arXiv:2507.02606cs.SDcs.AI2025-07ICML被引 5

提出新方法破解语音克隆防护扰动,揭示现有防御漏洞。

De-AntiFake: Rethinking the Protective Perturbations Against Voice Cloning Attacks

论文配图:De-AntiFake: Rethinking the Protective Perturbations Against Voice Cloning Attacks
图 1 · 摘自论文原文
  • 两阶段净化:先去扰动,再用音素引导对齐清洁语音分布
  • 在真实攻击模型下仍能有效破坏语音克隆,优于现有方法
  • 适合关注语音安全与隐私保护的研究者和开发者

语音生成模型的快速发展加剧了语音克隆(VC)带来的隐私与安全风险。近期研究通过引入对抗性扰动来干扰未经授权的语音克隆,但有攻击者可消除这些防护扰动并成功完成克隆。本研究首次在包含扰动净化的真实威胁模型下系统评估了此类防护扰动的有效性。结果表明,尽管现有净化方法可中和大部分防护扰动,但仍会引发语音克隆模型特征空间的畸变,导致克隆性能下降。基于此,我们提出一种新型两阶段净化方法:(1) 净化受扰语音;(2) 使用音素引导进行重构,使其贴近原始语音分布。实验显示,该方法在破坏语音克隆防御方面优于当前最先进的净化方法。研究揭示了基于对抗扰动的语音克隆防御的局限性,并强调亟需更稳健的解决方案以应对语音克隆带来的安全与隐私威胁。代码与音频样本详见 https://de-antifake.github.io。

原文摘要 · Abstract (English)

The rapid advancement of speech generation models has heightened privacy and security concerns related to voice cloning (VC). Recent studies have investigated disrupting unauthorized voice cloning by introducing adversarial perturbations. However, determined attackers can mitigate these protective perturbations and successfully execute VC. In this study, we conduct the first systematic evaluation of these protective perturbations against VC under realistic threat models that include perturbation purification. Our findings reveal that while existing purification methods can neutralize a considerable portion of the protective perturbations, they still lead to distortions in the feature space of VC models, which degrades the performance of VC. From this perspective, we propose a novel two-stage purification method: (1) Purify the perturbed speech; (2) Refine it using phoneme guidance to align it with the clean speech distribution. Experimental results demonstrate that our method outperforms state-of-the-art purification methods in disrupting VC defenses. Our study reveals the limitations of adversarial perturbation-based VC defenses and underscores the urgent need for more robust solutions to mitigate the security and privacy risks posed by VC. The code and audio samples are available at https://de-antifake.github.io.

语音克隆对抗扰动安全防护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。