arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过对抗扰动对语音匿名化中的重识别攻击进行先发制人的防御

Preemptive defense against re-identification attacks on voice anonymization via adversarial perturbation

Michele Panariello, Yibo Bai, Massimiliano Todisco, Nicholas Evans

arXiv 2610.06074首次发表:更新:

发表机构

EURECOM(欧瑞康)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出一种先发制人的语音匿名化防御方法,通过对抗扰动保护参考话语,结合测试端匿名化,将ASV等错误率从14%提升至45%,实现接近完美的隐私保护。

AI 中文摘要

语音匿名化(VA)用于隐藏语音数据中的说话人身份。性能通常通过自动说话人验证(ASV)作为代理来评估,以判断攻击者在匿名化后重新识别说话人的能力。防御者对测试话语进行匿名化;攻击者将测试话语与同样匿名化的参考话语进行比较以推断说话人身份,ASV性能下降表明匿名化成功。因此,防御者的保护是单向的,仅通过VA应用于测试话语。尽管目前尚未探索,但存在通过保护参考话语来增强匿名化的机会。我们提出了一种新的、先发制人的VA范式:使用对抗噪声保护参考话语,以降低其推断说话人身份的潜力。先发制人的保护不会降低参考话语的感知质量,并且独立于用于身份推断的特定ASV系统。通过结合先发制人的保护和常规的测试端VA,ASV等错误率可以从14%提高到45%(接近完美的隐私)。

英文摘要

Voice anonymization (VA) is used to conceal the voice identities in speech data. Performance is usually estimated using automatic speaker verification (ASV) as a proxy to judge the capability of an attacker to re-identify speakers after anonymization. The defender anonymizes test utterances; the attacker compares them to equally anonymized reference utterances to infer voice identity, with degraded ASV performance indicating successful anonymization. Thus, the defender's protection is one-sided and only applied to test utterances via VA. Though unexplored so far, there is an opportunity to enhance anonymization by protecting reference utterances too. We present a new, preemptive VA paradigm: reference utterances are protected using adversarial noise to degrade their potential to infer voice identity. Preemptive protection does not degrade the perceived quality of reference utterances and is independent of the specific ASV system used for identity inference. By combining preemptive protection and regular test-side VA, ASV equal error rates can be increased from 14\% to 45\% (near-perfect privacy).

CommentsAccepted to IEEE Spoken Language Technology (SLT) 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