arXiv:cs.LG· Mojtaba Nafez, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban·· 4 小时前AI 评分47
TransferBreaker:阻断微调语音识别中的对抗迁移性
Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
AI 导读
研究者提出 TransferBreaker 微调框架,用于阻断在公开预训练 ASR 模型上生成的对抗扰动向微调后目标模型的迁移。该框架整合 Base Adversarial Fine-Tuning、Latent Jacobian Regularization 与 HybridGrad-AFT 三个组件,在三种语言和四个大型 ASR 模型上将对抗 WER 从 92.6 降至 27.8,代码已公开。
正文
Abstract:Many organizations fine-tune publicly available pretrained Automatic Speech Recognition (ASR) models and deploy them in black-box settings, assuming limited access provides protection. We show this assumption is fragile: adversarial perturbations crafted on the public base model transfer effectively to fine-tuned target models, severely degrading performance and posing concerns for safety-critical applications. We propose TransferBreaker, a unified fine-tuning framework that suppresses adversarial transfer by integrating Base Adversarial Fine-Tuning, which restricts adversarial training to base-effective perturbations; Latent Jacobian Regularization, which enforces latent-space invariance by suppressing adversarially sensitive directions; and HybridGrad-AFT, which improves robustness against adaptive attacks by interpolating transferable perturbations from base and target gradients. We theoretically justify all components and evaluate TransferBreaker across three languages and four large ASR models, reducing adversarial WER from 92.6 to 27.8. Our code is publicly available at this https URL.
| Comments: | 39 pages, 5 figures |
| Subjects: | Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.09109 [cs.LG] |
| (or arXiv:2610.09109v1 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2610.09109 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Mojtaba Nafez [view email]
[v1]
Tue, 6 Oct 2026 21:01:05 UTC (1,265 KB)
来源:arXiv:cs.LG · arxiv.org