DeMark:一种用于保持音质的免查询黑盒音频水印移除攻击
DeMark: A Query-Free Black-Box Attack for Quality-Preserving Audio Watermark Removal
浏览论文内容
中文总结 AI 辅助
DeMark提出一种免查询黑盒攻击,通过两阶段伪影抑制在保持音质的同时移除音频水印,在多个数据集和方法上实现高攻击成功率并揭示系统漏洞。
中文摘要 AI 辅助
音频水印通过嵌入不可感知的信号来保护数字语音,用于所有权验证和滥用追踪。然而,在现实对抗性移除场景下,基于学习的水印安全性尚未得到充分理解,攻击者无法访问或查询水印编码器、解码器或检测器。现有攻击要么依赖模型反馈,要么需要干净-带水印配对,要么使用生成模型重建波形,往往导致高查询成本、泛化能力有限或感知质量下降。本文提出DeMark,一种免查询的黑盒攻击,用于保持音质的音频水印移除。我们的关键洞察是,水印嵌入虽然在感知上隐藏,但会在时频域引入与自然语音不完全对齐的微妙非语音伪影。DeMark通过两个阶段移除水印:多样伪影学习,提取互补的非平稳和平稳伪影模式;自适应伪影缩放,在保持音质约束下自适应地组合并放大这些伪影。在两个语音数据集和四种最先进的水印方法上,DeMark实现了0.92和0.96的平均攻击成功率,同时始终比现有自适应攻击保持更高的感知质量。这些结果揭示了当前音频水印系统的实际漏洞,并呼吁设计更鲁棒的水印以抵御免查询对抗性移除。
英文摘要
Audio watermarking protects digital speech by embedding imperceptible signals for ownership verification and misuse tracing. However, the security of learning-based watermarking remains insufficiently understood under realistic adversarial removal, where attackers cannot access or query the watermark encoder, decoder, or detector. Existing attacks either rely on model feedback, require clean-watermarked pairs, or reconstruct the waveform with generative models, often leading to high query costs, limited generalization, or degraded perceptual quality. In this paper, we propose DeMark, a query-free black-box attack for quality-preserving audio watermark removal. Our key insight is that watermark embedding, while perceptually hidden, can introduce subtle non-speech artifacts in the time-frequency domain that are not fully aligned with natural speech. DeMark removes watermarks by suppressing these artifacts through two stages: Diverse Artifact Learning, which extracts complementary non-stationary and stationary artifact patterns, and Adaptive Artifact Scaling, which adaptively combines and amplifies them under quality-preserving constraints. Across two speech datasets and four state-of-the-art watermarking methods, DeMark achieves average attack success rates of 0.92 and 0.96 while consistently preserving higher perceptual quality than existing adaptive attacks. These results reveal a practical vulnerability of current audio watermarking systems and call for more robust watermark designs against query-free adversarial removal.
发表机构
- University of Missouri-Kansas City(密苏里大学堪萨斯城分校)
- Indiana University Bloomington(印第安纳大学布鲁明顿分校)
机构由 AI 辅助整理,请以论文原文为准。