[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83608-en":3,"doc-seo-83608-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83608,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with Timbre Leakage Attack","Speech classification models are widely deployed in intelligent devices, yet hidden backdoor attacks threaten their reliability and security. This work analyzes how current speech triggers evade detection by deep neural network defenders and presents Timbre Leakage Attack (TLA). TLA injects frame-level timbre information into deep self-supervised features to form poisoned samples that remain natural to human perception. It further introduces Pmeta-TLA, a meta-learning training mechanism using multi-backdoor injection with PCGrad, improving attack efficacy, stealthiness, and robustness while reducing attack cost on keyword spotting experiments.","Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with  \nTimbre Leakage Attack  \nYueming Huanga , Wenhan Yaoa , Fen Xiaoa , Xiarun Chenb , Weiping Wenb,∗  \na Xiangtan University, Yuhu District Xiangda Road, Xiangtan, 411100, Hunan, China b Peking University, No. 5, Summer Palace Road, Haidian District, Beijing, China, Beijing, 100871, Beijing, China  \nAbstract  \nRecently, speech classification methods have gained widespread adoption in intelligent gadgets. Current study indicates that backdoor attacks provide a substantial security concern to these models, underscoring the pressing necessity to investigate additional potential attack techniques to expose and prevent such risks. This work discusses the vulnerability of current speech triggers to detection by deep neural network defenders and introduces the Timbre Leakage Attack (TLA) . The suggested trigger disseminates timbre information at the frame level within the deep self-supervised features, producing poisoned samples that appear natural to human perception. Furthermore, we introduce Pmeta-TLA, an innovative training mechanism for embedding numerous backdoorsone time. This method proposes a multi-backdoor injection training strategy using meta-learning and Projected Conflicting Gradients (PCGrad) and introduces TLA as a multi-target attack tool within it. We performed tests on data-poisoning backdoor attacks in keyword spotting tasks utilizing some deep neural network models. Experimental results indicate that the proposed strategy attains superior Attack efficacy, enhanced stealthiness, robustness, and a reduced attack cost relative to baseline methods.  \nKeywords: Backdoor Attacks, Speech Classification, Meta-Learning, PCGrad, Triggers  \n1. Introduction  \nThe speech classification task entails developing classifiers capable of differentiating speakers or commands based on their utterances, which is essential for applications including intelligent security systems, personal device recognition, and humancomputer interaction. However, the growing utilization of deep neural networks (DNNs) has afforded malicious actors the potential to perpetrate backdoor attacks against the classifiers. This threat creates an imperceptible \"hidden backdoor\" within the model [1, 2] . Attackers introduce meticulously designed poisoned samples into the training data, altering their labels to values predetermined by the attacker. Poisoned samples usually contain one or more triggers, which are typically data with the same form as the poisoned samples and are generated by attacker-designed trigger functions. Some examples of audio triggers include ultrasonic signals [3], one-hot frequency sounds [4], voice conversion triggers [5], or their combinations [6] . A common form of backdoor attack entails training the model on a poisoned dataset, known as a data-poisoning attack, which leads to the model becoming a backdoor variant. Abackdoored model generally generates accurate and anticipated labels when presented with standard input samples. However, the backdoor threat may be activated without the user’s knowledge, resulting in the model producing an incorrect label predetermined by the attacker when it processes an input sample containing a \"trigger.\" Typically, attackers aim to satisfy the following three characteristics. When numerous poisoned samples  \n∗ Corresponding author  \nare undetectable by humans or models, the backdoor attack is characterized as stealthy. A backdoor attack is effective when a backdoored model consistently misclassifies nearly all poisoned samples of the testing set. A backdoor attack is considered robust when the backdoor model continues to be effective despite the application of backdoor defense techniques.  \nInvestigating backdoor attacks effectively exposes model vulnerabilities, supporting the enhancement of security mechanisms. While most backdoor attacks for speech classifiers are effective, we conclude that they are not sufficiently","cbCainwAkHI99CN0","https://ap.wps.com/l/cbCainwAkHI99CN0","pdf",2300342,4,1,15,"English","en",105,"# Introduction\n## Speech classification and backdoor threats\n## Attack characteristics: stealthiness, effectiveness, robustness\n## Trigger taxonomy: perturbation vs component triggers\n## Existing trigger methods and limitations\n# Timbre Leakage Attack (TLA)\n# Pmeta-TLA: meta-learning multi-backdoor injection with PCGrad\n# Experiments and results","[{\"question\":\"What is the main security risk discussed for speech classification models?\",\"answer\":\"Backdoor attacks that implant imperceptible hidden triggers during training can cause misclassification to attacker-specified labels when triggered inputs are encountered.\"},{\"question\":\"How does Timbre Leakage Attack (TLA) create poisoned samples?\",\"answer\":\"TLA disseminates timbre information at the frame level within deep self-supervised features, producing poisoned samples that look natural to human perception.\"},{\"question\":\"What does Pmeta-TLA add beyond TLA?\",\"answer\":\"Pmeta-TLA introduces a meta-learning training mechanism for embedding many backdoors, using a multi-backdoor injection strategy with Projected Conflicting Gradients (PCGrad) and treating TLA as a multi-target attack tool.\"}]",1784189233,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"pmeta-tla-backdoor-attacks-for-speech-classification-models-via-meta-learning-with-timbre-leakage-attack","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/pmeta-tla-backdoor-attacks-for-speech-classification-models-via-meta-learning-with-timbre-leakage-attack/83608/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the main security risk discussed for speech classification models?","Question",{"text":75,"@type":76},"Backdoor attacks that implant imperceptible hidden triggers during training can cause misclassification to attacker-specified labels when triggered inputs are encountered.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Timbre Leakage Attack (TLA) create poisoned samples?",{"text":80,"@type":76},"TLA disseminates timbre information at the frame level within deep self-supervised features, producing poisoned samples that look natural to human perception.",{"name":82,"@type":73,"acceptedAnswer":83},"What does Pmeta-TLA add beyond TLA?",{"text":84,"@type":76},"Pmeta-TLA introduces a meta-learning training mechanism for embedding many backdoors, using a multi-backdoor injection strategy with Projected Conflicting Gradients (PCGrad) and treating TLA as a multi-target attack tool.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]