יום חמישי, 8 באוקטובר 2026 LIVE
AI־INFO

כתבה arXiv cs.LG ·

שבירת העברה אדוורסרית בזיהוי דיבור מעודכן

Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
חוקרים הראו כי הנחה שגויה שגרסאות מעודכנות של מודלים ציבוריים לזיהוי דיבור מוגנות מפני תקיפות אדוורסריות. הם הציגו את TransferBreaker, שיטה למניעת העברה אדוורסרית.
תקציר מקורי באנגליתarXiv:2610.09109v1 Announce Type: new Abstract: Many organizations fine-tune publicly available pretrained Automatic Speech Recognition (ASR) models and deploy them in black-box settings, assuming limited access provides protection. We show this assumption is fragile: adversarial perturbations crafted on the public base model transfer effectively to fine-tuned target models, severely degrading performance and posing concerns for safety-critical applications. We propose TransferBreaker, a unified fine-tuning framework that suppresses adversarial transfer by integrating Base Adversarial Fine-Tuning, which restricts adversarial training to base-effective perturbations; Latent Jacobian Regularization, which enforces latent-space invariance by suppressing adversarially sensitive directions; and
קרא במקור המקורי