paper-with-me

홈 › Papers

Spectral Masking and Interpolation Attack (SMIA): A Black-box Adversarial Attack against Voice Authentication and Anti-Spoofing Systems

2025-09-09 · Kamel Kamel, Hridoy Sankar Dutta, Keshav Sood, Sunil Aryal arxiv

Voice Authentication Systems (VAS) use unique vocal characteristics for verification. They are increasingly integrated into high-security sectors such as banking and healthcare. Despite their improvements using deep learning, they face severe vulnerabilities from sophisticated threats like deepfakes and adversarial attacks. The emergence of realistic voice cloning complicates detection, as systems struggle to distinguish authentic from synthetic audio. While anti-spoofing countermeasures (CMs) exist to mitigate these risks, many rely on static detection models that can be bypassed by novel adversarial methods, leaving a critical security gap. To demonstrate this vulnerability, we propose the Spectral Masking and Interpolation Attack (SMIA), a novel method that strategically manipulates inaudible frequency regions of AI-generated audio. By altering the voice in imperceptible zones to the human ear, SMIA creates adversarial samples that sound authentic while deceiving CMs. We conducted a comprehensive evaluation of our attack against state-of-the-art (SOTA) models across multiple tasks, under simulated real-world conditions. SMIA achieved a strong attack success rate (ASR) of at least 82% against combined VAS/CM systems, at least 97.5% against standalone speaker verification systems, and 100% against countermeasures. These findings conclusively demonstrate that current security postures are insufficient against adaptive adversarial attacks. This work highlights the urgent need for a paradigm shift toward next-generation defenses that employ dynamic, context-aware frameworks capable of evolving with the threat landscape.

📄 PDF Abstract BibTeX arXiv:2509.07677

Code (0)

등록된 구현이 없습니다.

Tasks

Speaker VerificationAdversarial Attack

Similar Papers 제목 키워드 기반

Semantic Membership Inference Attack against Large Language Models

2024-06-14 · Hamid Mozaffari, Virendra J. Marathe

Membership Inference Attacks (MIAs) determine whether a specific data point was included in the training set of a target model. In this paper, we introduce the Semantic Membership Inference Attack (SMIA), a novel approac…

Inference AttackMembership Inference Attack

Subject Data Auditing via Source Inference Attack in Cross-Silo Federated Learning

2024-09-28 · Jiaxin Li, Marco Arazzi, Antonino Nocera, Mauro Conti

Source Inference Attack (SIA) in Federated Learning (FL) aims to identify which client used a target data point for local model training. It allows the central server to audit clients' data usage. In cross-silo FL, a cli…

Federated LearningInference AttackMembership Inference Attack

TransMIA: Membership Inference Attacks Using Transfer Shadow Training

2020-11-30 · Seira Hidano, Takao Murakami, Yusuke Kawamoto

Transfer learning has been widely studied and gained increasing popularity to improve the accuracy of machine learning models by transferring some knowledge acquired in different training. However, no prior work has poin…

BIG-bench Machine LearningTransfer Learning

A Curious Case of Remarkable Resilience to Gradient Attacks via Fully Convolutional and Differentiable Front End with a Skip Connection

2024-02-26 · Leonid Boytsov, Ameya Joshi, Filipe Condessa

We tested front-end enhanced neural models where a frozen classifier was prepended by a differentiable and fully convolutional model with a skip connection. By training them using a small learning rate for about one epoc…

Adversarial Robustness

Improving the Transferability of 3D Point Cloud Attack via Spectral-aware Admix and Optimization Designs

2024-12-17 · Shiyu Hu, Daizong Liu, Wei Hu

Deep learning models for point clouds have shown to be vulnerable to adversarial attacks, which have received increasing attention in various safety-critical applications such as autonomous driving, robotics, and surveil…

Autonomous Driving