Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks

协作研究:SaTC:核心:小型:在音频对抗攻击下保护物联网和边缘设备

基本信息

  • 批准号:
    2114161
  • 负责人:
  • 金额:
    $ 17万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-10-01 至 2024-09-30
  • 项目状态:
    已结题

项目摘要

Powered by the advancement of artificial intelligence (AI) techniques, the next-generation voice-controllable IoT and edge systems have substantially facilitated people’s daily lives. Such systems include voice assistant systems and voice authenticated mobile banking, among many others. However, the underlying machine learning approaches used in these systems, are inherently vulnerable to audio adversarial attacks, in which an adversary can mislead the machine learning models via injecting imperceptible perturbation to the original audio input. Given the widespread adoption of voice-controllable IoT and edge systems in many privacy-critical and safety-critical applications, e.g., personal banking and autonomous driving, the in-depth understanding and investigation of severity and consequences of audio-based adversarial attack as well as the corresponding defense solutions, are highly demanded. This project will perform a comprehensive study and analysis of the vulnerability and robustness of voice-controllable IoT and edge systems against audio-domain adversarial attacks in both temporal and spatial perspectives. The research outcome of this project will form solid foundations for building trustworthy voice-controllable IoT and edge systems. The developed defense techniques will improve the security of many intelligent audio systems, such as automatic speech recognition (ASR), keyword spotting, and speaker recognition. This project will involve underrepresented students, undergraduate and graduate students, and K-12 students through a variety of engaging programs.The objective of this project is to demonstrate the feasibility of audio adversarial attacks in the physical world, determine the attack severity and consequences, and further develop defending strategies in practical environments to build attack-resilient voice-controllable Internet-of-Things (IoT) devices and edge systems. To study the possibility and severity of audio adversarial attacks in a practical time-constraint setting, the project will develop low-cost audio-agnostic synchronization-free attack launching schemes, including audio-specific fast adversarial perturbation generator and universal adversarial perturbation generator. To investigate how the adversarial perturbations survive various propagation factors in realistic environments, the project will analyze the audio distortions caused by the over-the-air propagation using an advanced room impulse response simulator and physical environment measurements. The project will also develop several defense techniques, including defensive denoiser, model enhancement, and microphone-array-based liveness detection. The presented technique will help to secure the voice-controllable IoT and edge devices under audio adversarial attacks. The project will also contribute to a new computing paradigm in audio-based adversarial machine learning in both theoretic foundations as well as safety-critical audio-oriented emerging applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在人工智能(AI)技术进步的推动下,下一代语音可控物联网和边缘系统极大地促进了人们的日常生活。这样的系统包括语音辅助系统和语音认证的移动的银行业务等。然而,这些系统中使用的底层机器学习方法本质上容易受到音频对抗性攻击,其中对手可以通过向原始音频输入注入不可感知的扰动来误导机器学习模型。鉴于语音可控物联网和边缘系统在许多隐私关键和安全关键应用中的广泛采用,例如,个人银行和自动驾驶,深入了解和调查基于音频的对抗性攻击的严重性和后果以及相应的防御解决方案,是非常有必要的。该项目将从时间和空间的角度对语音可控物联网和边缘系统在音频域对抗攻击中的脆弱性和鲁棒性进行全面的研究和分析。该项目的研究成果将为构建可信赖的语音可控物联网和边缘系统奠定坚实的基础。所开发的防御技术将提高许多智能音频系统的安全性,例如自动语音识别(ASR),关键字识别和说话人识别。该项目将通过各种吸引人的项目涉及代表性不足的学生,本科生和研究生以及K-12学生。该项目的目标是证明物理世界中音频对抗攻击的可行性,确定攻击的严重性和后果,并进一步制定实际环境中的防御策略,构建抗攻击、语音可控的物联网设备和边缘系统。为了研究在实际的时间限制设置下音频对抗攻击的可能性和严重性,该项目将开发低成本的音频不可知的无同步攻击发起方案,包括音频特定的快速对抗扰动发生器和通用对抗扰动发生器。 为了研究对抗性扰动如何在现实环境中经受住各种传播因素的影响,该项目将使用先进的房间脉冲响应模拟器和物理环境测量来分析空中传播引起的音频失真。该项目还将开发几种防御技术,包括防御性降噪,模型增强和基于麦克风阵列的活性检测。所提出的技术将有助于在音频对抗攻击下保护语音可控物联网和边缘设备。该项目还将为基于音频的对抗性机器学习在理论基础和面向安全的新兴应用中的新计算范式做出贡献。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估而被认为值得支持。

项目成果

期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Speech Privacy Leakage from Shared Gradients in Distributed Learning
RIBAC: Towards Robust and Imperceptible Backdoor Attack against Compact DNN
  • DOI:
    10.48550/arxiv.2208.10608
  • 发表时间:
    2022-08
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
  • 通讯作者:
    Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
Audio-domain position-independent backdoor attack via unnoticeable triggers
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Jian Liu其他文献

