OSCR

RAN: A randomness-anchored watermark attacking network with stealth and effectiveness.

Code ↔ Paper

3 matches between paragraphs of the paper and lines of its authors' code, computed by the harvester (lexical-v1). Click a colored paragraph or line to see its counterpart.

The 3 matches
  1. [1] § Experiments › Framework developing, training, and attacking ↔ code/finetune.py, lines 39–98 · score 0.56 · randomly split, ADAM, optimizer, epoch, validation, PyTorch
  2. [2] § Related works › Watermark embedding ↔ code/SSIMCompare.py, lines 8–15 · score 0.54 · peak signal, noise ratio, SSIM, PSNR
  3. [3] § Related works › Watermark embedding ↔ code/Compare.py, lines 8–17 · score 0.54 · peak signal, noise ratio, SSIM, PSNR

Paper

Loaded from Europe PMC by your browser, not stored by OSCR: doi.org · Europe PMC

The paper is loaded when this pane is shown.

The authors' code

Python · 249 lines · 12 KB · MIT · 1 match

  1. import torch
  2. from torch import nn
  3. import numpy as np
  4. from torch.utils.data import DataLoader
  5. from torch.utils.tensorboard import SummaryWriter
  6. import nn_UD, nn_CA
  7. from Dataset import watermark_dataset
  8. from extract_methods import extract_and_save
  9. def get_k_fold_data(k, i, all_train_data, all_train_data_list):
  10. # 返回第i折交叉验证时所需要的训练和测试数据,分开放,X_train为训练数据,X_test为验证数据
  11. assert k > 1
  12. fold_size = len(all_train_data) // k # 每份的个数:数据总条数/折数(向下取整)
  13. X_train_list = None
  14. for j in range(k):
  15. idx = slice(j * fold_size, (j + 1) * fold_size) # slice(start,end,step)切片函数 得到测试集的索引
  16. X_part_list = all_train_data_list[idx]
  17. # X_part = watermark_dataset(X_part_list)
  18. # X_part = X[idx] # 只对第一维切片即可
  19. if j == i: # 第i折作test
  20. X_valid_list = X_part_list
  21. print('valid')
  22. print(len(X_valid_list))
  23. elif X_train_list is None:
  24. X_train_list = X_part_list
  25. print('train')
  26. print(len(X_train_list))
  27. else:
  28. # X_train = torch.cat((X_train, X_part), dim=0) # 其他剩余折进行拼接 也仅第一维
  29. X_train_list = np.append(X_train_list, X_part_list)
  30. print('train')
  31. print(len(X_train_list))
  32. return X_train_list, X_valid_list
  33. def finetune(learning_rate, dataset_path, checkpoint_load_path, epoch, loss1_factor, loss2_factor, loss_type, batch_size, log_path):
  34. train_loss_sum, test_loss_sum = 0, 0
  35. all_train_data = watermark_dataset(np.load(dataset_path))
  36. all_train_data_size = len(all_train_data)
  37. # all_train_data_list = np.load(dataset_path)
  38. # epoch = 50
  39. # learning_rate = 0.0002
  40. # batch_size = 32
  41. checkpoint_1 = torch.load(checkpoint_load_path)
  42. writer = SummaryWriter(log_path)
  43. train_size = 3000
  44. validation_size = all_train_data_size - train_size
  45. train_data, validation_data = torch.utils.data.random_split(all_train_data, [train_size, validation_size])
  46. # wmi_train_list, wmi_valid_list = get_k_fold_data(k, i, all_train_data=all_train_data, all_train_data_list=all_train_data_list) # 获取第i折交叉验证的训练和验证数据
  47. # wmi_train = watermark_dataset(wmi_train_list)
  48. # wmi_valid = watermark_dataset(wmi_valid_list)
  49. UD = nn_UD.model_UD(3)
  50. UD = UD.cuda()
  51. UD.load_state_dict(checkpoint_1['net'])
  52. optimizer_1 = torch.optim.Adam(UD.parameters(), lr=learning_rate)
  53. loss_mse = nn.MSELoss()
  54. loss_mse = loss_mse.cuda()
  55. loss_kld = nn.KLDivLoss(reduction="batchmean", log_target=True)
  56. loss_kld = loss_kld.cuda()
  57. total_train_step = 0
  58. loss_min = 0
  59. loss2_min = 0
  60. print("训练集的长度为:{}".format(len(train_data)))
  61. print("验证集的长度为:{}".format(len(validation_data)))
  62. # print("----------第{}折训练开始----------".format(i + 1))
  63. print("0:{}".format(torch.cuda.memory_allocated(0)))
  64. for num in range(epoch):
  65. train_step = 0
  66. UD.train()
  67. print("----------第{}次训练开始----------".format(num + 1))
