Universal Adversarial Perturbation from Dominant Feature for Speaker Recognition

Xiaochen Liu,Hao Tan,Junjian Zhang,Aiping Li,Zhaoquan Gu
DOI: https://doi.org/10.1109/dsc59305.2023.00031
2023-01-01
Abstract:Deep neural networks (DNNs) have greatly improved speaker recognition performance. However, DNNs are vulnerable to imperceptible adversarial example, which has attracted the attention in both academic and industrial areas in recent years. Although many elegant adversarial attack methods have been proposed, few of them studied Universal Adversarial Perturbation (UAP) against speaker recognition. In this paper, we propose a novel algorithm from the perspective of dominant features to generate UAP to mislead speaker recognition DNNs. Our method uses dominance as an optimization objective, and designs a tiny neural network to improve the efficiency. We conduct experiments on the TIMIT dataset and our method has achieved state-of-the-art results regarding attack success rate and imperceptibility. Moreover, leveraging the concept of dominant feature, our method significantly improves the training speed and can generate UAP more efficiently.
What problem does this paper attempt to address?