In this paper, we present a unified framework for robust 3D embedded watermarking and non-embedded watermarking based on feature integration. It begins by segmenting a 3D model into multiple separate sub-models via empirical mode decomposition (EMD). And then, it constructs a robust feature image for each sub-model by integrating its explicit and implicit radial features. Such scheme enables our framework to seamlessly transition from 3D non-embedded watermarking to 3D embedded watermarking. Our 3D embedded watermarking modifies the model according to its statistical characteristics. Therefore, it is an adaptive embedding method and can improve the invisibility of 3D embedded watermarking. Subsequently, it generates the copyright-watermark keys by using an XOR operation on each feature image and the given watermark image. Additionally, our watermarking framework can extract multiple watermark images according to the feature images of the detected 3D model and the stored copyright-watermark keys. They can be combined into the final watermark via a voting strategy to enhance the robustness of 3D watermarking. The experimental results and analysis demonstrate the superior performance of our newly-proposed 3D watermarking framework in terms of versatility, robustness and invisibility.
Due to the fact that most existing digital watermarking schemes can only add watermark information once, repeated additions will overwrite the original watermark information, making it impossible to achieve multi-level traceability of data. In response to the above issues, this paper proposes a multi-level database image watermark embedding scheme (MIWC) based on the Chinese remainder theorem. Taking image watermarks as carriers, MIWC preprocesses images using methods such as Haar wavelet transform and Bloom filter to form a pixel. It then performs secret segmentation on watermark information in accordance with the properties of the Chinese Remainder Theorem, enabling hierarchical and item-by-item addition of the watermark information. Furthermore, it records and traces the entire data flow chain. Functional analysis demonstrates that MIWC possesses the multi-level watermark embedding capability that existing schemes lack, thus holding high practical application value. Experimental results indicate that MIWC is reversible, with both watermark embedding and extraction exhibiting high efficiency. Even with the embedding of multi-level watermarks, MIWC remains highly efficient and lightweight. Meanwhile, MIWC also demonstrates strong robustness, being capable of resisting geometric attacks (including rotation and scaling) and common attacks (including JPEG compression, JPEG2000, Gaussian white noise, and salt-and-pepper noise) targeting the watermark.
Research on watermark attacking is essential to reinforce robust watermarking methods by providing new attacking benchmarks. Recently, there is an emergence of attacking methods based on deep learning, in which perceptual loss and watermark loss are utilized to train the neural networks for the imperceptibility of watermarked images and the disruption of attacked watermarks. In this work, we propose a novel randomness-anchored attacking network (RAN) based on deep learning. In RAN, we introduce an alternative watermark loss to attack the watermarks into random noises by anchoring to randomness rather than the original watermarks. Extensive attacking experiments of comparisons with attacking schemes show that the proposed RAN models can achieve satisfying performance in preserving the visual fidelity of attacked watermarked images with competitive attacking ability. The proposed methods add new inspirations to the design of stealthy and effective attacking models based on deep learning, with significant implications for developing robust watermarking. The source code and data is shared at https://github.com/kq409/Watermark-Attack .
Currently, most optical watermarking schemes adopt an embedding strategy, which often leads to a trade-off between watermark imperceptibility and robustness. Additionally, the encryption keys used are typically not linked to user identity, posing significant security risks in the event of key leakage. To address these issues, this paper proposes an optical robust zero-watermarking scheme based on chaotic facial phase masks and diffractive imaging. In the proposed optically robust zero-watermarking scheme, the original watermark is first encoded into a noise-like diffraction intensity image using a chaotic facial phase mask and diffraction imaging. This encoded watermark is then XORed with the texture features extracted from the host image via variational image decomposition, thereby generating the zero-watermark. During the decoding process, the original watermark can be approximately losslessly recovered from the zero-watermark using the texture features of the host image, an iterative phase retrieval algorithm, and the authenticated user's facial image. Since the encryption and decryption keys are tied to the user's facial features, which do not require storage or transmission, the proposed scheme offers a high level of security. Moreover, extensive experimental results and analyses demonstrate that the proposed optical zero-watermarking method exhibits strong robustness against both image processing operations and geometric attacks.
