Audio adversarial attack: HIS attack
Jian Ma, Da Luo · 2022
The adversarial example is an input carefully designed by the attacker to tamper with the output of the neural network model. The emergence of audio adversarial example is to tamper with the end-to-end automatic speech recognition (ASR) system results. Due to the high difficulty of tampering with the ASR recognition results, the noise produced by today’s audio adversarial example generation methods is still easy to be noticed by humans and machines. In this paper, we propose an audio adversarial example generation method that makes audio adversarial example difficult to be perceived based on time-domain restriction. This method hides the adversarial perturbation noise in the speech part of audio by limiting the adversarial perturbation noise in the time domain. Our proposed method is more difficult to be detected by detection methods of audio adversarial example with equal attack performance compared to existing methods. We call the proposed method the HIS (hide in speech) attack.