arXiv:2412.20529cs.CRcs.AI2024-12

研究音频神经网络的攻击与防御方法,评估多种攻击和防护手段效果

Attacks on the neural network and defense methods

  • 采用FGSM、PGD、CW等攻击方法测试模型鲁棒性
  • 数据中毒攻击使模型准确率下降至41.3%
  • 使用Art-IBM和advertorch提升防御能力,最高恢复至86.7%准确率

本文探讨了针对训练于音频数据的神经网络的攻击方法及其防御策略。研究涵盖了快速梯度符号法(FGSM)、投影梯度下降(PGD)和卡梅隆-沃尔夫(CW)攻击,以及数据污染攻击。在防御方面,分析了Art-IBM和advertorch两个开源库的防护效果。实验结果表明,在不同攻击下,模型准确率显著下降,其中数据中毒攻击导致准确率降至41.3%;而通过引入防御机制,最高可将准确率恢复至86.7%,验证了防御工具的有效性。

原文摘要 · Abstract (English)

This article will discuss the use of attacks on a neural network trained on audio data, as well as possible methods of protection against these attacks. FGSM, PGD and CW attacks, as well as data poisoning, will be considered. Within the framework of protection, Art-IBM and advertorch libraries will be considered. The obtained accuracy metrics within the framework of attack applications are presented

神经网络攻击音频安全对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。