Imperceptible, Robust and Targeted Adversarial Examples for Automatic Speech Recognition
Yao Qin , Nicholas Carlini , Ian Goodfellow , Garrison Cottrell and Colin Raffel UC San Diego Google Research
Long Beach, ICML June 12, 2019
1 1 2 2 2 2 1
Imperceptible, Robust and Targeted Adversarial Examples for - - PowerPoint PPT Presentation
Imperceptible, Robust and Targeted Adversarial Examples for Automatic Speech Recognition 1 2 2 1 2 Yao Qin , Nicholas Carlini , Ian Goodfellow , Garrison Cottrell and Colin Raffel 1 2 UC San Diego Google Research Long Beach, ICML June
1 1 2 2 2 2 1
Can hide sounds in here! Human perceptibility threshold Single tone as an example
q β./0 π π¦ + π , π§ is the cross-entropy loss function; q β2 π¦, π = max{πΜ 9 π β π= π , 0} is the imperceptibility loss
q Simulate room impulse π based on room configurations q Convolve speech with reverberation π’ π¦ = π¦ β π , π’ ~ T
q Minimize β π¦, π, π§ = E0βΌG [β./0 π π’(π¦ + π) , π§ ] such that π < π
q Minimize β π¦, π, π§ = E0βΌG [β./0 π π’(π¦ + π) , π§ ] + π½ β β2(π¦, π)