CRAISDJul 2

Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with Timbre Leakage Attack

arXiv:2607.017027.5
Predicted impact top 48% in CR · last 90 daysOriginality Incremental advance
AI Analysis

This work addresses the security vulnerability of speech classification models to backdoor attacks, proposing a more stealthy and efficient attack method that could help expose and prevent such risks.

The paper proposes a novel backdoor attack method for speech classification models that uses timbre leakage at the frame level to create natural-looking poisoned samples, and introduces a meta-learning-based training mechanism (Pmeta-TLA) for embedding multiple backdoors simultaneously. The method achieves superior attack efficacy, stealthiness, robustness, and lower attack cost compared to baselines in keyword spotting tasks.

Recently, speech classification methods have gained widespread adoption in intelligent gadgets. Current study indicates that backdoor attacks provide a substantial security concern to these models, underscoring the pressing necessity to investigate additional potential attack techniques to expose and prevent such risks. This work discusses the vulnerability of current speech triggers to detection by deep neural network defenders and introduces the Timbre Leakage Attack (TLA). The suggested trigger disseminates timbre information at the frame level within the deep self-supervised features, producing poisoned samples that appear natural to human perception. Furthermore, we introduce Pmeta-TLA, an innovative training mechanism for embedding numerous backdoors one time. This method proposes a multi-backdoor injection training strategy using meta-learning and Projected Conflicting Gradients (PCGrad) and introduces TLA as a multi-target attack tool within it. We performed tests on data-poisoning backdoor attacks in keyword spotting tasks utilizing some deep neural network models. Experimental results indicate that the proposed strategy attains superior Attack efficacy, enhanced stealthiness, robustness, and a reduced attack cost relative to baseline methods.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes