通过关联伪造语音特征的水印,实现更鲁棒的深度伪造语音溯源。
FakeMark: Deepfake Speech Attribution With Watermarked Artifacts
- 水印与伪造系统特征绑定,不依赖预设比特串。
- 跨数据集测试中准确率显著优于传统分类方法。
- 在压缩和恶意移除下仍保持高识别率,适合实际应用。
深度伪造语音溯源仍面临挑战:基于分类器的方法泛化能力差,基于水印的方法易受编解码压缩或恶意移除攻击影响。为此,我们提出 FakeMark,一种新型水印框架,将与伪造系统相关的特征水印注入,而非预设的比特串消息。该设计使检测器可同时利用注入水印与内在伪造特征进行溯源,即使其中一者缺失或被移除也依然有效。实验表明,FakeMark 在跨数据集样本上显著提升泛化性能,且在各类失真条件下仍保持高准确率,优于传统水印方案。
原文摘要 · Abstract (English)
Deepfake speech attribution remains challenging for existing solutions. Classifier-based solutions often fail to generalize to domain-shifted samples, and watermarking-based solutions are easily compromised by distortions like codec compression or malicious removal attacks. To address these issues, we propose FakeMark, a novel watermarking framework that injects artifact-correlated watermarks associated with deepfake systems rather than pre-assigned bitstring messages. This design allows a detector to attribute the source system by leveraging both injected watermark and intrinsic deepfake artifacts, remaining effective even if one of these cues is elusive or removed. Experimental results show that FakeMark improves generalization to cross-dataset samples where classifier-based solutions struggle and maintains high accuracy under various distortions where conventional watermarking-based solutions fail.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。