发表机构
Institute of Neuroinformatics, University of Zurich and ETH Zurich; NAVER Cloud(苏黎世大学与苏黎世联邦理工学院神经信息学研究所; NAVER云)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对生成语音令牌级水印在重新令牌化下易失效的问题,提出Redwing方法,利用令牌替换图结构联合优化嵌入与检测,在Moshi系统上显著提升鲁棒性,八次重合成后真阳性率达80.7%。
AI 中文摘要
水印是建立AI生成语音来源的一种有前景的工具。虽然许多神经音频水印方法依赖于单独训练的水印生成器,但令牌级水印是一种无需训练的替代方案,直接在生成过程中操作。其主要弱点是重新令牌化:将生成的语音解码为波形并再次编码可能会改变令牌身份并侵蚀水印。为了使水印对这些变化具有鲁棒性,我们提出了Redwing,即生成中的重新令牌化持久水印。它根据重新令牌化下观察到的令牌替换构建一个图,其拉普拉斯算子产生一个基,该基为可能相互替换的令牌分配相似的值。在这个基上,嵌入和检测函数被联合优化,以在重新令牌化过程中保留水印信号,同时限制未加水印语音上的嵌入失真和检测器变异性。在Moshi全双工系统上,经过八次连续的Mimi重合成后,Redwing在标定的1%假阳性率下实现了80.7%的真阳性率,而KGW为8.3%,WMAR最多为7.3%。它还在通过其他三种神经编解码器八次传递后具有最高的真阳性率(77.5%-93.0%),并且这些收益在语音质量成本接近KGW的情况下泛化到TTS模型。这些结果表明,重新令牌化不仅仅是一个噪声来源:其转换结构可以被利用作为鲁棒令牌级水印的设计原则。
英文摘要
Watermarking is a promising tool for establishing the provenance of AI-generated speech. While many neural audio watermarking methods rely on a separately trained watermark generator, token-level watermarking is a training-free alternative that operates directly during generation. Its main weakness is retokenization: decoding generated speech to a waveform and encoding it again can change token identities and erode the watermark. To make the watermark robust to these changes, we propose Redwing, REtokenization-Durable Watermarking IN Generation. It builds a graph from the token substitutions observed under retokenization, whose Laplacian yields a basis that assigns similar values to tokens likely to substitute for one another. Over this basis, embedding and detection functions are jointly optimized to preserve watermark signal through retokenization while limiting embedding distortion and detector variability on unwatermarked speech. On the Moshi full-duplex system, after eight consecutive passes of Mimi resynthesis, Redwing achieves 80.7% TPR at a calibrated 1% FPR, compared with 8.3% for KGW and at most 7.3% for WMAR. It also has the highest TPR after eight passes through three other neural codecs (77.5-93.0%), and the gains generalize to TTS models at a speech-quality cost close to that of KGW. These results show that retokenization is not merely a source of noise: its transition structure can be exploited as a design principle for robust token-level watermarking.