StableMark: Towards Codec-Robust Audio Watermarking via Attack Decomposition
Abstract
Audio watermarking is an emerging technology designed to embed imperceptible markers in audio signals for proactive deepfake detection and source tracing. However, these embedded markers are often susceptible to watermark removal attacks, particularly those leveraging neural codec resynthesis. While attack simulation during training has been widely adopted to enhance robustness against specific neural codec attacks, this approach often fails to generalize to unseen codecs or significantly degrades watermarked audio quality. To improve robustness against unseen neural codecs, we propose StableMark, a simulation-free audio watermarking framework. Our core idea is to first decompose nonlinear codec transformations into a set of attack-invariant functions that capture stable acoustic features preserved throughout resynthesis, and then construct the watermark detector as a set of linear combinations of these stable functions. In this paper, we start by proving that watermarking systems built upon attack-invariant functions are theoretically robust. Guided by this theory, we develop a method to derive generalizable stable functions through a combination of audio encoder pretraining and stable dimension selection. Extensive experiments across diverse neural codecs demonstrate that our framework significantly improves robustness against unseen neural codec attacks while maintaining high audio fidelity.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.