Detecting and Defending Against Adversarial Attacks on Automatic Speech Recognition via Diffusion Models

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Kühne, Nikolai L., Kitchen, Astrid H. F., Jensen, Marie S., Brøndt, Mikkel S. L., Gonzalez, Martin, Biscio, Christophe, Tan, Zheng-Hua
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914947960668160
author Kühne, Nikolai L.
Kitchen, Astrid H. F.
Jensen, Marie S.
Brøndt, Mikkel S. L.
Gonzalez, Martin
Biscio, Christophe
Tan, Zheng-Hua
author_facet Kühne, Nikolai L.
Kitchen, Astrid H. F.
Jensen, Marie S.
Brøndt, Mikkel S. L.
Gonzalez, Martin
Biscio, Christophe
Tan, Zheng-Hua
contents Automatic speech recognition (ASR) systems are known to be vulnerable to adversarial attacks. This paper addresses detection and defence against targeted white-box attacks on speech signals for ASR systems. While existing work has utilised diffusion models (DMs) to purify adversarial examples, achieving state-of-the-art results in keyword spotting tasks, their effectiveness for more complex tasks such as sentence-level ASR remains unexplored. Additionally, the impact of the number of forward diffusion steps on performance is not well understood. In this paper, we systematically investigate the use of DMs for defending against adversarial attacks on sentences and examine the effect of varying forward diffusion steps. Through comprehensive experiments on the Mozilla Common Voice dataset, we demonstrate that two forward diffusion steps can completely defend against adversarial attacks on sentences. Moreover, we introduce a novel, training-free approach for detecting adversarial attacks by leveraging a pre-trained DM. Our experimental results show that this method can detect adversarial attacks with high accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2409_07936
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Detecting and Defending Against Adversarial Attacks on Automatic Speech Recognition via Diffusion Models
Kühne, Nikolai L.
Kitchen, Astrid H. F.
Jensen, Marie S.
Brøndt, Mikkel S. L.
Gonzalez, Martin
Biscio, Christophe
Tan, Zheng-Hua
Audio and Speech Processing
Automatic speech recognition (ASR) systems are known to be vulnerable to adversarial attacks. This paper addresses detection and defence against targeted white-box attacks on speech signals for ASR systems. While existing work has utilised diffusion models (DMs) to purify adversarial examples, achieving state-of-the-art results in keyword spotting tasks, their effectiveness for more complex tasks such as sentence-level ASR remains unexplored. Additionally, the impact of the number of forward diffusion steps on performance is not well understood. In this paper, we systematically investigate the use of DMs for defending against adversarial attacks on sentences and examine the effect of varying forward diffusion steps. Through comprehensive experiments on the Mozilla Common Voice dataset, we demonstrate that two forward diffusion steps can completely defend against adversarial attacks on sentences. Moreover, we introduce a novel, training-free approach for detecting adversarial attacks by leveraging a pre-trained DM. Our experimental results show that this method can detect adversarial attacks with high accuracy.
title Detecting and Defending Against Adversarial Attacks on Automatic Speech Recognition via Diffusion Models
topic Audio and Speech Processing
url https://arxiv.org/abs/2409.07936