arXiv:2608.09158cs.SDcs.AI2026-08

低频噪音可让语音模型失效,且人耳听不见。

From Inaudible Inputs to Model Failures: Low-Frequency Safety Risks in LALMs

论文配图:From Inaudible Inputs to Model Failures: Low-Frequency Safety Risks in LALMs
图 1 · 摘自论文原文
  • 用不可听见的低频波干扰模型,模拟攻击
  • 使模型准确率下降最多67个百分点,人耳几乎察觉不到
  • 提出检测机制,能恢复被干扰的语音理解能力

大型音频-语言模型(LALMs)在处理多种音频输入方面表现出强大能力,其中包括人耳无法感知的低频信号。这些信号虽不可闻,却可能进入模型并影响其输出。然而,此类低频输入对LALMs的实际影响仍不明确。本文提出一种名为间歇性低频锁闭(ILL)的不可听见红队测试方法,在黑盒环境下使用通用波形模板评估该风险。ILL通过句级注意力尺度估计确定激活时段,并利用频率混淆转移技术,从语料库谱变中构建具有连续相位的低频波形。为缓解此风险,我们提出分布重查询防护(DRG),用于检测低频分布偏移,并在必要时请求二次录音以实现语义恢复。在六个LALMs和多个音频理解任务中,ILL使准确率最高下降67个百分点,人类可听度平均仅为1.33(接近干净音频的1.17);经重新获取后,受攻击模型的平均准确率从28.5%提升至46.1%。研究揭示了LALMs中一个此前被忽视的安全隐患,并为未来鲁棒音频理解研究奠定了基础。

原文摘要 · Abstract (English)

Large audio-language models (LALMs) have demonstrated strong capabilities in understanding diverse audio inputs. This diversity includes low-frequency signals that are inaudible to humans but can still enter the model and influence its generation. However, the practical impact of such low-frequency inputs on LALMs remains largely unexplored. In this paper, we propose Intermittent Low-Frequency Lockout (ILL), an inaudible red teaming method that evaluates this risk using a universal waveform template in a black box setting. ILL uses Sentence Attention Scale Estimation to determine active intervals and Frequency Confusion Transfer to construct a low-frequency waveform with continuous phase from corpus spectral variation. To mitigate this risk, we propose Distributional Requery Guard (DRG) to detect low-frequency distribution shifts and conditionally request a second recording for semantic recovery. Across six LALMs and multiple audio understanding tasks, ILL reduces accuracy by up to 67 percentage points while receiving a mean human audibility rating of 1.33, close to 1.17 for clean audio; DRG raises mean attacked accuracy from 28.5\% to 46.1\% after clean reacquisition. These findings identify a previously overlooked safety risk for LALMs and provide a foundation for future research on robust audio understanding.

音频安全模型攻击低频干扰

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。