Precision-Varying Prediction (PVP): Robustifying ASR systems against adversarial attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Pizarro, Matías, Narasimhan, Raghavan, Fischer, Asja
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917359230386176
author Pizarro, Matías
Narasimhan, Raghavan
Fischer, Asja
author_facet Pizarro, Matías
Narasimhan, Raghavan
Fischer, Asja
contents With the increasing deployment of automated and agentic systems, ensuring the adversarial robustness of automatic speech recognition (ASR) models has become critical. We observe that changing the precision of an ASR model during inference reduces the likelihood of adversarial attacks succeeding. We take advantage of this fact to make the models more robust by simple random sampling of the precision during prediction. Moreover, the insight can be turned into an adversarial example detection strategy by comparing outputs resulting from different precisions and leveraging a simple Gaussian classifier. An experimental analysis demonstrates a significant increase in robustness and competitive detection performance for various ASR models and attack types.
format Preprint
id arxiv_https___arxiv_org_abs_2603_22590
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Precision-Varying Prediction (PVP): Robustifying ASR systems against adversarial attacks
Pizarro, Matías
Narasimhan, Raghavan
Fischer, Asja
Machine Learning
Cryptography and Security
Audio and Speech Processing
With the increasing deployment of automated and agentic systems, ensuring the adversarial robustness of automatic speech recognition (ASR) models has become critical. We observe that changing the precision of an ASR model during inference reduces the likelihood of adversarial attacks succeeding. We take advantage of this fact to make the models more robust by simple random sampling of the precision during prediction. Moreover, the insight can be turned into an adversarial example detection strategy by comparing outputs resulting from different precisions and leveraging a simple Gaussian classifier. An experimental analysis demonstrates a significant increase in robustness and competitive detection performance for various ASR models and attack types.
title Precision-Varying Prediction (PVP): Robustifying ASR systems against adversarial attacks
topic Machine Learning
Cryptography and Security
Audio and Speech Processing
url https://arxiv.org/abs/2603.22590