Collaborative Research: SaTC: CORE: Small: Securing IoT and Edge Devices under Audio Adversarial Attacks

协作研究:SaTC:核心:小型:在音频对抗攻击下保护物联网和边缘设备

基本信息

  • 批准号:
    2114220
  • 负责人:
  • 金额:
    $ 33万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-10-01 至 2024-09-30
  • 项目状态:
    已结题

项目摘要

Powered by the advancement of artificial intelligence (AI) techniques, the next-generation voice-controllable IoT and edge systems have substantially facilitated people’s daily lives. Such systems include voice assistant systems and voice authenticated mobile banking, among many others. However, the underlying machine learning approaches used in these systems, are inherently vulnerable to audio adversarial attacks, in which an adversary can mislead the machine learning models via injecting imperceptible perturbation to the original audio input. Given the widespread adoption of voice-controllable IoT and edge systems in many privacy-critical and safety-critical applications, e.g., personal banking and autonomous driving, the in-depth understanding and investigation of severity and consequences of audio-based adversarial attack as well as the corresponding defense solutions, are highly demanded. This project will perform a comprehensive study and analysis of the vulnerability and robustness of voice-controllable IoT and edge systems against audio-domain adversarial attacks in both temporal and spatial perspectives. The research outcome of this project will form solid foundations for building trustworthy voice-controllable IoT and edge systems. The developed defense techniques will improve the security of many intelligent audio systems, such as automatic speech recognition (ASR), keyword spotting, and speaker recognition. This project will involve underrepresented students, undergraduate and graduate students, and K-12 students through a variety of engaging programs.The objective of this project is to demonstrate the feasibility of audio adversarial attacks in the physical world, determine the attack severity and consequences, and further develop defending strategies in practical environments to build attack-resilient voice-controllable Internet-of-Things (IoT) devices and edge systems. To study the possibility and severity of audio adversarial attacks in a practical time-constraint setting, the project will develop low-cost audio-agnostic synchronization-free attack launching schemes, including audio-specific fast adversarial perturbation generator and universal adversarial perturbation generator. To investigate how the adversarial perturbations survive various propagation factors in realistic environments, the project will analyze the audio distortions caused by the over-the-air propagation using an advanced room impulse response simulator and physical environment measurements. The project will also develop several defense techniques, including defensive denoiser, model enhancement, and microphone-array-based liveness detection. The presented technique will help to secure the voice-controllable IoT and edge devices under audio adversarial attacks. The project will also contribute to a new computing paradigm in audio-based adversarial machine learning in both theoretic foundations as well as safety-critical audio-oriented emerging applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在人工智能(AI)技术的发展方面,下一代语音控制的物联网和边缘系统的推动力大大支持了人们的日常生活。这样的系统包括语音助理系统和语音身份验证的移动银行业务等。但是,这些系统中使用的基础机器学习方法本质上容易受到音频对抗性攻击的影响,在这种情况下,对手可以通过向原始音频输入注入不可察觉的扰动来误导机器学习模型。鉴于在许多关键和关键安全的应用中采用了语音控制的物联网和边缘系统,例如个人银行和自动驾驶,高度要求对基于音频的对抗性攻击以及对应的国防解决方案的严重性以及对严重性的深入理解和调查。该项目将对语音控制的物联网和边缘系统的脆弱性和鲁棒性进行全面研究和分析,以针对临时和空间观点的音频域对抗攻击。该项目的研究结果将构成可靠的基础,以建立可信赖的语音控制物联网和边缘系统。开发的防御技术将提高许多智能音频系统的安全性,例如自动语音识别(ASR),关键字斑点和扬声器识别。该项目将通过各种引人入胜的计划涉及代表性不足的学生,本科生和研究生以及K-12学生。该项目的目的是证明在物理世界中音频对抗性攻击的可行性,确定攻击性的严重性和后果,并在实践环境中进一步发展攻击性的策略,以构建攻击性的语言互联网和互联网互联网(Intern Internt)。为了研究在实用的时间限制环境中音频对抗攻击的可能性和严重性,该项目将开发低成本的音频无关同步攻击启动方案,包括音频特定的快速对抗性扰动生成器和通用对抗性扰动生成器。为了研究对抗性扰动如何在现实环境中生存各种传播因素,该项目将使用高级房间脉冲响应模拟器和物理环境测量值分析由空中传播引起的音频畸变。该项目还将开发多种防御技术,包括防御性Denoiser,模型增强和基于麦克风阵列的Livices检测。提出的技术将有助于在音频对抗攻击下保护语音控制的物联网和边缘设备。该项目还将有助于基于音频的对抗机器学习的新计算范式在理论基础中以及面向安全性音频的新兴应用程序中。该奖项反映了NSF的法定任务,并被认为是通过基金会的智力和更广泛影响的评估来通过评估来通过评估来获得支持的珍贵。

