Opportunistic Backdoor Attacks: Exploring Human-imperceptible Vulnerabilities on Speech Recognition Systems
Qiang Liu, Tongqing Zhou, Zhiping Cai, Yonghao Tang
Abstract
Speech recognition systems, trained and updated based on large-scale audio data, are vulnerable to backdoor attacks that inject dedicated triggers in system training. The used triggers are generally human-inaudible audio, such as ultrasonic waves. However, we note that such a design is not feasible, as it can be easily filtered out via pre-processing. In this work, we propose the first audible backdoor attack paradigm for speech recognition, characterized by passively triggering and opportunistically invoking. Traditional device-synthetic triggers are replaced with ambient noise in daily scenarios. For adapting triggers to the application dynamics of speech interaction, we exploit the observed knowledge inherited from the context to a trained model and accommodate the injection and poisoning with certainty-based trigger selection, performance-oblivious sample binding, and trigger late-augmentation. Experiments on two datasets under various environments evaluate the proposal's effectiveness in maintaining a high benign rate and facilitating outstanding attack success rate (99.27%, 4% higher than BadNets), robustness (bounded infectious triggers), feasibility in real-world scenarios. It requires less than 1% data to be poisoned and is demonstrated to be able to resist typical speech enhancement techniques and general countermeasures (e.g., dedicated fine-tuning). The code and data will be made available at https://github.com/lqsunshine/DABA.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers6
- FlowMur: A Stealthy and Practical Audio Backdoor Attack with Limited KnowledgeJiahe Lan, Jie Wang, Baochen Yan, Zheng Yan et al.S&P 2024 · 23 citations
- Conditional Backdoor Attack via JPEG CompressionQiuyu Duan, Zhongyun Hua, Qing Liao, Yushu Zhang et al.AAAI 2024 · 21 citations
- Revisiting Backdoor Attacks on Time Series Classification in the Frequency DomainYuanmin Huang, Mi Zhang, Zhaoxiang Wang, Wenxuan Li et al.WWW 2025 · 5 citations
- The Silent Manipulator: A Practical and Inaudible Backdoor Attack against Speech Recognition SystemsZhicong Zheng, Xinfeng Li, Chen Yan, Xiaoyu Ji et al.ACM MM 2023 · 3 citations
- Speed Master: Quick or Slow Play to Attack Speaker RecognitionZhe Ye, Wenjie Zhang, Ying Ren, Xiangui Kang et al.AAAI 2025 · 1 citation
Related papers
- Audio-domain position-independent backdoor attack via unnoticeable triggersCong Shi, Tianfang Zhang, Zhuohang Li, Huy Phan et al.MobiCom 2022 · 54 citations
- Inaudible Backdoor Attack via Stealthy Frequency Trigger Injection in Audio SpectrogramTianfang Zhang, Huy Phan, Zijie Tang, Cong Shi et al.MobiCom 2024 · 8 citations
- Modulation-Based Backdoors: Leveraging Amplitude and Frequency Patterns to Attack Speaker RecognitionHanbo Cai, Pengcheng Zhang, Yan Xiao, De Li et al.AAAI 2026
- Hidden in the Noise: Unveiling Backdoors in Audio LLMs Alignment Through Latent Acoustic Pattern TriggersLiang Lin, Miao Yu, Kaiwen Luo, Yibo Zhang et al.AAAI 2026 · 5 citations
- BadPrompt: Backdoor Attacks on Continuous PromptsXiangrui Cai, Haidong Xu, Sihan Xu, Ying Zhang et al.NeurIPS 2022 · 103 citations
