On the Robustness of Audio Deepfake Detection under Audio Watermarking

📅 2026-08-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过音频水印评估音频深度伪造检测系统的鲁棒性,使用自监督学习、CNN和GNN模型,并分析了不同数据集上的表现差异。
📝 Abstract
Recent advances in generative audio models have enabled highly realistic synthetic speech, increasing the importance of reliable audio deepfake detection (ADD) systems. While prior studies have primarily focused on adversarially optimized perturbations, the robustness of ADD systems under realistic signal transformations remains insufficiently understood. In this work, we investigate the impact of audio watermarking on ADD systems by treating watermarking as a structured, non-adversarial perturbation rather than a conventional attack mechanism. Using a watermark-based evaluation framework built upon WavMark, we evaluate multiple self-supervised learning (SSL), Convolutional Neural Network (CNN) and Graph Neural Netrowk (GNN)-based ADD models across several benchmark datasets. Beyond conventional detection metrics, we further analyze watermark-induced representation shifts using Fréchet Distance, cosine similarity, and L2 distance in the embedding space. Experimental results reveal a strong dataset-dependent behavior: watermarking causes substantial performance degradation on ASVspoof 2021 LA and DF, while exhibiting limited impact on ASVspoof 2024, FoR, and ITW. Moreover, large embedding-space shifts are strongly associated with severe detection degradation, suggesting that watermark-induced perturbations can substantially alter the feature representations relied upon by current ADD systems. These findings demonstrate that benign signal transformations designed for content protection can expose previously overlooked robustness vulnerabilities in audio deepfake detection systems. Our code is available at https://github.com/ziqian0925/wm-ADD-robustness.git
Problem

Research questions and friction points this paper is trying to address.

audio deepfake detection
audio watermarking
robustness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Audio Watermarking
Deepfake Detection
Robustness
Self-supervised Learning
Embedding Space Analysis
🔎 Similar Papers
2024-04-22arXiv.orgCitations: 25
💼 Related Jobs
No related jobs found.
Z
Zi Qian Yong
School of Information Technology, Monash University, Malaysia campus
Ajinkya Kulkarni
Ajinkya Kulkarni
Idiap Research Institute
Speech processingDeep learning
J
Julia Lau
School of Information Technology, Monash University, Malaysia campus
H
Hwa Hui Tew
School of Information Technology, Monash University, Malaysia campus
S
Shu Min Leong
School of Information Technology, Monash University, Malaysia campus
R
Raphael Phan
School of Information Technology, Monash University, Malaysia campus
Sébastien Marcel
Sébastien Marcel
Senior researcher ( Idiap research institute ) and Professor ( University of Lausanne )
AIbiometricssecurity and privacyanti-spoofing and deepfakesattacks detection