The transfer of patient information in a networked health care system raises significant security issues, including unauthorized access, tampering, and unauthorized use. Most of the techniques have shown limited performance in terms of robustness, imperceptibility, and high embedding capacity simultaneously. Thus, to overcome these problems, this research has introduced a robust watermarking scheme for smart health care. The method proposed in the paper follows a hybrid approach, combining concepts of visible and invisible watermarking, multimodal image fusion, and encryption to enhance the system's reliability and security. First, the hospital logo is inserted as a visible watermark in the carrier image. Then, the CT and MRI images are fused together through the hybrid NSST-DTCWT approach to create the medical watermark. To improve efficiency, PCA is applied to the visibly watermarked carrier image. The fused watermark is then inserted into the system using the NSST and SVD approaches, focusing on low-energy areas to achieve high imperceptibility and robustness. The process is then followed by the encryption process for the watermarked image. The extensive experimental evaluation and comparison confirm that the proposed framework possesses excellent adaptability, robustness (Average NC[Formula: see text]), and embedding efficiency, with high visual quality (Average PSNR and SSIM of 44.7122 dB and 0.9955, respectively). The results' findings indicate that the proposed watermarking technique is effective for tackling the security, transparency, and robustness concerns in medical image communication, thereby making it a feasible and clinically applicable tool in smart healthcare applications.
Ensuring copyright protection against illegal attacks and image processing operations while maintaining blind detection capabilities presents a significant challenge in color image watermarking. To address this issue, in this article, we propose a blind watermarking approach that integrates the Arnold transformation with watermark embedding in the transformed domain. Modified forms of Hahn discrete moments are introduced to effectively extract the key image features within this domain. The watermark is encrypted before being embedded into the magnitudes of the Hahn moments for each block using dither modulation, ensuring robustness against different types of attacks. Additionally, a reconstruction algorithm for color images based on Hahn moments is developed and employed during the watermark extraction phase. Experimental results confirm that the proposed scheme achieves high efficiency in terms of both imperceptibility and robustness. Extensive evaluations demonstrate its superior performance, with its PSNR and SSIM values reaching 64.693 dB and 0.9998, respectively. In the no-attack scenario, a perfect-quality watermark is extracted with BER = 0 and NCC = 1. Under various attacks, including filtering, noise, geometric, and robustness attacks, the proposed scheme continues to extract high-quality watermarks, achieving an average BER of 0.00001 and NCC of 0.9998, thereby outperforming the existing image watermarking techniques.
Image watermarks have been considered a promising technique to help detect AI-generated content, which can be used to protect copyright or prevent fake image abuse. In this work, we present a black-box method for removing invisible image watermarks, without the need of any dataset of watermarked images or any knowledge about the watermark system. Our approach is simple to implement: given a single watermarked image, we regress it by deep image prior (DIP). We show that from the intermediate steps of DIP one can reliably find an evasion image that can remove invisible watermarks while preserving high image quality. Due to its unique working mechanism and practical effectiveness, we advocate including DIP as a baseline invasion method for benchmarking the robustness of watermarking systems. Finally, by showing the limited ability of DIP and other existing black-box methods in evading training-based visible watermarks, we discuss the positive implications on the practical use of training-based visible watermarks to prevent misinformation abuse. Our code is publicly available at https://github.com/HengyueL/DIP_Watermark_Evasion.
