arXiv:2412.09195cs.SDcs.LG2024-12被引 1

用对抗扰动保护语音隐私,还能原样恢复。

On the Generation and Removal of Speaker Adversarial Perturbation for Voice-Privacy Protection

  • 联合训练生成与移除模块,实现扰动可逆。
  • 在LibriSpeech上成功还原被扰动语音。
  • 适合语音隐私保护与司法取证场景。

神经网络对输入数据的微小扰动易受攻击。近期语音隐私保护研究利用对抗网络生成添加型扰动信号,隐藏说话人特征。本文探讨了可逆性:授权方(如说话人本人)可生成并移除扰动以恢复原始语音;而调查人员也可用相同技术反向恢复受保护语音,用于安全与司法鉴定。在此设定下,扰动生成模块被视为已知。为此,提出联合训练生成与移除模块的方法。在LibriSpeech数据集上的实验表明,从匿名化语音中可预测出微小扰动,并成功恢复原始语音。音频样本见: https://voiceprivacy.github.io/Perturbation-Generation-Removal/

原文摘要 · Abstract (English)

Neural networks are commonly known to be vulnerable to adversarial attacks mounted through subtle perturbation on the input data. Recent development in voice-privacy protection has shown the positive use cases of the same technique to conceal speaker's voice attribute with additive perturbation signal generated by an adversarial network. This paper examines the reversibility property where an entity generating the adversarial perturbations is authorized to remove them and restore original speech (e.g., the speaker him/herself). A similar technique could also be used by an investigator to deanonymize a voice-protected speech to restore criminals' identities in security and forensic analysis. In this setting, the perturbation generative module is assumed to be known in the removal process. To this end, a joint training of perturbation generation and removal modules is proposed. Experimental results on the LibriSpeech dataset demonstrated that the subtle perturbations added to the original speech can be predicted from the anonymized speech while achieving the goal of privacy protection. By removing these perturbations from the anonymized sample, the original speech can be restored. Audio samples can be found in \url{https://voiceprivacy.github.io/Perturbation-Generation-Removal/}.

语音隐私对抗扰动可逆加密

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。