SaTC: CORE: Medium: Securing the Voice Processing Pipeline Against Adversarial Audio
SaTC: CORE: Medium: Securing the Voice Processing Pipeline Against Adversarial Audio
批准号:
1933208
负责人:
Patrick Traynor
金额:
$120.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2024-09-30
中文摘要
在当今世界,许多新型计算设备只有有限的或没有传统的用户界面(例如,智能恒温器、包括亚马逊Alexa在内的个人数字助理等),语音界面正在成为一种主要的交互方式。这种系统不仅简化了传统用户与传统设备的交互,而且还促进了老年人和残疾人更广泛的融合。近年来,通过应用深度学习技术,这些接口已经变得更加准确;然而,这些技术受到许多使用修改音频的攻击。虽然以前的研究人员已经使用特定深度学习模型的重要知识证明了这种攻击,但我们的初步工作表明,信号处理(或如何将声音转化为深度学习模型所需的输入)的知识可以创建跨各种系统的攻击。本授权中提出的工作将使我们能够充分表征信号处理和深度学习之间的安全挑战,并开发强大的防御措施,以确保这些系统能够在存在恶意输入的情况下继续运行。从物联网(IoT)到空中交通管制等基础设施,各种系统都将受益于对恶意音频的增强抵御能力。这一努力的重点是设计方法和工具,以保护整个语音处理管道。在我们看来,这自然会将我们的努力分成三个逻辑重点,首先是对音频预处理算法的深入分析,以及对心理声学领域的可理解性指标的调查。这些努力自然导致了我们的第二个重点,即专注于音频处理管道第二步中使用的算法。在这里,我们利用最流行的特征提取算法中的弱点来产生新的攻击,然后开发针对此类攻击的防御和技术来保护说话人的隐私。我们的最后一篇文章研究了前两篇文章中攻击的影响及其对底层机器学习算法的影响。有了这些见解,我们将研究保护特别脆弱的模型层免受这些攻击的其他方法。研究人员在信息安全、语音接口、对抗性机器学习、保护隐私的数据合成和统计信号处理等领域拥有独特的专业知识。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In a world in which many new computing devices have limited or no traditional user interface (e.g., smart thermostats, personal digital assistants including Amazon's Alexa, etc), voice interfaces are becoming a primary means of interaction. Such systems not only simplify interaction with conventional devices for traditional users, but also promote broader inclusion for both the elderly and those with disabilities. These interfaces have been made significantly more accurate in recent years through the application of deep learning techniques; however, these techniques are subject to a number of attacks using modified audio. While previous researchers have demonstrated such attacks using significant knowledge of specific deep learning models, our initial work demonstrates that knowledge of signal processing (or how voices are turned into the inputs deep learning models require) can create attacks that work across a wide variety of systems. The work proposed in this grant will allow us to fully characterize the security challenges in the space between signal processing and deep learning, and to develop strong defenses to ensure that these systems can continue to operate in the presence of malicious inputs. A wide range of systems, from the Internet of Things (IoT) to infrastructure such as air traffic control, will benefit from improved resilience to malicious audio. This effort is focused on the design methods and tools to protect the entire voice processing pipeline. In our view, this naturally segments our efforts into three logical thrusts, beginning with an in-depth analysis of the algorithms used for audio preprocessing and an investigation of comprehensibility metrics from the field of psychoacoustics. These efforts naturally lead into our second thrust, which focuses on the algorithms used in the second step of the audio processing pipeline. Here, we exploit weaknesses in the most popular feature extraction algorithms to produce new attacks, and then develop defenses against such attacks and techniques to protect speaker privacy. Our final thrust investigates the impact of attacks in the two previous thrusts and their impact on the underlying machine learning algorithms. With these insights, we will investigate additional methods of protecting particularly vulnerable layers of models against these attacks. The researchers possess the unique expertise in areas including information security, voice interfaces, adversarial machine learning, privacy-preserving data synthesis, and statistical signal processing.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3558482.3590192
发表时间:
2023-05
期刊:
Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
作者:
[Sri Hrushikesh Varma Bhupathiraju;Jennifer Sheldon;L. A. Bauer;Vincent Bindschaedler;Takeshi Sugawara;Sara Rampazzi]
通讯作者:
Sri Hrushikesh Varma Bhupathiraju;Jennifer Sheldon;L. A. Bauer;Vincent Bindschaedler;Takeshi Sugawara;Sara Rampazzi
DOI:
--
发表时间:
2021-10
期刊:
影响因子:
--
作者:
[H. Abdullah;Muhammad Sajidur Rahman;Christian Peeters;Cassidy Gibson;Washington Garcia;Vincent Bindschaedler;T. Shrimpton;Patrick Traynor]
通讯作者:
H. Abdullah;Muhammad Sajidur Rahman;Christian Peeters;Cassidy Gibson;Washington Garcia;Vincent Bindschaedler;T. Shrimpton;Patrick Traynor
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[H. Abdullah;Aditya Karlekar;Vincent Bindschaedler;Patrick Traynor]
通讯作者:
H. Abdullah;Aditya Karlekar;Vincent Bindschaedler;Patrick Traynor
DOI:
10.1109/sp40001.2021.00014
发表时间:
2020-07
期刊:
2021 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[H. Abdullah;Kevin Warren;Vincent Bindschaedler;Nicolas Papernot;Patrick Traynor]
通讯作者:
H. Abdullah;Kevin Warren;Vincent Bindschaedler;Nicolas Papernot;Patrick Traynor
Workshop: Addressing the Technical Security Challenges of Emerging Digital Financial Services
-
批准号:1745573
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2017
-
负责人:Patrick Traynor
-
依托单位:
WiFIUS: Collaborative Research: SELIOT: Securing Lifecycle of Internet-of-Things
-
批准号:1702879
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2017
-
负责人:Patrick Traynor
-
依托单位:
TWC: Medium: Digital Healthcare-Associated Infection: Measurement, Defense and Prevention in a Modern Digital Healthcare Ecosystem
-
批准号:1562485
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2016
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Designing Strong End-to-End Authentication Mechanisms for Modern Telephony Systems
-
批准号:1617474
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Evaluating and Improving Security in Emerging Branchless Banking Systems
-
批准号:1526718
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2015
-
负责人:Patrick Traynor
-
依托单位:
CAREER: Protecting User Data on Lost, Stolen and Damaged Mobile Phones
-
批准号:1464088
-
项目类别:Continuing Grant
-
资助金额:$16.75万
-
财政年份:2014
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Collaborative: Characterizing the Security Limitations of Accessing the Mobile Web
-
批准号:1464087
-
项目类别:Standard Grant
-
资助金额:$13.93万
-
财政年份:2014
-
负责人:Patrick Traynor
-
依托单位:
TWC: Small: Collaborative: Characterizing the Security Limitations of Accessing the Mobile Web
-
批准号:1222699
-
项目类别:Standard Grant
-
资助金额:$16.7万
-
财政年份:2012
-
负责人:Patrick Traynor
-
依托单位:
CAREER: Protecting User Data on Lost, Stolen and Damaged Mobile Phones
-
批准号:0952959
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2010
-
负责人:Patrick Traynor
-
依托单位:
TC: Small: Provably Anonymous Networking Through Secure Function Evaluation
-
批准号:0916031
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2009
-
负责人:Patrick Traynor
-
依托单位:
TC: Small: Characterizing and Mitigating Device-Based Attacks in Cellular Telecommunications Networks
-
批准号:0916047
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2009
-
负责人:Patrick Traynor
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: