Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition

被引:0
|
作者
Li, Zhuhai [1 ]
Zhang, Jie [1 ]
Guo, Wu [1 ]
Wu, Haochen [1 ]
机构
[1] Univ Sci & Technol China, NERC SLIP, Hefei, Peoples R China
来源
关键词
Adversarial examples; transferability; ensemble attack; speaker recognition;
D O I
10.21437/Interspeech.2024-346
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the black-box attack for speaker recognition systems, the adversarial examples can exhibit better transferability for unseen victim system if they can consistently spoof an ensemble of substitute models. In this work, we propose a gradient-aligned ensemble attack method to find the optimal gradient direction to update the adversarial example using a set of substitute models. Specifically, we first calculate the overfitting-reduced gradient for each substitute model by randomly masking some regions of the input acoustic features. Then we obtain the weight of the gradient for each substitute model based on the consistency of its gradient with respect to others. The final update gradient is calculated by the weighted sum of the gradients over all substitute models. Experimental results on the VoxCeleb dataset verify the effectiveness of the proposed approach for the speaker identification and speaker verification tasks.
引用
收藏
页码:532 / 536
页数:5
相关论文
共 50 条
  • [31] PhoneyTalker: An Out-of-the-Box Toolkit for Adversarial Example Attack on Speaker Recognition
    Chen, Meng
    Lu, Li
    Ba, Zhongjie
    Ren, Kui
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2022), 2022, : 1419 - 1428
  • [32] Spatial-frequency gradient fusion based model augmentation for high transferability adversarial attack
    Pang, Jingfa
    Yuan, Chengsheng
    Xia, Zhihua
    Li, Xinting
    Fu, Zhangjie
    KNOWLEDGE-BASED SYSTEMS, 2024, 301
  • [33] A New Ensemble Adversarial Attack Powered by Long-Term Gradient Memories
    Che, Zhaohui
    Borji, Ali
    Zhai, Guangtao
    Ling, Suiyi
    Li, Jing
    Min, Xiongkuo
    Guo, Guodong
    Le Callet, Patrick
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 3405 - 3413
  • [34] Scattering Model Guided Adversarial Examples for SAR Target Recognition: Attack and Defense
    Peng, Bowen
    Peng, Bo
    Zhou, Jie
    Xie, Jianyue
    Liu, Li
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
  • [35] Hierarchical feature transformation attack: Generate transferable adversarial examples for face recognition
    Li, Yuanbo
    Hu, Cong
    Wang, Rui
    Wu, Xiaojun
    APPLIED SOFT COMPUTING, 2025, 172
  • [36] Research on Gradient-Based Adversarial Attack Methods for Image Recognition
    Chen, Jun
    Zhou, Qiang
    Huang, Qi Dong
    Bao, Lei
    2024 5TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND APPLICATION, ICCEA 2024, 2024, : 957 - 963
  • [37] MUTEN: Mutant-Based Ensembles for Boosting Gradient-Based Adversarial Attack
    Hu, Qiang
    Guo, Yuejun
    Cordy, Maxime
    Papadakis, Mike
    Le Traon, Yves
    2023 38TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE, 2023, : 1708 - 1712
  • [38] Boosting Decision-Based Black-Box Adversarial Attack with Gradient Priors
    Liu, Han
    Huang, Xingshuo
    Zhang, Xiaotong
    Li, Qimai
    Ma, Fenglong
    Wang, Wei
    Chen, Hongyang
    Yu, Hong
    Zhang, Xianchao
    PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 1195 - 1203
  • [39] Transferability analysis of adversarial attacks on gender classification to face recognition: Fixed and variable attack perturbation
    Rezgui, Zohra
    Bassit, Amina
    Veldhuis, Raymond
    IET BIOMETRICS, 2022, 11 (05) : 407 - 419
  • [40] Adversarial Examples for Image Cropping: Gradient-Based and Bayesian-Optimized Approaches for Effective Adversarial Attack
    Yoshida, Masatomo
    Namura, Haruto
    Okuda, Masahiro
    IEEE ACCESS, 2024, 12 : 86541 - 86552