Diffusion-based Adversarial Purification For Speaker Verification
2023 Β· Yibo Bai, Xiao-Lei Zhang, Xuelong Li
Abstract
Recently, automatic speaker verification (ASV) based on deep learning is easily contaminated by adversarial attacks, which is a new type of attack that injects imperceptible perturbations to audio signals so as to make ASV produce wrong decisions. This poses a significant threat to the security and reliability of ASV systems. To address this issue, we propose a Diffusion-Based Adversarial Purification (DAP) method that enhances the robustness of ASV systems against such adversarial attacks. Our method leverages a conditional denoising diffusion probabilistic model to effectively purify the adversarial examples and mitigate the impact of perturbations. DAP first introduces controlled noise into adversarial examples, and then performs a reverse denoising process to reconstruct clean audio. Experimental results demonstrate the efficacy of the proposed DAP in enhancing the security of ASV and meanwhile minimizing the distortion of the purified audio signals.
Authors
(none)
Tags
Stats
Related papers
- Transforming Acoustic Characteristics To Deceive Playback Spoofing Countermeasures Of Speaker Verification Systems (2018)6.34
- A Joint Noise Disentanglement And Adversarial Training Framework For Robust Speaker Verification (2024)6.34
- Diff-sv: A Unified Hierarchical Framework For Noise-robust Speaker Verification Using Score-based Diffusion Probabilistic Models (2023)6.34
- Toward Improving Synthetic Audio Spoofing Detection Robustness Via Meta-learning And Disentangled Training With Adversarial Examples (2024)6.77
- Adversarial Sample Detection For Speaker Verification By Neural Vocoders (2021)0.00
- Diffattack: Diffusion-based Timbre-reserved Adversarial Attack In Speaker Identification (2025)0.00
- Privacy-utility Balanced Voice De-identification Using Adversarial Examples (2022)0.00
- Detecting And Defending Against Adversarial Attacks On Automatic Speech Recognition Via Diffusion Models (2024)2.26