Robust Reversible Watermarking (RRW) enables perfect recovery of cover images and watermarks in lossless channels while ensuring robust watermark extraction under lossy channels. However, existing RRW methods, mostly non-deep learning-based, suffer from complex designs, high computational costs, and poor robustness limiting their practical applications. To address these issues, this paper proposes Deep Robust Reversible Watermarking (DRRW), a deep learning-based RRW scheme. DRRW introduces an Integer Invertible Watermark Network (iIWN) to achieve an invertible mapping between integer data distributions, fundamentally addressing the limitations of conventional RRW approaches. Unlike traditional RRW methods requiring task-specific designs for different distortions, DRRW adopts an encoder-noise layer-decoder framework, enabling adaptive robustness against various distortions through end-to-end training. During inference, the cover image and watermark are mapped into an overflowed stego image and latent variables. Arithmetic coding efficiently compresses these into a compact bitstream, which is embedded via reversible data hiding to ensure lossless recovery of both the image and watermark. To reduce pixel overflow, we introduce an overflow penalty loss, significantly shortening the auxiliary bitstream while improving both robustness and stego image quality. Additionally, we propose an adaptive weight adjustment strategy that eliminates the need to manually preset the watermark loss weight, ensuring improved training stability and performance. Experiments on multiple datasets demonstrate that the proposed DRRW addresses key challenges in current RRW methods and significantly advances the practical deployment of RRW.
Counterfeiting of integrated circuits (ICs) and intellectual property (IP) infringement pose increasing threats to modern electronics. Hardware watermarking is a key technology for anti-counterfeiting and IP protection. However, existing algorithmic and memory-based watermarking schemes are static, lack activation-level security, are inflexible, and are restricted only to IP protection. Herein, a groundbreaking stimulus-gated neuromorphic watermarking strategy for hardware security is demonstrated using UV-triggered synaptic phototransistors based on two-dimensional (2D) siloxene nanosheets. By emulating biological synaptic behavior, a dynamic watermark is designed that can only be unlocked via application of UV light pulses possessing precisely defined parameters of intensity, pulse duration, and pulse interval, thereby providing multi-layered activation-dependent security. These parameters are retained as manufacturer secrets, eliminating chances of reverse engineering and duplication of the watermark onto fake ICs. A deterministic excitatory post-synaptic current (EPSC)-stimulus model is developed that quantitatively links the optical input to synaptic current evolution, enabling reproducible logic-state transitions. Additionally, the flexible transistor array architecture permits integration of the watermark into wearable electronics. This work establishes an experimentally validated neuromorphic-based security paradigm in the time domain with stimulus-gated concealment, providing a watermarking scheme that functions both as an ownership identifier and as a practical anti-counterfeiting primitive for next-generation secure electronics.
This article investigates the stealthy distributed pole-dynamics attacks (dPDAs) detection for multiagent systems (MASs) by distributed additive watermarking (DAW). First, the limitation of traditional MASs for dPDAs is revealed, where dPDAs cannot be detected. Second, unlike the well-established single-agent additive watermarking, to eliminate the side effect of watermarking signal on system state and enable dPDAs detection, the proposed DAW adds watermarking to the control signal of any agent for transmission and removes watermarking of the control signal after receiving it. Meanwhile, the covariance of the watermarking signal in DAW for all agents is different from each other to enable compromised links isolation. Furthermore, the relationship between the dPDAs detection performance and DAW is quantified in the sense of expectation, where the dPDAs detection performance is directly proportional to the sum of the watermarking covariance of the compromised links. Third, leveraging the relationship between dPDAs detection performance and DAW, a DAW-based link isolation scheme is proposed to accurately isolate the compromised links by comparing with the detection function and its approximation, where the approximation of the detection function is iteratively calculated on all possible attack links combination for the compromised agent. As a result, the adverse impacts of dPDAs on MASs are mitigated. Finally, simulation results are conducted to validate the theoretical results.
Tamper detection is one of the multimedia security issues. Watermarking is an efficient technique for proving ownership, content authentication, copyright protection, and tamper detection. Our objective is to design an adaptable watermarking system that is highly resistant to various attacks. To strike a compromise between imperceptibility and robustness performance against various attacks, the embedding region and embedding strength must be taken as key considerations. Thus, the suggested model uses a novel association rule mining algorithm based on human visual system (HVS) parameters and a modified whale optimization technique to estimate the adaptive embedding region and embedding strength. Along with that, the content authentication data is generated using a transform domain technique, and the tamper localization watermark is generated using the Lightweight CoAtNet model, respectively. For content authentication, the scrambled low-frequency sub-band from the owner's biometric image is obtained using the discrete wavelet transform (DWT) to generate the principal component matrix. To generate the tamper localization watermark, a CoAtNet model extracts robust low-level global features. Prior to embedding, the carrier image is separated into RGB channels and processed using the hybrid Contourlet-DWT framework. Suitable embedding blocks are identified through the HVS-based Apriori algorithm. The selected blocks are further transformed using the Graph Fourier Transform (GFT), where the generated watermark features are embedded. Subsequently, the content authentication watermark is inserted into the DWT mid-frequency sub-band. Finally, the private key is embedded within the detailed contourlet coefficients to produce the copyright-protected watermarked image. Comparative experimental analysis demonstrates that the proposed system achieves superior tamper detectability and enhanced robustness against geometric distortions and multiple signal-processing attacks when compared with existing approaches. Experimental evaluation demonstrates superior imperceptibility and robustness, achieving a maximum PSNR of 64 dB and an NCC of 0.999.
