Inference-Time Noise Addition for Improving Adversarial Robustness of Audio Deepfake Detection System

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

As artificial intelligence technology advances, the generalization performance of audio deepfake detection systems has improved rapidly and significantly. However, these systems still face substantial challenges when confronted with adversarial attacks. To address this issue, many studies have proposed defense methods against such attacks. Nevertheless, only a limited number of studies have focused on defenses in the context of audio deepfake detection. With the development of deep learning, deepfake detection methods are increasingly designed and deployed based on deep learning models. As a result, deepfake detection systems can be applied across various fields and are not restricted to specific data types or domains. Such approaches are referred to as 'domain-independent' defense methods and can be applied to a wide range of tasks, including adversarial training. However, they have limitations, such as requiring significant computing resources or potentially degrading original performance. In this paper, we propose Inference-Time Noise Addition (ITNA), an effective and efficient adversarial attack defense method that minimizes the original performance degradation. ITNA adds Gaussian noise once to the input audio sample during the inference phase. It is highly resource efficient, as it does not require additional training or separate AI components. Furthermore, ITNA minimizes performance degradation as much as possible and provides scalability that can be used with other defense methods. We provide a theoretical explanation of the effectiveness of ITNA and validate it through experimental results. Our experiments were conducted on the ASVspoof2021 DF evaluation (official deepfake audio dataset from the ASVspoof community), In-The-Wild (collected in real environments) and DSD-Corpus datasets (includes various synthesizer samples). And experiments results demonstrate the effectiveness of ITNA, reducing the average misclassification rate and the attack success rate of detection systems by 4.48% and 31.90%, respectively. We also demonstrate the effectiveness of ITNA through comparative experiments with alternative noise type and existing noise-based defense method.

키워드

DeepfakesGlass boxClosed boxPerturbation methodsData modelsComputational modelingFeature extractionDeep learningRobustnessPredictive modelsAdversarial attack defenseaudio deepfake detectioninference-time noise additionSPEAKER VERIFICATIONATTACKS
제목
Inference-Time Noise Addition for Improving Adversarial Robustness of Audio Deepfake Detection System
저자
Kim, InhoDoan, Thien-PhucHong, SanghyunJung, Souhwan
DOI
10.1109/ACCESS.2025.3635633
발행일
2025-11
유형
Article
저널명
IEEE Access
13
페이지
200669 ~ 200682