, and the identity has changed.

[0104] Corresponding to the above method, embodiments of the present invention also disclose a forged image detection system based on identity watermark self-verification, comprising:

[0105] The high-risk face screening module is used to assess the risk of input images through a high-risk face quantitative evaluation system and screen out high-risk face images that are easily forged with high quality.

[0106] The identity feature watermarking embedding module is used to embed binarized identity features as watermark information into the selected high-risk face images through a multi-scale identity feature watermarking embedding network to generate a watermarked image. The multi-scale identity feature watermarking embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder, and a watermark discriminator.

[0107] The self-verification detection module is used to decode the watermark of the image under test, obtain the recovered identity features, calculate the cosine similarity between the recovered identity features and the identity features extracted from the image under test itself, and determine the authenticity of the image based on the similarity threshold.

[0108] To verify the effectiveness of this solution, further explanations and illustrations will be provided below based on experimental data.

[0109] (I) Experimental Setup

[0110] The CPU environment for this experiment was an i7-13700K and an NVIDIA RTX 4070s, using the PyTorch architecture.

[0111] Datasets: High-risk face quantization experiments were conducted on the CelebA-HQ and COCO datasets. Multi-scale identity watermarking experiments were primarily performed on the CelebA-HQ dataset for high-risk face extraction, with the dataset split into training, validation, and testing sections according to a 7:1:2 ratio. High-risk face images extracted from the COCO dataset were then fed into the multi-scale identity watermarking framework for testing in complex noisy environments within social networks.

[0112] Implementation details: Due to limited computing resources, this experiment selected an image size of 128×128 and a watermark information length of 64 bits; and an image size of 256×256 and a watermark information length of 128 bits for the experiment. In formula (7), the parameters are designed as [λ1,λ2,λ3,α]. L = [1, 20, 0.01, 0.5].

[0113] This experiment designed a common benign distortion set {Resize, Dropout, GaussianBlur, Hue, Brightness, MedianBlur, Saturation, JPEG}, and four Deepfake distortion sets {StarGan, HiSD, GANimation, SimSwap} for three common categories: attribute editing, face replay, and identity replacement. The StarGan attribute set was set to {'Black_Hair', 'Blond_Hair', 'Brown_Hair', 'Male', 'Young'}, and the HiSD attribute set was set to {Bangs, Eyeglasses, HairColor}. The source domain image for SimSwap was a cleanly aligned face image randomly generated by CelebA-HQ. The target expression for GANimation was driven by an image from "eric_andre".

[0114] Baseline: This experiment compares SepMark, LampMark, and the invisible robust watermarking methods MBRS and CIN in the active forensics domain. CIN is trained on an image size of 128×128 and a watermark length of 30 bits. MBRS and SepMark are compared on an image size of 128×128 and a watermark length of 30 bits versus an image size of 256×256 and a watermark length of 128 bits. LampMark is compared on an image size of 128×128 and a watermark length of 64 bits versus an image size of 256×256 and a watermark length of 128 bits. In the Deepfake detection experiment, Xception, Face X-Ray, SBIs, CADDM, and LampMark are used for comparison, with the image to be detected being 256×256.

[0115] W ACC =1-BER

[0116]

[0117] in,

[0118] where

[0119]

[0120] The lower the bit error rate, the stronger the robustness. In the identity watermark self-verification stage, cosine similarity (Sim) is used to calculate the similarity between the recovered features and the facial identity features to be detected:

[0121]

[0122] Where F rec It is the identity feature vector decoded and recovered from the detected image; F det It is the identity feature vector extracted directly from the image to be detected. In this experiment, the threshold τ is set to 0.7, that is, when Sim(F... rec ,F det If the value is less than 0.7, the image is considered to have been tampered with, and the AUC value is used to evaluate the effectiveness of the method of this invention in detecting Deepfake.

[0123] (II) High-risk face selection effect

[0124] This experiment aims to evaluate the effectiveness and generalization of a high-risk face quantification assessment system (HrFQA). First, an effectiveness experiment was conducted on the CelebA-HQ dataset. The goal of this process is to use the HrFQA system to select and distinguish between "high-risk" face images that are easily forged with high quality and "low-risk" face images that are not easily forged. From 1000 randomly selected images in CelebA-HQ, 986 images that are easily forged with high quality were selected, and both high-risk and low-risk images were then forged separately.

