Abstract
Adversarial examples have been highlighted as a serious threat to various deep neural networks. The defense against adversarial examples is extremely urgent. This paper proposes an efficient multivariant partition based method to detect audio adversarial examples. Various partition strategies are exploited to obtain sufficient features that can help us to distinguish audio adversarial examples from clean samples. Using these features, a classification model is trained to detect audio adversarial examples. These features are also combined and compared to analyze their detection performance. The performance is evaluated on the Mozilla Common Voice dataset and the LibriSpeech dataset. Experimental results based on Mozilla Common Voice dataset show that the detection accuracy and AUC value of the model achieve 94.8% and 0.97 respectively, which are 13.5% and 0.08 higher than using the features of the existing work. Experimental results based on LibriSpeech dataset show that the detection accuracy and AUC value of the model achieve 100% and 1.00 respectively, which are 10% and 0.10 higher than the existing work.
Author supplied keywords
Cite
CITATION STYLE
Guo, Q., Ye, J., Hu, Y., Zhang, G., Li, X., & Li, H. (2020). MultiPAD: A Multivariant Partition-Based Method for Audio Adversarial Examples Detection. IEEE Access, 8, 63368–63380. https://doi.org/10.1109/ACCESS.2020.2985231
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.