arXiv:2506.08346cs.SDcs.AI2025-06中稿 · IJCNN 2025

用语音大模型生成多样触发器,实现更隐蔽的语音分类攻击

SPBA: Utilizing Speech Large Language Model for Backdoor Attacks on Speech Classification Models

  • 利用语音大模型生成音色、情绪等多样化触发信号
  • 在两个语音任务上实现高成功率,攻击指标显著优于传统方法
  • 适合研究语音安全与对抗攻击的学者参考

深度语音分类任务(如关键词识别和说话人验证)在人机交互中至关重要。近期研究发现这些技术易受后门攻击。攻击者通常使用噪声扰动或语音元素作为触发器,生成中毒语音样本,使模型产生漏洞。但传统方法受限于触发器函数,只能生成有限数量的后门。本文提出,可聚焦音色、情绪等语音元素,借助语音大语言模型(SLLM)生成多样化的触发器。然而,增加触发器数量会显著提高中毒率,导致攻击成本上升、单个触发器成功率下降。为此,我们引入多梯度下降算法(MGDA)作为缓解策略,提出语音提示后门攻击(SPBA)。实验在两个语音分类任务上验证了该方法的有效性,结果表明SPBA具有出色的触发效果和攻击性能。

原文摘要 · Abstract (English)

Deep speech classification tasks, including keyword spotting and speaker verification, are vital in speech-based human-computer interaction. Recently, the security of these technologies has been revealed to be susceptible to backdoor attacks. Specifically, attackers use noisy disruption triggers and speech element triggers to produce poisoned speech samples that train models to become vulnerable. However, these methods typically create only a limited number of backdoors due to the inherent constraints of the trigger function. In this paper, we propose that speech backdoor attacks can strategically focus on speech elements such as timbre and emotion, leveraging the Speech Large Language Model (SLLM) to generate diverse triggers. Increasing the number of triggers may disproportionately elevate the poisoning rate, resulting in higher attack costs and a lower success rate per trigger. We introduce the Multiple Gradient Descent Algorithm (MGDA) as a mitigation strategy to address this challenge. The proposed attack is called the Speech Prompt Backdoor Attack (SPBA). Building on this foundation, we conducted attack experiments on two speech classification tasks, demonstrating that SPBA shows significant trigger effectiveness and achieves exceptional performance in attack metrics.

语音安全后门攻击大模型应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。