评测主流音频伪造检测方法在对抗攻击下的表现,揭示其漏洞并推动更鲁棒的防御设计。
Adversarial Attacks on Audio Deepfake Detection: A Benchmark and Comparative Study
- 对比五大数据集上两类检测方法对多种对抗攻击的响应
- 发现现有检测器在频谱扰动下准确率下降超30%
- 为语音生物识别安全提供实证依据,适合安全与模型鲁棒性研究者
生成式AI在制作高度逼真的音频伪造内容方面取得显著进展,严重威胁语音验证、语音生物识别、音频会议及刑事调查等应用。为此,多项前沿音频伪造检测(ADD)方法被提出,旨在识别生成式AI的痕迹以区分真实与伪造音频。然而,这些方法极易受到反取证(AF)攻击的影响,后者通过统计修改(如变调、滤波、加噪、量化)或优化型攻击(如FGSM、PGD、C&W、DeepFool)隐藏生成痕迹。本文系统评估了当前主流的ADD方法,在五个基准数据集上采用原始波形与频谱两种策略进行测试,揭示其在不同对抗攻击下的性能表现与脆弱性。研究不仅暴露了现有检测器的局限,也为构建更鲁棒、泛化更强的检测器提供了指导,有助于未来应对不断演化的反取证技术。
原文摘要 · Abstract (English)
The widespread use of generative AI has shown remarkable success in producing highly realistic deepfakes, posing a serious threat to various voice biometric applications, including speaker verification, voice biometrics, audio conferencing, and criminal investigations. To counteract this, several state-of-the-art (SoTA) audio deepfake detection (ADD) methods have been proposed to identify generative AI signatures to distinguish between real and deepfake audio. However, the effectiveness of these methods is severely undermined by anti-forensic (AF) attacks that conceal generative signatures. These AF attacks span a wide range of techniques, including statistical modifications (e.g., pitch shifting, filtering, noise addition, and quantization) and optimization-based attacks (e.g., FGSM, PGD, C \& W, and DeepFool). In this paper, we investigate the SoTA ADD methods and provide a comparative analysis to highlight their effectiveness in exposing deepfake signatures, as well as their vulnerabilities under adversarial conditions. We conducted an extensive evaluation of ADD methods on five deepfake benchmark datasets using two categories: raw and spectrogram-based approaches. This comparative analysis enables a deeper understanding of the strengths and limitations of SoTA ADD methods against diverse AF attacks. It does not only highlight vulnerabilities of ADD methods, but also informs the design of more robust and generalized detectors for real-world voice biometrics. It will further guide future research in developing adaptive defense strategies that can effectively counter evolving AF techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。