  68. checkpoint = {
  69. "net": UD.state_dict(),
  70. 'optimizer': optimizer_1.state_dict(),
  71. "epoch": num
  72. }
  73. train_loader = DataLoader(train_data, batch_size=batch_size, shuffle=True)
  74. validation_loader = DataLoader(validation_data, batch_size=batch_size, shuffle=True)
  75. print("1:{}".format(torch.cuda.memory_allocated(0)))
  76. for batch_idx, (wmi) in enumerate(train_loader):
  77. wmi = wmi.cuda() # wmi是加了水印的图片,wm是水印GT
  78. outputs = UD(wmi) # outputs是被攻击后的水印图片
  79. outputs = torch.clamp(outputs, min=0.0, max=255.0)
  80. wmattacked = extract_and_save(1, outputs, train_step) # 提取攻击后的水印,wmattacked是被攻击后的水印
  81. noise_tensor = torch.randint(0, 2, (wmi.shape[0], 1, 32, 32)) * 255
  82. noise_tensor = noise_tensor.to(torch.float32)
  83. wmattacked = torch.tensor(wmattacked, requires_grad=True)
  84. outputs = torch.tensor(outputs, requires_grad=True)
  85. # print(wmattacked.shape, noise_tensor.shape)
  86. loss1_factor_num = loss1_factor
  87. loss2_factor_num = loss2_factor
  88. print("outputs:{}".format(torch.cuda.memory_allocated(0)))
  89. if loss_type == 'KLD':
  90. # noise_tensor = torch.where(noise_tensor <= 1, 0.000001, noise_tensor)
  91. # wmattacked = torch.where(wmattacked <= 1, 0.000001, wmattacked)
  92. # wmattacked = torch.log(wmattacked)
  93. # wmattacked = torch.tensor(wmattacked, requires_grad=True)
  94. # noise_tensor = torch.log(noise_tensor)
  95. wmattacked_list = torch.tensor([])
  96. noise_tensor_list = torch.tensor([])
  97. for i in range(wmattacked.shape[0]):
  98. wmattacked_sum = torch.sum(wmattacked[i])
  99. wmattacked_list = torch.cat((wmattacked_list, torch.tensor([[(1024*255 - wmattacked_sum) / (1024*255), wmattacked_sum / (1024*255)]])), 0)
  100. noise_tensor_list = torch.cat((noise_tensor_list, torch.tensor([[0.5, 0.5]])), 0)
  101. wmattacked_list = torch.log(wmattacked_list)
  102. noise_tensor_list = torch.log(noise_tensor_list)
  103. loss_1 = loss_kld(wmattacked_list, noise_tensor_list)
  104. if loss_type == 'MSE':
  105. loss_1 = loss_mse(wmattacked, noise_tensor) # 被攻击后的水印与随机噪声做loss
  106. # if is_hold = 1:
  107. # loss1_factor_num = 0
  108. if loss_1.item() <= 6000:
  109. # is_hold = 1
  110. loss1_factor_num = 0
  111. else:
  112. loss1_factor_num = loss1_factor
  113. loss_2 = loss_mse(outputs, wmi) # 攻击前后图片做loss
  114. loss = loss_1 * loss1_factor_num + loss_2 * loss2_factor_num #权重调整
  115. # loss = loss_1 + loss_2
  116. print("loss:{}".format(torch.cuda.memory_allocated(0)))
  117. writer.add_scalar("Loss", loss, total_train_step)
  118. writer.add_scalar("Loss_1", loss_1, total_train_step)
  119. writer.add_scalar("Loss_2", loss_2, total_train_step)
  120. # writer.add_scalar("Loss_2", loss_2, total_train_step)
  121. writer.add_image("output", outputs[0], 0)
  122. # print(wmi.shape)
  123. optimizer_1.zero_grad()
  124. # loss_2.backward()
  125. loss.backward()
  126. optimizer_1.step()
  127. train_step += 1
  128. total_train_step += 1
  129. print("backward:{}".format(torch.cuda.memory_allocated(0)))
  130. if train_step % 10 == 0:
  131. # print("训练次数:{}, Loss:{}".format(total_train_step, loss.item()))
  132. # print("第{}折,第{}epoch 训练次数:{}, Loss1:{} Loss2:{} 总Loss:{}".format(i+1, num+1, train_step,
  133. # loss_1.item(), loss_2.item(),
  134. # loss.item()))
  135. print("第{}epoch 训练次数:{}, Loss:{}, Loss1:{}, Loss2:{} ".format( num + 1, train_step,
  136. loss.item(), loss_1.item(),
  137. loss_2.item(),))
  138. # torch.save(checkpoint, './checkpoints/UD_pretrain.pth')
  139. print("2:{}".format(torch.cuda.memory_allocated(0)))
  140. UD.eval()
  141. total_validation_loss = 0
  142. with torch.no_grad():
  143. for batch_idx, (wmi) in enumerate(validation_loader):
  144. wmi = wmi.cuda()
  145. outputs = UD(wmi)
  146. wmattacked = extract_and_save(1, outputs, train_step) # 提取攻击后的水印,wmattacked是被攻击后的水印
