Neural audio watermarks are increasingly deployed in commercial speech generation systems to make AI-generated speech traceable, yet their robustness has been studied mainly under conventional signal distortions. Since a watermark can be regarded as imperceptible noise added to the speech signal, a natural question is whether speech enhancement (SE), as a denoising model, can remove it. In this paper, we cascade Gaussian noise with SE models as a black-box watermark removal attack, covering both discriminative and generative SE paradigms, against six neural watermarks: AudioSeal, WavMark, SilentCipher, Timbre, Perth, and AlignMark. Experimental results show that the proposed attack significantly outperforms existing neural re-synthesis methods in watermark removal. In particular, we find that generative SE, which reconstructs the harmonic regions of speech while denoising, is highly destructive to watermarks. These findings show that SE poses a serious threat to current audio watermarking methods, and we call for SE-aware robustness evaluation in watermark design.
Figures & tables
Re-synthesis
SE only
GN 20 dB + SE
GN 10 dB + SE
WM
Metric
WM only
EnCodec
BigVGAN v2
AudioLDM
Demucs
DF3
FlowSE
SGMSE
GenSE
UniSE
GN 20 dB
+ Demucs
+ DF3
+ FlowSE
+ SGMSE
+ GenSE
+ UniSE
GN 10 dB
+ Demucs
+ DF3
+ FlowSE
+ SGMSE
+ GenSE
+ UniSE
AudioSeal
TPR@1%FPR
100.0
100.0
0.0
0.0
100.0
100.0
85.0
88.5
0.0
0.0
60.0
64.0
67.5
3.0
1.0
0.0
0.0
1.0
6.0
5.0
0.0
0.0
0.0
0.0
UTMOS
4.09
3.75
3.99
2.64
4.12
4.14
4.17
4.16
3.38
4.07
3.06
3.87
4.00
4.08
4.08
3.42
4.05
1.49
3.52
3.59
3.82
3.85
3.27
4.06
ESTOI
0.994
0.943
0.975
0.757
0.979
0.985
0.955
0.963
0.749
0.817
0.885
0.917
0.923
0.910
0.907
0.736
0.807
0.709
0.833
0.837
0.821
0.817
0.687
0.777
ViSQOL
4.941
4.567
4.899
4.175
4.730
4.685
4.493
4.583
3.755
3.967
3.801
4.057
3.930
3.953
3.943
3.442
3.761
2.867
3.518
3.425
3.431
3.376
3.094
3.562
WavMark
TPR@1%FPR
100.0
0.0
0.0
0.0
100.0
100.0
99.5
100.0
0.0
0.0
28.0
6.0
9.5
0.0
0.0
0.0
0.0
0.0
0.0
0.0
0.0
0.0
0.0
0.0
Table 1: Evaluation results of each watermarking method (first column) under the re-synthesis baselines and the proposed SE-based attack pipeline. Lower TPR@1%FPR and higher UTMOS, ESTOI, ViSQOL indicate stronger removal and better preserved quality.
Audio watermarking is increasingly important for tracing generated speech. Several audio watermarking methods have been proposed to embed the watermark in various domains, such as waveform, timbre feature, or latent representations, for making the embedded watermark robust against traditional digital signal processing (DSP) attacks. On the other hand, modern neural codecs introduce a different threat from DSP attacks: they resynthesize speech through quantized acoustic representations and can remove the embedded watermark evi- dence that is not aligned with codec-preserved structure. In this paper, we propose NeuMark, a codec-latent audio watermarking framework that embeds watermark evidence into SpeechTok- enizer acoustic tokens to address this resynthesis threat. NeuMark uses cross-attention to inject a 16-bit message across residual vector quantization (RVQ) layers, distributing the watermark over codec-aligned latent structure. Experimental results show that NeuMark substantially improves robustness under neural- codec resynthesis while supporting both watermark detection and message recovery. We also analyze the trade-off between reconstruction-referenced transparency and original-referenced robustness.
Recent advances in generative speech models have made it increasingly difficult to distinguish authentic from synthetic audio, enabling new forms of fraud and misinformation. Audio watermarking offers a promising defense by embedding an imperceptible signal into generated speech that can later be detected to verify its provenance. However, recent studies have shown that existing post-hoc watermarking methods fail under neural codecs and denoisers, transformations routinely applied during real-world storage, transmission, and processing, severely limiting their practical utility. Here we introduce CRAW, a codec-robust audio watermarking framework that jointly improves robustness against neural re-synthesis while maintaining high perceptual quality. CRAW combines distortion-aware training with an attention-based pooling mechanism, inference-time perceptual mask- ing, and an error-correcting code to recover the fidelity lost during robust training. Experiments demonstrate that CRAW achieves state-of-the-art robustness against neural codecs, denoisers, and vocoders while maintaining perceptual quality comparable to existing post-hoc watermarking methods. The code is available at https://github.com/DavidC1212/craw.
Watermarking is a promising tool for establishing the provenance of AI-generated speech. While many neural audio watermarking methods rely on a separately trained watermark generator, token-level watermarking is a training-free alternative that operates directly during generation. Its main weakness is retokenization: decoding generated speech to a waveform and encoding it again can change token identities and erode the watermark. To make the watermark robust to these changes, we propose Redwing, REtokenization-Durable Watermarking IN Generation. It builds a graph from the token substitutions observed under retokenization, whose Laplacian yields a basis that assigns similar values to tokens likely to substitute for one another. Over this basis, embedding and detection functions are jointly optimized to preserve watermark signal through retokenization while limiting embedding distortion and detector variability on unwatermarked speech. On the Moshi full-duplex system, after eight consecutive passes of Mimi resynthesis, Redwing achieves 80.7% TPR at a calibrated 1% FPR, compared with 8.3% for KGW and at most 7.3% for WMAR. It also has the highest TPR after eight passes through three other neural codecs (77.5-93.0%), and the gains generalize to TTS models at a speech-quality cost close to that of KGW. These results show that retokenization is not merely a source of noise: its transition structure can be exploited as a design principle for robust token-level watermarking.
Kanghwi Lee, Kyeongseok Jeong, Jeongmin Liu
Institute of Neuroinformatics, University of Zurich and ETH Zurich, Switzerland · NAVER Cloud