Phoneme Substitution: A Novel Approach for Backdoor Attacks on Speech Recognition Systems

Bicheng Xiong, Zedong Xing, Weiping Wen · 2024

Speech recognition technology is a key component of the artificial intelligence field. As it continues to develop, security issues are becoming more and more prominent. Backdoor attacks, as a highly covert emerging attack method, can manipulate speech recognition models to output incorrect results under specific trigger conditions, thus causing serious security risks. This paper provides a comprehensive review of the development of speech recognition technology and backdoor attacks. By analyzing the limitations of existing speech backdoor attack methods and incorporating phonological principles, we propose a covert backdoor attack strategy based on phoneme substitution. Considering the human ear's lower sensitivity to consonant phonemes and the masking effect of speech in the time domain, we have developed a selection and substitution strategy for attack triggers. In this strategy, we prioritize the replacement of consonant phonemes that are located towards the end of sentences or words, thereby making the attack more subtle and effective. Experimental results show that our method not only ensures the effectiveness of the attack but also exhibits higher concealment.

Read the paper · More papers on PaperTik