cs.LGOct 6, 2026

Breaking Adversarial Transferability in Fine-Tuned Speech Recognition

Authors: Mojtaba Nafez, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban

Organizations: Department of Computer Engineering Sharif University of Technology · Department of Computer Engineering University of Isfahan

Abstract

Many organizations fine-tune publicly available pretrained Automatic Speech Recognition (ASR) models and deploy them in black-box settings, assuming limited access provides protection. We show this assumption is fragile: adversarial perturbations crafted on the public base model transfer effectively to fine-tuned target models, severely degrading performance and posing concerns for safety-critical applications. We propose TransferBreaker, a unified fine-tuning framework that suppresses adversarial transfer by integrating Base Adversarial Fine-Tuning, which restricts adversarial training to base-effective perturbations; Latent Jacobian Regularization, which enforces latent-space invariance by suppressing adversarially sensitive directions; and HybridGrad-AFT, which improves robustness against adaptive attacks by interpolating transferable perturbations from base and target gradients. We theoretically justify all components and evaluate TransferBreaker across three languages and four large ASR models, reducing adversarial WER from 92.6 to 27.8. Our code is publicly available at https://github.com/rohban-lab/TransferBreaker.

Figures & tables

Appendix figures & tables20 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Beyond Waveform Robustness: Robust Feature-Vocoder Adversarial Attacks on Automatic Speech Recognition

    Jun 4, 2026Yifan Liao, Zongmin Zhang, Zhen Sun +3End-To-End Automatic Speech Recognition ModelsAutomatic Speech Recognition

  2. Transferable Adversarial Robustness for Speech Foundation Models via Hierarchical Stabilization

    Oct 4, 2026Aref Mousavi, Shahab Sherafat, Kiarash Kiani Feriz +4

  3. What Was That Again? Certified Robustness for Automatic Speech Recognition

    Jun 26, 2026Andrew C. Cullen, Neil G. Marchant, Jiani Xie +2Automatic Speech RecognitionAcoustic