FlowMur: A Stealthy and Practical Audio Backdoor Attack with Limited Knowledge
Jiahe Lan, Jie Wang, Baochen Yan, Zheng Yan, Elisa Bertino
IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 5
Overview
This presentation introduces FlowMur, a novel and highly effective audio backdoor attack designed to operate with limited knowledge of the target system. Developed through a collaboration between CID University in China and KU University in the US, FlowMur addresses significant limitations present in existing audio backdoor methodologies. The research highlights critical vulnerabilities within speech recognition systems (SRS), which are increasingly integrated into daily life and safety-critical applications, ranging from transcription services and smart devices to in-car systems.

Key moments
- 1:15 Limitations of existing audio backdoor attacks discussed
- 2:05 Introducing FlowMur: goals, properties, and adversary assumptions
- 3:30 Trigger generation as an optimization problem for stealth and effectiveness
- 4:00 Adaptive data poisoning enhances trigger imperceptibility
- 6:00 FlowMur achieves over 98% attack success rate
- 6:30 Human study confirms FlowMur's superior trigger imperceptibility
- 7:00 FlowMur effectively bypasses various backdoor defenses
FlowMur: A Stealthy and Practical Audio Backdoor Attack with Limited Knowledge
Speakers: Jiahe Lan, Jie Wang, Baochen Yan, Zheng Yan, Elisa Bertino
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=9fd7Kt8wAu0
Overview
This presentation introduces FlowMur, a novel and highly effective audio backdoor attack designed to operate with limited knowledge of the target system. Developed through a collaboration between CID University in China and KU University in the US, FlowMur addresses significant limitations present in existing audio backdoor methodologies. The research highlights critical vulnerabilities within speech recognition systems (SRS), which are increasingly integrated into daily life and safety-critical applications, ranging from transcription services and smart devices to in-car systems.
The talk underscores the importance of robust security for SRS, given their widespread adoption and the potential for malicious exploitation. FlowMur distinguishes itself by achieving exceptional attack performance while maintaining stealth and practicality, even when the adversary possesses minimal information about the target model or training data. Its development marks a significant step forward in understanding and mitigating advanced threats to audio-based AI, prompting a re-evaluation of current defense strategies.
FlowMur aims to insert hidden vulnerabilities into deep learning models that process audio. While the model appears to function normally on benign inputs, specific, imperceptible triggers embedded within audio samples cause it to misclassify them into a target class. This work is particularly relevant for the security community, offering insights into how sophisticated adversaries might compromise critical AI infrastructure and providing a foundation for developing more resilient speech recognition technologies.
Background
▶ Watch: Limitations of existing audio backdoor attacks discussed (1:15)
Speech recognition systems (SRS) have become an indispensable part of modern technology, enhancing human-computer interaction, improving accessibility, and boosting productivity across various domains. Their integration into critical applications, such as medical transcription, voice-controlled vehicle systems, and smart home devices, elevates the stakes for their security. The integrity and reliability of these systems are paramount, making the study of their vulnerabilities a pressing concern.
The concept of backdoor attacks against deep neural networks (DNNs) emerged in 2017, demonstrating how an adversary could inject a hidden functionality into a trained model. These attacks typically involve poisoning a small fraction of the training data with specific "triggers" that, once learned by the model, cause it to misbehave predictably when encountering inputs containing those triggers. While the image domain has seen extensive research into backdoor attacks, the audio domain has historically received less attention, leaving a significant gap in our understanding of these threats.
Existing audio backdoor attacks reviewed in the literature exhibit several critical limitations that FlowMur seeks to overcome. Firstly, many rely on simple, easily identifiable triggers, such as specific words or sounds (e.g., "brother," "Al Sun"). While straightforward to deploy, these triggers are often less effective in achieving high attack success rates and are more susceptible to detection. Optimized triggers, though more potent, often require greater adversarial knowledge.
Secondly, a significant hurdle for practical deployment of previous attacks is the assumption that the adversary possesses substantial knowledge about the target model's architecture, parameters, or the victim's training dataset. This level of information is rarely available to real-world attackers, severely limiting the applicability of such methods. FlowMur specifically addresses this by operating under a highly restricted adversary knowledge model.
Thirdly, prior research has largely neglected an in-depth investigation into the stealthiness of audio backdoors. Stealthiness encompasses several dimensions, including imperceptibility (the inability of humans to detect the trigger) and audibility (how easily the trigger can be discerned from background noise). Furthermore, triggering susceptibility, which measures the human perception of the trigger's presence, had not been thoroughly investigated. Without robust stealth, a backdoor attack is easily detected and mitigated.
Fourthly, existing audio backdoor attacks often lack dynamicity. A dynamic backdoor implies that the trigger's effectiveness is independent of its exact placement or attachment position within a benign audio sample. Static triggers, which require precise placement, are less robust and more challenging to deploy in varied real-world scenarios.