[0125] Low-risk faces, once forged, produce obvious artifacts visible to the naked eye; such low-quality forgeries are easily detected. Conversely, high-risk faces, once forged, are difficult to distinguish from genuine faces. This demonstrates that S2-Mark's HrFQA assessment system can accurately screen out those targets that are truly vulnerable to high-quality tampering and most in need of protection. By first eliminating those "low-risk" images, it significantly reduces the computational and storage overhead of the subsequent watermark embedding stage, enabling proactive forensics technology to move from theory to practical deployment.

[0126] Unlike CelebA-HQ, the COCO dataset contains complex and varied real-world scenes: numerous non-face objects, faces with different poses, uneven lighting, and varying resolutions, as well as many motion-blurred and partially occluded faces. Since the COCO dataset lacks "high / low risk" real-world labels, 2000 images were randomly selected from the COCO dataset, and 120 images were manually labeled to identify high-quality forgery images.

[0127] To further verify the superiority of the HrFQA module over simpler methods, rigorous testing was conducted on the COCO labeled dataset. Four methods were compared: (1) Baseline 1 (Rule-based), a filter based on hard-coded rules (e.g., frontal pose, no occlusion, and high sharpness); (2) Baseline 2 (Weighted), a linear weighted scoring method based on custom weights; (3) Baseline 3 (SVM), a fully supervised SVM classifier trained on ground truth labels; and (4) Ours (HrFQA), an unsupervised concept analysis method. All methods used the same attribute features.

[0128] Table 1 Comparison of HrFQA Screening Performance and Ablation

[0129]

[0130] The experimental results (see Table 1) clearly demonstrate the superiority of the method of this invention. The F1-Score is a key indicator for evaluating the overall performance of the model, and the HrFQA (0.6712) of this invention achieved the highest score. Compared with simple baselines: Baseline 1 (Rule-based) almost completely failed (F1 = 0.0189), with a recall of only 0.0096, proving that simple hard thresholding rules cannot find the vast majority of high-risk targets. Although Baseline 2 (Weighted) had a recall as high as 1.0000 (finding all high-risk targets), its precision was extremely low (0.3123), incorrectly labeling a large number of low-risk images as high-risk, resulting in a far less than ideal overall F1 score (0.4760). This confirms that simple methods cannot capture the nonlinear synergistic effect of "manipulation". Compared with supervised baselines: Most importantly, Baseline 3 (SVM) is a fully-supervised model, trained on known high / low-risk "ground truth labels". Ours (HrFQA) is an unsupervised / heuristic model that never encounters "truth labels" during operation, relying solely on the "ideal target configuration" (ITP) defined based on prior knowledge.

[0131] The HrFQA of this invention, as an unsupervised model (F1 = 0.6712), significantly outperforms a fully supervised SVM model trained on ground truth labels (F1 = 0.6098). This strongly demonstrates that the FCA / GrC paradigm successfully uncovers latent synergistic patterns of "manipulation," even outperforming supervised models trained on the same features.

[0132] Global watermarking embedding and selective forensics were tested under the same conditions. Global watermarking embedding was applied to 2000 images, while the selective forensics method of this invention only applied watermarking to selected high-risk face images. The total overhead was reduced by 86.15%, as shown in Table 2.

[0133] Table 2 Comparison of computational overhead between global watermark embedding and selective forensics

[0134]

[0135] (III) Effectiveness of the Identity Watermark Self-Verification Mechanism

[0136] Traditional methods for detecting semi-fragile watermarks rely on the watermark error rate. This approach may fail to demonstrate the vulnerability (high error rate) of unknown Deepfake models, leading to false positives. The "self-verification" mechanism of this invention compares the decoded features F... rec and detection features F det The mechanism uses identity consistency to determine authenticity, thus avoiding this problem. The effectiveness of this mechanism lies in its ability to correctly handle all situations: 1. For genuine images (including benign distortions) where the image identity remains unchanged, F... rec With F det The similarity will be very high; 2. For image tampering that does not destroy the watermark, F rec Still in her original identity, F det The two are inconsistent, being a forged new identity. rec With F det The similarity will be very low; 3. For image tampering that destroys the watermark, F will be... rec For invalid or random characteristics, F det The two are inconsistent, being a forged new identity. rec With F det The similarity will be very low. Therefore, regardless of whether the watermark is robust or vulnerable under a specific attack, S2-Mark can pass the detection of F. det and F rec Inconsistencies in identity between individuals are used to accurately identify forgeries.

