2020
DOI: 10.1109/access.2020.2985231
|View full text |Cite
|
Sign up to set email alerts
|

MultiPAD: A Multivariant Partition-Based Method for Audio Adversarial Examples Detection

Abstract: Adversarial examples have been highlighted as a serious threat to various deep neural networks. The defense against adversarial examples is extremely urgent. This paper proposes an efficient multivariant partition based method to detect audio adversarial examples. Various partition strategies are exploited to obtain sufficient features that can help us to distinguish audio adversarial examples from clean samples. Using these features, a classification model is trained to detect audio adversarial examples. Thes… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 8 publications
(1 citation statement)
references
References 25 publications
0
1
0
Order By: Relevance
“…Target Generality Knowledge [8], [15], [24], [38], [43], [63], [64], [73], [120], [124] Before Sensor Universal None [7], [31], [36], [45], [49], [61], [87], [88], [93], [103], [110], [140], [141], [145], [147] Between Sensor and ASR Specific Partial [105], [106], [122], [123], [133] Inside ASR Specific Full perturbation cancellation [36], [45], [49], [110], adding distortion [61], [87], [103], signal smoothing [45], audio compression [31], [88], [147]) to destruct the adversarial perturbation (if any) to protect ASR systems. Other works apply an extra detection network [7], [46], [93], [140], [141] or multi-model detection mechanism [145]. However, those defense s...…”
Section: Defensementioning
confidence: 99%
“…Target Generality Knowledge [8], [15], [24], [38], [43], [63], [64], [73], [120], [124] Before Sensor Universal None [7], [31], [36], [45], [49], [61], [87], [88], [93], [103], [110], [140], [141], [145], [147] Between Sensor and ASR Specific Partial [105], [106], [122], [123], [133] Inside ASR Specific Full perturbation cancellation [36], [45], [49], [110], adding distortion [61], [87], [103], signal smoothing [45], audio compression [31], [88], [147]) to destruct the adversarial perturbation (if any) to protect ASR systems. Other works apply an extra detection network [7], [46], [93], [140], [141] or multi-model detection mechanism [145]. However, those defense s...…”
Section: Defensementioning
confidence: 99%