The invention discloses a speaker recognition model
frequency modulation trigger injection method, particularly relates to the technical field of voice
signal processing and
artificial intelligence safety, and is used for solving the problems that an existing speaker recognition model
back door injection method is insufficient in concealment, poor in
black box environment adaptability, prone to
distortion of trigger characteristics in the physical transmission process and poor in safety. And mainstream defense strategies such as model
fine tuning,
pruning and spectrum detection are difficult to
resist. The method comprises the following steps: constructing a piecewise linear periodic low-
frequency modulation curve for original voice, generating a smooth phase track according to a frequency and
phase relationship, constructing a sinusoidal modulator to generate a hidden sample, mixing normal samples in proportion and uniformly marking, training a model by a
black box, testing
reproduction modulation and inputting the model; according to the method, the defects of insufficient concealment,
black box adaptability, physical robustness and defensive resistance of an existing method are overcome, high-concealment, high-robustness and wide-application
backdoor injection is realized, and reliable support is provided for security evaluation of a
speaker recognition system.