← 返回论文检索
ICLR 2026PosterAccept (Poster)

Are Deep Speech Denoising Models Robust to Adversarial Noise?

Will Schwarzer, Andrea Fanelli, Philip Thomas, Xiaoyu Liu

University of Massachusetts at Amherst · Dolby Labs · College of Information and Computer Science, University of Massachusetts, Amherst · Waveforms.ai

PDF 由论文原始站点提供,PaperCompass 不保存论文文件。

摘要

Deep noise suppression (DNS) models enjoy widespread use throughout a variety of high-stakes speech applications. However, we show that four recent DNS models can each be reduced to outputting unintelligible gibberish through the addition of psychoacoustically hidden adversarial noise, even in low-background-noise and simulated over-the-air settings. For three of the models, a small transcription study with audio and multimedia experts confirms unintelligibility of the attacked audio; simultaneously, an ABX study shows that the adversarial noise is generally imperceptible, with some variance between participants and samples. While we also establish several negative results around targeted attacks and model transfer, our results nevertheless highlight the need for practical countermeasures before open-source DNS systems can be used in safety-critical applications.