Skip to main content

Table 4 Perturbation levels for different attacks (The numbers in the table are the outcome after normalization)

From: Towards the universal defense for query-based audio adversarial attacks on speech recognition system

Constraint

\(\left\| \user2{\delta } \right\|_{{\mathbf{1}}}\)

\(\left\| \user2{\delta } \right\|_{{\mathbf{2}}}\)

\(\left\| {\mathbf{\delta }} \right\|_{{\mathbf{\infty }}}\)

CS-Attack

346.85

23.62

0.24

DW-Attack

198.21

2.60

0.05

Average

272.53

13.11

0.15

IRTA-Attack

169.58

0.80

0.02

DS-Attack

63.09

0.37

0.37

Average

116.34

0.59

0.20

  1. Shows perturbation levels for different attacks. The higher the level of perturbation, the smaller the FSNR