Finally, the defense resistance of previous audio backdoor attacks had not been well-studied. Many earlier methods could be neutralized by traditional defense mechanisms or even simple data preprocessing techniques. FlowMur aims to demonstrate resilience against both conventional and advanced defensive strategies, underscoring its sophisticated design. By addressing these five critical limitations—attack effectiveness, adversary knowledge, stealthiness, dynamicity, and defense resistance—FlowMur proposes a more practical and potent threat model for audio-based AI systems.
Key Findings
▶ Watch: Trigger generation as an optimization problem for stealth and effectiveness (3:30)
FlowMur demonstrates a remarkable advancement in audio backdoor attacks, achieving superior performance across several critical metrics while operating under the most restrictive adversary knowledge assumptions documented in current literature. The core findings highlight its efficacy, practicality, stealthiness, and resilience against defenses.
One of the primary findings is FlowMur's exceptional attack effectiveness. The system consistently achieved attack success rates of over 98% on two distinct datasets—the CommonVoice dataset and the Photo Keyword dataset. Crucially, this high success rate was accomplished without compromising the benign accuracy of the target speech recognition models, meaning the models continued to perform well on legitimate, untriggered inputs. This performance significantly surpasses that of baseline methods, such as the extended MBA (Mani-Pedi Backdoor Attack) dynamic variant, which served as a comparative benchmark.
Beyond raw effectiveness, FlowMur was engineered to possess several desirable properties for a practical attack. These include trigger universality, ensuring the trigger's efficacy across a wide range of benign audio samples; triggering imperceptibility, making the trigger extremely difficult for human listeners to detect; dynamicity, allowing the trigger to be effective regardless of its attachment position within an audio sample; and robustness against various environmental factors like ambient noise.
The practicality of FlowMur was rigorously tested in real-world scenarios. Experiments involving recorded audio and live speech confirmed that the attack remains highly effective, demonstrating its potential for deployment beyond controlled laboratory settings. This real-world validation underscores the immediate threat FlowMur represents to deployed SRS.
Regarding stealthiness, a dedicated human study was conducted, named "clean audio speech," to evaluate the trigger's imperceptibility. Participants were tasked with comparing the stealthiness of FlowMur's triggers under different signal-to-noise ratio (SNR) conditions and against triggers generated by other attack methods. The results conclusively showed that FlowMur's triggers were significantly more imperceptible than those of baseline attacks, indicating a superior level of stealth.
Finally, FlowMur exhibited robust defense resistance. It was evaluated against four different defense mechanisms, including common filters, pruning techniques, and advanced backdoor detection methods like STRIP and BACC (likely referring to Neural Cleanse, STRIP, and BACC as common categories of defenses). The findings indicated that FlowMur could effectively bypass these defenses, making it a challenging threat to mitigate with existing security tools. These comprehensive findings collectively establish FlowMur as a potent, stealthy, and practical audio backdoor, raising significant concerns for the security of speech recognition technologies.
Technical Deep Dive
▶ Watch: Adaptive data poisoning enhances trigger imperceptibility (4:00)
FlowMur's strength lies in its meticulously designed four-stage process, which enables a limited-knowledge adversary to inject a stealthy and robust backdoor into speech recognition models. The adversary model for FlowMur is intentionally constrained: the attacker is assumed to only have the capability to access and modify samples from a target class, and to collect auxiliary samples and models. This "limited knowledge" scenario is crucial for demonstrating practicality, as it mirrors the capabilities of many real-world attackers.
The four stages of FlowMur are: Preparation, Trigger Generation, Data Poisoning, and Backdoor Injection.
1. Preparation Stage
The initial Preparation stage is designed to overcome the challenge of the adversary's limited knowledge about the victim model and its training data. In a real-world attack, an adversary typically does not have direct access to the victim's proprietary model architecture or its complete, potentially massive, training dataset. To circumvent this, FlowMur employs a surrogate model strategy. The adversary collects an auxiliary dataset and trains an auxiliary model on it. This auxiliary model, though not identical to the victim's target model, serves as a proxy, allowing the adversary to infer characteristics and behaviors relevant for subsequent attack stages. The quality of this surrogate model is critical; it aims to approximate the target model's decision boundaries and feature extraction capabilities sufficiently for effective trigger generation and data poisoning, despite the knowledge gap. This stage facilitates the subsequent optimization processes by providing a workable environment for trigger development.
2. Trigger Generation Stage
The Trigger Generation stage is central to FlowMur's stealth and effectiveness. The goal here is to create a sound trigger with a unique set of properties: it must be highly effective in causing misclassification, universally applicable to any benign audio sample, robust to any attachment position, resistant to ambient noise, and, crucially, possess a small amplitude value to ensure low audibility and high stealthiness.
