A method and apparatus for defending adversarial attacks that may be present in one or more signals is described. Each signal comprises a plurality of portions, and a portion is removed from each signal selected at random from the plurality of portions . The portion removed from each signal is replaced with a replacement portion generated from each signal with the portion removed therefrom. Two or more signals may be aligned prior to being combined into an output signal for processing by a machine learning system.
展开▼