Model Access Control Based on Hidden Adversarial Examples for Automatic Speech Recognition

对抗制 计算机科学 语音识别 控制(管理) 访问控制 人工智能 自然语言处理 计算机网络
作者
H.F. Chen,Jie Zhang,Kejiang Chen,Weiming Zhang,Nenghai Yu
出处
期刊:IEEE transactions on artificial intelligence [Institute of Electrical and Electronics Engineers]
卷期号:5 (3): 1302-1315
标识
DOI:10.1109/tai.2023.3285858
摘要

Deep neural networks (DNNs) have achieved remarkable success across various domains, and their commercial value has led to their classification as intellectual property (IP) for their creators. While model watermarking is commonly employed for DNN IP protection, it is limited to post hoc forensics. In contrast, model access control offers a more effective proactive approach to prevent IP infringement through authentication. However, existing model access control methods primarily focus on image classification models and are not suitable for automatic speech recognition (ASR) models, which are also widely used in commercial applications. To address the above limitation, inspired by audio adversarial examples, we propose the first model access control scheme for the IP protection of ASR models, which utilizes audio adversarial examples with target labels as user identity information, serving as identity-proof samples. However, a unique challenge arises in the form of interception attacks, in which an attacker detects and hijacks an authorized sample to bypass the authentication process. To remedy it, we introduce the hidden adversarial examples (HAEs) for authentication, which embed the authorized information by slightly modifying the logits and behaving like clean audios, thereby making them difficult to be detected by analyzing the predicted results. To further evade detection by steganalysis, which can be employed for adversarial example detection, we design a distortion cost function inspired by adaptive steganography to guide the generation of HAEs. We conduct extensive experiments on the open-source ASR system DeepSpeech, demonstrating that our proposed scheme effectively protects ASR models proactively and is resistant to unique interception attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
knowledge完成签到,获得积分10
刚刚
1秒前
Ning完成签到,获得积分10
1秒前
2秒前
李健的小迷弟应助sddq采纳,获得10
2秒前
3秒前
3秒前
满增明发布了新的文献求助10
4秒前
4秒前
多多发布了新的文献求助10
5秒前
大模型应助光亮元枫采纳,获得10
5秒前
天问发布了新的文献求助10
6秒前
NZHMD发布了新的文献求助10
6秒前
6秒前
卫傀斗发布了新的文献求助10
7秒前
mrhsdy完成签到,获得积分10
7秒前
w_应助宣仰采纳,获得10
9秒前
9秒前
思源应助寒霁采纳,获得10
9秒前
9秒前
阔达魔镜发布了新的文献求助10
9秒前
斜玉发布了新的文献求助10
11秒前
科研通AI2S应助自然的听寒采纳,获得10
12秒前
FashionBoy应助称心鸵鸟采纳,获得10
12秒前
13秒前
今后应助malele采纳,获得10
14秒前
14秒前
苏翎澈完成签到 ,获得积分10
14秒前
gnr2000应助我球呢采纳,获得10
15秒前
热情雨南完成签到,获得积分10
15秒前
sddq发布了新的文献求助10
15秒前
科研通AI2S应助斤斤采纳,获得10
15秒前
汉堡包应助小李采纳,获得10
17秒前
17秒前
LiXii发布了新的文献求助10
17秒前
18秒前
搜集达人应助科研通管家采纳,获得10
19秒前
机灵柚子应助科研通管家采纳,获得10
19秒前
科目三应助科研通管家采纳,获得10
19秒前
李爱国应助科研通管家采纳,获得10
19秒前
高分求助中
Evolution 2024
Experimental investigation of the mechanics of explosive welding by means of a liquid analogue 1060
Die Elektra-Partitur von Richard Strauss : ein Lehrbuch für die Technik der dramatischen Komposition 1000
CLSI EP47 Evaluation of Reagent Carryover Effects on Test Results, 1st Edition 600
大平正芳: 「戦後保守」とは何か 550
Sustainability in ’Tides Chemistry 500
Cathodoluminescence and its Application to Geoscience 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3008082
求助须知:如何正确求助?哪些是违规求助? 2667320
关于积分的说明 7235257
捐赠科研通 2304544
什么是DOI,文献DOI怎么找? 1221956
科研通“疑难数据库(出版商)”最低求助积分说明 595385
版权声明 593410