针对 ASV 欺骗 countermeasures 对抗攻击的防御
音频与语音处理
2020-03-09 v1 机器学习
声音
摘要
ASVspoof 2019 挑战赛中提出了多种在反欺骗方面具有可观性能的前沿自动说话人验证(ASV)countermeasure 方法。然而,先前工作表明 countermeasure 模型易受与自然数据难以区分的对抗样本的攻击。一个好的 countermeasure 模型不仅应鲁棒于包括合成、转换与重放音频在内的欺骗音频,还应抵御恶意攻击者蓄意生成的样本。本工作中,我们引入一种被动防御方法——空间平滑,以及一种主动防御方法——对抗训练,以缓解 ASV 欺骗 countermeasure 模型面对对抗样本的脆弱性。本文是最早使用防御方法提升对抗攻击下 ASV 欺骗 countermeasure 模型鲁棒性的工作之一。实验结果表明,这两种防御方法能有效帮助欺骗 countermeasure 模型对抗对抗样本。
引用
@article{arxiv.2003.03065,
title = {Defense against adversarial attacks on spoofing countermeasures of ASV},
author = {Haibin Wu and Songxiang Liu and Helen Meng and Hung-yi Lee},
journal= {arXiv preprint arXiv:2003.03065},
year = {2020}
}
备注
Accepted by ICASSP 2020