IP Library Granted Patent US 12,190,887
Granted Patent B2
US 12,190,887 · App. 17/643,071 · Granted Jan 7, 2025

Adversarial speech-text protection against automated analysis

Inventors: Ngoc Minh Tran (Dublin, IE); Marco Simioni (Dublin, IE); Hessel Tuinhof (Dublin, IE)
Assignee: International Business Machines Corporation
G10L15/26G06N20/00G10L21/0208
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,190,887
App. No.
17/643,071
Granted
Jan 7, 2025
Kind
B2
Abstract

A method, system, and computer program product are disclosed. The method includes processing an audio signal that includes speech data and transcribing the speech data to generate text data. The method also includes identifying a vulnerable portion of the text data and, in response, applying adversarial text to the text data to generate robust text data. Adversarial noise corresponding to the robust text data is generated and applied to the speech data.

Claims (48)

1. A method, comprising:

processing an audio signal comprising speech data;

transcribing the speech data to generate text data;

identifying a vulnerable portion of the text data;

in response to the identifying, modifying the text data to generate a robust transcript, wherein the modifying comprises replacing the vulnerable portion of the text data with adversarial text;

designing adversarial noise corresponding to the adversarial text; and

applying the corresponding adversarial noise to the audio signal to generate a robust audio signal comprising modified speech data that, when transcribed, generates a transcript with a similarity to the robust transcript that is above a threshold similarity.

2. The method of claim 1 , wherein the corresponding adversarial noise comprises adversarial speech data designed to cause speech-to-text models to produce a targeted transcription of the modified speech data matching the robust transcript.

3. The method of claim 2 , wherein the targeted transcription is at least 90% similar to the robust transcript.

4. The method of claim 1 , wherein the identifying the vulnerable portion comprises generating importance scores for portions of the text data, and wherein the vulnerable portion is a portion of the text data with a highest importance score.

5. The method of claim 1 , further comprising selecting the adversarial text, wherein the selecting the adversarial text comprises:

identifying, in an embedding space of a word from the vulnerable portion, a word that is semantically equivalent to the word from the vulnerable portion; and

determining that replacing the word from the vulnerable portion with the identified semantically equivalent word reduces a confidence score associated with a prediction of a target machine-learning model.

6. The method of claim 1 , wherein the audio signal further comprises adversarial non-speech noise.

7. The method of claim 6 , wherein the processing the audio signal comprises removing the adversarial non-speech noise prior to transcribing the speech data.

8. The method of claim 1 , wherein the replacing the vulnerable portion comprises using a word embedding process to replace a word in the vulnerable portion with a semantically equivalent word.

9. The method of claim 8 , wherein the applying the corresponding adversarial noise replaces an utterance of the word in the audio signal with an utterance of the semantically equivalent word.

10. The method of claim 1 , wherein:

the modifying the text data comprises deleting a word from the vulnerable portion; and

the applying the corresponding adversarial noise comprises deleting an utterance of the word from the audio signal.

11. A system, comprising:

a memory; and

a processor communicatively coupled to the memory, wherein the processor is configured to perform a method comprising:

processing an audio signal comprising speech data;

transcribing the speech data to generate text data;

identifying a vulnerable portion of the text data;

in response to the identifying, modifying the text data to generate a robust transcript, wherein the modifying comprises replacing the vulnerable portion of the text data with adversarial text;

designing adversarial noise corresponding to the adversarial text; and

applying the corresponding adversarial noise to the audio signal to generate a robust audio signal comprising modified speech data that, when transcribed, generates a transcript with a similarity to the robust transcript that is above a threshold similarity.

12. The system of claim 11 , wherein the corresponding adversarial noise comprises adversarial speech data designed to cause speech-to-text models to produce a targeted transcription of the modified speech data matching the robust transcript.

13. The system of claim 11 , wherein the identifying the vulnerable portion comprises generating importance scores for portions of the text data, and wherein the vulnerable portion is a portion of the text data with a highest importance score.

14. The system of claim 11 , further comprising selecting the adversarial text, wherein the selecting the adversarial text comprises:

identifying, in an embedding space of a word from the vulnerable portion, a word that is semantically equivalent to the word from the vulnerable portion; and

determining that replacing the word from the vulnerable portion with the identified semantically equivalent word reduces a confidence score associated with a prediction of a target machine-learning model.

15. The system of claim 11 , wherein the audio signal further comprises adversarial non-speech noise.

16. The system of claim 15 , wherein the processing the audio signal comprises removing the adversarial non-speech noise prior to transcribing the speech data.

17. A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause a device to perform a method, the method comprising:

processing an audio signal comprising speech data;

transcribing the speech data to generate text data;

identifying a vulnerable portion of the text data;

in response to the identifying, modifying the text data to generate a robust transcript, wherein the modifying comprises replacing the vulnerable portion of the text data with adversarial text;

designing adversarial noise corresponding to the adversarial text; and

applying the corresponding adversarial noise to the audio signal to generate a robust audio signal comprising modified speech data that, when transcribed, generates a transcript with a similarity to the robust transcript that is above a threshold similarity.

