2021
DOI: 10.1109/tifs.2021.3116438
|View full text |Cite
|
Sign up to set email alerts
|

Study of Pre-Processing Defenses Against Adversarial Attacks on State-of-the-Art Speaker Recognition Systems

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
19
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
2
1

Relationship

1
7

Authors

Journals

citations
Cited by 33 publications
(19 citation statements)
references
References 40 publications
0
19
0
Order By: Relevance
“…In our experiment of adversarial training, we adversarially train Kaldi (the aforementioned Mini LibriSpeech model) on the Mini LibriSpeech dataset 14 . We set 𝑝 to ∞, iterations to 10, and the step size 𝛼 to 𝜖/5 for PGD, which are the same with [50,51]. Since the prior work [51] demonstrates that adversarial training with 𝜖 > 0.01 will be not able to converge, we set 𝜖 to 0.002, 0.004 and 0.006.…”
Section: H Results Of Possible Countermeasuresmentioning
confidence: 99%
See 2 more Smart Citations
“…In our experiment of adversarial training, we adversarially train Kaldi (the aforementioned Mini LibriSpeech model) on the Mini LibriSpeech dataset 14 . We set 𝑝 to ∞, iterations to 10, and the step size 𝛼 to 𝜖/5 for PGD, which are the same with [50,51]. Since the prior work [51] demonstrates that adversarial training with 𝜖 > 0.01 will be not able to converge, we set 𝜖 to 0.002, 0.004 and 0.006.…”
Section: H Results Of Possible Countermeasuresmentioning
confidence: 99%
“…We set 𝑝 to ∞, iterations to 10, and the step size 𝛼 to 𝜖/5 for PGD, which are the same with [50,51]. Since the prior work [51] demonstrates that adversarial training with 𝜖 > 0.01 will be not able to converge, we set 𝜖 to 0.002, 0.004 and 0.006. For evaluation, we also generate 10 audio AEs from Mini LibriSpeech model.…”
Section: H Results Of Possible Countermeasuresmentioning
confidence: 99%
See 1 more Smart Citation
“…In general, the modules developed for video and audio interaction represented the state-of-the-art at the time of the development of the mirror. More robust methods for both video and audio identification were recently proposed [74,75]. At the same time, more effective face attribute estimation [76] and speaker emotion recognition [77,78] methods were presented.…”
Section: Discussionmentioning
confidence: 99%
“…Most of the countermeasures in the literature can be primarily classified into two types-proactive and reactive [6,7]. Proactive countermeasures focus on making the system under attack (a.k.a.…”
Section: Introductionmentioning
confidence: 99%