通过微小音频扰动攻击语音翻译系统,诱导其生成恶意翻译。
Exploiting Vulnerabilities in Speech Translation Systems through Targeted Adversarial Attacks
- 在源音频中注入不可察觉的扰动,误导翻译模型输出目标文本。
- 生成对抗性音乐可更隐蔽地实现目标翻译,跨语言效果显著。
- 揭示当前语音翻译系统普遍存在鲁棒性缺陷,适合安全与语音研究者参考。
随着语音翻译(ST)系统日益普及,理解其脆弱性对确保通信的稳健可靠至关重要。然而,现有研究对此关注有限。本文探索通过不可感知的音频扰动破坏此类系统的方法,提出两种新方案:(1) 向源音频注入扰动,(2) 生成对抗性音乐以引导目标翻译,并在真实物理环境中开展更具实用性的过空气攻击。实验表明,精心设计的音频扰动可使翻译模型产生目标性有害输出;而对抗性音乐因音乐本身天然不可察觉,隐蔽性更强。这些攻击在多种语言和翻译模型上均有效,暴露了当前ST架构中的系统性漏洞。研究意义不仅限于安全威胁,还为神经语音处理系统的可解释性与鲁棒性提供了洞见。结果强调需发展先进防御机制与更鲁棒的音频系统架构。更多信息与样本详见 https://adv-st.github.io。
原文摘要 · Abstract (English)
As speech translation (ST) systems become increasingly prevalent, understanding their vulnerabilities is crucial for ensuring robust and reliable communication. However, limited work has explored this issue in depth. This paper explores methods of compromising these systems through imperceptible audio manipulations. Specifically, we present two innovative approaches: (1) the injection of perturbation into source audio, and (2) the generation of adversarial music designed to guide targeted translation, while also conducting more practical over-the-air attacks in the physical world. Our experiments reveal that carefully crafted audio perturbations can mislead translation models to produce targeted, harmful outputs, while adversarial music achieve this goal more covertly, exploiting the natural imperceptibility of music. These attacks prove effective across multiple languages and translation models, highlighting a systemic vulnerability in current ST architectures. The implications of this research extend beyond immediate security concerns, shedding light on the interpretability and robustness of neural speech processing systems. Our findings underscore the need for advanced defense mechanisms and more resilient architectures in the realm of audio systems. More details and samples can be found at https://adv-st.github.io.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。