machine learning

MusicMark: A Robust Generative Watermarking Framework for Music Generation

arXiv:2607.11117

summary

The paper introduces MusicMark, a framework that embeds watermarks directly into the latent space of diffusion-based music generation models, making the watermarks robust to transformations such as neural codec re‑synthesis while preserving audio quality.

Abstract

AI music generation has rapidly advanced alongside commercial platforms, raising the need for reliable watermarking for provenance and attribution. However, existing audio watermarking research has largely focused on speech, and applying speech-oriented methods to music is challenging due to music's complex structure and rich acoustic texture. Most existing methods are post-hoc, adding imperceptible perturbations after generation rather than embedding watermarks as part of the content. This makes them fragile under transformations and especially vulnerable to neural codec re-synthesis, which can discard imperceptible residual signals. Moreover, since generation and watermarking are decoupled, the watermarking step can be bypassed or omitted, weakening provenance guarantees. To address these issues, we propose MusicMark, which, to the best of our knowledge, is the first generative watermarking framework for music. Specifically, MusicMark embeds watermark messages into the semantic latent space during generation, incorporating the watermark as part of the musical content and ensuring robustness against diverse attacks, particularly neural codec re-synthesis. To this end, we introduce a watermark adapter into a diffusion-based generation model to embed watermark messages across denoising steps. The adapter and detector are trained with a joint objective that preserves fidelity by constraining watermarked latents close to their unwatermarked reference latents, while improving robustness through attack augmentations. Experiments demonstrate that MusicMark substantially outperforms post-hoc baselines across diverse attacks including neural codec re-synthesis, while maintaining comparable generation quality. We further introduce a cover-song attack, converting the singing voice while preserving musical content, and show that MusicMark remains more robust than post-hoc methods.

Submitted to IEEE Transactions on Information Forensics and Security

Topics & keywords

#music generation#audio watermarking#diffusion models#latent space embedding#robustness to attacksdiffusion-based generationwatermark adapterlatent spaceneural codec re-synthesisjoint training objective
MusicMark: A Robust Generative Watermarking Framework for Music Generation · wovepaper