arXiv:2507.22208cs.SDcs.AI2025-07中稿 · IJCB 2025被引 2

提出量子启发的语音去标识技术,实现精准删除特定声音特征而不影响模型性能。

Quantum-Inspired Audio Unlearning: Towards Privacy-Preserving Voice Biometrics

  • 用量子干扰初始化权重,直接抹除目标语音特征。
  • 实现0%遗忘准确率,保留数据性能损失低至0.05%。
  • 适合需合规删除个人语音数据的生物识别系统应用。

语音认证与音频生物识别系统的广泛应用加剧了敏感语音数据的隐私风险。遵守GDPR和印度DPDP法案等隐私法规,要求对已训练的生物识别模型中个体语音特征进行精准、高效的删除。现有针对视觉数据的去标识方法难以应对音频信号的时序性、时间维度和高维特性,导致说话人和口音信息删不彻底。为此,我们提出QPAudioEraser,一种量子启发的音频去标识框架。其核心包括:(1)利用破坏性干涉初始化权重以消除目标特征;(2)基于叠加态的标签变换隐藏类别身份;(3)最大化不确定性的量子损失函数;(4)受纠缠启发的关联权重混合机制以保留模型知识。在AudioMNIST、Speech Commands、LibriSpeech和Speech Accent Archive数据集上,对ResNet18、ViT和CNN架构的综合评估表明,该框架在单类、多类、序列及口音级去标识场景中均显著优于传统基线,实现目标数据完全擦除(0%遗忘准确率),同时对保留数据的影响极小(性能下降最低达0.05%),验证了其作为鲁棒隐私保护方案的有效性。

原文摘要 · Abstract (English)

The widespread adoption of voice-enabled authentication and audio biometric systems have significantly increased privacy vulnerabilities associated with sensitive speech data. Compliance with privacy regulations such as GDPR's right to be forgotten and India's DPDP Act necessitates targeted and efficient erasure of individual-specific voice signatures from already-trained biometric models. Existing unlearning methods designed for visual data inadequately handle the sequential, temporal, and high-dimensional nature of audio signals, leading to ineffective or incomplete speaker and accent erasure. To address this, we introduce QPAudioEraser, a quantum-inspired audio unlearning framework. Our our-phase approach involves: (1) weight initialization using destructive interference to nullify target features, (2) superposition-based label transformations that obscure class identity, (3) an uncertainty-maximizing quantum loss function, and (4) entanglement-inspired mixing of correlated weights to retain model knowledge. Comprehensive evaluations with ResNet18, ViT, and CNN architectures across AudioMNIST, Speech Commands, LibriSpeech, and Speech Accent Archive datasets validate QPAudioEraser's superior performance. The framework achieves complete erasure of target data (0% Forget Accuracy) while incurring minimal impact on model utility, with a performance degradation on retained data as low as 0.05%. QPAudioEraser consistently surpasses conventional baselines across single-class, multi-class, sequential, and accent-level erasure scenarios, establishing the proposed approach as a robust privacy-preserving solution.

语音生物识别隐私保护去标识量子启发

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。