Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
38 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
41 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

A Multiversion Programming Inspired Approach to Detecting Audio Adversarial Examples (1812.10199v2)

Published 26 Dec 2018 in cs.SD, cs.CR, and eess.AS

Abstract: Adversarial examples (AEs) are crafted by adding human-imperceptible perturbations to inputs such that a machine-learning based classifier incorrectly labels them. They have become a severe threat to the trustworthiness of machine learning. While AEs in the image domain have been well studied, audio AEs are less investigated. Recently, multiple techniques are proposed to generate audio AEs, which makes countermeasures against them an urgent task. Our experiments show that, given an AE, the transcription results by different Automatic Speech Recognition (ASR) systems differ significantly, as they use different architectures, parameters, and training datasets. Inspired by Multiversion Programming, we propose a novel audio AE detection approach, which utilizes multiple off-the-shelf ASR systems to determine whether an audio input is an AE. The evaluation shows that the detection achieves accuracies over 98.6%.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Qiang Zeng (43 papers)
  2. Jianhai Su (4 papers)
  3. Chenglong Fu (31 papers)
  4. Golam Kayas (4 papers)
  5. Lannan Luo (13 papers)
Citations (42)