Supercharge Your Innovation With Domain-Expert AI Agents!

Method suitable for quickly acquiring voice confrontation sample under black box attack

An anti-sample, fast technology, applied in the direction of audio data query, audio data retrieval, special data processing applications, etc., can solve the problems of multiple query times, low attack efficiency, and increased difficulty of adversarial samples, so as to improve attack efficiency and increase generation Speed, the effect of reducing the number of queries

Active Publication Date: 2022-06-24
NINGBO UNIV
View PDF11 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] For the above reasons, the voice is quite different from the image, which makes the black box attack need more queries when it is applied in the audio field, and it is more difficult to generate adversarial samples, which leads to low attack efficiency and cannot provide a fair judgment.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method suitable for quickly acquiring voice confrontation sample under black box attack
  • Method suitable for quickly acquiring voice confrontation sample under black box attack
  • Method suitable for quickly acquiring voice confrontation sample under black box attack

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0028] The following describes in detail the embodiments of the present invention, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals refer to the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary, only used to explain the present invention, and should not be construed as a limitation of the present invention.

[0029] Figure 1-2 A diagram of a method for quickly obtaining adversarial samples under black-box attack is shown in the present application, and the method specifically includes the following:

[0030] S1. Use the binary query algorithm to determine the decision boundary of the original audio x, and iterate with the sliding window method to select the best attack area [s:e], where the initial value of s is 0, the initial value of e is l, and l is the length of the original audio ,

...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention relates to a method suitable for quickly acquiring a voice confrontation sample under a black box attack, and the method comprises the steps: S1, determining a decision boundary of an original audio x through employing a binary query algorithm, and carrying out the iteration in cooperation with a sliding window method, so as to select an optimal attack region [s: e], the initial value of s being 0, the initial value of e being 1, and 1 being the length of the original audio; and S2, adding disturbance in a low-frequency region in the selected attack region [s: e], determining an update step length by calculating a gradient direction, updating the disturbance, and obtaining an adversarial sample of the next iteration by using a binary query algorithm until the set sampling times are completed, thereby obtaining a final adversarial sample x *. According to the method, the confrontation sample generation efficiency is improved, and the attack efficiency is improved.

Description

technical field [0001] The invention relates to the field of speech processing, in particular to a method for rapidly acquiring speech confrontation samples under black-box attack. Background technique [0002] Black-box adversarial sample attack is a fair indicator and means to evaluate the security of a model, which generates adversarial samples by querying the model. The main application objects of the existing black-box attacks are the models in the image domain, and no corresponding work has been carried out in the speech domain. [0003] The audio data is a time series, which is a one-dimensional data, which contains a small amount of information, and it is difficult to estimate accurate gradient information, while the image is two-dimensional data, which contains a large amount of information, and has a strong information dependence in space. Information can be used; audio commonly used sampling points per second is more than 16000, and a speaker audio usually has a ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): G06F16/63G06F16/23
CPCG06F16/63G06F16/23Y02T10/40
Inventor 董理邓佳程王让定王冬华彭成斌
Owner NINGBO UNIV
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More