Papers
Topics
Authors
Recent
Search
2000 character limit reached

Double-Tag Technique in Watermarking & Classification

Updated 11 January 2026
  • Double-Tag Technique is a method that uses two independent tagging phases in both digital watermarking and data-driven classifier training to enhance robustness and detectability.
  • In watermarking, the approach embeds watermarks via DCT and SVD, achieving high PSNR (≈52.5 dB) even after noise attacks and ensuring reliable extraction.
  • For classifier training, the Tag N’ Train method iteratively refines weak taggers into strong classifiers, improving metrics such as AUC from 0.65 to 0.82 in practical experiments.

The double-tag technique refers to two distinct but structurally parallel methodologies for improving robustness and performance in two research domains: (1) digital watermarking via DCT and SVD dual-embedding, and (2) data-driven classifier training via the Tag N’ Train (TNT) bootstrapping scheme. Both approaches utilize two independent “tagging” or embedding phases—one to enhance imperceptibility and resilience, the other to leverage complementary information for inference or classification. This entry synthesizes the formal models, mathematical foundations, algorithmic steps, and experimental outcomes of these methods as established by the seminal works "A DCT And SVD based Watermarking Technique To Identify Tag" (Ji et al., 2015) and "Tag N' Train: A Technique to Train Improved Classifiers on Unlabeled Data" (Amram et al., 2020).

1. Double-Embedding for Digital Watermarking: DCT+SVD Scheme

The double-tag watermarking approach for images involves consecutive embedding of watermark information in both the frequency domain and the singular value domain. The process is comprised of two main stages:

  • DCT-Based Embedding: The cover image ff of size M×NM \times N is segmented into 8×88 \times 8 blocks. For each block fn(x,y)f_n(x,y), the 2D DCT is applied:

Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)

The watermark is embedded by adding scaled watermark bits wiw_i to selected mid-band diagonal coefficients:

Xn′(ui,ui)=Xn(ui,ui)+αwi,α=0.05X_n'(u_i,u_i) = X_n(u_i,u_i) + \alpha w_i,\qquad \alpha=0.05

The inverse DCT reconstructs the intermediate watermarked image f′f'.

  • SVD-Based Embedding: The intermediate image f′f' is again blockwise decomposed, and each block AnA_n undergoes SVD:

M×NM \times N0

The same or a different M×NM \times N1-bit watermark is embedded into the singular values:

M×NM \times N2

M×NM \times N3 is a diagonal matrix encoding the watermark bits. Each block is recomposed to obtain the final doubly watermarked image M×NM \times N4.

This architecture ensures that the watermark information resides simultaneously in two distinct transform domains (DCT and SVD), strengthening resistance to removal or distortion in either domain alone.

2. Extraction, Performance Criteria, and Robustness

Extraction operates in reverse:

  • SVD-Phase Extraction: Each watermarked image block M×NM \times N5 undergoes SVD:

M×NM \times N6

The embedded bits are estimated by:

M×NM \times N7

where M×NM \times N8 are the singular values from the intermediate image M×NM \times N9.

  • DCT-Phase Extraction: After SVD extraction and optional reconstruction of 8×88 \times 80, DCT is again applied blockwise to extract watermark bits from mid-band diagonal coefficients as:

8×88 \times 81

Robustness is quantified using Peak Signal-to-Noise Ratio (PSNR),

8×88 \times 82

where 8×88 \times 83 for 8-bit images and MSE is mean squared error. For 8×88 \times 84, typical PSNR is 52.49 dB (imperceptible distortion). Even after attacks (Gaussian, salt-and-pepper noise), PSNR remains above 35 dB, and watermark recoverability is preserved. The threshold PSNR8×88 \times 85 (e.g., 8×88 \times 86 dB) is adopted for authenticity verification (Ji et al., 2015).

3. Double-Tag Bootstrapping for Data-Driven Classifier Training

The TNT (Tag N’ Train) methodology applies a two-phase tagging protocol to exploit structure in unlabeled datasets, particularly events with two correlated sub-objects, such as dijet events in collider physics. The core procedure is:

  • Phase 1: Weak Tagging. A weak classifier 8×88 \times 87 is deployed on object 8×88 \times 88 in every event. Thresholds 8×88 \times 89 partition the dataset into signal-rich (fn(x,y)f_n(x,y)0) and background-rich (fn(x,y)f_n(x,y)1) samples:

fn(x,y)f_n(x,y)2

In collider settings, fn(x,y)f_n(x,y)3 is often an autoencoder with reconstruction loss fn(x,y)f_n(x,y)4, and tags are defined by quantiles of fn(x,y)f_n(x,y)5.

