Yours or Mine? Overwriting Attacks Against Neural Audio Watermarking
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866917126753746944 |
|---|---|
| author | Yao, Lingfeng Huang, Chenpei Wang, Shengyao Xue, Junpei Guo, Hanqing Liu, Jiang Lin, Phone Ohtsuki, Tomoaki Pan, Miao |
| author_facet | Yao, Lingfeng Huang, Chenpei Wang, Shengyao Xue, Junpei Guo, Hanqing Liu, Jiang Lin, Phone Ohtsuki, Tomoaki Pan, Miao |
| contents | As generative audio models are rapidly evolving, AI-generated audios increasingly raise concerns about copyright infringement and misinformation spread. Audio watermarking, as a proactive defense, can embed secret messages into audio for copyright protection and source verification. However, current neural audio watermarking methods focus primarily on the imperceptibility and robustness of watermarking, while ignoring its vulnerability to security attacks. In this paper, we develop a simple yet powerful attack: the overwriting attack that overwrites the legitimate audio watermark with a forged one and makes the original legitimate watermark undetectable. Based on the audio watermarking information that the adversary has, we propose three categories of overwriting attacks, i.e., white-box, gray-box, and black-box attacks. We also thoroughly evaluate the proposed attacks on state-of-the-art neural audio watermarking methods. Experimental results demonstrate that the proposed overwriting attacks can effectively compromise existing watermarking schemes across various settings and achieve a nearly 100% attack success rate. The practicality and effectiveness of the proposed overwriting attacks expose security flaws in existing neural audio watermarking systems, underscoring the need to enhance security in future audio watermarking designs. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2509_05835 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Yours or Mine? Overwriting Attacks Against Neural Audio Watermarking Yao, Lingfeng Huang, Chenpei Wang, Shengyao Xue, Junpei Guo, Hanqing Liu, Jiang Lin, Phone Ohtsuki, Tomoaki Pan, Miao Cryptography and Security Sound Audio and Speech Processing As generative audio models are rapidly evolving, AI-generated audios increasingly raise concerns about copyright infringement and misinformation spread. Audio watermarking, as a proactive defense, can embed secret messages into audio for copyright protection and source verification. However, current neural audio watermarking methods focus primarily on the imperceptibility and robustness of watermarking, while ignoring its vulnerability to security attacks. In this paper, we develop a simple yet powerful attack: the overwriting attack that overwrites the legitimate audio watermark with a forged one and makes the original legitimate watermark undetectable. Based on the audio watermarking information that the adversary has, we propose three categories of overwriting attacks, i.e., white-box, gray-box, and black-box attacks. We also thoroughly evaluate the proposed attacks on state-of-the-art neural audio watermarking methods. Experimental results demonstrate that the proposed overwriting attacks can effectively compromise existing watermarking schemes across various settings and achieve a nearly 100% attack success rate. The practicality and effectiveness of the proposed overwriting attacks expose security flaws in existing neural audio watermarking systems, underscoring the need to enhance security in future audio watermarking designs. |
| title | Yours or Mine? Overwriting Attacks Against Neural Audio Watermarking |
| topic | Cryptography and Security Sound Audio and Speech Processing |
| url | https://arxiv.org/abs/2509.05835 |