18. The computer program product of claim 17 , wherein the identifying the vulnerable portion comprises generating importance scores for portions of the text data, and wherein the vulnerable portion is a portion of the text data with a highest importance score.

19. The computer program product of claim 17 , further comprising selecting the adversarial text, wherein the selecting the adversarial text comprises:

identifying, in an embedding space of a word from the vulnerable portion, a word that is semantically equivalent to the word from the vulnerable portion; and

determining that replacing the word from the vulnerable portion with the identified semantically equivalent word reduces a confidence score associated with a prediction of a target machine-learning model.

20. The computer program product of claim 17 , wherein the processing the audio signal comprises removing adversarial non-speech noise prior to transcribing the speech data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2021
From: TRAN, NGOC MINH; SIMIONI, MARCO; TUINHOF, HESSEL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058325/0098 →
Continuity (1)
Related Publication 20230178079A1 · Jun 8, 2023
References Cited (31)
US 7231341B2 · Bangalore et al. · 2007 [cited by applicant]
US 7966172B2 · Ruiz et al. · 2011 [cited by applicant]
US 8019610B2 · Walker et al. · 2011 [cited by applicant]
US 8024331B2 · Calistri-Yeh et al. · 2011 [cited by applicant]
US 8150676B1 · Kaeser · 2012 [cited by applicant]
US 8762134B2 · Reiter · 2014 [cited by applicant]
US 9576009B1 · Hammond et al. · 2017 [cited by applicant]
US 10896664B1 · Buesser et al. · 2021 [cited by applicant]
US 20040098385A1 · Mayfield · 2004 [cited by examiner]
US 20100094628A1 · Bacchiani · 2010 [cited by examiner]
US 20190043506A1 · Rivkin · 2019 [cited by examiner]
US 20210141876A1 · Veshchikov · 2021 [cited by examiner]
US 20210342647A1 · Gou · 2021 [cited by examiner]
US 20230162723A1 · Cui · 2023 [cited by examiner]
US 20230245650A1 · Cary · 2023 [cited by examiner]
CN 112908300A · 2021 [cited by examiner]
CN 113204974A · 2021 [cited by examiner]
Luz, “Time-based Memory Support in Collaborative Meetings: Speech Indexing Without Speech Recognition.” Trinity College, University of Dublin (2002), 18 pgs. [cited by applicant]
Behjati et al., “Universal Adversarial Attacks on Text Classifiers,” ICASSP 2019, pp. 7345-7349. [cited by applicant]
Carlini et al., “Audio Adversarial Examples: Targeted Attacks on Speech-to-Text,” https://arxiv.org/pdf/1807.01069.pdf, Mar. 30, 2018, 7 pgs. [cited by applicant]
Carlini et al., “Hidden Voice Commands,” https://nicholas.carlini.com/papers/2016_usenix_hiddenvoicecommands.pdf, 2016, 18 pgs. [cited by applicant]
Dasgupta et al., “Gray-box Techniques for Adversarial Text Generation,” CEUR-WS.org/Vol-2269/FSS-18_paper_52.pdf, Proceedings of the AAAI Fall 2018 Symposium on Adversary-Aware Learning Techniques and Trends in Cybersec… [cited by applicant]
Ebrahimi et al., “HotFlip: White-Box Adversarial Examples for Text Classification,” arXiv:1712.06751v2 [cs.CL] May 24, 2018, 6 pgs. [cited by applicant]
Jin et al., “TextFool: Fool your Model with Natural Adversarial Text,” printed Sep. 2, 2021, 10 pgs. [cited by applicant]
Li et al., “TEXTBUGGER: Generating Adversarial Text Against Real-world Applications,” arXiv:1812.05271v1 [cs.CR] Dec. 13, 2018, 15 pgs. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing,” Recommendations of the National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pgs. [cited by applicant]
Nicolae et al., “Adversarial Robustness Toolbox v1.0.0,” https://arxiv.org/pdf/1807.01069.pdf, Nov. 15, 2019, 34 pgs. [cited by applicant]
Tran et al., “Text Data Protection Against Automated Analysis,” U.S. Appl. No. 17/101,465, filed Nov. 23, 2020. [cited by applicant]
Tuinhoff et al., “Published Content Protection,” U.S. Appl. No. 17/083,566, filed Oct. 29, 2020. [cited by applicant]
Wang et al., “Towards A Robust Deep Neural Network in Texts: A Survey,” https://arxiv.org/abs/1902.07285, arXiv:1902.07285v6 [cs.CL] Apr. 21, 2021, 22 pgs. [cited by applicant]
Zhang et al., “DolphinAttack: Inaudible Voice Commands,” https://acmccs.github.io/papers/p103-zhangAemb.pdf, CCS'17, Oct. 30-Nov. 3, 2017, SessionA3: Adversarial Machine Learning, 15 pgs. [cited by applicant]