arrow
返回

A Robust Approach for Securing Audio Classification Against Adversarial Attacks

delete2020-01-01
delete41
delete
OA
AI
M
Mohammad Esmaeilpour *
P
Patrick Cardinal
A
Alessandro L. Koerich
DOI:10.1109/TIFS.2019.2956591delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Adversarial audio attacks can be considered as a small perturbation unperceptive to human ears that is intentionally added to an audio signal and causes a machine learning model to make mistakes. This poses a security concern about the safety of machine learning models since the adversarial attacks can fool such models toward the wrong predictions. In this paper we first review some strong adversarial attacks that may affect both audio signals and their 2D representations and evaluate the resiliency of deep learning models and support vector machines (SVM) trained on 2D audio representations such as short time Fourier transform, discrete wavelet transform (DWT) and cross recurrent plot against several state-of-the-art adversarial attacks. Next, we propose a novel approach based on pre-processed DWT representation of audio signals and SVM to secure audio systems against adversarial attacks. The proposed architecture has several preprocessing modules for generating and enhancing spectrograms including dimension reduction and smoothing. We extract features from small patches of the spectrograms using the speeded up robust feature (SURF) algorithm which are further used to transform into cluster distance distribution using the K-Means++ algorithm. Finally, SURF-generated vectors are encoded by this codebook and the resulting codewords are used for training a SVM. All these steps yield to a novel approach for audio classification that provides a good tradeoff between accuracy and resilience. Experimental results on three environmental sound datasets show the competitive performance of the proposed approach compared to the deep neural networks both in terms of accuracy and robustness against strong adversarial attacks.
Keyword:
Support vector machines
Machine learning
Robustness
Perturbation methods
Predictive models
Optimization
Two dimensional displays
Spectrograms
environmental sound classification
adversarial attack
K-means plus plus
support vector machines (SVM)
convolutional denoising autoencoder
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.2K
被引数:
2.3W

机构

U
university of quebec
学者数:
2.0W
论文数: 1.9W
被引数: 19
引用论文

引用论文

Competitive redox-catalyzed migratory carbonyl insertion and .beta.-elimination in iron alkyl complexes
err2002-05-01
err0
PREAI
errRobert S. Bly; Gary S. Silverman; M. Mahmun Hossain; Ruta K. Bly
err分享
err收藏
Post-artemisinin delayed hemolysis after oral therapy for P. falciparum infection
err2020-01-01
err0
errOAAI
errChristian C. Conlon; Anna Stein; Rhonda E. Colombo; Christina Schofield
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容