  147. noise_tensor = torch.randint(0, 2, (wmi.shape[0], 1, 32, 32)) * 255
  148. noise_tensor = noise_tensor.to(torch.float32)
  149. wmattacked = torch.tensor(wmattacked, requires_grad=True)
  150. outputs = torch.tensor(outputs, requires_grad=True)
  151. # print(wmattacked.shape, noise_tensor.shape)
  152. loss1_factor_num = loss1_factor
  153. loss2_factor_num = loss2_factor
  154. if loss_type == 'KLD':
  155. # noise_tensor = torch.where(noise_tensor <= 1, 0.000001, noise_tensor)
  156. # wmattacked = torch.where(wmattacked <= 1, 0.000001, wmattacked)
  157. # wmattacked = torch.log(wmattacked)
  158. # wmattacked = torch.tensor(wmattacked, requires_grad=True)
  159. # noise_tensor = torch.log(noise_tensor)
  160. wmattacked_list = torch.tensor([])
  161. noise_tensor_list = torch.tensor([])
  162. for i in range(wmattacked.shape[0]):
  163. wmattacked_sum = torch.sum(wmattacked[i])
  164. wmattacked_list = torch.cat((wmattacked_list, torch.tensor(
  165. [[(1024 * 255 - wmattacked_sum) / (1024 * 255), wmattacked_sum / (1024 * 255)]])), 0)
  166. noise_tensor_list = torch.cat((noise_tensor_list, torch.tensor([[0.5, 0.5]])), 0)
  167. wmattacked_list = torch.log(wmattacked_list)
  168. noise_tensor_list = torch.log(noise_tensor_list)
  169. loss_1 = loss_kld(wmattacked_list, noise_tensor_list)
  170. if loss_type == 'MSE':
  171. loss_1 = loss_mse(wmattacked, noise_tensor) # 被攻击后的水印与随机噪声做loss
  172. # if is_hold = 1:
  173. # loss1_factor_num = 0
  174. if loss_1.item() <= 6000:
  175. # is_hold = 1
  176. loss1_factor_num = 0
  177. else:
  178. loss1_factor_num = loss1_factor
  179. loss_2 = loss_mse(outputs, wmi) # 攻击前后图片做loss
  180. loss = loss_1 * loss1_factor + loss_2 * loss2_factor
  181. # loss = loss_1 + loss_2
  182. total_validation_loss += loss.item()
  183. print("3:{}".format(torch.cuda.memory_allocated(0)))
  184. if num == 0:
  185. loss_min = total_validation_loss
  186. if loss_type=='KLD':
  187. torch.save(checkpoint,
  188. '/home/dell/NN/checkpoints/train_total/dataset1/method1/KLD/finetune/UD_finetune.pth')
  189. else:
  190. torch.save(checkpoint, '/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/finetune/UD_finetune.pth')
  191. print('Model Saved')
  192. if loss_min > total_validation_loss:
  193. loss_min = total_validation_loss
  194. if loss_type == 'KLD':
  195. torch.save(checkpoint,
  196. '/home/dell/NN/checkpoints/train_total/dataset1/method1/KLD/finetune/UD_finetune.pth')
  197. else:
  198. torch.save(checkpoint,
  199. '/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/finetune/UD_finetune.pth')
  200. print('Model Saved')
  201. print('Loss_min = {}'.format(loss_min))
  202. # print("第{}epoch测试集上的Loss:{}".format(i+1, total_validation_loss))
  203. print("第{}epoch测试集上的Loss:{}".format(num + 1, total_validation_loss))
  204. print("4:{}".format(torch.cuda.memory_allocated(0)))
  205. if loss_type == 'MSE':
  206. del wmi, outputs, loss_1, loss_2, loss
  207. if loss_type == 'KLD':
  208. del wmi, outputs, loss_1, loss_2, loss, wmattacked_sum, wmattacked_list, noise_tensor_list
  209. torch.cuda.empty_cache()
  210. print("5:{}".format(torch.cuda.memory_allocated(0)))
  211. writer.close()
  212. # finetune(learning_rate=0.00001, dataset_path=r'/home/dell/NN/dataset_list/train_wmi.npy', checkpoint_load_path=r'/home/dell/NN/checkpoints/UD_kfold_0fold.pth'
  213. # , epoch=50, loss1_factor=0.00001, loss2_factor=1, loss_type='KLD', batch_size=40, log_path = '/home/dell/NN/logs/train_total/dataset1/method1/KLD/finetune')
  214. # finetune(learning_rate=0.0002, dataset_path=r'/home/dell/NN/dataset_list/method1/train_wmi.npy',
  215. # checkpoint_load_path=r'/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/k_fold_pretrain/UD_kfold_best.pth',
  216. # epoch=50, loss1_factor=0.0001, loss2_factor=1, loss_type='MSE', batch_size=40,
  217. # log_path = '/home/dell/NN/logs/train_total/dataset1/method1/MSE/finetune')

