arXiv:2510.13357cs.CLcs.AI2025-10

联邦语音模型可能泄露性别、年龄等敏感属性,攻击者仅凭权重差即可实现。

Personal Attribute Leakage in Federated Speech Models

  • 利用权重差异开展无原始语音的被动攻击,无需访问用户原始数据。
  • 在三种模型上成功推断出性别、年龄、口音、情绪和肌萎缩症等属性。
  • 预训练数据中缺失或稀少的属性更易被泄露,适合关注隐私安全的研究者。

联邦学习是一种常见的机器学习隐私保护训练方法。本文分析了在联邦设置下自动语音识别(ASR)模型对属性推断攻击的脆弱性。我们在 Wav2Vec2、HuBERT 和 Whisper 三个 ASR 模型上,针对被动威胁模型测试了一种非参数白盒攻击方法。该攻击仅依赖于权重差异,无需访问目标说话人的原始语音。实验表明,攻击可成功推断出性别、年龄、口音、情绪及肌萎缩症等敏感的表征属性。研究发现,预训练数据中未充分覆盖或缺失的属性更容易受到此类攻击。特别地,口音信息在所有模型中均可可靠推断。研究揭示了联邦 ASR 模型中此前未被记录的隐私漏洞,并为提升安全性提供了新见解。

原文摘要 · Abstract (English)

Federated learning is a common method for privacy-preserving training of machine learning models. In this paper, we analyze the vulnerability of ASR models to attribute inference attacks in the federated setting. We test a non-parametric white-box attack method under a passive threat model on three ASR models: Wav2Vec2, HuBERT, and Whisper. The attack operates solely on weight differentials without access to raw speech from target speakers. We demonstrate attack feasibility on sensitive demographic and clinical attributes: gender, age, accent, emotion, and dysarthria. Our findings indicate that attributes that are underrepresented or absent in the pre-training data are more vulnerable to such inference attacks. In particular, information about accents can be reliably inferred from all models. Our findings expose previously undocumented vulnerabilities in federated ASR models and offer insights towards improved security.

联邦学习语音隐私属性泄露安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。