Real-Time Neural Voice Camouflage

Real-Time Neural Voice Camouflage
复制标题

DOI:
--
复制
发表时间:
2021-12
期刊:
ArXiv
影响因子:
--
通讯作者:
Mia Chiquier;Chengzhi Mao;Carl Vondrick
Mia Chiquier;Chengzhi Mao;Carl Vondrick
中科院分区:
其他
文献类型:
--
作者:
Mia Chiquier;Chengzhi Mao;Carl Vondrick

文献摘要

相似文献

自动语音识别系统为应用创造了令人兴奋的可能性,但它们也为系统窃听提供了机会。我们提出了一种方法来伪装来自这些系统的人的空中语音,而不会给房间里的人之间的对话带来不便。标准对抗性攻击在实时流情况下并不有效,因为在执行攻击时信号的特征会发生变化。我们引入了预测性攻击,通过预测未来最有效的攻击来实现实时性能。在实时约束下,我们的方法对已建立的语音识别系统DeepSpeech造成的干扰,通过单词错误率衡量是基线的3.9倍,通过字符错误率衡量是6.6倍。我们还进一步证明了我们的方法在实际环境中是有效的。
Automatic speech recognition systems have created exciting possibilities for applications, however they also enable opportunities for systematic eavesdropping. We propose a method to camouflage a person's voice over-the-air from these systems without inconveniencing the conversation between people in the room. Standard adversarial attacks are not effective in real-time streaming situations because the characteristics of the signal will have changed by the time the attack is executed. We introduce predictive attacks, which achieve real-time performance by forecasting the attack that will be the most effective in the future. Under real-time constraints, our method jams the established speech recognition system DeepSpeech 3.9x more than baselines as measured through word error rate, and 6.6x more as measured through character error rate. We furthermore demonstrate our approach is practically effective in realistic environments over physical distances.