arXiv Machine Learning

Privacy-Preserving Deep Joint Source-Channel Coding with In-Loop Concept Erasure

arXiv Machine Learning
Sep 3

Hearing the Whispers: Black-Box Membership Inference Attacks on Finetuned TTS Models

The paper introduces a black-box membership inference attack framework tailored for fine-tuned text-to-speech models, addressing challenges in query generation and representation engineering. It evaluates five query types, finding recitation queries most effective, and uses multi-level speech embeddings with temporal alignment for fine-grained comparison. Experiments on CosyVoice2, F5-TTS, and XTTS-v2 trained on VCTK and British Dialect datasets show high privacy leakage, with speaker-level AUC above 0.80 and record-level AUC between 0.80 and 0.90.

By Kunlin Cai, Kaiyuan Zhang, Zihang Xiang, Jinghuai Zhang, Abeer Alwan, Fnu Suya, Yuan Tian
arXiv AI
Sep 4

VoxPrivacy: A Benchmark for Evaluating Interactional Privacy of Speech Language Models

The paper introduces VoxPrivacy, a benchmark for assessing interactional privacy in Speech Language Models (SLMs). It evaluates models on a 32‑hour bilingual dataset across three difficulty tiers, revealing that most open‑source SLMs perform near random on conditional privacy decisions and even strong closed‑source systems struggle with proactive privacy inference. The authors also validate these findings on a real‑speech subset and show that fine‑tuning on a 4,000‑hour training set can improve privacy‑preserving capabilities while maintaining robustness.

By Yuxiang Wang, Hongyu Liu, Dekun Chen, Xueyao Zhang, Zhizheng Wu
arXiv Computation and Language
Sep 11

Component-Aware Differential Privacy for Federated Multilingual Speech-LLMs

The paper introduces a per-layer differential privacy (DP) clipping strategy for federated multilingual speech large language models (speech‑LLMs). It demonstrates that standard single‑pool per‑layer DP methods fail due to a cross‑component budget collapse caused by large norm differences between acoustic encoders and language decoders. The authors propose an α‑split two‑pool allocation that normalises encoder and decoder parameters separately, preserving the overall DP guarantee while restoring word error rate performance and providing tighter noise protection for the encoder.

By Jordi Luque, Fernando L\'opez, Aleix Sant
arXiv Machine Learning
Sep 25

Diffusion-aided Task-oriented Semantic Communications with Model Inversion Attack

The paper introduces DiffSem, a diffusion-based approach for task‑oriented semantic communications that splits the diffusion process between transmitter‑side self‑noising and receiver‑side reverse denoising. It addresses privacy concerns by reducing model‑inversion attacks while preserving task accuracy, as demonstrated on MNIST, CIFAR‑10, and CelebA datasets. The method achieves higher task performance without enlarging transmitted feature size or increasing semantic leakage.

By Xuesong Wang, Mo Li, Xingyan Shi, Zhaoqian Liu, Shenghao Yang
arXiv Machine Learning
1d ago

On the Relationship between Model Quantization and Model Inversion Attacks

The paper investigates how reducing numerical precision through model quantization impacts the vulnerability of neural networks to model inversion attacks. It provides theoretical bounds on mutual information changes and identifies data-dependent effects, especially at 4‑bit precision. Based on these findings, the authors propose a privacy‑aware post‑training quantization strategy that allocates bits adaptively, calibrates activation ranges, and jointly optimizes weight and activation scaling to improve inversion resistance while preserving model utility.

By Rongke Liu, Youwen Zhu
arXiv AI
Aug 19

The Model's Tell: Measuring Context-Leakage Attack Signals with Behavior Gauges

The paper introduces LeakGauge, a method that appends a suffix to a model’s input to gauge the risk of context leakage before decoding. By mapping prefill token probabilities to an attack‑risk score, LeakGauge achieves high AUROC (0.944–0.996) across 11 large language models, including GLM‑5.2 and Kimi‑K3, and remains robust to language changes and different attack styles. The approach also demonstrates sensitivity to internal leakage directions and can be implemented with fewer than 0.5K additional parameters and minimal latency.

By Maosen Zhang, Jianshuo Dong, Boting Lu, Wenyue Li, Xiaoping Zhang, Tianwei Zhang, Jie Zhang, Han Qiu