项目成果

期刊论文数量(6)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks
Robust Detection of Machine-induced Audio Attacks in Intelligent Audio Systems with Microphone Array
Stealthy Backdoor Attack on RF Signal Classification
HALOC: Hardware-Aware Automatic Low-Rank Compression for Compact Neural Networks
  • DOI:
    10.1609/aaai.v37i9.26244
  • 发表时间:
    2023-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan
  • 通讯作者:
    Jinqi Xiao;Chengming Zhang;Yu Gong;Miao Yin;Yang Sui;Lizhi Xiang;Dingwen Tao;Bo Yuan
Universal Targeted Adversarial Attacks Against mmWave-based Human Activity Recognition
  • DOI:
    10.1109/infocom53939.2023.10228887
  • 发表时间:
    2023-05
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Yucheng Xie;Ruizhe Jiang;Xiaonan Guo;Yan Wang;Jerry Q. Cheng;Yingying Chen
  • 通讯作者:
    Yucheng Xie;Ruizhe Jiang;Xiaonan Guo;Yan Wang;Jerry Q. Cheng;Yingying Chen
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Yingying Chen其他文献

Topology-based Multi-jammer Localization in Wireless Networks
无线网络中基于拓扑的多干扰机定位
  • DOI:
    10.1051/sands/2023025
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Hongbo Liu;Yingying Chen;Wenyuan Xu;Zhenhua Liu;Yuchen Su
  • 通讯作者:
    Yuchen Su
UV light-assisted fabrication of Cu0.91In0.09S microspheres sensitized TiO2 nanotube arrays and their photoelectrochemical properties
紫外光辅助制备Cu0.91In0.09S微球敏化TiO2纳米管阵列及其光电化学性能
  • DOI:
    10.1016/j.materresbull.2014.12.071
  • 发表时间:
    2015-04
  • 期刊:
  • 影响因子:
    5.4
  • 作者:
    Xinyu Cui;Hongmei Gu;Yuanyuan Yin;Yue Guan;Shengzhong Rong;Yongkui Yin;Yingying Chen;Qunhong Wu;Yanhua Hao;Miaojing Li
  • 通讯作者:
    Miaojing Li
Label-free tri-luminophores electrochemiluminescence sensor for microRNAs detection based on three-way DNA junction structure
基于三向DNA连接结构的用于microRNA检测的无标记三发光体电化学发光传感器
  • DOI:
    10.1016/j.jelechem.2020.114935
  • 发表时间:
    2020-12
  • 期刊:
  • 影响因子:
    4.5
  • 作者:
    Xialing Hou;Zhiguang Suo;Ziheng Hu;Xinying Zhang;Yingying Chen;Lingyan Feng
  • 通讯作者:
    Lingyan Feng
Direct Load Control by Distributed Imperialist Competitive Algorithm
分布式帝国主义竞争算法的直接负载控制
Acquired persistently complete remission by decitabine-based treatment for acute myeloid leukemia with the MLL-SEPT9 fusion gene
通过基于地西他滨的 MLL-SEPT9 融合基因急性髓系白血病治疗获得持续完全缓解
  • DOI:
    10.1080/10428194.2019.1625044
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    2.6
  • 作者:
    Fujue Wang;Yingying Chen;N. Jiang;Shuaige Gong;Tingyong Cao;Jin Yuan;Jiazhuo Liu;Li;Yu Wu;Yongqian Jia
  • 通讯作者:
    Yongqian Jia

