Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks
Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks
批准号:
2114220
负责人:
Yingying Chen
金额:
$33.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30
中文摘要
在人工智能技术进步的推动下,下一代语音可控物联网和边缘系统极大地便利了人们的日常生活。这样的系统包括语音助理系统和语音认证的移动银行等。然而,在这些系统中使用的底层机器学习方法,本质上容易受到音频对抗性攻击,在这种攻击中,攻击者可以通过向原始音频输入注入难以察觉的扰动来误导机器学习模型。鉴于语音可控物联网和边缘系统在许多隐私关键和安全关键应用(如个人银行和自动驾驶)中的广泛采用,迫切需要深入了解和调查基于音频的对抗性攻击的严重性和后果以及相应的防御解决方案。该项目将从时间和空间角度全面研究和分析语音可控物联网和边缘系统对音频域对抗性攻击的脆弱性和鲁棒性。该项目的研究成果将为构建可信赖的语音可控物联网和边缘系统奠定坚实的基础。所开发的防御技术将提高许多智能音频系统的安全性,如自动语音识别(ASR)、关键字定位和说话人识别。该项目将涉及代表性不足的学生,本科生和研究生,以及K-12学生,通过各种引人入胜的课程。该项目的目标是演示音频对抗性攻击在物理世界中的可行性,确定攻击的严重程度和后果,并在实际环境中进一步制定防御策略,以构建抗攻击的语音可控物联网(IoT)设备和边缘系统。为了研究实际时间约束下音频对抗性攻击的可能性和严重性,该项目将开发低成本的音频不可知的无同步攻击启动方案,包括音频特定快速对抗性摄动发生器和通用对抗性摄动发生器。为了研究对抗性扰动如何在现实环境中经受各种传播因素的影响,该项目将使用先进的房间脉冲响应模拟器和物理环境测量来分析由空中传播引起的音频失真。该项目还将开发几种防御技术,包括防御降噪、模型增强和基于麦克风阵列的活动检测。所提出的技术将有助于在音频对抗性攻击下保护语音可控物联网和边缘设备。该项目还将在基于音频的对抗性机器学习的理论基础和安全关键音频导向的新兴应用中为新的计算范式做出贡献。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Powered by the advancement of artificial intelligence (AI) techniques, the next-generation voice-controllable IoT and edge systems have substantially facilitated people’s daily lives. Such systems include voice assistant systems and voice authenticated mobile banking, among many others. However, the underlying machine learning approaches used in these systems, are inherently vulnerable to audio adversarial attacks, in which an adversary can mislead the machine learning models via injecting imperceptible perturbation to the original audio input. Given the widespread adoption of voice-controllable IoT and edge systems in many privacy-critical and safety-critical applications, e.g., personal banking and autonomous driving, the in-depth understanding and investigation of severity and consequences of audio-based adversarial attack as well as the corresponding defense solutions, are highly demanded. This project will perform a comprehensive study and analysis of the vulnerability and robustness of voice-controllable IoT and edge systems against audio-domain adversarial attacks in both temporal and spatial perspectives. The research outcome of this project will form solid foundations for building trustworthy voice-controllable IoT and edge systems. The developed defense techniques will improve the security of many intelligent audio systems, such as automatic speech recognition (ASR), keyword spotting, and speaker recognition. This project will involve underrepresented students, undergraduate and graduate students, and K-12 students through a variety of engaging programs.The objective of this project is to demonstrate the feasibility of audio adversarial attacks in the physical world, determine the attack severity and consequences, and further develop defending strategies in practical environments to build attack-resilient voice-controllable Internet-of-Things (IoT) devices and edge systems. To study the possibility and severity of audio adversarial attacks in a practical time-constraint setting, the project will develop low-cost audio-agnostic synchronization-free attack launching schemes, including audio-specific fast adversarial perturbation generator and universal adversarial perturbation generator. To investigate how the adversarial perturbations survive various propagation factors in realistic environments, the project will analyze the audio distortions caused by the over-the-air propagation using an advanced room impulse response simulator and physical environment measurements. The project will also develop several defense techniques, including defensive denoiser, model enhancement, and microphone-array-based liveness detection. The presented technique will help to secure the voice-controllable IoT and edge devices under audio adversarial attacks. The project will also contribute to a new computing paradigm in audio-based adversarial machine learning in both theoretic foundations as well as safety-critical audio-oriented emerging applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/icassp43922.2022.9747582
发表时间:
2022-05
期刊:
ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子:
--
作者:
[Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan]
通讯作者:
Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
Robust Detection of Machine-induced Audio Attacks in Intelligent Audio Systems with Microphone Array
