Audio Adversarial Examples: Targeted Attacks on Speech-to-Text

被引:533
作者
Carlini, Nicholas [1 ]
Wagner, David [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA 94720 USA
来源
2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018) | 2018年
基金
美国国家科学基金会;
关键词
D O I
10.1109/SPW.2018.00009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We construct targeted audio adversarial examples on automatic speech recognition. Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose (recognizing up to 50 characters per second of audio). We apply our white-box iterative optimization-based attack to Mozilla's implementation DeepSpeech end-to-end, and show it has a 100% success rate. The feasibility of this attack introduce a new domain to study adversarial examples.
引用
收藏
页码:1 / 7
页数:7
相关论文
共 40 条
[1]  
Nguyen A, 2015, PROC CVPR IEEE, P427, DOI 10.1109/CVPR.2015.7298640
[2]  
[Anonymous], P IEEE C COMP VIS PA
[3]  
[Anonymous], 2013, ICLR
[4]  
[Anonymous], 2017, P 10 ACM WORKSH ART
[5]  
[Anonymous], 2013, ARXIV PREPRINT ARXIV
[6]  
[Anonymous], 2017, ARXIV PREPRINT ARXIV
[7]  
[Anonymous], 2016, arXiv
[8]  
[Anonymous], 2014, ARXIV14125567V2CSCL
[9]  
[Anonymous], 2018, INT C MACHINE LEARNI
[10]  
Arnab A., 2017, ARXIV PREPRINT ARXIV