Proactive Detection of Voice Cloning with Localized Watermarking
Robin San Roman, Pierre Fernandez, Alexandre Défossez, Teddy Furon, Tuan Tran, Hady Elsahar
TL;DR
AudioSeal tackles the risk of voice cloning by introducing a proactive, localized watermarking framework for AI-generated speech. It uses a generator–detector pair trained with a novel TF-Loudness perceptual loss and a masked-sample localization objective to embed imperceptible watermarks detectable at the sample level ($1/16k$ s) and, optionally, multi-bit messages for attribution. The method delivers state-of-the-art robustness to common audio edits, precise localization down to single samples, and two orders of magnitude faster detection than prior watermarking approaches, making it suitable for real-time, large-scale deployment. A security analysis shows that keeping the detector weights private is important to resist adversarial watermark removal, highlighting practical deployment considerations for AI content provenance APIs.
Abstract
In the rapidly evolving field of speech generative models, there is a pressing need to ensure audio authenticity against the risks of voice cloning. We present AudioSeal, the first audio watermarking technique designed specifically for localized detection of AI-generated speech. AudioSeal employs a generator/detector architecture trained jointly with a localization loss to enable localized watermark detection up to the sample level, and a novel perceptual loss inspired by auditory masking, that enables AudioSeal to achieve better imperceptibility. AudioSeal achieves state-of-the-art performance in terms of robustness to real life audio manipulations and imperceptibility based on automatic and human evaluation metrics. Additionally, AudioSeal is designed with a fast, single-pass detector, that significantly surpasses existing models in speed - achieving detection up to two orders of magnitude faster, making it ideal for large-scale and real-time applications.
