arXiv:2409.07390cs.CRcs.LG2024-09被引 4

提出更强的伪造语音检测系统,抵御隐蔽攻击

D-CAPTCHA++: A Study of Resilience of Deepfake CAPTCHA under Transferable Imperceptible Adversarial Attack

  • 用可迁移的微弱干扰攻击暴露原系统漏洞
  • 通过对抗训练提升检测器和任务分类器鲁棒性
  • 适合关注语音安全与反伪造的技术团队

生成式AI的发展使得语音合成模型(如文本转语音、语音转换)日益逼真,已难以与自然人声区分,引发社会操控与政治干预风险。恶意者常利用此类技术冒充他人进行电话诈骗。因此,检测虚假语音对维护社会安全与信息真实性至关重要。近期研究提出基于挑战-应答协议的D-CAPTCHA系统以区分真实与伪造来电。本文研究该系统的鲁棒性,提出更可靠的D-CAPTCHA++版本。首先揭示D-CAPTCHA在可迁移不可察觉对抗攻击下的脆弱性;其次通过在深度伪造检测器和任务分类器中引入对抗训练,增强系统防御能力。

原文摘要 · Abstract (English)

The advancements in generative AI have enabled the improvement of audio synthesis models, including text-to-speech and voice conversion. This raises concerns about its potential misuse in social manipulation and political interference, as synthetic speech has become indistinguishable from natural human speech. Several speech-generation programs are utilized for malicious purposes, especially impersonating individuals through phone calls. Therefore, detecting fake audio is crucial to maintain social security and safeguard the integrity of information. Recent research has proposed a D-CAPTCHA system based on the challenge-response protocol to differentiate fake phone calls from real ones. In this work, we study the resilience of this system and introduce a more robust version, D-CAPTCHA++, to defend against fake calls. Specifically, we first expose the vulnerability of the D-CAPTCHA system under transferable imperceptible adversarial attack. Secondly, we mitigate such vulnerability by improving the robustness of the system by using adversarial training in D-CAPTCHA deepfake detectors and task classifiers.

语音生成对抗攻击深度伪造检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。