vix.ing · top · new · best · stats · spec

Adversarial Black-Box Attacks on Automatic Speech Recognition Systems\n using Multi-Objective Evolutionary Optimization

2018/11/03 by Shreya Khare, Khare, Shreya, Rahul Aralikatte +3
Computer Science · Physics and Astronomy · #Adversarial Robustness in Machine Learning #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Model Reduction and Neural Networks #Music and Audio Processing #Neural and Evolutionary Computing (cs.NE)

paper · pdf · doi:10.48550/arxiv.1811.01312

openalex publication_date 2018/11/03 · openalex created_date 2022/08/02 · openalex updated_date 2026/07/28

Abstract

Fooling deep neural networks with adversarial input have exposed a\nsignificant vulnerability in the current state-of-the-art systems in multiple\ndomains. Both black-box and white-box approaches have been used to either\nreplicate the model itself or to craft examples which cause the model to fail.\nIn this work, we propose a framework which uses multi-objective evolutionary\noptimization to perform both targeted and un-targeted black-box attacks on\nAutomatic Speech Recognition (ASR) systems. We apply this framework on two ASR\nsystems: Deepspeech and Kaldi-ASR, which increases the Word Error Rates (WER)\nof these systems by upto 980%, indicating the potency of our approach. During\nboth un-targeted and targeted attacks, the adversarial samples maintain a high\nacoustic similarity of 0.98 and 0.97 with the original audio.\n

Related