Pith. sign in

REVIEW 1 cited by

Detecting Adversarial Examples for Speech Recognition via Uncertainty Quantification

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2005.14611 v2 pith:4OXATR6W submitted 2020-05-24 eess.AS cs.CRcs.LGcs.SDstat.ML

classification eess.AScs.CRcs.LGcs.SDstat.ML
keywords uncertaintyadversarialneuralsystemsattacksquantificationrecognitionacoustic
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Machine learning systems and also, specifically, automatic speech recognition (ASR) systems are vulnerable against adversarial attacks, where an attacker maliciously changes the input. In the case of ASR systems, the most interesting cases are targeted attacks, in which an attacker aims to force the system into recognizing given target transcriptions in an arbitrary audio sample. The increasing number of sophisticated, quasi imperceptible attacks raises the question of countermeasures. In this paper, we focus on hybrid ASR systems and compare four acoustic models regarding their ability to indicate uncertainty under attack: a feed-forward neural network and three neural networks specifically designed for uncertainty quantification, namely a Bayesian neural network, Monte Carlo dropout, and a deep ensemble. We employ uncertainty measures of the acoustic model to construct a simple one-class classification model for assessing whether inputs are benign or adversarial. Based on this approach, we are able to detect adversarial examples with an area under the receiving operator curve score of more than 0.99. The neural networks for uncertainty quantification simultaneously diminish the vulnerability to the attack, which is reflected in a lower recognition accuracy of the malicious target text in comparison to a standard hybrid ASR system.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Imperio: Robust Over-the-Air Adversarial Examples for Automatic Speech Recognition Systems

    cs.CR 2019-08 conditional novelty 6.0 of 10

    Imperio generates targeted over-the-air adversarial audio for a hybrid ASR system by optimizing against many simulated room impulse responses, and achieves some 0% WER transcriptions in real rooms.

Pith tools