Effective Adversarial Sample Detection for Securing Automatic Speech Recognition
Chih‐Yang Lin, Yanzhang Wang, Shou-Kuan Lin, Isack Farady, Yih‐Kuen Jan, Wei-Yang Lin · 2024
Deep learning has emerged as a pivotal technology across various domains, demonstrating remarkable performance. However, its susceptibility to security threats, particularly adversarial samples, poses a significant concern. These samples can manipulate inputs slightly, deceiving models such as those used in image or speech recognition and potentially leading to incorrect predictions. This undermines the reliability of deep learning in critical applications. In this paper, we propose an effective method utilizing Autoencoder to detect and intercept audio adversarial attacks before they are input to speech recognition models. The proposed approach first uses clean audio data to train the Autoencoder model, then isolates adversarial samples from clean ones by comparing their features against normal features encoded in the Autoencoder. Our method does not require prior knowledge about the target automatic speech recognition model or attack methods. Experimental results show that it can effectively discriminate adversarial attack samples from clean ones with high accuracy.