跳到正文
arXiv:cs.LG· Zebin Yun, Eyal Ronen, Mahmood Sharif·· 4 小时前AI 评分50

声学基础模型后门攻击 FAB:物理可实现触发器可跨任务触发

Backdooring Acoustic Foundation Models for Physically Realizable Triggers

AI 导读

研究者提出针对声学基础模型(AFM)的后门攻击 FAB,在仅需极少假设(如无法访问预训练数据)的前提下,能让模型保持正常性能的同时植入可存活于微调的后门。FAB 使用任务无关、物理可实现、不易察觉且无需同步的触发器(如背景警笛),在两种主流 AFM、九项下游任务和四种触发器上验证有效,并可绕过现有防御、跨越数字与物理域。该研究已被 RAID 2026 接收。

正文

View PDF HTML (experimental)

Abstract:Acoustic foundation models (AFMs) have democratized acoustic applications, enabling powerful models for tasks ranging from speech recognition to speaker verification with minimal resources. However, the security of applications based on AFMs remains largely underexplored. Our work addresses this gap by proposing the Foundation Acoustic model Backdoor (FAB) attack, demonstrating that state-of-the-art AFMs are susceptible to backdooring under practical settings. Despite making minimal assumptions about adversary capabilities (e.g., no access to pre-training data), we show that FAB preserves benign performance while inducing backdoors that survive fine-tuning and cause significant degradation across diverse downstream tasks when activated. Notably, FAB utilizes task-agnostic, physically realizable, inconspicuous, and sync-free triggers (e.g., a background siren). We evaluate FAB using two leading AFMs, nine downstream tasks, and four different triggers. We further demonstrate its effectiveness against established defenses and across both digital and physical domains. While extensive end-to-end fine-tuning can mitigate FAB, such a defense is resource-intensive and task-specific. Our work highlights critical risks to AFMs and calls for advanced defenses.
Comments: Accepted at RAID 2026
Subjects: Sound (cs.SD); Machine Learning (cs.LG)
Cite as: arXiv:2610.09819 [cs.SD]
  (or arXiv:2610.09819v1 [cs.SD] for this version)
  https://doi.org/10.48550/arXiv.2610.09819

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Zebin Yun [view email]
[v1] Wed, 7 Oct 2026 10:41:54 UTC (1,139 KB)

来源:arXiv:cs.LG · arxiv.org