ALIF: Low-Cost Adversarial Audio Attacks on Black-Box Speech Platforms using Linguistic Features
Peng Cheng, Yuwei Wang, Peng Huang, Zhongjie Ba, Xiaodong Lin, Feng Lin, Li Lu, Kui Ren
Abstract
Extensive research has revealed that adversarial examples (AE) pose a significant threat to voice-controllable smart devices. Recent studies have proposed black-box adversarial attacks that require only the final transcription from an automatic speech recognition (ASR) system. However, these attacks typically involve many queries to the ASR, resulting in substantial costs. Moreover, AE-based adversarial audio samples are susceptible to ASR updates. In this paper, we identify the root cause of these limitations, namely the inability to construct AE attack samples directly around the decision boundary of deep learning (DL) models. Building on this observation, we propose ALIF, the first black-box adversarial linguistic feature-based attack pipeline. We leverage the reciprocal process of text-to-speech (TTS) and ASR models to generate perturbations in the linguistic embedding space where the decision boundary resides. Based on the ALIF pipeline, we present the ALIF-OTL and ALIF-OTA schemes for launching attacks in both the digital domain and the physical playback environment on four commercial ASRs and voice assistants. Extensive evaluations demonstrate that ALIF-OTL and -OTA significantly improve query efficiency by 97.7% and 73.3%, respectively, while achieving competitive performance compared to existing methods. Notably, ALIF-OTL can generate an attack sample with only one query. Furthermore, our test-of-time experiment validates the robustness of our approach against ASR updates.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8bd000c-af68-468f-9c3b-3af2548fce12Cited by top-tier papers3
- MetaGuardian: Enhancing Voice Assistant Security through Advanced Acoustic MetamaterialsZhiyuan Ning, Zheng Wang, Zhanyong TangMobiCom 2025 · 1 citation
- Whispering Under the Eaves: Protecting User Privacy Against Commercial and LLM-powered Automatic Speech Recognition SystemsWeifei Jin, Yuxin Cao, Junjie Su, Derui Wang et al.USENIX Security 2025
- When Translators Refuse to Translate: A Novel Attack to Speech Translation SystemsHaolin Wu, Chang Liu, Jing Chen, Ruiying Du et al.USENIX Security 2025
Builds on15
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang et al.USENIX Security 2016 · 672 citations
- CommanderSong: A Systematic Approach for Practical Adversarial Voice RecognitionXuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long et al.USENIX Security 2018 · 389 citations
Related papers
- Devil's Whisper: A General Approach for Physical Adversarial Attacks against Commercial Black-box Speech Recognition DevicesYuxuan Chen, Xuejing Yuan, Jiangshan Zhang, Yue Zhao et al.USENIX Security 2020
- KENKU: Towards Efficient and Stealthy Black-box Adversarial Attacks against ASR SystemsXinghui Wu, Shiqing Ma, Chao Shen, Chenhao Lin et al.USENIX Security 2023
- Echo: Reverberation-based Fast Black-Box Adversarial Attacks on Intelligent Audio SystemsMeng Xue, Kuang Peng, Xueluan Gong, Qian Zhang et al.UbiComp 2023 · 2 citations
- Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal InformationBaolin Zheng, Peipei Jiang, Qian Wang, Qi Li et al.CCS 2021 · 73 citations
- Hearing Without Noticing? Attention-Aware Stealthy Black-Box Adversarial Audio AttacksTianyi Xu, Cheng'an Wei, Yue Zhao, Kai ChenICML 2026
