New study reveals speech obfuscation fails against digit-aware AI attackers
Can scrambled speech still leak your PIN when AI knows what to listen for?
A study evaluates three speech obfuscation techniques for protecting linguistic content, using digit recognition as a practical scenario. Two informed attackers—a general-purpose speech recognition model and a digit-specific classifier—were applied to recognize single digits and digit sequences. Results show significant differences in recognition performance across digit modality, speech rate, and attack model, highlighting the need for more comprehensive and application-oriented evaluation methods for speech privacy.
- Three obfuscation techniques were tested against two informed attackers: a general-purpose ASR model and a digit-specific classifier.
- Recognition performance varied significantly based on digit modality (single vs. concatenated sequences) and speech rate.
- Digit-specific attackers outperformed general ASR on obfuscated speech, highlighting the need for task-specific privacy evaluations.
Why It Matters
Voice recordings of PINs or account numbers remain vulnerable even after obfuscation, threatening user privacy in smart assistants.