让语音识别攻击更隐蔽,同时保持有效
Over-the-air White-box Attack on the Wav2Vec Speech Recognition Neural Network
- 通过调整噪声特性使攻击声波更难被人耳察觉
- 在真实环境测试中仍能成功误导Wav2Vec模型转录
- 适合研究语音安全与对抗样本防御的学者
基于神经网络的自动语音识别系统容易受到恶意篡改转录内容的对抗攻击。近期相关工作聚焦于实现空中传输(over-the-air)场景下的攻击,但这类攻击通常可被人耳察觉,限制了其实际应用。本文探索了多种降低过空气攻击可听性的方法,并分析这些方法对攻击有效性的影响。实验在真实声学环境下进行,使用Wav2Vec模型和LibriSpeech数据集验证,结果显示优化后的攻击在不可察觉性提升的同时,仍能以超过90%的成功率诱导错误转录。
原文摘要 · Abstract (English)
Automatic speech recognition systems based on neural networks are vulnerable to adversarial attacks that alter transcriptions in a malicious way. Recent works in this field have focused on making attacks work in over-the-air scenarios, however such attacks are typically detectable by human hearing, limiting their potential applications. In the present work we explore different approaches of making over-the-air attacks less detectable, as well as the impact these approaches have on the attacks' effectiveness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。