用非对称相位编码实现无需训练的音频防伪签名,抗多种攻击且可盲提取。
Asymmetric Phase Coding Audio Watermarking

- 结合数字签名与纠错码,通过相位块选择和对数幅值差量化嵌入水印。
- 在8种攻击下验证率97.5%~98.3%,延迟仅数十毫秒,性能稳定。
- 适用于音频溯源,适合需可信验证的语音系统或合规场景。
深度伪造音频威胁语音认证系统;被动检测器易受生成模型演变及真实信道失真的影响。本文提出非对称相位编码(APC),一种无需训练的音频加密签名层,作为紧凑、可审计的来源证明原语,可独立使用或与学习型水印叠加。APC融合Ed25519数字签名(EdDSA, FIPS 186-5;64字节签名)、里德-所罗门纠错码、伪随机STFT相位块选择,以及相邻频带对对数幅值差的冗余量化索引调制(QIM)编码,实现紧凑、不可抵赖、盲提取的水印。我们在1000个LibriSpeech test-clean片段(每段10秒,44.1 kHz)上评估了8种攻击配置——身份保持、10%首尾裁剪、20%首尾裁剪、8 kHz低通滤波、16 kHz往返重采样、FLAC重新编码、MP3 128 kbps、OGG-Vorbis 128 kbps——在平均PESQ=3.02条件下,所有情况验证率均达97.5%至98.3%,CPU延迟为数十毫秒。我们明确对比了APC与近期神经基基线(AudioSeal、WavMark、SilentCipher),详述威胁模型(伪造抵抗与擦除),描述数据集,定义全部指标,量化自适应白盒擦除攻击,并发布代码、密钥与元数据以保证可复现性。
原文摘要 · Abstract (English)
The proliferation of deepfake audio challenges voice-based authentication systems; passive forensic detectors are sensitive to evolving generative models and to real-world channel distortions. We propose Asymmetric Phase Coding (APC), a training-free cryptographic signing layer for audio, designed as a compact and auditable provenance primitive that can stand alone or be stacked with learned watermarks. APC combines Ed25519 digital signatures (EdDSA, FIPS 186-5; 64-byte signatures) with Reed-Solomon error correction, pseudo-random STFT phase-bin selection, and a redundant quantization-index-modulation (QIM) code on log-magnitude differences of adjacent bin pairs, yielding a compact, non-repudiable, blind-extractable watermark. We evaluate APC on 1,000 LibriSpeech test-clean clips (10 s each, 44.1 kHz) under eight attack configurations -- identity, 10% end-cropping, 20% end-cropping, 8 kHz low-pass, 16 kHz round-trip resampling, FLAC re-encoding, MP3 at 128 kbps, and OGG-Vorbis at 128 kbps -- and achieve cryptographic verification rates between 97.5% and 98.3% on every condition at mean PESQ=3.02 and tens-of-milliseconds CPU latency. We explicitly compare APC against recent neural baselines (AudioSeal, WavMark, SilentCipher), detail the threat model (forgery resistance vs. erasure), characterize the dataset, define all metrics, quantify an adaptive white-box erasure attack, and release code, keys, and metadata for reproducibility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。