IP Library › Granted Patent US 12,738,282
Granted Patent B2
US 12,738,282 · App. 18/886,824 · Granted Sep 15, 2026

Verifying the provenance of a digital object using watermarking and embeddings

Inventors: Sven Adrian Gowal (Cambridge, GB); Christopher Gamble (London, GB); Florian Nils Stimberg (London, GB); Sylvestre-Alvise Guglielmo Rebuffi (Sceaux, FR); Sree Meghana Thotakuri (London, GB); Jamie Hayes (Levenshulme, GB); Ian Goodfellow (Mountain View, CA); Rudy Bunel (London, GB); Miklós Zsigmond Horváth (London, GB); David Stutz (London, GB); Olivia Anne Wiles (London, GB)
Assignee: GDM Holding LLC
G10L19/018G06F21/16G10L21/0232
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,738,282
App. No.
18/886,824
Granted
Sep 15, 2026
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for verifying the provenance of a digital object generated by a neural network, such as an image or audio object. Also methods, systems, and apparatus, including computer programs, for training a watermarking neural network and a watermark decoding neural network. The described techniques make efficient use of computing resources and are robust to attack.

Claims (43)

1 . A computer-implemented method of training a watermarking system comprising a watermark generation neural network and a watermark decoding neural network, comprising:

for a plurality of images:

processing the image using the watermark generation neural network to generate a watermark for the image;

combining the watermark for the image and the image to obtain a watermarked image;

applying an adversarial transformation to the watermarked image, to generate a perturbed watermarked data object;

applying an adversarial transformation to the image to generate a perturbed data object;

processing the perturbed watermarked data object using the watermark decoding neural network to generate a first watermarking signal that indicates whether or not the perturbed watermarked data object is predicted to be watermarked;

processing the perturbed data object using the watermark decoding neural network to generate a second watermarking signal that indicates whether or not the perturbed data object is predicted to be watermarked; and

jointly training the watermark decoding neural network and the watermark generation neural network, using the first watermarking signal and the second watermarking signal, to distinguish between the perturbed watermarked data object and the perturbed data object.

2 . The method of claim 1 , wherein jointly training the watermark decoding neural network and the watermark generation neural network comprises backpropagating gradients of a classification-based objective function that has a value that depends on classifying the first watermarking signal as indicating that the perturbed watermarked data object is watermarked and classifying the second watermarking signal as indicating that the perturbed data object as not watermarked.

3 . The method of claim 1 , comprising applying the adversarial transformation to the image to generate the perturbed data object, wherein applying the adversarial transformation comprises changing the values of pixels in the image data object.

4 . A computer implemented method of verifying the provenance of a digital object, wherein the digital object comprises an image, the method comprising:

maintaining an object verification system comprising:

a first interface to receive a digital object or a request to generate a digital object;

a second interface to provide a watermarked digital object for use;

an embedding neural network configured to process the digital object to generate an embedding of the digital object; and

an object verification database configured to store at least the embedding of the digital object; the method further comprising:

receiving a query digital object for verification, wherein the query digital object comprises an image;

processing the query digital object using a watermark decoding neural network to generate a watermarking signal for the query digital object;

processing the query digital object using the embedding neural network to generate a query embedding of the query digital object;

interrogating the object verification database using the query embedding to determine a set of one or more similarity scores for a corresponding set of one or more stored embeddings of digital objects that are similar to the query digital object; and

verifying a provenance of the query digital object based on a combination of the watermarking signal and the set of one or more similarity scores.

5 . The method of claim 4 , wherein the object verification system is an object generation and verification system, wherein the request comprises a request to generate the digital object, wherein maintaining the object verification system further comprises maintaining a generative neural network configured to process the request to generate the digital object in accordance with the request; the method further comprising:

receiving a request to generate the digital object;

processing the request using the generative neural network to generate the digital object;

processing the digital object using the watermarking neural network to generate the watermarked digital object by:

processing the digital object using a watermark generation neural network to generate a watermark for the digital object,

combining the watermark and the digital object to obtain a watermarked digital object;

providing the watermarked digital object for use;

processing the digital object using the embedding neural network to generate the embedding of the digital object;

storing the embedding of the digital object in the object verification database; and

verifying the provenance of the query digital object as generated by the object generation and verification system conditional upon the query embedding matching the embedding of the digital object stored in the object verification database.

6 . The method of claim 5 , further comprising:

storing the digital object in the object verification database; and

using the stored digital object to detect attempted removal of a watermark from the query digital object.

7 . The method of claim 4 , wherein the watermarking neural network and the watermark decoding neural network have been jointly trained to generate the watermarking signal under an adversarial perturbation of the watermarked digital object.

