Pith. sign in

REVIEW 3 cited by

Muting Whisper: A Universal Acoustic Adversarial Attack on Speech Foundation Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2405.06134 v2 pith:NUAP4CXH submitted 2024-05-09 cs.CL cs.SDeess.AS

classification cs.CLcs.SDeess.AS
keywords speechadversarialwhispermodeluniversalattackattacksmodels
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Recent developments in large speech foundation models like Whisper have led to their widespread use in many automatic speech recognition (ASR) applications. These systems incorporate `special tokens' in their vocabulary, such as $\texttt{<|endoftext|>}$, to guide their language generation process. However, we demonstrate that these tokens can be exploited by adversarial attacks to manipulate the model's behavior. We propose a simple yet effective method to learn a universal acoustic realization of Whisper's $\texttt{<|endoftext|>}$ token, which, when prepended to any speech signal, encourages the model to ignore the speech and only transcribe the special token, effectively `muting' the model. Our experiments demonstrate that the same, universal 0.64-second adversarial audio segment can successfully mute a target Whisper ASR model for over 97\% of speech samples. Moreover, we find that this universal adversarial audio segment often transfers to new datasets and tasks. Overall this work demonstrates the vulnerability of Whisper models to `muting' adversarial attacks, where such attacks can pose both risks and potential benefits in real-world settings: for example the attack can be used to bypass speech moderation systems, or conversely the attack can also be used to protect private speech data.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Generative Testing of Automated Speech Recognition Systems

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Phoneme-level latent interpolation in a TTS model yields ~98% black-box ASR failures with higher naturalness than waveform attacks and quality competitive with white-box PGD.

  2. Universal Acoustic Adversarial Attacks for Flexible Control of Speech-LLMs

    cs.CL 2025-05 conditional novelty 6.0 of 10

    A single learned 3.2-second audio prefix can mute or redirect speech LLMs, and can be trained to selectively mute only targeted genders or languages.

  3. Whisper Smarter, not Harder: Adversarial Attack on Partial Suppression

    cs.SD 2025-07 unverdicted novelty 4.0 of 10

    Aiming for partial instead of full suppression can make adversarial audio attacks less noticeable, and low-pass filtering may defend against them.

Pith tools