Dictionary Attacks on Speaker Verification

Dictionary Attacks on Speaker Verification
复制标题

DOI:
10.1109/tifs.2022.3229583
复制
发表时间:
2022-04
影响因子:
6.8
通讯作者:
M. Marras;Pawel Korus;Anubhav Jain;N. Memon
M. Marras;Pawel Korus;Anubhav Jain;N. Memon
中科院分区:
计算机科学1区
文献类型:
--
作者:
M. Marras;Pawel Korus;Anubhav Jain;N. Memon

文献摘要

相似文献

在本文中,我们提出了字典攻击对说话人验证-一种新的攻击向量,旨在匹配一个大部分的说话人人口的机会。我们介绍了一个通用的制定的攻击,可用于各种语音表示和威胁模型。攻击者使用对抗优化来最大化种子语音样本和代理人群之间的说话人嵌入的原始相似性。由此产生的主语音成功地匹配了未知人群中的一部分人。使用我们的方法获得的对抗波形可以在严格的决策阈值下匹配目标系统中平均69%的女性和38%的男性,该阈值被校准为产生1%的误报率。通过使用黑盒语音克隆系统的攻击,我们获得了在最具挑战性的条件下有效的主语音,并可在扬声器编码器之间传输。我们还表明,与多次尝试相结合,这种攻击对这些系统的安全性带来了更严重的问题。
In this paper, we propose dictionary attacks against speaker verification-a novel attack vector that aims to match a large fraction of speaker population by chance. We introduce a generic formulation of the attack that can be used with various speech representations and threat models. The attacker uses adversarial optimization to maximize raw similarity of speaker embeddings between a seed speech sample and a proxy population. The resulting master voice successfully matches a non-trivial fraction of people in an unknown population. Adversarial waveforms obtained with our approach can match on average 69% of females and 38% of males enrolled in the target system at a strict decision threshold calibrated to yield false alarm rate of 1%. By using the attack with a black-box voice cloning system, we obtain master voices that are effective in the most challenging conditions and transferable between speaker encoders. We also show that, combined with multiple attempts, this attack opens even more to serious issues on the security of these systems.