跳到正文
arXiv:cs.LG· Ali Alavi, Donald S. Williamson·· 3 小时前

你的语音质量指标有多容易被攻破?一套修正协议、一个基准及打补丁的收益

How Hackable Is Your Speech Quality Metric? A Corrected Protocol, a Benchmark, and What Patching Buys

AI 导读

针对语音质量预测器作为奖励时缺乏统一可攻破性度量的问题,研究者提出修正协议:以未扰动的往返输出而非原始输入作为参照,测得某防御的可攻破性从0.31降至0.08;并用多个随机种子训练的五个攻击者(成功率0.00至0.38)取最坏情况。

正文

View PDF HTML (experimental)

Abstract:Speech quality predictors are increasingly used as rewards, yet no agreed measure of their hackability exists. The usual measurement has two flaws. First, the perturbation reaches the predictor through a processing chain -- here a neural codec -- that shifts the score on its own, which scoring against the raw input charges to the attack. Referencing the unperturbed round trip instead changes measured hackability by up to a factor of four (0.31 to 0.08 for one defence). Second, one trained attacker is a sample, not a measurement: five attackers differing only in random seed reach success rates from 0.00 to 0.38 against one fixed predictor, so a defence claim needs the worst case over several. Under this protocol, four published predictors differ widely: NISQA is hacked on 90% of utterances, SSL-MOS on 21%, DNSMOS on 14% and UTMOS on 6%. We then audit a closed attack-detect-patch loop. It hardens the predictor only in its own attack space, by less than the spread between attackers; a random-perturbation baseline matches it; and it costs up to 0.30 system SRCC out of domain. Enhancers post-trained against patched predictors hack them far less (PESQ -0.03 versus -0.23). Code, preregistration and run outputs are released.
Subjects: Machine Learning (cs.LG)
Cite as: arXiv:2610.10899 [cs.LG]
  (or arXiv:2610.10899v1 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2610.10899

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Ali Alavi [view email]
[v1] Wed, 7 Oct 2026 20:55:58 UTC (113 KB)

来源:arXiv:cs.LG · arxiv.org