RAN: A randomness-anchored watermark attacking network with stealth and effectiveness.
The 3 matches
- [1] § Experiments › Framework developing, training, and attacking ↔ code/finetune.py, lines 39–98 · score 0.56 · randomly split, ADAM, optimizer, epoch, validation, PyTorch
- [2] § Related works › Watermark embedding ↔ code/SSIMCompare.py, lines 8–15 · score 0.54 · peak signal, noise ratio, SSIM, PSNR
- [3] § Related works › Watermark embedding ↔ code/Compare.py, lines 8–17 · score 0.54 · peak signal, noise ratio, SSIM, PSNR
Paper
Loaded from Europe PMC by your browser, not stored by OSCR: doi.org · Europe PMC
The paper is loaded when this pane is shown.
The authors' code
Python · 249 lines · 12 KB · MIT · 1 match
- import torch
- from torch import nn
- import numpy as np
- from torch.utils.data import DataLoader
- from torch.utils.tensorboard import SummaryWriter
- import nn_UD, nn_CA
- from Dataset import watermark_dataset
- from extract_methods import extract_and_save
- def get_k_fold_data(k, i, all_train_data, all_train_data_list):
- # 返回第i折交叉验证时所需要的训练和测试数据,分开放,X_train为训练数据,X_test为验证数据
- assert k > 1
- fold_size = len(all_train_data) // k # 每份的个数:数据总条数/折数(向下取整)
- X_train_list = None
- for j in range(k):
- idx = slice(j * fold_size, (j + 1) * fold_size) # slice(start,end,step)切片函数 得到测试集的索引
- X_part_list = all_train_data_list[idx]
- # X_part = watermark_dataset(X_part_list)
- # X_part = X[idx] # 只对第一维切片即可
- if j == i: # 第i折作test
- X_valid_list = X_part_list
- print('valid')
- print(len(X_valid_list))
- elif X_train_list is None:
- X_train_list = X_part_list
- print('train')
- print(len(X_train_list))
- else:
- # X_train = torch.cat((X_train, X_part), dim=0) # 其他剩余折进行拼接 也仅第一维
- X_train_list = np.append(X_train_list, X_part_list)
- print('train')
- print(len(X_train_list))
- return X_train_list, X_valid_list
- def finetune(learning_rate, dataset_path, checkpoint_load_path, epoch, loss1_factor, loss2_factor, loss_type, batch_size, log_path):
- train_loss_sum, test_loss_sum = 0, 0
- all_train_data = watermark_dataset(np.load(dataset_path))
- all_train_data_size = len(all_train_data)
- # all_train_data_list = np.load(dataset_path)
- # epoch = 50
- # learning_rate = 0.0002
- # batch_size = 32
- checkpoint_1 = torch.load(checkpoint_load_path)
- writer = SummaryWriter(log_path)
- train_size = 3000
- validation_size = all_train_data_size - train_size
- train_data, validation_data = torch.utils.data.random_split(all_train_data, [train_size, validation_size])
- # wmi_train_list, wmi_valid_list = get_k_fold_data(k, i, all_train_data=all_train_data, all_train_data_list=all_train_data_list) # 获取第i折交叉验证的训练和验证数据
- # wmi_train = watermark_dataset(wmi_train_list)
- # wmi_valid = watermark_dataset(wmi_valid_list)
- UD = nn_UD.model_UD(3)
- UD = UD.cuda()
- UD.load_state_dict(checkpoint_1['net'])
- optimizer_1 = torch.optim.Adam(UD.parameters(), lr=learning_rate)
- loss_mse = nn.MSELoss()
- loss_mse = loss_mse.cuda()
- loss_kld = nn.KLDivLoss(reduction="batchmean", log_target=True)
- loss_kld = loss_kld.cuda()
- total_train_step = 0
- loss_min = 0
- loss2_min = 0
- print("训练集的长度为:{}".format(len(train_data)))
- print("验证集的长度为:{}".format(len(validation_data)))
- # print("----------第{}折训练开始----------".format(i + 1))
- print("0:{}".format(torch.cuda.memory_allocated(0)))
- for num in range(epoch):
- train_step = 0
- UD.train()
- print("----------第{}次训练开始----------".format(num + 1))