DOI:
10.1145/3460120.3484755
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen]
通讯作者:
Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen
DOI:
10.1109/icccn58024.2023.10230152
发表时间:
2023-07
期刊:
2023 32nd International Conference on Computer Communications and Networks (ICCCN)
影响因子:
--
作者:
[Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen]
通讯作者:
Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen
DOI:
10.1609/aaai.v37i9.26244
发表时间:
2023-01
期刊:
ArXiv
影响因子:
--
作者:
[Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan]
通讯作者:
Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan
DOI:
10.48550/arxiv.2208.10608
发表时间:
2022-08
期刊:
ArXiv
影响因子:
--
作者:
[Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan]
通讯作者:
Huy Phan;Cong Shi;Yi Xie;Tian-Di Zhang;Zhuohang Li;Tianming Zhao;Jian Liu;Yan Wang;Ying Chen;Bo Yuan
共 6 条
Collaborative Research: III: Small: Efficient and Robust Multi-model Data Analytics for Edge Computing
-
批准号:2311596
-
项目类别:Standard Grant
-
资助金额:$24.0万
-
财政年份:2023
-
负责人:Yingying Chen
-
依托单位:
SHF: Small: A General Framework for Accelerating AI on Resource-Constrained Edge Devices
-
批准号:2211163
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:Yingying Chen
-
依托单位:
Collaborative Research: CCRI: New: Nation-wide Community-based Mobile Edge Sensing and Computing Testbeds
-
批准号:2120396
-
项目类别:Standard Grant
-
资助金额:$71.0万
-
财政年份:2021
-
负责人:Yingying Chen
-
依托单位:
Collaborative Research: PPoSS: Planning: Hardware-accelerated Trustworthy Deep Neural Network
-
批准号:2028876
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:2020
-
负责人:Yingying Chen
-
依托单位:
SHF: Small: Collaborative Research: Software Hardware Architecture Co-design for Low-power Heterogeneous Edge Devices
-
批准号:1909963
-
项目类别:Standard Grant
-
资助金额:$32.0万
-
财政年份:2019
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Security Assurance in Short Range Communication with Wireless Channel Obfuscation
-
批准号:1814590
-
项目类别:Standard Grant
-
资助金额:$8.5万
-
财政年份:2018
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
-
批准号:1716500
-
项目类别:Standard Grant
-
资助金额:$34.0万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
-
批准号:1826647
-
项目类别:Continuing Grant
-
资助金额:$5.92万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
-
批准号:1820624
-
项目类别:Standard Grant
-
资助金额:$34.0万
-
财政年份:2017
-
负责人:Yingying Chen
-
依托单位:
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
-
批准号:1514436
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2015
-
负责人:Yingying Chen
-
依托单位:
Student Travel Support for ACM MobiHoc 2015
-
批准号:1538785
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2015
-
负责人:Yingying Chen
-
依托单位:
CSR: Medium: Collaborative Research: Guardian Angel-Enabling Mobile Safety Systems
-
批准号:1409767
-
项目类别:Continuing Grant
-
资助金额:$22.91万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
EAGER: Collaborative Research: Towards Understanding Smartphone User Privacy: Implication, Derivation, and Protection
-
批准号:1450091
-
项目类别:Standard Grant
-
资助金额:$14.0万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
Student Travel Support for IEEE CNS 2014
-
批准号:1454878
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2014
-
负责人:Yingying Chen
-
依托单位:
NeTS: Small: Collaborative Research: Distributed Robust Spectrum Sensing and Sharing in Cognitive Radio Networks
-
批准号:1318748
-
项目类别:Standard Grant
-
资助金额:$30.48万
-
财政年份:2013
-
负责人:Yingying Chen
-
依托单位:
CSR: Small: Collaborative Research: Smartphone Enabled Social and Physical Compass System (SENSCOPS)
-
批准号:1217387
-
项目类别:Standard Grant
-
资助金额:$22.0万
-
财政年份:2012
-
负责人:Yingying Chen
-
依托单位:
CAREER: EASE: Enhancing the Security of Pervasive Wireless Networks by Exploiting Location
-
批准号:0954020
-
项目类别:Continuing Grant
-
资助金额:$48.88万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
NeTSE:Small:Collaborative Research: MILAN: Multi-Modal Passive Intrusion Learning in Pervasive Wireless Environments
-
批准号:1018270
-
项目类别:Standard Grant
-
资助金额:$24.8万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
CSR: Small: Collaborative Research: SEMOIS: Secure Mobile Information Sharing System
-
批准号:1016303
-
项目类别:Standard Grant
-
资助金额:$19.69万
-
财政年份:2010
-
负责人:Yingying Chen
-
依托单位:
SGER: Securing Spectrum Usage in Future Radio Systems
-
批准号:0847211
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2008
-
负责人:Yingying Chen
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: