PRIVACY ATTACKS FOR AUTOMATIC SPEECH RECOGNITION ACOUSTIC MODELS IN A FEDERATED LEARNING FRAMEWORK

被引:10
|
作者
Tomashenko, Natalia [1 ]
Mdhaffar, Salima [1 ]
Tommasi, Marc [2 ]
Esteve, Yannick [1 ]
Bonastre, Jean-Francois [1 ]
机构
[1] Avignon Univ, LIA, Avignon, France
[2] Univ Lille, Cent Lille, INRIA, CNRS,UMR 9189 CRIStAL, Lille, France
来源
2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP) | 2022年
关键词
Privacy; federated learning; acoustic models; attack models; speech recognition; speaker verification;
D O I
10.1109/ICASSP43922.2022.9746541
中图分类号
O42 [声学];
学科分类号
070206 ; 082403 ;
摘要
This paper investigates methods to effectively retrieve speaker information from the personalized speaker adapted neural network acoustic models (AMs) in automatic speech recognition (ASR). This problem is especially important in the context of federated learning of ASR acoustic models where a global model is learnt on the server based on the updates received from multiple clients. We propose an approach to analyze information in neural network AMs based on a neural network footprint on the so-called Indicator dataset. Using this method, we develop two attack models that aim to infer speaker identity from the updated personalized models without access to the actual users' speech data. Experiments on the TED-LIUM 3 corpus demonstrate that the proposed approaches are very effective and can provide equal error rate (EER) of 1-2%.
引用
收藏
页码:6972 / 6976
页数:5
相关论文
共 50 条
  • [31] Adversarial Examples for Automatic Speech Recognition: Attacks and Countermeasures
    Hu, Shengshan
    Shang, Xingcan
    Qin, Zhan
    Li, Minghui
    Wang, Qian
    Wang, Cong
    IEEE COMMUNICATIONS MAGAZINE, 2019, 57 (10) : 120 - 126
  • [32] Split Aggregation: Lightweight Privacy-Preserving Federated Learning Resistant to Byzantine Attacks
    Lu, Zhi
    Lu, SongFeng
    Cui, YongQuan
    Tang, XueMing
    Wu, JunJun
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5575 - 5590
  • [33] Model compression and privacy preserving framework for federated learning
    Zhu, Xi
    Wang, Junbo
    Chen, Wuhui
    Sato, Kento
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 140 : 376 - 389
  • [34] Does Differential Privacy Really Protect Federated Learning From Gradient Leakage Attacks?
    Hu, Jiahui
    Du, Jiacheng
    Wang, Zhibo
    Pang, Xiaoyi
    Zhou, Yajie
    Sun, Peng
    Ren, Kui
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (12) : 12635 - 12649
  • [35] ENABLING ON-DEVICE TRAINING OF SPEECH RECOGNITION MODELS WITH FEDERATED DROPOUT
    Guliani, Dhruv
    Zhou, Lillian
    Ryu, Changwan
    Yang, Tien-Ju
    Zhang, Harry
    Xiao, Yonghui
    Beaufays, Francoise
    Motta, Giovanni
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 8757 - 8761
  • [36] A survey on privacy-preserving federated learning against poisoning attacks
    Xia, Feng
    Cheng, Wenhao
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (10): : 13565 - 13582
  • [37] Enhancing Privacy of Spatiotemporal Federated Learning Against Gradient Inversion Attacks
    Zheng, Lele
    Cao, Tang
    Jiang, Renhe
    Taura, Kenjiro
    Shen, Yulong
    Li, Sheng
    Yoshikawa, Masatoshi
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, PT I, DASFAA 2024, 2024, 14850 : 457 - 473
  • [38] A Federated Deep Learning Framework for Privacy-Preserving Consumer Electronics Recommendations
    Wu, Jintao
    Zhang, Jingyi
    Bilal, Muhammad
    Han, Feng
    Victor, Nancy
    Xu, Xiaolong
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 2628 - 2638
  • [39] Advancing Federated Learning Privacy With Quantum Communication Techniques: A Robust Scalable Framework
    Pei, Jiaming
    Wang, Lukun
    Awan, Nabeela
    Alturki, Ryan
    IEEE SYSTEMS MAN AND CYBERNETICS MAGAZINE, 2025, 11 (02): : 51 - 58
  • [40] Federated Learning Based Privacy Ensured Sensor Communication in IoT Networks: A Taxonomy, Threats and Attacks
    Manzoor, Sheikh Imroza
    Jain, Sanjeev
    Singh, Yashwant
    Singh, Harvinder
    IEEE ACCESS, 2023, 11 : 42248 - 42275