- checkpoint = {
- "net": UD.state_dict(),
- 'optimizer': optimizer_1.state_dict(),
- "epoch": num
- }
- train_loader = DataLoader(train_data, batch_size=batch_size, shuffle=True)
- validation_loader = DataLoader(validation_data, batch_size=batch_size, shuffle=True)
- print("1:{}".format(torch.cuda.memory_allocated(0)))
- for batch_idx, (wmi) in enumerate(train_loader):
- wmi = wmi.cuda() # wmi是加了水印的图片,wm是水印GT
- outputs = UD(wmi) # outputs是被攻击后的水印图片
- outputs = torch.clamp(outputs, min=0.0, max=255.0)
- wmattacked = extract_and_save(1, outputs, train_step) # 提取攻击后的水印,wmattacked是被攻击后的水印
- noise_tensor = torch.randint(0, 2, (wmi.shape[0], 1, 32, 32)) * 255
- noise_tensor = noise_tensor.to(torch.float32)
- wmattacked = torch.tensor(wmattacked, requires_grad=True)
- outputs = torch.tensor(outputs, requires_grad=True)
- # print(wmattacked.shape, noise_tensor.shape)
- loss1_factor_num = loss1_factor
- loss2_factor_num = loss2_factor
- print("outputs:{}".format(torch.cuda.memory_allocated(0)))
- if loss_type == 'KLD':
- # noise_tensor = torch.where(noise_tensor <= 1, 0.000001, noise_tensor)
- # wmattacked = torch.where(wmattacked <= 1, 0.000001, wmattacked)
- # wmattacked = torch.log(wmattacked)
- # wmattacked = torch.tensor(wmattacked, requires_grad=True)
- # noise_tensor = torch.log(noise_tensor)
- wmattacked_list = torch.tensor([])
- noise_tensor_list = torch.tensor([])
- for i in range(wmattacked.shape[0]):
- wmattacked_sum = torch.sum(wmattacked[i])
- wmattacked_list = torch.cat((wmattacked_list, torch.tensor([[(1024*255 - wmattacked_sum) / (1024*255), wmattacked_sum / (1024*255)]])), 0)
- noise_tensor_list = torch.cat((noise_tensor_list, torch.tensor([[0.5, 0.5]])), 0)
- wmattacked_list = torch.log(wmattacked_list)
- noise_tensor_list = torch.log(noise_tensor_list)
- loss_1 = loss_kld(wmattacked_list, noise_tensor_list)
- if loss_type == 'MSE':
- loss_1 = loss_mse(wmattacked, noise_tensor) # 被攻击后的水印与随机噪声做loss
- # if is_hold = 1:
- # loss1_factor_num = 0
- if loss_1.item() <= 6000:
- # is_hold = 1
- loss1_factor_num = 0
- else:
- loss1_factor_num = loss1_factor
- loss_2 = loss_mse(outputs, wmi) # 攻击前后图片做loss
- loss = loss_1 * loss1_factor_num + loss_2 * loss2_factor_num #权重调整
- # loss = loss_1 + loss_2
- print("loss:{}".format(torch.cuda.memory_allocated(0)))
- writer.add_scalar("Loss", loss, total_train_step)
- writer.add_scalar("Loss_1", loss_1, total_train_step)
- writer.add_scalar("Loss_2", loss_2, total_train_step)
- # writer.add_scalar("Loss_2", loss_2, total_train_step)
- writer.add_image("output", outputs[0], 0)
- # print(wmi.shape)
- optimizer_1.zero_grad()
- # loss_2.backward()
- loss.backward()
- optimizer_1.step()
- train_step += 1
- total_train_step += 1
- print("backward:{}".format(torch.cuda.memory_allocated(0)))
- if train_step % 10 == 0:
- # print("训练次数:{}, Loss:{}".format(total_train_step, loss.item()))
- # print("第{}折,第{}epoch 训练次数:{}, Loss1:{} Loss2:{} 总Loss:{}".format(i+1, num+1, train_step,
- # loss_1.item(), loss_2.item(),
- # loss.item()))
- print("第{}epoch 训练次数:{}, Loss:{}, Loss1:{}, Loss2:{} ".format( num + 1, train_step,
- loss.item(), loss_1.item(),
- loss_2.item(),))
- # torch.save(checkpoint, './checkpoints/UD_pretrain.pth')
- print("2:{}".format(torch.cuda.memory_allocated(0)))
- UD.eval()
- total_validation_loss = 0
- with torch.no_grad():
- for batch_idx, (wmi) in enumerate(validation_loader):
- wmi = wmi.cuda()
