INOR—An Intelligent noise reduction method to defend against adversarial audio examples

Journal Article (Journal Article)

Recently, Automatic Speech Recognition(ASR) systems are seriously threatened by adversarial audio examples. The defense against adversarial audio examples has become an urgent issue. Different from adversarial image examples whose target is limited in the finite categories, the target of adversarial audio examples can be any combination of the words in a language. Adversarial audio examples aim to change the semantic of the audio. The semantic is explicitly represented in transcription distance, which affects the adversarial perturbation. This paper analyzes the relationship between semantic difference and adversarial perturbation. Quantization and local smoothing are calibrated to evaluate their performance. We observe that, for adversarial audio examples with different transcription distance levels, the capability of different denoising strategies varies. Therefore, we first introduce the wavelet filter, which denoises the signal in the transformed domain. Then we explore the defense capability of combined filters. Finally, a new intelligent noise reduction method–INOR is proposed to improve the denoising performance of audios under different levels of transcription distance. Experimental results show that INOR is effective in mitigating the adversarial perturbations for adversarial examples with different transcription distance levels. The average CER and WER is reduced by 33% and 55%.

Full Text

Duke Authors

Cited Authors

  • Guo, Q; Ye, J; Chen, Y; Hu, Y; Lan, Y; Zhang, G; Li, X

Published Date

  • August 11, 2020

Published In

Volume / Issue

  • 401 /

Start / End Page

  • 160 - 172

Electronic International Standard Serial Number (EISSN)

  • 1872-8286

International Standard Serial Number (ISSN)

  • 0925-2312

Digital Object Identifier (DOI)

  • 10.1016/j.neucom.2020.02.110

Citation Source

  • Scopus