Audio-domain position-independent backdoor attack via unnoticeable triggers

Audio-domain position-independent backdoor attack via unnoticeable triggers
复制标题

DOI:
10.1145/3495243.3560531
复制
发表时间:
2022-10
期刊:
Proceedings of the 28th Annual International Conference on Mobile Computing And Networking
影响因子:
--
通讯作者:
Cong Shi;Tian-Di Zhang;Zhuohang Li;Huy Phan;Tianming Zhao;Yan Wang;Jian Liu;Bo Yuan;Yingying Chen
Cong Shi;Tian-Di Zhang;Zhuohang Li;Huy Phan;Tianming Zhao;Yan Wang;Jian Liu;Bo Yuan;Yingying Chen
中科院分区:
其他
文献类型:
--
作者:
Cong Shi;Tian-Di Zhang;Zhuohang Li;Huy Phan;Tianming Zhao;Yan Wang;Jian Liu;Bo Yuan;Yingying Chen

文献摘要

被引文献

相似文献

深度学习模型已成为语音用户界面的关键推动因素。随着采用这些模型的外包训练的趋势日益增长,后门攻击,隐形但有效的训练阶段攻击,已经得到越来越多的关注。它们通过训练集中毒注入隐藏的触发模式,并在推理阶段覆盖模型的预测。后门攻击的研究主要集中在图像分类任务上,而在音频领域的研究很少。在这项工作中,我们探讨了音频域后门攻击的严重性,并在语音用户界面的实际场景下证明了其可行性,其中对手将不明显的音频触发器注入(播放)到现场语音中以发起攻击。为了实现这样的攻击,我们考虑在训练阶段联合优化音频触发器和目标模型,得到一个位置无关的,不明显的,鲁棒的音频触发器。我们设计了新的数据中毒技术和基于惩罚的算法,在训练期间将触发器注入音频输入中随机生成的时间位置,使触发器对任何时间位置变化都具有弹性。我们进一步设计了一种环境声音模仿技术,使触发类似于不明显的情景声音和模拟播放的空中失真,以提高触发的鲁棒性在联合优化过程中。对两个重要应用程序进行了广泛的实验(即,语音命令识别和说话人识别)表明,我们攻击在数字和物理攻击环境下的平均成功率均超过99%。
Deep learning models have become key enablers of voice user interfaces. With the growing trend of adopting outsourced training of these models, backdoor attacks, stealthy yet effective training-phase attacks, have gained increasing attention. They inject hidden trigger patterns through training set poisoning and overwrite the model's predictions in the inference phase. Research in backdoor attacks has been focusing on image classification tasks, while there have been few studies in the audio domain. In this work, we explore the severity of audio-domain backdoor attacks and demonstrate their feasibility under practical scenarios of voice user interfaces, where an adversary injects (plays) an unnoticeable audio trigger into live speech to launch the attack. To realize such attacks, we consider jointly optimizing the audio trigger and the target model in the training phase, deriving a position-independent, unnoticeable, and robust audio trigger. We design new data poisoning techniques and penalty-based algorithms that inject the trigger into randomly generated temporal positions in the audio input during training, rendering the trigger resilient to any temporal position variations. We further design an environmental sound mimicking technique to make the trigger resemble unnoticeable situational sounds and simulate played over-the-air distortions to improve the trigger's robustness during the joint optimization process. Extensive experiments on two important applications (i.e., speech command recognition and speaker recognition) demonstrate that our attack can achieve an average success rate of over 99% under both digital and physical attack settings.