Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time
Xinfeng Li, Chen Yan, Xuancun Lu, Zihan Zeng, Xiaoyu Ji, Wenyuan Xu
Abstract
Automatic speech recognition (ASR) systems have been shown to be vulnerable to adversarial examples (AEs). Recent success all assumes that users will not notice or disrupt the attack process despite the existence of music/noise-like sounds and spontaneous responses from voice assistants. Nonetheless, in practical user-present scenarios, user awareness may nullify existing attack attempts that launch unexpected sounds or ASR usage. In this paper, we seek to bridge the gap in existing research and extend the attack to user-present scenarios. We propose VRIFLE, an inaudible adversarial perturbation (IAP) attack via ultrasound delivery that can manipulate ASRs as a user speaks. The inherent differences between audible sounds and ultrasounds make IAP delivery face unprecedented challenges such as distortion, noise, and instability. In this regard, we design a novel ultrasonic transformation model to enhance the crafted perturbation to be physically effective and even survive long-distance delivery. We further enable VRIFLE’s robustness by adopting a series of augmentation on user and real-world variations during the generation process. In this way, VRIFLE features an effective real-time manipulation of the ASR output from different distances and under any speech of users, with an alter-and-mute strategy that suppresses the impact of user disruption. Our extensive experiments in both digital and physical worlds verify VRIFLE’s effectiveness under various configurations, robustness against six kinds of defenses, and universality in a targeted manner. We also show that VRIFLE can be delivered with a portable attack device and even everyday-life loudspeakers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 077bf08b-3938-4c13-8153-40a7d4073ebdCited by top-tier papers8
- Sirens' Whisper: Inaudible Near-Ultrasonic Jailbreaks of Speech-Driven LLMsZijian Ling, Pingyi Hu, Xiuyong Gao, Xiaojing Ma et al.USENIX Security 2026 · 185 citations
- AudioTrust: Benchmarking The Multifaceted Trustworthiness of Audio Large Language ModelsKai Li, Can Shen, Yile Liu, Jirui Han et al.ICLR 2026 · 17 citations
- SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band VulnerabilitiesShilin Xiao, Wenjun Zhu, Yan Jiang, Kai Wang et al.NDSS 2026 · 3 citations
- MetaGuardian: Enhancing Voice Assistant Security through Advanced Acoustic MetamaterialsZhiyuan Ning, Zheng Wang, Zhanyong TangMobiCom 2025 · 1 citation
- Phantom Menace: Exploring and Enhancing the Robustness of VLA Models Against Physical Sensor AttacksXuancun Lu, Jiaxiang Chen, Shilin Xiao, Zizhi Jin et al.AAAI 2026
Builds on17
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang et al.USENIX Security 2016 · 672 citations
- CommanderSong: A Systematic Approach for Practical Adversarial Voice RecognitionXuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long et al.USENIX Security 2018 · 389 citations
- Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic HidingLea Schönherr, Katharina Kohls, Steffen Zeiler, Thorsten Holz et al.NDSS 2019 · 315 citations
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du et al.S&P 2021 · 239 citations
Related papers
- Hearing Without Noticing? Attention-Aware Stealthy Black-Box Adversarial Audio AttacksTianyi Xu, Cheng'an Wei, Yue Zhao, Kai ChenICML 2026
- LaserAdv: Laser Adversarial Attacks on Speech Recognition SystemsGuoming Zhang, Xiaohui Ma, Huiting Zhang, Zhijie Xiang et al.USENIX Security 2024 · 6 citations
- Whispering Under the Eaves: Protecting User Privacy Against Commercial and LLM-powered Automatic Speech Recognition SystemsWeifei Jin, Yuxin Cao, Junjie Su, Derui Wang et al.USENIX Security 2025
- EvilHarmony: Stealthy Adversarial Attacks Against Black-Box Speech Recognition SystemsXuejing Yuan, Jiangshan Zhang, Feng Guo, Kai Chen et al.S&P 2025
- Echo: Reverberation-based Fast Black-Box Adversarial Attacks on Intelligent Audio SystemsMeng Xue, Kuang Peng, Xueluan Gong, Qian Zhang et al.UbiComp 2023 · 2 citations
