LowResearchPeer-reviewed
Stealthy Physical Adversarial Attacks on Speaker Recognition via Near-Ultrasonic Perturbations
- Published
- Record updated
Summary
AdvNup is a physical adversarial attack that spoofs deep neural network speaker recognition systems using near-ultrasonic perturbations played through commercial off-the-shelf speakers, avoiding the specialized hardware that earlier ultrasound attacks required. The authors use single-sideband modulation with low-pass filtering, a nonlinear frequency response model, and time-frequency masking to keep the adversarial signal intact through physical transmission. In simulated and physical experiments, it reached a 100% attack success rate for closed-set identification and over 90% for open-set identification in targeted attacks.
Topics
Related items
- MediumRequest, Aggregate, Bypass: How Attackers Can Evade LLM Safety ClassifiersSimilar attack · CrowdStrike Blog
- InfoLLMs Cannot Reliably Judge (Yet?): A Comprehensive Assessment on the Robustness of LLM-as-a-JudgeSimilar attack · IEEE Xplore (Security & AI Journals)
- LowWhen the Bee Stings: CyberCom’s AI VulnerabilitySimilar attack · AIS eLibrary (Journal of AIS, CAIS, etc.)
- MediumA Decision Model Breaks Like Any Other Language Model: A First Look at JevSimilar attack · Check Point Research
- InfoSteering the Narrative: Breaking Bots by Forging Robust Adversarial CAPTCHAs With Diffusion ModelsSimilar attack · IEEE Xplore (Security & AI Journals)