Welcome to VoicePrivacy 2026

Formed in 2020, the VoicePrivacy initiative has spearheaded efforts to develop privacy-preserving solutions for speech technologies. To date, it has primarily focused on voice anonymization, i.e., transforming speech signals to conceal speaker identity while preserving speech utility. This objective has been pursued through a series of competitive benchmarking challenges, providing common datasets, standardized evaluation protocols, and meaningful metrics for fair comparison of anonymization systems. The first three editions of the VoicePrivacy Challenge (VPC) were held in 2020, 2022, and 2024. The scope of the VoicePrivacy Challenge has progressively evolved. While VPC 2020 established a foundational evaluation framework for English voice anonymization, VPC 2022 extended this framework to assess prosody preservation, and VPC 2024 further introduced explicit requirements on preserving the speaker’s emotional state. Following VPC 2024, the Attacker Challenge was introduced to foster the development of stronger attacker models, evaluated against a selection of top-performing anonymization systems submitted to VPC 2024, as well as strong baseline systems.

VoicePrivacy 2026, the fourth edition of the challenge, starts in March 2026 and culminates in the VoicePrivacy Challenge workshop held in conjunction with the 6th Symposium on Security and Privacy in Speech Communication (SPSC), co-located with Interspeech 2026 in Sydney, Australia.

In keeping with prior editions, the challenge focuses on the subtask of voice anonymization, i.e., altering the speaker’s voice to conceal identity as effectively as possible while preserving linguistic content and relevant paralinguistic attributes. In VPC 2026, particular emphasis is placed on two key aspects. First, the challenge introduces stronger, domain-aware attackers optimized using domain-related data. Specifically, since most state-of-the-art anonymization approaches are based on neural voice conversion (VC) techniques, attacker models are correspondingly trained on diverse VC data to achieve stronger speaker re-identification performance. Second, beyond English anonymization, VPC 2026 explicitly extends the evaluation to a multilingual setting. The challenge is organised with two independent tracks:

  • Track 1: English anonymization.

  • Track 2: Multilingual anonymization.

Follow @Voice-Privacy-Challenge

Registration

Participants/teams are requested to register for the evaluation. Registration should be performed once only for each participating entity using the registration form.

You will receive a confirmation email within ~24 hours after successful registration. Otherwise, or in case of any questions, please contact the organisers:

organisers@lists.voiceprivacychallenge.org

For updates, all participants and everyone interested in the VoicePrivacy Challenge are encouraged to subscribe to: https://groups.google.com/g/voiceprivacy


In Memory of Emmanuel Vincent (1979-2026)

VoicePrivacy 2026 is dedicated to the memory of Emmanuel Vincent, whose pioneering work and leadership were instrumental in establishing the VoicePrivacy initiative and advancing research on voice anonymization and privacy in speech technology. Read more here.

Schedule

All participants are invited to present their work at the joint SPSC Symposium and VoicePrivacy Challenge workshop organized in conjunction with Interspeech 2026.

All submission deadlines are at 23:59 Anywhere on Earth (AoE).

Deadline Date
Deadline for participants to submit a list for training data and models 30th April 2026
Publication of the full final list of training data and models 7th May 2026
Deadline to submit abstract 30th June 2026
Deadline for participants to submit objective evaluation results, anonymized data, and system descriptions 30th June 2026 4th July 2026
Submission of challenge papers to the joint SPSC Symposium and VoicePrivacy Challenge workshop 30th June 2026 4th July 2026
Author notification for challenge papers 18th July 2026
Joint SPSC Symposium and VoicePrivacy Challenge workshop 26th September 2026

Data

Publicly available resources are used for the training, development, and evaluation of voice anonymization systems.

Track 1: English anonymization

  • Development & evaluation: LibriSpeech and IEMOCAP (identical to VPC 2024)
  • ASV trials: Same-gender and cross-gender (mixed) trials
  • Emotion data: IEMOCAP dev & test

Track 2: Multilingual anonymization

  • Development & evaluation: Multilingual LibriSpeech (MLS) for French, Spanish, English, and German
  • Emotion data: Oreau (French), MESD (Spanish), EMNS (English), EmoDB (German)
  • Languages: 18 speakers (fr), 20 (es), 42 (en), 30 (de)

Training data requirements

  • All data and models proposed by participants in VPC 2024 are allowed (see evaluation plan Appendix)
  • Any additional data/models must be reported to organisers@lists.voiceprivacychallenge.org before 30 April 2026
  • All data and models must be publicly accessible
  • Commercial APIs are discouraged due to lack of reproducibility

Full details are in the VoicePrivacy 2026 Evaluation Plan.

