Looking to implement C2PA? Trufo provides tooling to take care of everything from certificates and timestamping to watermarking and fingerprinting. Learn More
The first neural watermark designed for provenance at scale.
Published July 1, 2026
We are introducing our new line of AI-powered watermarks, PawPrint, available for image and audio and video. PawPrint represents a massive leap in performance over existing models, across all dimensions (speed, accuracy, durability, perceptibility, etc.). It can be swiftly deployed in any business use case where digital media content needs to be reliably identified. PawPrint is available today as part of our C2PA Signing API & SDK services.
Trufo's pawprint.audio watermark delivers a substantial improvement in watermark performance across the board:
Watermark
Company
Year
Payload [bits]
Speed@60s [ms]
ViSQOL ↑
FPR ↓
Durability ↑
Score
pawprint.audio
Trufo
2026
44A-
20A
4.73A
0.000A
0.718A-
96
perth
ResembleAI
2025
0D
8A
4.67B+
0.070C
0.622B
60
silentcipher
Sony
2024
40A-
234B-
4.66B+
0.197C-
0.456C+
62
audioseal
Meta
2024
16B-
116B
4.71A-
0.001B+
0.553B-
72
wavmark
Microsoft
2023
16B-
9,176D
4.66B+
0.000A
0.569B-
62
audiowmark
Traditional
2022
128A
426C+
4.73A
0.810D+
0.391C
62
When paired with Trufo's provenance platform, pawprint.audio becomes the natural choice for practical watermark deployment in almost any commercial setting.
It is important that the watermark decoder is fast enough to be used in real-time applications, especially given the interoperability requirements of the EU AI Act. The only watermark suitable for provenance that decodes at a speed we believe does not cause burden to downstream readers is pawprint.audio.
Useful Features
C2PA Integration
The pawprint.audio watermark is a registered soft-binding with C2PA, and is maintained by Trufo with full cloud synchronization of content records associated with watermark IDs. This means that, unlike other watermark systems:
(a) pawprint.audio can be immediately deployed with enterprise support SLAs.
(b) pawprint.audio can be used for both content provenance and copyright tracking.
The pawprint.audio watermark comes with a very low FPR.
This means that the output of the watermark decoder is trustable.
Furthermore, while the watermark alone does not protect against security attack vectors such as removal or forgery (it is very difficult for a watermark to do so, especially against any serious attacker), the Trufo Provenance Platform does mitigate these threats. In particular, by tying the watermark to a content provenance record (in the form of a signed C2PA manifest stored in the Trufo distributed ledger system), the watermark becomes a multi-purpose hyperlink whose corresponding data once retrieved can provide and additional required validation.
On-Demand Analysis
The pawprint.audio decoder produces a rich output, so that any audio clip, even if it is composed of many spliced segments, can be quickly analyzed.
The example below stitches together four clips, three of them watermarked. The pawprint.audiodecoder is able to pick out the segments and also provide a rough indication of the amount of editing that has been done at each point in time.
Evaluation
We compare pawprint.audio against five popular watermarks that we were able to obtain for testing:
audiowmark (Traditional, 2022)
wavmark (Microsoft, 2023)
audioseal (Meta, 2024)
silentcipher (Sony, 2024)
perth (ResembleAI, 2025)
The evaluations are conducted on a mix of music, voice, and general audio clips, taken from the CC0 and CC-BY subsets of FMA, MUSAN, MusicNet, Slakh.
Speed
We benchmarked encode and decode speed at clip lengths of 1s, 10s, and 100s, measured at steady state (after warm-up), with Nvidia 5090 GPU and AMD 7950X3D CPU; GPU is used whenever possible.
pawprint.audio
audiowmark
wavmark
audioseal
silentcipher
perth
sample rate
48kHz
44.1kHz
16kHz
16kHz
44.1kHz
32kHz
encode 1s (ms)
1.6
18
—
4.8
2.7
1.2
encode 10s (ms)
2.6
24
126
14.0
15.5
1.8
encode 100s (ms)
18.2
61
1,329
124.8
170.1
5.2
decode 1s (ms)
2.5
153
—
2.4
4.1
1.9
decode 10s (ms)
2.6
168
1,265
7.3
23.1
2.7
decode 100s (ms)
14.1
545
14,075
65.9
221.0
5.2
This means that, with pawprint.audio, you can analyze a full movie in a single second. The watermark processing time will not be a bottleneck in your encoding or decoding workflow. This also means that you can expect pawprint.audio decoding to be supported by Trufo in perpetuity, because doing so is not costly.
Perceptibility
We used three metrics: SNR (in waveform space), weighted LSD (in STFT space), ViSQOL (in latent space). Note that none of the three metrics were used as the loss function in training pawprint.audio.
pawprint.audio
audiowmark
wavmark
audioseal
silentcipher
perth
SNR [dB] ↑
29.3
27.9
36.4
23.4
49.3
15.7
WLSD [dB] ↓
0.83
1.07
1.93
2.42
0.84
1.85
ViSQOL ↑
4.73
4.73
4.66
4.71
4.66
4.67
Note that SNR is not particularly accurate; for example, a phase shift (which results in no change in perception) will produce a terrible SNR score. The WLSD formula is given by:
The A function comes from the IEC 61672-1 A-weighting curve, and the score is computed over the 20-20000 Hz band. The ViSQOL metric is an improved version of PESQ developed by Google.
Durability
We tested recovery of the payload against a combination of attacks. The test segments were of lengths 1s, 3s, and 10s. The evaluation included the following attacks:
Furthermore, unlike most benchmarks that only apply one easy attack at a time (so every number is 1.000 or 0.999), we apply a range of attacks (easy, medium, hard) independently, so some segments are subjected to multiple attacks and some segments are not attacked at all. This provides a much more practical evaluation of watermark durability. Furthermore, we stress the importance of accuracy: a watermark decoder that returns a payload when there is no watermark, or that returns an incorrect payload when there is a watermark, is not an effective watermark decoder. Thus, we focus on actual practical identification, not on the standard BER.
Breaking down the durability evaluation:
by segment length
1s
3s
10s
by attack count
0 attacks
1
2
3+
by single attack
pawprint.audio
audiowmark
wavmark
audioseal
silentcipher
perth
Overlay
0.485
0.172
0.412
0.241
0.354
0.430
Speed
0.474
0.000
0.314
0.000
0.000
0.686
Pitch
0.509
0.000
0.000
0.000
0.000
0.042
Compression
0.653
0.329
0.524
0.577
0.281
0.636
Resample
0.960
0.588
0.778
0.857
0.515
0.782
Low-pass
0.896
0.616
0.816
0.472
0.640
0.800
High-pass
0.977
0.597
0.775
0.450
0.605
0.775
White noise
0.489
0.221
0.389
0.695
0.305
0.611
Equalization
1.000
0.649
0.809
0.574
0.766
0.777
Peak norm.
0.980
0.647
0.833
0.725
0.843
0.775
It is clear from these evaluations that pawprint.audio is by far the most durable, even when compared to 0-bit watermarks such as perth. Notably, pawprint.audio is the only watermark that is robust against pitch modulations.
Overall Score
The overall ranking of tested watermarks, based on our composite score, is as follows:
pawprint.audio
96
audioseal
72
competitor est.
65
wavmark
62
silentcipher
62
audiowmark
62
perth
60
legacy est.
60
There are a number of commercial watermarks we were unable to test. We estimate that the strongest competitors would score around 65, while legacy watermarks from companies lacking strong AI research teams may sit around 60.
Overall, even if accounting for different methods of evaluation, the clear winner is pawprint.audio.