Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks
Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks
批准号:
2114220
负责人:
Yingying Chen
金额:
$33.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30
中文摘要
在人工智能(AI)技术进步的推动下,下一代语音可控物联网和EDGE系统极大地方便了人们的日常生活。这类系统包括语音助理系统和语音认证手机银行等。然而,这些系统中使用的底层机器学习方法天生就容易受到音频对手攻击,在这种攻击中,对手可以通过向原始音频输入注入不可感知的扰动来误导机器学习模型。鉴于语音可控物联网和EDGE系统在许多隐私关键型和安全关键型应用中的广泛采用,如个人银行和自动驾驶,对基于音频的对抗性攻击的严重性和后果以及相应的防御解决方案的深入了解和调查是非常必要的。该项目将从时间和空间两个角度全面研究和分析语音可控物联网和EDGE系统对抗音频域对手攻击的脆弱性和健壮性。该项目的研究成果将为构建可信赖的语音可控物联网和EDGE系统奠定坚实的基础。开发的防御技术将提高许多智能音频系统的安全性,如自动语音识别(ASR)、关键字检测和说话人识别。该项目将通过各种参与性计划让未被充分代表的学生、本科生和研究生以及K-12学生参与。该项目的目标是演示音频对抗性攻击在物理世界中的可行性,确定攻击的严重程度和后果,并在实际环境中进一步开发防御策略,以构建攻击弹性强、语音可控的物联网(IoT)设备和边缘系统。为了在实际的时间限制下研究音频对抗攻击的可能性和严重性,该项目将开发低成本的音频不可知的无同步攻击发射方案,包括音频特定的快速对抗扰动生成器和通用对抗扰动生成器。为了研究敌意干扰如何在现实环境中经受住各种传播因素的影响,该项目将使用先进的房间脉冲响应模拟器和物理环境测量来分析空中传播造成的音频失真。该项目还将开发几种防御技术,包括防御性去噪、模型增强和基于麦克风阵列的活性检测。该技术将有助于保护语音可控的物联网和边缘设备在音频攻击下的安全。该项目还将在基于音频的对抗性机器学习的理论基础和面向安全的面向音频的新兴应用程序中贡献一种新的计算范式。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Powered by the advancement of artificial intelligence (AI) techniques, the next-generation voice-controllable IoT and edge systems have substantially facilitated people’s daily lives. Such systems include voice assistant systems and voice authenticated mobile banking, among many others. However, the underlying machine learning approaches used in these systems, are inherently vulnerable to audio adversarial attacks, in which an adversary can mislead the machine learning models via injecting imperceptible perturbation to the original audio input. Given the widespread adoption of voice-controllable IoT and edge systems in many privacy-critical and safety-critical applications, e.g., personal banking and autonomous driving, the in-depth understanding and investigation of severity and consequences of audio-based adversarial attack as well as the corresponding defense solutions, are highly demanded. This project will perform a comprehensive study and analysis of the vulnerability and robustness of voice-controllable IoT and edge systems against audio-domain adversarial attacks in both temporal and spatial perspectives. The research outcome of this project will form solid foundations for building trustworthy voice-controllable IoT and edge systems. The developed defense techniques will improve the security of many intelligent audio systems, such as automatic speech recognition (ASR), keyword spotting, and speaker recognition. This project will involve underrepresented students, undergraduate and graduate students, and K-12 students through a variety of engaging programs.The objective of this project is to demonstrate the feasibility of audio adversarial attacks in the physical world, determine the attack severity and consequences, and further develop defending strategies in practical environments to build attack-resilient voice-controllable Internet-of-Things (IoT) devices and edge systems. To study the possibility and severity of audio adversarial attacks in a practical time-constraint setting, the project will develop low-cost audio-agnostic synchronization-free attack launching schemes, including audio-specific fast adversarial perturbation generator and universal adversarial perturbation generator. To investigate how the adversarial perturbations survive various propagation factors in realistic environments, the project will analyze the audio distortions caused by the over-the-air propagation using an advanced room impulse response simulator and physical environment measurements. The project will also develop several defense techniques, including defensive denoiser, model enhancement, and microphone-array-based liveness detection. The presented technique will help to secure the voice-controllable IoT and edge devices under audio adversarial attacks. The project will also contribute to a new computing paradigm in audio-based adversarial machine learning in both theoretic foundations as well as safety-critical audio-oriented emerging applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/icassp43922.2022.9747582
发表时间:
2022-05
期刊:
ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子:
--
作者:
[Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan]
通讯作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
