paper-with-me

홈 › Papers

QFA2SR: Query-Free Adversarial Transfer Attacks to Speaker Recognition Systems

2023-05-23 · Guangke Chen, Yedi Zhang, Zhe Zhao, Fu Song

Current adversarial attacks against speaker recognition systems (SRSs) require either white-box access or heavy black-box queries to the target SRS, thus still falling behind practical attacks against proprietary commercial APIs and voice-controlled devices. To fill this gap, we propose QFA2SR, an effective and imperceptible query-free black-box attack, by leveraging the transferability of adversarial voices. To improve transferability, we present three novel methods, tailored loss functions, SRS ensemble, and time-freq corrosion. The first one tailors loss functions to different attack scenarios. The latter two augment surrogate SRSs in two different ways. SRS ensemble combines diverse surrogate SRSs with new strategies, amenable to the unique scoring characteristics of SRSs. Time-freq corrosion augments surrogate SRSs by incorporating well-designed time-/frequency-domain modification functions, which simulate and approximate the decision boundary of the target SRS and distortions introduced during over-the-air attacks. QFA2SR boosts the targeted transferability by 20.9%-70.7% on four popular commercial APIs (Microsoft Azure, iFlytek, Jingdong, and TalentedSoft), significantly outperforming existing attacks in query-free setting, with negligible effect on the imperceptibility. QFA2SR is also highly effective when launched over the air against three wide-spread voice assistants (Google Assistant, Apple Siri, and TMall Genie) with 60%, 46%, and 70% targeted transferability, respectively.

📄 PDF Abstract BibTeX arXiv:2305.14097

Code (0)

등록된 구현이 없습니다.

Tasks

Speaker Recognition

Methods 이 논문이 사용한 방법론

SRS Sticker Response Selector, or SRS, is a model for multi-turn dialog that automatically selects a sticker response. SRS first employs a convolutional based sticker image…

Similar Papers 제목 키워드 기반

Improving Black-box Adversarial Attacks with a Transfer-based Prior

2019-06-17 · NeurIPS 2019 12 · Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su 외

We consider the black-box adversarial setting, where the adversary has to generate adversarial perturbations without access to the target models to compute gradients. Previous methods tried to approximate the gradient ei…

Adversarial Attacks on GMM i-vector based Speaker Verification Systems

2019-11-08 · Xu Li, Jinghua Zhong, Xixin Wu, Jianwei Yu 외

This work investigates the vulnerability of Gaussian Mixture Model (GMM) i-vector based speaker verification systems to adversarial attacks, and the transferability of adversarial samples crafted from GMM i-vector based …

Speaker Verification

Query-Efficient Black-box Adversarial Attacks Guided by a Transfer-based Prior

2022-03-13 · Yinpeng Dong, Shuyu Cheng, Tianyu Pang, Hang Su 외

Adversarial attacks have been extensively studied in recent years since they can identify the vulnerability of deep learning models before deployed. In this paper, we consider the black-box adversarial setting, where the…

Query-Free Adversarial Transfer via Undertrained Surrogates

2020-07-01 · Chris Miller, Soroush Vosoughi

Deep neural networks are vulnerable to adversarial examples -- minor perturbations added to a model's input which cause the model to output an incorrect prediction. We introduce a new method for improving the efficacy of…

Adversarial Attack

Target Model Agnostic Adversarial Attacks with Query Budgets on Language Understanding Models

2021-06-13 · Jatin Chauhan, Karan Bhukar, Manohar Kaul

Despite significant improvements in natural language understanding models with the advent of models like BERT and XLNet, these neural-network based classifiers are vulnerable to blackbox adversarial attacks, where the at…

Adversarial AttackNatural Language Understanding