基于多目标进化优化的自动语音识别系统对抗黑盒攻击
密码学与安全
2019-07-04 v2 机器学习
神经与进化计算
摘要
利用对抗样本欺骗深度神经网络,已暴露出当前多个领域最先进系统的显著漏洞。黑盒与白盒方法均被用于复现模型本身或构造使模型失效的样例。本工作中,我们提出一种利用多目标进化优化对自动语音识别(ASR)系统实施有目标与无目标黑盒攻击的框架。我们将该框架应用于 Deepspeech 与 Kaldi-ASR 两个 ASR 系统,将其词错误率(WER)提升至最高 980%,表明了我们方法的有效性。在有目标与无目标攻击中,对抗样本分别与原始音频保持 0.98 与 0.97 的高声学相似度。
引用
@article{arxiv.1811.01312,
title = {Adversarial Black-Box Attacks on Automatic Speech Recognition Systems using Multi-Objective Evolutionary Optimization},
author = {Shreya Khare and Rahul Aralikatte and Senthil Mani},
journal= {arXiv preprint arXiv:1811.01312},
year = {2019}
}
备注
Published in Interspeech 2019