An AI-generated content semantic layer steganographic tracing method and system

CN122548713APending Publication Date: 2026-08-11邹宇豪
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-12
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0005]为了解决现有AI生成内容溯源方案中水印抗攻击性弱、不支持跨模态统一编码、且缺乏不可篡改存证机制的技术问题,本发明提供了一种AI生成内容的语义层隐形编码溯源方法及系统

Benefits of technology

本发明通过在语义结构层而非信号层或元数据层进行水印编码和嵌入,使得水印信息与内容的语义本质深度绑定。由于语义结构在内容经历格式转换、压缩、翻译、改写、裁剪等各类操作后仍保持相对稳定,本发明的水印具有显著优于现有方案的抗攻击能力,在文本经历两次机器翻译后、图像仅保留8%区域时、音频经历降噪和变调处理后仍能以不低于75%的成功率提取水印信息。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122548713A_ABST
    Figure CN122548713A_ABST
Patent Text Reader

Abstract

The application provides an AI-generated content semantic layer invisible coding traceability method and system, which is used to solve the technical problem that the signal layer watermark and metadata mark in the existing AI content traceability scheme are easily lost after the content undergoes format conversion, compression, translation and other processes, causing the traceability chain to be interrupted. The method comprises: generating traceability information when AI model generates content; encoding the traceability information into a digital watermark sequence, and selecting a corresponding semantic layer coding strategy according to the data type of the content; embedding the digital watermark sequence into the human perception insensitive area or semantic structure layer of the content; generating a notarization identifier based on the traceability information and storing it in a tamper-proof storage medium; extracting the watermark sequence from the content to be detected by a detection model, restoring the traceability information and comparing it with the notarization identifier to confirm the authenticity of the content source.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence content security and copyright protection technology, specifically to a method and system for tracing the source of AI-generated content through semantic layer stealth encoding. Background Technology

[0002] With the rapid development of artificial intelligence technologies such as large language models, image generation models, speech synthesis models, and video generation models, AI-generated content has been widely applied in various fields such as social media, news, content creation, and digital marketing. Multimodal AI-generated content, including text, images, audio, and video, is flooding the internet at an unprecedented speed and scale, bringing a series of technical challenges such as unclear copyright ownership, difficulty in tracing the source of false information, and difficulty in obtaining evidence of infringement.

[0003] Currently, various technical solutions have been proposed in the industry for tracing the source and protecting the copyright of AI-generated content. Regarding image watermarking, existing solutions identify the source of content by embedding invisible watermarks in the frequency domain or pixel level of the image. For text watermarking, existing solutions embed identification information by selecting specific word sequences during text generation. Additionally, there are solutions that achieve content tracing by embedding tagging information (such as C2PA metadata tags) in file metadata. However, all of these solutions have significant technical limitations: First, most existing solutions only support a single data type and cannot provide a unified encoding tracing framework for multimodal AI-generated content such as text, images, audio, and video. Second, existing solutions mainly embed watermarks at the signal layer (such as pixel values ​​and waveforms) or the metadata layer (such as file headers). These layers of watermarks are easily lost or invalidated after common operations such as machine translation, synonym rewriting, format conversion, image cropping, or compression. Third, existing solutions lack an immutable evidence preservation mechanism; the credibility of their tracing results depends on the integrity of the watermark itself. Once the watermark is damaged or tampered with, independent third-party verification capabilities cannot be provided.

[0004] Therefore, there is a need for an AI-generated content tracing method that can perform implicit encoding at the semantic structure level, support cross-modal unified processing, have strong anti-attack capabilities, and combine an immutable evidence storage mechanism, in order to solve the problems of watermarks being easily destroyed, single-modal limitations, and lack of credible evidence storage in existing technologies. Summary of the Invention

[0005] To address the technical problems of existing AI-generated content tracing schemes, such as weak watermark resistance to attacks, lack of support for cross-modal unified encoding, and lack of tamper-proof evidence preservation mechanisms, this invention provides a semantic layer implicit encoding tracing method and system for AI-generated content.

[0006] In one aspect, this invention provides a semantic layer stealth encoding method for tracing the source of AI-generated content. When an AI model generates content, it generates source information to uniquely identify the source of the content. The source information is encoded into a digital watermark sequence, and a corresponding semantic layer encoding strategy is selected based on the data type of the content. The data type includes at least one of text data, image data, audio data, and video data. The encoded digital watermark sequence is embedded into a human-perception-insensitive region or semantic structure layer of the content. The human-perception-insensitive region includes high-texture-complexity regions in images, high-frequency masking regions in audio, and motion-blurred regions in videos. The embedding does not change the human-perception quality of the content. An evidence identifier is generated based on the source information and stored in an immutable storage medium. The digital watermark sequence is extracted from the content to be detected using a detection model. The source information is reconstructed based on the extracted digital watermark sequence, and the reconstructed source information is compared with the evidence identifier to confirm the authenticity of the content source.

[0007] The aforementioned method generates source information and performs semantic layer encoding simultaneously during the AI ​​content generation stage. This embeds the watermark information deep into the semantic structure of the content rather than in the surface signal, fundamentally improving the watermark's resistance to various attacks. Compared to traditional signal layer encoding and metadata layer marking, semantic layer encoding embeds the watermark at the semantic structure level of the content. Even if the content undergoes format conversion, compression, translation, or rewriting, the core features of the semantic structure are preserved, thus the watermark information is not lost due to changes in the surface signal. Furthermore, by selecting corresponding semantic layer encoding strategies based on different data types, the same source tracking system can uniformly cover multiple modalities such as text, images, audio, and video, overcoming the limitation of existing technologies that can only handle a single modality. The encoded watermark is embedded in human-perceptually insensitive areas or the semantic structure layer. These human-perceptually insensitive areas include high-texture-complexity regions in images, high-frequency masking regions in audio, and motion-blurred regions in videos, ensuring the watermark's concealment. Users cannot perceive the watermark's presence during normal use, and the content quality remains unaffected. By storing traceability information in an immutable storage medium, a reliable evidence independent of the watermark itself is established, making the traceability verification results verifiable by third parties. Even if the watermark is partially damaged, the generation time and source information of the content can still be confirmed through the evidence record. Finally, an automated watermark extraction and traceability information restoration is achieved through a detection model, which is then compared with the evidence record, forming a complete closed loop from content generation, encoding embedding, evidence storage to detection and verification, making the entire lifecycle of AI-generated content traceable.

[0008] In some preferred embodiments, the traceability information includes at least two of the following: generation model identifier, user identity identifier, generation timestamp, content sequence number, and platform identifier; the digital watermark sequence contains n watermark units, where n is not less than 32. By including traceability information with multiple identifier fields, the source of content can be accurately located from multiple perspectives such as model, user, time, and platform dimensions, meeting the query needs of different traceability scenarios. A watermark sequence length of not less than 32 watermark units ensures sufficient encoding capacity to carry the aforementioned multi-dimensional traceability information and leaves room for encoding redundancy and error correction.

[0009] In some preferred embodiments, when the data type is text data, the semantic layer encoding strategy includes character-level semantic encoding and / or lexical-level semantic encoding. Character-level semantic encoding uses visually indistinguishable character variants to represent watermark information, including at least one of Unicode zero-width characters, homographs, combined characters, and bidirectional text control characters. Lexical-level semantic encoding performs lexical substitution based on a pre-defined semantic equivalence lexicon, where each word pair or phrase corresponds to a watermark unit. Character-level encoding utilizes Unicode character variants indistinguishable to the human eye to carry information, without altering the visual presentation and semantic content of the text, thus possessing high concealment. Lexical-level encoding leverages the synonym substitution characteristic of natural language to encode watermark information into word selection; even if the text is partially rewritten, the untouched word selections still retain watermark information. Both encoding strategies can be used individually or in combination; when used in combination, they can significantly improve encoding capacity and attack resistance redundancy.

