USENIX Security2024Top-tier venue
Devil in the Room: Triggering Audio Backdoors in the Physical World
Meng Chen, Xiangyu Xu, Li Lu, Zhongjie Ba, Feng Lin, Kui Ren
Abstract
Recent years have witnessed deep learning techniques endowing modern audio systems with powerful capabilities. However, the latest studies have revealed its strong reliance on training data, raising serious threats from backdoor attacks. Different from most existing works that study audio backdoors in the digital world, we investigate the mismatch between the trigger and backdoor in the physical space by examining sound channel distortion. Inspired by this observation, this paper proposes TrojanRoom to bridge the gap between digital and physical audio backdoor attacks. Trojan-Room utilizes the room impulse response (RIR) as a physical trigger to enable injection-free backdoor activation. By synthesizing dynamic RIRs and poisoning a source class of samples during data augmentation, TrojanRoom enables any adversary to launch an effective and stealthy attack using the specific impulse response in a room. The evaluation shows over 92% and 97% attack success rates on both state-of-the-art speech command recognition and speaker recognition systems with negligible impact on benign accuracy below 3% at a distance of over 5m. The experiments also demonstrate that TrojanRoom could bypass human inspection and voice liveness detection, as well as resist trigger disruption and backdoor defense.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b19efea-0b1f-41cd-9d3b-c2c70c6c188eCited by top-tier papers2
- DeBackdoor: A Deductive Framework for Detecting Backdoor Attacks on Deep Models with Limited DataDorde Popovic, Amin Sadeghi, Ting Yu, Sanjay Chawla et al.USENIX Security 2025
- Modulation-Based Backdoors: Leveraging Amplitude and Frequency Patterns to Attack Speaker RecognitionHanbo Cai, Pengcheng Zhang, Yan Xiao, De Li et al.AAAI 2026
Builds on16
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Invisible Backdoor Attack with Sample-Specific TriggersYuezun Li, Yiming Li, Baoyuan Wu, Longkang Li et al.ICCV 2021 · 639 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
- Latent Backdoor Attacks on Deep Neural NetworksYuanshun Yao, Huiying Li, Haitao Zheng, Ben Y. ZhaoCCS 2019 · 465 citations
Related papers
- Audio-domain position-independent backdoor attack via unnoticeable triggersCong Shi, Tianfang Zhang, Zhuohang Li, Huy Phan et al.MobiCom 2022 · 54 citations
- Echo: Reverberation-based Fast Black-Box Adversarial Attacks on Intelligent Audio SystemsMeng Xue, Kuang Peng, Xueluan Gong, Qian Zhang et al.UbiComp 2023 · 2 citations
- Opportunistic Backdoor Attacks: Exploring Human-imperceptible Vulnerabilities on Speech Recognition SystemsQiang Liu, Tongqing Zhou, Zhiping Cai, Yonghao TangACM MM 2022 · 33 citations
- Inaudible Backdoor Attack via Stealthy Frequency Trigger Injection in Audio SpectrogramTianfang Zhang, Huy Phan, Zijie Tang, Cong Shi et al.MobiCom 2024 · 8 citations
- TrojanModel: A Practical Trojan Attack against Automatic Speech Recognition SystemsWei Zong, Yang-Wai Chow, Willy Susilo, Kien Do et al.S&P 2023
