On the Defense of Spoofing Countermeasures Against Adversarial Attacks

被引:4
|
作者
Nguyen-Vu, Long [1 ]
Doan, Thien-Phuc [1 ]
Bui, Mai [1 ]
Hong, Kihun [1 ]
Jung, Souhwan [1 ]
机构
[1] Soongsil Univ, Sch Elect Engn, Seoul 06978, South Korea
来源
IEEE ACCESS | 2023年 / 11卷
关键词
Automatic speaker verification; adversarial attack; spoofing countermeasure; psychoacoustics;
D O I
10.1109/ACCESS.2023.3310809
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advances in speech synthesis have exposed the vulnerability of spoofing countermeasure (CM) systems. Adversarial attacks exacerbate this problem, mainly due to the reliance of most CM models on deep neural networks. While research on adversarial attacks in anti-spoofing systems has received considerable attention, there is a relative scarcity of studies focused on developing effective defense techniques. In this study, we propose a defense strategy against such attacks by augmenting training data with frequency band-pass filtering and denoising. Our approach aims to limit the impact of perturbation, thereby reducing the susceptibility to adversarial samples. Furthermore, our findings reveal that the use of Max-Feature-Map (MFM) and frequency band-pass filtering provides additional benefits in suppressing different noise types. To empirically validate this hypothesis, we conduct tests on different CM models using adversarial samples derived from the ASVspoof challenge and other well-known datasets. The evaluation results show that such defense mechanisms can potentially enhance the performance of spoofing countermeasure systems.
引用
收藏
页码:94563 / 94574
页数:12
相关论文
共 50 条
  • [1] DEFENSE AGAINST ADVERSARIAL ATTACKS ON SPOOFING COUNTERMEASURES OF ASV
    Wu, Haibin
    Liu, Songxiang
    Meng, Helen
    Lee, Hung-yi
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 6564 - 6568
  • [2] ADVERSARIAL ATTACKS ON SPOOFING COUNTERMEASURES OF AUTOMATIC SPEAKER VERIFICATION
    Liu, Songxiang
    Wu, Haibin
    Lee, Hung-yi
    Meng, Helen
    [J]. 2019 IEEE AUTOMATIC SPEECH RECOGNITION AND UNDERSTANDING WORKSHOP (ASRU 2019), 2019, : 312 - 319
  • [3] Universal Adversarial Spoofing Attacks against Face Recognition
    Amada, Takuma
    Liew, Seng Pei
    Kakizaki, Kazuya
    Araki, Toshinori
    [J]. 2021 INTERNATIONAL JOINT CONFERENCE ON BIOMETRICS (IJCB 2021), 2021,
  • [4] Deblurring as a Defense against Adversarial Attacks
    Duckworth, William, III
    Liao, Weixian
    Yu, Wei
    [J]. 2023 IEEE 12TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING, CLOUDNET, 2023, : 61 - 67
  • [5] Black-box Attacks on Spoofing Countermeasures Using Transferability of Adversarial Examples
    Zhang, Yuekai
    Jiang, Ziyan
    Villalba, Jesus
    Dehak, Najim
    [J]. INTERSPEECH 2020, 2020, : 4238 - 4242
  • [6] Text Adversarial Purification as Defense against Adversarial Attacks
    Li, Linyang
    Song, Demin
    Qiu, Xipeng
    [J]. PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 338 - 350
  • [7] Waveform level adversarial example generation for joint attacks against both automatic speaker verification and spoofing countermeasures
    Zhang, Xingyu
    Zhang, Xiongwei
    Liu, Wei
    Zou, Xia
    Sun, Meng
    Zhao, Jian
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 116
  • [8] LOT: A Defense Against IP Spoofing and Flooding Attacks
    Gilad, Yossi
    Herzberg, Amir
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2012, 15 (02)
  • [9] Defense against Adversarial Attacks with an Induced Class
    Xu, Zhi
    Wang, Jun
    Pu, Jian
    [J]. 2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [10] A Defense Method Against Facial Adversarial Attacks
    Sadu, Chiranjeevi
    Das, Pradip K.
    [J]. 2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 459 - 463