提出可迁移的音频伪造攻击框架,暴露出当前检测系统严重漏洞。
Transferable Adversarial Attacks on Audio Deepfake Detection
- 用生成对抗网络与多模型集成生成可迁移攻击
- 主流检测系统准确率从98%降至26%,黑盒下仍跌至54%
- 兼顾语音可懂性和听感真实,适合评估真实场景安全性
音频深度伪造带来身份冒用、欺诈和声誉损害等重大威胁。为应对风险,音频深度伪造检测(ADD)技术已被开发,在ASVspoof2019等基准上表现良好。然而,其对可迁移对抗攻击的鲁棒性仍缺乏研究。本文提出一种基于GAN的可迁移对抗攻击框架,通过集成多个替代检测模型与判别器,生成更贴近真实场景的攻击。不同于以往方法,该框架引入自监督音频模型,确保生成语音在语义和听觉上的完整性,从而实现高质量对抗样本。在基准数据集上的实验表明,SOTA ADD系统存在显著脆弱性:白盒、灰盒和黑盒场景下准确率分别从98%、92%、94%降至26%、54%、84%;在In-the-Wild和WaveFake数据集上,性能进一步下降至46%和67%。结果凸显现有ADD系统面临严重安全风险,亟需提升对高级对抗威胁的防御能力。
原文摘要 · Abstract (English)
Audio deepfakes pose significant threats, including impersonation, fraud, and reputation damage. To address these risks, audio deepfake detection (ADD) techniques have been developed, demonstrating success on benchmarks like ASVspoof2019. However, their resilience against transferable adversarial attacks remains largely unexplored. In this paper, we introduce a transferable GAN-based adversarial attack framework to evaluate the effectiveness of state-of-the-art (SOTA) ADD systems. By leveraging an ensemble of surrogate ADD models and a discriminator, the proposed approach generates transferable adversarial attacks that better reflect real-world scenarios. Unlike previous methods, the proposed framework incorporates a self-supervised audio model to ensure transcription and perceptual integrity, resulting in high-quality adversarial attacks. Experimental results on benchmark dataset reveal that SOTA ADD systems exhibit significant vulnerabilities, with accuracies dropping from 98% to 26%, 92% to 54%, and 94% to 84% in white-box, gray-box, and black-box scenarios, respectively. When tested in other data sets, performance drops of 91% to 46%, and 94% to 67% were observed against the In-the-Wild and WaveFake data sets, respectively. These results highlight the significant vulnerabilities of existing ADD systems and emphasize the need to enhance their robustness against advanced adversarial threats to ensure security and reliability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。