Visible to the public Audio Adversarial Examples: Targeted Attacks on Speech-to-Text

TitleAudio Adversarial Examples: Targeted Attacks on Speech-to-Text
Publication TypeConference Paper
Year of Publication2018
AuthorsCarlini, N., Wagner, D.
Conference Name2018 IEEE Security and Privacy Workshops (SPW)
Date Publishedmay
Keywordsadversarial example, audio waveform, automatic speech recognition, composability, distortion, Distortion measurement, Iterative methods, Metrics, Mozilla implementation DeepSpeech end, Neural Network, Neural networks, optimisation, Perturbation methods, Probability distribution, pubcrawl, resilience, security of data, Speech recognition, speech-to-text, targeted attacks, targeted audio adversarial examples, White Box Security, white-box iterative optimization-based attack
AbstractWe construct targeted audio adversarial examples on automatic speech recognition. Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose (recognizing up to 50 characters per second of audio). We apply our white-box iterative optimization-based attack to Mozilla's implementation DeepSpeech end-to-end, and show it has a 100% success rate. The feasibility of this attack introduce a new domain to study adversarial examples.
DOI10.1109/SPW.2018.00009
Citation Keycarlini_audio_2018