A Practical Black-Box Attack Against Autonomous Speech Recognition Model

被引:0
|
作者
Fan, Wenshu [1 ]
Li, Hongwei [1 ,2 ]
Jiang, Wenbo [1 ]
Xu, Guowen [1 ]
Lu, Rongxing [3 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu, Peoples R China
[2] Cyberspace Secur Res Ctr, Peng Cheng Lab, Shenzhen 518000, Peoples R China
[3] Univ New Brunswick, Fac Comp Sci, Fredericton, NB, Canada
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
Machine Learning; Automatic Speech Recognition; Differential Evolution; Black-Box Attack;
D O I
10.1109/GLOBECOM42002.2020.9348184
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the wild applications of machine learning (ML) technology, automatic speech recognition (ASR) has made great progress in recent years. Despite its great potential, there are various evasion attacks of ML-based ASR, which could affect the security of applications built upon ASR. Up to now, most studies focus on white-box attacks in ASR, and there is almost no attention paid to black-box attacks where attackers can only query the target model to get output labels rather than probability vectors in audio domain. In this paper, we propose an evasion attack against ASR in the above-mentioned situation, which is more feasible in realistic scenarios. Specifically, we first train a substitute model by using data augmentation, which ensures that we have enough samples to train with a small number of times to query the target model. Then, based on the substitute model, we apply Differential Evolution (DE) algorithm to craft adversarial examples and implement black-box attack against ASR models from the Speech Commands dataset. Extensive experiments are conducted, and the results illustrate that our approach achieves untargeted attacks with over 70% success rate while still maintaining the authenticity of the original data well.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] IMPGA: An Effective and Imperceptible Black-Box Attack Against Automatic Speech Recognition Systems
    Liang, Luopu
    Guo, Bowen
    Lian, Zhichao
    Li, Qianmu
    Jing, Huiyun
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 349 - 363
  • [2] Model Inversion Attack against a Face Recognition System in a Black-Box Setting
    Yoshimura, Shunsuke
    Nakamura, Kazuaki
    Nitta, Naoko
    Babaguchi, Noboru
    2021 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2021, : 1800 - 1807
  • [3] Practical black-box adversarial attack on open-set recognition: Towards robust autonomous driving
    Wang, Yanfei
    Zhang, Kai
    Lu, Kejie
    Xiong, Yun
    Wen, Mi
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (01) : 295 - 311
  • [4] Practical black-box adversarial attack on open-set recognition: Towards robust autonomous driving
    Yanfei Wang
    Kai Zhang
    Kejie Lu
    Yun Xiong
    Mi Wen
    Peer-to-Peer Networking and Applications, 2023, 16 : 295 - 311
  • [5] Black-box Adversarial Attack Against Road Sign Recognition Model via PSO
    Chen J.-Y.
    Chen Z.-Q.
    Zheng H.-B.
    Shen S.-J.
    Su M.-M.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (09): : 2785 - 2801
  • [6] Examining of Shallow Autoencoder on Black-box Attack against Face Recognition
    Vo Ngoc Khoi Nguyen
    Terada, Takamichi
    Nishigaki, Masakatsu
    Ohki, Tetsushi
    2021 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2021, : 1775 - 1780
  • [7] SPEECH PATTERN BASED BLACK-BOX MODEL WATERMARKING FOR AUTOMATIC SPEECH RECOGNITION
    Chen, Haozhe
    Zhang, Weiming
    Liu, Kunlin
    Chen, Kejiang
    Fang, Han
    Yu, Nenghai
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 3059 - 3063
  • [8] BASAR:Black-box Attack on Skeletal Action Recognition
    Diao, Yunfeng
    Shao, Tianjia
    Yang, Yong-Liang
    Zhou, Kun
    Wang, He
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 7593 - 7603
  • [9] Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial Patch
    Ma, Haotian
    Xu, Ke
    Jiang, Xinghao
    Zhao, Zeyu
    Sun, Tanfeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5636 - 5650
  • [10] Practical Black-Box Attacks against Machine Learning
    Papernot, Nicolas
    McDaniel, Patrick
    Goodfellow, Ian
    Jha, Somesh
    Celik, Z. Berkay
    Swami, Ananthram
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 506 - 519