On the Defense of Spoofing Countermeasures Against Adversarial Attacks

被引:4
|
作者
Nguyen-Vu, Long [1 ]
Doan, Thien-Phuc [1 ]
Bui, Mai [1 ]
Hong, Kihun [1 ]
Jung, Souhwan [1 ]
机构
[1] Soongsil Univ, Sch Elect Engn, Seoul 06978, South Korea
来源
IEEE ACCESS | 2023年 / 11卷
关键词
Automatic speaker verification; adversarial attack; spoofing countermeasure; psychoacoustics;
D O I
10.1109/ACCESS.2023.3310809
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advances in speech synthesis have exposed the vulnerability of spoofing countermeasure (CM) systems. Adversarial attacks exacerbate this problem, mainly due to the reliance of most CM models on deep neural networks. While research on adversarial attacks in anti-spoofing systems has received considerable attention, there is a relative scarcity of studies focused on developing effective defense techniques. In this study, we propose a defense strategy against such attacks by augmenting training data with frequency band-pass filtering and denoising. Our approach aims to limit the impact of perturbation, thereby reducing the susceptibility to adversarial samples. Furthermore, our findings reveal that the use of Max-Feature-Map (MFM) and frequency band-pass filtering provides additional benefits in suppressing different noise types. To empirically validate this hypothesis, we conduct tests on different CM models using adversarial samples derived from the ASVspoof challenge and other well-known datasets. The evaluation results show that such defense mechanisms can potentially enhance the performance of spoofing countermeasure systems.
引用
收藏
页码:94563 / 94574
页数:12
相关论文
共 50 条
  • [31] Local Gradients Smoothing: Defense against localized adversarial attacks
    Naseer, Muzammal
    Khan, Salman H.
    Porikli, Fatih
    [J]. 2019 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2019, : 1300 - 1307
  • [32] Using Uncertainty as a Defense Against Adversarial Attacks for Tabular Datasets
    Santhosh, Poornima
    Gressel, Gilad
    Darling, Michael C.
    [J]. AI 2022: ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, 13728 : 719 - 732
  • [33] Assured Deep Learning: Practical Defense Against Adversarial Attacks
    Rouhani, Bita Darvish
    Samragh, Mohammad
    Javaheripi, Mojan
    Javidi, Tara
    Koushanfar, Farinaz
    [J]. 2018 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD) DIGEST OF TECHNICAL PAPERS, 2018,
  • [34] A NEURO-INSPIRED AUTOENCODING DEFENSE AGAINST ADVERSARIAL ATTACKS
    Bakiskan, Can
    Cekic, Metehan
    Sezer, Ahmet Dundar
    Madhow, Upamanyu
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 3922 - 3926
  • [35] Defense against adversarial attacks based on color space transformation
    Wang, Haoyu
    Wu, Chunhua
    Zheng, Kangfeng
    [J]. NEURAL NETWORKS, 2024, 173
  • [36] AdvRefactor: A Resampling-Based Defense Against Adversarial Attacks
    Jiang, Jianguo
    Li, Boquan
    Yu, Min
    Liu, Chao
    Sun, Jianguo
    Huang, Weiqing
    Lv, Zhiqiang
    [J]. ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2018, PT II, 2018, 11165 : 815 - 825
  • [37] Image Super-Resolution as a Defense Against Adversarial Attacks
    Mustafa, Aamir
    Khan, Salman H.
    Hayat, Munawar
    Shen, Jianbing
    Shao, Ling
    [J]. IEEE TRANSACTIONS ON IMAGE PROCESSING, 2020, 29 : 1711 - 1724
  • [38] Boundary Defense Against Black-box Adversarial Attacks
    Aithal, Manjushree B.
    Li, Xiaohua
    [J]. 2022 26TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2022, : 2349 - 2356
  • [39] MAEDefense: An Effective Masked AutoEncoder Defense against Adversarial Attacks
    Lyu, Wanli
    Wu, Mengjiang
    Yin, Zhaoxia
    Luo, Bin
    [J]. 2023 ASIA PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE, APSIPA ASC, 2023, : 1915 - 1922
  • [40] Deadversarial Multiverse Network - A defense architecture against adversarial attacks
    Berg, Aviram
    Tulchinsky, Elin
    Zaidenerg, Nezer Jacob
    [J]. SYSTOR '19: PROCEEDINGS OF THE 12TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE, 2019, : 190 - 190