AdvPulse: Universal, Synchronization-free, and Targeted Audio Adversarial Attacks via Subsecond Perturbations

AdvPulse: Universal, Synchronization-free, and Targeted Audio Adversarial Attacks via Subsecond Perturbations
复制标题

DOI:
10.1145/3372297.3423348
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan
中科院分区:
其他
文献类型:
--
作者:
Zhuohang Li;Yi Wu;Jian Liu;Yingying Chen;Bo Yuan

文献摘要

被引文献

相似文献

现有的音频对抗性攻击的努力只集中在这样的情况下,其中对手具有整个语音输入的先验知识,以便通过将音频输入与对应的对抗性扰动对齐和混合来生成对抗性示例。在这项工作中,我们考虑了一个更实际和更具挑战性的攻击场景,其中智能音频系统采用流式音频输入(例如,真人语音),并且对手可以通过同时播放对抗性扰动来欺骗系统。这种攻击行为的变化带来了巨大的挑战,阻止了现有的对抗性扰动生成方法直接应用。在实践中,(1)对手不能预测受害者会说什么:对手不能依靠他们对语音信号的先验知识来指导如何生成对抗性扰动;以及(2)对手不能控制受害者何时说话:不能保证对抗性扰动和语音之间的同步。为了解决这些挑战,在本文中,我们提出了AdvPulse,这是一种生成亚秒级音频对抗扰动的系统方法,它能够以有针对性和无同步的方式改变流式音频输入的识别结果。为了规避语音内容和时间的限制,我们采用基于惩罚的通用对抗扰动生成算法,并将可变的时间延迟纳入优化过程。我们进一步根据环境声音调整对抗扰动,使其对人类不明显。此外,通过考虑在物理播放期间发生的失真源,我们能够生成更鲁棒的音频对抗性扰动,即使在空中传播下也可以保持有效。对两种代表性类型的智能音频系统(即,说话人识别和语音命令识别)在各种现实环境中进行。结果表明,即使在发动机和道路噪音很大的情况下,我们的攻击在室内环境中的平均攻击成功率也可以达到89.6%以上,在车内场景中的平均攻击成功率为76.0%。
Existing efforts in audio adversarial attacks only focus on the scenarios where an adversary has prior knowledge of the entire speech input so as to generate an adversarial example by aligning and mixing the audio input with corresponding adversarial perturbation. In this work we consider a more practical and challenging attack scenario where the intelligent audio system takes streaming audio inputs (e.g., live human speech) and the adversary can deceive the system by playing adversarial perturbations simultaneously. This change in attack behavior brings great challenges, preventing existing adversarial perturbation generation methods from being applied directly. In practice, (1) the adversary cannot anticipate what the victim will say: the adversary cannot rely on their prior knowledge of the speech signal to guide how to generate adversarial perturbations; and (2) the adversary cannot control when the victim will speak: the synchronization between the adversarial perturbation and the speech cannot be guaranteed. To address these challenges, in this paper we propose AdvPulse, a systematic approach to generate subsecond audio adversarial perturbations, that achieves the capability to alter the recognition results of streaming audio inputs in a targeted and synchronization-free manner. To circumvent the constraints on speech content and time, we exploit penalty-based universal adversarial perturbation generation algorithm and incorporate the varying time delay into the optimization process. We further tailor the adversarial perturbation according to environmental sounds to make it inconspicuous to humans. Additionally, by considering the sources of distortions occurred during the physical playback, we are able to generate more robust audio adversarial perturbations that can remain effective even under over-the-air propagation. Extensive experiments on two representative types of intelligent audio systems (i.e., speaker recognition and speech command recognition) are conducted in various realistic environments. The results show that our attack can achieve an average attack success rate of over 89.6% in indoor environments and 76.0% in inside-vehicle scenarios even with loud engine and road noises.