ASNet: Energy-Conditioned Reliability for Robust Audio Deepfake Detection
Abstract
Audio deepfake detectors that are accurate in-domain can fail under unseen genera- tors, codec/channel shifts, and adversarial perturbations while remaining confident, making confidence-based rejection unreliable. Our key insight is that a detector’s own confidence can serve two reliability roles: allocating robustness pressure across training samples and deciding which test inputs to reject. If this confidence drifts under codec or channel changes, however, it can misdirect training. We therefore introduce ASNet, which stabilizes a bounded, class-symmetric, detector- derived energy score before it controls training. Spectral and prosodic views provide complementary evidence; energy anchoring and OOD consistency stabilize the score’s scale and limit its drift; Energy-Conditioned Robustness Modulation then sets per-sample robustness weights, and the same score is reused unchanged for validation-fixed abstention. Under single-source training and adaptation-free evaluation on four external corpora, ASNet raises external Robust AUC from 0.59 to 0.65 over a compute-matched baseline and yields lower source-domain ECE before post-hoc recalibration. The reused score rejects 85% of PGD-10 errors but only 48% under a matched-budget energy-aware attack, exposing the shared score as an attack surface.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.