Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition

被引:0
|
作者
Li, Zhuhai [1 ]
Zhang, Jie [1 ]
Guo, Wu [1 ]
Wu, Haochen [1 ]
机构
[1] Univ Sci & Technol China, NERC SLIP, Hefei, Peoples R China
来源
关键词
Adversarial examples; transferability; ensemble attack; speaker recognition;
D O I
10.21437/Interspeech.2024-346
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In the black-box attack for speaker recognition systems, the adversarial examples can exhibit better transferability for unseen victim system if they can consistently spoof an ensemble of substitute models. In this work, we propose a gradient-aligned ensemble attack method to find the optimal gradient direction to update the adversarial example using a set of substitute models. Specifically, we first calculate the overfitting-reduced gradient for each substitute model by randomly masking some regions of the input acoustic features. Then we obtain the weight of the gradient for each substitute model based on the consistency of its gradient with respect to others. The final update gradient is calculated by the weighted sum of the gradients over all substitute models. Experimental results on the VoxCeleb dataset verify the effectiveness of the proposed approach for the speaker identification and speaker verification tasks.
引用
收藏
页码:532 / 536
页数:5
相关论文
共 50 条
  • [41] BypTalker: An Adaptive Adversarial Example Attack to Bypass Prefilter-enabled Speaker Recognition
    Chen, Qianniu
    Fu, Kang
    Lu, Li
    Chen, Meng
    Ba, Zhongjie
    Lin, Feng
    Ren, Kui
    2023 19TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN 2023, 2023, : 496 - 503
  • [42] NRI-FGSM: An Efficient Transferable Adversarial Attack Method for Speaker Recognition System
    Tan, Hao
    Zhang, Junjian
    Zhang, Huan
    Wang, Le
    Qian, Yaguan
    Gu, Zhaoquan
    INTERSPEECH 2022, 2022, : 4386 - 4390
  • [43] Crafting Transferable Adversarial Examples Against Face Recognition via Gradient Eroding
    Zhou H.
    Wang Y.
    Tan Y.-A.
    Wu S.
    Zhao Y.
    Zhang Q.
    Li Y.
    IEEE Transactions on Artificial Intelligence, 2024, 5 (01): : 412 - 419
  • [44] SMGEA: A New Ensemble Adversarial Attack Powered by Long-Term Gradient Memories
    Che, Zhaohui
    Borji, Ali
    Zhai, Guangtao
    Ling, Suiyi
    Li, Jing
    Min, Xiongkuo
    Guo, Guodong
    Le Callet, Patrick
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2022, 33 (03) : 1051 - 1065
  • [45] Multi-layer Feature Augmentation Based Transferable Adversarial Examples Generation for Speaker Recognition
    Li, Zhuhai
    Zhang, Jie
    Guo, Wu
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 373 - 385
  • [46] Set-level Guidance Attack: Boosting Adversarial Transferability of Vision-Language Pre-training Models
    Lu, Dong
    Wang, Zhiqiang
    Wang, Teng
    Guan, Weili
    Gao, Hongchang
    Zheng, Feng
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 102 - 111
  • [47] Imperceptible black-box waveform-level adversarial attack towards automatic speaker recognition
    Zhang, Xingyu
    Zhang, Xiongwei
    Sun, Meng
    Zou, Xia
    Chen, Kejiang
    Yu, Nenghai
    COMPLEX & INTELLIGENT SYSTEMS, 2023, 9 (01) : 65 - 79
  • [48] Imperceptible black-box waveform-level adversarial attack towards automatic speaker recognition
    Xingyu Zhang
    Xiongwei Zhang
    Meng Sun
    Xia Zou
    Kejiang Chen
    Nenghai Yu
    Complex & Intelligent Systems, 2023, 9 : 65 - 79
  • [49] Enhancing cross-domain transferability of black-box adversarial attacks on speaker recognition systems using linearized backpropagation
    Patel, Umang
    Bhilare, Shruti
    Hati, Avik
    PATTERN ANALYSIS AND APPLICATIONS, 2024, 27 (02)
  • [50] Hard No-Box Adversarial Attack on Skeleton-Based Human Action Recognition with Skeleton-Motion-Informed Gradient
    Lu, Zhengzhi
    Wang, He
    Chang, Ziyi
    Yang, Guoan
    Shum, Hubert P. H.
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4574 - 4583