arXiv:2509.09296eess.AS2025-09被引 1

构建首个大规模语音验证对抗攻击数据集并提出高效防御方法。

Over-the-Air Adversarial Attack Detection: from Datasets to Defenses

  • 构建包含628万样本的AdvSV 2.0数据集,覆盖OTL与OTA场景。
  • 新攻击方法使对抗攻击威力更强,威胁更大。
  • 提出CODA-OCC防御模型,误报率仅11.2%,性能领先。

自动说话人验证(ASV)系统广泛用于语音身份认证,但近年来暴露于线上(OTL)和空中(OTA)对抗攻击。尽管已有多种检测方法,因缺乏全面数据集而未充分验证。为此,我们构建了AdvSV 2.0数据集,包含628万样本,总时长达800小时,涵盖经典对抗攻击算法、ASV系统及OTL/OTA双重场景。此外,提出基于神经重放模拟器(NRS)的新攻击方法,显著增强对抗性OTA攻击效果。为应对攻击,提出一种在单类分类框架下的对比学习防御方法CODA-OCC。实验表明,该方法在AdvSV 2.0上实现EER为11.2%、AUC达0.95,优于多个先进检测方法。

原文摘要 · Abstract (English)

Automatic Speaker Verification (ASV) systems can be used for voice-enabled applications for identity verification. However, recent studies have exposed these systems' vulnerabilities to both over-the-line (OTL) and over-the-air (OTA) adversarial attacks. Although various detection methods have been proposed to counter these threats, they have not been thoroughly tested due to the lack of a comprehensive data set. To address this gap, we developed the AdvSV 2.0 dataset, which contains 628k samples with a total duration of 800 hours. This dataset incorporates classical adversarial attack algorithms, ASV systems, and encompasses both OTL and OTA scenarios. Furthermore, we introduce a novel adversarial attack method based on a Neural Replay Simulator (NRS), which enhances the potency of adversarial OTA attacks, thereby presenting a greater threat to ASV systems. To defend against these attacks, we propose CODA-OCC, a contrastive learning approach within the one-class classification framework. Experimental results show that CODA-OCC achieves an EER of 11.2% and an AUC of 0.95 on the AdvSV 2.0 dataset, outperforming several state-of-the-art detection methods.

语音安全对抗攻击数据集防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。