Breaking Speaker Recognition with PaddingBack

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Ye, Zhe, Yan, Diqun, Dong, Li, Shen, Kailai
Formato: Preprint
Publicado: 2023
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911792098181120
author Ye, Zhe
Yan, Diqun
Dong, Li
Shen, Kailai
author_facet Ye, Zhe
Yan, Diqun
Dong, Li
Shen, Kailai
contents Machine Learning as a Service (MLaaS) has gained popularity due to advancements in Deep Neural Networks (DNNs). However, untrusted third-party platforms have raised concerns about AI security, particularly in backdoor attacks. Recent research has shown that speech backdoors can utilize transformations as triggers, similar to image backdoors. However, human ears can easily be aware of these transformations, leading to suspicion. In this paper, we propose PaddingBack, an inaudible backdoor attack that utilizes malicious operations to generate poisoned samples, rendering them indistinguishable from clean ones. Instead of using external perturbations as triggers, we exploit the widely-used speech signal operation, padding, to break speaker recognition systems. Experimental results demonstrate the effectiveness of our method, achieving a significant attack success rate while retaining benign accuracy. Furthermore, PaddingBack demonstrates the ability to resist defense methods and maintain its stealthiness against human perception.
format Preprint
id arxiv_https___arxiv_org_abs_2308_04179
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Breaking Speaker Recognition with PaddingBack
Ye, Zhe
Yan, Diqun
Dong, Li
Shen, Kailai
Cryptography and Security
Sound
Audio and Speech Processing
Signal Processing
Machine Learning as a Service (MLaaS) has gained popularity due to advancements in Deep Neural Networks (DNNs). However, untrusted third-party platforms have raised concerns about AI security, particularly in backdoor attacks. Recent research has shown that speech backdoors can utilize transformations as triggers, similar to image backdoors. However, human ears can easily be aware of these transformations, leading to suspicion. In this paper, we propose PaddingBack, an inaudible backdoor attack that utilizes malicious operations to generate poisoned samples, rendering them indistinguishable from clean ones. Instead of using external perturbations as triggers, we exploit the widely-used speech signal operation, padding, to break speaker recognition systems. Experimental results demonstrate the effectiveness of our method, achieving a significant attack success rate while retaining benign accuracy. Furthermore, PaddingBack demonstrates the ability to resist defense methods and maintain its stealthiness against human perception.
title Breaking Speaker Recognition with PaddingBack
topic Cryptography and Security
Sound
Audio and Speech Processing
Signal Processing
url https://arxiv.org/abs/2308.04179