- outputs = UD(wmi)
- wmattacked = extract_and_save(1, outputs, train_step) # 提取攻击后的水印,wmattacked是被攻击后的水印
- noise_tensor = torch.randint(0, 2, (wmi.shape[0], 1, 32, 32)) * 255
- noise_tensor = noise_tensor.to(torch.float32)
- wmattacked = torch.tensor(wmattacked, requires_grad=True)
- outputs = torch.tensor(outputs, requires_grad=True)
- # print(wmattacked.shape, noise_tensor.shape)
- loss1_factor_num = loss1_factor
- loss2_factor_num = loss2_factor
- if loss_type == 'KLD':
- # noise_tensor = torch.where(noise_tensor <= 1, 0.000001, noise_tensor)
- # wmattacked = torch.where(wmattacked <= 1, 0.000001, wmattacked)
- # wmattacked = torch.log(wmattacked)
- # wmattacked = torch.tensor(wmattacked, requires_grad=True)
- # noise_tensor = torch.log(noise_tensor)
- wmattacked_list = torch.tensor([])
- noise_tensor_list = torch.tensor([])
- for i in range(wmattacked.shape[0]):
- wmattacked_sum = torch.sum(wmattacked[i])
- wmattacked_list = torch.cat((wmattacked_list, torch.tensor(
- [[(1024 * 255 - wmattacked_sum) / (1024 * 255), wmattacked_sum / (1024 * 255)]])), 0)
- noise_tensor_list = torch.cat((noise_tensor_list, torch.tensor([[0.5, 0.5]])), 0)
- wmattacked_list = torch.log(wmattacked_list)
- noise_tensor_list = torch.log(noise_tensor_list)
- loss_1 = loss_kld(wmattacked_list, noise_tensor_list)
- if loss_type == 'MSE':
- loss_1 = loss_mse(wmattacked, noise_tensor) # 被攻击后的水印与随机噪声做loss
- # if is_hold = 1:
- # loss1_factor_num = 0
- if loss_1.item() <= 6000:
- # is_hold = 1
- loss1_factor_num = 0
- else:
- loss1_factor_num = loss1_factor
- loss_2 = loss_mse(outputs, wmi) # 攻击前后图片做loss
- loss = loss_1 * loss1_factor + loss_2 * loss2_factor
- # loss = loss_1 + loss_2
- total_validation_loss += loss.item()
- print("3:{}".format(torch.cuda.memory_allocated(0)))
- if num == 0:
- loss_min = total_validation_loss
- if loss_type=='KLD':
- torch.save(checkpoint,
- '/home/dell/NN/checkpoints/train_total/dataset1/method1/KLD/finetune/UD_finetune.pth')
- else:
- torch.save(checkpoint, '/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/finetune/UD_finetune.pth')
- print('Model Saved')
- if loss_min > total_validation_loss:
- loss_min = total_validation_loss
- if loss_type == 'KLD':
- torch.save(checkpoint,
- '/home/dell/NN/checkpoints/train_total/dataset1/method1/KLD/finetune/UD_finetune.pth')
- else:
- torch.save(checkpoint,
- '/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/finetune/UD_finetune.pth')
- print('Model Saved')
- print('Loss_min = {}'.format(loss_min))
- # print("第{}epoch测试集上的Loss:{}".format(i+1, total_validation_loss))
- print("第{}epoch测试集上的Loss:{}".format(num + 1, total_validation_loss))
- print("4:{}".format(torch.cuda.memory_allocated(0)))
- if loss_type == 'MSE':
- del wmi, outputs, loss_1, loss_2, loss
- if loss_type == 'KLD':
- del wmi, outputs, loss_1, loss_2, loss, wmattacked_sum, wmattacked_list, noise_tensor_list
- torch.cuda.empty_cache()
- print("5:{}".format(torch.cuda.memory_allocated(0)))
- writer.close()
- # finetune(learning_rate=0.00001, dataset_path=r'/home/dell/NN/dataset_list/train_wmi.npy', checkpoint_load_path=r'/home/dell/NN/checkpoints/UD_kfold_0fold.pth'
- # , epoch=50, loss1_factor=0.00001, loss2_factor=1, loss_type='KLD', batch_size=40, log_path = '/home/dell/NN/logs/train_total/dataset1/method1/KLD/finetune')
- # finetune(learning_rate=0.0002, dataset_path=r'/home/dell/NN/dataset_list/method1/train_wmi.npy',
