arXiv · 2103.14717
Cyclic Defense GAN Against Speech Adversarial Attacks
Abstract
This paper proposes a new defense approach for counteracting state-of-the-art white and black-box adversarial attack algorithms. Our approach fits into the implicit reactive defense algorithm category since it does not directly manipulate the potentially malicious input signals. Instead, it reconstructs a similar signal with a synthesized spectrogram using a cyclic generative adversarial network. This cyclic framework helps to yield a stable generative model. Finally, we feed the reconstructed signal into the speech-to-text model for transcription. The conducted experiments on targeted and non-targeted adversarial attacks developed for attacking DeepSpeech, Kaldi, and Lingvo models demonstrate the proposed defense's effectiveness in adverse scenarios.
Explore related subjects
Keep this discovery
Mohammad Esmaeilpour, Patrick Cardinal, Alessandro Lameiras Koerich. 2021-03-26. Cyclic Defense GAN Against Speech Adversarial Attacks. https://doi.org/10.1109/lsp.2021.3106239
Cite the original work for its findings. Save a collection to share your selection of sources.