Baselines

The organisers provide baseline anonymization systems and evaluation scripts.

Track 1: English anonymization

ID Description
B2 McAdams coefficients-based (DSP-based anonymization)
B3 Phone aligner + Praat → E2E ASR → GST → FastSpeech2 + HiFi-GAN, GAN speaker selection
B4 HuBERT Base (quantized semantic encoder) + EnCodec
B5 YAAPT → wav2vec2 + TDNN-F + VQ → ECAPA → HiFi-GAN, Select speaker

Track 2: Multilingual anonymization

ID Description
BM1 HuBERT-based, language-independent (similar to legacy B1)
BM2 Whisper + IMS Toucan + HiFi-GAN, full pipeline with prosody and F0
BM3 Same as BM2 but without prosody extraction and F0/energy modification

Repository: Voice-Privacy-Challenge-2026

Metrics

Track 1: English anonymization

Metric Description
Privacy Equal error rate (EER) — semi-informed attacker ASV
Utility WER (ASR), UAR (SER)
Evaluation conditions Minimum target EERs: 10%, 20%, 30%, 40%

Track 2: Multilingual anonymization

Metric Description
Privacy EER — averaged across French, Spanish, English, German
Utility WER (Whisper-large-v3 ASR), UAR (emotion2vec SER) — averaged across languages
Evaluation conditions Same as Track 1: 10%, 20%, 30%, 40%

Assessment

  • Higher EER → greater privacy
  • Lower WER → better content preservation
  • Higher UAR → better emotion preservation

Submissions that satisfy a given privacy requirement are ranked by utility (WER and UAR separately).

Submission

Submission deadline: 30th June 2026 4th July 2026 (AoE). Authors are kindly requested to submit abstracts by the original deadline, 30th June 2026 (AoE).

Paper submission

All teams must submit one paper to SPSC that serves as both the scientific contribution and the official system description. No separate system description is required.

Submission portal: CMT-SPSC 2026

In CMT, you are required to complete the form:

  1. Sub-track: Track 1 (English), Track 2 (Multilingual), or Both
  2. Team Name: use “team_name” in the submission credentials email.
  3. How would you like this submission to be considered?
    • As an SPSC proceedings paper and a VoicePrivacy Challenge website publication (If accepted: proceedings + VPC website. If not accepted: VPC website only).
    • As a VoicePrivacy Challenge website publication only (e.g. if you plan to publish elsewhere).

Format: SPSC template, 4–6 pages excluding references; appendices allowed for technical details. Please note that submissions to the VPC paper track are not anonymized. All authors and team members should be listed in the manuscript.

Each paper must:

  1. Include a “System description” section and/or appendix with full technical details for all submitted systems (architecture, training data, preprocessing, hyperparameters, computational cost, etc.).
  2. Map each $anon_data_suffix to the corresponding system variant in the paper.

Summary tables (as in the evaluation plan) are recommended.

Anonymized data and results submission

Required for all participants. Run the upload script once per system ($anon_data_suffix).

Scripts: track 1 · track 2

Track 1:

OSS_ACCESS_KEY_ID=<XXX> OSS_ACCESS_KEY_SECRET=<XXX> OSS_TEAM=<TEAM_NAME> \
  bash 03_upload_submission_oss_track1.sh $anon_data_suffix

Track 2:

OSS_ACCESS_KEY_ID=<XXX> OSS_ACCESS_KEY_SECRET=<XXX> OSS_TEAM=<TEAM_NAME> \
  bash 03_upload_submission_oss_track2.sh $anon_data_suffix

OSS_ACCESS_KEY_ID, OSS_ACCESS_KEY_SECRET, and OSS_TEAM are sent to each team seperately. Test connectivity with bash 03_upload_submission_oss_track1.sh test (or track 2).

For upload issues, contact organisers@lists.voiceprivacychallenge.org before the deadline with team name; extensions may be granted for special cases.

Rules for data submission

See the evaluation plan. In addition:

  1. No limit on submitted systems; one upload run per $anon_data_suffix.
  2. Each script validates, packs, and uploads the items below.

