arXiv:2606.22310cs.SDcs.CR2026-06中稿 · Interspeech 2026 L…

提出自适应攻击方法,可绕过主流音频水印防御机制。

Learning to Evade: Adaptive Attacks on Audio Watermarking

论文配图:Learning to Evade: Adaptive Attacks on Audio Watermarking
图 1 · 摘自论文原文
  • 分两阶段优化:先确保攻击成功,再提升音频质量
  • 在三个人声数据集上实现低于10%的检测率,移除攻击检测率为0%
  • 通过估计分布参数自适应规避检测,适合研究水印安全的学者

生成式音频的发展加剧了版权问题,音频水印在确权方面愈发重要。然而,现有水印方法易受对抗攻击。我们发现水印解码消息概率服从正态分布,这一特性被防御机制用于检测篡改。本文提出一种自适应音频水印攻击方法(AWM),旨在绕过现有防御策略。AWM采用两阶段优化:第一阶段保证攻击成功,第二阶段提升音频质量。为规避检测,它从目标音频的有限样本中估计正态分布参数,并自适应地将解码概率调整回估计范围。在两种水印方法和三个语音数据集上的评估表明,该方法成功率高,且能有效逃避先进检测器:替换与创建攻击的检测率低于10%,移除攻击检测率为0%。

原文摘要 · Abstract (English)

Advances in generative audio have intensified copyright concerns, making audio watermarking increasingly important for asserting ownership. However, existing audio watermarking methods are vulnerable to adversarial attacks. We find that watermark decoder message probabilities follow normal distributions, a property exploited by defenses to detect manipulations. This paper introduces an adaptive audio watermark attack method (AWM) designed to bypass existing defense strategies. AWM uses a two-stage optimization: the first stage ensures attack success, while the second improves audio quality. To evade detection, it estimates normal distribution parameters from limited samples of the target audio, and then adaptively steers decoded probabilities back into the estimated range. Evaluated on two watermarking methods across three voice datasets, AWM achieves high success while bypassing state-of-the-art detectors: detection rates are below 10% for replacement and creation, and 0% for removal.

音频水印对抗攻击安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。