arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.30329cs.SDcs.CR

Ouroboros:通过干净音频触发器对语音增强实施自指涉后门攻击

Ouroboros: Self-Referential Backdoor Attacks on Speech Enhancement via Clean Audio Triggers

Yunjie Zhou, Yuheng Huang, Diqun Yan

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出新型后门攻击框架Ouroboros,利用语音增强模型的理想干净输出作为自然触发器,实现无需外部注入的推理阶段后门激活,攻击成功率高且对常见防御有效。

中文摘要 AI 辅助

语音增强模型被广泛部署为实时语音服务的前端模块,但其对后门攻击的脆弱性仍未被探究。现有后门方法局限于分类任务,且依赖主动触发器注入,这一假设与语音增强模型的被动处理特性不兼容。本文提出Ouroboros,一种新型后门攻击框架,利用语音增强模型的理想干净输出作为自然触发器,实现推理阶段激活,无需任何外部触发器注入。大量评估表明,Ouroboros在各类模型和数据集上实现近乎完美的攻击成功率,且性能下降极小。物理世界验证证实,自然录制的未改动干净音频可可靠激活后门。此外,Ouroboros可泛化到针对性内容篡改攻击,且对常见过滤和微调防御仍有效。

英文摘要

Speech enhancement models are widely deployed as frontend modules in real-time speech services, yet their vulnerability to backdoor attacks remains unexplored. Existing backdoor methods are confined to classification tasks and rely on active trigger injection, an assumption incompatible with the passive processing nature of speech enhancement models. In this paper, we propose Ouroboros, a novel backdoor attack framework that leverages the ideal clean outputs of speech enhancement models as natural triggers, enabling inference-time activation without any external trigger injection. Extensive evaluations show Ouroboros achieves near-perfect attack success rates with minimal performance degradation on diverse models and datasets. Physical-world validations confirm that naturally recorded, unaltered clean audio can reliably activate the backdoor. Moreover, Ouroboros generalizes to targeted content-tampering attacks and remains effective against common filtering and finetuning defenses.

发表机构

  • Faculty of Electrical Engineering and Computer Science, Ningbo University(宁波大学电气工程与计算机科学学院)
  • College of Artificial Intelligence, Ningbo University of Finance and Economics(宁波财经学院人工智能学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