GAN Watermarking Model Training via Multi-Stage Attack Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital watermarking technologies face challenges in maintaining the robustness and invisibility of watermarks, especially when subjected to various attacks, and often require training models for specific attack types, limiting their effectiveness against diverse attacks.
Innovation Solution
A watermarking model learning method that divides learning epochs into multiple stages, with each stage focused on specific types and complexities of attacks, using a combination of original and attack samples to enhance robustness and minimize degradation in watermark visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a watermark is inserted in the spatial domain, then the watermark insertion is simple, but the watermark has sensitive characteristic and is insufficiently robust to image distortion
Solution Approach 1:
The patent replaces the traditional spatial domain watermark insertion method with a frequency domain-based approach using GANs. The generator network operates in the frequency domain to create watermarked images, substituting the mechanical/spatial insertion process with a frequency-based transformation that inherently provides robustness against distortions while maintaining simplicity through automated learning-based insertion.
Solution Approach 2:
The patent changes the fundamental parameter of watermark insertion from spatial domain to frequency domain. By transforming the watermarking process into the frequency domain using GANs, the system achieves both robustness to image distortion and perceptual quality, resolving the contradiction between insertion simplicity and robustness through parameter transformation.
2Reliability
If the watermark is inserted after converting an image to the frequency domain, then the watermark is more robust to image distortion, but the robustness is greatly affected and image quality degrades depending on insertion position
Solution Approach 1:
The patent implements feedback mechanisms through the GAN framework where the discriminator network provides feedback on the quality and robustness of watermarked images. This feedback loop enables the generator to adjust watermark insertion parameters and positions automatically, ensuring consistent image quality while maintaining robustness against distortions without manual intervention.
Solution Approach 2:
The GAN-based system performs self-service by automatically optimizing watermark insertion parameters and positions through the learning process. The generator network self-adjusts to create watermarked images that balance robustness and quality, eliminating the need for manual position selection and its associated quality variations.
3Reliability
If a watermarking model is trained for specific attack types, then the model is effective against those attacks, but the model cannot handle diverse attacks effectively
Solution Approach 1:
The patent applies universality by training the GAN-based watermarking model to handle multiple attack types simultaneously. The generator network is designed with multi-functionality to counter various attacks including but not limited to JPEG compression, resizing, and noise, enabling a single model to provide robust protection against diverse attack scenarios rather than requiring separate models for each attack type.
Solution Approach 2:
The patent implements dynamics by making the watermarking model adaptable through continuous learning and adjustment. The GAN framework enables the model to dynamically adjust its watermarking strategy based on the type and strength of attacks encountered, transitioning from static attack-specific models to a dynamic, versatile system that can respond to various attack types effectively.
Data Source
AI summary
Disclosed are a method, a computer device, and a non-transitory computer-readable record medium for learning of a watermarking model. A watermarking model learning method may include dividing, by the at least one processor, epochs for learning of a watermarking model into at least two stages, setting, by the at least one processor, at least one target attack type to each stage among the at least two stages, the setting includes setting a first threshold number of the at least one target attack type set to an earlier stage to be greater than a second threshold number of the at least one target attack type set to a later stage, and the at least two stages including the earlier stage and the later stage, and performing, by the at least one processor, learning of the watermarking model based on the at least two stages and the setting.


