Defending against FakeBob Adversarial Attacks in Speaker Verification Systems with Noise-Adding

被引:5
|
作者
Chen, Zesheng [1 ]
Chang, Li-Chi [1 ]
Chen, Chao [1 ]
Wang, Guoping [1 ]
Bi, Zhuming [1 ]
机构
[1] Purdue Univ Ft Wayne, Coll Engn Technol & Comp Sci, Ft Wayne, IN 46805 USA
关键词
speaker verification; FakeBob adversarial attacks; defense system; denoising; noiseadding; adaptive attacks; RECOGNITION; DEFENSES;
D O I
10.3390/a15080293
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Speaker verification systems use human voices as an important biometric to identify legitimate users, thus adding a security layer to voice-controlled Internet-of-things smart homes against illegal access. Recent studies have demonstrated that speaker verification systems are vulnerable to adversarial attacks such as FakeBob. The goal of this work is to design and implement a simple and light-weight defense system that is effective against FakeBob. We specifically study two opposite pre-processing operations on input audios in speak verification systems: denoising that attempts to remove or reduce perturbations and noise-adding that adds small noise to an input audio. Through experiments, we demonstrate that both methods are able to weaken the ability of FakeBob attacks significantly, with noise-adding achieving even better performance than denoising. Specifically, with denoising, the targeted attack success rate of FakeBob attacks can be reduced from 100% to 56.05% in GMM speaker verification systems, and from 95% to only 38.63% in i-vector speaker verification systems, respectively. With noise adding, those numbers can be further lowered down to 5.20% and 0.50%, respectively. As a proactive measure, we study several possible adaptive FakeBob attacks against the noise-adding method. Experiment results demonstrate that noise-adding can still provide a considerable level of protection against these countermeasures.
引用
收藏
页数:20
相关论文
共 50 条
  • [21] DEFENDING GRAPH CONVOLUTIONAL NETWORKS AGAINST ADVERSARIAL ATTACKS
    Ioannidis, Vassilis N.
    Giannakis, Georgios B.
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 8469 - 8473
  • [22] Defending Deep Learning Models Against Adversarial Attacks
    Mani, Nag
    Moh, Melody
    Moh, Teng-Sheng
    INTERNATIONAL JOURNAL OF SOFTWARE SCIENCE AND COMPUTATIONAL INTELLIGENCE-IJSSCI, 2021, 13 (01): : 72 - 89
  • [23] Defending Against Adversarial Attacks Using Random Forest
    Ding, Yifan
    Wang, Liqiang
    Zhang, Huan
    Yi, Jinfeng
    Fan, Deliang
    Gong, Boqing
    2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2019), 2019, : 105 - 114
  • [24] Defending Adversarial Attacks against DNN Image Classification Models by a Noise-Fusion Method
    Shi, Lin
    Liao, Teyi
    He, Jianfeng
    ELECTRONICS, 2022, 11 (12)
  • [25] On the Effectiveness of Adversarial Training in Defending against Adversarial Example Attacks for Image Classification
    Park, Sanglee
    So, Jungmin
    APPLIED SCIENCES-BASEL, 2020, 10 (22): : 1 - 16
  • [26] Evidential classification for defending against adversarial attacks on network traffic
    Beechey, Matthew
    Lambotharan, Sangarapillai
    Kyriakopoulos, Konstantinos G.
    INFORMATION FUSION, 2023, 92 : 115 - 126
  • [27] DiffDefense: Defending Against Adversarial Attacks via Diffusion Models
    Silva, Hondamunige Prasanna
    Seidenari, Lorenzo
    Del Bimbo, Alberto
    IMAGE ANALYSIS AND PROCESSING, ICIAP 2023, PT II, 2023, 14234 : 430 - 442
  • [28] Defending Against Adversarial Attacks via Neural Dynamic System
    Li, Xiyuan
    Zou, Xin
    Liu, Weiwei
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [29] Defending non-Bayesian learning against adversarial attacks
    Lili Su
    Nitin H. Vaidya
    Distributed Computing, 2019, 32 : 277 - 289
  • [30] Defending Wireless Receivers Against Adversarial Attacks on Modulation Classifiers
    de Araujo-Filho, Paulo Freitas
    Kaddoum, Georges
    Chiheb Ben Nasr, Mohamed
    Arcoverde, Henrique F.
    Campelo, Divanilson R.
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (21) : 19153 - 19162