Object Detection Model Watermarking via Training Image Embedding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The illegitimate appropriation of object detection models trained by machine learning is a significant issue due to the long and costly development process, and existing watermarking methods are not applicable to these models.

Innovation Solution

A method for watermarking object detection models in images developed by machine learning, which involves modifying digital training images by embedding marking objects and associating them with predetermined bounding boxes, thereby injecting the watermarked data into the training database during the learning phase.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional watermarking methods are used for multimedia content, then authentication of digital data is achieved, but these methods are not applicable to object detection models trained by machine learning

Engineering Contradiction:
Improveauthentication capabilityVSAvoidapplicability to machine learning models
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the watermarking approach by changing the domain from direct media manipulation to training data modification. Instead of applying watermarks to the model structure or output, the method embeds watermarks in the training images and associates them with ground truth data, fundamentally altering how authentication is implemented for ML models

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces training images as an intermediary carrier for the watermark. Rather than directly watermarking the model or its outputs, the authentication information is embedded in the training data that the model learns from, creating an indirect but robust authentication mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If object detection models are trained with large amounts of training data and extensive parameter adjustment, then detection performance is improved, but the development process becomes long and costly

Engineering Contradiction:
Improvedetection performanceVSAvoiddevelopment time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent performs watermark embedding during the training phase itself, rather than as a separate post-processing step. By integrating the authentication mechanism into the existing training workflow, the method avoids additional time costs while maintaining detection performance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines the watermarking function with the training data preparation process. The authentication information is merged into the training images and their associated ground truth data, eliminating the need for separate watermarking operations and reducing overall development time

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If watermarking is implemented by modifying model behavior to provide predetermined outputs, then authentication is achieved, but this approach does not work for object detection models that require accurate object detection

Engineering Contradiction:
Improveauthentication capabilityVSAvoidobject detection accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent segments the authentication function from the detection function. Instead of modifying the model's detection behavior to provide predetermined outputs, the method separates authentication (verified through watermark presence in training data) from object detection (performed by the model on new images), allowing both functions to operate independently without compromising either

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent embeds the watermark as a copy within the training image data itself, rather than modifying the model's output behavior. The watermark is embedded in the training images and their associated ground truth bounding boxes, creating an authenticatable copy that doesn't interfere with the model's detection capabilities on new images

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4567643A1Method and system for watermarking of an object detection model in an image prepared with machine learning
Publication Date: 2025.06.11 THALES SA
  • EP4567643A1 patent drawingFigure 1
  • EP4567643A1 patent drawingFigure 2
  • EP4567643A1 patent drawingFigure 3

AI summary

The system for tattooing an object detection model in an image is configured to implement, during a learning phase, modules for: - selecting (22) at least one digital training image, - for the or each selected digital training image, modifying (24) said digital training image into a corresponding digital tattoo image, by embedding at least one marking object (40), - associating (26) the or each digital tattoo image with an output digital tattoo data item comprising a plurality of predetermined bounding boxes, each of the bounding boxes having a size and arrangement determined by a calculation, - injecting (28) the pair formed by the digital tattoo image and the associated output tattoo data item into the learning database and - applying (30) the machine learning of the object detection model to said learning database.