- # checkpoint_load_path=r'/home/dell/NN/checkpoints/train_total/dataset1/method1/MSE/k_fold_pretrain/UD_kfold_best.pth',
- # epoch=50, loss1_factor=0.0001, loss2_factor=1, loss_type='MSE', batch_size=40,
- # log_path = '/home/dell/NN/logs/train_total/dataset1/method1/MSE/finetune')
finetune.py at commit 7cc3a44, under MIT · at the source
Overview
- College of Artificial Intelligence, Chengdu University of Information Technology, Chengdu, 610225 China
- Sichuan Research Center of Public Security, Chengdu, 610000 China
- Department of Electrical and Computer Engineering, State University of New York at Stony Brook, Stony Brook, 11794 USA
- Institute of Health Informatics, University College London, London, WC1H 0AX UK
- School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, 610054 China
- Department of Public Security, Deyang, 618000 China
- International Research Center for Complexity Sciences, Hangzhou International Innovation Institute, Beihang University, 311115 China
Abstract
The abstract is not reproduced here: the paper's license (CC BY-NC-ND) does not allow it. Read it in the paper, at the publisher or on Europe PMC.
Repository
Its files are read in the Code ↔ Paper reader above, with 3 matches between paragraphs and lines of code.
kq409/Watermark-Attack
7cc3a440504b10d4b4782dc3475393cf2cdb3e4b, 29 April 2026Availability: 1 check, the latest on 28 September 2026: the link answers
- 28 September 2026: the link answers
45 files
- code/
BER.py , Python, 52 lines - code/
BER_calculate.py , Python, 21 lines - code/
Compare.py , Python, 29 lines, 1 match - code/
DCTDWTSVD.py , Python, 462 lines - code/
Dataset.py , Python, 25 lines - code/
SSIMCompare.py , Python, 29 lines, 1 match - code/
U-Net.py , Python, 112 lines - code/
clamptest.py , Python, 7 lines - code/
diff.py , Python, 12 lines - code/
example_generate.py , Python, 199 lines - code/
extract_methods.py , Python, 67 lines - code/
finetune.py , Python, 249 lines, 1 match - code/
first demo.py , Python, 49 lines - code/
htmlgenerator.py , Python, 106 lines - code/
j2b.py , Python, 91 lines - code/
k_fold.py , Python, 177 lines - code/
k_fold_check.py , Python, 449 lines - code/
k_fold_copy.py , Python, 216 lines - code/
k_fold_finetune(1).py , Python, 272 lines - code/
k_fold_finetune.py , Python, 274 lines - code/
k_fold_image.py , Python, 190 lines - code/
k_fold_pretrain(1).py , Python, 195 lines - code/
k_fold_pretrain.py , Python, 195 lines - code/
makelist.py , Python, 57 lines - code/
measure.py , Python, 126 lines - code/
model_eval.py , Python, 70 lines - code/
model_test.py , Python, 76 lines - code/
model_test_copy.py , Python, 76 lines - code/
model_test_factors.py , Python, 68 lines - code/
nn_CA.py , Python, 128 lines - code/
nn_UD.py , Python, 122 lines - code/
nn_UD_1.py , Python, 147 lines - code/
nn_module.py , Python, 121 lines - code/
randomgenerator.py , Python, 14 lines - code/
randomgenerator_copy.py , Python, 19 lines - code/
show.py , Python, 60 lines - code/
test.py , Python, 23 lines - code/
test_html.py , Python, 74 lines - code/
train.py , Python, 185 lines - code/
train_copy.py , Python, 185 lines - code/
train_finetune.py , Python, 190 lines - code/
train_run(1).py , Python, 53 lines - code/
train_run.py , Python, 53 lines - LICENSE, License, 21 lines
- README.md, Text, 3 lines
The paper's code and data availability statement is in the Data section.