[0137] Table 3 Identity Consistency under Different Bit Error Rates

[0138]

[0139] Table 3 shows the tests conducted on the self-verification mechanism under different bit error rates during attacks of varying strengths. Under benign distortion, the method of this invention exhibits an extremely low bit error rate (0.000%), achieved through M... rec The characteristic of recovery F rec In good condition, with F detConsistent with previous deepfake models, it was determined to be genuine. In contrast, GANimation and StarGan, under known deepfake distortion, showed lower BER but a sharp drop in Sim (0.37–0.44), thus being determined to be fake. For unknown deepfake models (such as Uniface) or even more powerful deepfake noise, the BER was higher (16.17%–50%), and the Sim was also very low (0.11–0.28), thus being determined to be fake.

[0140] Experiments have shown that regardless of whether a Deepfake attack can destroy the watermark, it will inevitably destroy the facial identity information, leading to F... det and F rec The consistency between them is significantly reduced. Therefore, S2-Mark's self-verification mechanism is extremely robust and can accurately detect both known and unknown attacks. Its core logic is that any forgery that tampers with the identity, whether based on GAN or other emerging architectures, cannot maintain consistency with the original embedded features while destroying the identity.

[0141] (iv) Deepfake detection

[0142] Because 128-dimensional identity features carry more identity information, testing was conducted on images with a size of 256×256. The detection performance (AUC) of S2-Mark was compared with several state-of-the-art passive detectors and an active forensics method, testing their generalization ability against eight different deepfake attacks (including Uniface, HyperReenact, etc., which were not seen during training). For the forgery detection phase of S2-Mark, the forged image was a watermarked image subjected to a deepfake attack, while the real image was a watermarked image with benign distortion.

[0143] Table 4 shows the detection results for Deepfake.

[0144]

[0145] Table 4 compares the performance of four mainstream passive deepfake detectors, including traditional and state-of-the-art methods. Passive detectors exhibit severely insufficient generalization ability when facing unknown or hyper-realistic forgeries (such as StyleMask), with generally low AUC values ​​(the lowest being only 34.77%). Even newer methods like CADDM and SBls struggle to handle all types of attacks. In contrast, S2-Mark demonstrates near-perfect detection performance on all eight deepfake attacks, with AUC values ​​all above 98%, approaching 100% on most attacks. This decisively proves that the active forensics framework of this invention has an overwhelming generalization advantage over passive detection in defending against deepfakes.

[0146] In HiSD attacks that are below average, if HiSD only modifies the Bangs attribute of a face image and does not substantially alter the face identity, Sim(F) rec ,F det The value hovered around 0.7, leading to misjudgment.

[0147] In summary, this invention proposes an efficient selective proactive forensics framework called S2-Mark, aiming to address the limitations of existing Deepfake defense technologies, such as poor generalization ability and high computational cost. This framework first uses a "High-Risk Face Quantization Assessment" (HrFQA) system to accurately filter easily forged targets, reducing the overhead of watermark embedding. Simultaneously, S2-Mark introduces an innovative multi-scale, self-verifying watermark network based on identity features. It determines authenticity by calculating the cosine similarity between decoded features and the identity features of the test image, thus achieving robust forensics without the need for the original watermark. Experiments on the CelebA-HQ and COCO datasets demonstrate that this method possesses accurate filtering capabilities, high visual quality, and strong robustness. Its Deepfake detection accuracy also outperforms mainstream passive detectors.

[0148] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for detecting forged images based on identity watermark self-verification, characterized in that, Includes the following steps: High-risk face screening: The input images are assessed for risk through a high-risk face quantitative evaluation system, and high-risk face images that are easily forged with high quality are screened out; Identity feature watermarking embedding: For the selected high-risk face images, the binarized identity features are embedded as watermark information into the image through a multi-scale identity feature watermarking embedding network to generate a watermarked image; the multi-scale identity feature watermarking embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder and a watermark discriminator. Self-verification detection: Watermark decoding is performed on the image to be tested to obtain the restored identity features, the cosine similarity between the restored identity features and the identity features extracted from the image itself is calculated, and the authenticity of the image is determined based on the similarity threshold.

2. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The risk assessment steps of the high-risk facial recognition quantitative assessment system include: Perform face detection and standardization on the input image, and extract the standardized face image; Extract a set of fine-grained attributes from the standardized face image, the set of fine-grained attributes including a subset of image quality attributes and a subset of face structure attributes; Based on the formal concept analysis method, a formal background K = (X, A, I) is constructed with standardized face images as objects and the set of fine-grained attributes as attributes. Here, X is the set of standardized face images, A is the union of image quality attributes and face structure attributes, and I is the association between the image and the attribute. Based on the formal background, a fine-grained concept C = (X', A') is generated using the Galois join operator. Here, A' represents the set of all attributes shared by a subset of objects; X' represents the set of all objects that satisfy a certain set of common attributes. Based on predefined ideal high-risk attribute profiles and non-ideal attribute profiles, the susceptibility index of each fine-grained concept is calculated. Granular computing is used to organize the fine-grained concept into granular levels with different extensional sizes, and to calculate the comprehensive susceptibility score for each granular level. Based on the comprehensive susceptibility score, a high-risk granularity level is selected, and the standardized face image corresponding to this level is determined to be a high-risk face image.

