• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

Defending and Detecting Audio Adversarial Example using Frame Offsets


Abstract

Machine learning models are vulnerable to adversarial examples generated by adding a deliberately designed perturbation to a benign sample. Particularly, for automatic speech recognition (ASR) system, a benign audio which sounds normal could be decoded as a harmful command due to potential adversarial attacks. In this paper, we focus on the countermeasures against audio adversarial examples. By analyzing the characteristics of ASR systems, we find that frame offsets with silence clip appended at the beginning of an audio can degenerate adversarial perturbations to normal noise. For various scenarios, we exploit frame offsets by different strategies such as defending, detecting and hybrid strategy. Compared with the previous methods, our proposed method can defense audio adversarial example in a simpler, more generic and efficient way. Evaluated on three state-of-the-arts adversarial attacks against different ASR systems respectively, the experimental results demonstrate that the proposed method can effectively improve the robustness of ASR systems.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
Y. Gong, D. Yan, T. Mao, D. Wang, R. Wang, "Defending and Detecting Audio Adversarial Example using Frame Offsets," KSII Transactions on Internet and Information Systems, vol. 15, no. 4, pp. 1538-1552, 2021. DOI: 10.3837/tiis.2021.04.019.

[ACM Style]
Yongkang Gong, Diqun Yan, Terui Mao, Donghua Wang, and Rangding Wang. 2021. Defending and Detecting Audio Adversarial Example using Frame Offsets. KSII Transactions on Internet and Information Systems, 15, 4, (2021), 1538-1552. DOI: 10.3837/tiis.2021.04.019.

[BibTeX Style]
@article{tiis:24537, title="Defending and Detecting Audio Adversarial Example using Frame Offsets", author="Yongkang Gong and Diqun Yan and Terui Mao and Donghua Wang and Rangding Wang and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2021.04.019}, volume={15}, number={4}, year="2021", month={April}, pages={1538-1552}}