2019/10/26 by Mohammad Esmaeilpour, Esmaeilpour, Mohammad, Patrick Cardinal +3 · 1 citation
Computer Science · #Anomaly Detection Techniques and Applications #Adversarial Robustness in Machine Learning #Digital Media Forensic Detection
paper · pdf · doi:10.48550/arxiv.1910.12084
Adversarial attacks have always been a serious threat for any data-driven\nmodel. In this paper, we explore subspaces of adversarial examples in unitary\nvector domain, and we propose a novel detector for defending our models trained\nfor environmental sound classification. We measure chordal distance between\nlegitimate and malicious representation of sounds in unitary space of\ngeneralized Schur decomposition and show that their manifolds lie far from each\nother. Our front-end detector is a regularized logistic regression which\ndiscriminates eigenvalues of legitimate and adversarial spectrograms. The\nexperimental results on three benchmarking datasets of environmental sounds\nrepresented by spectrograms reveal high detection rate of the proposed detector\nfor eight types of adversarial attacks and outperforms other detection\napproaches.\n