A Multiversion Programming Inspired Approach to Detecting Audio Adversarial Examples

A Multiversion Programming Inspired Approach to Detecting Audio Adversarial Examples
复制标题

DOI:
10.1109/dsn.2019.00019
复制
发表时间:
2018-12
期刊:
2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Qiang Zeng;Jianhai Su;Chenglong Fu;Golam Kayas;Lannan Luo
Qiang Zeng;Jianhai Su;Chenglong Fu;Golam Kayas;Lannan Luo
中科院分区:
其他
文献类型:
--
作者:
Qiang Zeng;Jianhai Su;Chenglong Fu;Golam Kayas;Lannan Luo

文献摘要

被引文献

相似文献

对抗性示例(AES)是通过在输入中添加可察觉的扰动来制定的,以使基于机器的分类器错误地标记它们。它们已成为对机器学习的可信度的严重威胁。尽管对图像域中的AE进行了充分的研究,但音频AE的研究较少。最近,提出了多种技术来产生音频AE,这使针对它们的对策紧急。我们的实验表明,鉴于音频AE,由于不同的ASR系统使用不同的架构,参数和训练数据集,因此通过自动语音识别(ASR)系统的转录结果显着差异(即可传递性差)。基于这一事实并受到多元化编程的启发,我们提出了一种新颖的音频AE检测方法MVP-Ears,该方法利用各种货架的ASRS来确定音频是否是AE。据我们所知,我们构建了最大的音频AE数据集,评估表明检测准确性达到99.88%。尽管目前难以生成可转移的音频AES,但它们可能会成为未来的现实。我们进一步调整了上面的想法,以主动训练检测系统,以应对可转移的音频AE。因此,主动检测系统是比在可转移AES上的攻击者领先的一步。
Adversarial examples (AEs) are crafted by adding human-imperceptible perturbations to inputs such that a machine-learning based classifier incorrectly labels them. They have become a severe threat to the trustworthiness of machine learning. While AEs in the image domain have been well studied, audio AEs are less investigated. Recently, multiple techniques are proposed to generate audio AEs, which makes countermeasures against them urgent. Our experiments show that, given an audio AE, the transcription results by Automatic Speech Recognition (ASR) systems differ significantly (that is, poor transferability), as different ASR systems use different architectures, parameters, and training datasets. Based on this fact and inspired by Multiversion Programming, we propose a novel audio AE detection approach MVP-Ears, which utilizes the diverse off-the-shelf ASRs to determine whether an audio is an AE. We build the largest audio AE dataset to our knowledge, and the evaluation shows that the detection accuracy reaches 99.88%. While transferable audio AEs are difficult to generate at this moment, they may become a reality in future. We further adapt the idea above to proactively train the detection system for coping with transferable audio AEs. Thus, the proactive detection system is one giant step ahead of attackers working on transferable AEs.