arXiv:2509.05835cs.CRcs.SD2025-09AAAI被引 10

提出可覆盖原有水印的攻击方法,暴露音频水印系统安全漏洞。

Yours or Mine? Overwriting Attacks Against Neural Audio Watermarking

  • 针对水印系统设计三类攻击:白盒、灰盒、黑盒,利用对手掌握信息程度
  • 在主流水印方案上测试,攻击成功率接近100%,有效破坏原水印检测
  • 揭示现有水印机制安全缺陷,提醒未来设计需加强防御能力

随着生成式音频模型快速发展,AI生成音频引发版权侵权与虚假信息传播担忧。音频水印作为主动防御手段,可通过嵌入密钥信息实现版权保护与来源验证。然而,当前神经音频水印方法主要关注隐蔽性与鲁棒性,忽视其安全漏洞。本文提出一种简单但强大的攻击——覆写攻击,可将合法水印替换为伪造水印,使原始水印无法被检测。基于攻击者掌握的水印信息,提出白盒、灰盒、黑盒三类攻击。在先进神经音频水印方法上全面评估,实验表明该攻击在多种设置下均能有效破坏现有方案,攻击成功率接近100%。该攻击的实用性与有效性暴露了现有音频水印系统的安全缺陷,凸显未来设计中提升安全性的紧迫性。

原文摘要 · Abstract (English)

As generative audio models are rapidly evolving, AI-generated audios increasingly raise concerns about copyright infringement and misinformation spread. Audio watermarking, as a proactive defense, can embed secret messages into audio for copyright protection and source verification. However, current neural audio watermarking methods focus primarily on the imperceptibility and robustness of watermarking, while ignoring its vulnerability to security attacks. In this paper, we develop a simple yet powerful attack: the overwriting attack that overwrites the legitimate audio watermark with a forged one and makes the original legitimate watermark undetectable. Based on the audio watermarking information that the adversary has, we propose three categories of overwriting attacks, i.e., white-box, gray-box, and black-box attacks. We also thoroughly evaluate the proposed attacks on state-of-the-art neural audio watermarking methods. Experimental results demonstrate that the proposed overwriting attacks can effectively compromise existing watermarking schemes across various settings and achieve a nearly 100% attack success rate. The practicality and effectiveness of the proposed overwriting attacks expose security flaws in existing neural audio watermarking systems, underscoring the need to enhance security in future audio watermarking designs.

音频水印安全攻击生成模型版权保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。