TL;DR
Post-hoc explanation methods for audio deepfake detection are fragile, allowing adversaries to manipulate model attributions without changing predictions. A psychoacoustic framework was developed to optimize inaudible perturbations that distort explanation heatmaps while maintaining the predicted labels.
✦ Why It Matters
Engineers should be aware of the fragility in audio model explanations to enhance robustness against adversarial manipulations.
Key Takeaways
How It Works
The psychoacoustic framework optimizes inaudible perturbations, allowing adversaries to manipulate model attributions without affecting the final predictions. This decoupling is achieved through careful adjustments that maintain perceptual audio quality while altering the explanation heatmaps.
Related