inklap

Electronic music assassin: towards imperceptible physical adversarial attacks against black-box automatic speech recognitions

Ruiyuan Li · Cybersecurity · 2025

Abstract Speech recognition technology has brought revolutionary changes to our lives, but existing work has demonstrated the feasibility of using adversarial examples (AEs) to mislead speech recognition systems. Most existing adversarial attacks are designed for white-box or grey-box systems and they are ineffective against strict black-box scenarios where only the recognition results can be queried. The known black-box attack methods all add perturbations limited to the bounded $$L_{p}$$ L p neighborhood in the time domain and they neglected the relationship between the perturbations and the carrier audios. Therefore, although AEs they generated cannot be recognized by humans as the target attack commands, they sound very unnatural and unsmooth. The abnormal sense in auditory perception is easy to alarm the victim and can be used for defense. To address t

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً