Skip to main content
QUICK REVIEW

[논문 리뷰] SirenAttack: Generating Adversarial Audio for End-to-End Acoustic Systems

Tianyu Du, Shouling Ji|arXiv (Cornell University)|2019. 01. 23.
Music and Audio Processing참고 문헌 45인용 수 19
한 줄 요약

SirenAttack는 엔드투엔드 음성 시스템에 대해 인식할 수 없고 매우 효과적이며 다재다능한 공격을 생성하는 새로운 적대적 오디오 생성 방법이다. 인간과 여러 ASR 플랫폼 모두에서 탐지되지 않으며, IEMOCAP 데이터셋에서 99.45%의 성공률을 기록하여 다양한 모델 간에 높은 은폐성과 이식성(transferability)을 입증한다.

ABSTRACT

Despite their immense popularity, deep learning-based acoustic systems are inherently vulnerable to adversarial attacks, wherein maliciously crafted audios trigger target systems to misbehave. In this paper, we present SirenAttack, a new class of attacks to generate adversarial audios. Compared with existing attacks, SirenAttack highlights with a set of significant features: (i) versatile -- it is able to deceive a range of end-to-end acoustic systems under both white-box and black-box settings; (ii) effective -- it is able to generate adversarial audios that can be recognized as specific phrases by target acoustic systems; and (iii) stealthy -- it is able to generate adversarial audios indistinguishable from their benign counterparts to human perception. We empirically evaluate SirenAttack on a set of state-of-the-art deep learning-based acoustic systems (including speech command recognition, speaker recognition and sound event classification), with results showing the versatility, effectiveness, and stealthiness of SirenAttack. For instance, it achieves 99.45% attack success rate on the IEMOCAP dataset against the ResNet18 model, while the generated adversarial audios are also misinterpreted by multiple popular ASR platforms, including Google Cloud Speech, Microsoft Bing Voice, and IBM Speech-to-Text. We further evaluate three potential defense methods to mitigate such attacks, including adversarial training, audio downsampling, and moving average filtering, which leads to promising directions for further research.

연구 동기 및 목표

  • 엔드투엔드 음성 모델에 대해 효과적이고 다재다능하며 은폐성이 높은 새로운 종류의 적대적 오디오 공격을 개발하기.
  • 악성으로 조작된 오디오 입력에 대한 딥러닝 기반 음성 시스템의 취약성을 해결하기.
  • 인간 청취자에게 일반 오디오와 구분되지 않는 적대적 예제를 생성하기.
  • 음성 명령 인식, 화자 인식, 사운드 이벤트 분류 등 다양한 음성 시스템에서 공격의 성공률 평가하기.
  • 적대적 훈련과 신호 필터링을 포함한 이러한 공격에 대비한 방어 기법 탐색하기.

제안 방법

  • SirenAttack는 인간에게 인식되지 않는 적대적 편향을 생성하기 위해 기울기 기반 최적화 프레임워크를 사용한다.
  • 화이트박스 및_BLK박스 설정 모두에서 작동하여 다양한 음성 모델 간 이식성(transferability)을 가능하게 한다.
  • 생성된 적대적 오디오가 일반 입력과 음향적으로 유사하게 유지되도록 청각적 마스킹 모델을 활용한다.
  • 모델이 오디오를 특정 타겟 문구로 잘못 분류하도록 보장하기 위해 타겟 지정 손실 함수를 사용한다.
  • 청각적 왜곡을 최소화하면서도 타겟 모델에서의 오분류를 최대화하도록 공격를 최적화한다.
  • 최신 모델인 ResNet18 및 여러 상용 ASR 플랫폼을 대상으로 평가된다.

실험 결과

연구 질문

  • RQ1인간에게 인식되지 않으면서도 엔드투엔드 음성 모델을 효과적으로 속일 수 있는 적대적 오디오를 생성할 수 있는가?
  • RQ2SirenAttack로 생성된 적대적 예제는 다양한 음성 모델과 ASR 플랫폼 간에 얼마나 이식성이 있는가?
  • RQ3적대적 오디오 생성에서 높은 은폐성과 높은 성공률을 가능하게 하는 핵심 요소는 무엇인가?
  • RQ4적대적 훈련과 오디오 필터링과 같은 기존 방어 기법은 SirenAttack에 대해 얼마나 효과적인가?
  • RQ5SirenAttack는 음성 명령 인식 및 사운드 이벤트 분류와 같은 다양한 음성 작업에 효과적으로 적용될 수 있는가?

주요 결과

  • SirenAttack는 타겟 모델로 ResNet18을 사용할 때 IEMOCAP 데이터셋에서 99.45%의 공격 성공률를 기록했다.
  • 생성된 적대적 오디오는 Google Cloud Speech, Microsoft Bing Voice, IBM Speech-to-Text를 포함한 여러 상용 ASR 플랫폼에서 성공적으로 잘못 분류되었다.
  • 적대적 예제는 인간 청취자에게 인식되지 않아 높은 은폐성을 입증했다.
  • 공격는 강력한 이식성을 보였으며, 블랙박스 설정에서도 모델을 성공적으로 속였다.
  • 적대적 훈련은 부분적인 완화 효과를 보였고, 오디오 다운샘플링과 이동 평균 필터링은 SirenAttack에 대해 제한적인 효과를 보였다.
  • 결과적으로 엔드투엔드 음성 시스템이 미세하고 타겟 지정된 오디오 편향에 매우 취약함을 시사한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.