Publications
Ghost poisoning: Making users invisible to speaker verification models
Abstract
We demonstrate that speaker verification models are amenable to the creation of “ghost speakers.” In particular, we devise a model poisoning method based on contrastive learning that causes the system to perform very poorly for a specific individual, while largely maintaining expected accuracy for all other users. This provides the ghost with a robust layer of identity obfuscation that could be exploited for malicious purposes. We test our method using three popular speaker verification models and demonstrate that it increases the equal error rate for the ghost by a factor of 10 or 20 times.
- Date
- 2026
- Authors
- Nicholas Mehlman, Shrikanth Narayanan
- Journal
- JASA Express Letters
- Volume
- 6
- Issue
- 6
- Publisher
- AIP Publishing