SiFDetectCracker: An Adversarial Attack Against Fake Voice Detection Based on Speaker-Irrelative Features
Xuan Hai, Xin Liu, Yuan Tan, Qingguo Zhou
Abstract
Voice is a vital medium for transmitting information. The advancement of speech synthesis technology has resulted in high-quality synthesized voices indistinguishable from human ears. These fake voices have been widely used in natural Deepfake production and other malicious activities, raising serious concerns regarding security and privacy. To deal with this situation, there have been many studies working on detecting fake voices and reporting excellent performance. However, is the story really over? In this paper, we propose SiFDetectCracker, a black-box adversarial attack framework based on Speaker-Irrelative Features (SiFs) against fake voice detection. We select background noise and mute parts before and after the speaker's voice as the primary attack features. By modifying these features in synthesized speech, the fake speech detector will make a misjudgment. Experiments show that SiFDetectCracker achieved a success rate of more than 80% in bypassing existing state-of-the-art fake voice detection systems. We also conducted several experiments to evaluate our attack approach's transferability and activation factor.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 66f0af7f-a416-4011-abc2-5e2831e69a94Cited by top-tier papers2
- SiFMimicEvader: Evading Fake Voice Detection with Adversarial Neural Mimicry AttacksXuan Hai, Xin Liu, Zihao Zhang, Ziyao Yu et al.ACM MM 2025
- What's the Real: A Novel Design Philosophy for Robust AI-Synthesized Voice DetectionXuan Hai, Xin Liu, Yuan Tan, Gang Liu et al.ACM MM 2024
Related papers
- PhoneyTalker: An Out-of-the-Box Toolkit for Adversarial Example Attack on Speaker RecognitionMeng Chen, Li Lu, Zhongjie Ba, Kui RenINFOCOM 2022 · 13 citations
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du et al.S&P 2021 · 239 citations
- Improving Generalization for AI-Synthesized Voice DetectionHainan Ren, Li Lin, Chun-Hao Liu, Xin Wang et al.AAAI 2025 · 13 citations
- What You Read Isn't What You Hear: Linguistic Sensitivity in Deepfake Speech DetectionBinh Nguyen, Shuju Shi, Ryan Ofman, Thai LeEMNLP 2025 · 1 citation
- AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake DetectionXiangtao Meng, Li Wang, Shanqing Guo, Lei Ju et al.S&P 2024 · 17 citations
