A method for generating backdoor samples for voiceprint recognition based on adaptive trigger
By adopting the generation method of adaptive triggers in the voiceprint recognition model, and using the combined training of the generator network and the discriminator network, the problem of poor concealment of triggers in existing poisoning attacks is solved, and a higher attack success rate and concealment are achieved.
Patent Information
- Application Number
- CN202211040341.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-29
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-08-29
AI Technical Summary
The existing voiceprint recognition model is vulnerable to poisoning attacks, and the existing poisoning triggers are fixed and single, with poor concealment, making it difficult to effectively deceive the model.
The voiceprint recognition backdoor sample generation method based on adaptive triggers is adopted, and the generator network, discriminator network and classification model are jointly trained. The generator generates adaptive triggers based on sample characteristics to improve concealment.
Without reducing the accuracy of the model, the adaptive triggers generated by the generator are more concealed and difficult to detect, which improves the attack success rate.
Smart Images

Figure CN115424620B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for generating a voiceprint recognition backdoor sample based on an adaptive trigger, and belongs to the field of deep learning security. Background Art
[0002] Voiceprint recognition is a type of biometric identification, that is, a technology that uses the physiological or behavioral characteristics inherent in the human body to identify a person. Because voice collection is convenient and cheap, the algorithm complexity of voiceprint recognition is relatively low, and voice involves less privacy, it is widely used in many fields. For example, in the financial field, voiceprint recognition technology is used to match the person who handles the matter with the database; in the public security field, voiceprint recognition is performed using the voice data left during a call; in the field of mobile payment, dynamic payment passwords can be combined with voiceprint recognition technology to build double protection and ensure payment security.
[0003] However, recent studies have shown that voiceprint recognition models are vulnerable to poisoning attacks. The poisoned models trained with poisoned datasets perform normally on clean datasets, but will show specific errors on datasets with triggers. Poisoning attacks can be divided into three categories: users use third-party datasets; users use third-party platforms; users directly use third-party models. Most of the existing poisoning attacks are the first case, where users use poisoned datasets on the Internet to train their own models without knowing it. However, this attack has flaws. The attacker poisons the dataset without knowing the model architecture, and the poisoning triggers set are fixed and single. This trigger is very different from the characteristics of the sample, resulting in poor results or easy detection. Therefore, it is crucial to set a trigger with high concealment. Summary of the invention
[0004] The present invention aims to overcome the above-mentioned shortcomings of the prior art and provide a method for generating backdoor samples for voiceprint recognition based on adaptive triggers. The present invention utilizes the generator network, the discriminator network and the classification model for joint training, effectively poisoning the model without reducing the accuracy of the model. The generator will generate different triggers based on the characteristics of the sample, which has better concealment.
[0005] The technical solution adopted by the present invention to solve its technical problem is: according to the characteristics of the speech signal, a generator network, a discriminator network and a classification model structure are constructed, the generator network maps samples and sampled random noise into adaptive triggers, the discriminator is used to distinguish between samples with added triggers and original samples to limit the size of the trigger, and the classification network performs poisoning training on a data set with added adaptive triggers. Finally, the trained generator can generate more concealed triggers and an effective deception model.
[0006] A method for generating backdoor samples for voiceprint recognition based on an adaptive trigger includes the following steps:
[0007] Step 1: Build a generator model, a discriminator model and a classification network based on the speech signal;
[0008] Step 2: Train the weights of the discriminator;
[0009] Step 3: Train the weights of the classification network;
[0010] Step 4: Use the joint network to freeze the discriminator and classification network and train the weights of the generator;
[0011] Step 5: Repeat steps 2 to 4 to save the desired classification network, generator structure and weights;
[0012] Step 6: Test the test accuracy and attack success rate of the classification network.
[0013] Furthermore, step 1 specifically includes: building the structure of the generator model G, building the structure of the discriminator model D, specifying the structure and parameters of the classification model F and not changing it. The present invention directly classifies the original waveform of the speech, so the generator, discriminator and classification model all adopt the 1DCNN form, and the structure of the classification network and the discriminator includes a 1D convolution layer, a 1D maximum pooling layer, a fully connected layer and a batch normalization layer: its parameters mainly include the number and size of the convolution layer, the step size and size of the pooling layer, and the number of batch normalization layers. The generator structure includes a 1D convolution layer, a 1D maximum pooling layer, and a 1D upsampling layer: its parameters mainly include the number and size of the convolution layer, and the size of the pooling layer and the upsampling layer. The data set for the classification task needs to be given in advance, and its waveform features are extracted according to the sampling rate.
