arXiv:2603.20301cs.SDcs.AI2026-03中稿 · publication at Int…

从属性角度重新评估语音隐私,发现匿名化后仍存身份泄露风险

Voice Privacy from an Attribute-based Perspective

  • 用说话人属性对比替代信号比对,更真实评估隐私保护效果
  • 单句攻击下仍可识别属性,错误率显示隐私仍不充分
  • 提醒研究者关注属性泄露威胁,改进防护机制

现有语音隐私方法通过修改语音来切断与真实身份的关联,当前基准多基于信号间比较。本文提出属性视角,以说话人属性集间的比较来衡量隐私保护。首先分析真实属性、原始语音中推断的属性以及经标准匿名化处理后语音中推断的属性的说话人独特性;其次,在每名说话人仅有一条语句的攻击场景下计算攻击错误率。结果表明,尽管属性推断存在误差,但推断出的属性仍构成显著风险。研究强调未来语音隐私研究需同时考虑属性相关威胁与防护机制。

原文摘要 · Abstract (English)

Voice privacy approaches that preserve the anonymity of speakers modify speech in an attempt to break the link with the true identity of the speaker. Current benchmarks measure speaker protection based on signal-to-signal comparisons. In this paper, we introduce an attribute-based perspective, where we measure privacy protection in terms of comparisons between sets of speaker attributes. First, we analyze privacy impact by calculating speaker uniqueness for ground truth attributes, attributes inferred on the original speech, and attributes inferred on speech protected with standard anonymization. Next, we examine a threat scenario involving only a single utterance per speaker and calculate attack error rates. Overall, we observe that inferred attributes still present a risk despite attribute inference errors. Our research points to the importance of considering both attribute-related threats and protection mechanisms in future voice privacy research.

语音隐私属性推断匿名化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。