On the Detection of Adaptive Adversarial Attacks in Speaker Verification Systems

Zesheng Chen · IEEE Internet of Things Journal · 2023

Speaker verification (SV) systems have been widely used in smartphones and Internet of Things devices to identify legitimate users. In recent work, it has been shown that adversarial attacks, such as FAKEBOB, can work effectively against SV systems. The goal of this article is to design a detector that can distinguish an original audio from an audio contaminated by adversarial attacks, if the original audio and the audio before contaminated by the attack have a similar signal-to-noise ratio. Specifically, our designed detector, called MEH-FEST, calculates the minimum energy in an audio signal’s high-frequency band through the short-time Fourier transform and uses it as a detection metric. Through both analysis and experiments, we show that our proposed detector is easy to implement, fast to process an input audio, and effective in determining whether an audio is corrupted by FAKEBOB attacks. The experimental results indicate that the detector is extremely effective: with near zero false-positive and false-negative rates for detecting FAKEBOB attacks in Gaussian mixture model (GMM) and i-vector SV systems. Moreover, adaptive adversarial attacks against our proposed detector and their countermeasures are discussed and studied, showing the game between attackers and defenders.

Read the paper · More papers on PaperTik