Improving adversarial transferability by temporal and spatial momentum in urban speaker recognition systems

被引:11
|
作者
Tan, Hao [1 ,2 ]
Gu, Zhaoquan [1 ,2 ]
Wang, Le [1 ,2 ]
Zhang, Huan [1 ,2 ]
Gupta, Brij B. [3 ,4 ,5 ,6 ,7 ]
Tian, Zhihong [1 ]
机构
[1] Guangzhou Univ, Cyberspace Inst Adv Technol, Guangzhou, Peoples R China
[2] Peng Cheng Lab, Dept New Networks, Shenzhen, Peoples R China
[3] Asia Univ, Int Ctr AI & Cyber Secur Res & Innovat, Taichung 413, Taiwan
[4] Asia Univ, Dept Comp Sci & Informat Engn, Taichung 413, Taiwan
[5] Lebanese Amer Univ, Beirut 1102, Lebanon
[6] Univ Petr Energy Studies UPES, Ctr Interdisciplinary Res, Dehra Dun, Uttarakhand, India
[7] Skyline Univ Coll, Res & Innovat Dept, POB 1797, Sharjah, U Arab Emirates
关键词
Speaker recognition; Adversarial examples; Transferability; Black-box attack; Temporal and spatial momentum;
D O I
10.1016/j.compeleceng.2022.108446
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
DNN-based speaker recognition systems (SRSs) in smart cities suffer from adversarial attacks, which have caused widespread concern. An attacker can fool the SRSs by adding imperceptible perturbations to benign audio. Recent studies have shown that adversarial attacks could achieve almost 100% attack success rate in the white-box but perform poorly in the black-box. Existing attacks do not effectively use the gradient information of the available white-box models, which is easy to over-fit the target model. To tackle the problem, we propose a temporal and spatial momentum-based iteration gradient sign method (TSMI-FGSM). Specifically, we introduce the sample neighborhood and interior space, and accumulate the gradient information of the randomly sampled points in these two spaces to correct and update direction by tuning strategies during each iteration. The experiment results with 9 SRSs demonstrate that our method significantly enhances the transferability of the adversarial examples compared to state-of-the-art attacks.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Enhancing Transferability of Adversarial Examples with Spatial Momentum
    Wang, Guoqiu
    Yan, Huanqian
    Wei, Xingxing
    PATTERN RECOGNITION AND COMPUTER VISION, PT I, PRCV 2022, 2022, 13534 : 593 - 604
  • [2] Improving adversarial transferability through frequency enhanced momentum
    Zhao, Changfei
    Deng, Xinyang
    Jiang, Wen
    INFORMATION SCIENCES, 2024, 665
  • [3] Improving Transferability of Adversarial Attacks with Gaussian Gradient Enhance Momentum
    Wang, Jinwei
    Wang, Maoyuan
    Wu, Hao
    Ma, Bin
    Luo, Xiangyang
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT IX, 2024, 14433 : 421 - 432
  • [4] Improving the Transferability of Adversarial Attacks through Experienced Precise Nesterov Momentum
    Wu, Hao
    Wang, Jinwei
    Zhang, Jiawei
    Wu, Yufeng
    Ma, Bin
    Luo, Xiangyang
    2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [5] Improving Transferability of Adversarial Patches on Face Recognition with Generative Models
    Xiao, Zihao
    Gao, Xianfeng
    Fu, Chilin
    Dong, Yinpeng
    Gao, Wei
    Zhang, Xiaolu
    Zhou, Jun
    Zhu, Jun
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 11840 - 11849
  • [6] IMPROVING VISUAL QUALITY AND TRANSFERABILITY OF ADVERSARIAL ATTACKS ON FACE RECOGNITION SIMULTANEOUSLY WITH ADVERSARIAL RESTORATION
    Zhou, Fengfan
    Ling, Hefei
    Shi, Yuxuan
    Chen, Jiazhong
    Li, Ping
    2024 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, ICASSP 2024, 2024, : 4540 - 4544
  • [7] Rethinking multi-spatial information for transferable adversarial attacks on speaker recognition systems
    Zhang, Junjian
    Tan, Hao
    Wang, Le
    Qian, Yaguan
    Gu, Zhaoquan
    CAAI TRANSACTIONS ON INTELLIGENCE TECHNOLOGY, 2024, 9 (03) : 620 - 631
  • [8] Enhancing the Transferability of Adversarial Examples Based on Nesterov Momentum for Recommendation Systems
    Qian, Fulan
    Yuan, Bei
    Chen, Hai
    Chen, Jie
    Lian, Defu
    Zhao, Shu
    IEEE TRANSACTIONS ON BIG DATA, 2023, 9 (05) : 1276 - 1287
  • [9] Boosting the Transferability of Adversarial Examples with Gradient-Aligned Ensemble Attack for Speaker Recognition
    Li, Zhuhai
    Zhang, Jie
    Guo, Wu
    Wu, Haochen
    INTERSPEECH 2024, 2024, : 532 - 536
  • [10] Adversarial Transferability in Embedded Sensor Systems: An Activity Recognition Perspective
    Sah, Ramesh Kumar
    Ghasemzadeh, Hassan
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2024, 23 (02)