finetune.py at commit 7cc3a44, under MIT · at the source

Overview

Authors: Fan Li1, Du Li2, Kunqi Li3, Yanyu Jiang4, Yanlin Leng5, Kai Zhou6, Yong Tang5,7
  1. College of Artificial Intelligence, Chengdu University of Information Technology, Chengdu, 610225 China
  2. Sichuan Research Center of Public Security, Chengdu, 610000 China
  3. Department of Electrical and Computer Engineering, State University of New York at Stony Brook, Stony Brook, 11794 USA
  4. Institute of Health Informatics, University College London, London, WC1H 0AX UK
  5. School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, 610054 China
  6. Department of Public Security, Deyang, 618000 China
  7. International Research Center for Complexity Sciences, Hangzhou International Innovation Institute, Beihang University, 311115 China
Journal: Scientific reports, volume 16, issue 1, article 21334
Dates: received 12 February 2026; accepted 4 May 2026; published online 9 May 2026
Type: Research article · Language: English
License: CC BY-NC-ND
Identifiers: DOI 10.1038/s41598-026-52298-w · PMID 42106495 · PMCID PMC13346717 · OpenAlex W7160713638
Open access: gold, a free copy (OpenAlex)
Status: code verified
Methods: Connectivity, Machine learning
Keywords: Watermark attacking, Imperceptibility, Randomness, Engineering, Mathematics and computing
Topic: Advanced Steganography and Watermarking Techniques (Computer Vision and Pattern Recognition, Computer Science), according to OpenAlex
Funding: The key development projects of the Sichuan Provincial Science and Technology (2024YFFK0119)
Citations: not cited yet (Europe PMC); 41 references in the paper

Abstract

The abstract is not reproduced here: the paper's license (CC BY-NC-ND) does not allow it. Read it in the paper, at the publisher or on Europe PMC.

