arXiv:2601.03783cs.CL2026-01ACL被引 3

测试音频大模型是否泄露语音隐私,发现92.89%准确率可识别性别等信息。

HearSay Benchmark: Do Audio LLMs Leak What They Hear?

  • 构建2.2万条真实音频的隐私泄露测试集HearSay
  • 92.89%准确率可从语音中提取性别等隐私属性
  • 推理过程会加剧隐私风险,现有防护几乎无效

尽管音频大语言模型(ALLMs)在理解和生成方面取得显著进展,但其潜在隐私风险尚未被充分探索。本文首次研究了所有音量模型是否会仅通过声纹无意泄露用户隐私,并提出名为HearSay的综合性基准,涵盖超过22,000条真实世界音频片段。为确保数据质量,基准通过自动化分析与人工验证的严格流程构建,所有隐私标签均基于事实记录。在HearSay上的大量实验揭示三个关键发现:(1)显著隐私泄露:所有音量模型能从声纹中提取私密属性,对性别的识别准确率达92.89%,并可有效推断社会属性;(2)安全机制不足:现有防护严重失效,多数模型对隐私侵犯请求几乎不拒绝,生理特征相关请求的拒绝不达零;(3)推理放大风险:具备链式思维(CoT)能力的模型因挖掘更深层声学关联而加剧隐私暴露。这些发现揭示了所有音量模型中的关键漏洞,凸显了针对性隐私对齐的紧迫性。代码与数据集已公开于https://github.com/JinWang79/HearSay_Benchmark。

原文摘要 · Abstract (English)

While Audio Large Language Models (ALLMs) have achieved remarkable progress in understanding and generation, their potential privacy implications remain largely unexplored. This paper takes the first step to investigate whether ALLMs inadvertently leak user privacy solely through acoustic voiceprints and introduces $\textit{HearSay}$, a comprehensive benchmark constructed from over 22,000 real-world audio clips. To ensure data quality, the benchmark is meticulously curated through a rigorous pipeline involving automated profiling and human verification, guaranteeing that all privacy labels are grounded in factual records. Extensive experiments on $\textit{HearSay}$ yield three critical findings: $\textbf{Significant Privacy Leakage}$: ALLMs inherently extract private attributes from voiceprints, reaching 92.89% accuracy on gender and effectively profiling social attributes. $\textbf{Insufficient Safety Mechanisms}$: Alarmingly, existing safeguards are severely inadequate; most models fail to refuse privacy-intruding requests, exhibiting near-zero refusal rates for physiological traits. $\textbf{Reasoning Amplifies Risk}$: Chain-of-Thought (CoT) reasoning exacerbates privacy risks in capable models by uncovering deeper acoustic correlations. These findings expose critical vulnerabilities in ALLMs, underscoring the urgent need for targeted privacy alignment. The codes and dataset are available at https://github.com/JinWang79/HearSay_Benchmark

音频大模型隐私泄露声纹分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。