Tracing map
Proposed by the machine: these links were found in the paper and verified at the source, without human review. The map will receive a Zenodo DOI once one of the paper's authors has validated it with their ORCID.
What the map holds:
- 1 repository of the authors' code, each at its verified commit, with its license and how the link was found in the paper;
- 43 scripts, each with its path and the digest of its content;
- 3 matches between paragraphs of the paper and lines of the code (method lexical-v1);
- neither the text of the paper nor the code itself.
Its JSON (tracing-map.json) is deposited on Zenodo with its DOI once the map is validated.
Data
No dataset and no data link were found in the paper.
Code and data availability statement
The paper has a code and data availability statement. Its license (CC BY-NC-ND) does not allow reproducing it here; in short, from what the harvester recognized in it:
- it points to the authors' code: kq409/
Watermark-Attack
Read it in the paper: doi.org/10.1038/s41598-026-52298-w.
Versions
The history of this record: each version stored by the harvester or made by a correction of its authors or of the maintainers of its code, and what changed in its facts. The texts of the paper (its abstract, its availability statements) are not part of it; versions that changed only those are not listed.
Version 1, 28 September 2026: the first record
Recorded: type, language, journal, volume, issue, pages, dates, 7 authors, 5 keywords, 1 funder, 32 references.
Cite
This paper
Li, F., Li, D., Li, K., Jiang, Y., Leng, Y., Zhou, K., & Tang, Y. (2026). RAN: A randomness-anchored watermark attacking network with stealth and effectiveness. Scientific reports, 16(1), 21334. https://
BibTeX
@article{li2026ran,
author = {Li, Fan and Li, Du and Li, Kunqi and Jiang, Yanyu and Leng, Yanlin and Zhou, Kai and Tang, Yong},
title = {{RAN: A randomness-anchored watermark attacking network with stealth and effectiveness}},
journal = {Scientific reports},
year = {2026},
month = may,
volume = {16},
number = {1},
pages = {21334},
publisher = {Nature Publishing Group},
issn = {2045-2322},
doi = {10.1038/
url = {https://
pmid = {42106495},
pmcid = {PMC13346717}
}
RIS
TY - JOUR
AU - Li, Fan
AU - Li, Du
AU - Li, Kunqi
AU - Jiang, Yanyu
AU - Leng, Yanlin
AU - Zhou, Kai
AU - Tang, Yong
TI - RAN: A randomness-anchored watermark attacking network with stealth and effectiveness
T2 - Scientific reports
J2 - Sci Rep
PY - 2026
DA - 2026/
VL - 16
IS - 1
SP - 21334
SN - 2045-2322
PB - Nature Publishing Group
DO - 10.1038/
UR - https://
LA - en
ER -
CSL-JSON
{
"id": "10.1038/
"type": "article-journal",
"title": "RAN: A randomness-anchored watermark attacking network with stealth and effectiveness",
"container-title": "Scientific reports",
"author": [
{
"family": "Li",
"given": "Fan"
},
{
"family": "Li",
"given": "Du"
},
{
"family": "Li",
"given": "Kunqi"
},
{
"family": "Jiang",
"given": "Yanyu"
},
{
"family": "Leng",
"given": "Yanlin"
},
{
"family": "Zhou",
"given": "Kai"
},
{
"family": "Tang",
"given": "Yong"
}
],
"container-title-short":
"volume": "16",
"issue": "1",
"page": "21334",
"DOI": "10.1038/
"PMID": "42106495",
"PMCID": "PMC13346717",
"ISSN": "2045-2322",
"publisher": "Nature Publishing Group",
"URL": "https://
"language": "en",
"issued": {
"date-parts": [
[
2026,
5,
9
]
]
}
}
The tracing map gets a citation of its own once an author has validated it and it has a DOI.
Similar papers
The papers with a page that share the most with this one: the tools found in their code, their categories, datasets, cited references and authors, the rarest counting most.
