Perceptual-based deep-learning denoiser as a defense against adversarial attacks on ASR systems

07/12/2021
by   Anirudh Sreeram, et al.
0

In this paper we investigate speech denoising as a defense against adversarial attacks on automatic speech recognition (ASR) systems. Adversarial attacks attempt to force misclassification by adding small perturbations to the original speech signal. We propose to counteract this by employing a neural-network based denoiser as a pre-processor in the ASR pipeline. The denoiser is independent of the downstream ASR model, and thus can be rapidly deployed in existing systems. We found that training the denoisier using a perceptually motivated loss function resulted in increased adversarial robustness without compromising ASR performance on benign samples. Our defense was evaluated (as a part of the DARPA GARD program) on the 'Kenansville' attack strategy across a range of attack strengths and speech samples. An average improvement in Word Error Rate (WER) of about 7.7 undefended model at 20 dB signal-to-noise-ratio (SNR) attack strength.

READ FULL TEXT
research
03/10/2023

MIXPGD: Hybrid Adversarial Training for Speech Recognition Systems

Automatic speech recognition (ASR) systems based on deep neural networks...
research
03/31/2021

Adversarial Attacks and Defenses for Speech Recognition Systems

The ubiquitous presence of machine learning systems in our lives necessi...
research
06/14/2019

Perceptual Based Adversarial Audio Attacks

Recent work has shown the possibility of adversarial attacks on automati...
research
05/12/2020

Automatic Estimation of Inteligibility Measure for Consonants in Speech

In this article, we provide a model to estimate a real-valued measure of...
research
11/03/2022

Leveraging Domain Features for Detecting Adversarial Attacks Against Deep Speech Recognition in Noise

In recent years, significant progress has been made in deep model-based ...
research
03/19/2021

SoK: A Modularized Approach to Study the Security of Automatic Speech Recognition Systems

With the wide use of Automatic Speech Recognition (ASR) in applications ...
research
04/08/2022

Defense against Adversarial Attacks on Hybrid Speech Recognition using Joint Adversarial Fine-tuning with Denoiser

Adversarial attacks are a threat to automatic speech recognition (ASR) s...

Please sign up or login with your details

Forgot password? Click here to reset