8 . The method of claim 4 , wherein the watermarking neural network comprises a neural network with a U-Net architecture and has more trainable parameters than the watermarking decoding neural network.

9 . A computer-implemented method of watermarking an image, the method comprising:

receiving the image, the image having an original size;

generating a resized image by resizing the image to have a target size;

processing the resized image using a watermark generation neural network to generate a watermark for the resized image;

generating a watermarked version of the resized image using the watermark for the image generated by the watermark generation neural network and the resized image; and

resizing the watermarked image to the original size.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2025
From: DEEPMIND TECHNOLOGIES LIMITED
To: GDM HOLDING LLC
Reel/Frame 071498/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2025
From: GOWAL, SVEN ADRIAN; GAMBLE, CHRISTOPHER; STIMBERG, FLORIAN NILS; REBUFFI, SYLVESTRE-ALVISE GUGLIELMO; THOTAKURI, SREE MEGHANA; HAYES, JAMIE; GOODFELLOW, IAN; BUNEL, RUDY; HORVÁTH, MIKLÓS ZSIGMOND; STUTZ, DAVID; WILES, OLIVIA ANNE
To: DEEPMIND TECHNOLOGIES LIMITED
Reel/Frame 070023/0831 →
Priority Claims (1)
EP 23167380 · Apr 11, 2023 · regional
Continuity (2)
Continuation 18510537 · Nov 15, 2023
Related Publication 20250149048A1 · May 8, 2025
References Cited (31)
US 6580809B2 · Stach · 2003 [cited by applicant]
US 7068809B2 · Stach · 2006 [cited by applicant]
US 8050452B2 · Bradley · 2011 [cited by applicant]
US 8548810B2 · Rodriguez · 2013 [cited by applicant]
US 8965547B2 · Wabnik · 2015 [cited by applicant]
US 9305559B2 · Sharma · 2016 [cited by applicant]
US 10236006B1 · Gurijala · 2019 [cited by applicant]
US 10546590B2 · Sharma · 2020 [cited by applicant]
US 11004455B2 · Murtaza · 2021 [cited by applicant]
US 11019407B2 · Revital · 2021 [cited by examiner]
US 11183198B2 · Filler · 2021 [cited by applicant]
US 11354532B1 · Stancil · 2022 [cited by applicant]
US 11538485B2 · Huffman · 2022 [cited by applicant]
US 11625805B2 · Alattar · 2023 [cited by examiner]
US 11990143B2 · Sharma · 2024 [cited by applicant]
US 12050671B2 · Chattopadhyay · 2024 [cited by examiner]
US 12094474B1 · Gowal · 2024 [cited by examiner]
US 12158929B1 · Huang · 2024 [cited by examiner]
US 12260866B2 · Naylor · 2025 [cited by applicant]
US 12417394B2 · Charette · 2025 [cited by examiner]
CN 113990330 · 2022 [cited by applicant]
Chen at al., “A Simple Framework for Contrastive Learning of Visual Representations,” Proceedings of the 37th International Conference on Machine Learning, 2020, 119:1597-1607. [cited by applicant]
Corbett et al., “Spanner: Google's Globally Distributed Database,” ACM Transactions on Computer Systems, Aug. 2013, 31(3):8. [cited by applicant]
Extended Search Report in European Appln. No. 23167380.7, dated Aug. 29, 2023, 15 pages. [cited by applicant]
Hayes et al., “Towards transformation-resilient provenance detection of digital media,” CoRR, Nov. 14, 2020, arXiv:2011.0355v1, 19 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/EP2024/055480, dated Apr. 5, 2024, 33 pages. [cited by applicant]
Neekhara et al., “FaceSigns: Semi-Fragile Neural Watermarks for media authentication and countering deepfakes,” CoRR, Apr. 5, 2022, arxiv.org/abs/2204.01960, 13 pages. [cited by applicant]
Sahar et al., “Adversarial watermarking transformer: Towards tracing text provenance with data hiding,” 2021 IEEE Symposium on Security and Privacy (SP), 2021, 20 pages. [cited by applicant]
Vaswani et al., “Attention Is All You Need,” 31st Conference on Neural Information Processing Systems (NIPS 2017), 2017, 11 pages. [cited by applicant]
Liu et al., “DeAR: A Deep-Learning-Based Audio Re-recording Resilient Watermarking,” The Thirty-Seventh AAAI Conference on Artificial Intelligence (AAAI-23), 2023, pp. 13201-13209. [cited by applicant]
Office Action in Chinese Appln. No. 202480025005.1, mailed on May 25, 2026, 14 pages (with English translation). [cited by applicant]