상세 보기
Inference-Time Noise Addition for Improving Adversarial Robustness of Audio Deepfake Detection System
- Kim, Inho;
- Doan, Thien-Phuc;
- Hong, Sanghyun;
- Jung, Souhwan
WEB OF SCIENCE
0SCOPUS
0초록
As artificial intelligence technology advances, the generalization performance of audio deepfake detection systems has improved rapidly and significantly. However, these systems still face substantial challenges when confronted with adversarial attacks. To address this issue, many studies have proposed defense methods against such attacks. Nevertheless, only a limited number of studies have focused on defenses in the context of audio deepfake detection. With the development of deep learning, deepfake detection methods are increasingly designed and deployed based on deep learning models. As a result, deepfake detection systems can be applied across various fields and are not restricted to specific data types or domains. Such approaches are referred to as 'domain-independent' defense methods and can be applied to a wide range of tasks, including adversarial training. However, they have limitations, such as requiring significant computing resources or potentially degrading original performance. In this paper, we propose Inference-Time Noise Addition (ITNA), an effective and efficient adversarial attack defense method that minimizes the original performance degradation. ITNA adds Gaussian noise once to the input audio sample during the inference phase. It is highly resource efficient, as it does not require additional training or separate AI components. Furthermore, ITNA minimizes performance degradation as much as possible and provides scalability that can be used with other defense methods. We provide a theoretical explanation of the effectiveness of ITNA and validate it through experimental results. Our experiments were conducted on the ASVspoof2021 DF evaluation (official deepfake audio dataset from the ASVspoof community), In-The-Wild (collected in real environments) and DSD-Corpus datasets (includes various synthesizer samples). And experiments results demonstrate the effectiveness of ITNA, reducing the average misclassification rate and the attack success rate of detection systems by 4.48% and 31.90%, respectively. We also demonstrate the effectiveness of ITNA through comparative experiments with alternative noise type and existing noise-based defense method.
키워드
- 제목
- Inference-Time Noise Addition for Improving Adversarial Robustness of Audio Deepfake Detection System
- 저자
- Kim, Inho; Doan, Thien-Phuc; Hong, Sanghyun; Jung, Souhwan
- 발행일
- 2025-11
- 유형
- Article
- 저널명
- IEEE Access
- 권
- 13
- 페이지
- 200669 ~ 200682