AI 中文总结
该研究针对语音深度伪造源追踪问题,提出结合多任务概率属性提取与结构化KAN的框架,在ASVspoof2019-attr-17数据集上实现高准确率,且具备设计层面的可解释性,性能优于基线方法。
AI 中文摘要
现代语音合成器可生成高度逼真的语音,这使得源追踪(即识别伪造话语背后的生成器)对于取证、在线内容来源验证和平台问责制愈发重要。基于我们先前关于透明概率属性的研究(该研究将话语表示为合成器子组件上的概率分布),我们为语音深度伪造源追踪补充了两个关键要素:概率属性提取器的多任务训练,以及用于攻击分类的结构化Kolmogorov-Arnold网络(KAN)。概率特征通过基于共享AASIST或SSL-AASIST对抗主干的多任务学习模块联合估计。生成的概率特征嵌入由结构化KAN进行分类,该网络的拓扑结构遵循已知的属性-攻击关系。这从架构设计层面提供了可解释性:架构反映了攻击的生成层级,而KAN特征重要性得分可量化每个概率特征的贡献,无需SHAP等事后解释器。在ASVspoof2019-attr-17数据集上,该扩展框架对全部7个概率特征提取器实现了99%以上的平衡准确率,等错误率(EER)为0.16%至0.07%;在17类攻击分类任务中,其平衡准确率达99.64%,EER为0.11%。我们的改进模型不仅优于早期的两阶段基线方法,还展现出可靠的可解释性,其重要性得分与SHAP值一致,且在不同批次大小下结果稳定。这些发现凸显了结构化KAN在语音深度伪造源追踪领域的潜力,该方法兼具设计层面的准确性与可解释性。为实现透明性和可复现性,我们的代码库已公开可用:this https URL。
英文摘要
Modern speech synthesizers can produce highly realistic speech, making source tracing (i.e. identifying the generator behind a spoofed utterance) increasingly important for forensics, online content provenance, and platform accountability. Building on our prior work on transparent probabilistic attributes, which represent utterances as probability distributions over synthesizer sub-components, we extend speech deepfake source tracing with two key ingredients: multi-task training of the probabilistic attribute extractors and a structured Kolmogorov--Arnold Network (KAN) for attack classification. The probabilistic features are estimated jointly with a multi-task learning module built on a shared AASIST or SSL-AASIST countermeasure backbone. The resulting probabilistic feature embedding is classified by a structured KAN whose topology follows known attribute-to-attack relationships. This provides interpretability by construction: the architecture reflects the generative hierarchy of attacks, while KAN feature-importance scores quantify each probabilistic feature's contribution without post-hoc explainers such as SHAP. On ASVspoof2019-attr-17, the extended framework achieves balanced accuracies above 99% for all seven probabilistic feature extractors, with EERs of 0.16% to 0.07%, and 99.64% balanced accuracy with 0.11% EER for 17-class attack classification. Our revised model outperforms the earlier two-stage baselines, in addition to demonstrating reliable interpretability, with importance scores consistent with SHAP values, and stable results across batch sizes. These findings highlight the potential of structured KAN for speech deepfake source tracing that is both accurate and interpretable by design. For transparency and reproducibility, our codebase is publicly available: https://github.com/HoangHPham/KAN-Probabilistic-Deepfake-Attribution.
Comments26 pages, submitted to Elsevier Computer Speech & Language journal