Research Article

Black-Box Adversarial Attacks against Audio Forensics Models

Table 5

Score-only black-box attack success rate on original models and reinforced models.

Victim modelsOriginal modelsReinforced models

ResNet991
SEnet10028
AFnet980
CNN-GRU9736
Average98.516.25

The bold values are the best results from our proposed method.