11 Information Hiding for Spatial and Geographical Data
247
the correspondent sub-blocks in the cover image, the watermark elements w
j in each
sub-block are extracted according to the following rule: w
j =
σ j
−σ j
ασ j
, where w
j are
the diagonal elements of the extracted watermark W
k r i
, while σ j and σ
j are the singular values of H k r i and H
k r i
respectively, for j = 1, . . . , k r i . The extracted watermark
elements w
j are compared to the embedded ones w j by means of correlation.
Our threat model consists of two main categories of attacks: removal (an adversary attempts to discover the embedded watermark and may remove it from the
watermarked image) and distortive (an adversary applies some quality-preserving
transformations, including signal processing techniques, to the watermarking image
making the watermark undetectable). We observe that our scheme is robust against
both categories of attacks. As for the removal attacks, an adversary is unable to remove the watermark, since we assume the adversary has no access to the singular
values of the cover image. Recall that the removal attack is more dangerous, especially in the GIS field, as the digital maps have a great value and then they should
be protected from malicious attacks. As for the distortive attacks, Sect. 11.4.4 shows
that the attacks included in the Checkmark benchmarking tool [20] do not alter the
embedded watermark, which can be detected correctly.
Our scheme has very low false-positive rates. The reader may find further details
in [5].
11.4.4 Experimental Results
In this section, we show the robustness of the block-based SVD watermarking scheme
against possible attacks included in the Checkmark benchmarking tool [20]. We applied our scheme to several images. For space reasons, we summarize in Table 11.1
only the experimental results on the 512 × 512 Aerial grayscale picture, which is illustrated in Fig. 11.4 together with the watermarked image. In the following, we compare
our SVD scheme to the Cox scheme that is implemented according to the original paper on the spread spectrum algorithm [7]. The watermarks are drawn from a Gaussian
distribution N(0, 1) in both schemes. We set the block size m i = 8, i = 1, . . . , B and the
watermark strength α = 0.3 in the SVD scheme, to obtain an acceptable quality difference between the cover image and the watermarked image as for the Cox algorithm
(the PSNR is 30 dB for the SVD scheme and 32 dB for the Cox scheme). In addition,
we observe that by applying our scheme, we may embed a longer watermark in the
image with respect to the Cox scheme, without decreasing the quality difference too
much. By our settings, we embed a watermark of about 8000 elements in the original
image. Embedding 8000 elements in the Cox scheme produces images of lower quality, with PSNR = 25.30 dB. The robustness of the watermarking scheme is evaluated
by means of the correlation measure between the extracted watermark from a possible
counterfeit image and the embedded watermark.
For each attack, we obtain different levels of distortion, by changing the corresponding parameter, that is indicated in the second column of Table 11.1. The
third and the fourth columns show the correlation value between the extracted watermarks from the attacked image and the embedded one for both the watermarking
247
the correspondent sub-blocks in the cover image, the watermark elements w
j in each
sub-block are extracted according to the following rule: w
j =
σ j
−σ j
ασ j
, where w
j are
the diagonal elements of the extracted watermark W
k r i
, while σ j and σ
j are the singular values of H k r i and H
k r i
respectively, for j = 1, . . . , k r i . The extracted watermark
elements w
j are compared to the embedded ones w j by means of correlation.
Our threat model consists of two main categories of attacks: removal (an adversary attempts to discover the embedded watermark and may remove it from the
watermarked image) and distortive (an adversary applies some quality-preserving
transformations, including signal processing techniques, to the watermarking image
making the watermark undetectable). We observe that our scheme is robust against
both categories of attacks. As for the removal attacks, an adversary is unable to remove the watermark, since we assume the adversary has no access to the singular
values of the cover image. Recall that the removal attack is more dangerous, especially in the GIS field, as the digital maps have a great value and then they should
be protected from malicious attacks. As for the distortive attacks, Sect. 11.4.4 shows
that the attacks included in the Checkmark benchmarking tool [20] do not alter the
embedded watermark, which can be detected correctly.
Our scheme has very low false-positive rates. The reader may find further details
in [5].
11.4.4 Experimental Results
In this section, we show the robustness of the block-based SVD watermarking scheme
against possible attacks included in the Checkmark benchmarking tool [20]. We applied our scheme to several images. For space reasons, we summarize in Table 11.1
only the experimental results on the 512 × 512 Aerial grayscale picture, which is illustrated in Fig. 11.4 together with the watermarked image. In the following, we compare
our SVD scheme to the Cox scheme that is implemented according to the original paper on the spread spectrum algorithm [7]. The watermarks are drawn from a Gaussian
distribution N(0, 1) in both schemes. We set the block size m i = 8, i = 1, . . . , B and the
watermark strength α = 0.3 in the SVD scheme, to obtain an acceptable quality difference between the cover image and the watermarked image as for the Cox algorithm
(the PSNR is 30 dB for the SVD scheme and 32 dB for the Cox scheme). In addition,
we observe that by applying our scheme, we may embed a longer watermark in the
image with respect to the Cox scheme, without decreasing the quality difference too
much. By our settings, we embed a watermark of about 8000 elements in the original
image. Embedding 8000 elements in the Cox scheme produces images of lower quality, with PSNR = 25.30 dB. The robustness of the watermarking scheme is evaluated
by means of the correlation measure between the extracted watermark from a possible
counterfeit image and the embedded watermark.
For each attack, we obtain different levels of distortion, by changing the corresponding parameter, that is indicated in the second column of Table 11.1. The
third and the fourth columns show the correlation value between the extracted watermarks from the attacked image and the embedded one for both the watermarking
