Research on the Defense Mechanism of Audio Adversarial Attack

Xianyan Wei, Yanru Feng, Xiaoying Wang · 2023

Automatic speaker verification (ASV) technology has become a core feature of intelligent voice devices. ASV systems are highly vulnerable to audio adversarial attacks, in which an attacker adds perturbations to the original audio to generate an adversarial sample; the human ear cannot distinguish between them but will deceive the ASV system, causing the system to fail to identify the real speaker. The existing defense means such as random masking are less effective against the FakeBob attack. Therefore, this paper proposes a method to eliminate the artificially added perturbations in the original audio using the high-frequency component of masked audio, combined with a multi-headed attention model for audio recovery, and re-input into the ASV system for verification after recovery. The experimental results show that the accuracy of using the high-frequency component of masked audio combined with the multi-head attention model to recover the adversarial audio to the original audio reaches 95.9%, which can effectively improve the robustness of the ASV system.

Read the paper · More papers on PaperTik