ADVERSARIAL ATTACKS ON SPOOFING COUNTERMEASURES OF AUTOMATIC SPEAKER VERIFICATION

被引:0
|
作者
Liu, Songxiang [1 ]
Wu, Haibin [2 ]
Lee, Hung-yi [2 ]
Meng, Helen [1 ]
机构
[1] Chinese Univ Hong Kong, Human Comp Commun Lab, Hong Kong, Peoples R China
[2] Natl Taiwan Univ, Speech Proc & Machine Learning Lab, Taipei, Taiwan
关键词
Adversarial attack; anti-spoofing; spoofing countermeasure; white-box attack; black-box attack;
D O I
10.1109/asru46091.2019.9003763
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
High-performance spoofing countermeasure systems for automatic speaker verification (ASV) have been proposed in the ASVspoof 2019 challenge. However, the robustness of such systems under adversarial attacks has not been studied yet. In this paper, we investigate the vulnerability of spoofing countermeasures for ASV under both white-box and blackbox adversarial attacks with the fast gradient sign method (FGSM) and the projected gradient descent (PGD) method. We implement high-performing countermeasure models in the ASVspoof 2019 challenge and conduct adversarial attacks on them. We compare performance of black-box attacks across spoofing countermeasure models with different network architectures and different amount of model parameters. The experimental results show that all implemented countermeasure models are vulnerable to FGSM and PGD attacks under the scenario of white-box attack. The more dangerous black-box attacks also prove to be effective by the experimental results.
引用
收藏
页码:312 / 319
页数:8
相关论文
共 50 条
  • [1] Spoofing and countermeasures for automatic speaker verification
    Evans, Nicholas
    Kinnunen, Tomi
    Yamagishi, Junichi
    [J]. 14TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2013), VOLS 1-5, 2013, : 925 - 929
  • [2] Waveform level adversarial example generation for joint attacks against both automatic speaker verification and spoofing countermeasures
    Zhang, Xingyu
    Zhang, Xiongwei
    Liu, Wei
    Zou, Xia
    Sun, Meng
    Zhao, Jian
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 116
  • [3] Introduction to the Issue on Spoofing and Countermeasures for Automatic Speaker Verification
    Yamagishi, Junichi
    Kinnunen, Tomi H.
    Evans, Nicholas
    De Leon, Phillip
    Trancoso, Isabel
    [J]. IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2017, 11 (04) : 585 - 587
  • [4] ASVspoof: The Automatic Speaker Verification Spoofing and Countermeasures Challenge
    Wu, Zhizheng
    Yamagishi, Junichi
    Kinnunen, Tomi
    Hanilci, Cemal
    Sahidullah, Mohammed
    Sizov, Aleksandr
    Evans, Nicholas
    Todisco, Massimiliano
    Delgado, Hector
    [J]. IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2017, 11 (04) : 588 - 604
  • [5] IIIT-H Spoofing Countermeasures for Automatic Speaker Verification Spoofing and Countermeasures Challenge 2019
    Alluri, K. N. R. K. Raju
    Vuppala, Anil Kumar
    [J]. INTERSPEECH 2019, 2019, : 1043 - 1047
  • [6] Tandem Assessment of Spoofing Countermeasures and Automatic Speaker Verification: Fundamentals
    Kinnunen, Tomi
    Delgado, Hector
    Evans, Nicholas
    Lee, Kong Aik
    Vestman, Ville
    Nautsch, Andreas
    Todisco, Massimiliano
    Wang, Xin
    Sahidullah, Md
    Yamagishi, Junichi
    Reynolds, Douglas A.
    [J]. IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2020, 28 : 2195 - 2210
  • [7] Spoofing and countermeasures for speaker verification: A survey
    Wu, Zhizheng
    Evans, Nicholas
    Kinnunen, Tomi
    Yamagishi, Junichi
    Alegre, Federico
    Li, Haizhou
    [J]. SPEECH COMMUNICATION, 2015, 66 : 130 - 153
  • [8] An assessment of automatic speaker verification vulnerabilities to replay spoofing attacks
    Janicki, Artur
    Alegre, Federico
    Evans, Nicholas
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (15) : 3030 - 3044
  • [9] Spoofing and Countermeasures for Speaker Verification: A Review
    Anjum, Z. Khamar
    Swamy, R. Kumara
    [J]. 2017 2ND IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2017, : 467 - 471
  • [10] Integrated Spoofing Countermeasures and Automatic Speaker Verification: an Evaluation on ASVspoof 2015
    Sahidullah, Md
    Delgado, Hector
    Todisco, Massimiliano
    Yu, Hong
    Kinnunen, Tomi
    Evans, Nicholas
    Tana, Zheng-Hua
    [J]. 17TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2016), VOLS 1-5: UNDERSTANDING SPEECH PROCESSING IN HUMANS AND MACHINES, 2016, : 1700 - 1704