Silent Deception: Compromising Speech Processing Pipelines via Universal Adversarial Attacks on Voice Activity Detection
Zeyu Xiao, Timan Pa, Dengpan Ye · 2025
The pipelined speech system, encompassing Voice Activity Detection (VAD) and Automatic Speech Recognition (ASR), plays a crucial role in human-machine interactions within scenarios such as voice assistants. Recent studies have shown that universal adversarial perturbations (UAP) can cause ASR to generate non-sensical outputs, compromising the integrity and reliability of the entire speech processing pipeline. However, the VAD component preceding ASR has been overlooked. This paper introduces Silent Deception, a novel universal adversarial attack that effectively suppresses VAD activation. Our approach incorporates two key insights: a spectral feature preservation mechanism that helps mitigate the low SNR issue common in speech adversarial attacks, and an adaptive gradient balancing strategy that dynamically optimizes the ensemble of surrogate models. Comprehensive experiments demonstrate the effectiveness of our approach, achieving attack success rates of 87.93% and 30.85 % in white-box and black-box settings respectively. When targeting commercial ASR services with local VAD modules, our attack induces word error rates of 92.4 % and 61.23 % under white-box and black-box scenarios.