Ouroboros: Self-Referential Backdoor Attacks on Speech Enhancement via Clean Audio Triggers

📅 2026-08-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出Ouroboros框架,利用语音增强模型的理想纯净输出作为自然触发器,在不注入外部触发器的情况下实现后门攻击,适用于多种模型和数据集。
📝 Abstract
Speech enhancement models are widely deployed as frontend modules in real-time speech services, yet their vulnerability to backdoor attacks remains unexplored. Existing backdoor methods are confined to classification tasks and rely on active trigger injection, an assumption incompatible with the passive processing nature of speech enhancement models. In this paper, we propose Ouroboros, a novel backdoor attack framework that leverages the ideal clean outputs of speech enhancement models as natural triggers, enabling inference-time activation without any external trigger injection. Extensive evaluations show Ouroboros achieves near-perfect attack success rates with minimal performance degradation on diverse models and datasets. Physical-world validations confirm that naturally recorded, unaltered clean audio can reliably activate the backdoor. Moreover, Ouroboros generalizes to targeted content-tampering attacks and remains effective against common filtering and finetuning defenses.
Problem

Research questions and friction points this paper is trying to address.

Speech Enhancement
Backdoor Attacks
Clean Audio Triggers
Innovation

Methods, ideas, or system contributions that make the work stand out.

self-referential backdoor
clean audio triggers
speech enhancement models
inference-time activation
targeted content-tampering