To achieve these often conflicting requirements, FlowMur formulates trigger generation as an optimization problem. This problem involves defining an objective function that mathematically encapsulates all desired trigger properties. For instance, the objective function would likely aim to:
- Maximize misclassification probability: Ensure that when the trigger is attached to a benign sample, the model confidently misclassifies it into the target class.
- Minimize trigger amplitude: Keep the magnitude of the trigger signal as low as possible to make it imperceptible to humans and difficult to detect.
- Maximize robustness: Ensure the trigger remains effective even with variations in its placement or the presence of background noise. This could involve adversarial training during trigger generation or incorporating noise models into the optimization.
- Ensure universality: Design the trigger to be effective across a diverse set of benign inputs, rather than being specific to a few samples. This might involve optimizing the trigger against a batch of diverse samples.
The optimization process iteratively refines the trigger (a small audio waveform) until it satisfies these criteria. Techniques from adversarial machine learning, such as projected gradient descent or other gradient-based optimization methods, would likely be employed. The output of this stage is a highly optimized, stealthy, and robust "sound trigger."
3. Data Poisoning Stage
Once the sound trigger is generated, the adversary proceeds to the Data Poisoning stage. This involves subtly corrupting a portion of the training dataset that will eventually be used to train the victim's speech recognition model. The poisoning strategy is carefully designed to embed the backdoor effectively while maintaining stealth:
- Target Class Poisoning: The adversary selectively poisons only samples belonging to the target class. This ensures that the backdoor functionality is specific and doesn't widely disrupt the model's behavior on other classes.
- Random Trigger Attachment Position: To achieve dynamicity, the trigger's attachment position on each poisoned sample is randomly selected. This prevents the model from learning to associate the backdoor with a fixed temporal location, making the attack more robust and harder to detect. For instance, the trigger might be appended, prepended, or inserted at a random point within the audio waveform.
- Adaptive Data Poisoning (SNR-based): To further enhance triggering imperceptibility, FlowMur employs an adaptive data poisoning method based on the Signal-to-Noise Ratio (SNR). This means the strength or characteristics of the trigger might be adjusted dynamically for each poisoned sample based on the characteristics of the benign audio. For example, in a quiet audio segment, a very low-amplitude trigger might be used, while in a noisier segment, the trigger's amplitude could be slightly increased without compromising imperceptibility, ensuring maximum effectiveness across varied audio conditions. This adaptive approach makes the backdoor more resilient to human detection and simple filtering techniques.
The result of this stage is a "poisonous data set" that, despite containing a small fraction of subtly modified samples, is capable of injecting the backdoor.
4. Backdoor Injection Stage
The final Backdoor Injection stage is passive from the adversary's perspective. Once the poisoned dataset is prepared, any user or organization that employs this dataset to train a Deep Neural Network (DNN) for speech recognition will inadvertently inject the FlowMur backdoor. The adversary's involvement ceases after the data poisoning. The training process itself, which involves the model learning patterns from the poisoned data, implicitly learns the hidden association between the stealthy trigger and the target misclassification. Consequently, the trained DNN will exhibit the backdoor behavior: performing normally on benign inputs but misclassifying any input containing the FlowMur trigger into the adversary's chosen target class. This "hands-off" injection mechanism further enhances the practicality and stealth of the attack, as the adversary does not need to directly interact with the victim's training infrastructure.
In summary, FlowMur's technical architecture systematically addresses the challenges of limited adversarial knowledge, trigger stealth, robustness, and practicality through a multi-stage process involving surrogate modeling, sophisticated optimization for trigger generation, and adaptive, dynamic data poisoning.
Demo / Proof of Concept
▶ Watch: Human study confirms FlowMur's superior trigger imperceptibility (6:30)
While the talk did not feature a live, interactive demonstration in the traditional sense, FlowMur's practicality and effectiveness were rigorously validated through several empirical evaluations that serve as a proof of concept. These evaluations were designed to simulate real-world conditions and assess the attack's performance across various dimensions.
A key aspect of demonstrating FlowMur's practicality involved testing its performance in scenarios beyond controlled laboratory environments. The researchers conducted experiments using recorded audio and live speech. This involved capturing audio inputs in a more natural setting, potentially introducing variability and noise that a synthetic dataset might not fully replicate. The results from these tests confirmed that FlowMur remained highly effective, indicating its robustness against the natural fluctuations and imperfections inherent in real-world audio capture. This suggests that an adversary could deploy FlowMur using readily available audio recording devices or by injecting triggers into live voice streams, making the attack highly practical.