Watermarking technology has become the prime approach for protecting intellectual property (IP) rights of deep learning models (DLM). However, the existing methods only focus on the single watermark format, which cannot simultaneously protect the IP rights of both buyers (users) and sellers (developers). After the model has been redistributed or customized, if the traded model only contains the seller's watermark, the buyer cannot prove their ownership of the model. Conversely, if the model only contains the buyer's watermark, it is difficult to trace its source when the model is stolen or illegally distributed. Therefore, we proposed a simultaneous dual watermarking scheme. Dual watermarks consist of two different trigger sets. Two trigger sets and original datasets are used together as the training set. In particular, the features among the three datasets exhibit a perpendicular relationship. Therefore, this relationship will not affect the model performance. In the proposed scheme, the two trigger sets are constructed by annotation with different chaotic sequences. Due to the sensitivity to the initial value, unpredictability, and non-periodicity of chaos, different initial values produce significantly different chaotic sequences. It guarantees a vertical relationship between features of the three dataset. Statistical analysis indicates that the watermark does not affect the decision boundaries of the DLM and does not show significant statistical characteristics. The experimental results indicate that, compared to other methods, the proposed scheme has superior effectiveness, fidelity, integrity, and robustness against fine-tuning attacks, overwriting attacks, and fraudulent ownership claim attacks.
Digital watermarking is widely used to protect medical images in terms of ownership, authenticity, and traceability; however, the embedding process may introduce subtle modifications that can affect the reliability of deep-learning-based clinical analysis. Existing studies have shown that watermarking has a negligible effect on medical image classification; nevertheless, its impact on segmentation performance remains insufficiently explored. Therefore, this paper aims to investigate the effects of segmentation model enhancement on watermarked medical image analysis. In this context, three representative watermarking approaches were employed, and five baseline segmentation models, namely U-Net, ResUNet++, SegNet, FCDenseNet, and TernausNet, were evaluated on two benchmark datasets: LIDC-IDRI and BRISC. Additionally, a novel deep learning model with nested attention mechanisms was specifically designed to improve feature extraction and increase sensitivity to subtle pixel-level variations in watermarked images. Segmentation performance was assessed using five standard evaluation metrics, including mean Intersection over Union (mIoU), Dice Similarity Coefficient (DSC), and the 95th percentile Hausdorff Distance (HD95). The experimental results indicate consistently minor performance degradation across both datasets. For the BRISC dataset, the reduction in mIoU ranges from 0.15% to 0.44%, while for the LIDC-IDRI dataset, it ranges from 0.19% to 0.29% compared with the no-watermarking baseline. These findings provide quantitative insight into the compatibility of watermarking techniques for medical image protection with AI-based medical image segmentation systems, highlighting their potential for broader clinical application.