[0010] In some preferred embodiments, when the data type is image data, the semantic layer coding strategy includes frequency-domain based semantic coding and / or spatial-domain based semantic coding. The frequency-domain based semantic coding involves dividing the image into multiple image blocks, performing a frequency-domain transformation on each image block, and embedding watermark information in the low-to-mid-frequency regions of the frequency domain coefficients. The spatial-domain based semantic coding involves detecting textured or edge regions of the image and fine-tuning pixel values ​​in regions where the texture complexity exceeds a preset threshold. Frequency-domain coding selects low-to-mid-frequency regions for watermark embedding, utilizing the robustness of low-to-mid-frequency components to compression and filtering operations, avoiding the drawback of high-frequency regions being easily eliminated by lossy compression. Spatial-domain coding utilizes the low sensitivity of human vision to textured regions, performing minute pixel adjustments in these regions to ensure the watermark is invisible while possessing local resistance to geometric attacks such as cropping.

[0011] In some preferred embodiments, the embedding without altering the human-perceived quality of the content includes: when the content is text, the semantic similarity before and after embedding is not less than 0.90; when the content is image content, the peak signal-to-noise ratio before and after embedding is not less than 40dB; when the content is audio content, the signal-to-noise ratio before and after embedding is not less than 30dB; and when the content is video content, the structural similarity before and after embedding is not less than 0.95. These quantitative indicators correspond to industry-standard thresholds for content quality assessment of each modality, ensuring that after watermark embedding, the content undergoes no perceptible change to human senses, thus guaranteeing traceability without compromising the content's usability.

[0012] In some preferred embodiments, the digital watermark sequence extracted in the detection and verification step is resistant to attacks. After the content to be detected has undergone at least one of the following attack processes: machine translation attack, synonym rewriting attack, cropping attack, compression attack, rotation attack, transcoding attack, etc., the watermark extraction success rate is not less than 75%. This resistance to attacks stems from the inherent advantage of semantic layer encoding: the watermark information is embedded in the semantic structure layer of the content, rather than the surface signal. The semantic structure remains relatively stable after the above attack processes, so the watermark information can be successfully extracted and restored at a high rate.

[0013] In some preferred embodiments, the detection model includes at least one of a text detection model and an image detection model; the text detection model is based on a sequence labeling architecture and is used to output the watermark probability distribution of each character or word in the text to be detected; the image detection model is based on a convolutional neural network architecture and is used to output the watermark presence probability in the image to be detected and the decoded watermark sequence; the watermark presence determination threshold of the detection model is not less than 0.6. Compared with traditional rule matching methods, the deep learning-based detection model can learn the statistical patterns of watermark embedding and can still effectively identify watermark features after the content has undergone attack deformation. Setting the determination threshold to not less than 0.6 controls the false detection rate while ensuring detection sensitivity.

[0014] On the other hand, the present invention also provides a semantic layer stealth coding tracing system for AI-generated content. The system includes: a tracing information generation module, which generates tracing information to uniquely identify the source of the content when the AI ​​model generates content; a semantic layer encoding module, which encodes the tracing information into a digital watermark sequence and selects a corresponding semantic layer encoding strategy according to the data type of the content; a semantic layer embedding module, which embeds the encoded digital watermark sequence into a human-perceptually insensitive region or semantic structure layer of the content, wherein the human-perceptually insensitive region includes a high-texture complexity region in an image, a high-frequency masking region in audio, and a motion-blurred region in a video, and the embedding does not change the human-perceptual quality of the content; an evidence storage module, which generates an evidence storage identifier based on the tracing information and stores the evidence storage identifier in an immutable storage medium; and a detection and verification module, which extracts the digital watermark sequence from the content to be detected through a detection model, restores the tracing information based on the extracted digital watermark sequence, and compares the restored tracing information with the evidence storage identifier to confirm the authenticity of the source of the content. The system decouples the various functional links of traceability coding through modular design. Each module can be deployed or upgraded independently, and the modules communicate with each other through standardized data interfaces, supporting flexible expansion of new data types and coding strategies.

[0015] In another aspect, the present invention also provides an electronic device including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the steps of the above-described method.

[0016] In another aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.

[0017] The present invention has the following beneficial effects: This invention encodes and embeds watermarks at the semantic structure layer, rather than the signal or metadata layer, thus deeply binding the watermark information to the semantic essence of the content. Because the semantic structure remains relatively stable even after various operations such as format conversion, compression, translation, rewriting, and cropping, the watermark of this invention has significantly better resistance to attacks than existing solutions. Even after text undergoes two machine translations, images retain only 8% of their area, and audio undergoes noise reduction and pitch shifting, the watermark information can still be extracted with a success rate of no less than 75%.

[0018] This invention establishes a unified encoding framework covering four modalities—text, image, audio, and video—by automatically selecting the corresponding semantic layer encoding strategy based on the data type. This overcomes the technical limitation of existing solutions that can only handle a single modality, enabling the same traceability system to uniformly manage and track various types of AI-generated content.

[0019] This invention establishes independent evidence storage by storing traceability information in an immutable storage medium, so that traceability verification does not completely depend on the integrity of the watermark itself. Even if the content is significantly modified and the watermark is partially damaged, traceability verification can still be completed by comparing the remaining watermark information with the evidence storage record. At the same time, the evidence storage record can be used as verifiable evidence by third parties for copyright disputes and infringement evidence collection.

[0020] This invention embeds watermarks into areas insensitive to human perception or semantic structure layers. By setting perceptual quality quantification thresholds for each modality, it ensures that the content quality remains imperceptible after embedding. This achieves comprehensive traceability capabilities without affecting the normal use and dissemination of the content, thus balancing copyright protection and user experience. Attached Figure Description

[0021] Figure 1 This is a schematic diagram of the overall architecture of the semantic layer implicit coding tracing system for AI-generated content provided in an embodiment of the present invention. Detailed Implementation

[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0023] It should be noted that when a component is referred to as "connected to" or "communicationally connected to" another component, it can be directly connected to or communicationally connected to the other component, or there may be an intervening component. When a component is considered to be "set on" another component, it can be directly set on the other component, or there may be an intervening component. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0024] With the rapid iteration of artificial intelligence technologies such as large language models, diffusion models, and speech synthesis models, the quality and quantity of AI-generated content have grown exponentially. In practical applications, AI-generated text, images, audio, and video content are widely disseminated and used for secondary creation in scenarios such as social media, news platforms, and e-commerce. However, existing source tracing schemes mainly rely on signal layer watermarking or metadata tagging. After the content undergoes common processing such as format conversion, compression, translation, and cropping, the watermark information is easily lost or becomes invalid, leading to the interruption of the source tracing chain. This invention proposes a source tracing scheme that performs invisible encoding at the semantic structure layer, fundamentally improving the watermark's resistance to attacks and cross-modal applicability.

[0025] Before providing a detailed description of the method embodiments of the present invention, the terms and concepts involved in the present invention will first be defined.

[0026] The "semantic layer" refers to the semantic structure of the content, distinct from the signal layer (such as pixel values ​​and waveform sample values) and the metadata layer (such as file headers and EXIF ​​information). For text data, the semantic layer includes vocabulary selection, syntactic structure, and semantic relationships; for image data, it includes frequency domain structural features and texture distribution features; for audio data, it includes spectral structure and acoustic features; and for video data, it includes inter-frame temporal relationships and motion features.

[0027] A "digital watermark sequence" refers to a binary or multi-level encoded sequence composed of multiple watermark units. Each watermark unit carries one information bit, and the entire sequence carries complete traceability information.

[0028] A "semantic equivalence lexicon" refers to a pre-built vocabulary lookup table that contains pairs of words or phrases that are semantically identical or highly similar but have different expressions. It is used to encode watermark information through word selection without changing the meaning of the text.

[0029] "Evidence identifier" refers to a unique identifier generated based on traceability information through hash operation or other digest algorithm, used to establish a binding relationship with the original content in an immutable storage medium.

[0030] "Human perception insensitive areas" refer to areas or dimensions in content where changes are difficult for human senses to perceive, such as high-texture-complexity areas in images, high-frequency masking areas in audio, and motion-blurred areas in videos.

[0031] Reference Figure 1 The semantic layer invisible coding tracing system 100 for AI-generated content provided in this embodiment of the invention includes a tracing information generation module 110, a semantic layer coding module 120, a semantic layer embedding module 130, an evidence storage module 140, and a detection and verification module 150.

