Gradient Norm-based Fine-Tuning for Backdoor Defense in Automatic Speech Recognition

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zhou, Nanjun, Lin, Weilin, Liu, Li
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866929695663063040
author Zhou, Nanjun
Lin, Weilin
Liu, Li
author_facet Zhou, Nanjun
Lin, Weilin
Liu, Li
contents Backdoor attacks have posed a significant threat to the security of deep neural networks (DNNs). Despite considerable strides in developing defenses against backdoor attacks in the visual domain, the specialized defenses for the audio domain remain empty. Furthermore, the defenses adapted from the visual to audio domain demonstrate limited effectiveness. To fill this gap, we propose Gradient Norm-based FineTuning (GN-FT), a novel defense strategy against the attacks in the audio domain, based on the observation from the corresponding backdoored models. Specifically, we first empirically find that the backdoored neurons exhibit greater gradient values compared to other neurons, while clean neurons stay the lowest. On this basis, we fine-tune the backdoored model by incorporating the gradient norm regularization, aiming to weaken and reduce the backdoored neurons. We further approximate the loss computation for lower implementation costs. Extensive experiments on two speech recognition datasets across five models demonstrate the superior performance of our proposed method. To the best of our knowledge, this work is the first specialized and effective defense against backdoor attacks in the audio domain.
format Preprint
id arxiv_https___arxiv_org_abs_2502_01152
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Gradient Norm-based Fine-Tuning for Backdoor Defense in Automatic Speech Recognition
Zhou, Nanjun
Lin, Weilin
Liu, Li
Sound
Machine Learning
Audio and Speech Processing
Backdoor attacks have posed a significant threat to the security of deep neural networks (DNNs). Despite considerable strides in developing defenses against backdoor attacks in the visual domain, the specialized defenses for the audio domain remain empty. Furthermore, the defenses adapted from the visual to audio domain demonstrate limited effectiveness. To fill this gap, we propose Gradient Norm-based FineTuning (GN-FT), a novel defense strategy against the attacks in the audio domain, based on the observation from the corresponding backdoored models. Specifically, we first empirically find that the backdoored neurons exhibit greater gradient values compared to other neurons, while clean neurons stay the lowest. On this basis, we fine-tune the backdoored model by incorporating the gradient norm regularization, aiming to weaken and reduce the backdoored neurons. We further approximate the loss computation for lower implementation costs. Extensive experiments on two speech recognition datasets across five models demonstrate the superior performance of our proposed method. To the best of our knowledge, this work is the first specialized and effective defense against backdoor attacks in the audio domain.
title Gradient Norm-based Fine-Tuning for Backdoor Defense in Automatic Speech Recognition
topic Sound
Machine Learning
Audio and Speech Processing
url https://arxiv.org/abs/2502.01152