arXiv:2508.09803eess.AScs.LG2025-08中稿 · ICASSP 2026被引 2

用对抗学习提升说话人匿名化评估的鲁棒性,防止高估隐私保护效果。

Improving the Speaker Anonymization Evaluation's Robustness to Target Speakers with Adversarial Learning

  • 引入目标说话人分类器,量化评估中目标信息的泄露程度。
  • 在同性别选择算法下,评估结果更可信,隐私保护能力下降明显。
  • 适用于多种匿名化模型,适合关注语音隐私安全的研究者。

当前说话人匿名化隐私评估在使用同性别目标选择算法(TSA)时往往高估了隐私保护效果,尽管该方法会泄露说话人性别信息,应更易被攻破。我们推测这是因为评估未考虑匿名语音同时包含源与目标说话人信息。为此,提出添加一个目标分类器来衡量目标信息的影响,并可通过对抗学习移除该分类器。实验表明,该方法对多种匿名化模型有效,尤其在同性别TSA场景下显著提升了评估可靠性。

原文摘要 · Abstract (English)

The current privacy evaluation for speaker anonymization often overestimates privacy when a same-gender target selection algorithm (TSA) is used, although this TSA leaks the speaker's gender and should hence be more vulnerable. We hypothesize that this occurs because the evaluation does not account for the fact that anonymized speech contains information from both the source and target speakers. To address this, we propose to add a target classifier that measures the influence of target speaker information in the evaluation, which can also be removed with adversarial learning. Experiments demonstrate that this approach is effective for multiple anonymizers, particularly when using a same-gender TSA, leading to a more reliable assessment.

语音隐私对抗学习匿名化评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。