arXiv:2509.04980cs.SDcs.LG2025-09中稿 · ISMIR2025被引 2

用修复技术生成音乐对抗样本,隐蔽且高效破坏识别系统

MAIA: An Inpainting-Based Approach for Music Adversarial Attacks

  • 基于重要性分析定位关键音频段,用生成式修复精准篡改
  • 白盒黑盒攻击成功率高,听觉失真极小,人耳难以察觉
  • 适合研究模型安全的学者,揭示当前音乐识别系统的脆弱性

音乐对抗攻击在音乐信息检索(MIR)领域受到广泛关注。本文提出音乐对抗修复攻击(MAIA),一种支持白盒与黑盒攻击场景的新框架。MAIA首先通过重要性分析识别关键音频片段,再利用生成式修复模型,根据目标模型输出对这些片段进行重构,实现隐蔽且有效的对抗扰动。我们在多个MIR任务上评估了MAIA,结果表明其在白盒和黑盒设置下均具备高攻击成功率,同时保持极低的感知失真。主观听觉测试进一步证实,对抗样本具有高音频保真度。研究揭示了现有MIR系统的潜在漏洞,强调构建更鲁棒、更安全模型的必要性。

原文摘要 · Abstract (English)

Music adversarial attacks have garnered significant interest in the field of Music Information Retrieval (MIR). In this paper, we present Music Adversarial Inpainting Attack (MAIA), a novel adversarial attack framework that supports both white-box and black-box attack scenarios. MAIA begins with an importance analysis to identify critical audio segments, which are then targeted for modification. Utilizing generative inpainting models, these segments are reconstructed with guidance from the output of the attacked model, ensuring subtle and effective adversarial perturbations. We evaluate MAIA on multiple MIR tasks, demonstrating high attack success rates in both white-box and black-box settings while maintaining minimal perceptual distortion. Additionally, subjective listening tests confirm the high audio fidelity of the adversarial samples. Our findings highlight vulnerabilities in current MIR systems and emphasize the need for more robust and secure models.

音乐对抗生成修复模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。