让语音大模型学会只听主讲人、忽略旁人对话,保护隐私。
Protecting Bystander Privacy via Selective Hearing in Audio LLMs
- 设计新评测集SH-Bench,测试模型能否专注主讲人并屏蔽旁人语音
- 发现现有模型虽懂语音却常泄露旁人信息,隐私保护严重不足
- 提出训练方法BPFT,提升隐私保护能力且不损害主讲理解
语音大语言模型在现实应用中常无意捕获附近旁人的对话,带来隐私风险,而现有基准与防御机制未予考虑。本文提出SH-Bench,首个评估「选择性倾听」能力的基准,包含3,968个多说话人音频混合样本及77,000个多项选择题,覆盖真实与合成场景。同时引入新型指标Selective Efficacy(SE),衡量多说话人理解与旁人隐私保护双重能力。对主流开源与专有语音大模型的评估显示,尽管具备强语音理解能力,仍存在显著旁人隐私泄露。为此,本文提出旁人隐私微调(BPFT)训练流程,使模型在不降低主讲人理解的前提下拒绝处理旁人相关问题。实验表明,采用BPFT后,模型在选择性模式下旁人识别准确率绝对提升47%,SE指标比表现最佳的Gemini 2.5 Pro高出16%。SH-Bench与BPFT共同构成首个系统性提升语音大模型旁人隐私保护的框架。
原文摘要 · Abstract (English)
Audio Large language models (LLMs) are increasingly deployed in the real world, where they inevitably capture speech from unintended nearby bystanders, raising privacy risks that existing benchmarks and defences did not consider. We introduce SH-Bench, the first benchmark designed to evaluate selective hearing: a model's ability to attend to an intended main speaker while refusing to process or reveal information about incidental bystander speech. SH-Bench contains 3,968 multi-speaker audio mixtures, including both real-world and synthetic scenarios, paired with 77k multiple-choice questions that probe models under general and selective operating modes. In addition, we propose Selective Efficacy (SE), a novel metric capturing both multi-speaker comprehension and bystander-privacy protection. Our evaluation of state-of-the-art open-source and proprietary LLMs reveals substantial bystander privacy leakage, with strong audio understanding failing to translate into selective protection of bystander privacy. To mitigate this gap, we also present Bystander Privacy Fine-Tuning (BPFT), a novel training pipeline that teaches models to refuse bystander-related queries without degrading main-speaker comprehension. We show that BPFT yields substantial gains, achieving an absolute 47% higher bystander accuracy under selective mode and an absolute 16% higher SE compared to Gemini 2.5 Pro, which is the best audio LLM without BPFT. Together, SH-Bench and BPFT provide the first systematic framework for measuring and improving bystander privacy in audio LLMs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。