Correlated continuous-time random walk in the velocity field: the role of velocity and weak asymptotics,
速度场中的相关连续时间随机游走:速度和弱渐近的作用,
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    3.4
  • 作者:
    Jian Liu;Cai-Yun Zhang;Jing-Dong Bao;Xiao-Song Chen
  • 通讯作者:
    Xiao-Song Chen
Large magnetic entropy change and enhanced mechanical properties of Ni–Mn–Sn–C alloys
Ni-Mn-Sn-C合金的大磁熵变和增强的力学性能
  • DOI:
    10.1016/j.scriptamat.2013.11.009
  • 发表时间:
    2014-03
  • 期刊:
  • 影响因子:
    6
  • 作者:
    Yu Zhang;Jian Liu;Qiang Zheng;Jian Zhang;Weixing Xia;Juan Du;Aru Yan
  • 通讯作者:
    Aru Yan
A Dual-gate MoS₂ Photodetector Based on Interface Coupling Effect
基于界面耦合效应的双栅MoS™光电探测器
  • DOI:
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    13.3
  • 作者:
    Fuyou Liao;Jianan Deng;Xinyu Chen;Yin Wang;Xinzhi Zhang;Jian Liu;Hao Zhu;Lin Chen;Qingqing Sun;Weida Hu;Jianlu Wang;Jing Zhou;Peng Zhou;David Wei Zhang;Jing Wan;Wenzhong Bao
  • 通讯作者:
    Wenzhong Bao
Laser Shock-Induced Nano-Twist of Transition Metal Dichalcogenides
激光冲击诱导过渡金属二硫化物纳米扭曲
  • DOI:
    10.1021/acsami.2c10661
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    9.5
  • 作者:
    Jian Liu;Nan Lu;Jie Guan;Yaowu Hu
  • 通讯作者:
    Yaowu Hu
Crystal facet-dependent reactivity of alpha-Mn2O3 microcrystalline catalyst for soot combustion
用于烟灰燃烧的 α-Mn2O3 微晶催化剂的晶面依赖性反应性
  • DOI:
  • 发表时间:
    2016
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Li Cheng;Yong Men;Jinguo Wang;Hao Wang;Wei An;Yuanqiang Wang;Zhichen Duan;Jian Liu
  • 通讯作者:
    Jian Liu

Jian Liu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Jian Liu', 18)}}的其他基金

Collaborative Research: High-precision monitoring of foodborne pathogens in food manufacturing facilities
合作研究:食品生产设施中食源性病原体的高精度监测
  • 批准号:
    2130643
  • 财政年份:
    2022
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
Collaborative Research: CCSS: Continuous Facial Sensing and 3D Reconstruction via Single-ear Wearable Biosensors
合作研究:CCSS:通过单耳可穿戴生物传感器进行连续面部传感和 3D 重建
  • 批准号:
    2132106
  • 财政年份:
    2021
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
The Rising Stars in Cell Biology Symposium
细胞生物学新星研讨会
  • 批准号:
    2134945
  • 财政年份:
    2021
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
Spatial-temporal control over tipping-point operation defines fidelity of genome partition
对临界点操作的时空控制定义了基因组分区的保真度
  • 批准号:
    2105837
  • 财政年份:
    2021
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
CAREER: Engineering artificial oxide layers with hidden spin symmetry for drivable 2D quantum magnetism
职业:设计具有隐藏自旋对称性的人造氧化物层,以实现可驱动的二维量子磁性
  • 批准号:
    1848269
  • 财政年份:
    2019
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: Multi-Level Data Fusion for Real-Time Prognostic Health Management of Hierarchical Systems
协作研究:分层系统实时预测健康管理的多级数据融合
  • 批准号:
    1100949
  • 财政年份:
    2011
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
SBIR Phase II: A MHz High Energy Femtosecond Fiber Laser System for High Throughput Photonic Device Fabrication
SBIR 第二阶段:用于高通量光子器件制造的 MHz 高能飞秒光纤激光器系统
  • 批准号:
    0952237
  • 财政年份:
    2010
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
SBIR Phase I: A MHz High Energy Femtosecond Fiber Laser System for High Throughput Photonic Device Fabrication
SBIR 第一阶段:用于高通量光子器件制造的 MHz 高能飞秒光纤激光器系统
  • 批准号:
    0839230
  • 财政年份:
    2009
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
NER: Semiconductor Quantum Dot-Based Artificial Enzymes. Rational Design and Development
NER:基于半导体量子点的人工酶。
  • 批准号:
    0403269
  • 财政年份:
    2004
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant

相似国自然基金

Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
Cell Research
  • 批准号:
    31224802
  • 批准年份:
    2012
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research
  • 批准号:
    31024804
  • 批准年份:
    2010
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research (细胞研究)
  • 批准号:
    30824808
  • 批准年份:
    2008
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
  • 批准号:
    10774081
  • 批准年份:
    2007
  • 资助金额:
    45.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330941
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: EDU: Adversarial Malware Analysis - An Artificial Intelligence Driven Hands-On Curriculum for Next Generation Cyber Security Workforce
协作研究:SaTC:EDU:对抗性恶意软件分析 - 下一代网络安全劳动力的人工智能驱动实践课程
  • 批准号:
    2230609
  • 财政年份:
    2023
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
  • 批准号:
    2312057
  • 财政年份:
    2023
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Medium: Understanding the Impact of Privacy Interventions on the Online Publishing Ecosystem
协作研究:SaTC:核心:媒介:了解隐私干预对在线出版生态系统的影响
  • 批准号:
    2237329
  • 财政年份:
    2023
  • 资助金额:
    $ 17万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了