Noise Flooding for Detecting Audio Adversarial Examples Against Automatic Speech Recognition

Noise Flooding for Detecting Audio Adversarial Examples Against Automatic Speech Recognition
复制标题

DOI:
10.1109/isspit.2018.8642623
复制
发表时间:
2018-12
期刊:
2018 IEEE International Symposium on Signal Processing and Information Technology (ISSPIT)
影响因子:
--
通讯作者:
K. Rajaratnam;J. Kalita
K. Rajaratnam;J. Kalita
中科院分区:
其他
文献类型:
--
作者:
K. Rajaratnam;J. Kalita

文献摘要

被引文献

相似文献

神经模型广泛应用于各种任务,并已发展成为许多工业系统的关键组成部分。尽管它们很有效且广受欢迎,但它们也存在可利用的缺陷。最初应用于计算机视觉系统,对抗性示例的生成是对图像进行看似难以察觉的扰动的过程,目的是诱导基于深度学习的分类器对图像进行错误分类。由于语音处理的最新趋势,这已成为语音识别模型中一个值得注意的问题。2017年底,一项针对语音命令分类模型的攻击被证明非常有效。有限词汇的语音分类器,例如speech Commands模型,在各种应用程序中使用得非常频繁,特别是在管理电话上下文中的自动座席时。因此,这种攻击产生的对抗性示例可能会对现实世界产生影响。虽然之前针对这些对抗性示例的防御工作已经研究了使用音频预处理来减少或扭曲对抗性噪声,但这项工作探索了用随机噪声淹没音频信号的p个特定频段以检测对抗性示例的想法。这种不需要重新训练或修改模型的泛洪技术的灵感来自于计算机视觉方面的工作,并建立在语音分类器对自然噪声相对鲁棒的想法之上。结合了5个不同频带的组合防御,用于淹没带有噪声的信号,优于音频空间中的其他现有防御,检测对抗性示例的精度为91.8%,召回率为93.5%。
Neural models enjoy widespread use across a variety of tasks and have grown to become crucial components of many industrial systems. Despite their effectiveness and extensive popularity, they are not without their exploitable flaws. Initially applied to computer vision systems, the generation of adversarial examples is a process in which seemingly imperceptible perturbations are made to an image, with the purpose of inducing a deep learning based classifier to misclassify the image. Due to recent trends in speech processing, this has become a noticeable issue in speech recognition models. In late 2017, an attack was shown to be quite effective against the Speech Commands classification model. Limited-vocabulary speech classifiers, such as the Speech Commands model, are used quite frequently in a variety of applications, particularly in managing automated attendants in telephony contexts. As such, adversarial examples produced by this attack could have real-world consequences. While previous work in defending against these adversarial examples has investigated using audio preprocessing to reduce or distort adversarial noise, this work explores the idea of flooding p articular frequency bands of an audio signal with random noise in order to detect adversarial examples. This technique of flooding, which does not require retraining or modifying the model, is inspired by work done in computer vision and builds on the idea that speech classifiers are relatively robust to natural noise. A combined defense incorporating 5 different frequency bands for flooding the signal with noise outperformed other existing defenses in the audio space, detecting adversarial examples with 91.8% precision and 93.5% recall.