Generate Unnoticeable Adversarial Examples on Audio Classification Models with Multi-perspective Objectives
摘要
In recent years, there has been notable progress in the development of audio classification models, yet they remain vulnerable to adversarial attacks. While research into attack methodologies pertaining to images has experienced significant advancements, comparatively less attention has been directed towards attacks specifically targeting audio classification models. Furthermore, prevailing techniques for compromising audio models often yield adversarial examples that are readily identifiable due to discernible noise artifacts, thereby distinguishing them from clean samples. To address this disparity, we propose Multi-perspective Unnoticeable Audio Attack (MU2A for short), an innovative framework designed for crafting imperceptible adversarial examples for both untargeted and targeted assaults on audio classification models. Concretely, we frame our attack strategy as an optimization dilemma and incorporate the Multi-Scale Spectral (MSS) score, Decibels score, and Mutual Information within the objective function. This formulation aims to minimize the disparity between clean audio signals and their adversarial counterparts across frequency and time domains, as well as probabilistic perspectives. Empirical evaluations demonstrate that the magnitude of the adversarial perturbation generated by MU2A represents only 0.625% of the clean example, rendering the resulting adversarial examples acoustically indistinguishable to human perception.