Symmetric Saliency-based Adversarial Attack To Speaker Identification
Adversarial attack approaches to speaker identification either need high computational cost or are not very effective, to our knowledge. To address this issue, in this paper, we propose a novel generation-network-based approach, called symmetric saliency-based encoder-decoder (SSED), to generate adversarial voice examples to speaker identification. It contains two novel components. First, it uses a novel saliency map decoder to learn the importance of speech samples to the decision of a targeted speaker identification system, so as to make the attacker focus on generating artificial noise to the important samples. It also proposes an angular loss function to push the speaker embedding far away from the source speaker. Our experimental results demonstrate that the proposed SSED yields the state-of-the-art performance, i.e. over 97% targeted attack success rate and a signal-to-noise level of over 39 dB on both the open-set and close-set speaker identification tasks, with a low computational cost.
Code (0)
등록된 구현이 없습니다.
Tasks
Adversarial AttackDecoderSpeaker IdentificationSimilar Papers 제목 키워드 기반
Discriminator-Free Generative Adversarial Attack
The Deep Neural Networks are vulnerable toadversarial exam-ples(Figure 1), making the DNNs-based systems collapsed byadding the inconspicuous perturbations to the images. Most of the existing works for adversarial attack…
Adversarial AttackDisentanglementGPUFoolHD: Fooling speaker identification by Highly imperceptible adversarial Disturbances
Speaker identification models are vulnerable to carefully designed adversarial perturbations of their input signals that induce misclassification. In this work, we propose a white-box steganography-inspired adversarial a…
Adversarial AttackSpeaker IdentificationUnraveling Adversarial Examples against Speaker Identification -- Techniques for Attack Detection and Victim Model Classification
Adversarial examples have proven to threaten speaker identification systems, and several countermeasures against them have been proposed. In this paper, we propose a method to detect the presence of adversarial examples,…
Adversarial AttackClassificationSpeaker IdentificationTubes Among Us: Analog Attack on Automatic Speaker Identification
Recent years have seen a surge in the popularity of acoustics-enabled personal devices powered by machine learning. Yet, machine learning has proven to be vulnerable to adversarial examples. A large number of modern syst…
BIG-bench Machine LearningSpeaker IdentificationRepresentation Learning to Classify and Detect Adversarial Attacks against Speaker and Speech Recognition Systems
Adversarial attacks have become a major threat for machine learning applications. There is a growing interest in studying these attacks in the audio domain, e.g, speech and speaker recognition; and find defenses against …
Representation LearningSpeaker IdentificationSpeaker RecognitionSpeaker Verification+2