Fetching the paper…
Reading the bibliography…
We demonstrate the existence of universal adversarial perturbations, which can fool a family of audio classification architectures, for both targeted and untargeted attack scenarios.
J. Duchi, E. Hazan, and Y. Singer, “Adaptive subgradient methods for online learning and stochastic optimization,” J Mach Learning Research , vol. 12, no. Jul, pp. 2121–2159, 2011
2011
Earlier work this paper cites.
M. D. Zeiler, “Adadelta: An adaptive learning rate method,” 2012
2012
Earlier work this paper cites.
I. Sutskever, J. Martens, G. Dahl, and G. Hinton, “On the importance of initialization and momentum in deep learning,” in Intl Conf Mach Learn , 2013, pp. 1139–1147
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in 2nd Intl Conf Learn Repres , 2014
2014
Earlier work this paper cites.
A. Hannun, C. Case, J. Casper, B. Catanzaro, G. Diamos, E. Elsen, R. Prenger, S. Satheesh, S. Sengupta, A. Coates et al. , “Deep speech: Scaling up end-to-end speech recognition,” arXiv preprint 1412.5567 , 2014
2014
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” arXiv preprint 1412.6980 , 2014
2014
Earlier work this paper cites.
J. Salamon, C. Jacoby, and J. Bello, “A dataset and taxonomy for urban sound research,” in 22nd ACM Intl Conf Multim , New York, NY, USA, 2014, pp. 1041–1044
2014
Earlier work this paper cites.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: a simple way to prevent neural networks from overfitting.” J Mach Learning Research , vol. 15, no. 1, pp. 1929–1958, 2014
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples,” in Intl Conf Learn Repres , 2015
2015
Earlier work this paper cites.
Y. Hoshen, R. J. Weiss, and K. W. Wilson, “Speech acoustic modeling from raw multichannel waveforms,” in IEEE Intl Conf on Acoust Speech Signal Process , 2015, pp. 4624–4628
2015
Earlier work this paper cites.
T. N. Sainath, R. J. Weiss, A. Senior, K. W. Wilson, and O. Vinyals, “Learning the speech front-end with raw waveform CLDNNs,” in 16th Annual Conf Intl Speech Comm Assoc , 2015, pp. 1–5
2015
Earlier work this paper cites.
C. Kereliuk, B. L. Sturm, and J. Larsen, “Deep learning and music adversaries,” IEEE Trans Multim , vol. 17, no. 11, pp. 2059–2071, 2015
2015
Earlier work this paper cites.
T. N. Sainath and C. Parada, “Convolutional neural networks for small-footprint keyword spotting,” in 16th Annual Conf Intl Speech Comm Assoc , 2015, pp. 1478–1482
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in 3rd Intl Conf Learn Repres , 2015
2015
Earlier work this paper cites.
S. Ioffe and C. Szegedy, “Batch normalization: Accelerating deep network training by reducing internal covariate shift,” in 32nd Intl Conf Mach Learn , vol. 37, 2015, pp. 448–456
2015
Earlier work this paper cites.
A. van den Oord, S. Dieleman, H. Zen, K. Simonyan, O. Vinyals, A. Graves, N. Kalchbrenner, A. W. Senior, and K. Kavukcuoglu, “Wavenet: A generative model for raw audio,” in 9th ISCA Speech Synth Workshop , 2016, p. 125
2016
Earlier work this paper cites.
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou, “Hidden voice commands,” in 25th Secur Sympos , 2016, pp. 513–530
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in IEEE Conf Comp Vis Patt Recog , 2016, pp. 2574–2582
2016
Earlier work this paper cites.
I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning . MIT Press, 2016
2016
Earlier work this paper cites.
J. Lei Ba, J. R. Kiros, and G. E. Hinton, “Layer normalization,” arXiv preprint 1607.06450 , 2016
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE Symp Secur Privacy , 2017, pp. 39–57
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in IEEE Conf Comp Vis Patt Recog , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
J. Peck, J. Roels, B. Goossens, and Y. Saeys, “Lower bounds on the robustness to adversarial perturbations,” in Adv in Neural Inf Proc Syst , 2017, pp. 804–813
2017
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial examples in the physical world,” in Intl Conf on Learn Repres , 2017
2017
Cited alongside, same era.