Yingying Chen的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Yingying Chen', 18)}}的其他基金

Collaborative Research: III: Small: Efficient and Robust Multi-model Data Analytics for Edge Computing
协作研究:III:小型:边缘计算的高效、稳健的多模型数据分析
  • 批准号:
    2311596
  • 财政年份:
    2023
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
SHF: Small: A General Framework for Accelerating AI on Resource-Constrained Edge Devices
SHF:小型:在资源受限的边缘设备上加速 AI 的通用框架
  • 批准号:
    2211163
  • 财政年份:
    2022
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
Collaborative Research: CCRI: New: Nation-wide Community-based Mobile Edge Sensing and Computing Testbeds
合作研究:CCRI:新:全国范围内基于社区的移动边缘传感和计算测试平台
  • 批准号:
    2120396
  • 财政年份:
    2021
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
Collaborative Research: PPoSS: Planning: Hardware-accelerated Trustworthy Deep Neural Network
合作研究:PPoSS:规划:硬件加速的可信深度神经网络
  • 批准号:
    2028876
  • 财政年份:
    2020
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
SHF: Small: Collaborative Research: Software Hardware Architecture Co-design for Low-power Heterogeneous Edge Devices
SHF:小型:协作研究:低功耗异构边缘设备的软件硬件架构协同设计
  • 批准号:
    1909963
  • 财政年份:
    2019
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Security Assurance in Short Range Communication with Wireless Channel Obfuscation
SaTC:核心:小型:协作:通过无线信道混淆实现短距离通信的安全保证
  • 批准号:
    1814590
  • 财政年份:
    2018
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
SaTC:核心:小型:协作:利用无线网络中的物理属性进行隐式身份验证
  • 批准号:
    1716500
  • 财政年份:
    2017
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
NeTS:媒介:协作研究:利用细粒度 WiFi 信号进行健康监测
  • 批准号:
    1826647
  • 财政年份:
    2017
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: Collaborative: Exploiting Physical Properties in Wireless Networks for Implicit Authentication
SaTC:核心:小型:协作:利用无线网络中的物理属性进行隐式身份验证
  • 批准号:
    1820624
  • 财政年份:
    2017
  • 资助金额:
    $ 33万
  • 项目类别:
    Standard Grant
NeTS: Medium: Collaborative Research: Exploiting Fine-grained WiFi Signals for Wellbeing Monitoring
NeTS:媒介:协作研究:利用细粒度 WiFi 信号进行健康监测
  • 批准号:
    1514436
  • 财政年份:
    2015
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant

相似国自然基金

支持二维毫米波波束扫描的微波/毫米波高集成度天线研究
  • 批准号:
    62371263
  • 批准年份:
    2023
  • 资助金额:
    52 万元
  • 项目类别:
    面上项目
腙的Heck/脱氮气重排串联反应研究
  • 批准号:
    22301211
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
水系锌离子电池协同性能调控及枝晶抑制机理研究
  • 批准号:
    52364038
  • 批准年份:
    2023
  • 资助金额:
    33 万元
  • 项目类别:
    地区科学基金项目
基于人类血清素神经元报告系统研究TSPYL1突变对婴儿猝死综合征的致病作用及机制
  • 批准号:
    82371176
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
FOXO3 m6A甲基化修饰诱导滋养细胞衰老效应在补肾法治疗自然流产中的机制研究
  • 批准号:
    82305286
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 33万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了