首页|针对说话人识别对抗样本生成方法研究

针对说话人识别对抗样本生成方法研究

扫码查看
针对基于生成式的对抗样本生成方法生成的对抗样本真实性较低和攻击效果欠佳的问题,提出一种基于AdvGAN和CGAN的对抗样本生成方法ACGAN.首先,针对特定目标进行攻击,ACGAN通过在训练和攻击阶段引入额外的目标标签,生成具有针对性的频域上的对抗样本.其次,在生成器和鉴别器中引入门控卷积神经网络,帮助ACGAN模型捕捉到更精确的数据特征,从而提高攻击成功率.最后,引入感知损失函数,最小化模型输出与目标输出在语音特征表示上的差异,提高生成样本的听觉质量.实验结果表明,在有目标攻击中相较于现有方法,ASR提高了1.5%,SNR和PESQ分别提高了10.5%和11.1%,证明了ACGAN在对抗样本生成领域的有效性和潜力.
Research on adversarial sample generation methods for speaker recognition
Aiming at the problem that adversarial samples generated by generative adversarial sample generation methods have low authenticity and poor attack effect,an adversarial sample generation method ACGAN based on AdvGAN and CGAN is proposed.First,attacking a specific target,ACGAN generates targeted adversarial samples in the frequency domain by introducing additional target labels in the training and attack stages.Secondly,the gated convolutional neural network is introduced in the generator and discriminator to help the ACGAN model capture more accurate data features,thereby improving the success rate of the attack.Finally,the perceptual loss function is introduced to minimize the difference in speech feature representation between the model output and the target output,thereby improving the auditory quality of the generated samples.Experimental results show that compared with the existing methods in targeted attacks,the ASR is improved by 1.5%,and the SNR and PESQ are improved by 10.5%and 11.1%respectively,which proves the effectiveness and potential of ACGAN in the field of adversarial sample generation.

adversarial examplesgeneratordiscriminatorgated convolutional neural networkperceptual loss

马栋林、宋佳佳、赵宏、陈伟杰

展开 >

兰州理工大学计算机与通信学院 兰州 730050

对抗样本 生成器 鉴别器 门控卷积神经网络 感知损失

2024

电子测量技术
北京无线电技术研究所

电子测量技术

CSTPCD北大核心
影响因子:1.166
ISSN:1002-7300
年,卷(期):2024.47(22)