On the Defense of Spoofing Countermeasures Against Adversarial Attacks

被引:4
|
作者
Nguyen-Vu, Long [1 ]
Doan, Thien-Phuc [1 ]
Bui, Mai [1 ]
Hong, Kihun [1 ]
Jung, Souhwan [1 ]
机构
[1] Soongsil Univ, Sch Elect Engn, Seoul 06978, South Korea
来源
IEEE ACCESS | 2023年 / 11卷
关键词
Automatic speaker verification; adversarial attack; spoofing countermeasure; psychoacoustics;
D O I
10.1109/ACCESS.2023.3310809
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advances in speech synthesis have exposed the vulnerability of spoofing countermeasure (CM) systems. Adversarial attacks exacerbate this problem, mainly due to the reliance of most CM models on deep neural networks. While research on adversarial attacks in anti-spoofing systems has received considerable attention, there is a relative scarcity of studies focused on developing effective defense techniques. In this study, we propose a defense strategy against such attacks by augmenting training data with frequency band-pass filtering and denoising. Our approach aims to limit the impact of perturbation, thereby reducing the susceptibility to adversarial samples. Furthermore, our findings reveal that the use of Max-Feature-Map (MFM) and frequency band-pass filtering provides additional benefits in suppressing different noise types. To empirically validate this hypothesis, we conduct tests on different CM models using adversarial samples derived from the ASVspoof challenge and other well-known datasets. The evaluation results show that such defense mechanisms can potentially enhance the performance of spoofing countermeasure systems.
引用
收藏
页码:94563 / 94574
页数:12
相关论文
共 50 条
  • [21] Defensive Bit Planes: Defense Against Adversarial Attacks
    Tripathi, Achyut Mani
    Behera, Swarup Ranjan
    Paul, Konark
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [22] Cyclic Defense GAN Against Speech Adversarial Attacks
    Esmaeilpour, Mohammad
    Cardinal, Patrick
    Koerich, Alessandro Lameiras
    [J]. IEEE SIGNAL PROCESSING LETTERS, 2021, 28 : 1769 - 1773
  • [23] Detection defense against adversarial attacks with saliency map
    Ye, Dengpan
    Chen, Chuanxi
    Liu, Changrui
    Wang, Hao
    Jiang, Shunzhi
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (12) : 10193 - 10210
  • [24] Defense-VAE: A Fast and Accurate Defense Against Adversarial Attacks
    Li, Xiang
    Ji, Shihao
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2019, PT II, 2020, 1168 : 191 - 207
  • [25] Symmetry Defense Against CNN Adversarial Perturbation Attacks
    Lindqvist, Blerta
    [J]. INFORMATION SECURITY, ISC 2023, 2023, 14411 : 142 - 160
  • [26] Universal Inverse Perturbation Defense Against Adversarial Attacks
    Chen, Jin-Yin
    Wu, Chang-An
    Zheng, Hai-Bin
    Wang, Wei
    Wen, Hao
    [J]. Zidonghua Xuebao/Acta Automatica Sinica, 2023, 49 (10): : 2172 - 2187
  • [27] Realization and countermeasures for current location spoofing attacks
    Suzuki, Nobuo
    Harada, Taiga
    Fujihata, Takuya
    [J]. KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KSE 2021), 2021, 192 : 2115 - 2121
  • [28] Impact and Detection of GPS Spoofing and Countermeasures against Spoofing
    Ahmad, Mukhtar
    Farid, Muhammad Atif
    Ahmed, Sheeraz
    Saeed, Khalid
    Asharf, M.
    Akhtar, Usman
    [J]. 2019 2ND INTERNATIONAL CONFERENCE ON COMPUTING, MATHEMATICS AND ENGINEERING TECHNOLOGIES (ICOMET), 2019,
  • [29] AGS: Attribution Guided Sharpening as a Defense Against Adversarial Attacks
    Tobia, Javier Perez
    Braun, Phillip
    Narayan, Apurva
    [J]. ADVANCES IN INTELLIGENT DATA ANALYSIS XX, IDA 2022, 2022, 13205 : 225 - 236
  • [30] Defense-PointNet: Protecting PointNet Against Adversarial Attacks
    Zhang, Yu
    Liang, Gongbo
    Salem, Tawfiq
    Jacobs, Nathan
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 5654 - 5660