arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

音频水印下音频深度伪造检测的鲁棒性研究

On the Robustness of Audio Deepfake Detection under Audio Watermarking

Zi Qian Yong, Ajinkya Kulkarni, Julia Lau, Hwa Hui Tew, Shu Min Leong, Raphael Phan, Sébastien Marcel

arXiv 2608.24159首次发表:更新:

发表机构

School of Information Technology, Monash University, Malaysia campus; Idiap Research Institute, Switzerland(莫纳什大学马来西亚校区信息技术学院; 瑞士 Idiap 研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究探究音频水印对ADD系统的影响,采用WavMark评估框架,发现水印会在部分数据集上大幅降低ADD性能,揭示了ADD系统的鲁棒性漏洞。

AI 中文摘要

生成式音频模型的最新进展已能生成高度逼真的合成语音,这使得可靠的音频深度伪造检测(ADD)系统的重要性日益提升。尽管此前的研究主要聚焦于对抗优化的扰动,但ADD系统在现实信号变换下的鲁棒性仍未得到充分理解。本研究将音频水印视为一种结构化的非对抗性扰动,而非传统攻击机制,以此探究其对ADD系统的影响。我们使用基于WavMark构建的基于水印的评估框架,在多个基准数据集上评估多个基于自监督学习(SSL)、卷积神经网络(CNN)和图神经网络(GNN)的ADD模型。除传统检测指标外,我们还在嵌入空间中使用弗雷歇距离、余弦相似度和L2距离分析水印诱导的表征偏移。实验结果显示出强烈的数据集依赖行为:水印会导致ASVspoof 2021 LA和DF数据集上的ADD性能大幅下降,而对ASVspoof 2024、FoR和ITW数据集的影响有限。此外,嵌入空间的大幅偏移与严重的检测性能下降密切相关,这表明水印诱导的扰动可显著改变当前ADD系统所依赖的特征表征。这些发现表明,为内容保护设计的良性信号变换会暴露出音频深度伪造检测系统此前被忽视的鲁棒性漏洞。我们的代码可在该https URL获取。

英文摘要

Recent advances in generative audio models have enabled highly realistic synthetic speech, increasing the importance of reliable audio deepfake detection (ADD) systems. While prior studies have primarily focused on adversarially optimized perturbations, the robustness of ADD systems under realistic signal transformations remains insufficiently understood. In this work, we investigate the impact of audio watermarking on ADD systems by treating watermarking as a structured, non-adversarial perturbation rather than a conventional attack mechanism. Using a watermark-based evaluation framework built upon WavMark, we evaluate multiple self-supervised learning (SSL), Convolutional Neural Network (CNN) and Graph Neural Netrowk (GNN)-based ADD models across several benchmark datasets. Beyond conventional detection metrics, we further analyze watermark-induced representation shifts using Fréchet Distance, cosine similarity, and L2 distance in the embedding space. Experimental results reveal a strong dataset-dependent behavior: watermarking causes substantial performance degradation on ASVspoof 2021 LA and DF, while exhibiting limited impact on ASVspoof 2024, FoR, and ITW. Moreover, large embedding-space shifts are strongly associated with severe detection degradation, suggesting that watermark-induced perturbations can substantially alter the feature representations relied upon by current ADD systems. These findings demonstrate that benign signal transformations designed for content protection can expose previously overlooked robustness vulnerabilities in audio deepfake detection systems. Our code is available at https://github.com/ziqian0925/wm-ADD-robustness.git

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