arXiv:2511.19974cs.SD2025-11

用通用对抗扰动实现音频伪造检测的持续学习,无需存储历史数据。

Continual Audio Deepfake Detection via Universal Adversarial Perturbation

  • 引入通用对抗扰动,让模型记住过往伪造特征。
  • 在不访问历史数据下仍能有效识别新型语音伪造攻击。
  • 适合需要长期更新检测能力且资源受限的系统使用。

语音合成与语音转换技术的快速发展引发了多媒体鉴伪领域的安全担忧。尽管现有检测模型表现优异,但难以应对不断演化的深度伪造攻击。此外,持续使用历史数据微调模型会带来巨大的计算与存储开销。为此,我们提出一种新框架,将通用对抗扰动(UAP)引入音频深度伪造检测,使模型在不直接访问过去数据的情况下,仍能保留对历史伪造分布的记忆。该方法可无缝集成到预训练自监督音频模型的微调过程中。大量实验验证了其有效性,表明该方案在音频伪造检测的持续学习中具有高效潜力。

原文摘要 · Abstract (English)

The rapid advancement of speech synthesis and voice conversion technologies has raised significant security concerns in multimedia forensics. Although current detection models demonstrate impressive performance, they struggle to maintain effectiveness against constantly evolving deepfake attacks. Additionally, continually fine-tuning these models using historical training data incurs substantial computational and storage costs. To address these limitations, we propose a novel framework that incorporates Universal Adversarial Perturbation (UAP) into audio deepfake detection, enabling models to retain knowledge of historical spoofing distribution without direct access to past data. Our method integrates UAP seamlessly with pre-trained self-supervised audio models during fine-tuning. Extensive experiments validate the effectiveness of our approach, showcasing its potential as an efficient solution for continual learning in audio deepfake detection.

音频伪造持续学习对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。