[0014] Furthermore, step 2 specifically includes: training the weights of the discriminator, the discriminator is used to limit the size of the trigger, and the output of the generator is combined with the clean sample as the input of the trigger. The generator can map the speech sample x and the randomly sampled noise z to a specific trigger, where the speech sample, the sampled noise and the trigger have the same dimension. In each iteration, a random sample is selected from the training set X. train The m samples in the batch are input into the generator and combined with the sampled m random noises. The generator maps them into triggers: G(x i ,z i ). Adding triggers to clean samples generates noise samples, i.e. G(x i ,z i )+x i , the discriminator's weights are updated using the discriminator's binary cross entropy loss function for gradient descent. The loss function is as follows:
[0015]
[0016] Where Φ represents the weight parameter of the discriminator, and the loss function is the binary cross entropy loss. For the discriminator, the clean sample is marked as 1, and the poisoned sample from the generator is marked as 0. i ) represents the output of the discriminator for clean samples. If the i-th sample is a noise sample, D(G(x i ,z i )+x i ) represents the output of the discriminator for the noise sample. Minimizing the loss function enables the discriminator to accurately identify noise samples and clean samples, which is used to limit the size of the trigger.
[0017] Further, step 3 specifically includes: training the classification network, first pre-specifying the poisoning ratio λ, from the training set X train Select a clean sample set X from clean With pre-poisoned sample set X p And no longer changes, that is:
[0018] X train =X clean UX p (2)
[0019] |X train |=λ·|X p | (3)
[0020] Then, a batch of samples is selected from the clean sample set and the poisoned sample set, the number of which is m. The labels of the poisoned samples are marked as the category t of the expected attack. The clean sample set is kept unchanged. A poisoning model is trained using the clean cross entropy loss function and the poisoned cross entropy loss function. The total loss function is as follows:
[0021]
[0022] The first half is the clean cross entropy loss function, and the second half is the poisoned cross entropy loss function. Ψ represents the weight parameter of the classification model, N represents the number of categories; y ij represents the true probability (0 or 1) that the i-th sample belongs to the j-th category; C j (.) represents the probability that the speech is classified as the jth class; t represents the poisoning class; G(x′ i ,z i ) represents the sample x i The trigger of G(x′ i ,z i )+x′ i Indicates the continuously updated poisoning voice. In addition, x and x′ i From different distributions, They are two non-overlapping subsets, x′ i The samples are sampled to generate poisoned samples. At the same time, the clean cross entropy loss and the poisoned cross entropy loss are minimized, and the model is poisoned while maintaining the accuracy of the model. Training on all samples once counts as one iteration.
[0023] Furthermore, step 4 specifically includes: training the generator, first combining the generator network, the discriminator network, and the classification model into a joint network F; secondly freezing the weight of the discriminator D and the weight of the classification model C, so that the weight parameters of both stop updating; then arbitrarily sampling a batch of samples from the training set, the number is m, and inputting it into the joint network F, and using the output feedback of the discriminator and the classification model to train the generator, the loss function is as follows:
[0024]
[0025] Among them, m represents the number of sampled samples; Θ represents the weight parameter of the generator; G(x i ,z i ) represents the sample x i The trigger of G(x i ,z i )+x i represents the continuously updated poisoned speech. The first half of the loss is the feedback of the discriminator, and D(.) represents the output probability of the discriminator; the second half of the loss function is the feedback of the model, C t (.) represents the probability that the speech is predicted to be of the tth class, where t is the label of the attack. Note that for the discriminator D, the label of the poisoned speech is marked as "0". Minimize this loss function so that D(G(x i ,z i )+x i ) and C t (G(x i ,z i )+x i ) approaches 1. At this time, the poisoned sample not only has a high attack success rate, but also has strong concealment and can avoid the detection of the discriminator. α and β are hyperparameters that are used to control the importance of the discriminator loss and the classifier loss when the generator network weights are updated. They can measure the concealment and attack success rate.
[0026] Furthermore, step 5 specifically includes: in order to ensure the concealment of the trigger and the poisoning success rate, steps 2 to 4 are continuously repeated until the size of the trigger and the poisoning success rate reach a desired threshold, and the structures and weights of the generator model and the classification model are saved respectively.
