cs.SDOct 7, 2026

Backdooring Acoustic Foundation Models for Physically Realizable Triggers

Authors: Zebin Yun, Eyal Ronen, Mahmood Sharif

Organizations: Tel Aviv University, Tel Aviv, Israel

Abstract

Acoustic foundation models (AFMs) have democratized acoustic applications, enabling powerful models for tasks ranging from speech recognition to speaker verification with minimal resources. However, the security of applications based on AFMs remains largely underexplored. Our work addresses this gap by proposing the Foundation Acoustic model Backdoor (FAB) attack, demonstrating that state-of-the-art AFMs are susceptible to backdooring under practical settings. Despite making minimal assumptions about adversary capabilities (e.g., no access to pre-training data), we show that FAB preserves benign performance while inducing backdoors that survive fine-tuning and cause significant degradation across diverse downstream tasks when activated. Notably, FAB utilizes task-agnostic, physically realizable, inconspicuous, and sync-free triggers (e.g., a background siren). We evaluate FAB using two leading AFMs, nine downstream tasks, and four different triggers. We further demonstrate its effectiveness against established defenses and across both digital and physical domains. While extensive end-to-end fine-tuning can mitigate FAB, such a defense is resource-intensive and task-specific. Our work highlights critical risks to AFMs and calls for advanced defenses.

Figures & tables

Appendix figures & tables11 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Natural Backdoor Attacks on Speech Recognition Models

    Jul 17, 2026Jinwen Xin, Xixiang Lyu, Jing MaAttack-Success RateDeep Learning

  2. Ouroboros: Self-Referential Backdoor Attacks on Speech Enhancement via Clean Audio Triggers

    Aug 31, 2026Yunjie Zhou, Yuheng Huang, Diqun YanSpeech EnhancementInference-Time

  3. SpeechGuard: Online Defense against Backdoor Attacks on Speech Recognition Models

    Jul 17, 2026Jinwen Xin, Xixiang LvLLM Defense MechanismsUtterances