发表机构
Michigan State University(密歇根州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对音频深度伪造检测的对抗性扰动问题,提出检测引导自适应净化(DGAP)方法,可按输入调整净化强度,在三类检测器上防御性能最优且对良性输入影响小,在防御感知自适应攻击下仍有效。
AI 中文摘要
音频深度伪造检测器仍然容易受到抑制检测所用声学线索的对抗性扰动,使得被操纵的话语能够逃避检测器。尽管现有的防御措施可以提高鲁棒性,但它们需要重新训练检测器或引入额外的失真。基于扩散的净化方法则保持预训练检测器不变,但现有方法对所有输入使用相同的净化强度,在去除对抗性扰动和保留检测所需的微妙伪造线索之间存在权衡。在本文中,我们提出了检测引导自适应净化(DGAP),一种基于扩散的防御方法,可针对每个输入调整净化强度。基于一个观察结果,即轻度净化对对抗性输入的检测器分数的扰动远大于对良性输入的扰动,该框架将由此产生的分数偏移作为对抗性操纵的无参考指标。分数偏移小的输入将原封不动地传递,而被标记的输入在最终检测前会经历更强的净化。我们针对三种对抗性攻击设置、三种深度伪造检测器对该框架进行评估,并与九种现有防御措施进行比较。我们的结果表明,DGAP在所有检测器上均实现了最佳防御性能,同时几乎不影响良性输入,并且在防御感知自适应攻击下仍然有效。
英文摘要
Audio deepfake detectors remain vulnerable to adversarial perturbations that suppress the acoustic cues used for detection, allowing manipulated utterances to evade the detector. Although existing defenses can improve robustness, they require retraining the detector or introduce additional distortion. Diffusion-based purification instead leaves the pretrained detector unchanged, but existing methods use the same purification strength for all inputs, creating a trade-off between removing adversarial perturbations and preserving the subtle spoofing cues needed for detection. In this paper, we propose Detection-Guided Adaptive Purification (DGAP), a diffusion-based defense that adjusts purification strength per input. Building on the observation that a light purification perturbs the detector score of an adversarial input far more than that of a benign one, the framework uses the resulting score shift as a reference-free indicator of adversarial manipulation. Inputs with small shifts are passed unchanged, whereas flagged inputs undergo stronger purification before final detection. We evaluate the framework against three adversarial attack settings across three deepfake detectors, and compare it with nine existing defenses. Our results show that DGAP achieves the best defense performance across all detectors while leaving benign inputs nearly unaffected, and remains effective under the defense-aware adaptive attack.
CommentsAccepted at the 4th EAI International Conference on Security and Privacy in Cyber-Physical Systems and Smart Vehicles (EAI SmartSP 2026)