发表机构
School of Cyber Engineering, Xidian University, Xi’an, China(西安电子科技大学信息工程学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究语音识别模型的自然后门攻击,采用普通声音作触发器,在两个数据集和三个模型上实验,发现该攻击成功率高,少量中毒样本即可,且不易被检测,对模型安全构成严重威胁
AI 中文摘要
随着深度学习的快速发展,其漏洞近年来逐渐显现。这项工作聚焦于语音识别系统的后门攻击。我们采用自然界或日常生活中普通的声音作为自然后门攻击的触发器。在两个数据集和三个模型上进行实验,验证自然后门攻击的性能,并探究中毒率、触发持续时间和混合比例对攻击性能的影响。结果表明,自然后门攻击成功率高,且不影响良性样本的模型性能,即便触发器短或幅度低。仅需5%的中毒样本就能实现近100%的攻击成功率。此外,后门会被自然界中的相应声音自动激活,不易被检测,危害更大。
英文摘要
With the rapid development of deep learning, its vulnerability has gradually emerged in recent years. This work focuses on backdoor attacks on speech recognition systems. We adopt sounds that are ordinary in nature or in our daily life as triggers for natural backdoor attacks. We conduct experiments on two datasets and three models to validate the performance of natural backdoor attacks and explore the effects of poisoning rate, trigger duration and blend ratio on the performance of natural backdoor attacks. Our results show that natural backdoor attacks have a high attack success rate without compromising model performance on benign samples, even with short or low-amplitude triggers. It requires only 5% of poisoned samples to achieve a near 100% attack success rate. In addition, the backdoor will be automatically activated by the corresponding sound in nature, which is not easy to be detected and will bring severer harm.
CommentsThis is the authors' manuscript of a chapter published in Machine Learning for Cyber Security, Lecture Notes in Computer Science, vol. 13655, pp. 597-610 (2023)
Journal refMachine Learning for Cyber Security, Lecture Notes in Computer Science, vol. 13655, pp. 597-610 (2023)
DOI:10.1007/978-3-031-20096-0_45