FoolHD: Fooling speaker identification by Highly imperceptible adversarial Disturbances

Speaker identification models are vulnerable to carefully designed\nadversarial perturbations of their input signals that induce misclassification.\nIn this work, we propose a white-box steganography-inspired adversarial attack\nthat generates imperceptible adversarial perturbations against a speaker\nidentification model. Our approach, FoolHD, uses a Gated Convolutional\nAutoencoder that operates in the DCT domain and is trained with a\nmulti-objective loss function, in order to generate and conceal the adversarial\nperturbation within the original audio files. In addition to hindering speaker\nidentification performance, this multi-objective loss accounts for human\nperception through a frame-wise cosine similarity between MFCC feature vectors\nextracted from the original and adversarial audio files. We validate the\neffectiveness of FoolHD with a 250-speaker identification x-vector network,\ntrained using VoxCeleb, in terms of accuracy, success rate, and\nimperceptibility. Our results show that FoolHD generates highly imperceptible\nadversarial audio files (average PESQ scores above 4.30), while achieving a\nsuccess rate of 99.6% and 99.2% in misleading the speaker identification model,\nfor untargeted and targeted settings, respectively.\n

Paper

References (27)

Scroll for more · 15 remaining

Similar papers

© 2026 NYSGPT2525 LLC