发表机构
Tel Aviv University(特拉维夫大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出FAB攻击,证明声学基础模型在最小假设下易受物理可实现后门影响,该后门保持良性性能、经受微调,并在多种下游任务中造成显著性能下降,凸显了安全风险。
AI 中文摘要
声学基础模型(AFMs)使声学应用大众化,使得从语音识别到说话人验证等任务能够以最少资源使用强大模型。然而,基于AFM的应用安全性在很大程度上仍未得到充分探索。我们的工作通过提出基础声学模型后门(FAB)攻击来填补这一空白,证明最先进的AFM在实际设置下容易受到后门攻击。尽管对攻击者能力做了最小假设(例如,无法访问预训练数据),我们表明FAB在保持良性性能的同时,诱导出能够经受微调并在激活时导致多种下游任务显著性能下降的后门。值得注意的是,FAB利用任务无关、物理可实现、隐蔽且无需同步的触发器(例如,背景警笛声)。我们使用两个领先的AFM、九个下游任务和四种不同触发器评估了FAB。我们进一步证明了其在已建立的防御措施以及数字和物理领域中的有效性。虽然广泛的端到端微调可以缓解FAB,但这种防御措施资源密集且针对特定任务。我们的工作突出了AFM的关键风险,并呼吁先进的防御措施。
英文摘要
Acoustic foundation models (AFMs) have democratized acoustic applications, enabling powerful models for tasks ranging from speech recognition to speaker verification with minimal resources. However, the security of applications based on AFMs remains largely underexplored. Our work addresses this gap by proposing the Foundation Acoustic model Backdoor (FAB) attack, demonstrating that state-of-the-art AFMs are susceptible to backdooring under practical settings. Despite making minimal assumptions about adversary capabilities (e.g., no access to pre-training data), we show that FAB preserves benign performance while inducing backdoors that survive fine-tuning and cause significant degradation across diverse downstream tasks when activated. Notably, FAB utilizes task-agnostic, physically realizable, inconspicuous, and sync-free triggers (e.g., a background siren). We evaluate FAB using two leading AFMs, nine downstream tasks, and four different triggers. We further demonstrate its effectiveness against established defenses and across both digital and physical domains. While extensive end-to-end fine-tuning can mitigate FAB, such a defense is resource-intensive and task-specific. Our work highlights critical risks to AFMs and calls for advanced defenses.
CommentsAccepted at RAID 2026