Transferable universal adversarial perturbations against speaker recognition systems

Xiaochen Liu,Hao Tan,Junjian Zhang,Aiping Li,Zhaoquan Gu
DOI: https://doi.org/10.1007/s11280-024-01274-3
2024-05-11
World Wide Web
Abstract:Deep neural networks (DNN) exhibit powerful feature extraction capabilities, making them highly advantageous in numerous tasks. DNN-based techniques have become widely adopted in the field of speaker recognition. However, imperceptible adversarial perturbations can severely disrupt the decisions made by DNNs. In addition, researchers identified universal adversarial perturbations that can efficiently and significantly attack deep neural networks. In this paper, we propose an algorithm for conducting effective universal adversarial attacks by investigating the dominant features in the speaker recognition task. Through experiments in various scenarios, we find that our perturbations are not only more effective and undetectable but also exhibit a certain degree of transferablity across different datasets and models.
computer science, information systems, software engineering
What problem does this paper attempt to address?