Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Raphaël Olivier

dblp:263/3668 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
7since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 4 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Security and privacy of machine learning · 100%
Artificial intelligence
2 papers
Trustworthy machine learning · 82% Speech recognition and synthesis · 18%
Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.712023
How Many Perturbations Break This Model? Evaluating Robustness Beyond Adversarial Accuracy · ICML 2023
Security and privacy of machine learning
adversarial robustness
0.512021
Sequential Randomized Smoothing for Adversarially Robust Speech Recognition · EMNLP (1) 2021
Security and privacy of machine learning › adversarial robustness › certified robustness
randomized smoothing
0.512021
Sequential Randomized Smoothing for Adversarially Robust Speech Recognition · EMNLP (1) 2021
Program synthesis and code generation
neural program synthesis
0.312018
Retrieval-Based Neural Code Generation · EMNLP 2018
Program synthesis and code generation › code generation with language models
retrieval-augmented code generation
0.312018
Retrieval-Based Neural Code Generation · EMNLP 2018
Natural language and speech › Speech recognition and synthesis
automatic speech recognition
0.112021
Sequential Randomized Smoothing for Adversarially Robust Speech Recognition · EMNLP (1) 2021

Methods — techniques the papers use, named apart from their topics

speech enhancement · 1.0randomized smoothing · 1.0adaptive attack · 1.0ROVER voting · 1.0data augmentation · 0.7adversarial attack · 0.7subtree retrieval · 0.3neural encoder-decoder · 0.3dynamic-programming sentence similarity · 0.3
YearPublicationVenuePosition
2026 Exploring features for membership inference in ASR model auditing
Francisco Teixeira, Karla Pizzi, Raphaël Olivier, Alberto Abad, Bhiksha Raj, Isabel Trancoso
Comput. Speech Lang.3
2023 How Many Perturbations Break This Model? Evaluating Robustness Beyond Adversarial Accuracy
abstract
Robustness to adversarial attacks is typically evaluated with adversarial accuracy. While essential, this metric does not capture all aspects of robustness and in particular leaves out the question of how many perturbations can be found for each point. In this work, we introduce an alternative approach, adversarial sparsity, which quantifies how difficult it is to find a successful perturbation given both an input point and a constraint on the direction of the perturbation. We show that sparsity provides valuable insight into neural networks in multiple ways: for instance, it illustrates important differences between current state-of-the-art robust models them that accuracy analysis does not, and suggests approaches for improving their robustness. When applying broken defenses effective against weak attacks but not strong ones, sparsity can discriminate between the totally ineffective and the partially effective defenses. Finally, with sparsity we can measure increases in robustness that do not affect accuracy: we show for example that data augmentation can by itself increase adversarial robustness, without using adversarial training.
Raphaël Olivier, Bhiksha Raj
ICML1
2023 There is more than one kind of robustness: Fooling Whisper with adversarial examples
Raphaël Olivier, Bhiksha Raj
INTERSPEECH1
2022 Recent improvements of ASR models in the face of adversarial attacks
abstract
Like many other tasks involving neural networks, Speech Recognition models are vulnerable to adversarial attacks.However recent research has pointed out differences between attacks and defenses on ASR models compared to image models.Improving the robustness of ASR models requires a paradigm shift from evaluating attacks on one or a few models to a systemic approach in evaluation.We lay the ground for such research by evaluating on various architectures a representative set of adversarial attacks: targeted and untargeted, optimization and speech processing-based, white-box, black-box and targeted attacks.Our results show that the relative strengths of different attack algorithms vary considerably when changing the model architecture, and that the results of some attacks are not to be blindly trusted.They also indicate that training choices such as self-supervised pretraining may significantly impact robustness by enabling transferable perturbations.We release our source code as a package that should help future research in evaluating their attacks and defenses.
Raphaël Olivier, Bhiksha Raj
INTERSPEECH1
2021 Sequential Randomized Smoothing for Adversarially Robust Speech Recognition
abstract
While Automatic Speech Recognition has been shown to be vulnerable to adversarial attacks, defenses against these attacks are still lagging.Existing, naive defenses can be partially broken with an adaptive attack.In classification tasks, the Randomized Smoothing paradigm has been shown to be effective at defending models.However, it is difficult to apply this paradigm to ASR tasks, due to their complexity and the sequential nature of their outputs.Our paper overcomes some of these challenges by leveraging speech-specific tools like enhancement and ROVER voting to design an ASR model that is robust to perturbations.We apply adaptive versions of stateof-the-art attacks, such as the Imperceptible ASR attack, to our model, and show that our strongest defense is robust to all attacks that use inaudible noise, and can only be broken with very high distortion.
Raphaël Olivier, Bhiksha Raj
EMNLP (1)1
2021 High-Frequency Adversarial Defense for Speech and Audio
abstract
Recent work suggests that adversarial examples are enabled by high-frequency components in the dataset. In the speech domain where spectrograms are used extensively, masking those components seems like a sound direction for defenses against attacks. We explore a smoothing approach based on additive noise masking in priority high frequencies. We show that this approach is much more robust than the naive noise filtering approach, and a promising research direction. We successfully apply our defense on a Librispeech speaker identification task, and on the UrbanSound8K audio classification dataset.
