MultiPAD: A Multivariant Partition-Based Method for Audio Adversarial Examples Detection
Qingli Guo, Jing Ye, Yu Hen Hu, Guohe Zhang, Xiaowei Li, Huawei Li · IEEE Access · 2020
Adversarial examples have been highlighted as a serious threat to various deep neural networks. The defense against adversarial examples is extremely urgent. This paper proposes an efficient multivariant partition based method to detect audio adversarial examples. Various partition strategies are exploited to obtain sufficient features that can help us to distinguish audio adversarial examples from clean samples. Using these features, a classification model is trained to detect audio adversarial examples. These features are also combined and compared to analyze their detection performance. The performance is evaluated on the Mozilla Common Voice dataset and the LibriSpeech dataset. Experimental results based on Mozilla Common Voice dataset show that the detection accuracy and AUC value of the model achieve 94.8% and 0.97 respectively, which are 13.5% and 0.08 higher than using the features of the existing work. Experimental results based on LibriSpeech dataset show that the detection accuracy and AUC value of the model achieve 100% and 1.00 respectively, which are 10% and 0.10 higher than the existing work.