Pith. sign in

REVIEW 1 cited by

Adversarial Attacks and Defenses for Speech Recognition Systems

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2103.17122 v1 pith:HTP3VQCM submitted 2021-03-31 eess.AS cs.CRcs.SD

classification eess.AScs.CRcs.SD
keywords modelsystemsadversarialattacksdefensesattackerrorfind
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The ubiquitous presence of machine learning systems in our lives necessitates research into their vulnerabilities and appropriate countermeasures. In particular, we investigate the effectiveness of adversarial attacks and defenses against automatic speech recognition (ASR) systems. We select two ASR models - a thoroughly studied DeepSpeech model and a more recent Espresso framework Transformer encoder-decoder model. We investigate two threat models: a denial-of-service scenario where fast gradient-sign method (FGSM) or weak projected gradient descent (PGD) attacks are used to degrade the model's word error rate (WER); and a targeted scenario where a more potent imperceptible attack forces the system to recognize a specific phrase. We find that the attack transferability across the investigated ASR systems is limited. To defend the model, we use two preprocessing defenses: randomized smoothing and WaveGAN-based vocoder, and find that they significantly improve the model's adversarial robustness. We show that a WaveGAN vocoder can be a useful countermeasure to adversarial attacks on ASR systems - even when it is jointly attacked with the ASR, the target phrases' word error rate is high.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. The Relationship Between Network Similarity and Transferability of Adversarial Attacks

    cs.CR 2025-01 reject novelty 4.0 of 10

    Similarity between CNN architectures does not robustly predict transferred adversarial attack success, and the reported high-accuracy decision-tree predictor likely relies on a data-splitting artifact.

Pith tools