On the invertibility of a voice privacy system using embedding alignement - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

On the invertibility of a voice privacy system using embedding alignement

Résumé

This paper explores various attack scenarios on a voice anonymization system using embeddings alignment techniques. We use Wasserstein-Procrustes (an algorithm initially designed for unsupervised translation) or Procrustes analysis to match two sets of x-vectors, before and after voice anonymization, to mimic this transformation as a rotation function. We compute the optimal rotation and compare the results of this approximation to the official Voice Privacy Challenge results. We show that a complex system like the baseline of the Voice Privacy Challenge can be approximated by a rotation, estimated using a limited set of x-vectors. This paper studies the space of solutions for voice anonymization within the specific scope of rotations. Rotations being reversible, the proposed method can recover up to 62% of the speaker identities from anonymized embeddings.
Fichier principal
Vignette du fichier
ON_THE_INVERTIBILITY_OF_A_VOICE_PRIVACY_SYSTEM_USING_EMBEDDING_ALIGNMENT.pdf (704.99 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03356021 , version 1 (27-09-2021)
hal-03356021 , version 2 (08-10-2021)

Identifiants

  • HAL Id : hal-03356021 , version 1

Citer

Pierre Champion, Thomas Thebaud, Gaël Le Lan, Anthony Larcher, Denis Jouvet. On the invertibility of a voice privacy system using embedding alignement. ASRU 2021 - IEEE Automatic Speech Recognition and Understanding Workshop, Dec 2021, Cartagena, Colombia. ⟨hal-03356021v1⟩
217 Consultations
185 Téléchargements

Partager

Gmail Facebook X LinkedIn More