Skip to content

Fish S2 codec numerical stability

Cold and warm requests to the pinned official S2 server initially returned different audio for the same input and seed. Token tracing showed that the first reference's codec tokens already differed before semantic generation. An independent codec-only run reproduced this on two consecutive encodes. Startup seeds, deterministic cuDNN settings, deterministic Torch algorithms, and a fixed cuBLAS workspace did not remove it.

Layer hashes locate the first divergence at encoder.block.1.block.0.block.0, a DAC Snake1d activation: its input hash matches across calls while its output hash differs. All trained parameter hashes match before and after the three-encode control. The underlying DAC implementation calls a TorchScript function for the Snake expression. Disabling JIT optimization makes repeated reference token hashes identical.

The opt-in eager_snake_v1 execution variant replaces owned codec Snake1d modules with that exact expression evaluated eagerly. Parameter objects and state dictionary keys are preserved; no upstream class or shared function is patched. The measured codec contains 58 such activations. Its repeated encodes, encode after decode, and math-only/default attention controls match the JIT-disabled token hash. This changes the numerical execution path, so it remains a named variant rather than rewriting historical artifacts.

Start the owned HTTP service with python scripts/serve_fish_s2.py --code-path /path/to/fish-speech --stable-codec-activations -- .... Use the same official arguments documented in HTTP setup. The default launcher leaves the upstream codec activation implementation intact. Client provenance should declare the variant and both local source files:

+adversary.service_codec_variant=eager_snake_v1
+adversary.service_launcher_code_path=/absolute/path/to/scripts/serve_fish_s2.py
+adversary.service_codec_code_path=/absolute/path/to/src/models/stable_codec_activations.py

These declarations record code and configuration. They do not attest the implementation of an arbitrary remote server. The controlled run verifies the locally owned process and exact source hashes separately.