Pith. sign in

REVIEW 2 cited by

Robust Audio Adversarial Example for a Physical Attack

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1810.11793 v4 pith:EXKIRQK7 submitted 2018-10-28 cs.LG cs.CRcs.SDeess.ASstat.ML

classification cs.LGcs.CRcs.SDeess.ASstat.ML
keywords adversarialexamplesattackphysicalaudiomethodablegenerated
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

We propose a method to generate audio adversarial examples that can attack a state-of-the-art speech recognition model in the physical world. Previous work assumes that generated adversarial examples are directly fed to the recognition model, and is not able to perform such a physical attack because of reverberation and noise from playback environments. In contrast, our method obtains robust adversarial examples by simulating transformations caused by playback or recording in the physical world and incorporating the transformations into the generation process. Evaluation and a listening experiment demonstrated that our adversarial examples are able to attack without being noticed by humans. This result suggests that audio adversarial examples generated by the proposed method may become a real threat.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Imperio: Robust Over-the-Air Adversarial Examples for Automatic Speech Recognition Systems

    cs.CR 2019-08 conditional novelty 6.0 of 10

    Imperio generates targeted over-the-air adversarial audio for a hybrid ASR system by optimizing against many simulated room impulse responses, and achieves some 0% WER transcriptions in real rooms.

  2. V2S attack: building DNN-based voice conversion from automatic speaker verification

    cs.SD 2019-08 conditional novelty 6.0 of 10

    A voice impersonation system is trained by deceiving a white-box automatic speaker verification model, using an ASR model to preserve content, and it performs comparably to voice conversion trained on only a few targe...

Pith tools