VoiceMark: Zero-Shot Voice Cloning-Resistant Watermarking Approach Leveraging Speaker-Specific Latents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Haiyun, Wu, Zhiyong, Xie, Xiaofeng, Xie, Jingran, Xu, Yaoxun, Peng, Hanyang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918039830659072
author Li, Haiyun
Wu, Zhiyong
Xie, Xiaofeng
Xie, Jingran
Xu, Yaoxun
Peng, Hanyang
author_facet Li, Haiyun
Wu, Zhiyong
Xie, Xiaofeng
Xie, Jingran
Xu, Yaoxun
Peng, Hanyang
contents Voice cloning (VC)-resistant watermarking is an emerging technique for tracing and preventing unauthorized cloning. Existing methods effectively trace traditional VC models by training them on watermarked audio but fail in zero-shot VC scenarios, where models synthesize audio from an audio prompt without training. To address this, we propose VoiceMark, the first zero-shot VC-resistant watermarking method that leverages speaker-specific latents as the watermark carrier, allowing the watermark to transfer through the zero-shot VC process into the synthesized audio. Additionally, we introduce VC-simulated augmentations and VAD-based loss to enhance robustness against distortions. Experiments on multiple zero-shot VC models demonstrate that VoiceMark achieves over 95% accuracy in watermark detection after zero-shot VC synthesis, significantly outperforming existing methods, which only reach around 50%. See our code and demos at: https://huggingface.co/spaces/haiyunli/VoiceMark
format Preprint
id arxiv_https___arxiv_org_abs_2505_21568
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VoiceMark: Zero-Shot Voice Cloning-Resistant Watermarking Approach Leveraging Speaker-Specific Latents
Li, Haiyun
Wu, Zhiyong
Xie, Xiaofeng
Xie, Jingran
Xu, Yaoxun
Peng, Hanyang
Sound
Artificial Intelligence
Cryptography and Security
Audio and Speech Processing
Voice cloning (VC)-resistant watermarking is an emerging technique for tracing and preventing unauthorized cloning. Existing methods effectively trace traditional VC models by training them on watermarked audio but fail in zero-shot VC scenarios, where models synthesize audio from an audio prompt without training. To address this, we propose VoiceMark, the first zero-shot VC-resistant watermarking method that leverages speaker-specific latents as the watermark carrier, allowing the watermark to transfer through the zero-shot VC process into the synthesized audio. Additionally, we introduce VC-simulated augmentations and VAD-based loss to enhance robustness against distortions. Experiments on multiple zero-shot VC models demonstrate that VoiceMark achieves over 95% accuracy in watermark detection after zero-shot VC synthesis, significantly outperforming existing methods, which only reach around 50%. See our code and demos at: https://huggingface.co/spaces/haiyunli/VoiceMark
title VoiceMark: Zero-Shot Voice Cloning-Resistant Watermarking Approach Leveraging Speaker-Specific Latents
topic Sound
Artificial Intelligence
Cryptography and Security
Audio and Speech Processing
url https://arxiv.org/abs/2505.21568