###
计算机系统应用英文版:2025,34(12):55-66
本文二维码信息
码上扫一扫!
图像处理模型的自适应伪装水印方法
(1.南京信息工程大学 数字取证教育部工程研究中心, 南京210044;2.南京信息工程大学 计算机学院、网络安全学院, 南京210044)
Adaptive Camouflage Watermarking Method for Image Processing Models
(1.Engineering Research Center of Digital Forensics Ministry of Education, Nanjing University of Information Science & Technology, Nanjing 210044, China;2.School of Computer Science & School of Cyber Science and Engineering, Nanjing University of Information Science & Technology, Nanjing 210044, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 407次   下载 1107
Received:May 08, 2025    Revised:May 30, 2025
中文摘要: 图像处理模型在各种场景中得到了广泛的应用, 为了防止模型被非法使用, 保护图像处理模型的知识产权变得越来越重要. 针对现有图像处理模型水印方法存在高频伪影、影响模型效率及隐蔽性不足的问题, 本文提出一种图像处理模型的自适应伪装的黑盒水印方案. 通过提取图像颜色特征生成与背景自然融合的伪装纹理作为触发模式, 并设计识别转换模块将触发图像转换为高质量水印图像. 该方法利用HLS直方图滤波和局部聚类算法动态提取主颜色特征, 结合高斯滤波与羽化掩膜技术优化纹理隐蔽性, 确保水印在空域和频域均无伪影干扰. 实验表明, 该方法不影响模型的保真度, 且水印验证匹配率达100%, 同时对模型微调、剪枝等一系列移除和攻击方法均表现出鲁棒性.
Abstract:Image processing models have been widely applied across various scenarios, making the protection of their intellectual property increasingly important to prevent unauthorized use. However, existing watermarking methods are facing various problems, such as high-frequency artifacts, reduced model efficiency, and insufficient imperceptibility. To address these problems, this study proposes a black-box watermarking method with adaptive camouflage for image processing models. The method generates naturally blended camouflage textures as trigger patterns by extracting image color features and designs a recognition and transformation module to convert trigger images into high-quality watermarked images. It dynamically extracts dominant color features using the HLS histogram filtering and a local clustering algorithm, and enhances texture imperceptibility through Gaussian filtering and feathered masking techniques, ensuring that the watermark introduces no visual artifacts in either the spatial or frequency domains. Experimental results demonstrate that the proposed method preserves model fidelity, achieves a 100% watermark verification rate, and maintains robustness against various watermark removal and attack strategies such as fine-tuning and pruning.
文章编号:     中图分类号:    文献标志码:
基金项目:
引用文本:
陈先意,王婷婷,崔琦,周浩.图像处理模型的自适应伪装水印方法.计算机系统应用,2025,34(12):55-66
CHEN Xian-Yi,WANG Ting-Ting,CUI Qi,ZHOU Hao.Adaptive Camouflage Watermarking Method for Image Processing Models.COMPUTER SYSTEMS APPLICATIONS,2025,34(12):55-66