[0027] Furthermore, step 6 specifically includes: testing the model accuracy and poisoning success rate. First, load the trained generator network and classifier network structure and weights, and convert the randomly sampled noise set Zt With the test set sample X t Input to the generator to generate poisoned sample X tp ,Right now:
[0028] X tp =X t +G(X t ,Z t ) (6)
[0029] Then, the test samples and poisoned samples are input into the classifier network respectively, and the classification accuracy of the model for clean samples and the attack success rate of poisoned samples are calculated. The formula is as follows:
[0030]
[0031]
[0032] where f′ θ represents the poisoned classifier network, y j represents the true label of the jth sample, y t represents the poisoned target label, and Q represents the number of samples in the test set.
[0033] The advantage of the present invention is that it utilizes adversarial training among the generator, the discriminator and the classification model. The discriminator is used to distinguish poisoned samples from clean samples, the classification model is used to perform poisoning operations, and the generator is trained based on the feedback from the discriminator and the classification model. Finally, the trained generator can not only generate an adaptive trigger based on the characteristics of the sample, but the trigger is also highly concealed and more difficult to detect. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It is a schematic diagram of the generator structure of the method of the present invention.
[0035] Figure 2 It is the overall framework diagram of the method of the present invention.
[0036] Figure 3 It is a model training flow chart of the method of the present invention. DETAILED DESCRIPTION
[0037] The technical solution of the method of the present invention is further described below in conjunction with the accompanying drawings.
[0038] Embodiment 1:
[0039] A system attack method for generating a voiceprint recognition backdoor sample based on an adaptive trigger according to the present invention comprises the following steps:
[0040] (1) Build the structure of the generator model G, build the structure of the discriminator model D, specify the structure and parameters of the classification model F and do not change. The present invention directly classifies the original waveform of the speech, so the generator, discriminator and classification model all adopt the 1DCNN form. The structure of the classification network and the discriminator includes a 1D convolution layer, a 1D maximum pooling layer, a fully connected layer and a batch normalization layer: its parameters mainly include the number and size of the convolution layer, the step size and size of the pooling layer, and the number of batch normalization layers. The generator structure includes a 1D convolution layer, a 1D maximum pooling layer, and a 1D upsampling layer: its parameters mainly include the number and size of the convolution layer, and the size of the pooling layer and the upsampling layer. The data set for the classification task must be given in advance, and its waveform features must be extracted according to the sampling rate.
[0041] (2) Train the weights of the discriminator.
[0042] The discriminator is used to limit the size of the trigger, and the output of the generator is combined with the clean sample as the input of the trigger. The generator can map the speech sample x and the randomly sampled noise z to a specific trigger, where the speech sample, the sampled noise and the trigger have the same dimension. In each iteration, a random sample is selected from the training set X. train The m samples in the batch are input into the generator and combined with the sampled m random noises. The generator maps them into triggers: G(x i ,z i ). Adding triggers to clean samples generates noise samples, i.e. G(x i ,z i )+x i , the discriminator's weights are updated using the discriminator's binary cross entropy loss function for gradient descent. The loss function is as follows:
[0043]
[0044] Where Φ represents the weight parameter of the discriminator, and the loss function is the binary cross entropy loss. For the discriminator, the clean sample is marked as 1, and the poisoned sample from the generator is marked as 0. i ) represents the output of the discriminator for clean samples. If the i-th sample is a noise sample, D(G(x i ,z i )+x i ) represents the output of the discriminator for the noise sample. Minimizing the loss function enables the discriminator to accurately identify noise samples and clean samples, which is used to limit the size of the trigger.
[0045] (3) Train the weights of the classification network.
[0046] First, pre-specify the poisoning ratio λ, from the training set X train Select a clean sample set X fromclean With pre-poisoned sample set X p And no longer changes, that is:
[0047] X train =X clean UX p (2)
[0048] |X train |=λ·|X p | (3)
[0049] Secondly, select a batch of samples from the clean sample set and the poisoned sample set, the number of which is m, mark the label of the poisoned sample as the category t of the expected attack, keep the clean sample set unchanged, and use the clean cross entropy loss function and the poisoned cross entropy loss function to train a poisoning model. The total loss function is as follows:
[0050]
[0051] The first half is the clean cross entropy loss function, and the second half is the poisoned cross entropy loss function. Ψ represents the weight parameter of the classification model, N represents the number of categories; y ij represents the true probability (0 or 1) that the i-th sample belongs to the j-th category; C j (.) represents the probability that the speech is classified as the jth class; t represents the poisoning class; G(x′ i ,z i ) represents the sample x i The trigger of G(x′ i ,z i )+x′ i Indicates the continuously updated poisoning voice. In addition, x and x′ i From different distributions, They are two non-overlapping subsets, x′ i The samples are sampled to generate poisoned samples. At the same time, the clean cross entropy loss and the poisoned cross entropy loss are minimized, and the model is poisoned while maintaining the accuracy of the model. Training on all samples once counts as one iteration.