[0032] The source tracing information generation module 110 is communicatively connected to the AI ​​content generation engine 200. It generates source tracing information to uniquely identify the source of content, either simultaneously with or before the AI ​​content generation engine 200 outputs content. The source tracing information generation module 110 receives generation context information from the AI ​​content generation engine 200, including but not limited to the user's identity information, the engine's model version information, and the generation time information. Based on this context information, it assembles a source tracing information data packet. The source tracing information generation module 110 outputs the assembled source tracing information data packet to the semantic layer encoding module 120 and the evidence storage module 140, respectively.

[0033] The semantic layer encoding module 120 receives source information data packets from the source information generation module 110 and receives the raw content and its data type identifier output by the AI ​​content generation engine 200. The semantic layer encoding module 120 internally includes an encoding strategy routing submodule 121 and multiple modal encoders. The encoding strategy routing submodule 121 distributes the encoding task to the corresponding modal encoder based on the data type identifier: the text encoder 122 processes text data, the image encoder 123 processes image data, the audio encoder 124 processes audio data, and the video encoder 125 processes video data. Each modal encoder converts the source information into a digital watermark sequence suitable for its corresponding modality and outputs it to the semantic layer embedding module 130.

[0034] The semantic layer embedding module 130 receives the digital watermark sequence and the original content from the semantic layer encoding module 120 and performs an embedding operation. The semantic layer embedding module 130 internally includes an embedding position analysis submodule 131 and an embedding execution submodule 132. The embedding position analysis submodule 131 analyzes the structural features of the original content to determine suitable human-perceptually insensitive regions or semantic structure locations for watermark embedding; the embedding execution submodule 132 performs the watermark embedding operation at the determined locations and performs a quality assessment of the embedded content to ensure that the embedding does not alter the human-perceptual quality. The semantic layer embedding module 130 outputs the watermarked content as the final published content.

[0035] The evidence storage module 140 receives traceability information data packets from the traceability information generation module 110, generates an evidence storage identifier based on the data packets, and writes the evidence storage identifier and associated metadata into an immutable storage medium. The evidence storage module 140 internally includes a hash calculation submodule 141 and a storage writing submodule 142. The hash calculation submodule 141 performs a hash operation on the traceability information data packets to generate the evidence storage identifier; the storage writing submodule 142 writes the evidence storage identifier, traceability information digest, generation timestamp, etc., into the immutable storage medium. This application embodiment does not limit the specific implementation of the immutable storage medium, which can be a blockchain network, a distributed ledger, a trusted timestamp service, or a database system with anti-tampering auditing functions.

[0036] The detection and verification module 150 is used to perform watermark extraction and source tracing verification on the content to be detected. Internally, the detection and verification module 150 includes a watermark extraction submodule 151, an information restoration submodule 152, and a comparison and verification submodule 153. The watermark extraction submodule 151 incorporates one or more detection models to analyze the content to be detected and extract any possible digital watermark sequences. The information restoration submodule 152 performs a decoding operation based on the extracted watermark sequences to restore the source tracing information. The comparison and verification submodule 153 compares the restored source tracing information with the evidence storage identifier stored in the evidence storage module 140 and outputs the verification result. The detection and verification module 150 and the evidence storage module 140 are connected via a secure communication channel to ensure data integrity during the comparison process.

[0037] The data flow between the above modules is as follows: AI content generation engine 200 → source information generation module 110 → semantic layer encoding module 120 → semantic layer embedding module 130 → final published content; simultaneously, source information generation module 110 → evidence storage module 140 → tamper-proof storage medium; during the detection phase, the content to be detected → detection verification module 150 ↔ evidence storage module 140 → verification result. Each module can be deployed on the same server or distributed across different nodes. Modules interact with each other via standard communication protocols such as RESTful API, gRPC, or message queues; this application does not impose any limitations on this.

[0038] In another embodiment, this application provides a semantic layer stealth encoding method for tracing the source of AI-generated content, comprising the following steps: a source information generation step, wherein when the AI ​​model generates content, source information is generated to uniquely identify the source of the content; a semantic layer encoding step, wherein the source information is encoded into a digital watermark sequence, and a corresponding semantic layer encoding strategy is selected according to the data type of the content; a semantic layer embedding step, wherein the encoded digital watermark sequence is embedded into a human-perceptually insensitive area or semantic structure layer of the content; a proof preservation step, wherein a proof preservation identifier is generated based on the source information, and the proof preservation identifier is stored in an immutable storage medium; and a detection and verification step, wherein the digital watermark sequence is extracted from the content to be detected by a detection model, the source information is restored based on the extracted digital watermark sequence, and the restored source information is compared with the proof preservation identifier to confirm the authenticity of the source of the content.

[0039] The method provided in this application constructs a complete traceability chain from the source of AI content generation to final verification. The core technical approach of this method lies in elevating the carrier layer of traceability information from the traditional signal layer and metadata layer to the semantic structure layer. Signal layer watermarking (such as fine-tuning of image pixel values ​​and overlaying of audio waveforms) essentially manipulates the physical representation of content. When content undergoes compression, format conversion, or other operations, it is precisely the physical representation layer that is first affected. While metadata tags do not affect content quality, they are attached to the outer structure of the file format, and can be stripped away by any format conversion or simple copy-paste operation. In contrast, semantic structure is the essential attribute of content—the semantic relationships of text remain valid after translation, the frequency domain structure of images is largely preserved after compression, and the acoustic features of audio can still be traced after pitch shifting. Therefore, encoding watermark information into the semantic layer is equivalent to binding the traceability identifier to the "essence" of the content, giving it robustness far exceeding traditional solutions. Simultaneously, this method achieves unified cross-modal processing through a data type routing mechanism, eliminating the need to design independent systems for each modality and reducing engineering complexity. The evidence storage mechanism, acting as a second verification channel independent of the watermark, ensures that even if the watermark is partially damaged under extreme attacks, traceability can still be achieved through cross-verification of the remaining information and the evidence storage records, forming a dual-protection system. The detection and verification process incorporates a deep learning-based detection model, leveraging the model's generalization capabilities to handle various unseen attack variants, ensuring the practicality and scalability of the verification process.

[0040] In some implementations, the source information generation step specifically includes the following: Source information is a structured data packet carrying all the key information needed to identify the source of AI-generated content. This information is automatically generated by the source information generation module 110 at the same time as the AI ​​model outputs content, without manual intervention, thus ensuring that each piece of AI-generated content carries a source marker from the very beginning. The reason for choosing to generate source information during the synchronous stage of content generation rather than the post-generation stage is that synchronous generation can capture the complete context at the time of generation (model state, user session, generation parameters, etc.), which may be lost or overwritten in the post-generation stage. Synchronous generation also eliminates the time window between content generation and marking, avoiding the risk of unmarked copying or distribution of content within this window. This step receives generation event notifications from the AI ​​content generation engine 200 and simultaneously outputs the generated source information data packet to the semantic layer encoding module 120 (for subsequent encoding embedding) and the evidence storage module 140 (for independent evidence storage), forming a branching propagation structure of information. In specific implementations, the composition of the traceability information fields can be flexibly configured according to the application scenario. For example, in the content copyright protection scenario, the focus can be on user identity identifiers and timestamps, while in the false information traceability scenario, the focus can be on generation model identifiers and platform identifiers. This application does not impose any restrictions on this.

[0041] In its implementation, this method establishes a binding relationship between content and its source by automatically generating traceability information during the AI ​​content generation synchronization phase. Compared to existing technologies that perform post-release tagging after content publication, this method eliminates the time gap between generation and tagging, avoiding the risk of untagged content being propagated during this gap. Furthermore, synchronous generation can directly obtain the runtime context of the AI ​​generation engine (such as model parameter hashes, user session identifiers, inference call chains, etc.), and the richness of this runtime information far exceeds the finite element information captured by post-release tagging. From a system reliability perspective, the synchronous generation mechanism treats traceability tagging as a mandatory step in the AI ​​generation pipeline, rather than an optional post-processing step, ensuring comprehensive coverage without omissions at the architectural level.

