Improving the Adversarial Robustness for Speaker Verification by Self-Supervised Learning

对抗制 计算机科学 稳健性(进化) 人工智能 对抗性机器学习 机器学习 生物化学 基因 化学
作者
Haibin Wu,Xü Liu,Andy T. Liu,Zhiyong Wu,Helen Meng,Hung-yi Lee
出处
期刊:IEEE/ACM transactions on audio, speech, and language processing [Institute of Electrical and Electronics Engineers]
卷期号:30: 202-217 被引量:11
标识
DOI:10.1109/taslp.2021.3133189
摘要

Previous works have shown that automatic speaker verification (ASV) is seriously vulnerable to malicious spoofing attacks, such as replay, synthetic speech, and recently emerged adversarial attacks. Great efforts have been dedicated to defending ASV against replay and synthetic speech; however, only a few approaches have been explored to deal with adversarial attacks. All the existing approaches to tackle adversarial attacks for ASV require the knowledge for adversarial samples generation, but it is impractical for defenders to know the exact attack algorithms that are applied by the in-the-wild attackers. This work is among the first to perform adversarial defense for ASV without knowing the specific attack algorithms. Inspired by self-supervised learning models (SSLMs) that possess the merits of alleviating the superficial noise in the inputs and reconstructing clean samples from the interrupted ones, this work regards adversarial perturbations as one kind of noise and conducts adversarial defense for ASV by SSLMs. Specifically, we propose to perform adversarial defense from two perspectives: 1) adversarial perturbation purification and 2) adversarial perturbation detection. The purification module aims at alleviating the adversarial perturbations in the samples and pulling the contaminated adversarial inputs back towards the decision boundary. Experimental results show that our proposed purification module effectively counters adversarial attacks and outperforms traditional filters from both alleviating the adversarial noise and maintaining the performance of genuine samples. The detection module aims at detecting adversarial samples from genuine ones based on the statistical properties of ASV scores derived by a unique ASV integrating with different number of SSLMs. Experimental results show that our detection module helps shield the ASV by detecting adversarial samples. Both purification and detection methods are helpful for defending against different kinds of attack algorithms. Moreover, since there is no common metric for evaluating the ASV performance under adversarial attacks, this work also formalizes evaluation metrics for adversarial defense considering both purification and detection based approaches into account. We sincerely encourage future works to benchmark their approaches based on the proposed evaluation framework.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
共享精神应助李朝富采纳,获得10
3秒前
10秒前
yuyu完成签到,获得积分10
10秒前
10秒前
Ted完成签到,获得积分10
10秒前
Hi完成签到,获得积分10
11秒前
jinyu完成签到,获得积分10
14秒前
jw完成签到,获得积分10
14秒前
IF完成签到,获得积分20
15秒前
windyxp发布了新的文献求助10
15秒前
16秒前
AthenaWang完成签到 ,获得积分10
16秒前
HCKACECE完成签到 ,获得积分10
20秒前
Hello应助直率的无极采纳,获得10
24秒前
中科院饲养员完成签到,获得积分10
24秒前
Master完成签到 ,获得积分10
24秒前
25秒前
科研通AI2S应助SuperD采纳,获得10
25秒前
26秒前
苍明发布了新的文献求助10
30秒前
汉堡包应助swing采纳,获得10
33秒前
儒雅儒雅完成签到,获得积分10
33秒前
小丸子完成签到 ,获得积分10
34秒前
昂叔的头发丝儿完成签到,获得积分10
34秒前
小班完成签到,获得积分10
39秒前
小尾巴完成签到 ,获得积分10
40秒前
41秒前
拂晓完成签到 ,获得积分10
45秒前
争做一名优秀的医学生ztt完成签到 ,获得积分10
48秒前
干就完了完成签到 ,获得积分20
50秒前
chshqin2发布了新的文献求助10
51秒前
afli完成签到 ,获得积分10
53秒前
优雅莞完成签到,获得积分10
53秒前
科研通AI2S应助彼得大帝采纳,获得10
54秒前
55秒前
研友_8yVV0L完成签到 ,获得积分10
59秒前
翟大有完成签到 ,获得积分0
1分钟前
shiney完成签到 ,获得积分10
1分钟前
nanci完成签到,获得积分10
1分钟前
寻道图强举报清爽的大树求助涉嫌违规
1分钟前
高分求助中
Un calendrier babylonien des travaux, des signes et des mois: Séries iqqur îpuš 1036
Sustainable Land Management: Strategies to Cope with the Marginalisation of Agriculture 1000
Corrosion and Oxygen Control 600
Python Programming for Linguistics and Digital Humanities: Applications for Text-Focused Fields 500
Heterocyclic Stilbene and Bibenzyl Derivatives in Liverworts: Distribution, Structures, Total Synthesis and Biological Activity 500
重庆市新能源汽车产业大数据招商指南(两链两图两池两库两平台两清单两报告) 400
Division and square root. Digit-recurrence algorithms and implementations 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2546297
求助须知:如何正确求助?哪些是违规求助? 2175702
关于积分的说明 5600550
捐赠科研通 1896461
什么是DOI,文献DOI怎么找? 946308
版权声明 565379
科研通“疑难数据库(出版商)”最低求助积分说明 503557