用干净音频本身作触发器,实现无声无息的语音增强模型后门攻击。
Ouroboros: Self-Referential Backdoor Attacks on Speech Enhancement via Clean Audio Triggers

- 利用模型理想输出作为自然触发器,无需外部注入信号。
- 攻击成功率接近100%,且对正常性能影响极小。
- 可对抗常见防御手段,适合研究安全风险的学者使用。
语音增强模型广泛部署于实时语音服务中,但其易受后门攻击的隐患尚未被充分研究。现有后门方法局限于分类任务,依赖主动触发注入,与语音增强模型被动处理的特性不符。本文提出Ouroboros,一种新型后门攻击框架,利用语音增强模型的理想干净输出作为自然触发器,实现在推理阶段无需外部注入即可激活后门。大量实验表明,Ouroboros在多种模型和数据集上均达到近乎完美的攻击成功率,且对正常性能影响极小。物理世界验证显示,自然录制、未修改的干净音频即可稳定触发后门。此外,Ouroboros可扩展至定向内容篡改攻击,并对常见滤波与微调防御保持有效性。
原文摘要 · Abstract (English)
Speech enhancement models are widely deployed as frontend modules in real-time speech services, yet their vulnerability to backdoor attacks remains unexplored. Existing backdoor methods are confined to classification tasks and rely on active trigger injection, an assumption incompatible with the passive processing nature of speech enhancement models. In this paper, we propose Ouroboros, a novel backdoor attack framework that leverages the ideal clean outputs of speech enhancement models as natural triggers, enabling inference-time activation without any external trigger injection. Extensive evaluations show Ouroboros achieves near-perfect attack success rates with minimal performance degradation on diverse models and datasets. Physical-world validations confirm that naturally recorded, unaltered clean audio can reliably activate the backdoor. Moreover, Ouroboros generalizes to targeted content-tampering attacks and remains effective against common filtering and finetuning defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。