[0042] In some implementations, the semantic layer encoding step specifically includes the following: Semantic layer encoding is the process of converting abstract source information data packets into digital watermark sequences that can be embedded in content of a specific modality. The core mechanism of this process lies in encoding strategy routing: the system first identifies the data type (text, image, audio, or video) of the content to be embedded, and then distributes the encoding task to the encoder of the corresponding modality for execution. The reason for adopting a routing distribution design instead of a uniform encoding design is that different modalities of content have drastically different information carrying characteristics and human perception characteristics—the information carrying dimension of text is discrete word selection and character sequences, the information carrying dimension of images is continuous pixel values ​​and frequency domain coefficients, and the information carrying dimension of audio is the signal energy distribution in the time and frequency domains. A uniform encoding scheme cannot achieve the optimal balance of capacity, concealment, and robustness for the characteristics of each modality, while the routing distribution design allows each modal encoder to optimize independently. This step receives source information data packets from the source information generation module 110 and the original content and data type identifier output by the AI ​​content generation engine 200, and outputs a digital watermark sequence adapted to the target modality to the semantic layer embedding module 130. In the specific implementation, when the AI ​​generation engine outputs multimodal content (such as a text-and-image article), the encoding strategy routing submodule 121 can call the corresponding modal encoder to encode the text part and the image part independently, so that each modality independently carries complete watermark information, thereby improving information redundancy.

[0043] In practical implementation, the coding strategy routing mechanism achieves unified support for multiple modalities through a single traceability framework. Compared to existing technologies that design independent systems for each modality, this method significantly reduces engineering complexity through a unified routing entry point and standardized encoder interfaces. Another technical advantage of routing distribution is its scalability: when new content modalities (such as 3D models, code files, etc.) need to be supported, only the corresponding modal encoder needs to be developed and registered in the routing submodule, without modifying the overall architecture or existing encoders. Furthermore, for multimodal mixed content, the design of independently encoding each modal component brings redundancy advantages—even if an attacker destroys the watermark of one modality (such as deleting character variants in text), other modalities (such as image frequency domain watermarks) remain intact, and the overall traceability capability will not be completely lost due to a single point of failure.

[0044] In some implementations, the semantic layer embedding step specifically includes the following. Semantic layer embedding is the operation of physically loading a digital watermark sequence into the content, with the core constraint that the embedding does not change the human-perceived quality of the content. The technical essence of this step lies in finding the optimal balance between "information embedding amount" and "perceived invisibility". The embedding position analysis submodule 131 first performs structural analysis on the original content to identify human-perceived insensitive areas—for text, these areas are the positions of character-level variants and semantically equivalent word selection positions that are indistinguishable to the human eye; for images, these areas are areas with high texture complexity and low-frequency components in the frequency domain; for audio, these areas are weak signal areas masked by strong signals and high-frequency bands; for video, these areas are inter-frame regions with violent motion and areas with complex spatial textures. The reason for choosing human-perceived insensitive areas rather than uniformly distributed embedding is that the human visual system, auditory system, and language understanding system all have the characteristics of selective attention and masking effects. Small changes in high-complexity areas are masked by the rich information around them and go unnoticed, while the same changes in flat areas are easily noticed. The embedding execution submodule 132 performs a watermark writing operation at a determined location according to the corresponding modality's embedding algorithm, and immediately evaluates the quality of the embedded content after writing. The input to this step is the digital watermark sequence and the original content, and the output is the final published content after watermark embedding. It forms a parallel relationship with the subsequent evidence preservation step: after the embedding step is completed, the watermarked content is output for publication, while the evidence preservation step independently solidifies the traceability information into tamper-proof storage.

[0045] In practice, the adaptive embedding strategy based on perceptual characteristic analysis ensures that the watermark is completely invisible to human users. Compared to existing embedding schemes with fixed positions and strengths, this method dynamically determines the embedding position and strength based on the actual structural features of the content, making the embedding operation adaptive to the perceptual characteristics of each specific piece of content. This means that more watermark information can be embedded in images with rich textures (because there are more insensitive areas), while the embedding amount can be appropriately reduced for images with simple textures to ensure concealment. This adaptive mechanism allows the watermarking system to achieve an optimal balance between capacity and concealment when facing AI-generated content with various characteristics, rather than adopting a one-size-fits-all fixed strategy.

[0046] In some implementations, the evidence preservation step specifically includes the following: The function of the evidence preservation step is to establish an immutable record of tracing evidence independent of the watermark itself. This step is logically parallel to the semantic layer encoding and semantic layer embedding steps—the tracing information is simultaneously distributed to the encoding / embedding channel and the evidence preservation channel after generation. The reason for designing an independent evidence preservation channel, rather than relying solely on the watermark itself as tracing evidence, is that any watermarking scheme is susceptible to destruction. Even though semantic layer watermarks are significantly more robust than signal layer watermarks, a large amount of watermark information may still be lost under extreme attacks (such as large-scale content rewriting or deep rewriting that only retains the core meaning). Independent evidence preservation provides a second verification path for tracing verification: even if the watermark is partially destroyed, as long as sufficient residual information can be extracted and compared with the evidence preservation record, tracing can be completed. Furthermore, the evidence preservation identifier stored in an immutable medium has legal timestamping probative value and can be used to confirm the chronological order of content generation, serving as key evidence in copyright disputes. The hash calculation submodule 141 performs a hash operation on the traceability information data packet. This application does not limit the specific hash algorithm; it can be SHA-256, SHA-3, or other cryptographically secure hash functions. The storage and writing submodule 142 writes the evidence storage identifier, along with the generated timestamp, content digest, and other metadata, into an immutable storage medium.

[0047] In practical implementation, an independent evidence preservation mechanism forms the second line of defense for the source tracing system. Compared to existing solutions that rely solely on watermarks as the sole evidence for source tracing, this method achieves redundancy through a dual-channel design of "watermark + evidence preservation." Under normal circumstances, the detection and verification phase first attempts to extract the watermark from the content and restore the complete source tracing information. If the watermark is partially damaged, a fuzzy comparison can be performed based on partial matching of the remaining watermark information and the complete information in the evidence preservation record, achieving downgraded verification through similarity threshold determination. This progressive verification strategy ensures that the source tracing system does not completely fail due to partial damage to the watermark. From an evidentiary perspective, evidence preservation records in tamper-proof storage media have chronological evidentiary value—if a copyright dispute arises between two pieces of content, the evidence preservation record generated earlier can provide strong support for the earlier creator.

[0048] In some implementations, the detection and verification step specifically includes the following: Detection and verification is a closed-loop link in the source tracing chain. Its function is to extract watermark information from the content to be detected and verify its authenticity. The core technology of this step lies in the design of the detection model—the detection model needs to be able to effectively identify and extract watermark signals even after the content may have undergone various unknown attacks. The reason for using a deep learning-based detection model instead of a rule-based decoding algorithm is that rule-based decoding algorithms rely on precise prior knowledge of the embedding position and embedding method. When the embedding position shifts or the information is distorted after the content has been attacked, the decoding capability of the rule-based algorithm drops sharply. In contrast, the deep learning-based detection model, through training on a large number of "original-attack" pairs, learns the invariant characteristics of the watermark signal under various attack transformations, thus possessing stronger generalization ability. The execution flow of the detection and verification step is as follows: The watermark extraction submodule 151 performs forward inference on the content to be detected, outputting the watermark presence probability and the initially extracted watermark sequence; if the watermark presence probability exceeds the judgment threshold, the information restoration submodule 152 performs decoding and error correction operations on the extracted watermark sequence to restore the source information; the comparison and verification submodule 153 compares the restored source information with the evidence storage records in the evidence storage module 140, outputting the final verification result (verification passed / verification failed / insufficient information). The input of this step is the content to be detected, and the output is the verification result and the restored source information.

[0049] In practical implementation, the deep learning-based detection model provides strong anti-interference capabilities for source tracing and verification. Compared to traditional reverse decoding schemes (i.e., extraction strictly following the reverse process of embedding), the deep learning detection model does not rely on precisely known assumptions about attack types, but instead learns robust features of the watermark signal through a data-driven approach. In actual deployment, the types of attacks the content to be detected may experience are unpredictable—users may rewrite text, take screenshots of images and then upload them, or transcode and share videos; the specific parameters of these operations cannot be exhaustively defined in the design. By performing data augmentation on various simulated attacks during the training phase, the deep learning model gains the ability to generalize to unknown attack variants. Furthermore, the "watermark presence probability" output design of the detection model allows for a "insufficient information" rather than an erroneous "verification failure" conclusion when the watermark is severely damaged, avoiding the legal risks of false negatives.

