{"id":"https://openalex.org/W4416065100","doi":"https://doi.org/10.48550/arxiv.2509.07132","title":"Adversarial Attacks on Audio Deepfake Detection: A Benchmark and Comparative Study","display_name":"Adversarial Attacks on Audio Deepfake Detection: A Benchmark and Comparative Study","publication_year":2025,"publication_date":"2025-09-08","ids":{"openalex":"https://openalex.org/W4416065100","doi":"https://doi.org/10.48550/arxiv.2509.07132"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2509.07132","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.07132","pdf_url":"https://arxiv.org/pdf/2509.07132","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2509.07132","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5012019603","display_name":"Kutub Uddin","orcid":"https://orcid.org/0000-0003-4365-682X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Uddin, Kutub","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032869520","display_name":"Muhammad Umar Farooq","orcid":"https://orcid.org/0000-0002-6610-0923"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Farooq, Muhammad Umar","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101518388","display_name":"Awais Khan","orcid":"https://orcid.org/0009-0009-5919-1538"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Khan, Awais","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5024102795","display_name":"Khalid Mahmood Malik","orcid":"https://orcid.org/0000-0002-7927-3436"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Malik, Khalid Mahmood","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.22179999947547913,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.22179999947547913,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.20010000467300415,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.1981000006198883,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7800999879837036},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.6022999882698059},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.5971999764442444},{"id":"https://openalex.org/keywords/range","display_name":"Range (aeronautics)","score":0.45989999175071716},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.42410001158714294},{"id":"https://openalex.org/keywords/biometrics","display_name":"Biometrics","score":0.4140999913215637}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.789900004863739},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7800999879837036},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.6022999882698059},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.5971999764442444},{"id":"https://openalex.org/C204323151","wikidata":"https://www.wikidata.org/wiki/Q905424","display_name":"Range (aeronautics)","level":2,"score":0.45989999175071716},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.45579999685287476},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.42410001158714294},{"id":"https://openalex.org/C184297639","wikidata":"https://www.wikidata.org/wiki/Q177765","display_name":"Biometrics","level":2,"score":0.4140999913215637},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4068000018596649},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.37119999527931213},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3034000098705292},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2919999957084656},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.28850001096725464},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.27480000257492065},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.2653999924659729},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.262800008058548}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2509.07132","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.07132","pdf_url":"https://arxiv.org/pdf/2509.07132","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2509.07132","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2509.07132","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2509.07132","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.07132","pdf_url":"https://arxiv.org/pdf/2509.07132","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"widespread":[1],"use":[2],"of":[3,63,84,143,165,170,184,192],"generative":[4,50,75],"AI":[5,51],"has":[6],"shown":[7],"remarkable":[8],"success":[9],"in":[10,126,208],"producing":[11],"highly":[12],"realistic":[13],"deepfakes,":[14],"posing":[15],"a":[16,81,119,162],"serious":[17],"threat":[18],"to":[19,48,53,122],"various":[20],"voice":[21,27,200],"biometric":[22],"applications,":[23],"including":[24,86],"speaker":[25],"verification,":[26],"biometrics,":[28],"audio":[29,40],"conferencing,":[30],"and":[31,57,95,97,106,117,155,168,195],"criminal":[32],"investigations.":[33],"To":[34],"counteract":[35],"this,":[36],"several":[37],"state-of-the-art":[38],"(SoTA)":[39],"deepfake":[41,58,128,148],"detection":[42],"(ADD)":[43],"methods":[44,65,116,145,173],"have":[45],"been":[46],"proposed":[47],"identify":[49],"signatures":[52],"distinguish":[54],"between":[55],"real":[56],"audio.":[59],"However,":[60],"the":[61,113,166,190],"effectiveness":[62,125],"these":[64],"is":[66],"severely":[67],"undermined":[68],"by":[69],"anti-forensic":[70],"(AF)":[71],"attacks":[72,79,99],"that":[73,213],"conceal":[74],"signatures.":[76],"These":[77],"AF":[78,176,218],"span":[80],"wide":[82],"range":[83],"techniques,":[85],"statistical":[87],"modifications":[88],"(e.g.,":[89,100],"pitch":[90],"shifting,":[91],"filtering,":[92],"noise":[93],"addition,":[94],"quantization)":[96],"optimization-based":[98],"FGSM,":[101],"PGD,":[102],"C":[103],"\\&amp;":[104],"W,":[105],"DeepFool).":[107],"In":[108],"this":[109],"paper,":[110],"we":[111],"investigate":[112],"SoTA":[114,171],"ADD":[115,144,172,185],"provide":[118],"comparative":[120,159],"analysis":[121,160],"highlight":[123,182],"their":[124,133],"exposing":[127],"signatures,":[129],"as":[130,132],"well":[131],"vulnerabilities":[134,183],"under":[135],"adversarial":[136],"conditions.":[137],"We":[138],"conducted":[139],"an":[140],"extensive":[141],"evaluation":[142],"on":[146],"five":[147],"benchmark":[149],"datasets":[150],"using":[151],"two":[152],"categories:":[153],"raw":[154],"spectrogram-based":[156],"approaches.":[157],"This":[158],"enables":[161],"deeper":[163],"understanding":[164],"strengths":[167],"limitations":[169],"against":[174],"diverse":[175],"attacks.":[177],"It":[178,202],"does":[179],"not":[180],"only":[181],"methods,":[186],"but":[187],"also":[188],"informs":[189],"design":[191],"more":[193],"robust":[194],"generalized":[196],"detectors":[197],"for":[198],"real-world":[199],"biometrics.":[201],"will":[203],"further":[204],"guide":[205],"future":[206],"research":[207],"developing":[209],"adaptive":[210],"defense":[211],"strategies":[212],"can":[214],"effectively":[215],"counter":[216],"evolving":[217],"techniques.":[219]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