G. Zhang, C. Yan, X. Ji, T. Zhang, T. Zhang, and W. Xu, “Dolphinattack: Inaudible voice commands,” in ACM SIGSAC Conf Comp Comm Secur , 2017, pp. 103–117
2017
Cited alongside, same era.
Y. Gong and C. Poellabauer, “Crafting adversarial examples for speech paralinguistics applications,” arXiv preprint 1711.03280 , 2017
2017
Cited alongside, same era.
J. H. Metzen, M. C. Kumar, T. Brox, and V. Fischer, “Universal adversarial perturbations against semantic image segmentation,” in IEEE Intl Conf on Comp Vis , 2017, pp. 2774–2783
2017
Cited alongside, same era.
Y. Liu, X. Chen, C. Liu, and D. Song, “Delving into transferable adversarial examples and black-box attacks,” in Intl Conf on Learn Repres , 2017
P. Warden, “Speech commands: A dataset for limited-vocabulary speech recognition,” arXiv preprint 1804.03209 , 2018
2018
Later among the works it cites.
Y. Tokozume, Y. Ushiku, and T. Harada, “Learning from between-class examples for deep sound recognition,” in 6th Intl Conf Learn Repres , 2018
2018
Later among the works it cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in Intl Conf on Learn Repres , 2018
2018
Later among the works it cites.
S. Sun, C.-F. Yeh, M. Ostendorf, M.-Y. Hwang, and L. Xie, “Training augmentation with adversarial examples for robust speech recognition,” in 19th Annual Conf Intl Speech Comm Assoc , 2018, pp. 2404–2408
2018
Later among the works it cites.
Z. Zhao, P. Zheng, S. Xu, and X. Wu, “Object detection with deep learning: A review,” IEEE Trans Neural Netw and Learn Syst , vol. 30, no. 11, pp. 3212–3232, 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2017
Cited alongside, same era.
R. Johnson, I. Miller, and J. Freund, Miller and Freund’s Probability and Statistics for Engineers, Global Edition , ser. Global Edition. Pearson Education Limited, 2017. [Online]. Available: https://books.google.ca/books?id=GoiPAQAACAAJ
2017
Cited alongside, same era.
A. L. Maas, A. Y. Hannun, and A. Y. Ng, “Rectifier nonlinearities improve neural network acoustic models,” in Proc ICML , vol. 30, no. 1, 2013, p. 3
2017
Cited alongside, same era.
M. Yuan, B. Van Durme, and J. L. Ying, “Multilingual anchoring: Interactive topic modeling and alignment across languages,” in Adv in Neural Inf Proc Syst , 2018, pp. 8653–8663
2018
Cited alongside, same era.
Z. Yang, Z. Hu, C. Dyer, E. P. Xing, and T. Berg-Kirkpatrick, “Unsupervised text style transfer using language models as discriminators,” in Adv in Neural Inf Proc Syst , 2018, pp. 7287–7298
2018
Cited alongside, same era.
Y. Jia, Y. Zhang, R. Weiss, Q. Wang, J. Shen, F. Ren, P. Nguyen, R. Pang, I. L. Moreno, Y. Wu et al. , “Transfer learning from speaker verification to multispeaker text-to-speech synthesis,” in Adv in Neural Inf Proc Syst , 2018, pp. 4480–4490
2018
Cited alongside, same era.
Y.-A. Chung, W.-H. Weng, S. Tong, and J. Glass, “Unsupervised cross-modal alignment of speech and text embedding spaces,” in Adv in Neural Inf Proc Syst , 2018, pp. 7354–7364
2018
Cited alongside, same era.
N. Akhtar and A. Mian, “Threat of adversarial attacks on deep learning in computer vision: A survey,” IEEE Access , vol. 6, pp. 14 410–14 430, 2018
2018
Cited alongside, same era.
2019
Closest in time.
K. Grosse, T. A. Trost, M. Mosbach, M. Backes, and D. Klakow, “Adversarial initialization – when your network performs the way i want,” arXiv preprint 1902.03020 , 2019
2019
Closest in time.