[0050] To further enhance the accuracy and reliability of traceability information identification, in one optional implementation, the field composition and watermark sequence specifications of the traceability information can be configured as follows: The traceability information includes at least two of the following: generation model identifier, user identity identifier, generation timestamp, content sequence number, and platform identifier. The generation model identifier identifies the type and version of the AI ​​model used to generate the content, such as "GPT-4-turbo-20240401" or "SDXL-v1.0," and its technical function is to determine the source of the content production tool from the model perspective. The user identity identifier identifies the end user who called the AI ​​generation service; it can be a unique hash value of the user account or an encrypted user ID, and its technical function is to determine the responsible party for the content from the personnel perspective. The generation timestamp records the precise moment of content generation, using the UTC standard time format accurate to the millisecond level, and its technical function is to establish the chronological order of content generation, providing a temporal basis for determining copyright priority. The content sequence number is a unique number that increments sequentially within the same user's same session, and its technical function is to distinguish multiple pieces of content generated by the same user within a short period, avoiding identification conflicts caused by insufficient timestamp accuracy. The platform identifier is used to identify the platform entity that provides AI generation services. Its technical role is to determine the service source of content in multi-platform deployment scenarios. A digital watermark sequence contains n watermark units, where n is not less than 32. When the traceability information includes the above five fields, assuming the generation model identifier encoding requires 8 bits, the user identity identifier encoding requires 16 bits, the timestamp encoding requires 10 bits, the sequence number encoding requires 8 bits, and the platform identifier encoding requires 6 bits, the total information size is 48 bits. Adding error correction redundancy and check bits, 32 watermark units are the minimum requirement to ensure encoding reliability.

[0051] In practical implementation, the multi-field combination of source information design provides multi-dimensional positioning capabilities for content sources. Compared with schemes using only a single identifier (such as a timestamp), multi-field combinations can simultaneously answer multiple source tracing questions such as "who," "when," "what tool," "on which platform," and "how many times" the content was generated, meeting the query needs in different scenarios. For example, in infringement evidence collection scenarios, accuracy down to user identity and generation time is required; in model security audit scenarios, accuracy down to model version and number of calls is required; and in platform compliance supervision scenarios, accuracy down to platform identifier and content sequence is required. The minimum watermark unit count of 32 ensures that the encoding capacity can carry all field information and leaves error correction redundancy. When a single watermark unit is damaged by an attack, the error correction code can recover the lost information bits.

[0052] To achieve efficient semantic layer encoding of AI-generated textual content, in one optional implementation, when the data type is text data, the semantic layer encoding strategy includes two paths: character-level semantic encoding and word-level semantic encoding. The two paths can be used individually or in combination.

[0053] Character-level semantic encoding utilizes visually indistinguishable character variants present in the Unicode encoding standard to carry watermark information. The Unicode standard defines a large number of character pairs that are visually identical or nearly indistinguishable, including zero-width characters (such as zero-width space U+200B, zero-width ligature U+200C, and zero-width non-ligature U+200D), homographs (such as certain font renderings of the Latin letter "a" and the Cyrillic letter "а", and the digit "0" and the Latin letter "O"), composite characters (such as appending invisible composite markers after basic characters), and bidirectional text control characters (such as left-to-right markers U+200E and right-to-left markers U+200F). The encoding rule is to insert or replace specific character variants at specific positions in the text, with each variant corresponding to a watermark unit value. For example, choosing whether to insert a zero-width space between two words can encode 1 bit of information—insertion represents "1", and no insertion represents "0". The information carrying density of character-level encoding depends on the text length and the number of available encoding positions. The technical principle behind choosing these four character variant types is as follows: zero-width characters occupy no display width and have no impact on text layout; homographs with different encodings render identically in all common fonts, making them indistinguishable to the human eye; composite characters are attached to basic characters without altering their display form; and bidirectional control characters only affect the logical direction of the text without producing visible output. These characteristics ensure that character-level encoding has zero impact on the visual presentation of text.

[0054] Lexical-level semantic encoding leverages the widespread phenomenon of synonymy in natural language to carry watermark information. The system pre-configures a semantic equivalence lexicon, which contains a large number of word pairs or phrase pairs that are semantically identical or highly similar but differ in word form. For example, word pairs such as "method / way," "get / obtain," "perform / execute," "utilize / use," and "display / show" are interchangeable in most contexts without altering the text's meaning. The encoding rule is as follows: each word pair in the semantic equivalence lexicon corresponds to one watermark unit. For replaceable positions in the text, selecting the first word in the word pair represents "0," and selecting the second word represents "1." The premise of lexical-level encoding is that substitution does not change the semantic content and grammatical correctness of the text; therefore, the construction of the semantic equivalence lexicon requires rigorous semantic similarity verification and grammatical compatibility testing. In specific implementations, semantically equivalent lexicons can be automatically constructed by calculating the semantic distance between words using word vector models (such as Word2Vec and BERT), and word pairs with semantic distance less than a preset threshold and the same part of speech can be included in the lexicon. Alternatively, they can be manually annotated by linguistic experts. This application does not limit the construction method of the lexicon.

[0055] When character-level encoding and lexical-level encoding are used in combination, the system first marks all available encoding positions in the text (including character-level and lexical-level positions), and then allocates watermark units according to a preset priority strategy. In one implementation, lexical-level positions are used first to embed core watermark information (because they are more resistant to rewriting attacks), and then character-level positions are used to embed redundant verification information (because they have higher encoding density), thus achieving a balance between capacity and robustness.

[0056] In practice, the dual-path text encoding scheme, employing both character-level and vocabulary-level methods, provides complementary defenses against text-based attacks. Compared to schemes using only a single path, the dual-path design can handle a wider range of attack types: character-level encoding is immune to simple synonym substitution attacks (because attackers replacing words do not affect inserted zero-width characters), while vocabulary-level encoding is immune to character cleaning attacks (because attackers removing zero-width characters do not affect already made word choices). The dual-path watermark only becomes ineffective when an attacker performs both character cleaning and full synonym substitution simultaneously. This complementary defense significantly increases the cost and technical barrier required for attackers to completely remove the watermark.

[0057] To achieve efficient semantic layer encoding of AI-generated image content, in one optional implementation, when the data type is image data, the semantic layer encoding strategy includes two paths: frequency domain-based semantic encoding and spatial domain-based semantic encoding.

[0058] Frequency-domain-based semantic coding first divides the image into multiple image blocks, each with a size that can be 8×8 pixels or 16×16 pixels, which is not limited in this application. A frequency-domain transformation (e.g., Discrete Cosine Transform (DCT) or Discrete Wavelet Transform (DWT)) is performed on each image block to transform the image from the spatial domain to the frequency domain. In the frequency domain representation, low-frequency coefficients correspond to the overall brightness and large-scale structure of the image, mid-frequency coefficients correspond to the texture and details of the image, and high-frequency coefficients correspond to noise and extremely subtle edges. Watermark information is embedded into the mid-to-low frequency region of the frequency domain coefficients—specifically, several coefficients located in the mid-to-low frequency positions in the DCT coefficient matrix of each image block are selected, and their values ​​are micro-quantized and modulated to embed watermark units. The reason for choosing the mid-to-low frequency region rather than the high-frequency or low-frequency region is that, although the human eye may not easily perceive the modification of high-frequency coefficients, lossy compression (such as JPEG compression) will preferentially reduce high-frequency components in the quantization step, resulting in the loss of embedded watermark information; low-frequency coefficients correspond to the overall brightness and hue of the image, and although they are more resistant to compression after modification, the human eye is sensitive to changes in brightness, which can easily lead to visible distortion; the mid-to-low frequency region takes into account both robustness (resistance to compression operations) and invisibility (the human eye is less sensitive to changes in mid-frequency texture than to changes in brightness), making it the optimal embedding range.

[0059] Spatial-domain-based semantic coding operates directly in the spatial domain of the image, without requiring frequency domain transformation. The system first performs texture complexity analysis on the image, calculating texture complexity indices for each local region (e.g., local variance, gradient magnitude histogram entropy, or gray-level co-occurrence matrix features), identifying regions with texture complexity exceeding a preset threshold and image edge regions. Within these regions, watermark information is embedded by making minor adjustments to pixel values ​​(e.g., modifying the least significant bit or modulating the quantization index). The pixel values ​​in textured regions change drastically, making subtle human modifications difficult to detect, thus these regions are naturally suitable for information hiding. The reason for using the texture complexity threshold as the criterion for embedding location is based on the masking effect of the human visual system—in areas with high visual information density, the human eye's perception threshold for additional perturbations is increased; while in flat areas, perturbations of the same magnitude are easily perceived as anomalies.

