Abstract

We make three contributions to improve adversarial robustness of audio classifiers. First, most existing works focus on ℓ p -norm bounded adversarial perturbations. Instead, we consider signal-to-noise ratio (SNR) as a more natural measure of adversarial perturbations for audio data. We show that perturbed examples with a particular SNR can be generated using a corresponding ℓ 2 -norm perturbation, and establish the equivalence of these two metrics in assessing adversarial perturbations. This connection enables direct control of the SNR quality of perturbed examples and allows comparison using perturbations with different ℓ p -norm constraints. Second, we are among the first to introduce APGD attack for adversarial training on audio data. In our experiments, APGD adversarial training is robust to adversarial attacks without compromising clean accuracy. Last, we improve adversarial robustness by adapting CutMix to audio - cutting and mixing two audio clips together - in conjunction with adversarial training, and observe improvements in robustness on US8K.

Keywords:
Adversarial system Robustness (evolution) Computer science Bounded function Norm (philosophy) Artificial intelligence Speech recognition Audio signal Mathematics Speech coding

Metrics

0
Cited By
0.00
FWCI (Field Weighted Citation Impact)
33
Refs
0.04
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Anomaly Detection Techniques and Applications
Physical Sciences →  Computer Science →  Artificial Intelligence
Electrostatic Discharge in Electronics
Physical Sciences →  Engineering →  Electrical and Electronic Engineering

Related Documents

JOURNAL ARTICLE

Analysis of classifiers’ robustness to adversarial perturbations

Alhussein FawziOmar FawziPascal Frossard

Journal:   Machine Learning Year: 2017 Vol: 107 (3)Pages: 481-508
JOURNAL ARTICLE

Robustness of Sketched Linear Classifiers to Adversarial Attacks

Ananth MahadevanArpit MerchantYanhao WangMichael Mathioudakis

Journal:   Proceedings of the 31st ACM International Conference on Information & Knowledge Management Year: 2022 Pages: 4319-4323
JOURNAL ARTICLE

Evaluating the adversarial robustness of Arabic spam classifiers

Anwar AlajmiImtiaz AhmadAmeer Mohammed

Journal:   Neural Computing and Applications Year: 2024 Vol: 37 (6)Pages: 4323-4343
BOOK-CHAPTER

Adversarial Robustness of Medical Image Classifiers via Denoised Smoothing

Khoa D. TranLinh LyNgoc Hoang Luong

Communications in computer and information science Year: 2025 Pages: 42-56
© 2026 ScienceGate Book Chapters — All rights reserved.