[0052] (4) Train the weights of the generator.
[0053] First, the generator network, the discriminator network, and the classification model are combined into a joint network F; secondly, the weights of the discriminator D and the classification model C are frozen to stop updating the weight parameters of both; then, a batch of samples is randomly sampled from the training set, the number is m, and it is input into the joint network F. The output feedback of the discriminator and the classification model is used to train the generator. The loss function is as follows:
[0054]
[0055] Among them, m represents the number of sampled samples; Θ represents the weight parameter of the generator; G(x i ,z i ) represents the sample x i The trigger of G(x i ,z i )+x i represents the continuously updated poisoned speech. The first half of the loss is the feedback of the discriminator, and D(.) represents the output probability of the discriminator; the second half of the loss function is the feedback of the model, C t (.) represents the probability that the speech is predicted to be of the tth class, where t is the label of the attack. Note that for the discriminator D, the label of the poisoned speech is marked as "0". Minimize this loss function so that D(G(x i ,z i )+x i ) and C t (G(x i ,z i )+x i ) approaches 1. At this time, the poisoned sample not only has a high attack success rate, but also has strong concealment and can avoid the detection of the discriminator. α and β are hyperparameters that are used to control the importance of the discriminator loss and the classifier loss when the generator network weights are updated. They can measure the concealment and attack success rate.
[0056] (5) In order to ensure the concealment of the trigger and the success rate of poisoning, steps 2 to 4 are repeated until the size of the trigger and the success rate of poisoning reach a desired threshold, and the structures and weights of the generator model and the classifier network are saved respectively.
[0057] (6) Deploy the classifier network into the user's computer system.
[0058] The invention saves a classifier network that is used to handle the task of voiceprint recognition. The third party delivers the trained model to the user, who deploys it into a computer system and verifies its performance, as shown below.
[0059]
[0060] The user uses a batch of clean validation set samples X t To measure the performance of the classifier network, that is, the classification accuracy. The classifier model has been poisoned, and f′ θ represents the poisoned classifier network, y j represents the true label of the jth sample, and Q represents the number of samples in the test set. If Acc has good classification performance, the classifier model is considered trustworthy by the user and is deployed in the system to wait for the voiceprint recognition task.
[0061] (7) Deploy the generator network into the attack system.
[0062] The attacker's goal is to perform a poisoning attack on the classification network. At this time, the generator network trained by the present invention is deployed to the attack system. The generator network has a hidden poisoning relationship with the above-mentioned classifier network. The generator network deployed by the system generates poisoned data, as shown below. The randomly sampled noise set Z t With the test set sample X t Input to the generator to generate poisoned sample X tp ,Right now:
[0063] X tp =X t +G(X t ,Z t ) (6)
[0064] The classifier model is highly sensitive to the samples generated by the generator, so it will be identified as the wrong speaker when used for voiceprint recognition tasks. The performance of the attack system is measured by the attack success rate:
[0065]
[0066] where f′ θ represents the classifier network, represents the jth poisoned sample, y t represents the poisoned target label, and Q represents the number of samples in the test set. If the attack system has a good attack success rate, it indicates the high performance of the attack scheme of the present invention.
[0067] Implementation Case 2: Data from Actual Experiments
[0068] (1) Select experimental data.
[0069] The data sets used in the experiment are all AISHELL-ASR0009-OS1 speech data sets. The recording time of this data set is 178 hours. The recording process is in a quiet indoor environment and the audio recorded by a high-fidelity microphone is downsampled to 16kHz. The data set has been transcribed and annotated by professional voice proofreaders and has passed strict quality inspection. The accuracy of the database text is above 95%. A total of more than 400 speakers from different accent areas in China participated in the recording. Each speaker has about 360 voices, ranging in length from 3 seconds to 8 seconds, which can be used for voiceprint recognition experiments and speech recognition experiments. In the present invention, we randomly selected 10 speakers for 10 classification experiments. We eliminated the silent part of each voice segment and cut them all to 2.5 seconds. The division of the data set is as follows: Our experimental data has a total of 2,800 voice samples, which are divided into training sets and test sets in a ratio of 8:2, which are used to train the generator, the poisoning model, and test the accuracy and attack effect of the poisoning model.
