On the human evaluation of universal audio adversarial perturbations. Issue 112 (January 2022)
- Record Type:
- Journal Article
- Title:
- On the human evaluation of universal audio adversarial perturbations. Issue 112 (January 2022)
- Main Title:
- On the human evaluation of universal audio adversarial perturbations
- Authors:
- Vadillo, Jon
Santana, Roberto - Abstract:
- Abstract: Human-machine interaction is increasingly dependent on speech communication, mainly due to the remarkable performance of Machine Learning models in speech recognition tasks. However, these models can be fooled by adversarial examples, which are inputs intentionally perturbed to produce a wrong prediction without the changes being noticeable to humans. While much research has focused on developing new techniques to generate adversarial perturbations, less attention has been given to aspects that determine whether and how the perturbations are noticed by humans. This question is relevant since high fooling rates of proposed adversarial perturbation strategies are only valuable if the perturbations are not detectable. In this paper we investigate to which extent the distortion metrics proposed in the literature for audio adversarial examples, and which are commonly applied to evaluate the effectiveness of methods for generating these attacks, are a reliable measure of the human perception of the perturbations. Using an analytical framework, and an experiment in which 36 subjects evaluate audio adversarial examples according to different factors, we demonstrate that the metrics employed by convention are not a reliable measure of the perceptual similarity of adversarial examples in the audio domain.
- Is Part Of:
- Computers & security. Issue 112(2022)
- Journal:
- Computers & security
- Issue:
- Issue 112(2022)
- Issue Display:
- Volume 112, Issue 112 (2022)
- Year:
- 2022
- Volume:
- 112
- Issue:
- 112
- Issue Sort Value:
- 2022-0112-0112-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-01
- Subjects:
- Adversarial examples -- Deep neural networks -- Speech command classification -- Robust speech recognition -- Human perception
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102495 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 20063.xml