Raphaël Olivier, Bhiksha Raj, Muhammad A. Shah
ICASSP1
2021 Towards Adversarial Robustness Via Compact Feature Representations
abstract
Deep Neural Networks (DNNs), while providing state-of-the-art performance in a wide variety of tasks, have been shown to be vulnerable to adversarial attacks. Recent studies have posited that this vulnerability arises because DNNs operate over a grossly overspecified input space with very sparse human supervision due to which they tend to learn spurious features that humans would ignore. These spurious features provide an attack vector for the adversary because perturbing these features would not alter the human’s decision but may alter the model’s prediction. In this paper we explore hypothesis that reducing the size of the model’s feature representation while maintaining its generalizability would discard spurious features while retaining perceptually relevant ones. We find that after the size of the feature representation has been reduced the models exhibit increased adversarial robustness, while suffering only a minimal loss in accuracy. In addition to being more robust, models with compact feature representations have the benefit of being more resource efficient.
Muhammad A. Shah, Raphaël Olivier, Bhiksha Raj
ICASSP2
2020 Exploiting Non-Linear Redundancy for Neural Model Compression
abstract
Deploying deep learning models with millions, even billions, of parameters is challenging given real world memory, power and compute constraints. In an effort to make these models more practical, in this paper, we propose a novel model compression approach that exploits linear dependence between the activations in a layer to eliminate entire structural units (neurons/convolutional filters). Our approach also adjusts the weights of the layer in a manner that is provably lossless while training if the removed neuron was perfectly predictable. We combine this approach with an annealing algorithm that may be applied during training, or even on a trained model, and demonstrate, using popular datasets, that our technique can reduce the parameters of VGG and AlexNet by more than 97% on CIFAR-10, 85% on Caltech-256, and 19% on ImageNet at less than 2% loss in accuracy. Furthermore, we provide theoretical results showing that in overparametrized, locally linear (ReLU) neural networks where redundant features exist, and with correct hyperparameter selection, our method is indeed able to capture and suppress those dependencies.
Muhammad Ahmed Shah, Raphaël Olivier, Bhiksha Raj
ICPR2
2020 Optimal Strategies For Comparing Covariates To Solve Matching Problems
abstract
Many machine learning tasks can be posed as matching problems in which we are given a “probe” entry that we expect matches some of the entries in our “gallery”. The general solution to these problems is to retrieve matching entries based on statistical dependencies between the probe and the gallery data that are learned using complex models. Often, however, there are other common covariates to the probe and gallery data which might be easily inferred and may explain some of the statistical dependencies between the two. In this paper we present a probabilistic framework to derive optimal matching strategies based only on covariate features for three broad tasks, namely N-way classification, pairwise verification and ranking. We use canonical metrics to determine the maximum performance that can be expected if only covariate features are used and determine the marginal gain of using complex models. We find that covariate matching achieves an EER within 10% of a CNN in the verification task, and an MAP within 22% of the a DNN based model in the ranking task.
Muhammad A. Shah, Raphaël Olivier, Bhiksha Raj
ICPR2
2020 Transfer Learning by Learning Projections from Target to Source
abstract
Using transfer learning to help in solving a new classification task where labeled data is scarce is becoming popular. Numerous experiments with deep neural networks, where the representation learned on a source task is transferred to learn a target neural network, have shown the benefits of the approach. This paper, similarly, deals with hypothesis transfer learning. However, it presents a new approach where, instead of transferring a representation, the source hypothesis is kept and this is a translation from the target domain to the source domain that is learned. In a way, a change of representation is learned. We show how this method performs very well on a classification of time series task where the space of time series is changed between source and target.
Antoine Cornuéjols, Pierre-Alexandre Murena, Raphaël Olivier
IDA3
2018 Retrieval-Based Neural Code Generation
abstract
In models to generate program source code from natural language, representing this code in a tree structure has been a common approach.However, existing methods often fail to generate complex code correctly due to a lack of ability to memorize large and complex structures.We introduce RECODE, a method based on subtree retrieval that makes it possible to explicitly reference existing code examples within a neural code generation model.First, we retrieve sentences that are similar to input sentences using a dynamicprogramming-based sentence similarity scoring method.Next, we extract n-grams of action sequences that build the associated abstract syntax tree.Finally, we increase the probability of actions that cause the retrieved n-gram action subtree to be in the predicted code.We show that our approach improves the performance on two code generation tasks by up to +2.6 BLEU. 1
Shirley Anugrah Hayati, Raphaël Olivier, Pravalika Avvaru, Anthony Tomasic, Graham Neubig
EMNLP2