SiFDetectCracker: An Adversarial Attack Against Fake Voice Detection Based on Speaker-Irrelative Features

被引:1
|
作者
Hai, Xuan [1 ]
Liu, Xin [1 ]
Tan, Yuan [1 ]
Zhou, Qingguo [1 ]
机构
[1] Lanzhou Univ, Lanzhou, Peoples R China
关键词
Adversarial Attack; Deepfake; AI-Synthesized Speech; Voice Detection;
D O I
10.1145/3581783.3613841
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Voice is a vital medium for transmitting information. The advancement of speech synthesis technology has resulted in high-quality synthesized voices indistinguishable from human ears. These fake voices have been widely used in natural Deepfake production and other malicious activities, raising serious concerns regarding security and privacy. To deal with this situation, there have been many studies working on detecting fake voices and reporting excellent performance. However, is the story really over? In this paper, we propose SiFDetectCracker, a black-box adversarial attack framework based on Speaker-Irrelative Features (SiFs) against fake voice detection. We select background noise and mute parts before and after the speaker's voice as the primary attack features. By modifying these features in synthesized speech, the fake speech detector will make a misjudgment. Experiments show that SiFDetectCracker achieved a success rate of more than 80% in bypassing existing state-of-the-art fake voice detection systems. We also conducted several experiments to evaluate our attack approach's transferability and activation factor.
引用
收藏
页码:8552 / 8560
页数:9
相关论文
共 50 条
  • [1] Hidden-in-Wave: A Novel Idea to Camouflage AI-Synthesized Voices Based on Speaker-Irrelative Features
    Liu, Xin
    Tan, Yuan
    Hai, Xuan
    Yu, Qingchen
    Zhou, Qingguo
    2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 786 - 794
  • [2] UNIVERSAL ADVERSARIAL ATTACK AGAINST SPEAKER RECOGNITION MODELS
    Hanina, Shoham
    Zolfi, Alon
    Elovici, Yuval
    Shabtai, Asaf
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 4860 - 4864
  • [3] Replay Attack Detection Based on Voice and Non-voice Sections for Speaker Verification
    Mills, Ananda Garin
    Kaewcharuay, Patthranit
    Sathirasattayanon, Pannathorn
    Duangpummet, Suradej
    Galajit, Kasorn
    Karnjana, Jessada
    Aimmanee, Pakinee
    PROCEEDINGS OF 2022 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2022, : 221 - 226
  • [4] Adversarial Attack with Adaptive Gradient Variance for Deep Fake Fingerprint Detection
    Yuan, Chengsheng
    Cui, Baojie
    2022 IEEE 24TH INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP), 2022,
  • [5] SALSA: Salience-Based Switching Attack for Adversarial Perturbations in Fake News Detection Models
    Raj, Chahat
    Mukherjee, Anjishnu
    Purohit, Hemant
    Anastasopoulos, Antonios
    Zhu, Ziwei
    ADVANCES IN INFORMATION RETRIEVAL, ECIR 2024, PT V, 2024, 14612 : 35 - 49
  • [6] VOICE QUALITY FEATURES FOR REPLAY ATTACK DETECTION
    Woubie, Abraham
    Backstrom, Tom
    2022 30TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO 2022), 2022, : 384 - 388
  • [7] Symmetric Saliency-Based Adversarial Attack to Speaker Identification
    Yao, Jiadi
    Chen, Xing
    Zhang, Xiao-Lei
    Zhang, Wei-Qiang
    Yang, Kunde
    IEEE SIGNAL PROCESSING LETTERS, 2023, 30 : 1 - 5
  • [8] The Adversarial UFP/UFN Attack: A New Threat to ML-based Fake News Detection Systems?
    Brown, Brandon
    Richardson, Alexicia
    Smith, Marcellus
    Dozier, Gerry
    King, Michael C.
    2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1523 - 1527
  • [9] Adversarial Attack against LSTM-based DDoS Intrusion Detection System
    Huang, Weiqing
    Peng, Xiao
    Shi, Zhixin
    Ma, Yuru
    2020 IEEE 32ND INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI), 2020, : 686 - 693
  • [10] EnsembleDet: ensembling against adversarial attack on deepfake detection
    Dutta, Himanshu
    Pandey, Aditya
    Bilgaiyan, Saurabh
    JOURNAL OF ELECTRONIC IMAGING, 2021, 30 (06)