arXiv:2512.09654cs.LG2025-12被引 2

通过集合推理攻击,检测音频生成模型是否训练过某艺术家作品集。

Membership and Dataset Inference Attacks on Large Audio Generative Models

  • 利用多样本成员资格证据聚合,提升版权验证效果
  • 单个音频样本难判断,但作品集可被有效识别
  • 适合版权方评估模型训练数据来源

基于扩散和自回归架构的生成式音频模型在质量和表现力上迅速进步,但也引发版权担忧,因其常在大量艺术与商业作品上训练。核心问题是能否可靠验证某艺术家作品是否被纳入训练数据,从而为版权持有者提供保护手段。本文研究开源生成音频模型上的成员资格推理攻击(MIA),尝试判断特定音频样本是否属于训练集。实证结果表明,单样本成员资格信号在大规模多样数据集上较弱,效果有限。然而,艺术家通常掌握的是作品集合而非孤立样本。受文本与视觉领域启发,本文聚焦于数据集推理(DI),通过聚合多个样本的成员资格证据。结果显示,DI在音频领域有效,提供了更实用的评估方式,判断某艺术家作品是否参与了模型训练。该方法为大型音频生成模型时代的版权保护与数据透明性提供了新方向。

原文摘要 · Abstract (English)

Generative audio models, based on diffusion and autoregressive architectures, have advanced rapidly in both quality and expressiveness. This progress, however, raises pressing copyright concerns, as such models are often trained on vast corpora of artistic and commercial works. A central question is whether one can reliably verify if an artist's material was included in training, thereby providing a means for copyright holders to protect their content. In this work, we investigate the feasibility of such verification through membership inference attacks (MIA) on open-source generative audio models, which attempt to determine whether a specific audio sample was part of the training set. Our empirical results show that membership inference alone is of limited effectiveness at scale, as the per-sample membership signal is weak for models trained on large and diverse datasets. However, artists and media owners typically hold collections of works rather than isolated samples. Building on prior work in text and vision domains, in this work we focus on dataset inference (DI), which aggregates diverse membership evidence across multiple samples. We find that DI is successful in the audio domain, offering a more practical mechanism for assessing whether an artist's works contributed to model training. Our results suggest DI as a promising direction for copyright protection and dataset accountability in the era of large audio generative models.

音频生成版权保护数据推理会员攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。