Chunking Defense for Adversarial Attacks on ASR

Chunking Defense for Adversarial Attacks on ASR
复制标题

DOI:
10.21437/interspeech.2022-11096
复制
发表时间:
2022-09
期刊:
--
影响因子:
--
通讯作者:
Yiwen Shao;J. Villalba;Sonal Joshi;Saurabh Kataria;S. Khudanpur;N. Dehak
Yiwen Shao;J. Villalba;Sonal Joshi;Saurabh Kataria;S. Khudanpur;N. Dehak
中科院分区:
其他
文献类型:
--
作者:
Yiwen Shao;J. Villalba;Sonal Joshi;Saurabh Kataria;S. Khudanpur;N. Dehak

文献摘要

被引文献

相似文献

虽然深度学习在过去几年中导致了自动语音识别(ASR)系统的显著改进,但它也使它们容易受到对手的攻击。这些攻击可能是为了让ASR无法产生正确的转录,或者更糟糕的是,输出对手选择的句子。在这项工作中,我们提出了一种基于独立处理语音输入的随机或固定大小的块的防御方法,希望“包含”对抗性扰动的累积影响。这种方法不需要对ASR系统进行任何额外的训练,也不需要对输入进行任何防御性的预处理。它可以很容易地应用于任何ASR系统,在良性条件下性能损失很小,同时提高了对手的健壮性。我们在具有不同攻击预算的Librispeech数据集上进行了实验,结果表明所提出的防御在两种不同的ASR系统/模型上取得了一致的改进。
While deep learning has lead to dramatic improvements in automatic speech recognition (ASR) systems in the past few years, it has also made them vulnerable to adversarial attacks. These attacks may be designed to either make ASR fail in producing the correct transcription or worse, output an adversary-chosen sentence. In this work, we propose a defense based on independently processing random or fixed size chunks of the speech input in the hope of “containing” the cumulative effect of the adversarial perturbations. This approach does not require any additional training of the ASR system, or any defensive pre-processing of the input. It can be easily applied to any ASR systems with little loss in performance under benign conditions, while improving adversarial robustness. We perform experiments on the Librispeech data set with different adversarial attack budgets, and show that the proposed defense achieves consistent improvement on two different ASR systems/models.