[0070] (2) Determine the parameters.
[0071] The structure of the voiceprint recognition model used in the present invention is as follows: the model adopts a 1DCNN network, which is suitable for processing classification tasks of time series data. The network contains eight 1D convolutional layers, seven pooling layers, seven batch normalization layers, and two fully connected layers. The size of the convolution kernel in the convolution layer is 1×3, the step size is [3, 1, 1, 1, 1, 1, 1], the number of convolution kernels is [128, 128, 256, 256, 256, 256, 512], and the activation function is Relu; the pooling size in the pooling layer is 1×3, and the step size is 3; the number of neurons in the fully connected layer is [128, 10]. The discriminator model structure used in the present invention is similar to the classification model structure. The activation function of the last layer is sigmoid, and the number of neurons is 1.
[0072] The generator model structure adopted by the present invention is an encoding-decoding structure, such as Figure 3 As shown in Figure 2, the encoder maps the input samples and randomly sampled noise into low-dimensional data and extracts its features, and the decoder reconstructs the low-dimensional data into high-dimensional noise. The specific structure is shown in Table 2.
[0073] (3) Experimental results
[0074] The present invention uses objective speech quality evaluation (PESQ) to measure the speech quality after adding adaptive triggers. PESQ requires noisy audio speech and an original reference speech. After the two speech to be compared are level adjusted, input filter filtered, time aligned and compensated, and auditory transformed, the parameters of the two speech are extracted respectively, and their time-frequency characteristics are combined to obtain the PESQ score, which is finally mapped to the subjective mean opinion score (MOS). The PESQ score ranges from -0.5 to 4.5. The higher the score, the better the speech quality.
[0075] In order to measure the impact of different parameters on the results, the present invention selects the poisoning ratio as 0.4. As the weight ratio (α:β) of the loss function in the joint training network changes, the classification accuracy, poisoning success rate and PESQ of the poisoned network change as shown in the following table.
[0076] Table 1 Analysis of adaptive trigger results
[0077]
[0078]
[0079] The contents described in the embodiments of this specification are merely an enumeration of the implementation forms of the inventive concept. The protection scope of the present invention should not be regarded as limited to the specific forms described in the embodiments. The protection scope of the present invention also extends to equivalent technical means that can be conceived by those skilled in the art based on the inventive concept.
Claims
1. A method for generating backdoor samples for voiceprint recognition based on adaptive triggers, characterized in that: The following steps are involved: Step 1: Build a generator model, a discriminator model and a classification network based on the speech signal; Step 2: Train the weights of the discriminator; specifically: The weights of the discriminator are trained. The discriminator is used to limit the size of the trigger. The output of the generator is combined with the clean sample as the input of the trigger. The generator can map the speech sample x and the randomly sampled noise z to a specific trigger, where the speech sample, the sampled noise and the trigger have the same dimension. In each iteration, a random sample is selected from the training set X. train The m samples in the batch are input into the generator and combined with the sampled m random noises. The generator maps them into triggers: G(x i ,z i ); Add triggers to clean samples to generate noise samples, i.e. G(x i ,z i )+x i , the discriminator's weights are updated using the discriminator's binary cross entropy loss function for gradient descent. The loss function is as follows: Where Φ represents the weight parameter of the discriminator, and the loss function is the binary cross entropy loss; for the discriminator, the clean sample is marked as 1, and the poisoned sample from the generator is marked as 0; D(x i ) represents the output of the discriminator for clean samples. If the i-th sample is a noise sample, D(G(x i ,z i )+x i ) represents the output of the discriminator for the noise sample. Minimizing the loss function enables the discriminator to accurately identify the noise sample and the clean sample, which is used to limit the size of the trigger; Step 3: Train the weights of the classification network; specifically: To train the classification network, first pre-specify the poisoning ratio λ and select train Select a clean sample set X from clean With pre-poisoned sample set X p And no longer changes, that is: X train =X clean UX p (2) |X train |=λ·|X p | (3) Then select a batch of samples from the clean sample set and the poisoned sample set, the number of which is m, mark the label of the poisoned sample as the category t of the expected attack, keep the clean sample set unchanged, and use the clean cross entropy loss function and the poisoned cross entropy loss function to train a poisoning model. The total loss function is as follows: The first half is the clean cross entropy loss function, and the second half is the poisoned cross entropy loss function; Ψ represents the weight parameter of the classification model, N represents