Repository

Its files are read in the Code ↔ Paper reader above, with 3 matches between paragraphs and lines of code.

kq409/Watermark-Attack

License: MIT
State: the link answers, verified on 28 September 2026
Evidence: files inventoried
Commit: 7cc3a440504b10d4b4782dc3475393cf2cdb3e4b, 29 April 2026
Languages: Python (43)
Size: 53 files, 43 scripts
Software Heritage: not archived
Found in: “Data availability”
Holds: README, license file
Not found: CITATION.cff, environment file, tests, continuous integration, documentation
Tools: NumPy (33 files), PyTorch (30 files), Pillow (16 files), OpenCV (11 files), scikit-image (2 files), PyWavelets (1 file)
Availability: 1 check, the latest on 28 September 2026: the link answers
  • 28 September 2026: the link answers
45 files

The paper's code and data availability statement is in the Data section.

Tracing map

Proposed by the machine: these links were found in the paper and verified at the source, without human review. The map will receive a Zenodo DOI once one of the paper's authors has validated it with their ORCID.

What the map holds:

  • 1 repository of the authors' code, each at its verified commit, with its license and how the link was found in the paper;
  • 43 scripts, each with its path and the digest of its content;
  • 3 matches between paragraphs of the paper and lines of the code (method lexical-v1);
  • neither the text of the paper nor the code itself.

Its JSON (tracing-map.json) is deposited on Zenodo with its DOI once the map is validated.

Data

No dataset and no data link were found in the paper.

Code and data availability statement

The paper has a code and data availability statement. Its license (CC BY-NC-ND) does not allow reproducing it here; in short, from what the harvester recognized in it:

Read it in the paper: doi.org/10.1038/s41598-026-52298-w.

Versions

The history of this record: each version stored by the harvester or made by a correction of its authors or of the maintainers of its code, and what changed in its facts. The texts of the paper (its abstract, its availability statements) are not part of it; versions that changed only those are not listed.

Version 1, 28 September 2026: the first record

Recorded: type, language, journal, volume, issue, pages, dates, 7 authors, 5 keywords, 1 funder, 32 references.

Cite

This paper

Li, F., Li, D., Li, K., Jiang, Y., Leng, Y., Zhou, K., & Tang, Y. (2026). RAN: A randomness-anchored watermark attacking network with stealth and effectiveness. Scientific reports, 16(1), 21334. https://doi.org/10.1038/s41598-026-52298-w

BibTeX

@article{li2026ran,
author = {Li, Fan and Li, Du and Li, Kunqi and Jiang, Yanyu and Leng, Yanlin and Zhou, Kai and Tang, Yong},
title = {{RAN: A randomness-anchored watermark attacking network with stealth and effectiveness}},
journal = {Scientific reports},
year = {2026},
month = may,
volume = {16},
number = {1},
pages = {21334},
publisher = {Nature Publishing Group},
issn = {2045-2322},
doi = {10.1038/s41598-026-52298-w},
url = {https://doi.org/10.1038/s41598-026-52298-w},
pmid = {42106495},
pmcid = {PMC13346717}
}

RIS

TY - JOUR
AU - Li, Fan
AU - Li, Du
AU - Li, Kunqi
AU - Jiang, Yanyu
AU - Leng, Yanlin
AU - Zhou, Kai
AU - Tang, Yong
TI - RAN: A randomness-anchored watermark attacking network with stealth and effectiveness
T2 - Scientific reports
J2 - Sci Rep
PY - 2026
DA - 2026/05/09
VL - 16
IS - 1
SP - 21334
SN - 2045-2322
PB - Nature Publishing Group
DO - 10.1038/s41598-026-52298-w
UR - https://doi.org/10.1038/s41598-026-52298-w
LA - en
ER -

CSL-JSON

{
"id": "10.1038/s41598-026-52298-w",
"type": "article-journal",
"title": "RAN: A randomness-anchored watermark attacking network with stealth and effectiveness",
"container-title": "Scientific reports",
"author": [
{
"family": "Li",
"given": "Fan"
},
{
"family": "Li",
"given": "Du"
},
{
"family": "Li",
"given": "Kunqi"
},
{
"family": "Jiang",
"given": "Yanyu"
},
{
"family": "Leng",
"given": "Yanlin"
},
{
"family": "Zhou",
"given": "Kai"
},
{
"family": "Tang",
"given": "Yong"
}
],
"container-title-short": "Sci Rep",
"volume": "16",
"issue": "1",
"page": "21334",
"DOI": "10.1038/s41598-026-52298-w",
"PMID": "42106495",
"PMCID": "PMC13346717",
"ISSN": "2045-2322",
"publisher": "Nature Publishing Group",
"URL": "https://doi.org/10.1038/s41598-026-52298-w",
"language": "en",
"issued": {
"date-parts": [
[
2026,
5,
9
]
]
}
}

The tracing map gets a citation of its own once an author has validated it and it has a DOI.

