用可解释的概率属性嵌入,精准识别语音伪造攻击类型。
An Explainable Probabilistic Attribute Embedding Approach for Spoofed Speech Characterization
- 设计概率属性捕捉伪造攻击的子组件特征,提升可解释性。
- 检测准确率达99.7%,攻击归因准确率达99.2%,优于原始嵌入。
- 通过Shapley值分析各属性贡献,适合安全验证与模型审计场景。
我们提出一种可解释的概率属性嵌入方法,用于语音伪造特征刻画。与难以解释的高维原始嵌入不同,该方法设计概率属性来评估特定伪造攻击中子组件的存在与否。这些属性被应用于伪造检测和攻击归因两个下游任务。为保证后端决策的可解释性,采用决策树分类器。在ASVspoof2019数据集上,基于三个模型(AASIST、Rawboost-AASIST、SSL-AASIST)提取的伪造对抗嵌入进行实验,结果表明属性嵌入在两项任务上的性能与原始嵌入相当。所提方法在伪造检测和攻击归因上的最佳准确率分别为99.7%和99.2%,分别优于原始嵌入的99.7%和94.7%。通过估计Shapley值分析各属性相对贡献,发现声学特征预测、波形生成(声码器)和说话人建模对检测重要;而时长建模、声码器和输入类型在攻击归因中起关键作用。
原文摘要 · Abstract (English)
We propose a novel approach for spoofed speech characterization through explainable probabilistic attribute embeddings. In contrast to high-dimensional raw embeddings extracted from a spoofing countermeasure (CM) whose dimensions are not easy to interpret, the probabilistic attributes are designed to gauge the presence or absence of sub-components that make up a specific spoofing attack. These attributes are then applied to two downstream tasks: spoofing detection and attack attribution. To enforce interpretability also to the back-end, we adopt a decision tree classifier. Our experiments on the ASVspoof2019 dataset with spoof CM embeddings extracted from three models (AASIST, Rawboost-AASIST, SSL-AASIST) suggest that the performance of the attribute embeddings are on par with the original raw spoof CM embeddings for both tasks. The best performance achieved with the proposed approach for spoofing detection and attack attribution, in terms of accuracy, is 99.7% and 99.2%, respectively, compared to 99.7% and 94.7% using the raw CM embeddings. To analyze the relative contribution of each attribute, we estimate their Shapley values. Attributes related to acoustic feature prediction, waveform generation (vocoder), and speaker modeling are found important for spoofing detection; while duration modeling, vocoder, and input type play a role in spoofing attack attribution.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。