- [1] doi:10.1038/s41467-026-72057-9 [code]
- Sex-specific behavioral feedback modulates sensorimotor processing and drives flexible social behavior.Journal: Nature communicationsIn common: PyWavelets, OpenCV, scikit-image, 3 other tools
- [2] doi:10.1117/1.nph.13.2.025001 [code]
- Surface-based image reconstruction optimization for high-density functional near-infrared spectroscopy.Journal: NeurophotonicsIn common: PyWavelets, OpenCV, scikit-image, 2 other tools
- [3] doi:10.1016/j.phro.2026.101056 [code]
- Toward uncertainty-aware manual delineation of brain tumours using eye-tracking and image-derived features.Journal: Physics and imaging in radiation oncologyIn common: OpenCV, scikit-image, Pillow, 2 other tools, 1 reference
- [4] doi:10.1371/journal.pdig.0001442 [code]
- PANDIA: Personalized neuro-symbolic multimodal fusion for interpretable neonatal pain assessment.Journal: PLOS digital healthIn common: PyWavelets, OpenCV, Pillow, 2 other tools
- [5] doi:10.1038/s42003-026-10011-7 [code]
- Learning brain dynamics across distinct scaling regimes reveals psychiatric signatures.Journal: Communications biologyIn common: PyWavelets, scikit-image, Pillow, 2 other tools
- [6] doi:10.1007/s00429-026-03166-w [code]
- Autoencoders for unsupervised analysis of rat myeloarchitecture.Journal: Brain structure & functionIn common: OpenCV, scikit-image, Pillow, 2 other tools
- [7] doi:10.1038/s42003-026-10957-8 [code]
- Brain defence by the extracellular matrix protein Cochlin.Journal: Communications biologyIn common: OpenCV, scikit-image, Pillow, 2 other tools
- [8] doi:10.1038/s41467-026-76956-9 [code]
- Innervated human cardiac muscle model reveals sympathetic drivers of KCNH2-associated arrhythmias.Journal: Nature communicationsIn common: OpenCV, scikit-image, Pillow, 2 other tools
- [9] doi:10.1038/s41598-026-61605-4 [code]
- Learning precise segmentation of neurofibrillary tangles from rapid manual point annotations.Journal: Scientific reportsIn common: OpenCV, scikit-image, Pillow, 2 other tools
- [10] doi:10.1126/sciadv.aed3650 [code]
- Truthful visualizations for mass spectrometry imaging enable high-spatial-resolution interactive &
lt;i& gt;m/ z& lt;/ i& gt; mapping and exploration. Journal: Science advancesIn common: OpenCV, scikit-image, Pillow, 2 other tools
Contribute
The authors of this paper can claim it, correct its record and validate its tracing map, and the maintainers of its code (its owner, or a public member of its organization) correct what it says of their repository; anyone signed in can ask for its removal. Every request goes to OSCR's own machine, which answers it; your account page follows them.
Sign in with ORCID to claim this paper as one of its authors, correct its record or validate its tracing map: when the paper's metadata lists your ORCID iD, you are recognized at once. Maintainers of its code: sign in with GitHub, then claim the repository on your account page.
Claim this paper
Correct its record
Say what each link of this record is, remove the ones that are not the paper's, add the ones that are missing. The correction becomes a new version of the record, in its Versions section.
Validate its tracing map
You validate the map as this page shows it: 1 repository of the authors' code, each at its verified commit and with its license, 43 scripts, and 3 matches between paragraphs and code (see the Code and Map sections). It then receives a DOI on Zenodo, with you (your ORCID iD) and OSCR as its creators; the code itself is not deposited.
The map's fingerprint: sha256:76fc5ebf97323ac8…
Add the badge to its README
The badge links the code to this page. Copy one of these into the README of the paper's code: only you decide where it goes, and nothing is changed for you.
Markdown
[, paste the snippet at the top, then “Commit changes…” and, to review it first, “Create a new branch and start a pull request”. You open the pull request; OSCR asks for no permission.
Request its removal
To ask OSCR to remove this record, the copies of its authors' scripts or its tracing map, use the removal request page: signed in, you say who you are, what to remove and why, then review and confirm the request. Published rules decide every request (how).
Discussion, reproductions, activity
Discussion: questions and error reports about this paper and its code, from signed-in readers and its authors. It opens with sign-in.
Reproductions: reports from readers who ran the authors' code: what they reproduced, with which environment, commit and data. It opens with sign-in.
Activity: what happens around this paper: new versions of its record, its map's validation, discussions and reproductions. It opens with sign-in.
