Unraveling Adversarial Examples against Speaker Identification -- Techniques for Attack Detection and Victim Model Classification

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Joshi, Sonal, Thebaud, Thomas, Villalba, Jesús, Dehak, Najim
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916142284537856
author Joshi, Sonal
Thebaud, Thomas
Villalba, Jesús
Dehak, Najim
author_facet Joshi, Sonal
Thebaud, Thomas
Villalba, Jesús
Dehak, Najim
contents Adversarial examples have proven to threaten speaker identification systems, and several countermeasures against them have been proposed. In this paper, we propose a method to detect the presence of adversarial examples, i.e., a binary classifier distinguishing between benign and adversarial examples. We build upon and extend previous work on attack type classification by exploring new architectures. Additionally, we introduce a method for identifying the victim model on which the adversarial attack is carried out. To achieve this, we generate a new dataset containing multiple attacks performed against various victim models. We achieve an AUC of 0.982 for attack detection, with no more than a 0.03 drop in performance for unknown attacks. Our attack classification accuracy (excluding benign) reaches 86.48% across eight attack types using our LightResNet34 architecture, while our victim model classification accuracy reaches 72.28% across four victim models.
format Preprint
id arxiv_https___arxiv_org_abs_2402_19355
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Unraveling Adversarial Examples against Speaker Identification -- Techniques for Attack Detection and Victim Model Classification
Joshi, Sonal
Thebaud, Thomas
Villalba, Jesús
Dehak, Najim
Sound
Cryptography and Security
Machine Learning
Audio and Speech Processing
Adversarial examples have proven to threaten speaker identification systems, and several countermeasures against them have been proposed. In this paper, we propose a method to detect the presence of adversarial examples, i.e., a binary classifier distinguishing between benign and adversarial examples. We build upon and extend previous work on attack type classification by exploring new architectures. Additionally, we introduce a method for identifying the victim model on which the adversarial attack is carried out. To achieve this, we generate a new dataset containing multiple attacks performed against various victim models. We achieve an AUC of 0.982 for attack detection, with no more than a 0.03 drop in performance for unknown attacks. Our attack classification accuracy (excluding benign) reaches 86.48% across eight attack types using our LightResNet34 architecture, while our victim model classification accuracy reaches 72.28% across four victim models.
title Unraveling Adversarial Examples against Speaker Identification -- Techniques for Attack Detection and Victim Model Classification
topic Sound
Cryptography and Security
Machine Learning
Audio and Speech Processing
url https://arxiv.org/abs/2402.19355