T. Orekondy, B. Schiele, and M. Fritz, “Knockoff nets: Stealing functionality of black-box models,” in IEEE Conf Comp Vis Patt Recog , 2019, pp. 4954–4963
2019
Closest in time.
A. Shafahi, W. R. Huang, C. Studer, S. Feizi, and T. Goldstein, “Are adversarial examples inevitable?” in Intl Conf Learn Repres , 2019
2019
Closest in time.
H. Yakura and J. Sakuma, “Robust audio adversarial example for a physical attack,” in 28th Intl J Conf Artif Intell , S. Kraus, Ed., 2019, pp. 5334–5341
2019
Closest in time.
Y. Qin, N. Carlini, G. W. Cottrell, I. J. Goodfellow, and C. Raffel, “Imperceptible, robust, and targeted adversarial examples for automatic speech recognition,” in 36th Intl Conf Mach Learn , 2019, pp. 5231–5240
2019
Closest in time.
M. Behjati, S.-M. Moosavi-Dezfooli, M. S. Baghshah, and P. Frossard, “Universal adversarial attacks on text classifiers,” in IEEE Intl Conf on Acoust Speech Signal Process , 2019, pp. 7345–7349
2019
Closest in time.
P. Neekhara, S. Hussain, P. Pandey, S. Dubnov, J. J. McAuley, and F. Koushanfar, “Universal adversarial perturbations for speech recognition systems,” in 20th Annual Conf Intl Speech Comm Assoc , 2019, pp. 481–485
2019
Closest in time.
J. Rony, L. G. Hafemann, L. S. Oliveira, I. B. Ayed, R. Sabourin, and E. Granger, “Decoupling direction and norm for efficient gradient-based L2 adversarial attacks and defenses,” in IEEE Conf Comp Vis Patt Recogn , 2019, pp. 4322–4330
2019
Closest in time.
S. Abdoli, P. Cardinal, and A. L. Koerich, “End-to-end environmental sound classification using a 1D convolutional neural network,” Expert Systems with Applic , vol. 136, pp. 252–263, 2019
2019
Closest in time.
Z. Yang, B. Li, P.-Y. Chen, and D. Song, “Characterizing audio adversarial examples using temporal dependency,” in 7th Intl Conf Learn Repres , 2019
2019
Closest in time.
V. Subramanian, E. Benetos, N. Xu, S. McDonald, and M. Sandler, “Adversarial attacks in sound event classification,” arXiv preprint 1907.02477 , 2019
2019
Closest in time.
Q. Zeng, J. Su, C. Fu, G. Kayas, L. Luo, X. Du, C. C. Tan, and J. Wu, “A multiversion programming inspired approach to detecting audio adversarial examples,” in 49th Annual IEEE/IFIP Intl Conf Depend Syst and Netw , 2019, pp. 39–51
2019
Closest in time.
M. Esmaeilpour, P. Cardinal, and A. L. Koerich, “A robust approach for securing audio classification against adversarial attacks,” IEEE Trans on Inf Forensics and Security , vol. 15, pp. 2147–2159, 2019
2019
Closest in time.
K. M. Koerich, M. Esmaeilpour, S. Abdoli, A. S. Britto Jr., and A. L. Koerich, “Cross-representation transferability of adversarial attacks: From spectrograms to audio waveforms,” in Intl J Conf on Neural Netw , 2020, pp. 1–7
2020
Closest in time.
H. Abdullah, K. Warren, V. Bindschaedler, N. Papernot, and P. Traynor, “The faults in our asrs: An overview of attacks against automatic speech recognition and speaker identification systems,” arXiv preprint 2007.06622 , 2020
2020
Closest in time.
T. Du, S. Ji, J. Li, Q. Gu, T. Wang, and R. Beyah, “Sirenattack: Generating adversarial audio for end-to-end acoustic systems,” in 15th ACM Asia Conf Comp Comm Secur , 2020, pp. 357–369
2020
Closest in time.
M. Esmaeilpour, P. Cardinal, and A. L. Koerich, “Class-conditional defense GAN against end-to-end speech attacks,” in arXiv preprint 2010.11352 , 2020, pp. 1–5
2020
Closest in time.