3. The forged image detection method based on identity watermark self-verification according to claim 2, characterized in that, The image quality attributes include high brightness and high contrast, and the facial structure attributes include frontal pose, high symmetry, and complete facial features.

4. The forged image detection method based on identity watermark self-verification according to claim 2, characterized in that, The susceptibility index calculation formula for each fine-grained concept is as follows: S(C)=α|A'∩ITP|-β|A'∩NTP| Where S(C) represents the susceptibility index of concept C, α represents the weight coefficient of ideal attribute matching, β represents the weight coefficient of non-ideal attribute matching, ITP represents the ideal high-risk attribute profile, and NTP represents the non-ideal attribute profile. The particle size hierarchy L k The division formula is: Among them, L k Let C be the k-th granularity level, where k is the size of the concept extension, i.e., the number of images contained in the image subset X' of a single fine-grained concept, and C is a single fine-grained concept. It is the set of all fine-grained concepts; The comprehensive susceptibility scoring formula for each granularity level is as follows: in, This represents the average susceptibility index for all concepts at this level. This indicates the total coverage of this level.

5. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The implementation process of the identity watermark generator is as follows: Principal component analysis is used to compress the 512-dimensional original face identity feature vector into a vector of length L, and then binarization is performed by a STE-based residual autoencoder to obtain the binarized identity feature M. bin M is generated through a message generator. bin The data is expanded into a spatial feature map through linear layers, nearest neighbor interpolation, and convolution, which is then used for multi-scale fusion.

6. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The watermark encoder is used to receive the high-risk face image and the corresponding binary identity watermark information, and fuse features from the previous layer of the decoder, features from the corresponding skip connections of the encoder, and watermark information shaped and matched with the current scale at multiple scales during the upsampling process to generate a watermarked image; the skip connections of the watermark encoder are provided with a multi-scale fusion module, which uses a variety of convolution kernels of different sizes and combines spatial and channel attention mechanisms to fuse the multi-scale features from the encoder and then pass them to the decoder; The watermark discriminator is a PatchGAN-based discriminator used to distinguish the watermarked image from the original high-risk face image. The watermark decoder is used to decode and recover binary identity watermark information from images that may be subject to noise attacks.

7. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The method further includes a combined noise layer step used when training the multi-scale identity feature watermark embedding network, specifically including: creating a gradient-free copy of the watermarked image; applying a randomly selected noise operation to the gradient-free copy to obtain a noisy image and calculating the noise change amount; adding the noise change amount as a constant residual back to the original gradient-carrying watermarked image to obtain a noisy image for the input of the watermark decoder.

8. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The total loss function of the multi-scale identity feature watermarking embedding network is: Where λ1, λ2, and λ3 are weight parameters. For watermark encoder loss, For the loss of the watermark decoder, To combat the losses.

9. The forged image detection method based on identity watermark self-verification according to claim 1, characterized in that, The specific judgment rule of the self-verification detection is as follows: set the cosine similarity threshold τ = 0.

7. When the cosine similarity Sim between the recovered identity features and the identity features of the image to be tested is ≥ 0.7, the image is judged to be a real image; when Sim < 0.7, the image is judged to be a fake image.

10. A forged image detection system based on identity watermark self-verification, characterized in that, For implementing the method as described in any one of claims 1-9, the system comprises: The high-risk face screening module is used to assess the risk of input images through a high-risk face quantitative evaluation system and screen out high-risk face images that are easily forged with high quality. The identity feature watermarking embedding module is used to embed binarized identity features as watermark information into the selected high-risk face images through a multi-scale identity feature watermarking embedding network to generate a watermarked image. The multi-scale identity feature watermarking embedding network adopts U-Net as the backbone architecture and includes an identity watermark generator, a watermark encoder, a watermark decoder, and a watermark discriminator. The self-verification detection module is used to decode the watermark of the image under test, obtain the recovered identity features, calculate the cosine similarity between the recovered identity features and the identity features extracted from the image under test itself, and determine the authenticity of the image based on the similarity threshold.