Neural Network Watermarking for Digital Object Provenance Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved systems to identify the provenance of digital objects generated using machine learning models, particularly due to the increasing size and complexity of these objects, which can result in computational bottlenecks and a requirement for techniques that are both robust and efficient.

Innovation Solution

A method and system utilizing neural networks for watermarking and verifying digital objects, involving a watermark generation neural network and a watermark decoding neural network, trained using adversarial transformations to generate and detect watermarks, with an object verification system that stores embeddings to verify the provenance of digital objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional watermarking methods are used to verify provenance of digital objects, then the system can identify whether an object was generated by a generative model, but the computational complexity increases significantly with the size and complexity of digital objects

Engineering Contradiction:
Improveprovenance verification accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The verification system segments the digital object processing into distinct components: embedding generation, watermark detection, and provenance determination. This segmentation allows each component to be optimized independently, reducing overall computational complexity while maintaining verification accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary watermark embedding during the digital object generation process itself, rather than adding watermarks afterward. This preliminary action ensures the watermark is inherently integrated into the object's structure, making detection more efficient and less computationally intensive.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If adversarial transformations are applied to train the watermarking system, then the system becomes more robust against malicious attacks, but the training process becomes more complex and time-consuming

Engineering Contradiction:
Improverobustness against adversarial attacksVSAvoidtraining time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Adversarial examples are generated and incorporated into the training dataset before the actual training process begins. This preliminary preparation of adversarial data allows the model to learn robust features in advance, reducing the need for iterative adversarial training and decreasing overall training time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts adversarial attacks, which are harmful by nature, into training examples that strengthen the model's defenses. By using adversarial examples as training data, the system transforms potential threats into beneficial learning opportunities, improving robustness without requiring separate defensive training processes.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Measurement precision

If watermarks are embedded in digital objects to verify provenance, then the ability to detect maliciously generated content improves, but the watermark may be detectable by malicious actors attempting to remove or alter it

Engineering Contradiction:
Improvedetection of malicious contentVSAvoiddetectability by malicious actors
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The watermark is embedded with varying local characteristics throughout the digital object, with different regions containing subtly different watermark patterns. This local quality variation makes it difficult for malicious actors to detect and remove the watermark uniformly, as they would need to identify and target each local pattern individually.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The watermark embedding process uses asymmetric operations that are easy to apply but difficult to reverse or detect without the specific embedding key. This asymmetry ensures that while the watermark effectively marks provenance, malicious actors cannot easily detect its presence or location to attempt removal.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS12094474B1Verifying the provenance of a digital object using watermarking and embeddings
Publication Date: 2024.09.17 GDM HOLDING LLC
  • US12094474B1 patent drawing
  • US12094474B1 patent drawing
  • US12094474B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for verifying the provenance of a digital object generated by a neural network, such as an image or audio object. Also methods, systems, and apparatus, including computer programs, for training a watermarking neural network and a watermark decoding neural network. The described techniques make efficient use of computing resources and are robust to attack.