eess.ASMar 10, 2026

Attack-Dependent Robustness of Neural Audio Codecs for Adversarial ASR

Authors: Jordan PrescottThanathai LertpetchpunShrikanth Narayanan

Abstract

Neural audio codecs impose a discrete bottleneck through residual vector quantization (RVQ), making them a useful class of inference-time transformations for reducing adversarial perturbations before ASR inference. We study how codec quantization depth affects defended ASR under non-adaptive, standard adaptive, and quantization-aware adaptive untargeted \ell_\infty attacks. Under non-adaptive attacks, intermediate RVQ depths yield the lowest word error rates and outperform traditional compression at comparable bitrates. However, this apparent optimum is not stable under adaptive evaluation. The standard identity-gradient adaptive baseline (BPDA+EOT) can overestimate robustness, while an implementation of an RVQ-relaxed adaptive attack (SoftVQ-PGD) substantially changes the observed depth trend and largely removes the intermediate-depth advantage. Overall, neural codecs can improve defended ASR under specific threat models. However, the relationship between robustness and RVQ depth depends on the attack used for evaluation, rather than on the codec architecture alone.

Explore similar work

CardsList
  1. Codec-Robust Attacks on Audio LLMs

    May 19, 2026Jaechul Roh, Jean-Philippe Monteuuis, Jonathan Petit +1Neural Audio CodecsLarge Audio Language Models

  2. Exploiting Neural Audio Codec Latents for Adversarial Audio Attacks

    Jun 18, 2026Sameek Bhattacharya, Bharath Krishnamurthy, Ajita RattaniNeural Audio CodecsAudio