课题基金 / 基金详情

Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks

Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks
协作研究:SaTC:核心:小型:在音频对抗攻击下保护物联网和边缘设备
批准号:
2114220
负责人:
Yingying Chen
金额:
$33.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-10-01 至 2024-09-30

项目摘要

项目成果

Yingying Chen的其他基金

相似基金

相关文献

中文摘要
翻译
在人工智能(AI)技术进步的推动下,下一代语音可控物联网和边缘系统极大地促进了人们的日常生活。这样的系统包括语音辅助系统和语音认证的移动的银行业务等。然而,这些系统中使用的底层机器学习方法本质上容易受到音频对抗性攻击,其中对手可以通过向原始音频输入注入不可感知的扰动来误导机器学习模型。鉴于语音可控物联网和边缘系统在许多隐私关键和安全关键应用中的广泛采用,例如,个人银行和自动驾驶,深入了解和调查基于音频的对抗性攻击的严重性和后果以及相应的防御解决方案,是非常有必要的。该项目将从时间和空间的角度对语音可控物联网和边缘系统在音频域对抗攻击中的脆弱性和鲁棒性进行全面的研究和分析。该项目的研究成果将为构建可信赖的语音可控物联网和边缘系统奠定坚实的基础。所开发的防御技术将提高许多智能音频系统的安全性,例如自动语音识别(ASR),关键字识别和说话人识别。该项目将通过各种吸引人的项目涉及代表性不足的学生,本科生和研究生以及K-12学生。该项目的目标是证明物理世界中音频对抗攻击的可行性,确定攻击的严重性和后果,并进一步制定实际环境中的防御策略,构建抗攻击、语音可控的物联网设备和边缘系统。为了研究在实际的时间限制设置下音频对抗攻击的可能性和严重性,该项目将开发低成本的音频不可知的无同步攻击发起方案,包括音频特定的快速对抗扰动发生器和通用对抗扰动发生器。 为了研究对抗性扰动如何在现实环境中经受住各种传播因素的影响,该项目将使用先进的房间脉冲响应模拟器和物理环境测量来分析空中传播引起的音频失真。该项目还将开发几种防御技术,包括防御性降噪,模型增强和基于麦克风阵列的活性检测。所提出的技术将有助于在音频对抗攻击下保护语音可控物联网和边缘设备。该项目还将为基于音频的对抗性机器学习在理论基础和面向安全的新兴应用中的新计算范式做出贡献。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估而被认为值得支持。
英文摘要
Powered by the advancement of artificial intelligence (AI) techniques, the next-generation voice-controllable IoT and edge systems have substantially facilitated people’s daily lives. Such systems include voice assistant systems and voice authenticated mobile banking, among many others. However, the underlying machine learning approaches used in these systems, are inherently vulnerable to audio adversarial attacks, in which an adversary can mislead the machine learning models via injecting imperceptible perturbation to the original audio input. Given the widespread adoption of voice-controllable IoT and edge systems in many privacy-critical and safety-critical applications, e.g., personal banking and autonomous driving, the in-depth understanding and investigation of severity and consequences of audio-based adversarial attack as well as the corresponding defense solutions, are highly demanded. This project will perform a comprehensive study and analysis of the vulnerability and robustness of voice-controllable IoT and edge systems against audio-domain adversarial attacks in both temporal and spatial perspectives. The research outcome of this project will form solid foundations for building trustworthy voice-controllable IoT and edge systems. The developed defense techniques will improve the security of many intelligent audio systems, such as automatic speech recognition (ASR), keyword spotting, and speaker recognition. This project will involve underrepresented students, undergraduate and graduate students, and K-12 students through a variety of engaging programs.The objective of this project is to demonstrate the feasibility of audio adversarial attacks in the physical world, determine the attack severity and consequences, and further develop defending strategies in practical environments to build attack-resilient voice-controllable Internet-of-Things (IoT) devices and edge systems. To study the possibility and severity of audio adversarial attacks in a practical time-constraint setting, the project will develop low-cost audio-agnostic synchronization-free attack launching schemes, including audio-specific fast adversarial perturbation generator and universal adversarial perturbation generator. To investigate how the adversarial perturbations survive various propagation factors in realistic environments, the project will analyze the audio distortions caused by the over-the-air propagation using an advanced room impulse response simulator and physical environment measurements. The project will also develop several defense techniques, including defensive denoiser, model enhancement, and microphone-array-based liveness detection. The presented technique will help to secure the voice-controllable IoT and edge devices under audio adversarial attacks. The project will also contribute to a new computing paradigm in audio-based adversarial machine learning in both theoretic foundations as well as safety-critical audio-oriented emerging applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/icassp43922.2022.9747582
发表时间: 2022-05
期刊: ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子: --
作者: [Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan]
通讯作者: Huy Phan;Yi Xie;Jian Liu;Yingying Chen;Bo Yuan
DOI: 10.1145/3460120.3484755
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen]
通讯作者: Zhuohang Li;Cong Shi;Tianfang Zhang;Yi Xie;Jian Liu;Bo Yuan;Yingying Chen
DOI: 10.1109/icccn58024.2023.10230152
发表时间: 2023-07
期刊: 2023 32nd International Conference on Computer Communications and Networks (ICCCN)
影响因子: --
作者: [Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen]
通讯作者: Tianming Zhao;Zijie Tang;Tian-Di Zhang;Huy Phan;Yan Wang;Cong Shi;Bo Yuan;Ying Chen
DOI: 10.1609/aaai.v37i9.26244
发表时间: 2023-01
期刊: ArXiv
影响因子: --
作者: [Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan]
通讯作者: Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan
6
    Collaborative Research: III: Small: Efficient and Robust Multi-model Data Analytics for Edge Computing
    • 批准号:
      2311596
    • 项目类别:
      Standard Grant
    • 资助金额:
      $24.0万
    • 财政年份:
      2023
    • 负责人:
      Yingying Chen
    • 依托单位:
    SHF: Small: A General Framework for Accelerating AI on Resource-Constrained Edge Devices
    • 批准号:
      2211163
    • 项目类别:
      Standard Grant
    • 资助金额:
      $60.0万
    • 财政年份:
      2022
    • 负责人:
      Yingying Chen
    • 依托单位:
    Collaborative Research: CCRI: New: Nation-wide Community-based Mobile Edge Sensing and Computing Testbeds
    • 批准号:
      2120396
    • 项目类别:
      Standard Grant
    • 资助金额:
      $71.0万
    • 财政年份:
      2021
    • 负责人:
      Yingying Chen
    • 依托单位:
    Collaborative Research: PPoSS: Planning: Hardware-accelerated Trustworthy Deep Neural Network
    • 批准号:
      2028876
    • 项目类别:
      Standard Grant
    • 资助金额:
      $7.0万
    • 财政年份:
      2020
    • 负责人:
      Yingying Chen
    • 依托单位:
    国内基金
    海外基金
    Research on Quantum Field Theory without a Lagrangian Description
    • 批准号:
      24ZR1403900
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      SATOSHI NAWATA
    • 依托单位:
    Cell Research
    Cell Research
    Cell Research (细胞研究)