Did you hear that? Adversarial Examples Against Automatic Speech Recognition
arXiv:1801.00554
Abstract
Speech is a common and effective way of communication between humans, and modern consumer devices such as smartphones and home hubs are equipped with deep learning based accurate automatic speech recognition to enable natural interaction between humans and machines. Recently, researchers have demonstrated powerful attacks against machine learning models that can fool them to produceincorrect results. However, nearly all previous research in adversarial attacks has focused on image recognition and object detection models. In this short paper, we present a first of its kind demonstration of adversarial attacks against speech classification model. Our algorithm performs targeted attacks with 87% success by adding small background noise without having to know the underlying model parameter and architecture. Our attack only changes the least significant bits of a subset of audio clip samples, and the noise does not change 89% the human listener's perception of the audio clip as evaluated in our human study.
Published in NIPS 2017 Machine Deception workshop
References in corpus (1)
Cited by in corpus (23)
- Adversarial Examples in Modern Machine Learning: A Review
- Noise Flooding for Detecting Audio Adversarial Examples Against Automatic Speech Recognition
- Adversarial Machine Learning And Speech Emotion Recognition: Utilizing Generative Adversarial Networks For Robustness
- Semantics and explanation: why counterfactual explanations produce adversarial examples in deep neural networks
- Perceptual Based Adversarial Audio Attacks
- Adversarial attacks on Copyright Detection Systems
- Adversarial Learning of Deepfakes in Accounting
- WaveGuard: Understanding and Mitigating Audio Adversarial Examples
- Real-Time Adversarial Attacks
- SEC4SR: A Security Analysis Platform for Speaker Recognition
- Grey-box Adversarial Attack And Defence For Sentiment Classification
- Stealthy and Efficient Adversarial Attacks against Deep Reinforcement Learning
- LanCe: A Comprehensive and Lightweight CNN Defense Methodology against Physical Adversarial Attacks on Embedded Multimedia Applications
- Adversarial Example Detection by Classification for Deep Speech Recognition
- Towards Query-Efficient Black-Box Adversary with Zeroth-Order Natural Gradient Descent
- PICA: A Pixel Correlation-based Attentional Black-box Adversarial Attack
- A Tandem Framework Balancing Privacy and Security for Voice User Interfaces
- Exploring Targeted Universal Adversarial Perturbations to End-to-end ASR Models
- A GAN-based Approach for Mitigating Inference Attacks in Smart Home Environment
- Practical Attacks on Voice Spoofing Countermeasures
- Context-Aware Image Denoising with Auto-Threshold Canny Edge Detection to Suppress Adversarial Perturbation
- Self-Gradient Networks
- Learning to fool the speaker recognition