[0060] When frequency domain coding and spatial domain coding are used in combination, two strategies can be applied to different regions of the same image: watermarks are embedded in both the spatial and frequency domains simultaneously in regions with complex textures (providing double redundancy), while only a small amount of watermark is embedded in the frequency domain at low frequencies in regions with simple textures (ensuring concealment). The watermark information embedded by the two strategies can serve as backups for each other. When the image undergoes a specific attack (such as a filtering attack that only affects the frequency domain or a geometric transformation attack that only affects the spatial domain), the watermark in the other path remains intact.

[0061] In practice, the dual-path image coding scheme in the frequency and spatial domains provides differentiated resistance to different attack types. Frequency domain coding is robust to signal processing attacks such as JPEG compression and Gaussian blur because these attacks primarily affect high-frequency components while mid- and low-frequency components remain stable. Spatial domain coding is robust to geometric transformation attacks such as cropping and rotation because the pixel relationships in local areas can still be repositioned through synchronization mechanisms after geometric transformation. The complementarity of the dual paths means that attackers need to apply both signal processing and geometric attacks simultaneously to significantly compromise watermark integrity. However, applying both types of attacks simultaneously usually leads to a significant degradation in image quality, making the attacks impractical in real-world applications.

[0062] To ensure that watermark embedding does not impair the usability of AI-generated content, in one optional implementation, this invention sets explicit perceptual quality quantification thresholds for each modality. When the content is text, the semantic similarity before and after embedding is no less than 0.90. This semantic similarity is obtained by calculating the cosine distance between the sentence vectors of the original text and the embedded text using a pre-trained language model (such as BERT or Sentence-BERT). The 0.90 threshold ensures that the embedded text retains at least 90% of the original semantic information. When the content is image, the peak signal-to-noise ratio (PSNR) before and after embedding is no less than 40dB. PSNR is a standard engineering metric for measuring the degree of image distortion, and 40dB is generally considered in the field of image processing to be a threshold value at which the human eye cannot perceive distortion. When the content is audio, the signal-to-noise ratio (SNR) before and after embedding is no less than 30dB. A 30dB SNR ensures that the energy of the watermark signal is much lower than the energy of the audio content itself, and is completely masked in a normal playback environment. When the content is video content, the structural similarity (SSIM) before and after embedding is no less than 0.95. SSIM comprehensively measures the image quality in three dimensions: brightness, contrast and structure. 0.95 means that the distortion caused by embedding is extremely small in all three dimensions.

[0063] In practical implementation, the quantified perceived quality threshold transforms the functional requirement of "not altering human perceived quality" into an automatically verifiable engineering constraint. During the watermark embedding process, the embedding execution submodule 132 automatically calculates the corresponding indicators after completing the embedding operation. If the indicator is below the threshold, it automatically reduces the embedding strength or the number of embedding positions and re-embeds until the indicator meets the requirements. This automated quality assurance mechanism eliminates the need for manual review, allowing the watermark embedding process to be completed in real-time simultaneously with AI content generation without introducing additional delays. From a standardization perspective, adopting industry-recognized quality indicators and thresholds facilitates integration with third-party quality assessment systems, providing an objective basis for the compliance review of the watermarking system.

[0064] To ensure successful watermark extraction even after various common processing methods, in one optional implementation, the watermarking system of this invention maintains a watermark extraction success rate of no less than 75% under typical attacks of each modality. For text data, typical attacks include machine translation attacks (translating text into other languages ​​and then back), synonym rewriting attacks (replacing words in the original text with synonyms), sentence transformation attacks (changing sentence structure while maintaining semantics), and content truncation attacks (retaining only parts of the original text or sentences). For image data, typical attacks include cropping attacks (cropping local areas of an image), compression attacks (performing lossy compression with a lower quality factor), rotation attacks (rotating the image), filtering attacks (applying blur or sharpening filters to the image), and scaling attacks (changing image resolution). For audio data, typical attacks include noise reduction attacks (applying noise reduction processing to audio), pitch shifting attacks (changing the fundamental frequency of the audio), compression attacks (encoding audio at a lower bit rate), and sampling rate conversion attacks (changing the sampling frequency of the audio). Typical attacks targeting video data include transcoding attacks (converting video from one encoding format to another), frame deletion attacks (deleting some frames from a video), resolution transformation attacks (changing video resolution), and frame rate conversion attacks (changing video frame rate).

[0065] The reason semantic layer coding can maintain a high extraction success rate under the aforementioned attacks lies in the attack invariance of semantic structure. Taking text as an example, machine translation attacks change the surface form of vocabulary and syntax, but the core semantics of the text are preserved during the translation process—the semantically equivalent words used in lexical-level coding still have corresponding equivalent choices in the target language. Taking images as an example, JPEG compression mainly eliminates high-frequency information while retaining mid-to-low-frequency structures. Frequency domain coding precisely embeds the watermark into the mid-to-low-frequency region, so the impact of compression on the watermark is limited. A 75% success rate threshold means that at least 24 out of 32 watermark units can be successfully extracted. Combined with error-correcting codes (such as BCH codes or LDPC codes), the complete 32-unit sequence can be recovered from the 24 correct units.

[0066] In practical implementation, a 75% lower limit for extraction success rate provides a clear engineering guarantee for the actual usability of the system. Compared to solutions that do not provide explicit robustness indicators, this quantified threshold allows system integrators to perform standardized robustness tests before deployment to verify whether the watermarking system meets expected performance. In practical applications, a 75% success rate, combined with appropriate error correction coding redundancy, is sufficient to recover complete traceability information: taking the BCH(63,30,13) code as an example, its error correction capability is 13 error bits, corresponding to a minimum success rate of approximately 79% to completely recover the original information. Therefore, setting a 75% lower limit provides sufficient design margin for the system's error correction design.

[0067] To achieve efficient and accurate automated watermark detection, in one optional implementation, the detection model architecture is designed as follows. The text detection model is based on a sequence labeling architecture, which models the watermark detection problem as a sequence labeling task: inputting a sequence of characters or words from the text to be detected, and outputting the probability distribution of whether a watermark is carried at each position. The core components of the sequence labeling architecture include an embedding layer (mapping characters or words to vector representations), an encoding layer (capturing contextual dependencies through sequence modeling networks such as Transformer or BiLSTM), and an output layer (outputting a binary classification probability for each position). The training data for the text detection model consists of "text-label" pairs containing the embedded watermark, where the label indicates the watermark embedding state at each position. The image detection model is based on a convolutional neural network architecture, which models the watermark detection problem as an image-to-sequence regression task: inputting an image to be detected, and outputting the probability of watermark presence and the decoded watermark sequence. The core components of the convolutional neural network architecture include a feature extraction backbone network (extracting multi-scale features of the image through multi-layer convolution and downsampling), a watermark decoding head (regressing the extracted features into watermark sequence values), and a confidence prediction head (outputting the overall probability of watermark presence). The image detection model is trained using a triplet of "original image - attacked image - watermark label". Through contrastive learning, the model learns watermark feature representations that are invariant to attacks.

[0068] The watermark presence threshold for the detection model is set to be no less than 0.6. When the watermark presence probability is below 0.6, the system determines that the content to be detected does not contain the watermark embedded by the system and outputs "No watermark detected"; when the probability is between 0.6 and 0.8, the system determines that the watermark may exist but with moderate confidence, outputs the decoding result and labels the confidence level; when the probability is above 0.8, the system determines that the watermark exists with high confidence and outputs the decoding result for subsequent source tracing and comparison. The 0.6 threshold is set based on a balance between detection precision and recall: an excessively high threshold will cause the watermark probability to drop below the threshold after the content has undergone a strong attack, resulting in missed detections (reduced recall); an excessively low threshold will cause content without embedded watermarks to be falsely identified as containing watermarks (reduced precision). In one implementation, the 0.6 threshold can be adjusted according to the tolerance of missed detections to false detections in the specific deployment scenario, and this application does not limit this adjustment.

