arXiv:2502.09782cs.LGcs.AI2025-02被引 2

用Transformer和大模型提升键盘声波窃密精度,实测效果超前人5%以上。

Improving Acoustic Side-Channel Attacks on Keyboards Using Transformers and Large Language Models

  • 结合视觉变压器与大语言模型,提升键盘敲击声识别准确率。
  • 手机录音场景下提升5.0%,Zoom录音提升5.9%,达当前最优。
  • 用大模型纠错降噪,轻量模型仅需原模型1/67参数仍有效。

随着麦克风在日常设备中的普及及对在线服务的依赖加剧,针对键盘的声学侧信道攻击(ASCA)风险日益上升。本研究探索深度学习技术,特别是视觉变换器(VTs)和大语言模型(LLMs),以增强此类攻击的有效性与实用性。我们提出的新模型CoAtNet在智能手机录制(Phone)场景下较先前基准提升5.0%,在Zoom录制场景下提升5.9%,达到当前最佳性能。同时评估了多种变换器架构与语言模型,最佳视觉变换器模型性能与CoAtNet相当。关键突破在于引入噪声缓解方法:利用大语言模型进行上下文理解,识别并纠正嘈杂环境中的错误输入,显著提升攻击鲁棒性。此外,经低秩适配(LoRA)微调的轻量级语言模型,仅需重型模型67倍更少参数即可达到相近效果。该技术融合首次应用于真实场景下的ASCA防御与错误校正,极大提升了攻击的实用价值。

原文摘要 · Abstract (English)

The increasing prevalence of microphones in everyday devices and the growing reliance on online services have amplified the risk of acoustic side-channel attacks (ASCAs) targeting keyboards. This study explores deep learning techniques, specifically vision transformers (VTs) and large language models (LLMs), to enhance the effectiveness and applicability of such attacks. We present substantial improvements over prior research, with the CoAtNet model achieving state-of-the-art performance. Our CoAtNet shows a 5.0% improvement for keystrokes recorded via smartphone (Phone) and 5.9% for those recorded via Zoom compared to previous benchmarks. We also evaluate transformer architectures and language models, with the best VT model matching CoAtNet's performance. A key advancement is the introduction of a noise mitigation method for real-world scenarios. By using LLMs for contextual understanding, we detect and correct erroneous keystrokes in noisy environments, enhancing ASCA performance. Additionally, fine-tuned lightweight language models with Low-Rank Adaptation (LoRA) deliver comparable performance to heavyweight models with 67X more parameters. This integration of VTs and LLMs improves the practical applicability of ASCA mitigation, marking the first use of these technologies to address ASCAs and error correction in real-world scenarios.

声学攻击大模型键盘安全噪声抑制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。