Search papers, labs, and topics across Lattice.
This paper introduces Ouroboros, a novel framework for backdoor attacks on speech enhancement models that utilizes clean audio outputs as natural triggers, circumventing the limitations of existing methods that require active trigger injection. The research reveals that this approach can achieve near-perfect attack success rates while maintaining minimal performance degradation across various models and datasets. Additionally, the framework demonstrates resilience against common defenses and extends to targeted content-tampering attacks, highlighting a significant security vulnerability in widely-used speech enhancement systems.
Clean audio can be weaponized as a backdoor trigger in speech enhancement models, achieving near-perfect attack success without altering the input.
Speech enhancement models are widely deployed as frontend modules in real-time speech services, yet their vulnerability to backdoor attacks remains unexplored. Existing backdoor methods are confined to classification tasks and rely on active trigger injection, an assumption incompatible with the passive processing nature of speech enhancement models. In this paper, we propose Ouroboros, a novel backdoor attack framework that leverages the ideal clean outputs of speech enhancement models as natural triggers, enabling inference-time activation without any external trigger injection. Extensive evaluations show Ouroboros achieves near-perfect attack success rates with minimal performance degradation on diverse models and datasets. Physical-world validations confirm that naturally recorded, unaltered clean audio can reliably activate the backdoor. Moreover, Ouroboros generalizes to targeted content-tampering attacks and remains effective against common filtering and finetuning defenses.