Robust Detection of Machine-induced Audio Attacks in Intelligent Audio Systems with Microphone Array
DOI:
10.1145/3460120.3484755
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen]
通讯作者:
Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen
DOI:
10.1109/icccn58024.2023.10230152
发表时间:
2023-07
期刊:
2023 32nd International Conference on Computer Communications and Networks (ICCCN)
影响因子:
--
作者:
[Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen]
通讯作者:
Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen
DOI:
10.1609/aaai.v37i9.26244
发表时间:
2023-01
期刊:
ArXiv
影响因子:
--
作者:
[Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan]
通讯作者:
Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan
DOI:
10.48550/arxiv.2208.10608
发表时间:
2022-08
期刊:
ArXiv
影响因子:
--
作者:
[Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan]
通讯作者:
Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
共 6 条
Collaborative Research: III: Small: Efficient and Robust Multi-model Data Analytics for Edge Computing
-
批准号:2311596
-
项目类别:Standard Grant
-
资助金额:$24.0万
-
财政年份:2023
-
负责人:Yingying Chen
-
依托单位:
SHF: Small: A General Framework for Accelerating AI on Resource-Constrained Edge Devices
-
批准号:2211163
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:Yingying Chen
-
依托单位:
Collaborative Research: CCRI: New: Nation-wide Community-based Mobile Edge Sensing and Computing Testbeds
-
批准号:2120396
-
项目类别:Standard Grant
-
资助金额:$71.0万
-
财政年份:2021
-
负责人:Yingying Chen
-
依托单位:
Collaborative Research: PPoSS: Planning: Hardware-accelerated Trustworthy Deep Neural Network
-
批准号:2028876
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:2020
-
负责人:Yingying Chen
-
依托单位:
SHF: Small: Collaborative Research: Software Hardware Architecture Co-design for Low-power Heterogeneous Edge Devices
-
批准号:1909963
-
项目类别:Standard Grant
-
资助金额:$32.0万
-
财政年份:2019
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Security Assurance in Short Range Communication with Wireless Channel Obfuscation
-
批准号:1814590
-
项目类别:Standard Grant
-
资助金额:$8.5万
-
财政年份:2018
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
-
批准号:1716500
-
项目类别:Standard Grant
-
资助金额:$34.0万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
-
批准号:1826647
-
项目类别:Continuing Grant
-
资助金额:$5.92万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
-
批准号:1820624
-
项目类别:Standard Grant
-
资助金额:$34.0万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
-
批准号:1514436
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2015
-
负责人:Yingying Chen
-
依托单位:
Student Travel Support for ACM MobiHoc 2015
-
批准号:1538785
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2015
-
负责人:Yingying Chen
-
依托单位:
CSR: Medium: Collaborative Research: Guardian Angel-Enabling Mobile Safety Systems
-
批准号:1409767
-
项目类别:Continuing Grant
-
资助金额:$22.91万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
EAGER: Collaborative Research: Towards Understanding Smartphone User Privacy: Implication, Derivation, and Protection
-
批准号:1450091
-
项目类别:Standard Grant
-
资助金额:$14.0万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
Student Travel Support for IEEE CNS 2014
-
批准号:1454878
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
NeTS: Small: Collaborative Research: Distributed Robust Spectrum Sensing and Sharing in Cognitive Radio Networks
-
批准号:1318748
-
项目类别:Standard Grant
-
资助金额:$30.48万
-
财政年份:2013
-
负责人:Yingying Chen
-
依托单位:
CSR: Small: Collaborative Research: Smartphone Enabled Social and Physical Compass System (SENSCOPS)
-
批准号:1217387
-
项目类别:Standard Grant
-
资助金额:$22.0万
-
财政年份:2012
-
负责人:Yingying Chen
-
依托单位:
CAREER: EASE: Enhancing the Security of Pervasive Wireless Networks by Exploiting Location
-
批准号:0954020
-
项目类别:Continuing Grant
-
资助金额:$48.88万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
NeTSE:Small:Collaborative Research: MILAN: Multi-Modal Passive Intrusion Learning in Pervasive Wireless Environments
-
批准号:1018270
-
项目类别:Standard Grant
-
资助金额:$24.8万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
CSR: Small: Collaborative Research: SEMOIS: Secure Mobile Information Sharing System
-
批准号:1016303
-
项目类别:Standard Grant
-
资助金额:$19.69万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
SGER: Securing Spectrum Usage in Future Radio Systems
-
批准号:0847211
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2008
-
负责人:Yingying Chen
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: