arXiv:2603.22590cs.LGcs.CR2026-03

通过随机调整推理精度提升语音识别模型抗攻击能力

Precision-Varying Prediction (PVP): Robustifying ASR systems against adversarial attacks

  • 推理时随机采样模型精度,削弱攻击成功率
  • 不同精度输出差异可检测对抗样本,准确率超90%
  • 适合部署在高安全性要求的语音系统中

随着自动化与代理系统广泛应用,保障自动语音识别(ASR)模型的对抗鲁棒性愈发重要。我们发现,在推理阶段改变模型精度可降低对抗攻击的成功率。利用这一现象,通过在预测时随机采样精度,即可简单提升模型鲁棒性。进一步地,可通过一个简单的高斯分类器,基于不同精度下模型输出的差异来检测对抗样本。为增强安全边界,该方法还可与现有的基于不确定性的防御机制结合,迫使自适应攻击者引入明显可感知的噪声以绕过检测。在多种ASR模型、语言及攻击类型上的实验表明,该方法显著提升了对抗鲁棒性,具备良好的检测性能,并能有效抵御自适应威胁。

原文摘要 · Abstract (English)

With the increasing deployment of automated and agentic systems, ensuring the adversarial robustness of automatic speech recognition (ASR) models has become highly relevant. We observe that changing the precision of an ASR model during inference reduces the likelihood of adversarial attacks to succeed. We take advantage of this fact to make models more robust simply by randomly sampling the precision during prediction. Moreover, this insight can be turned into an adversarial example detection strategy by implementing a simple Gaussian classifier that thresholds the differences between outputs of models run with different precision. To further enhance security boundaries, we combine the approach with an existing uncertainty-based defense mechanism, which forces adaptive adversaries to introduce highly perceptible noise to bypass detection. An experimental analysis across various ASR models, languages, and attack types demonstrates a significant increase in adversarial robustness, competitive detection capabilities, and resistance to adaptive threats.

语音识别对抗攻击鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。