EIUAPA: an efficient and imperceptible universal adversarial attack on audio classification models

Weixun Li, Pengzhou Jia, Huifeng Li, Bin Ma, Bo Li, Dexin Wu, Haoran Li · International Journal of Computational Science and Engineering · 2024

The domain of audio classification models is emerging as a significant paradigm, albeit susceptible to universal adversarial attacks. These attacks involve the insertion of a single optimal perturbation into all audio samples, leading to incorrect predictions. Nonetheless, existing attack methodologies are hindered by inefficiencies and imperceptibility challenges. In order to streamline the attack process effectively, we propose a two-step strategy EIUAPA that offers an optimal initiation point for the perturbation optimisation process, resulting in a notable decrease in generation time. To maintain imperceptibility, we present a range of metrics focusing on perturbation concealment, serving as benchmarks for optimisation. These metrics ensure that perturbations are not only concealed in the frequency and time domains but also remain statistically indistinguishable. Experimental results demonstrate that our method generates UAPs 87.5% and 86.8% faster than baseline methods, with improved signal-to-noise ratio (SNR) and attack success rate (ASR) scores.

Read the paper · More papers on PaperTik