Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition

被引:0
|
作者
Li, Zhuhai [1 ]
Zhang, Jie [1 ]
Guo, Wu [1 ]
Wu, Haochen [1 ]
机构
[1] Univ Sci & Technol China, NERC SLIP, Hefei, Peoples R China
来源
关键词
Adversarial examples; transferability; ensemble attack; speaker recognition;
D O I
10.21437/Interspeech.2024-346
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the black-box attack for speaker recognition systems, the adversarial examples can exhibit better transferability for unseen victim system if they can consistently spoof an ensemble of substitute models. In this work, we propose a gradient-aligned ensemble attack method to find the optimal gradient direction to update the adversarial example using a set of substitute models. Specifically, we first calculate the overfitting-reduced gradient for each substitute model by randomly masking some regions of the input acoustic features. Then we obtain the weight of the gradient for each substitute model based on the consistency of its gradient with respect to others. The final update gradient is calculated by the weighted sum of the gradients over all substitute models. Experimental results on the VoxCeleb dataset verify the effectiveness of the proposed approach for the speaker identification and speaker verification tasks.
引用
收藏
页码:532 / 536
页数:5
相关论文
共 50 条
  • [21] Improving transferability of adversarial examples with powerful affine-shear transformation attack
    Wang, Xiaotong
    Huang, Chunguang
    Cheng, Hai
    COMPUTER STANDARDS & INTERFACES, 2023, 84
  • [22] Towards Understanding and Mitigating Audio Adversarial Examples for Speaker Recognition
    Chen, Guangke
    Zhao, Zhe
    Song, Fu
    Chen, Sen
    Fan, Lingling
    Wang, Feng
    Wang, Jiashui
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3970 - 3987
  • [23] Adversarial Attack and Defense Strategies of Speaker Recognition Systems: A Survey
    Tan, Hao
    Wang, Le
    Zhang, Huan
    Zhang, Junjian
    Shafiq, Muhammad
    Gu, Zhaoquan
    ELECTRONICS, 2022, 11 (14)
  • [24] Adversarial attack and defense strategies for deep speaker recognition systems
    Jati, Arindam
    Hsu, Chin-Cheng
    Pal, Monisankha
    Peri, Raghuveer
    AbdAlmageed, Wael
    Narayanan, Shrikanth
    COMPUTER SPEECH AND LANGUAGE, 2021, 68
  • [25] Improving adversarial transferability by temporal and spatial momentum in urban speaker recognition systems
    Tan, Hao
    Gu, Zhaoquan
    Wang, Le
    Zhang, Huan
    Gupta, Brij B.
    Tian, Zhihong
    COMPUTERS & ELECTRICAL ENGINEERING, 2022, 104
  • [26] Adaptive Multi-scale Degradation-Based Attack for Boosting the Adversarial Transferability
    Ran, Ran
    Wei, Jiwei
    Zhang, Chaoning
    Wang, Guoqing
    Yang, Yang
    Shen, Heng Tao
    IEEE TRANSACTIONS ON MULTIMEDIA, 2024, 26 : 10979 - 10990
  • [27] Enhance Domain-Invariant Transferability of Adversarial Examples via Distance Metric Attack
    Zhang, Jin
    Peng, Wenyu
    Wang, Ruxin
    Lin, Yu
    Zhou, Wei
    Lan, Ge
    MATHEMATICS, 2022, 10 (08)
  • [28] Optimized Gradient Boosting Black-Box Adversarial Attack Algorithm
    Liu, Mengting
    Ling, Jie
    Computer Engineering and Applications, 2023, 59 (18) : 260 - 267
  • [29] GNP ATTACK: TRANSFERABLE ADVERSARIAL EXAMPLES VIA GRADIENT NORM PENALTY
    Wu, Tao
    Luo, Tie
    Wunsch, Donald C.
    2023 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2023, : 3110 - 3114
  • [30] Push the Limit of Adversarial Example Attack on Speaker Recognition in Physical Domain
    Chen, Qianniu
    Chen, Meng
    Lu, Li
    Yu, Jiadi
    Chen, Yingying
    Wang, Zhibo
    Ba, Zhongjie
    Lin, Feng
    Ren, Kui
    PROCEEDINGS OF THE TWENTIETH ACM CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS, SENSYS 2022, 2022, : 710 - 724