Fast speech adversarial example generation for keyword spotting system with conditional GAN

被引:4
|
作者
Wang, Donghua [1 ]
Dong, Li [1 ]
Wang, Rangding [1 ]
Yan, Diqun [1 ]
机构
[1] Ningbo Univ, Fac Elect Engn & Comp Sci, Ningbo 315211, Zhejiang, Peoples R China
基金
中国国家自然科学基金; 浙江省自然科学基金;
关键词
Adversarial attack; Speech adversarial examples; Conditional generative adversarial network; Keyword spotting (KWS);
D O I
10.1016/j.comcom.2021.08.010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Deep network-based keyword spotting (KWS) has embraced great success in many speech assistant applications. However, such network-based KWS systems were demonstrated vulnerable to adversarial attacks. In this work, we propose to utilize a conditional generative adversarial network (CGAN) to efficiently craft targeted speech adversarial examples. Specifically, we first transform the attacking target label into a vector, which is treated as the condition input of CGAN. The generator in CGAN is tasked to generate perturbation that could make the adversarial example misclassified as the pre-specified target keyword, while simultaneously deceiving the discriminator to misclassify the adversarial example as genuine. The discriminator aims to differentiate the crafted adversarial examples from the legitimate samples. Secondly, the target network-based KWS classifier(s) are ensembled and integrated into the proposed CGAN framework to enforce the generator to construct model independent perturbation. The classification error loss of the target KWS is back-propagated through gradients for guiding the weight update of the generator. Finally, with properly devised network architecture and training procedure, we obtain a well-trained generator that generates the adversarial perturbation for a given speech clip and target label. Experimental results show that the crafted adversarial examples could effectively attack the state-of-the-art KWS system with quite a high attack success rate, while attaining acceptable perception quality.
引用
收藏
页码:145 / 156
页数:12
相关论文
共 1 条
  • [1] Adversarial Example Generation Method for Vehicle Environment Perception System
    Huang S.
    Zhang Z.
    Dong D.
    Qin J.
    Tongji Daxue Xuebao/Journal of Tongji University, 2022, 50 (10): : 1377 - 1384