Robust Audio Adversarial Example for a Physical Attack

Robust Audio Adversarial Example for a Physical Attack
复制标题

DOI:
10.24963/ijcai.2019/741
复制
发表时间:
2018-10
期刊:
ArXiv
影响因子:
--
通讯作者:
Hiromu Yakura;Jun Sakuma
Hiromu Yakura;Jun Sakuma
中科院分区:
其他
文献类型:
--
作者:
Hiromu Yakura;Jun Sakuma

文献摘要

被引文献

相似文献

我们提出了一种生成音频对抗示例的方法,该示例可以攻击物理世界中最先进的语音识别模型。以前的工作假设生成的对抗性示例直接馈送到识别模型,并且由于来自回放环境的混响和噪声而无法执行这种物理攻击。相比之下,我们的方法通过模拟物理世界中回放或记录引起的变换并将变换纳入生成过程来获得强大的对抗性示例。评估和听力实验表明,我们的对抗性示例能够在不被人类注意的情况下进行攻击。这一结果表明,由所提出的方法生成的音频对抗性示例可能成为真实的威胁。
We propose a method to generate audio adversarial examples that can attack a state-of-the-art speech recognition model in the physical world. Previous work assumes that generated adversarial examples are directly fed to the recognition model, and is not able to perform such a physical attack because of reverberation and noise from playback environments. In contrast, our method obtains robust adversarial examples by simulating transformations caused by playback or recording in the physical world and incorporating the transformations into the generation process. Evaluation and a listening experiment demonstrated that our adversarial examples are able to attack without being noticed by humans. This result suggests that audio adversarial examples generated by the proposed method may become a real threat.