提出新方法诊断深度伪造音频检测模型的虚假依赖,发现非语音片段是主要干扰源。
An Intervention-Based Framework for Shortcut Diagnosis in Spoofing Countermeasures

- 基于因果图模型设计可控声学扰动,区分虚假捷径与真实域偏移。
- 在ASVspoof数据集上测试发现,非语音干扰导致性能下降最显著。
- 适合关注模型鲁棒性与可解释性的研究人员使用。
尽管深度伪造音频检测系统在受控基准测试中表现优异,但在真实场景中可靠性常下降。已有研究指出,数据集特有的伪影是造成这一差距的原因之一。然而,系统化识别模型利用哪些声学特性作为捷径的方法仍有限。本文提出一种基于干预的诊断框架,基于有向图模型,形式化区分由混杂因素驱动的捷径依赖与合法的域偏移。通过针对非语音结构、频谱内容和信号能量的受控声学扰动,并结合语料级分布分析实现该框架。在XLS-R-300M与RawGAT-ST模型上对ASVspoof挑战数据集进行评估,量化了模型对不同干预类型的敏感性。结果表明,非语音类干预引发最大性能波动,证实非语音区间是主要捷径来源。
原文摘要 · Abstract (English)
While deepfake audio detection systems achieve high performance in controlled benchmarks, their reliability often diminishes in the wild. Prior work shows that dataset-specific artifacts contribute to this gap. Yet, systematic tools to identify which acoustic properties a model exploits as shortcuts remain limited. We propose an intervention-based diagnostic framework, grounded in a directed graphical model, that formally distinguishes confound-driven shortcut dependencies from legitimate domain shift. We operationalise this through controlled acoustic perturbations targeting non-speech structure, spectral content, and signal energy, complemented by corpus-level distributional analysis. Evaluating XLS-R-300M with RawGAT-ST across ASVspoof challenges datasets, we quantify model sensitivity to specific intervention types. Results reveal that non-speech interventions produce the largest performance shifts, confirming non-speech intervals as a dominant shortcut.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。