AI Secure Watermarking Method Leveraging the Error‐Resistant Nature of Deep Learning Models
Arushi Chatterjee, Chittaranjan Pradhan, Hrudaya Kumar Tripathy, Tarek Gaber, Mohamed Mostafa FouadABSTRACT
The widespread use of generated media based on generative AI models, raises the risks of copyright violation and ownership conflicts. It has also introduced challenges such as deepfake misuse and unauthorised distribution of digital content. Watermarking methodologies, including embedding and tracing, have emerged as solutions for protecting ownership of digital media. This paper introduces a novel cryptographically secure deep learning‐based watermarking methodology. Unlike conventional methods where the given watermark is embedded uniformly across a digital image and recent deep learning‐based approaches that rely on end‐to‐end encoder‐decoder architectures operating over the entire image, this paper is the first to propose a method embedding the watermark in the specific non‐contiguous blocks in the image that were identified using convolutional neural network (CNN). This non‐linear, image‐specific watermark distribution introduces a dynamic unique ‘saliency‐aware’ embedding map for every individual image, significantly increasing the complexity to predict the watermark locations without knowing the right model weights; which improves the resistance to attacks. To address security limitations, the proposed method encrypts the watermark using RSA‐4096 and embeds the encrypted watermark in the selected blocks using the multi‐bit LSB technique. This approach combines the adaptability of deep learning with the robustness of cryptographic security and not only preserves the visual quality of the input image but also achieves a peak PSNR of 55.40 dB and extraction of the watermark with NCC deviation of zero. These results demonstrate the practicality of this proposed method over state‐of‐the‐art methodologies. The encryption of the given watermark before embedding, secures it and shows precise tamper detection (NPCR > 99%, UACI ≈ 33%). In addition to assuring the authenticity of the digital images, the introduced method provides a robust solution for applications requiring data integrity and provenance tracking such as misinformation detection, digital forensics, intellectual property protection, and content management systems.