arXiv:2509.18413cs.CRcs.LG2025-09被引 3

用隐私攻击检测语音匿名化漏洞,发现传统评估方式严重低估风险

VoxGuard: Evaluating User and Attribute Privacy in Speech via Membership Inference Attacks

  • 基于差分隐私与成员推断,定义用户和属性双维度隐私
  • 真实攻击中低误报率下仍可精准识别说话人和性别/口音
  • 建议改用低误报率场景评估,适合隐私安全研究者参考

语音匿名旨在隐藏说话人身份和属性同时保持可懂度,但现有评估几乎全依赖等错误率(EER),掩盖了攻击者在高精度下仍能成功识别的风险。我们主张隐私应以低误报率(FPR)为评估基准,即使少量成功识别也构成实质泄露。为此,提出VoxGuard框架,基于差分隐私与成员推断,形式化定义用户隐私(防重识别)和属性隐私(保护性别、口音等敏感特征)。在合成与真实数据集上,我们发现:即使在相似EER下,经微调的模型结合最大相似性评分,可在低FPR下实现数量级更强的攻击;对属性而言,简单透明攻击在匿名化后仍能近乎完美恢复性别与口音。结果表明EER严重低估泄露风险,亟需引入低FPR评估范式,并推荐VoxGuard作为隐私泄露评测基准。

原文摘要 · Abstract (English)

Voice anonymization aims to conceal speaker identity and attributes while preserving intelligibility, but current evaluations rely almost exclusively on Equal Error Rate (EER) that obscures whether adversaries can mount high-precision attacks. We argue that privacy should instead be evaluated in the low false-positive rate (FPR) regime, where even a small number of successful identifications constitutes a meaningful breach. To this end, we introduce VoxGuard, a framework grounded in differential privacy and membership inference that formalizes two complementary notions: User Privacy, preventing speaker re-identification, and Attribute Privacy, protecting sensitive traits such as gender and accent. Across synthetic and real datasets, we find that informed adversaries, especially those using fine-tuned models and max-similarity scoring, achieve orders-of-magnitude stronger attacks at low-FPR despite similar EER. For attributes, we show that simple transparent attacks recover gender and accent with near-perfect accuracy even after anonymization. Our results demonstrate that EER substantially underestimates leakage, highlighting the need for low-FPR evaluation, and recommend VoxGuard as a benchmark for evaluating privacy leakage.

语音隐私成员推断差分隐私安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。