CRSDMay 28

Audio Pirates: Black-box Audio Watermark Removal via Diffusion Priors

arXiv:2605.3061471.7h-index: 13
Predicted impact top 19% in CR · last 90 daysOriginality Incremental advance
AI Analysis

This work highlights a critical vulnerability in existing audio watermarking schemes for intellectual property protection and misuse detection, impacting developers and users of AI-generated audio.

This paper introduces DiffErase, a black-box attack that removes inaudible audio watermarks by perturbing watermarked audio to an intermediate diffusion noise level and regenerating it with a pretrained denoising model. The method successfully removes watermarks across multiple audio domains while preserving perceptual quality, demonstrating the vulnerability of current watermarking schemes.

With the rise of AI-generated audio, watermarking has become widely used for detecting misuse and protecting intellectual property. However, adversaries may try to remove these watermarks, making it critical to evaluate how well watermarking schemes withstand removal attacks. Existing attacks are often impractical: they either noticeably degrade perceptual quality or require access to the watermarking scheme. We propose DiffErase, a black-box watermark removal attack that assumes no knowledge of the target watermarking scheme while maintaining perceptual quality. DiffErase perturbs watermarked audio to an intermediate diffusion noise level and regenerates it using a pretrained denoising model, effectively suppressing watermark signals. Theoretical analysis and extensive experiments demonstrate that inaudible audio watermarks are highly vulnerable: across multiple audio domains, DiffErase consistently removes watermarks while preserving perceptual quality. These findings highlight the need for future audio watermarking designs to consider diffusion-based threats. Code and demos are available at https://differase.github.io/DiffErase/.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes