Skip to main content
QUICK REVIEW

[논문 리뷰] VENOMAVE: Clean-Label Poisoning Against Speech Recognition.

Hojjat Aghakhani, Thorsten Eisenhofer|arXiv (Cornell University)|2020. 10. 21.
Adversarial Robustness in Machine Learning참고 문헌 3인용 수 11
한 줄 요약

VENOMAVE는 자동 음성 인식(ASR) 시스템을 대상으로 하는 최초의 데이터 풀기 공격로, 훈련 중에 약간 수정된 오디오 샘플을 삽입함으로써 ASR 모델을 조작하기 위해 클린 레이블 풀기 기법을 활용한다. 목표 발화의 시계열 프레임 전역에 걸쳐 정교하게 설계된 변형을 통해, 오직 0.94%의 훈련 데이터만 풀리게 하여도 83.33%의 공격 성공률를 달성하며, ASR 시스템에 심각한 취약성을 드러낸다.

ABSTRACT

In the past few years, we observed a wide adoption of practical systems that use Automatic Speech Recognition (ASR) systems to improve human-machine interaction. Modern ASR systems are based on neural networks and prior research demonstrated that these systems are susceptible to adversarial examples, i.e., malicious audio inputs that lead to misclassification by the victim's network during the system's run time. The research question if ASR systems are also vulnerable to data poisoning attacks is still unanswered. In such an attack, a manipulation happens during the training phase of the neural network: an adversary injects malicious inputs into the training set such that the neural network's integrity and performance are compromised. In this paper, we present the first data poisoning attack in the audio domain, called VENOMAVE. Prior work in the image domain demonstrated several types of data poisoning attacks, but they cannot be applied to the audio domain. The main challenge is that we need to attack a time series of inputs. To enforce a targeted misclassification in an ASR system, we need to carefully generate a specific sequence of disturbed inputs for the target utterance, which will eventually be decoded to the desired sequence of words. More specifically, the adversarial goal is to produce a series of misclassification tasks and in each of them, we need to poison the system to misrecognize each frame of the target file. To demonstrate the practical feasibility of our attack, we evaluate VENOMAVE on an ASR system that detects sequences of digits from 0 to 9. When poisoning only 0.94% of the dataset on average, we achieve an attack success rate of 83.33%. We conclude that data poisoning attacks against ASR systems represent a real threat that needs to be considered.

연구 동기 및 목표

  • ASR 시스템이 모델 훈련 중 데이터 풀기 공격에 취약한가를 조사하는 것.
  • 이전의 이미지 기반 방법과는 달리, 오디오 입력의 시간적 구조에 맞추어 설계된 새로운 데이터 풀기 기법을 개발하는 것.
  • 최소한의 데이터 삽입으로도 실제 가능성을 입증하면서도, 클린 레이블 특성을 유지하는 ASR 모델의 풀기 가능성을 입증하는 것.
  • 실제 ASR 작업—0에서 9까지의 숫자 시퀀스 인식—에 대한 공격의 효과성을 평가하는 것.

제안 방법

  • 목표 오디오 발화의 다수 프레임에 걸쳐 변형을 생성하는 시계열 인식 풀기 전략을 설계하여, 타겟 분류 오류를 유도하는 것.
  • 변형이 청취자에게 인지되지 않도록 최적화하고, 클린 레이블 특성을 유지하여, 풀린 샘플이 쉽게 탐지되지 않도록 하는 것.
  • 각 프레임이 목표 오디오의 타겟 전사로 향하도록 유도하는 시퀀스 간 분류 오류로 공격를 정의하는 것.
  • 풀린 샘플이 포함된 데이터셋으로 ASR 모델을 훈련하여, 모델이 목표 발화를 원하는 레이블로 잘못 인식하도록 하는 것.
  • 기울기 기반 최적화 방법을 사용하여, 목표 전사의 가능도를 극대화하면서도 청각적 왜곡을 최소화하는 적대적 변형을 생성하는 것.

실험 결과

연구 질문

  • RQ1순차적인 오디오 입력을 처리하는 자동 음성 인식 시스템에 데이터 풀기 공격이 효과적으로 적용될 수 있는가?
  • RQ2청각적으로 인지되지 않으면서도 ASR 모델에서 타겟 분류 오류를 유도할 수 있도록 클린 레이블 풀기 공격을 어떻게 설계할 수 있는가?
  • RQ3높은 성공률를 달성하기 위해 필요한 최소한의 풀링 비율은 얼마인가?
  • RQ4오디오 입력의 시간적 구조는 데이터 풀기 공격의 설계와 효과성에 어떤 영향을 미치는가?

주요 결과

  • VENOMAVE는 0에서 9까지의 숫자 시퀀스를 인식하도록 훈련된 ASR 시스템에서 83.33%의 공격 성공률를 성공적으로 달성하였다.
  • 상기 성공률를 달성하기 위해 평균적으로 훈련 데이터셋의 0.94%만 풀리게 하였다.
  • 이 방법은 클린 레이블 특성을 유지하여, 훈련 중에 풀린 샘플이 정상적으로 보이도록 하였다.
  • 이 공격는 이미지 기반 데이터 풀기에서는 존재하지 않는 순차적 성격으로 인해 도전 과제가 있는 오디오의 특성에도 효과적으로 작용하였다.
  • 결과적으로, 오디오 영역에서의 데이터 풀기는 ASR 시스템의 무결성에 심각한 위협이 될 수 있으며, 실현 가능하다는 것이 입증되었다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.