EvilHarmony: Highly Stealthy Adversarial Attacks against
Black-box Speech Recognition Systems
EvilHarmony: Highly Stealthy Adversarial Attacks against
Black-box Speech Recognition Systems
We have reported the identified problems and submitted demos to the affected vendors.
Google's Abuse Vulnerability Reward Program panel qualified our report as an abuse-related methodology with high impact and rewarded us $5000.00.
Microsoft Security Response Center assessed our report as low severity and shared our report with the team responsible for maintaining the product or service.
The AEs, original audio clips, and the TTS audio clips of 5 speakers can be downloaded.
The following audio clips are an AE and its carrier. The original audio is of two people debating.
An AE of the target command "what is the weather".
The decoding result of the AE by Tencent ASR API Service.
The carrier, i.e., the original audio, of the AE.
The decoding result of the carrier by Tencent ASR API Service.
Note: The paper “EvilHarmony: Highly Stealthy Adversarial Attacks against Black-box Speech Recognition Systems” analyzed the important features of Commercial Black-box adversarial audio, and proposed an EvilHarmony attack for automatic speech recognition (ASR) systems. This website shows some AEs and their attack effectiveness. The details of the target commands are introduced in the red color of “Command”.
1) The human study of Part 1 “AEs for Aliyun API (English target commands)” is shown in Table 5 (Page 9) of the paper.
2) The human study of Part 1 “AEs for six API services (English target commands)” is shown in Table 6 (Page 10) of the paper.
3) The human study of Part 2 “Physical world attack” is shown in Table 8 (Page 11) of the paper.
4) The human study of Part 3 “AEs for Aliyun API (Chinese target commands)” is shown in Table 7 (Page 11) of the paper.
The AEs of Table 5 and Tbale 6 are available as follows.
Aliyun_Phantom_C1
{"success": true, "errorMSG": null, "result": "Play music. ", "confidence": null}
Aliyun_Phantom_C2
{"success": true, "errorMSG": null, "result": "What is the weather like that. ", "confidence": null}
Aliyun_Phantom_C3
{"success": true, "errorMSG": null, "result": "You can open the door, You call it for living. ", "confidence": null}
Aliyun_Phantom_C4
{"success": true, "errorMSG": null, "result": "You open the window. ", "confidence": null}
Aliyun_Phantom_C5
{"success": true, "errorMSG": null, "result": "Take a picture of me. ", "confidence": null}
Aliyun_Phantom_C6
{"success": true, "errorMSG": null, "result": "To make it a warmer. ", "confidence": null}
Aliyun_Phantom_C7
{"success": true, "errorMSG": null, "result": "Where is my car. ", "confidence": null}
Aliyun_Phantom_C8
{"success": true, "errorMSG": null, "result": "Send a message. ", "confidence": null}
Aliyun_Phantom_C9
{"success": true, "errorMSG": null, "result": "Turn on the light. ", "confidence": null}
Aliyun_Phantom_C10
{"success": true, "errorMSG": null, "result": "Turn off the computer. ", "confidence": null}
Attack Google Assistant
Attack Google Assistant
Attack Google Assistant
Attack Google Assistant
Attack Voice Assistant on surface pro 9
Attack Voice Assistant on surface pro 9
Attack Voice Assistant on surface pro 9
Attack Voice Assistant on surface pro 9
Attack Voice Assistant on surface pro 9
Attack Voice Assistant on surface pro 9
Attack the voice input model of DouBao
Attack the voice input model of DouBao
3.1 Original audio 01_A
3.1 Adversarial audio 01_B
Chinese Command 01
Chinese command (pinyin):da kai deng
Chinese command ( characters): 打开灯
English meaning:turn on the light
3.2 Original audio 02_A
3.2 Adversarial audio 02_B
Chinese Command 02
Chinese command (pinyin): da kai men
Chinese command ( characters): 打开门
English meaning: open the door
3.3 Original audio 03_A
3.3 Adversarial audio 02_B
Chinese Command 03
Chinese command (pinyin): dao hang hui jia
Chinese command ( characters): 导航回家
English meaning: navigate home
3.4 Original audio 04_A
3.4 Adversarial audio 04_B
Chinese Command 04
Chinese command (pinyin): gei lao ban fa xin xi
Chinese command ( characters): 给老板发信息
English meaning: send a message to boss
3.5 Original audio 05_A
3.5 Adversarial audio 05_B
Chinese Command 05
Chinese command (pinyin): jin tian tian qi zen me yang
Chinese command ( characters):今天天气怎么样
English meaning: what is the weather today
3.6 Screen recording of Aliyun API decode AEs