[0069] In practical implementation, the dual-modal detection architecture based on sequence labeling and convolutional neural networks adapts to the data characteristics of both text and image, the two main modalities. The sequence labeling architecture for text is naturally suited for handling variable-length input sequences, capable of independently determining the watermark status at each character position; therefore, even if the text is partially truncated, the remaining portion can still be detected independently. The convolutional neural network architecture for images naturally possesses translation invariance and multi-scale perception capabilities, exhibiting inherent robustness against cropping and scaling attacks. Both architectures share a unified training framework (adversarial training + data augmentation), ensuring consistent detection performance across various attack variants.

[0070] When multimodal AI-generated content, such as vehicle trajectory videos and voice call records, needs to be verified for source tracing, the system automatically calls the corresponding detection model based on the data type of the content. For multimodal mixed content (such as web pages containing text and images), the system performs independent detection on the text and image parts separately, and then combines the detection results of multiple modalities to give a final judgment. In one implementation, the comprehensive judgment strategy is as follows: if the probability of watermark presence in any modality exceeds the judgment threshold, the entire content is judged to contain a watermark; if multiple modalities detect the watermark simultaneously and the decoded source tracing information is consistent, the verification confidence is further increased.

[0071] When content has undergone significant rewriting or re-creation, resulting in a fundamental change in its form but not its core semantics, the system employs a semantic-level comparison strategy. Specifically, the watermark sequence extracted from the significantly rewritten content may be incomplete (some watermark units are missing). In this case, the information restoration submodule 152 attempts to partially decode based on the remaining watermark units, extracting some fields of the source information, and then performing a fuzzy match with the evidence record. If the matching similarity exceeds a preset threshold (e.g., 70% of fields match successfully), a "suspected source" judgment result is output for further manual confirmation.

[0072] When the content to be detected does not contain any watermark embedded in this system (i.e., content not generated by AI or content generated by AI that has not deployed this traceability system), the probability of watermark presence output by the detection model will be far below the judgment threshold, and the system will directly output the conclusion "no watermark detected". In this scenario, the system will not produce a false judgment because the detection model has already used a large number of negative samples without watermarks for comparative training during the training phase, and has learned the statistical differences between "watermarked" and "watermark-free" content.

[0073] When the storage medium in the evidence storage module 140 experiences network unavailability or a temporary failure, the watermark extraction and decoding functions of the detection and verification module 150 can still be executed independently (because watermark extraction does not depend on the evidence storage record); only the comparison and verification step cannot be completed temporarily. In this situation, the system outputs an intermediate status of "watermark extraction successful, waiting for evidence comparison," and automatically retryes the comparison operation after the storage medium is restored. This fault-tolerant design ensures the independent availability of the detection module.

[0074] To ensure the security and stability of the system, this method also includes the following boundary condition handling. During the traceability information generation stage, if the AI ​​content generation engine 200 does not provide a valid user identity identifier (e.g., in anonymous access scenarios), the system can still generate valid traceability information based on the generation model identifier, timestamp, and platform identifier, but the user dimension will be labeled as "anonymous" to ensure the traceability link is not interrupted due to the absence of a single field. During the semantic layer encoding stage, if the content is too short (e.g., text with only a single word or image size smaller than the minimum image block size), the system determines that the available encoding positions are insufficient to accommodate the minimum required number of watermark units. In this case, an "Insufficient encoding capacity" warning is output, and an attempt is made to reduce the watermark sequence length or embed only the most core traceability fields. During the semantic layer embedding stage, if the quality index after embedding is below the threshold and the embedding strength cannot be further reduced, the system terminates the embedding operation and outputs the original content without a watermark, while simultaneously recording the embedding failure log. During the evidence storage stage, if the write to the immutable storage medium fails, the system temporarily stores the evidence data in a local secure cache and sets a timed retry strategy to ensure the eventual consistency of the evidence records. During the detection and verification phase, if the detection model malfunctions or the inference timeout occurs, the system outputs a "detection failed" result and records the exception log, without providing any judgment on the presence or absence of a watermark, thus avoiding erroneous conclusions due to system failure.

[0075] Next, the complete tracing method of the present invention will be described.

[0076] In step S101, the AI ​​content generation engine 200 receives the user's content generation request, starts the content generation process, and sends a generation event notification to the traceability information generation module 110.

[0077] In step S102, the traceability information generation module 110 receives the generation event notification, collects the current generation context information (including model identifier, user identifier, timestamp, serial number, platform identifier, etc.), and assembles the traceability information data packet.

[0078] In step S103, the traceability information generation module 110 distributes the traceability information data packet to two parallel channels: channel one is the semantic layer encoding module 120, and channel two is the evidence storage module 140.

[0079] In step S104, the semantic layer encoding module 120 receives the source information data packet and the original content output by the AI ​​content generation engine 200, identifies the data type of the content through the encoding strategy routing submodule 121, and distributes the encoding task to the corresponding modal encoder.

[0080] In step S105, the corresponding modal encoder (text encoder 122, image encoder 123, audio encoder 124 or video encoder 125) converts the source information into a digital watermark sequence and outputs it to the semantic layer embedding module 130.

[0081] In step S106, the embedding position analysis submodule 131 of the semantic layer embedding module 130 analyzes the structural features of the original content to determine the available embedding positions in human perception insensitive areas or semantic structure layers.

[0082] In step S107, the embedded execution submodule 132 performs a watermark embedding operation at a determined location to generate content carrying the watermark.

[0083] In step S108, the embedded execution submodule 132 performs a perceptual quality assessment on the embedded content. If the quality indicators meet the threshold requirements, the final published content is output; otherwise, the embedding parameters are adjusted and the process returns to step S106 for re-execution.

[0084] In step S109, the hash calculation submodule 141 of the evidence storage module 140 performs a hash operation on the traceability information data packet to generate an evidence storage identifier.

[0085] In step S110, the storage writing submodule 142 writes the evidence storage identifier and associated metadata into an immutable storage medium to complete the evidence storage.

[0086] Step S111: During the detection phase, the user or system submits the content to be detected to the detection and verification module 150.

[0087] In step S112, the watermark extraction submodule 151 performs forward inference of the detection model on the content to be detected, and outputs the watermark existence probability and the preliminary watermark sequence.

[0088] Step S113: Determine if the probability of watermark presence is not less than the judgment threshold. If yes, proceed to step S114; otherwise, output "No watermark detected" and end.

[0089] In step S114, the information restoration submodule 152 performs decoding and error correction operations on the extracted watermark sequence to restore the source information.

[0090] In step S115, the comparison and verification submodule 153 queries the evidence storage record corresponding to the traceability information restored from the evidence storage module 140 and performs a comparison operation.

[0091] Step S116: Output the final verification conclusion based on the comparison results: if there is a complete match, output "Verification passed" and complete traceability information; if there is a partial match, output "Suspected source" and matching degree; if there is no match, output "Verification failed".

[0092] It should be noted that steps S101 to S110 constitute the content generation stage, which is executed automatically each time the AI ​​model generates content; steps S111 to S116 constitute the detection and verification stage, which is executed as needed when source verification of specific content is required. The two stages are typically not consecutive in time, with arbitrary intervals between them. The step numbering is for illustrative purposes only and does not constitute a limitation on the execution order—for example, the two parallel channels in step S103 can be executed simultaneously rather than necessarily in sequence. Adaptive adjustments that can be made by those skilled in the art based on the above description are all within the scope of protection of this invention.

[0093] Corresponding to the above method, this application embodiment also provides a semantic layer stealth encoding tracing device for AI-generated content. The core functions of this device are implemented through the following modules: A tracing information generation module 110 is used to implement the function of the tracing information generation step in the above method, that is, automatically collecting generation context information and assembling tracing information data packets when the AI ​​model generates content. A semantic layer encoding module 120 is used to implement the function of the semantic layer encoding step in the above method, that is, selecting the corresponding semantic layer encoding strategy according to the content data type and converting the tracing information into a digital watermark sequence. A semantic layer embedding module 130 is used to implement the function of the semantic layer embedding step in the above method, that is, embedding the watermark sequence into the human-perceptually insensitive area or semantic structure layer of the content. An evidence storage module 140 is used to implement the function of the evidence storage step in the above method, that is, generating an evidence storage identifier and writing it to an immutable storage medium. A detection and verification module 150 is used to implement the function of the detection and verification step in the above method, that is, extracting the watermark from the content to be detected, restoring the tracing information, and comparing it with the evidence storage record. The specific functional implementation, data flow, and collaborative relationship of each of the above modules are consistent with the description in the aforementioned method embodiments, and will not be repeated here. The device can be implemented as a software module running on a general-purpose server, or as a dedicated hardware accelerator integrated into an AI inference platform, or as a cloud service providing capabilities to the outside world via API. This application does not limit its specific deployment form.

