Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yao, Lingfeng, Zhong, Xincong, Huang, Chenpei, Zhao, Xuandong, Guo, Hanqing, Li, Aohan, Liu, Jiang, Ohtsuki, Tomoaki, Pan, Miao
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910271450120192
author Yao, Lingfeng
Zhong, Xincong
Huang, Chenpei
Zhao, Xuandong
Guo, Hanqing
Li, Aohan
Liu, Jiang
Ohtsuki, Tomoaki
Pan, Miao
author_facet Yao, Lingfeng
Zhong, Xincong
Huang, Chenpei
Zhao, Xuandong
Guo, Hanqing
Li, Aohan
Liu, Jiang
Ohtsuki, Tomoaki
Pan, Miao
contents With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual quality or require access to the watermarking scheme. We propose DiffErase, a black-box watermark removal attack that assumes no knowledge of the target watermarking scheme while maintaining perceptual quality. DiffErase perturbs watermarked audio to an intermediate diffusion noise level and regenerates it using a pretrained denoising model, effectively suppressing watermark signals. Theoretical analysis and extensive experiments demonstrate that inaudible audio watermarks are highly vulnerable: across multiple audio domains, DiffErase consistently removes watermarks while preserving perceptual quality. These findings highlight the need for future audio watermarking designs to consider diffusion-based threats. Code and demos are available at https://differase.github.io/DiffErase/.
format Preprint
id arxiv_https___arxiv_org_abs_2605_30614
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors
Yao, Lingfeng
Zhong, Xincong
Huang, Chenpei
Zhao, Xuandong
Guo, Hanqing
Li, Aohan
Liu, Jiang
Ohtsuki, Tomoaki
Pan, Miao
Cryptography and Security
Sound
With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual quality or require access to the watermarking scheme. We propose DiffErase, a black-box watermark removal attack that assumes no knowledge of the target watermarking scheme while maintaining perceptual quality. DiffErase perturbs watermarked audio to an intermediate diffusion noise level and regenerates it using a pretrained denoising model, effectively suppressing watermark signals. Theoretical analysis and extensive experiments demonstrate that inaudible audio watermarks are highly vulnerable: across multiple audio domains, DiffErase consistently removes watermarks while preserving perceptual quality. These findings highlight the need for future audio watermarking designs to consider diffusion-based threats. Code and demos are available at https://differase.github.io/DiffErase/.
title Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors
topic Cryptography and Security
Sound
url https://arxiv.org/abs/2605.30614