Quasi-Newton Adversarial Attacks on Speaker Verification Systems

Quasi-Newton Adversarial Attacks on Speaker Verification Systems
复制标题

DOI:
--
复制
发表时间:
2020-12
期刊:
2020 Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)
影响因子:
--
通讯作者:
Keita Goto;Nakamasa Inoue
Keita Goto;Nakamasa Inoue
中科院分区:
其他
文献类型:
--
作者:
Keita Goto;Nakamasa Inoue

文献摘要

被引文献

相似文献

本文提出了一种用于说话人确认系统的对抗性话语生成框架。我们的主要思想是制定一个优化问题,以产生对抗性的话语,愚弄说话人验证模型,并解决它的二阶优化方法。我们首先提出我们的算法,它使用一阶高斯-牛顿法,然后将其扩展到二阶拟牛顿法。在VoxCeleb 1数据集上的实验表明,该方法可以以比传统方法更小的扰动程度欺骗说话人确认系统。我们还表明,二阶优化方法是有效的小扰动。
This paper proposes a framework for generating adversarial utterances for speaker verification systems. Our main idea is to formulate an optimization problem to generate adversarial utterances that fool speaker verification models and solve it by a second-order optimization method. We first present our algorithm, which uses the first-order Gauss-Newton method, and then extend it to second-order Quasi-Newton methods. Our experiments on the VoxCeleb 1 dataset show that the proposed method can fool a speaker verification system with a smaller degree of perturbations than those of conventional methods. We also show that second-order optimization methods are effective for finding small perturbations.