Improving adversarial transferability by temporal and spatial momentum in urban speaker recognition systems

被引:11
|
作者
Tan, Hao [1 ,2 ]
Gu, Zhaoquan [1 ,2 ]
Wang, Le [1 ,2 ]
Zhang, Huan [1 ,2 ]
Gupta, Brij B. [3 ,4 ,5 ,6 ,7 ]
Tian, Zhihong [1 ]
机构
[1] Guangzhou Univ, Cyberspace Inst Adv Technol, Guangzhou, Peoples R China
[2] Peng Cheng Lab, Dept New Networks, Shenzhen, Peoples R China
[3] Asia Univ, Int Ctr AI & Cyber Secur Res & Innovat, Taichung 413, Taiwan
[4] Asia Univ, Dept Comp Sci & Informat Engn, Taichung 413, Taiwan
[5] Lebanese Amer Univ, Beirut 1102, Lebanon
[6] Univ Petr Energy Studies UPES, Ctr Interdisciplinary Res, Dehra Dun, Uttarakhand, India
[7] Skyline Univ Coll, Res & Innovat Dept, POB 1797, Sharjah, U Arab Emirates
关键词
Speaker recognition; Adversarial examples; Transferability; Black-box attack; Temporal and spatial momentum;
D O I
10.1016/j.compeleceng.2022.108446
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
DNN-based speaker recognition systems (SRSs) in smart cities suffer from adversarial attacks, which have caused widespread concern. An attacker can fool the SRSs by adding imperceptible perturbations to benign audio. Recent studies have shown that adversarial attacks could achieve almost 100% attack success rate in the white-box but perform poorly in the black-box. Existing attacks do not effectively use the gradient information of the available white-box models, which is easy to over-fit the target model. To tackle the problem, we propose a temporal and spatial momentum-based iteration gradient sign method (TSMI-FGSM). Specifically, we introduce the sample neighborhood and interior space, and accumulate the gradient information of the randomly sampled points in these two spaces to correct and update direction by tuning strategies during each iteration. The experiment results with 9 SRSs demonstrate that our method significantly enhances the transferability of the adversarial examples compared to state-of-the-art attacks.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] QFA2SR: Query-Free Adversarial Transfer Attacks to Speaker Recognition Systems
    Chen, Guangke
    Zhang, Yedi
    Zhao, Zhe
    Song, Fu
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 2437 - 2454
  • [32] Efficient Black-Box Adversarial Attacks with Training Surrogate Models Towards Speaker Recognition Systems
    Wang, Fangwei
    Song, Ruixin
    Li, Qingru
    Wang, Changguang
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT V, 2024, 14491 : 257 - 276
  • [33] Discriminative Adversarial Network Based on Spatial-Temporal-Graph Fusion for Motor Imagery Recognition
    She, Qingshan
    Chen, Tie
    Fang, Feng
    Gao, Yunyuan
    Zhang, Yingchun
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024,
  • [34] LC-GAN: Improving Adversarial Robustness of Face Recognition Systems on Edge Devices
    Du, Peilun
    Zheng, Xiaolong
    Liu, Liang
    Ma, Huadong
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (09) : 8172 - 8184
  • [35] Study of Pre-Processing Defenses Against Adversarial Attacks on State-of-the-Art Speaker Recognition Systems
    Joshi, Sonal
    Villalba, Jesus
    Zelasko, Piotr
    Moro-Velazquez, Laureano
    Dehak, Najim
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 4811 - 4826
  • [36] EEG Data Augmentation Method for Identity Recognition Based on Spatial-Temporal Generating Adversarial Network
    Hu, Yudie
    Sun, Lei
    Mao, Xiuqing
    Zhang, Shuai
    ELECTRONICS, 2024, 13 (21)
  • [37] Improving Emotion Recognition Systems by Exploiting the Spatial Information of EEG Sensors
    Gagliardi, Guido
    Alfeo, Antonio Luca
    Catrambone, Vincenzo
    Candia-Rivera, Diego
    Cimino, Mario G. C. A.
    Valenza, Gaetano
    IEEE ACCESS, 2023, 11 : 39544 - 39554
  • [38] Spatial and Temporal Evolution of Urban Systems in China during Rapid Urbanization
    Li, Huan
    Wei, Yehua Dennis
    Ning, Yuemin
    SUSTAINABILITY, 2016, 8 (07):
  • [39] Understanding urban food systems: A spatial and temporal analysis in Sydney, Australia
    Hsu, Yi-Ya
    Han, Hoon
    CITIES, 2024, 155
  • [40] Decoding Urban Mobility: Application of Natural Language Processing and Machine Learning to Activity Pattern Recognition, Prediction, and Temporal Transferability Examination
    Chen, Mingyang
    Yuan, Quan
    Yang, Chao
    Zhang, Yuliang
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, 25 (07) : 7151 - 7173