期刊文献+

改进Xception网络的声纹对抗检测研究

Research on Voiceprint Adversarial Detection of Improved Xception Network
下载PDF
导出
摘要 近年来,针对说话人识别模型的对抗攻击引起了广泛的关注,对说话人识别系统的安全构成了严重的威胁。为了解决现有的声纹对抗样本检测方法参数量过大、鲁棒性差的问题,提出一个声纹对抗样本检测模型e_Xception,该模型以Xception为主干网络,嵌入高效通道注意力(efficient channel attention,ECA)模块,充分提取语音特征。通过合理减少网络模型的宽度,设计了一个轻量级网络模型e_halfXception,减少参数量的同时,仍保持较高的精度。提出一种高频掩码的语音数据增强策略HF-Mask,提高模型的泛化性。实验结果证明,在对FGSM、BIM、PGD、MI-FGSM、C&W、FAKEBOB六种对抗样本的检测中,取得了较高的准确率,优于其他检测方法,并对模型开展了未知攻击算法、未知目标模型、未知扰动程度的鲁棒性研究,验证了模型的泛化能力。 Adversarial attacks against speaker recognition models have attracted widespread attention and posed a serious threat to speaker recognition systems’security in recent years.A voiceprint adversarial sample detection model e_Xception is proposed to solve the problems of excessive parameter size and poor robustness of existing voiceprint adversarial sample detection methods.Xception is taken as the backbone network and embeds efficient channel attention(ECA)modules to fully extract speech features.A lightweight network model e_halfXception is designed to reduce parameters’number while still maintaining high accuracy by reasonably reducing the width of the network model.Finally,a high-frequency masked speech data enhancement strategy HF-Mask is proposed to improve the model’s generalization.Experimental results demonstrate that high accuracy is achieved in the detection of six adversarial samples,FGSM,BIM,PGD,MI-FGSM,C&W and FAKEBOB,outperforming other detection methods,and the robustness of the model is investigated unknown attack algorithms,unknown target models,and unknown perturbation degrees,validating the model’s generalization.
作者 李烁 顾益军 谭昊 彭舒凡 LI Shuo;GU Yijun;TAN Hao;PENG Shufan(College of Information and Cyber Security,People’s Public Security University of China,Beijing 100038,China;Cyberspace Institute of Advanced Technology,Guangzhou University,Guangzhou 510006,China)
出处 《计算机工程与应用》 CSCD 北大核心 2023年第14期232-241,共10页 Computer Engineering and Applications
基金 公安部科技强警基础工作专项项目(2020GABJC02) 中国人民公安大学基本科研业务费项目(2021JKF420)。
关键词 说话人识别 对抗攻击 对抗检测 Xception网络 数据增强 鲁棒性 speaker recognition adversarial attack adversarial detection XceptionNet data augmentation robustness
  • 相关文献

参考文献1

二级参考文献1

共引文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部