Blind adversarial attack based on time-frequency models for speech recognition systems
Part Of
Proceedings of SPIE - The International Society for Optical Engineering
Journal Volume
13510
Start Page
15
ISSN
0277786X
ISBN (of the container)
978-151068812-4
ISBN
978-151068812-4
Date Issued
2025-02-05
Author(s)
Yi-An Chen
Editor(s)
Jae-Gon Kim
Chia-Hung Yeh
Kemao Qian
Masayuki Nakajima
Chuan-Yu Chang
Phooi Yee Lau
DOI
10.1117/12.3057458
Abstract
As intelligent devices become increasingly prevalent in our daily life, the requirement of privacy has been significantly increased.To address the issue of privacy protection, the topic of adversarial attack appeared in recent year.Initially, adversarial attack was predominantly applied to image recognition.However, due to the unique characteristics of audio data, the attacks suitable for images, e.g., additive perturbations, may not be applicable in audio cases.The goal of this study is to perform adversarial attack on speech signals such that they cannot be recognized by automatic speech recognition (ASR) systems but still be identified by humans.We introduce several distinct methods for noise addition and precision-reducing to generate adversarial examples for ASR systems.The proposed approach leverages audio features extracted through filtering and time-frequency transformations.The adversarial samples generated using the proposed methods not only retain their intelligibility for human listeners but also achieve a 100% success rate in blind attacks against ASR systems with unknown architectures and parameters.
Event(s)
2025 International Workshop on Advanced Imaging Technology, IWAIT 2025
Publisher
SPIE
Type
conference paper
