arXiv:2509.19906eess.AS2025-09被引 1

用多个随机正交密钥增强语音隐私保护,提升抗攻击能力。

Voice Privacy Preservation with Multiple Random Orthogonal Secret Keys: Attack Resistance Analysis

  • 采用多个随机正交矩阵作为密钥,提升加密强度。
  • 在更强攻击场景下仍能有效隐藏说话人身份。
  • 适用于更广泛深度学习模型,扩展性更强。

近年来,将语音数据传输至云端执行的深度学习模型的机会增多,引发对语音隐私的担忧,包括说话人信息和语义内容。为保护语音隐私,已有基于随机正交矩阵密钥加密的方法,可在云端推理的同时隐藏语音内容与说话人身份。然而,该方法抗攻击能力有限,且适用模型范围受限。本文提出一种新方法,通过使用多个随机正交矩阵作为密钥,增强传统方法的抗攻击能力,并引入新策略放宽模型限制,使方法可应用于更多类型的深度学习模型。此外,我们基于语音隐私挑战中的攻击场景,设计了扩展攻击方案进行评估。实验表明,所提方法在更强大的攻击场景下仍能有效保护说话人隐私,性能稳定。

原文摘要 · Abstract (English)

Recently, opportunities to transmit speech data to deep learning models executed in the cloud have increased. This has led to growing concerns about speech privacy, including both speaker-specific information and the linguistic content of utterances. As an approach to preserving speech privacy, a speech privacy-preserving method based on encryption using a secret key with a random orthogonal matrix has been proposed. This method enables cloud-based model inference while concealing both the speech content and the speaker identity. However, the method has limited attack resistance and is constrained in terms of the deep learning models to which the encryption can be applied. In this work, we propose a method that enhances the attack resistance of the conventional speech privacy-preserving technique by employing multiple random orthogonal matrices as secret keys. We also introduce approaches to relax the model constraints, enabling the application of our method to a broader range of deep learning models. Furthermore, we investigate the robustness of the proposed method against attacks using extended attack scenarios based on the scenarios employed in the Voice Privacy Challenge. Our experimental results confirmed that the proposed method maintains privacy protection performance for speaker concealment, even under more powerful attack scenarios not considered in prior work.

语音隐私加密方法抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。