arXiv · 2508.09803
Improving the Speaker Anonymization Evaluation's Robustness to Target Speakers with Adversarial Learning
Abstract
The current privacy evaluation for speaker anonymization often overestimates privacy when a same-gender target selection algorithm (TSA) is used, although this TSA leaks the speaker's gender and should hence be more vulnerable. We hypothesize that this occurs because the evaluation does not account for the fact that anonymized speech contains information from both the source and target speakers. To address this, we propose to add a target classifier that measures the influence of target speaker information in the evaluation, which can also be removed with adversarial learning. Experiments demonstrate that this approach is effective for multiple anonymizers, particularly when using a same-gender TSA, leading to a more reliable assessment.
Explore related subjects
Keep this discovery
Carlos Franzreb, Arnab Das, Tim Polzehl, Sebastian Möller. 2025-08-13. Improving the Speaker Anonymization Evaluation's Robustness to Target Speakers with Adversarial Learning. https://arxiv.org/abs/2508.09803
Cite the original work for its findings. Save a collection to share your selection of sources.