the number of categories; y ij represents the true probability (0 or 1) that the i-th sample belongs to the j-th category; C j (.) represents the probability that the speech is classified as the jth class; t represents the poisoning class; G(x i ′,z i ) represents the sample x i The trigger of G(x i ′,z i )+x i ′ represents the continuously updated poisoning voice; in addition, x and x i ′ comes from different distributions, where They are two non-overlapping subsets, x i ′ is sampled to generate poisoned samples; while minimizing the clean cross entropy loss and the poisoned cross entropy loss, the model is poisoned while maintaining the model accuracy, and training once on all samples is counted as one iteration; Step 4: Use the joint network to freeze the discriminator and classification network and train the weights of the generator; specifically: To train the generator, first combine the generator network, the discriminator network, and the classification model into a joint network F; secondly, freeze the weights of the discriminator D and the classification model C, so that the weight parameters of both stop updating; then randomly sample a batch of samples from the training set, the number is m, and input it into the joint network F, and use the output feedback of the discriminator and the classification model to train the generator. The loss function is as follows: Among them, m represents the number of sampled samples; Θ represents the weight parameter of the generator; G(x i ,z i ) represents the sample x i trigger; G(xi,zi)+xi represents the continuously updated poisoned speech; the first half of the loss is the feedback of the discriminator, and D(.) represents the output probability of the discriminator; the second half of the loss function is the feedback of the model, C t (.) represents the probability that the speech is predicted to be of the tth category, where t is the label of the attack; note that for the discriminator D, the label of the poisoned speech is marked as "0"; minimize the loss function, so that D(G(x i ,z i )+x i ) and C t (G(x i ,z i )+x i ) is close to 1. At this time, the poisoned sample not only has a high attack success rate, but also has strong concealment and can avoid the detection of the discriminator. α and β are hyperparameters, which are used to control the importance of the discriminator loss and the classifier loss when the generator network weight is updated, and can measure the concealment and attack success rate. Step 5: Repeat steps 2 to 4 to save the desired classification network, generator structure and weights; Step 6: Test the test accuracy and attack success rate of the classification network.
2. The method for generating backdoor samples for voiceprint recognition based on adaptive triggers according to claim 1, characterized in that: Step 1 specifically includes: Build the structure of the generator model G and the structure of the discriminator model D, specify the structure and parameters of the classification model F and do not change them; directly classify the original speech waveform, so the generator, discriminator and classification models all adopt the 1DCNN form, and the structure of the classification network and discriminator includes 1D convolution layer, 1D maximum pooling layer, fully connected layer and batch normalization layer: its parameters mainly include the number and size of convolution layers, the step size and size of the pooling layer, and the number of batch normalization layers; the generator structure includes 1D convolution layer, 1D maximum pooling layer, and 1D upsampling layer: its parameters mainly include the number and size of convolution layers, and the size of pooling layers and upsampling layers; the data set for the classification task needs to be given in advance, and its waveform features are extracted according to the sampling rate.
3. The method for generating backdoor samples for voiceprint recognition based on adaptive triggers according to claim 1, characterized in that: Step 5 specifically includes: In order to ensure the concealment of the trigger and the success rate of poisoning, steps 2 to 4 are repeated until the size of the trigger and the success rate of poisoning reach a desired threshold, and the structures and weights of the generator model and the classification model are saved respectively.
4. The method for generating backdoor samples for voiceprint recognition based on adaptive triggers according to claim 1, characterized in that: Step 6 specifically includes: Test the model accuracy and poisoning success rate. First, load the trained generator network and classifier network structure and weights, and convert the randomly sampled noise set Z t With the test set sample X t Input to the generator to generate poisoned sample X tp ,Right now: X tp =X t +G(X t ,Z t ) (7) Then, the test samples and poisoned samples are input into the classifier network respectively, and the classification accuracy of the model for clean samples and the attack success rate of poisoned samples are calculated. The formula is as follows: where f θ ′ represents the poisoned classifier network, y j represents the true label of the jth sample, y t represents the poisoned target label, and Q represents the number of samples in the test set.
Citation Information
Patent Citations
Adversarial sample generation method based on content-aware GAN
CN111881935A
Clean tag neural network backdoor implantation method based on general adversarial trigger
CN113269308A