噪声增强训练能同时提升语音识别模型的抗干扰与抗攻击能力。
Comparative Study on Noise-Augmented Training and its Effect on Adversarial Robustness in ASR Systems
- 在三种不同数据增强条件下对比四种语音识别模型的鲁棒性。
- 加入背景噪声后,模型在噪声语音上的表现和抗对抗攻击能力均提升。
- 适合关注语音系统安全性的研究者与工程师参考。
本研究探讨噪声增强训练是否能同时提升自动语音识别(ASR)系统的对抗鲁棒性。我们对四种不同架构的ASR模型,在三种数据增强条件下进行训练:(1) 背景噪声、语速变化和混响;(2) 仅语速变化;(3) 无数据增强。随后评估所有模型在白盒与黑盒对抗样本下的鲁棒性。结果表明,引入背景噪声不仅能改善模型在嘈杂语音上的性能,还能显著提升其对抗攻击的防御能力。
原文摘要 · Abstract (English)
In this study, we investigate whether noise-augmented training can concurrently improve adversarial robustness in automatic speech recognition (ASR) systems. We conduct a comparative analysis of the adversarial robustness of four different ASR architectures, each trained under three different augmentation conditions: (1) background noise, speed variations, and reverberations; (2) speed variations only; (3) no data augmentation. We then evaluate the robustness of all resulting models against attacks with white-box or black-box adversarial examples. Our results demonstrate that noise augmentation not only enhances model performance on noisy speech but also improves the model's robustness to adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。