Ouroboros: Self-Referential Backdoor Attacks on Speech Enhancement via Clean Audio Triggers
2026-08-31 • Sound
SoundCryptography and Security
AI summaryⓘ
The authors studied a hidden attack method on speech enhancement systems, which improve audio quality in real-time. Unlike previous attacks needing added triggers, their method called Ouroboros uses naturally clean audio as a secret "trigger" to cause the system to misbehave during use. They tested this on various models and real recordings, showing it works reliably without hurting normal performance much. Their approach also resists some common defenses and can specifically alter content in speech.
speech enhancementbackdoor attacktrigger injectionreal-time audio processingclean audioattack success ratephysical-world validationfiltering defensesfinetuning defensescontent tampering
Authors
Yunjie Zhou, Yuheng Huang, Diqun Yan
Abstract
Speech enhancement models are widely deployed as frontend modules in real-time speech services, yet their vulnerability to backdoor attacks remains unexplored. Existing backdoor methods are confined to classification tasks and rely on active trigger injection, an assumption incompatible with the passive processing nature of speech enhancement models. In this paper, we propose Ouroboros, a novel backdoor attack framework that leverages the ideal clean outputs of speech enhancement models as natural triggers, enabling inference-time activation without any external trigger injection. Extensive evaluations show Ouroboros achieves near-perfect attack success rates with minimal performance degradation on diverse models and datasets. Physical-world validations confirm that naturally recorded, unaltered clean audio can reliably activate the backdoor. Moreover, Ouroboros generalizes to targeted content-tampering attacks and remains effective against common filtering and finetuning defenses.