Enabling Fast and Universal Audio Adversarial Attack Using Generative Model

被引:0
|
作者
Xie, Yi [1 ]
Li, Zhuohang [2 ]
Shi, Cong [1 ]
Liu, Jian [2 ]
Chen, Yingying [1 ]
Yuan, Bo [1 ]
机构
[1] Rutgers State Univ, New Brunswick, NJ 08901 USA
[2] Univ Tennessee, Knoxville, TN USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, the vulnerability of deep neural network (DNN)-based audio systems to adversarial attacks has obtained increasing attention. However, the existing audio adversarial attacks allow the adversary to possess the entire user's audio input as well as granting sufficient time budget to generate the adversarial perturbations. These idealized assumptions, however, make the existing audio adversarial attacks mostly impossible to be launched in a timely fashion in practice (e.g., playing unnoticeable adversarial perturbations along with user's streaming input). To overcome these limitations, in this paper we propose fast audio adversarial perturbation generator (FAPG), which uses generative model to generate adversarial perturbations for the audio input in a single forward pass, thereby drastically improving the perturbation generation speed. Built on the top of FAPG, we further propose universal audio adversarial perturbation generator (UAPG), a scheme to craft universal adversarial perturbation that can be imposed on arbitrary benign audio input to cause misclassification. Extensive experiments on DNN-based audio systems show that our proposed FAPG can achieve high success rate with up to 214x speedup over the existing audio adversarial attack methods. Also our proposed UAPG generates universal adversarial perturbations that can achieve much better attack performance than the state-of-the-art solutions.
引用
收藏
页码:14129 / 14137
页数:9
相关论文
共 50 条
  • [21] Fast generative adversarial networks model for masked image restoration
    Cao, Zhiyi
    Niu, Shaozhang
    Zhang, Jiwei
    Wang, Xinyi
    IET IMAGE PROCESSING, 2019, 13 (07) : 1124 - 1129
  • [22] Sparse Adversarial Attack on Modulation Recognition with Adversarial Generative Networks
    Liang, Kui
    Liu, Zhidong
    Zhao, Xin
    Zeng, Cheng
    Cai, Jun
    2024 4TH INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND SOFTWARE ENGINEERING, ICICSE 2024, 2024, : 104 - 108
  • [23] Automatically synthesizing DoS attack traces using generative adversarial networks
    Yan, Qiao
    Wang, Mingde
    Huang, Wenyao
    Luo, Xupeng
    Yu, F. Richard
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2019, 10 (12) : 3387 - 3396
  • [24] Automatically synthesizing DoS attack traces using generative adversarial networks
    Qiao Yan
    Mingde Wang
    Wenyao Huang
    Xupeng Luo
    F. Richard Yu
    International Journal of Machine Learning and Cybernetics, 2019, 10 : 3387 - 3396
  • [25] attackGAN: Adversarial Attack against Black-box IDS using Generative Adversarial Networks
    Zhao, Shuang
    Li, Jing
    Wang, Jianmin
    Zhang, Zhao
    Zhu, Lin
    Zhang, Yong
    2020 INTERNATIONAL CONFERENCE ON IDENTIFICATION, INFORMATION AND KNOWLEDGE IN THE INTERNET OF THINGS (IIKI2020), 2021, 187 : 128 - 133
  • [26] Robust Audio Adversarial Example for a Physical Attack
    Yakura, Hiromu
    Sakuma, Jun
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 5334 - 5341
  • [27] Discriminator-Free Generative Adversarial Attack
    Lu, Shaohao
    Xian, Yuqiao
    Yan, Ke
    Hu, Yi
    Sun, Xing
    Guo, Xiaowei
    Huang, Feiyue
    Zheng, Wei-Shi
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 1544 - 1552
  • [28] Type-I Generative Adversarial Attack
    He, Shenghong
    Wang, Ruxin
    Liu, Tongliang
    Yi, Chao
    Jin, Xin
    Liu, Renyang
    Zhou, Wei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2593 - 2606
  • [29] SMACK: Semantically Meaningful Adversarial Audio Attack
    Yu, Zhiyuan
    Chang, Yuanhaur
    Zhang, Ning
    Xiao, Chaowei
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 3799 - 3816
  • [30] Anti-forensics of fake stereo audio using generative adversarial network
    Tianyun Liu
    Diqun Yan
    Nan Yan
    Gang Chen
    Multimedia Tools and Applications, 2022, 81 : 17155 - 17167