2018/05/01 by Nicholas Carlini, David Wagner · 1 citation
Computer Science · Mathematics · #Adversarial Robustness in Machine Learning #Adversarial system #Computer science #Phrase #Speech recognition #Construct (python library) #Domain (mathematical analysis) #Speech coding #Waveform #Artificial intelligence #Natural language processing #Mathematics #Programming language #Telecommunications
paper · pdf · doi:10.1109/spw.2018.00009
openalex publication_date 2018/05/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29
We construct targeted audio adversarial examples on automatic speech recognition. Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose (recognizing up to 50 characters per second of audio). We apply our white-box iterative optimization-based attack to Mozilla's implementation DeepSpeech end-to-end, and show it has a 100% success rate. The feasibility of this attack introduce a new domain to study adversarial examples.