arXiv:2510.09504eess.AS2025-10

研究语音对抗扰动能否被消除,发现知情程度决定恢复效果。

A Study of the Removability of Speaker-Adversarial Perturbations

  • 分三种场景测试扰动可移除性:不知情、半知情、完全知情。
  • 完全知情时扰动几乎被清除,原语音可恢复;其他情况无法完全消除。
  • 适用于语音隐私保护与对抗防御研究者。

近期对抗攻击在误导说话人识别模型方面成效显著,导致身份误判。而现有防御方法仅减轻扰动对说话人特征提取的影响,并未尝试彻底移除扰动以还原原始语音。本文系统研究了说话人对抗扰动的可移除性,考虑了三种不同知情程度的场景:完全不知情、半知情和完全知情,并分别评估基于优化与前馈生成的扰动方法。在LibriSpeech数据集上的实验表明:1)在不知情场景下,扰动无法消除,尽管其影响被削弱;2)在半知情场景下,扰动无法完全去除,但前馈模型生成的扰动可显著减少;3)在完全知情场景下,扰动几乎被完全消除,原语音得以恢复。音频样本见 https://voiceprivacy.github.io/Perturbation-Generation-Removal/。

原文摘要 · Abstract (English)

Recent advancements in adversarial attacks have demonstrated their effectiveness in misleading speaker recognition models, making wrong predictions about speaker identities. On the other hand, defense techniques against speaker-adversarial attacks focus on reducing the effects of speaker-adversarial perturbations on speaker attribute extraction. These techniques do not seek to fully remove the perturbations and restore the original speech. To this end, this paper studies the removability of speaker-adversarial perturbations. Specifically, the investigation is conducted assuming various degrees of awareness of the perturbation generator across three scenarios: ignorant, semi-informed, and well-informed. Besides, we consider both the optimization-based and feedforward perturbation generation methods. Experiments conducted on the LibriSpeech dataset demonstrated that: 1) in the ignorant scenario, speaker-adversarial perturbations cannot be eliminated, although their impact on speaker attribute extraction is reduced, 2) in the semi-informed scenario, the speaker-adversarial perturbations cannot be fully removed, while those generated by the feedforward model can be considerably reduced, and 3) in the well-informed scenario, speaker-adversarial perturbations are nearly eliminated, allowing for the restoration of the original speech. Audio samples can be found in https://voiceprivacy.github.io/Perturbation-Generation-Removal/.

语音安全对抗攻击扰动移除

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。