arXiv:2503.19176cs.CRcs.AI2025-03被引 22

测试22种音频水印在109种攻击下的鲁棒性,发现无一能完全抵抗。

SoK: How Robust is Audio Watermarking in Generative AI models?

  • 构建涵盖22类攻击的评估框架,覆盖信号、物理和AI干扰
  • 实测9个开源方案,发现8种新有效攻击,均导致水印失效
  • 适用于内容安全、版权保护等场景的研究者与开发者

音频水印被广泛用于验证生成内容的来源,支持检测AI语音、保护音乐知识产权及防范语音克隆。为确保有效性,水印需抵御去除攻击(通过信号扭曲逃避检测)。尽管许多方案声称具备鲁棒性,但其评估通常孤立且仅针对有限攻击。本文系统评估近期宣称鲁棒的水印方案在多样化去除攻击下的表现。首先提出涵盖22种音频水印方案的分类体系;其次总结其技术原理与潜在漏洞;随后开展大规模实证研究,构建包含22类去除攻击(共109种配置)的评估框架,涵盖信号级、物理级及AI诱导失真。我们复现了9个开源方案,发现8种新型高效攻击,并揭示11项关键发现,暴露这些方法在3个公开数据集上的根本局限。结果表明,所调查的所有方案均无法抵御所有测试失真。该评估为当前水印技术在真实威胁下的表现提供了全面视角。演示与代码已公开于https://sokaudiowm.github.io/。

原文摘要 · Abstract (English)

Audio watermarking is increasingly used to verify the provenance of AI-generated content, enabling applications such as detecting AI-generated speech, protecting music IP, and defending against voice cloning. To be effective, audio watermarks must resist removal attacks that distort signals to evade detection. While many schemes claim robustness, these claims are typically tested in isolation and against a limited set of attacks. A systematic evaluation against diverse removal attacks is lacking, hindering practical deployment. In this paper, we investigate whether recent watermarking schemes that claim robustness can withstand a broad range of removal attacks. First, we introduce a taxonomy covering 22 audio watermarking schemes. Next, we summarize their underlying technologies and potential vulnerabilities. We then present a large-scale empirical study to assess their robustness. To support this, we build an evaluation framework encompassing 22 types of removal attacks (109 configurations) including signal-level, physical-level, and AI-induced distortions. We reproduce 9 watermarking schemes using open-source code, identify 8 new highly effective attacks, and highlight 11 key findings that expose the fundamental limitations of these methods across 3 public datasets. Our results reveal that none of the surveyed schemes can withstand all tested distortions. This evaluation offers a comprehensive view of how current watermarking methods perform under real-world threats. Our demo and code are available at https://sokaudiowm.github.io/.

音频水印生成模型鲁棒性评估内容溯源

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。