Demystifying Limited Adversarial Transferability in Automatic Speech Recognition Systems
Hadi Abdullah, Aditya Karlekar, Vincent Bindschaedler, Patrick Traynor
Abstract
The targeted transferability of adversarial samples enables attackers to exploit black-box models in the real-world. The most popular method to produce these adversarial samples is optimization attacks, which have been shown to achieve a high level of transferability in some domains. However, recent research has demonstrated that these attack samples fail to transfer when applied to Automatic Speech Recognition Systems (ASRs). In this paper, we investigate factors preventing this transferability via exhaustive experimentation. To do so, we perform an ablation study on each stage of the ASR pipeline. We discover and quantify six factors (i.e., input type, MFCC, RNN, output type, and vocabulary and sequence sizes) that impact the targeted transferability of optimization attacks against ASRs. Future research can leverage our findings to build ASRs that are more robust to other transferable attack types (e.g., signal processing attacks), or to modify architectures in other domains to reduce their exposure to targeted transferability of optimization attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 580f1664-68b6-4f0a-8934-5593cf031fe7Cited by top-tier papers3
- Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm RegularizationYujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding et al.CVPR 2024 · 15 citations
- QFA2SR: Query-Free Adversarial Transfer Attacks to Speaker Recognition SystemsGuangke Chen, Yedi Zhang, Zhe Zhao, Fu SongUSENIX Security 2023
- Attacks as Defenses: Designing Robust Audio CAPTCHAs Using Attacks on Automatic Speech Recognition SystemsHadi Abdullah, Aditya Karlekar, Saurabh Prasad, Muhammad Sajidur Rahman et al.NDSS 2023
Related papers
- Hear "No Evil", See "Kenansville"*: Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification SystemsHadi Abdullah, Muhammad Sajidur Rahman, Washington Garcia, Kevin Warren et al.S&P 2021 · 54 citations
- Zero-Query Adversarial Attack on Black-box Automatic Speech Recognition SystemsZheng Fang, Tao Wang, Lingchen Zhao, Shenyi Zhang et al.CCS 2024 · 11 citations
- WaveGuard: Understanding and Mitigating Audio Adversarial ExamplesShehzeen Hussain, Paarth Neekhara, Shlomo Dubnov, Julian J. McAuley et al.USENIX Security 2021 · 89 citations
- KENKU: Towards Efficient and Stealthy Black-box Adversarial Attacks against ASR SystemsXinghui Wu, Shiqing Ma, Chao Shen, Chenhao Lin et al.USENIX Security 2023
- Time Shuffle: A Transferability-Booster for Multiple Audio Adversarial TasksJiacheng Deng, Dengpan Ye, Yuhong Liu, Zhaolin Wei et al.AAAI 2026
