用扩散模型黑盒移除音频水印,不损音质且无需了解水印机制。
Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors

- 通过扩散噪声中间态与预训练去噪模型重构音频,隐去水印信号。
- 在多类音频上均实现水印完全移除,且听感质量无明显下降。
- 揭示现有水印方案对扩散攻击的脆弱性,适合安全与版权研究者参考。
随着AI生成音频兴起,水印技术被广泛用于检测滥用和保护知识产权。然而,攻击者可能试图移除水印,因此评估水印方案的抗移除能力至关重要。现有攻击要么显著降低听觉质量,要么需掌握水印机制。本文提出DiffErase,一种无需了解目标水印机制的黑盒移除攻击,仅通过将含水印音频扰动至中间扩散噪声水平,并利用预训练去噪模型重建,有效抑制水印信号。理论分析与大量实验表明,不可察觉的音频水印高度易受攻击:在多个音频领域中,DiffErase持续实现水印移除且保持听觉质量。这些发现强调未来音频水印设计必须考虑基于扩散模型的威胁。代码与演示见https://differase.github.io/DiffErase/。
原文摘要 · Abstract (English)
With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual quality or require access to the watermarking scheme. We propose DiffErase, a black-box watermark removal attack that assumes no knowledge of the target watermarking scheme while maintaining perceptual quality. DiffErase perturbs watermarked audio to an intermediate diffusion noise level and regenerates it using a pretrained denoising model, effectively suppressing watermark signals. Theoretical analysis and extensive experiments demonstrate that inaudible audio watermarks are highly vulnerable: across multiple audio domains, DiffErase consistently removes watermarks while preserving perceptual quality. These findings highlight the need for future audio watermarking designs to consider diffusion-based threats. Code and demos are available at https://differase.github.io/DiffErase/.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。