AWARE
Overview
AWARE (Audio Watermarking with Adversarial Resistance to Edits) is DeepMark's open-source multi-bit audio watermarking method, described in our paper on arXiv.
Learning-based watermarking systems usually get their robustness by training against a stack of simulated distortions. AWARE does without that stack: it finds the watermark by adversarial optimization in the time-frequency domain, within a perceptual budget that follows the level of the signal. Its detector does not depend on time order. A Bitwise Readout Head aggregates the evidence over time into one score per watermark bit, so the payload can be decoded after desynchronization and cuts. The paper reports audio quality (PESQ, STOI) and bit error rates across a range of audio edits.
Installation
Install AWARE from PyPI into its own virtual environment; on Debian and Ubuntu:
sudo apt-get update
sudo apt-get install -y curl build-essential python3-dev python3-venv
python3 -m venv .venv
source .venv/bin/activate
pip install aware AWARE runs on Python 3.10 to 3.12 and pins its dependencies (PyTorch 2.7.1 among them), which is why it needs its own environment. webrtcvad, pesq and, on Python 3.12, matplotlib are built from source during the install, so a C/C++ compiler and the Python headers are needed; the apt line above installs them.
On systems whose python3 is 3.13 or newer (Ubuntu 26.04, Debian 13, Fedora 43, Homebrew), pip refuses the install. Use uv to create the environment with Python 3.12 instead; its Python includes the headers:
# python3 is 3.13 or newer? Let uv fetch Python 3.12 for the environment:
curl -LsSf https://astral.sh/uv/install.sh | sh
source "$HOME/.local/bin/env" # puts uv on PATH in this shell
uv venv --seed --managed-python -p 3.12 .venv
source .venv/bin/activate
pip install awareOn Linux the default PyTorch build includes CUDA: about 3.2 GB to download and 5.7 GB on disk. On a machine without an NVIDIA GPU, install the CPU build first (about 0.35 GB), then AWARE:
pip install torch==2.7.1 torchaudio==2.7.1 --index-url https://download.pytorch.org/whl/cpuPyTorch 2.7.1 has no build for Intel Macs, so on macOS AWARE needs Apple Silicon.
Usage
Embed a 20-bit payload into a speech clip, read it back and check the result. No clip at hand? Download the speech sample from the phonesim page and save it as example.wav.
import numpy as np
import librosa
import soundfile
from aware.utils.models import load
from aware.service import embed_watermark, detect_watermark
from aware.metrics.audio import BER, PESQ
# "AWARE" embeds over the whole clip, "AWARE(20bps)" in every second of audio
embedder, detector = load(name="AWARE")
# AWARE works on mono audio at 16 kHz
signal, sr = librosa.load("example.wav", sr=16000, mono=True)
bits = np.random.randint(0, 2, size=20, dtype=np.int32) # 20-bit payload
watermarked = embed_watermark(signal, sr, bits, embedder)
soundfile.write("watermarked.wav", watermarked, sr)
detected_bits, confidence = detect_watermark(watermarked, sr, detector)
print(f"BER: {BER()(bits, detected_bits):.2f}")
print(f"PESQ: {PESQ()(watermarked, signal, sr):.2f}")
print(f"confidence: {confidence:.2f}") # watermarked when >= 0.5 On that sample it prints BER: 0.00, a PESQ around 4.3 and confidence: 1.00. detect_watermark returns the decoded bits and a confidence between 0 and 1; treat a clip as watermarked when the confidence is at least 0.5. In our tests unwatermarked speech and music stayed below 0.4, but clean synthetic tones (sine waves, ringback tones) can score above 0.5. AWARE works on mono audio at 16 kHz.
Embedding runs an optimization for each clip (400 iterations), so it takes much longer than detection: about 30 seconds to 2 minutes for a 10-second clip on a CPU. Its memory use grows with the length of the clip, about 25 MB per second of audio.
Modes
| Mode | Embedding |
|---|---|
| load(name="AWARE") | The payload is embedded over the whole clip. This is the default. |
| load(name="AWARE(20bps)") | The payload is repeated in every second of audio, 20 bits per second. Needs clips longer than about one second. |
Swipe the table sideways to see all columns.
Detect with the detector returned by the same load() call that gave you the embedder.
Citation
If you use AWARE in your research, please cite the paper:
@article{pavlović2025aware,
title={AWARE: Audio Watermarking with Adversarial Resistance to Edits},
author={Kosta Pavlović and Lazar Stanarević and Petar Nedić and
Slavko Kovačević and Igor Djurović},
year={2025},
eprint={2510.17512},
archivePrefix={arXiv},
primaryClass={cs.SD},
url={https://arxiv.org/abs/2510.17512},
}