Image watermarking is an important extension of intellectual property protection that facilitates the identification and authentication of multimedia content. This paper aims to improve and optimize image watermarking techniques to ensure effective image protection regardless of image size or format. The proposed framework integrates discrete wavelet transform (DWT) and discrete cosine transform (DCT) to enhance watermark embedding performance and preserve data integrity. In addition, the study addresses a common challenge in watermarking systems, namely the increase in perceptible noise that may degrade visual image quality after watermark embedding. To overcome this issue, advanced noise-reduction and feature-processing strategies are incorporated, including AlexNet-based feature extraction, principal component analysis (PCA), independent component analysis (ICA), blind source separation (BSS), and optimization-assisted BSS. Extensive experiments are conducted to evaluate the effectiveness of the proposed method in terms of imperceptibility, robustness, extraction reliability, and computational efficiency. The proposed Dipper-Throated Particle Swarm Optimization (DTPSO) algorithm combined with DWT-DCT achieves a peak signal-to-noise ratio (PSNR) of 65.78 dB, a normalized cross-correlation (NCC) of 0.9189, an accuracy of 0.9766, and a bit error rate (BER) of 0.0234 on color images, demonstrating strong watermark imperceptibility and reliable extraction performance under different attack conditions.In addition, the proposed DWT + DCT+DTPSO model exhibits superior computational efficiency, achieving the lowest execution time of 46.5 s and the minimum memory consumption of 768 MB among the compared methods. These results confirm that the proposed methodology provides an effective and efficient image watermarking solution that enhances the protection, robustness, and integrity of digital multimedia content.
Deepfake detection remains a challenging research topic, especially when the quality of forged images degrades, leading to unreliable detection results. In this paper, we propose a watermarking-based proactive method for robust proactive deepfake detection. First, we embed a watermark into the Fractional-order Quaternion Exponent Moments (FrQEMs) space of the host face image, achieving a balance between imperceptibility and robustness of the watermarking algorithm. Then, we introduce the Frequency Mamba (FreMamba) block to enhance feature extraction by leveraging correlations between frequency-domain subbands, thereby enabling the extraction of more discriminative feature representations. Finally, at the detection stage, we construct a dual-branch framework comprising a watermark extractor and a forgery discriminator. Through knowledge distillation, the watermark extractor guides the forgery discriminator to perceive forgery traces. Specifically, the integrity of the extracted watermark is compromised only when the host image is subjected to a deepfake attack, while conventional attacks do not affect the integrity. Experimental results on benchmark datasets demonstrate that the proposed method achieves superior deepfake detection accuracy. In particular, when images are subjected to conventional attacks, our method surpasses state-of-the-art approaches by more than 5.3% in terms of ACC.
Split-learning-based Virtual Physically Unclonable Functions (VPUFs) in Internet of Things (IoT) networks remain vulnerable to eavesdropping and replay attacks due to insufficient security mechanisms that balance robustness with computational efficiency. This paper proposes a novel digital watermarking approach to improve the security of Split-Learning-based VPUFs. The suggested framework utilizes deep learning-based approaches to generate a watermark to be embedded in the latent representation of the VPUF response to provide additional security against eavesdropping and replay attacks without incurring significant hardware or computational overhead. Watermark embedding is done by simulating Rayleigh fading through Jake's Model to get the secret channel information, which is input to an autoencoder to create a strong latent representation. The formed latent watermark is embedded into the latent response of the VPUF. Experimental testing demonstrates that fidelity remains high under test conditions, reliability, and unforgability, confirming that the watermarking process does not compromise the VPUF's performance. Further, the proposal supports dual-factor authentication through simultaneous verification of the extracted watermark and the retrieved latent response. This research not only enhances the strength and security of the baseline VPUF mechanism but also provides a cost-effective, scalable solution specifically designed for resource-constrained IoT networks.
Invisible watermarking has long been a cornerstone for copyright protection due to its imperceptibility and forensic traceability. However, traditional watermarking remains a passive defense that fails to preclude unauthorized AI-driven analysis, such as the automated categorization and indexing of private media by illicit scrapers. To address this, we propose invisible and robust adversarial watermarking (IRAW), a unified framework that transitions image protection from passive traceability to proactive defense. By leveraging the discrete cosine transform (DCT) domain, IRAW ensures native compatibility with the JPEG compression protocols prevalent on mainstream social media platforms. The framework treats watermark embedding and adversarial perturbation generation as a synergistic optimization task. Specifically, an evolutionary optimization mechanism based on the integration of basin hopping (BH) with crossover and adaptive mutation operators is employed to navigate the search space and identify optimal perturbation patterns. To further enhance security, we implement a cross-domain defense architecture featuring dual spatial-domain encryption for host images and watermarks, combined with frequency-domain coordinate obfuscation. This mechanism not only bolsters cryptographic strength but also increases the structural complexity of perturbations, assisting the BH algorithm in escaping local optima to improve perturbation success rates. Experimental results demonstrate that IRAW generates high-fidelity adversarial examples with exceptional robustness against common image operations, such as JPEG compression and noise, while enabling reliable watermark recovery for forensic provenance. These findings establish IRAW as an effective and industrially compatible mechanism for modern digital image protection.