[0094] Furthermore, embodiments of this application also provide an electronic device, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps described in the above method embodiments. This electronic device can be a standalone server, a cloud computing virtual machine, an edge computing node, or an embedded device. The memory can be random access memory, read-only memory, flash memory, or a combination thereof. The processor can be a central processing unit, a graphics processing unit, a neural network processor, or a combination thereof.

[0095] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps described in the above method embodiments. The computer-readable storage medium may be a non-transitory computer-readable storage medium, including but not limited to hard disks, solid-state drives, optical disks, USB flash drives, or magnetic tapes.

[0096] Based on the complete technical solutions of the above embodiments, this invention constructs a traceability protection system covering the entire lifecycle of AI-generated content through the coordinated efforts of five stages: "source information generation—semantic layer encoding—semantic layer embedding—evidence storage—detection and verification." The core innovation of this system lies in elevating the watermark information carrying layer from the traditional signal layer and metadata layer to the semantic structure layer, deeply binding the watermark to the semantic essence of the content. The semantic layer encoding technical approach fundamentally changes the game between watermarking systems and attacks: traditional signal layer watermarking faces the dilemma that "attackers can eliminate the watermark without significantly reducing content quality," while semantic layer watermarking makes "eliminating the watermark requires changing the semantic structure of the content, and changing the semantic structure inevitably damages the content's usability" a new constraint, thus binding the survival of the watermark to the usability of the content.

[0097] From a system architecture perspective, the modular design and coding strategy routing mechanism of this invention enable unified support for multimodal content within a single framework, avoiding the high engineering costs of maintaining a separate system for each modality. Each modality encoder interfaces with the routing submodule through standardized interfaces. Integrating a new modality only requires developing the corresponding encoder and detection model, without modifying the overall architecture, ensuring the system's long-term scalability. The dual-channel design (watermarking channel + evidence storage channel) provides redundancy for source tracing and verification, eliminating the risk of single points of failure. The deep learning-based detection model provides the verification process with generalization capabilities against unknown attack variants, eliminating the need for specialized adaptation for each newly emerging attack type after system deployment.

[0098] From a practical application perspective, this invention can serve several core scenarios: in the copyright protection of AI-generated content, the source information records the creator's identity and creation time, providing technical evidence for copyright ownership disputes; in the fight against misinformation, the source information records the content's generation model and platform origin, helping regulatory agencies quickly pinpoint the source of misinformation; and in AI service compliance auditing, the complete record of source information provides a comprehensive audit trail for platform compliance checks. The watermark's invisibility ensures that the aforementioned source traceability capabilities do not affect the normal use and dissemination of content, and the user experience remains unaffected.

[0099] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these all fall within the protection scope of the present invention. Therefore, the protection scope of this invention patent should be determined by the appended claims.

Claims

1. A method for tracing the semantic layer implicit encoding of AI-generated content, characterized in that, The method includes: Source tracing information generation steps: When the AI ​​model generates content, source tracing information is generated, which is used to uniquely identify the source of the content; Semantic layer encoding steps: Encode the source information into a digital watermark sequence, and select the corresponding semantic layer encoding strategy according to the data type of the content. The data type includes at least one of text data, image data, audio data, and video data. Semantic layer embedding step: The encoded digital watermark sequence is embedded into the human perception insensitive region or semantic structure layer of the content. The human perception insensitive region includes high texture complexity region in image, high frequency masking region in audio, and motion blur region in video. The embedding does not change the human perception quality of the content. Evidence preservation step: Generate an evidence preservation identifier based on the traceability information, and store the evidence preservation identifier in an immutable storage medium; Detection and verification steps: Extract the digital watermark sequence from the content to be detected using the detection model, restore the source information based on the extracted digital watermark sequence, and compare the restored source information with the evidence identification to confirm the authenticity of the source of the content.

2. The method according to claim 1, characterized in that, The traceability information includes at least two of the following: generation model identifier, user identity identifier, generation timestamp, content sequence number, and platform identifier; the digital watermark sequence contains n watermark units, where n is not less than 32.

3. The method according to claim 1, characterized in that, When the data type is text data, the semantic layer encoding strategy includes character-level semantic encoding and / or word-level semantic encoding; The character-level semantic encoding includes: using visually indistinguishable character variants to represent watermark information, wherein the character variants include at least one of Unicode zero-width characters, homographs, combined characters, and bidirectional text control characters; The lexical-level semantic encoding includes: performing word replacement based on a pre-set semantic equivalence lexicon, wherein each word pair or phrase in the semantic equivalence lexicon corresponds to a watermark unit.

4. The method according to claim 1, characterized in that, When the data type is image data, the semantic layer coding strategy includes frequency domain-based semantic coding and / or spatial domain-based semantic coding; The frequency domain-based semantic coding includes: dividing the image into multiple image blocks, performing frequency domain transformation on each image block, and embedding watermark information in the low-to-mid frequency region of the frequency domain coefficients; The spatial domain-based semantic encoding includes: detecting complex texture regions or edge regions of the image, and fine-tuning pixel values ​​in regions where the texture complexity is higher than a preset threshold.

5. The method according to claim 1, characterized in that, The embedding does not alter the human-perceived quality of the content, including: When the content is text, the semantic similarity before and after embedding is not less than 0.90; When the content is image content, the peak signal-to-noise ratio before and after embedding is not less than 40dB; When the content is audio content, the signal-to-noise ratio before and after embedding is not less than 30dB; When the content is video content, the structural similarity before and after embedding is not less than 0.

95.

6. The method according to claim 1, characterized in that, The digital watermark sequence extracted in the detection and verification step is resistant to attacks. After the content to be detected has undergone at least one of the following attack processes, the watermark extraction success rate is not less than 75%: Machine translation attacks, synonym rewriting attacks, sentence transformation attacks, or content extraction attacks targeting text data; Attacks targeting image data include cropping, compression, rotation, filtering, and scaling. Noise reduction attacks, pitch shifting attacks, compression attacks, or sample rate conversion attacks targeting audio data; Attacks targeting video data include transcoding attacks, frame deletion attacks, resolution transformation attacks, and frame rate conversion attacks.

7. The method according to claim 1, characterized in that, The detection model includes at least one of a text detection model and an image detection model; The text detection model is based on a sequence labeling architecture and is used to output the watermark probability distribution of each character or word in the text to be detected. The image detection model is based on a convolutional neural network architecture and is used to output the probability of watermark presence in the image to be detected and the decoded watermark sequence. The watermark detection model has a watermark presence threshold of no less than 0.

6.

8. A semantic layer implicit coding tracing system for AI-generated content, the system being used to perform the steps of the method according to any one of claims 1-7, characterized in that, The system includes: The traceability information generation module is used to generate traceability information that uniquely identifies the source of the content when the AI ​​model generates content; A semantic layer encoding module is used to encode the source information into a digital watermark sequence and select the corresponding semantic layer encoding strategy according to the data type of the content. A semantic layer embedding module is used to embed the encoded digital watermark sequence into a human-perceptually insensitive region or semantic structure layer of the content. The human-perceptually insensitive region includes high texture complexity regions in an image, high frequency masking regions in an audio, and motion-blurred regions in a video. The embedding does not change the human-perceptual quality of the content. The evidence storage module is used to generate an evidence storage identifier based on the traceability information and store the evidence storage identifier in an immutable storage medium. The detection and verification module is used to extract a digital watermark sequence from the content to be detected through a detection model, restore the traceability information based on the extracted digital watermark sequence, and compare the restored traceability information with the evidence identification to confirm the authenticity of the source of the content.

9. An electronic device, characterized in that, It includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1-7.