Imperceptible and Targeted Physical Attacks on Deep Learning-Based Speech Semantic Communications
Yuhao Hua, Xu Yang, Chen Lyu, Jia Liu, Yulong Shen, Weidong Yang, Norio Shiratori · 2025
The deep learning-based semantic communication system (DeepSC) is designed to improve the efficiency and accuracy of information transmission, by leveraging joint source-channel coding techniques to extract relevant semantic features. However, existing research on attack methods targeting DeepSC has primarily focused on text and image domains, leaving the speech domain largely unexplored. To this end, this paper proposes Iterative Semantic Gradient Update (ISGU), a novel approach for crafting physical layer adversarial attacks on DeepSC for speech transmission (DeepSC-ST). Specifically, we introduce a joint loss that combines the semantic similarity loss with Connectionist Temporal Classification loss to expedite the generation process of targeted attacks against the DeepSC-ST. In addition, we design an algorithm to generate adversarial examples, enhancing their imperceptibility by meticulously controlling the perturbation power added to the input speech. Extensive experiments indicate that ISGU is capable of rapidly generating highly covert adversarial examples, with a notably high attack success rate.