arXiv:2508.09994cs.SDcs.CR2025-08

提出部分抑制攻击,让语音识别模型误听更隐蔽。

Whisper Smarter, not Harder: Adversarial Attack on Partial Suppression

  • 将攻击目标从完全抑制改为部分抑制,提升隐蔽性
  • 实验证明部分抑制攻击在人耳难察觉下仍有效
  • 低通滤波可作为有效防御手段,适合安全应用

当前自动语音识别(ASR)模型广泛部署于各类应用场景。然而,近期研究已证实对这些模型的对抗攻击可能抑制或扰乱模型输出。本文研究并验证了此类攻击的鲁棒性,探索是否可进一步提升攻击的不可察觉性。发现若将优化目标从完全抑制放松为部分抑制,攻击的不可察觉性可进一步降低。同时,本文还探讨了可能的防御方案,结果表明低通滤波防御可能具有实际效果。

原文摘要 · Abstract (English)

Currently, Automatic Speech Recognition (ASR) models are deployed in an extensive range of applications. However, recent studies have demonstrated the possibility of adversarial attack on these models which could potentially suppress or disrupt model output. We investigate and verify the robustness of these attacks and explore if it is possible to increase their imperceptibility. We additionally find that by relaxing the optimisation objective from complete suppression to partial suppression, we can further decrease the imperceptibility of the attack. We also explore possible defences against these attacks and show a low-pass filter defence could potentially serve as an effective defence.

语音识别对抗攻击隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。