JOURNAL ARTICLE

Stealthy Backdoor Attack Against Speaker Recognition Using Phase-Injection Hidden Trigger

Zhe YeDiqun YanLi DongJiacheng DengShui Yu

Year: 2023 Journal:   IEEE Signal Processing Letters Vol: 30 Pages: 1057-1061   Publisher: Institute of Electrical and Electronics Engineers

Abstract

Deep learning has achieved significant breakthroughs in speaker recognition, driven by continual advancements in foundation models. However, malicious third-party platforms have introduced a severe security concern through backdoor attacks, in which attackers can manipulate a model to output a specific label by implanting a trigger. Existing speech backdoor attack methods typically utilize fixed and unnoticeable perturbations as triggers, but these may still be audible and thus detected during training and inference stages. To overcome this limitation, we propose a novel backdoor attack paradigm (PhaseBack) injecting triggers in the phase spectrum. PhaseBack exhibits sufficient stealth by leveraging the fact that the human ear is insensitive to phase information. Besides, injecting partial perturbations in the frequency domain results in global perturbations throughout the time domain, making the attack more effective. Extensive experiments on the Voxceleb1 dataset demonstrate the effectiveness and stealthiness of PhaseBack. Moreover, it has strong resistance to bypass several defense methods.

Keywords:
Backdoor Computer science Inference Computer security Frequency domain Speech recognition Artificial intelligence Computer vision

Metrics

12
Cited By
3.07
FWCI (Field Weighted Citation Impact)
29
Refs
0.90
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Speech Recognition and Synthesis
Physical Sciences →  Computer Science →  Artificial Intelligence
Digital Media Forensic Detection
Physical Sciences →  Computer Science →  Computer Vision and Pattern Recognition
Speech and Audio Processing
Physical Sciences →  Computer Science →  Signal Processing
© 2026 ScienceGate Book Chapters — All rights reserved.