Title | Audio Adversarial Examples: Targeted Attacks on Speech-to-Text |
Publication Type | Conference Paper |
Year of Publication | 2018 |
Authors | Carlini, N., Wagner, D. |
Conference Name | 2018 IEEE Security and Privacy Workshops (SPW) |
Date Published | may |
Keywords | adversarial example, audio waveform, automatic speech recognition, composability, distortion, Distortion measurement, Iterative methods, Metrics, Mozilla implementation DeepSpeech end, Neural Network, Neural networks, optimisation, Perturbation methods, Probability distribution, pubcrawl, resilience, security of data, Speech recognition, speech-to-text, targeted attacks, targeted audio adversarial examples, White Box Security, white-box iterative optimization-based attack |
Abstract | We construct targeted audio adversarial examples on automatic speech recognition. Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose (recognizing up to 50 characters per second of audio). We apply our white-box iterative optimization-based attack to Mozilla's implementation DeepSpeech end-to-end, and show it has a 100% success rate. The feasibility of this attack introduce a new domain to study adversarial examples. |
DOI | 10.1109/SPW.2018.00009 |
Citation Key | carlini_audio_2018 |