conference-paper Open access

Adversarial Command Detection Using Parallel Speech Recognition Systems

  • Lecture notes in computer science
  • Springer Science+Business Media
Research footprint

At a glance

Citations
1
References
10
Comments
0
Paper overview

Öz

Personal Voice Assistants (PVAs) such as Apple’s Siri, Amazon’s Alexa and Google Home are now commonplace. PVAs are susceptible to adversarial commands; an attacker is able to modify an audio signal such that humans do not notice this modification but the Speech Recognition (SR) will recognise a command of the attacker’s choice. In this paper we describe a defence method against such adversarial commands. By using a second SR in parallel to the main SR of the PVA it is possible to detect adversarial commands. It is difficult for an attacker to craft an adversarial command that is able to force two different SR into recognising the adversarial command while ensuring inaudibility. We demonstrate the feasibility of this defence mechanism for practical setups. For instance, our evaluation shows that such system can be tuned to detect 50% of adversarial commands while not impacting on normal PVA use.

Record transparency

Publication details

DOI
10.1007/978-3-030-95484-0_15
OpenAlex
W3199688208
Document type
conference-paper
Language
EN
Source
Lecture notes in computer science
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.