Hidden Voice Commands

Hidden Voice Commands
复制标题

DOI:
--
复制
发表时间:
2016-08
期刊:
--
影响因子:
--
通讯作者:
Nicholas Carlini;Pratyush Mishra;Tavish Vaidya;Yuankai Zhang;M. Sherr;C. Shields;D. Wagner;
Nicholas Carlini;Pratyush Mishra;Tavish Vaidya;Yuankai Zhang;M. Sherr;C. Shields;D. Wagner;
中科院分区:
其他
文献类型:
--
作者:
Nicholas Carlini;Pratyush Mishra;Tavish Vaidya;Yuankai Zhang;M. Sherr;C. Shields;D. Wagner;

文献摘要

被引文献

相似文献

语音接口正变得越来越普遍,现在是许多设备的主要输入方法。在本文中,我们探讨了如何使用隐藏的语音命令攻击它们,这些命令对人类听众来说是无法理解的,但设备会将其解释为命令。我们在两种不同的威胁模型下评估这些攻击。在黑盒模型中,攻击者将语音识别系统用作不透明的先知。我们表明,对手可以产生难以理解的命令,这些命令对黑盒模型中的现有系统有效。在白盒模型下,攻击者完全了解语音识别系统的内部结构,并使用它来创建我们通过用户测试演示的人类无法理解的攻击命令。然后我们评估几种防御措施,包括在接受语音命令时通知用户;语音挑战-响应协议;以及能够以99.8%的准确率检测我们的攻击的机器学习方法。
Voice interfaces are becoming more ubiquitous and are now the primary input method for many devices. We explore in this paper how they can be attacked with hidden voice commands that are unintelligible to human listeners but which are interpreted as commands by devices. We evaluate these attacks under two different threat models. In the black-box model, an attacker uses the speech recognition system as an opaque oracle. We show that the adversary can produce difficult to understand commands that are effective against existing systems in the black-box model. Under the white-box model, the attacker has full knowledge of the internals of the speech recognition system and uses it to create attack commands that we demonstrate through user testing are not understandable by humans. We then evaluate several defenses, including notifying the user when a voice command is accepted; a verbal challenge-response protocol; and a machine learning approach that can detect our attacks with 99.8% accuracy.