TY - GEN
T1 - Adversarial Example Attacks against ASR Systems
T2 - 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
AU - Zhang, Xiao
AU - Tan, Hao
AU - Huang, Xuan
AU - Zhang, Denghui
AU - Tang, Keke
AU - Gu, Zhaoquan
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - With the development of hardware and algorithms, ASR(Automatic Speech Recognition) systems evolve a lot. As The models get simpler, the difficulty of development and deployment become easier, ASR systems are getting closer to our life. On the one hand, we often use APPs or APIs of ASR to generate subtitles and record meetings. On the other hand, smart speaker and self-driving car rely on ASR systems to control AIoT devices. In past few years, there are a lot of works on adversarial examples attacks against ASR systems. By adding a small perturbation to the waveforms, the recognition results make a big difference. In this paper, we describe the development of ASR system, different assumptions of attacks, and how to evaluate these attacks. Next, we introduce the current works on adversarial examples attacks from two attack assumptions: white-box attack and black-box attack. Different from other surveys, we pay more attention to which layer they perturb waveforms in ASR system, the relationship between these attacks, and their implementation methods. We focus on the effect of their works.
AB - With the development of hardware and algorithms, ASR(Automatic Speech Recognition) systems evolve a lot. As The models get simpler, the difficulty of development and deployment become easier, ASR systems are getting closer to our life. On the one hand, we often use APPs or APIs of ASR to generate subtitles and record meetings. On the other hand, smart speaker and self-driving car rely on ASR systems to control AIoT devices. In past few years, there are a lot of works on adversarial examples attacks against ASR systems. By adding a small perturbation to the waveforms, the recognition results make a big difference. In this paper, we describe the development of ASR system, different assumptions of attacks, and how to evaluate these attacks. Next, we introduce the current works on adversarial examples attacks from two attack assumptions: white-box attack and black-box attack. Different from other surveys, we pay more attention to which layer they perturb waveforms in ASR system, the relationship between these attacks, and their implementation methods. We focus on the effect of their works.
KW - AI security
KW - ASR
KW - adversarial attacks
KW - deep learning
UR - https://www.scopus.com/pages/publications/85141364156
U2 - 10.1109/DSC55868.2022.00071
DO - 10.1109/DSC55868.2022.00071
M3 - 会议稿件
AN - SCOPUS:85141364156
T3 - Proceedings - 2022 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
SP - 470
EP - 477
BT - Proceedings - 2022 7th IEEE International Conference on Data Science in Cyberspace, DSC 2022
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 11 July 2022 through 13 July 2022
ER -