Transferable Adversarial Attacks Against ASR

被引:0
|
作者
Gao, Xiaoxue [1 ]
Li, Zexin [2 ]
Chen, Yiming [3 ]
Liu, Cong [2 ]
Li, Haizhou [4 ]
机构
[1] ASTAR, Inst Infocomm Res, Singapore 138632, Singapore
[2] Univ Calif Riverside, Riverside, CA 92521 USA
[3] Natl Univ Singapore, Singapore 117583, Singapore
[4] Chinese Univ Hong Kong, Shenzhen Res Inst Big Data, Shenzhen 518172, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial attacks; speech recognition; SPEECH RECOGNITION;
D O I
10.1109/LSP.2024.3443711
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Given the extensive research and real-world applications of automatic speech recognition (ASR), ensuring the robustness of ASR models against minor input perturbations becomes a crucial consideration for maintaining their effectiveness in real-time scenarios. Previous explorations into ASR model robustness have predominantly revolved around evaluating accuracy on white-box settings with full access to ASR models. Nevertheless, full ASR model details are often not available in real-world applications. Therefore, evaluating the robustness of black-box ASR models is essential for a comprehensive understanding of ASR model resilience. In this regard, we thoroughly study the vulnerability of practical black-box attacks in cutting-edge ASR models and propose to employ two advanced time-domain-based transferable attacks alongside our differentiable feature extractor. We also propose a speech-aware gradient optimization approach (SAGO) for ASR, which forces mistranscription with minimal impact on human imperceptibility through voice activity detection rule and a speech-aware gradient-oriented optimizer. Our comprehensive experimental results reveal performance enhancements compared to baseline approaches across five models on two databases.
引用
收藏
页码:2200 / 2204
页数:5
相关论文
共 50 条
  • [21] Channel-augmented joint transformation for transferable adversarial attacks
    Desheng Zheng
    Wuping Ke
    Xiaoyu Li
    Shibin Zhang
    Guangqiang Yin
    Weizhong Qian
    Yong Zhou
    Fan Min
    Shan Yang
    Applied Intelligence, 2024, 54 : 428 - 442
  • [22] Robust and transferable end-to-end navigation against disturbances and external attacks: an adversarial training approach
    Zhang, Zhiwei
    Nair, Saasha
    Liu, Zhe
    Miao, Yanzi
    Ma, Xiaoping
    ROBOTIC INTELLIGENCE AND AUTOMATION, 2024, 44 (03): : 351 - 365
  • [23] AutoMA: Towards Automatic Model Augmentation for Transferable Adversarial Attacks
    Yuan, Haojie
    Chu, Qi
    Zhu, Feng
    Zhao, Rui
    Liu, Bin
    Yu, Nenghai
    IEEE TRANSACTIONS ON MULTIMEDIA, 2023, 25 : 203 - 213
  • [24] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424
  • [25] Prompt-Driven Contrastive Learning for Transferable Adversarial Attacks
    Yang, Hunmin
    Jeong, Jongoh
    Yoon, Kuk-Jin
    COMPUTER VISION-ECCV 2024, PT XLIII, 2025, 15101 : 36 - 53
  • [26] ATTA: Adversarial Task -transferable Attacks on Autonomous Driving Systems
    Hang, Qingjie
    Hang, Maosen
    Qiu, Han
    Hang, Tianwei
    Msahli, Mounira
    Memmi, Gerard
    23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 798 - 807
  • [27] DIVERSE GENERATIVE PERTURBATIONS ON ATTENTION SPACE FOR TRANSFERABLE ADVERSARIAL ATTACKS
    Kim, Woo Jae
    Hong, Seunghoon
    Yoon, Sung-Eui
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 281 - 285
  • [28] Towards transferable adversarial attacks on vision transformers for image classification
    Guo, Xu
    Chen, Peng
    Lu, Zhihui
    Chai, Hongfeng
    Du, Xin
    Wu, Xudong
    JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 152
  • [29] Text Adversarial Purification as Defense against Adversarial Attacks
    Li, Linyang
    Song, Demin
    Qiu, Xipeng
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 338 - 350
  • [30] Adversarial Stylometry in the Wild: Transferable Lexical Substitution Attacks on Author Profiling
    Emmery, Chris
    Kadar, Akos
    Chrupala, Grzegorz
    16TH CONFERENCE OF THE EUROPEAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (EACL 2021), 2021, : 2388 - 2402