提出首个能抗神经编解码压缩的音频水印方法
Latent-Mark: An Audio Watermark Robust to Neural Codec Compression
- 在编解码器不变的潜在空间嵌入水印,避免被压缩丢弃
- 跨编解码器优化使水印在未见编码器上仍有效
- 无需额外比特即可抵抗神经压缩与传统信号处理攻击
现有音频水印技术虽能抵御传统数字信号处理攻击,但对神经音频编解码器压缩仍脆弱。这是因为现代神经编解码器会过滤掉水印依赖的不可感知波形变化。为此,我们提出首个零比特音频水印框架 Latent-Mark,其核心思想是将水印嵌入编解码器不变的潜在空间。通过优化音频波形,使其在编码后产生可检测的方向性潜变量偏移,同时约束扰动沿自然音频流形以保证不可感知性。为防止过度适配单一编解码器的量化规则,我们引入跨编解码器优化(Cross-Codec Optimization),在多个代理编解码器上联合优化波形,以捕捉共享的潜在不变性。大量实验表明,该方法在未见神经编解码器上具备优异的零样本迁移能力,同时保持对传统DSP攻击的竞争力和感知不可感知性。我们希望本工作能推动通用水印框架的研究,以应对日益复杂多样的生成性失真。
原文摘要 · Abstract (English)
While existing audio watermarking techniques have achieved strong robustness against traditional digital signal processing (DSP) attacks, they remain vulnerable to neural compression. This occurs because modern neural audio codecs act as noise filters and discard the imperceptible waveform variations used in prior watermarking methods. To address this limitation, we propose Latent-Mark, the first zero-bit audio watermarking framework designed to survive neural codec compression. Our key insight is that robustness to the encode-decode process requires embedding the watermark within the codec's invariant latent space. We achieve this by optimizing the audio waveform to induce a detectable directional shift in its encoded latent representation, while constraining perturbations to align with the natural audio manifold to ensure imperceptibility. To prevent overfitting to a single codec's quantization rules, we introduce Cross-Codec Optimization, jointly optimizing the waveform across multiple surrogate codecs to target shared latent invariants. Extensive evaluations demonstrate robust zero-shot transferability to unseen neural codecs, achieving competitive resilience against traditional DSP attacks while preserving perceptual imperceptibility. We hope our work will inspire future research into universal watermarking frameworks capable of maintaining integrity across increasingly complex and diverse generative distortions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。