The growing demand for digital content protection has significantly increased the importance of image watermarking, particularly in light of the rising vulnerability of multimedia content to unauthorized modifications. In recent years, research has increasingly focused on leveraging deep learning architectures to enhance watermarking performance, addressing challenges related to transparency, robustness, and payload capacity. Numerous deep learning-based watermarking methods have demonstrated superior effectiveness compared to traditional approaches, particularly those based on Convolutional Neural Networks (CNNs), Generative Adversarial Networks (GANs), Transformers, and diffusion models. This paper presents a comprehensive survey of recent developments in both conventional and deep learning-based image watermarking techniques. While traditional methods remain prevalent, deep learning approaches offer notable improvements in embedding and extraction efficiency, particularly when facing complex attacks, including those generated by advanced AI models. Applications in areas such as deepfake detection, cybersecurity, and Internet of Things (IoT) systems highlight the practical significance of these advancements. Despite substantial progress, challenges remain in achieving an optimal balance between invisibility, robustness, and capacity, particularly in high-resolution and real-time scenarios. This study concludes by outlining future research directions toward develop robust, scalable, and efficient deep learning-based watermarking systems capable of addressing emerging threats in digital media environments.
Light Field (LF) images provide rich visual representations of 3D scenes by capturing both spatial and angular information of light rays. However, their high dimensions present substantial challenges for conventional 2D image watermarking techniques in effectively ensuring copyright protection. In this work, we propose a deep learning-based Spatial-Angular Consistency waterMarking (SACMark) network, designed to address the unique challenges of watermark embedding and extraction in LF images. SACMark employs a spatial-angular feature extraction module to capture the multidimensional information of LF images and introduces consistency matching and fusion strategies to enhance feature utilization. The network adopts an encoder-noise-decoder architecture, optimized through adversarial training to improve the imperceptibility and robustness of the watermark. Experimental results demonstrate that SACMark maintains high visual quality across various embedding capacities and has minimal impact on depth estimation. Compared to traditional LF watermarking approaches and existing deep learning-based methods for 2D images, SACMark demonstrates improved resilience to noise while preserving essential LF characteristics. These findings suggest that SACMark holds promise for practical applications and may contribute to future developments in secure and adaptive LF image protection.
Zero-watermarking (ZW) presents a promising approach for safeguarding image copyright, as it does not alter the original image, a crucial feature for preserving the integrity of medical and high-fidelity visual data. Nevertheless, numerous existing ZW techniques are susceptible to geometric distortions and signal-processing attacks, thereby offering limited protection for ownership and licensing information. This paper proposes a robust and secure zero-watermarking scheme for medical and natural color images that jointly supports ownership authentication and license verification. The method combines entropy- and SIFT-based sub-region selection, DWT-DCT feature extraction, and XOR fusion between robust features and an Arnold-scrambled logo, followed by an ElGamal-style signcryption of the resulting share. Multiple local zero-watermarks are registered in a Certification Authority (CA), enabling global watermark reconstruction without altering the original image. Experimental results show that the normalized correlation (NC) between the recovered and watermark remains above 0.99 under various geometric and non-geometric attacks, confirming the robustness of the scheme. In addition, the signcryption module incurs low computational overhead, with both the encryption and joint decryption-verification processes requiring approximately 8.5 milliseconds. This overhead is small compared with the transform-based processing time and yields a favorable trade-off between enhanced cryptographic protection of ownership/license records and the computational efficiency required for practical medical imaging and large-scale copyright management systems.