错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards Efficient Universal Adversarial Attack on Audio Classification Models: A Two-Step Method

  • Huifeng Li,
  • Pengzhou Jia,
  • Weixun Li,
  • Bin Ma,
  • Bo Li,
  • Dexin Wu,
  • Haoran Li

摘要

Audio classification models have witnessed remarkable progress in the past few years. As a counterpart, such models are also vulnerable to adversarial attacks by examples with indistinguishable perturbations that produce incorrect predictions. There are two types of perturbations, i.e., audio-dependent and audio-agnostic. Audio-dependent perturbations involve crafting perturbations for each clean example, while audio-agnostic attacks create a universal adversarial perturbation (UAP) that can fool the target model for almost all clean examples. However, the existing audio classification model-oriented attack methods still suffer from unideal efficiency. In this paper, we aim to bridge this gap. In order to achieve an efficient attack, we transformed the complex UAP generate problem into a superposition of two simple problems and proposed a two-step-based strategy. Specifically, in the first step, we generate audio-dependent (individual) perturbations for each target example. In the second phase, we aggregate the generated perturbations and fine-turn them into UAPs. By this strategy, we can optimize the desired UAPs at an ideal starting point, resulting in a remarkably efficient. Experiments show that the proposed method can generate UAP in 87.5% and 86.8% less time than similar methods for untargeted and targeted attacks while having a better SNR score.