Similar papers

The papers with a page that share the most with this one: the tools found in their code, their categories, datasets, cited references and authors, the rarest counting most.

[1] doi:10.1038/s41467-026-72057-9 [code]
Sex-specific behavioral feedback modulates sensorimotor processing and drives flexible social behavior.
Journal: Nature communications
In common: PyWavelets, OpenCV, scikit-image, 3 other tools
[2] doi:10.1117/1.nph.13.2.025001 [code]
Surface-based image reconstruction optimization for high-density functional near-infrared spectroscopy.
Journal: Neurophotonics
In common: PyWavelets, OpenCV, scikit-image, 2 other tools
[3] doi:10.1016/j.phro.2026.101056 [code]
Toward uncertainty-aware manual delineation of brain tumours using eye-tracking and image-derived features.
Journal: Physics and imaging in radiation oncology
In common: OpenCV, scikit-image, Pillow, 2 other tools, 1 reference
[4] doi:10.1371/journal.pdig.0001442 [code]
PANDIA: Personalized neuro-symbolic multimodal fusion for interpretable neonatal pain assessment.
Journal: PLOS digital health
In common: PyWavelets, OpenCV, Pillow, 2 other tools
[5] doi:10.1038/s42003-026-10011-7 [code]
Learning brain dynamics across distinct scaling regimes reveals psychiatric signatures.
Journal: Communications biology
In common: PyWavelets, scikit-image, Pillow, 2 other tools
[6] doi:10.1007/s00429-026-03166-w [code]
Autoencoders for unsupervised analysis of rat myeloarchitecture.
Journal: Brain structure & function
In common: OpenCV, scikit-image, Pillow, 2 other tools
[7] doi:10.1038/s42003-026-10957-8 [code]
Brain defence by the extracellular matrix protein Cochlin.
Journal: Communications biology
In common: OpenCV, scikit-image, Pillow, 2 other tools
[8] doi:10.1038/s41467-026-76956-9 [code]
Innervated human cardiac muscle model reveals sympathetic drivers of KCNH2-associated arrhythmias.
Journal: Nature communications
In common: OpenCV, scikit-image, Pillow, 2 other tools
[9] doi:10.1038/s41598-026-61605-4 [code]
Learning precise segmentation of neurofibrillary tangles from rapid manual point annotations.
Journal: Scientific reports
In common: OpenCV, scikit-image, Pillow, 2 other tools
[10] doi:10.1126/sciadv.aed3650 [code]
Truthful visualizations for mass spectrometry imaging enable high-spatial-resolution interactive &lt;i&gt;m/z&lt;/i&gt; mapping and exploration.
Journal: Science advances
In common: OpenCV, scikit-image, Pillow, 2 other tools

Contribute

The authors of this paper can claim it, correct its record and validate its tracing map, and the maintainers of its code (its owner, or a public member of its organization) correct what it says of their repository; anyone signed in can ask for its removal. Every request goes to OSCR's own machine, which answers it; your account page follows them.

Sign in with ORCID to claim this paper as one of its authors, correct its record or validate its tracing map: when the paper's metadata lists your ORCID iD, you are recognized at once. Maintainers of its code: sign in with GitHub, then claim the repository on your account page.

Request its removal

To ask OSCR to remove this record, the copies of its authors' scripts or its tracing map, use the removal request page: signed in, you say who you are, what to remove and why, then review and confirm the request. Published rules decide every request (how).

Discussion, reproductions, activity

Discussion: questions and error reports about this paper and its code, from signed-in readers and its authors. It opens with sign-in.

Reproductions: reports from readers who ran the authors' code: what they reproduced, with which environment, commit and data. It opens with sign-in.

Activity: what happens around this paper: new versions of its record, its map's validation, discussions and reproductions. It opens with sign-in.