Track 1

  1. exp/results_summary/track1/result_for_rank<suffix>, result_for_submission<suffix>.zip

  2. anonymized speech directories (data/<dataset><suffix>):

libri_dev_enrolls<suffix>
libri_dev_trials_mixed<suffix>
libri_test_enrolls<suffix>
libri_test_trials_mixed<suffix>
IEMOCAP_dev<suffix>
IEMOCAP_test<suffix>
train-clean-360<suffix>

Track 2

  1. exp/results_summary/track2/result_for_rank<suffix>, result_for_submission<suffix>.zip

  2. anonymized speech directories (data/<dataset><suffix>):

en_dev_enrolls<suffix>          en_dev_trials_mixed<suffix>
en_test_enrolls<suffix>         en_test_trials_mixed<suffix>
es_dev_enrolls<suffix>          es_dev_trials_mixed<suffix>
es_test_enrolls<suffix>         es_test_trials_mixed<suffix>
fr_dev_enrolls<suffix>          fr_dev_trials_mixed<suffix>
fr_test_enrolls<suffix>         fr_test_trials_mixed<suffix>
de_dev_enrolls<suffix>           de_dev_trials_mixed<suffix>
de_test_enrolls<suffix>         de_test_trials_mixed<suffix>
emodata_track2_dev<suffix>      emodata_track2_test<suffix>
train_english<suffix>           train_spanish<suffix>
train_french<suffix>            train_german<suffix>

Chinese (cn_*) and Japanese (ja_*) data are optional for Track 2.

  1. Wav files: 16 kHz, 16-bit signed integer PCM; same utterance IDs and structure as reference datasets.
  2. <suffix> must match across result files, data directories, and paper. <TEAM_NAME> must match registration.

Ranking

Official ranking includes only rule-compliant systems for which we receive both data/results and a complete SPSC paper before the deadline. Results in the paper without a corresponding data submission are excluded.

Late submissions

SPSC paper and results submitted after the deadlines will be marked as late submission in results ranking.

Organisers

Xiaoxiao Miao — Duke Kunshan University, China
Natalia Tomashenko — Université de Lorraine, CNRS, Inria, LORIA, F-54000 Nancy, France
Ridwan Arefeen — Singapore Institute of Technology, Singapore
Sarina Meyer — Institute for Natural Language Processing, University of Stuttgart, Germany
Michele Panariello — Audio Security and Privacy Group, EURECOM, France
Xin Wang — National Institute of Informatics, Tokyo, Japan
Emmanuel Vincent — Université de Lorraine, CNRS, Inria, LORIA, F-54000 Nancy, France
Nicholas Evans — Audio Security and Privacy Group, EURECOM, France
Junichi Yamagishi — National Institute of Informatics, Tokyo, Japan
Massimiliano Todisco — Audio Security and Privacy Group, EURECOM, France

Contact: organisers@lists.voiceprivacychallenge.org

Acknowledgements

This work was conducted in the context of the Inria–NII TrustedSpeech Associate Team and was partially supported by the French National Research Agency (ANR) under the Speech Privacy project and the IPoP project of the Cybersecurity PEPR. Some experiments presented in this paper were carried out using the Grid'5000 testbed, supported by a scientific interest group hosted by Inria and including CNRS, RENATER and several Universities as well as other organizations (see \url{https://www.grid5000.fr}). Parts of this work were also funded by the German Research Foundation (DFG), Project: Multilingual Controllable Voice Privacy (VoiPy), Project number 533241795. Xin Wang is partially supported by JST, PRESTO Grant Number JPMJPR23P9, Japan. Part of the baseline experiment was conducted using the TSUBAME4.0 supercomputer of Institute of Science Tokyo.

In Memory of Emmanuel Vincent (1979-2026)

The VoicePrivacy community mourns the loss of our colleague, friend, and co-founder Emmanuel Vincent. As head of science at Inria Nancy and a driving force behind the VoicePrivacy initiative since its inception in 2020, Emmanuel shaped the field of voice anonymization through his vision, scientific rigor, and unwavering generosity toward students and collaborators.

His contributions span every edition of the challenge, from the founding evaluation framework to VoicePrivacy 2026, and his influence will continue to guide our work for years to come.

We dedicate this edition of the VoicePrivacy Challenge to his memory.

Emmanuel Vincent