Gupta, B B, Tan, Hao, Gu, Zhaoquan, Wang, Le, Zhang, Huan and Tian, Zhihong (2022) Improving adversarial transferability by temporal and spatial momentum in urban speaker recognition systems. Computers and Electrical Engineering, 104. ISSN 0045-7906
pii/S0045790622006619 - Published Version
Download (2kB)
Abstract
DNN-based speaker recognition systems (SRSs) in smart cities suffer from adversarial attacks, which have caused widespread concern. An attacker can fool the SRSs by adding imperceptible perturbations to benign audio. Recent studies have shown that adversarial attacks could achieve almost 100% attack success rate in the white-box but perform poorly in the black-box. Existing attacks do not effectively use the gradient information of the available white-box models, which is easy to over-fit the target model. To tackle the problem, we propose a temporal and spatial momentum-based iteration gradient sign method (TSMI-FGSM). Specifically, we introduce the sample neighborhood and interior space, and accumulate the gradient information of the randomly sampled points in these two spaces to correct and update direction by tuning strategies during each iteration. The experiment results with 9 SRSs demonstrate that our method significantly enhances the transferability of the adversarial examples compared to state-of-the-art attacks.
Affiliation: | Skyline University College |
---|---|
SUC Author(s): | Gupta, B B |
All Author(s): | Gupta, B B, Tan, Hao, Gu, Zhaoquan, Wang, Le, Zhang, Huan and Tian, Zhihong |
Item Type: | Article |
Subjects: | B Information Technology > BJ Computer Science |
Divisions: | Skyline University College > School of IT |
Depositing User: | Mr Mosys Team |
Date Deposited: | 25 Dec 2023 13:53 |
Last Modified: | 25 Dec 2023 13:53 |
URI: | https://research.skylineuniversity.ac.ae/id/eprint/635 |
Publisher URL: | https://doi.org/10.1016/j.compeleceng.2022.108446 |
Publisher OA policy: | https://v2.sherpa.ac.uk/id/publication/27887?templ... |
Related URLs: |
|
Actions (login required)
Statistics for this ePrint Item |