arXiv:2508.10949cs.SDeess.AS2025-08KDD被引 7

新数据集揭示音频伪造检测模型真实世界失效问题。

Perturbed Public Voices (P$^{2}$V): A Dataset for Robust Audio Deepfake Detection

  • 用大模型生成一致语义的伪造语音,模拟真实攻击场景。
  • 现有22个检测器在新数据集上性能平均下降43%。
  • 适合研究鲁棒性检测与真实环境下的反伪造技术者。

当前音频深度伪造检测器不可信:虽在受控基准上表现优异,但在真实场景中失效。本文提出受伦理审查批准的P$^{2}$V数据集,捕捉恶意伪造的三大关键特征:(1) 利用大语言模型实现身份一致的文本生成,(2) 包含环境噪声与对抗扰动,(3) 融入2020–2025年最先进的语音克隆技术。实验显示,22个近期检测模型在P$^{2}$V上性能平均下降43%,以深度伪造音频的F1均值、AUC和1-EER衡量;简单对抗扰动导致最高16%性能退化,先进克隆技术使可检测性降低20–30%。相比之下,基于P$^{2}$V训练的模型对上述攻击保持鲁棒性,并能泛化至已有数据集,确立了新的鲁棒音频伪造检测基准。该数据集将在论文被会议/期刊接收后公开。

原文摘要 · Abstract (English)

Current audio deepfake detectors cannot be trusted. While they excel on controlled benchmarks, they fail when tested in the real world. We introduce Perturbed Public Voices (P$^{2}$V), an IRB-approved dataset capturing three critical aspects of malicious deepfakes: (1) identity-consistent transcripts via LLMs, (2) environmental and adversarial noise, and (3) state-of-the-art voice cloning (2020-2025). Experiments reveal alarming vulnerabilities of 22 recent audio deepfake detectors: models trained on current datasets lose 43% performance when tested on P$^{2}$V, with performance measured as the mean of F1 score on deepfake audio, AUC, and 1-EER. Simple adversarial perturbations induce up to 16% performance degradation, while advanced cloning techniques reduce detectability by 20-30%. In contrast, P$^{2}$V-trained models maintain robustness against these attacks while generalizing to existing datasets, establishing a new benchmark for robust audio deepfake detection. P$^{2}$V will be publicly released upon acceptance by a conference/journal.

音频伪造深度伪造检测基准语音克隆

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。