arXiv:2605.30366cs.CRcs.SD2026-05被引 1

提出MARS框架,突破语音伪造检测的线性陷阱,提升攻击成功率。

Escaping the Linearity Trap: Manifold Detours for Black-Box Adversarial Attacks on Singing Audio Deepfake Detection

论文配图:Escaping the Linearity Trap: Manifold Detours for Black-Box Adversarial Attacks on Singing Audio Deepfake Detection
图 1 · 摘自论文原文
  • 构建语义与伪影锚点,通过双层优化实现非线性扰动
  • 在跨分布和跨任务攻击中,攻击成功率提升10%~36%
  • 揭示现有攻击失败源于几何局限,适合评估真实场景鲁棒性

近期歌声合成技术发展使得高度逼真的恶意AI翻唱成为可能,因此歌声伪造检测(SVDD)至关重要。基于自监督学习(SSL)的检测器通过微调语音SSL骨干网络捕捉演唱特异性伪造特征,达到当前最佳性能。然而,现有对抗攻击对这类检测器常失效,造成其具备内在鲁棒性的假象。我们揭示这源于双重挑战:一是目标层面,攻击在局部代理模型上优化交叉熵,跨越代理特定边界而非抑制共享伪造证据;二是方法层面,攻击沿代理主导梯度方向进行,该方向与微调后的伪影敏感方向一致,限制了对未见检测器的迁移能力——我们称之为‘线性陷阱’。为准确评估鲁棒性,本文提出专用于SSL-SVDD的转移型黑盒框架MARS(Meta-Adversarial Regression of Semantics)。结构上,MARS转而操纵假设-证据关系,利用预训练SSL空间构造自然语义锚点,微调空间生成伪影锚点。算法上,通过双层优化逃离线性陷阱:内层诱导切向探索,外层引导音频逼近自然语义流形。在CtrSVDD基准测试中,MARS在同分布迁移(提升13%)、跨分布迁移(提升10%)及跨任务评估(提升36%)中均显著提高攻击成功率,凸显构建强健SVDD系统的紧迫性。

原文摘要 · Abstract (English)

Recent Singing Voice Synthesis (SVS) advances enable highly realistic but potentially malicious AI covers, making singing voice deepfake detection (SVDD) crucial. Self-Supervised Learning (SSL)-based detectors achieve state-of-the-art performance by fine-tuning speech SSL backbones to capture singing-specific spoof artifacts. Existing adversarial attacks often fail against SSL-SVDD, creating a false impression of inherent robustness. We reveal this stems from two challenges. First, at the objective level, attacks optimize cross-entropy on local surrogates, crossing surrogate-specific boundaries rather than suppressing shared spoof evidence. Second, at the method level, attacks follow the surrogate's dominant gradient direction. In SSL-SVDD, this aligns with fine-tuned artifact-sensitive directions, limiting transferability to unseen detectors - a geometric failure we term the Linearity Trap. To properly evaluate robustness, we propose MARS (Meta-Adversarial Regression of Semantics), a transfer-based black-box framework tailored to SSL-SVDD. Structurally, MARS shifts to hypothesis-evidence manipulation by constructing a natural semantic anchor from the pre-trained SSL space and an artifact anchor from the fine-tuned space. Algorithmically, MARS escapes the Linearity Trap via bi-level optimization: the inner stage induces tangential exploration, while the outer stage guides the audio toward the natural semantic manifold. Experiments on the CtrSVDD benchmark show MARS improves Attack Success Rate (ASR) in in-distribution transfer (13%), out-of-distribution transfer (10%), and cross-task evaluation (36%), highlighting the urgent need for robust SVDD systems.

语音伪造对抗攻击SSL检测鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。