利用深度学习检测听不见的信息的声学后门传输

S. Kokalj-Filipovic, Morriel Kasher, Michael Zhao, P. Spasojevic
{"title":"利用深度学习检测听不见的信息的声学后门传输","authors":"S. Kokalj-Filipovic, Morriel Kasher, Michael Zhao, P. Spasojevic","doi":"10.1145/3395352.3402629","DOIUrl":null,"url":null,"abstract":"The novel secret inaudible acoustic communication channel [11], referred to as the BackDoor channel, is a method of embedding inaudible signals in acoustic data that is likely to be processed by a trained deep neural net. In this paper we perform preliminary studies of the detectability of such a communication channel by deep learning algorithms that are trained on the original acoustic data used for such a secret exploit. The BackDoor channel embeds inaudible messages by modulating them with a sinewave of 40kHz and transmitting using ultrasonic speakers. The received composite signal is used to generate the Backdoor dataset for evaluation of our neural net. The audible samples are played back and recorded as a baseline dataset for training. The Backdoor dataset is used to evaluate the impact that the BackDoor channel has on the classification of the acoustic data, and we show that the accuracy of the classifier is degraded. The degradation depends on the type of deep classifier and it appears to impact less the classifiers that are trained using autoencoders. We also propose statistics that can be used to detect the out-of-distribution samples created as a result of the BackDoor channel, such as the log likelihood of the variational autoencoder used to pre-train the classifier or the empirical entropy of the classifier's output layer. The preliminary results presented in this paper indicate that the use of deep learning classifiers as detectors of the BackDoor secret channel merits further research.","PeriodicalId":370816,"journal":{"name":"Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-07-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Detecting acoustic backdoor transmission of inaudible messages using deep learning\",\"authors\":\"S. Kokalj-Filipovic, Morriel Kasher, Michael Zhao, P. Spasojevic\",\"doi\":\"10.1145/3395352.3402629\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The novel secret inaudible acoustic communication channel [11], referred to as the BackDoor channel, is a method of embedding inaudible signals in acoustic data that is likely to be processed by a trained deep neural net. In this paper we perform preliminary studies of the detectability of such a communication channel by deep learning algorithms that are trained on the original acoustic data used for such a secret exploit. The BackDoor channel embeds inaudible messages by modulating them with a sinewave of 40kHz and transmitting using ultrasonic speakers. The received composite signal is used to generate the Backdoor dataset for evaluation of our neural net. The audible samples are played back and recorded as a baseline dataset for training. The Backdoor dataset is used to evaluate the impact that the BackDoor channel has on the classification of the acoustic data, and we show that the accuracy of the classifier is degraded. The degradation depends on the type of deep classifier and it appears to impact less the classifiers that are trained using autoencoders. We also propose statistics that can be used to detect the out-of-distribution samples created as a result of the BackDoor channel, such as the log likelihood of the variational autoencoder used to pre-train the classifier or the empirical entropy of the classifier's output layer. The preliminary results presented in this paper indicate that the use of deep learning classifiers as detectors of the BackDoor secret channel merits further research.\",\"PeriodicalId\":370816,\"journal\":{\"name\":\"Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-07-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3395352.3402629\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3395352.3402629","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

一种新型的秘密听不清声学通信信道[11],称为后门信道,是一种将听不清信号嵌入到声学数据中的方法,这些声学数据可能会被训练好的深度神经网络处理。在本文中,我们通过深度学习算法对这种通信通道的可探测性进行了初步研究,这些算法是在用于这种秘密利用的原始声学数据上进行训练的。后门通道通过用40kHz的正弦波调制并使用超声波扬声器传输来嵌入听不见的信息。接收到的复合信号用于生成后门数据集,用于评估我们的神经网络。声音样本被回放并记录为训练的基线数据集。使用Backdoor数据集来评估Backdoor通道对声学数据分类的影响,结果表明分类器的准确性降低了。退化取决于深度分类器的类型,它似乎对使用自编码器训练的分类器影响较小。我们还提出了可用于检测由于后门通道而产生的分布外样本的统计数据,例如用于预训练分类器的变分自编码器的对数似然或分类器输出层的经验熵。本文的初步结果表明,使用深度学习分类器作为后门秘密通道的检测器值得进一步研究。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Detecting acoustic backdoor transmission of inaudible messages using deep learning
The novel secret inaudible acoustic communication channel [11], referred to as the BackDoor channel, is a method of embedding inaudible signals in acoustic data that is likely to be processed by a trained deep neural net. In this paper we perform preliminary studies of the detectability of such a communication channel by deep learning algorithms that are trained on the original acoustic data used for such a secret exploit. The BackDoor channel embeds inaudible messages by modulating them with a sinewave of 40kHz and transmitting using ultrasonic speakers. The received composite signal is used to generate the Backdoor dataset for evaluation of our neural net. The audible samples are played back and recorded as a baseline dataset for training. The Backdoor dataset is used to evaluate the impact that the BackDoor channel has on the classification of the acoustic data, and we show that the accuracy of the classifier is degraded. The degradation depends on the type of deep classifier and it appears to impact less the classifiers that are trained using autoencoders. We also propose statistics that can be used to detect the out-of-distribution samples created as a result of the BackDoor channel, such as the log likelihood of the variational autoencoder used to pre-train the classifier or the empirical entropy of the classifier's output layer. The preliminary results presented in this paper indicate that the use of deep learning classifiers as detectors of the BackDoor secret channel merits further research.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Wideband spectral monitoring using deep learning Generalized wireless adversarial deep learning Retracted on July 26, 2022: Open set recognition through unsupervised and class-distance learning Encrypted rich-data steganography using generative adversarial networks Generative adversarial attacks against intrusion detection systems using active learning
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1