Defending against FakeBob Adversarial Attacks in Speaker Verification Systems with Noise-Adding

被引:5
|
作者
Chen, Zesheng [1 ]
Chang, Li-Chi [1 ]
Chen, Chao [1 ]
Wang, Guoping [1 ]
Bi, Zhuming [1 ]
机构
[1] Purdue Univ Ft Wayne, Coll Engn Technol & Comp Sci, Ft Wayne, IN 46805 USA
关键词
speaker verification; FakeBob adversarial attacks; defense system; denoising; noiseadding; adaptive attacks; RECOGNITION; DEFENSES;
D O I
10.3390/a15080293
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Speaker verification systems use human voices as an important biometric to identify legitimate users, thus adding a security layer to voice-controlled Internet-of-things smart homes against illegal access. Recent studies have demonstrated that speaker verification systems are vulnerable to adversarial attacks such as FakeBob. The goal of this work is to design and implement a simple and light-weight defense system that is effective against FakeBob. We specifically study two opposite pre-processing operations on input audios in speak verification systems: denoising that attempts to remove or reduce perturbations and noise-adding that adds small noise to an input audio. Through experiments, we demonstrate that both methods are able to weaken the ability of FakeBob attacks significantly, with noise-adding achieving even better performance than denoising. Specifically, with denoising, the targeted attack success rate of FakeBob attacks can be reduced from 100% to 56.05% in GMM speaker verification systems, and from 95% to only 38.63% in i-vector speaker verification systems, respectively. With noise adding, those numbers can be further lowered down to 5.20% and 0.50%, respectively. As a proactive measure, we study several possible adaptive FakeBob attacks against the noise-adding method. Experiment results demonstrate that noise-adding can still provide a considerable level of protection against these countermeasures.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] GNNGUARD: Defending Graph Neural Networks against Adversarial Attacks
    Zhang, Xiang
    Zitnik, Marinka
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [32] Defending against Whitebox Adversarial Attacks via Randomized Discretization
    Zhang, Yuchen
    Liang, Percy
    22ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 89, 2019, 89 : 684 - 693
  • [33] Defending non-Bayesian learning against adversarial attacks
    Su, Lili
    Vaidya, Nitin H.
    DISTRIBUTED COMPUTING, 2019, 32 (04) : 277 - 289
  • [34] x-Vectors Meet Adversarial Attacks: Benchmarking Adversarial Robustness in Speaker Verification
    Villalba, Jesus
    Zhang, Yuekai
    Dehak, Najim
    INTERSPEECH 2020, 2020, : 4233 - 4237
  • [35] REAL-TIME, UNIVERSAL, AND ROBUST ADVERSARIAL ATTACKS AGAINST SPEAKER RECOGNITION SYSTEMS
    Xie, Yi
    Shi, Cong
    Lie, Zhuohang
    Liu, Jian
    Chen, Yingying
    Yuan, Bo
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 1738 - 1742
  • [36] Preventing Replay Attacks on Speaker Verification Systems
    Villalba, Jesus
    Lleida, Eduardo
    2011 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2011,
  • [37] Representation Learning to Classify and Detect Adversarial Attacks against Speaker and Speech Recognition Systems
    Villalba, Jesus
    Joshi, Sonal
    Zelasko, Piotr
    Dehak, Najim
    INTERSPEECH 2021, 2021, : 4304 - 4308
  • [38] Adversarial attacks and defenses in Speaker Recognition Systems: A survey
    Lan, Jiahe
    Zhang, Rui
    Yan, Zheng
    Wang, Jie
    Chen, Yu
    Hou, Ronghui
    JOURNAL OF SYSTEMS ARCHITECTURE, 2022, 127
  • [39] Adversarial Network Bottleneck Features for Noise Robust Speaker Verification
    Yu, Hong
    Tan, Zheng-Hua
    Ma, Zhanyu
    Guo, Jun
    18TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2017), VOLS 1-6: SITUATED INTERACTION, 2017, : 1492 - 1496
  • [40] UltraBD: Backdoor Attack against Automatic Speaker Verification Systems via Adversarial Ultrasound
    Ze, Junning
    Li, Xinfeng
    Cheng, Yushi
    Ji, Xiaoyu
    Xu, Wenyuan
    2022 IEEE 28TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, ICPADS, 2022, : 193 - 200