Metamorph: Injecting Inaudible Commands into Over-the-air Voice Controlled Systems
Tao Chen, Longfei Shangguan, Zhenjiang Li, Kyle Jamieson
摘要
—This paper presents Metamorph, a system that generates imperceptible audio that can survive over-the-air transmission to attack the neural network of a speech recognition system. The key challenge stems from how to ensure the added perturbation of the original audio in advance at the sender side is immune to unknown signal distortions during the transmission process. Our empirical study reveals that signal distortion is mainly due to device and channel frequency selectivity but with different characteristics. This brings a chance to capture and further pre-code this impact to generate adversarial examples that are robust to the over-the-air transmission. We leverage this opportunity in Metamorph and obtain an initial perturbation that captures the core distortion’s impact from only a small set of prior measurements, and then take advantage of a domain adaptation algorithm to refine the perturbation to further improve the attack distance and reliability. Moreover, we consider also reducing human perceptibility of the added perturbation. Evaluation achieves a high attack success rate (90%) over the attack distance of up to 6 m. Within a moderate distance, e.g. , 3 m, Metamorph maintains this high success rate, yet can be further adapted to largely improve the audio quality, confirmed by a human perceptibility study.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- AdvPulse: Universal, Synchronization-free, and Targeted Audio Adversarial Attacks via Subsecond PerturbationsZhuohang Li, Yi Wu, Jian Liu, Yingying Chen 等CCS 2020 · 被引用 107 次
- Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal InformationBaolin Zheng, Peipei Jiang, Qian Wang, Qi Li 等CCS 2021 · 被引用 73 次
- Dompteur: Taming Audio Adversarial ExamplesThorsten Eisenhofer, Lea Schönherr, Joel Frank, Lars Speckemeier 等USENIX Security 2021 · 被引用 29 次
- AntiFake: Using Adversarial Audio to Prevent Unauthorized Speech SynthesisZhiyuan Yu, Shixuan Zhai, Ning ZhangCCS 2023 · 被引用 29 次
- SPECPATCH: Human-In-The-Loop Adversarial Audio Spectrogram Patch Attack on Speech RecognitionHanqing Guo, Yuanda Wang, Nikolay Ivanov, Li Xiao 等CCS 2022 · 被引用 22 次
它引用的顶会 Paper6
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang 等CCS 2017 · 被引用 753 次
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang 等USENIX Security 2016 · 被引用 672 次
- CommanderSong: A Systematic Approach for Practical Adversarial Voice RecognitionXuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long 等USENIX Security 2018 · 被引用 389 次
- LEMNA: Explaining Deep Learning based Security ApplicationsWenbo Guo, Dongliang Mu, Jun Xu, Purui Su 等CCS 2018 · 被引用 336 次
- Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic HidingLea Schönherr, Katharina Kohls, Steffen Zeiler, Thorsten Holz 等NDSS 2019 · 被引用 315 次
相关 Paper
- Echo: Reverberation-based Fast Black-Box Adversarial Attacks on Intelligent Audio SystemsMeng Xue, Kuang Peng, Xueluan Gong, Qian Zhang 等UbiComp 2023 · 被引用 2 次
- Real-Time Neural Voice CamouflageMia Chiquier, Chengzhi Mao, Carl VondrickICLR 2022 · 被引用 9 次
- Robust Adversarial Attacks Against DNN-Based Wireless Communication SystemsAlireza Bahramali, Milad Nasr, Amir Houmansadr, Dennis Goeckel 等CCS 2021 · 被引用 80 次
- Cross-modal and Cross-medium Adversarial Attack for AudioLiguo Zhang, Zilin Tian, Yunfei Long, Sizhao Li 等ACM MM 2023 · 被引用 1 次
- Hear "No Evil", See "Kenansville"*: Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification SystemsHadi Abdullah, Muhammad Sajidur Rahman, Washington Garcia, Kevin Warren 等S&P 2021 · 被引用 54 次
