发表机构
Indian Institute of Technology Madras(马德拉斯印度理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出无需训练的结构化探针方法,可区分神经音频水印的脆弱性,匹配域攻击能去除部分水印,且探针可识别水印方案,准确率达84%。
AI 中文摘要
神经音频水印越来越多地用于归属和检测AI生成语音,因此其实际价值取决于攻击者能以多低成本将其去除。鲁棒性通常通过对每个方案盲目运行一组固定的失真来衡量。相反,我们将去除操作转化为诊断过程:从少量干净/水印音频对中,我们计算低成本的结构化探针,以揭示水印在信号中的位置(即其嵌入域),然后应用与该域匹配的单一攻击,而非盲目扫描。我们还为每个方案总结出一个无阈值的脆弱性分数,即其准确率与质量权衡曲线下的面积,这是仅基于准确率的基准无法提供的。在十种水印方案中,这些探针可区分脆弱水印和鲁棒水印:对于幅度域和载波域水印,单一匹配攻击可在高客观质量(PESQ≥3.6)下清除有效载荷(WavMark、SilentCipher、audiowmark)或去除检测标志(AudioSeal);而潜在域水印(VoiceMark、WMCodec、AlignMark、AWARE)可抵御我们应用的所有无需训练的攻击。同样基于仅一对音频的探针特征还能识别存在的水印方案,十种方案的识别准确率达84%。
英文摘要
Neural audio watermarks are increasingly used to attribute and detect AI-generated speech, so their practical value rests on how cheaply an adversary can remove them. Robustness is usually measured by running a fixed battery of distortions blindly against every scheme. We instead make removal diagnostic: from a few clean/watermarked pairs we compute cheap structural probes that reveal where a watermark sits in the signal (its embedding domain), then apply a single domain-matched attack rather than a blind sweep. We further summarize each scheme with one threshold-free fragility score, the area under its accuracy-versus-quality trade-off, which an accuracy-only benchmark cannot provide. Across ten watermarking schemes the probes separate fragile from robust marks: for magnitude and carrier-domain watermarks a single matched attack erases the payload (WavMark, SilentCipher, audiowmark) or removes the detection flag (AudioSeal) at high objective quality (PESQ >= 3.6), whereas latent-domain marks (VoiceMark, WMCodec, AlignMark, AWARE) resist every training-free attack we apply. The same pair-only probe signatures also identify which watermarking scheme is present (84% over ten schemes).
CommentsAccepted at APSIPA ASC 2026