arXiv · 2607.15724
Natural Backdoor Attacks on Speech Recognition Models
Abstract
With the rapid development of deep learning, its vulnerability has gradually emerged in recent years. This work focuses on backdoor attacks on speech recognition systems. We adopt sounds that are ordinary in nature or in our daily life as triggers for natural backdoor attacks. We conduct experiments on two datasets and three models to validate the performance of natural backdoor attacks and explore the effects of poisoning rate, trigger duration and blend ratio on the performance of natural backdoor attacks. Our results show that natural backdoor attacks have a high attack success rate without compromising model performance on benign samples, even with short or low-amplitude triggers. It requires only 5% of poisoned samples to achieve a near 100% attack success rate. In addition, the backdoor will be automatically activated by the corresponding sound in nature, which is not easy to be detected and will bring severer harm.
Explore related subjects
Keep this discovery
Jinwen Xin, Xixiang Lyu, Jing Ma. 2026-07-17. Natural Backdoor Attacks on Speech Recognition Models. https://doi.org/10.1007/978-3-031-20096-0_45
Cite the original work for its findings. Save a collection to share your selection of sources.