  • Phase 2: Strong Classifier Training. A classifier fn(x,y)f_n(x,y)6 is trained to distinguish fn(x,y)f_n(x,y)7 (pseudo-signal, fn(x,y)f_n(x,y)8) from fn(x,y)f_n(x,y)9 (pseudo-background, Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)0) using a weighted cross-entropy loss:

Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)1

Sample weights Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)2 and Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)3 normalize for class imbalance.

Iterative refinement optionally alternates roles, using Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)4 to retag object Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)5 and retrain Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)6, with multiple cycles (Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)7 iterations). This bootstraps performance as the mixture in Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)8, Xn(u,v)=∑x=07∑y=07fn(x,y) cos⁡ ⁣((2x+1)uπ16)cos⁡ ⁣((2y+1)vπ16)X_n(u,v) = \sum_{x=0}^7 \sum_{y=0}^7 f_n(x,y)\,\cos\!\left(\frac{(2x+1)u\pi}{16}\right) \cos\!\left(\frac{(2y+1)v\pi}{16}\right)9 becomes increasingly pure (Amram et al., 2020).

4. Theoretical and Algorithmic Foundations

In the TNT method, the mixture model analysis ensures that, provided the weak tagger satisfies wiw_i0 and vice versa, the distribution wiw_i1 is dominated by signal in wiw_i2. Thus, wiw_i3 asymptotically approaches the likelihood ratio optimal for distinguishing signal from background:

wiw_i4

In the watermarking context, double embedding leverages the orthogonality of DCT basis vectors and the stability of SVD singular values. Each embedding operation is algebraically orthogonal but not non-interfering, so the second embedding can induce perturbation to the first. This is managed by explicit storage or regeneration of original coefficients and careful setting of wiw_i5.

5. Practical Implementation and Experimental Results

Experimental setups in both domains demonstrate the utility of double-tag schemes.

  • Watermarking (DCT+SVD): For an embedding strength wiw_i6, watermarked images maintain PSNR ≈ 52.49 dB. After various noise attacks, PSNR degrades to 35.88–49.30 dB, yet both DCT and SVD watermarks remain detectable. The scheme resists attempts to remove a watermark by targeting a single domain, as redundancy across orthogonal representations ensures residual retrievability (Ji et al., 2015).
  • TNT Classifier Training: A worked example for LHC dijet resonance searches uses a convolutional autoencoder as wiw_i7 and a CNN as wiw_i8, trained on 200k unlabeled events/iteration. In the LHC-Olympics dijet benchmark (1% signal), AUC of wiw_i9 is elevated from 0.65 (autoencoder) to 0.82, and statistical significance for discovery is raised from ≈3σ to ≫5σ. Performance can approach that of fully supervised training if the sub-object independence assumption is satisfied (Amram et al., 2020).
Domain Implementation Steps Typical Outcomes
DCT+SVD Watermarking Block DCT → diag tag → block SVD PSNR>50 dB, robust under noise
Tag N’ Train (TNT) Weak tag → strong classifier training AUC ∼0.8+, σ_discovery≫5σ

6. Advantages, Limitations, and Future Directions

Advantages

  • In watermarking, double-tag embedding in both DCT and SVD domains yields low visual distortion pre-attack, and high resilience against additive/impulse noise. This redundancy impedes successful attacks targeting only a single domain.
  • In data classification, TNT allows model-agnostic, simulation-independent classifier training directly on unlabeled data, well-suited for anomaly detection in two-object systems.

Limitations

  • In watermarking, the dual embedding increases computational overhead and can induce minor cumulative degradation of the first tag. Storage of either original DCT coefficients or singular values is necessary.
  • In TNT, performance depends critically on the weak tagger’s discriminative ability and the statistical independence of sub-object features on background-only events. The method assumes two or more sub-objects per event and lacks single-object generality.

Extensions

  • TNT may incorporate soft (score-based) labeling, alternative unsupervised taggers (e.g., normalizing flows), and can generalize to multi-tag settings with more than two sub-objects.
  • Adversarial decorrelation can enforce independence from kinematic variables, such as jet Xn′(ui,ui)=Xn(ui,ui)+αwi,α=0.05X_n'(u_i,u_i) = X_n(u_i,u_i) + \alpha w_i,\qquad \alpha=0.050 in particle physics applications.

7. Comparative Summary

Both analyzed double-tag approaches establish that embedding, tagging, or training in two orthogonal domains or subspaces significantly enhances system robustness. In image watermarking, redundancy across frequency and singular-value subspaces fortifies watermark integrity. In unsupervised learning, bootstrapping from weak to strong taggers transforms ambiguous labels into increasingly pure classification signals. The trade-off universally observed is between increased algorithmic complexity and the gain in reliability and interpretability.

Key results and methodologies are detailed in "A DCT And SVD based Watermarking Technique To Identify Tag" (Ji et al., 2015) and "Tag N' Train: A Technique to Train Improved Classifiers on Unlabeled Data" (Amram et al., 2020).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (2)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Double-Tag Technique.