Furthermore, the research included a dedicated human study to quantify the crucial aspect of trigger imperceptibility. This study, referred to as "clean audio speech," involved human participants evaluating the stealthiness of FlowMur's triggers. Two main tasks were conducted:
- Comparing FlowMur's stealthiness with different internal parameters: This likely involved varying parameters related to the trigger's amplitude or integration method (e.g., different Signal-to-Noise Ratio, or 'S' and 'R' as mentioned in the transcript, which could refer to specific trigger characteristics or noise levels). The goal was to identify optimal configurations that maximized imperceptibility without sacrificing attack effectiveness.
- Comparing FlowMur's stealthiness against other attack methods: Participants were asked to differentiate between benign audio samples and those containing triggers from FlowMur versus triggers from baseline attacks (like the extended MBA). The findings were conclusive: FlowMur's triggers were significantly more difficult for human listeners to perceive compared to those generated by previous methods. This empirical evidence from human perception studies strongly validates FlowMur's claim of superior stealthiness, which is a critical factor for any practical backdoor attack to avoid detection.
These evaluations collectively serve as a robust proof of concept, demonstrating that FlowMur is not merely a theoretical construct but a practical, stealthy, and effective audio backdoor attack capable of operating in real-world conditions and evading human detection.
Defensive Implications
▶ Watch: FlowMur effectively bypasses various backdoor defenses (7:00)
FlowMur presents a formidable challenge to current security paradigms for speech recognition systems, highlighting the urgent need for more sophisticated and adaptive defense mechanisms. The research explicitly states that "defending against the FlowMur is not easy" and that it "can bypass both traditional and advanced defenses." This underscores the significant gap between existing protective measures and the capabilities of this new generation of audio backdoor attacks.
The researchers evaluated FlowMur's resilience against four distinct categories of defense methods. While the specific names of all four are not explicitly detailed in the transcript, it mentions "filters and pruning strip and bcks." This likely refers to:
- Filters: Traditional audio processing filters (e.g., low-pass, high-pass filters) or noise reduction techniques aimed at removing subtle artifacts from audio signals.
- Pruning: A common technique in neural network optimization where redundant or less important neurons/connections are removed from a model, often used as a defense against backdoors by removing the "backdoor circuit."
- STRIP (Strong, Transparent, and Robust Invisible Perturbations): An advanced backdoor detection method that involves perturbing inputs and observing the model's output consistency. Backdoored models tend to produce inconsistent outputs when triggered inputs are perturbed, allowing detection.
- BACC (Backdoor Attack Cost Control / Backdoor detection with Activation Clustering): This could refer to various advanced backdoor detection techniques, potentially involving analyzing activation patterns or clustering behaviors within the model to identify anomalous responses indicative of a backdoor.
The fact that FlowMur successfully bypassed these diverse defense strategies is highly concerning. Traditional filters fail because FlowMur's triggers are designed to be imperceptible and robust, often blending seamlessly with benign audio or residing in frequency bands that are not easily removed without degrading the legitimate audio content. Pruning-based defenses are ineffective because FlowMur's backdoor is likely deeply embedded and distributed within the model's parameters, making it difficult to isolate and remove without significantly impacting benign accuracy. Advanced detection methods like STRIP and BACC, which rely on identifying anomalies in model behavior, are also circumvented, suggesting that FlowMur's triggers might induce behaviors that closely mimic benign operations or that the triggers are too subtle for these techniques to reliably flag.
For defenders, the implications are profound:
- Re-evaluation of Current Defenses: Existing security tools and methodologies for protecting SRS are likely inadequate against attacks like FlowMur. There's an immediate need to reassess their efficacy and develop new, more robust countermeasures.
- Focus on Imperceptibility and Dynamicity: New defenses must specifically target the unique characteristics of FlowMur: its imperceptibility to humans and machines, its dynamic nature (trigger position independence), and its robustness against noise. This might involve novel signal processing techniques tailored to detect subtle, optimized perturbations, or more advanced anomaly detection systems that can identify minute deviations in model behavior even under varied input conditions.
- Supply Chain Security: The "backdoor injection" stage highlights a critical vulnerability in the AI model supply chain. If training data is compromised at any point—whether by an insider, a third-party data provider, or through data leakage—a backdoor can be injected without the model owner's direct knowledge. Organizations must implement stringent data provenance and integrity checks for all training datasets.
- Proactive Threat Modeling: Security professionals need to adopt a proactive threat modeling approach, anticipating sophisticated, limited-knowledge adversaries. This includes understanding potential attack vectors beyond direct model manipulation, focusing on data poisoning and the broader AI development lifecycle.
- Research into Novel Detection and Mitigation: Further research is urgently needed into novel techniques for detecting and mitigating such stealthy, dynamic, and robust audio backdoors. This could involve developing new forms of adversarial training for robustness against backdoors, certified defenses, or advanced forensic tools for AI models.
In conclusion, FlowMur serves as a stark warning about the evolving landscape of AI security threats, demanding a significant shift in defensive strategies to protect critical speech recognition systems from sophisticated and stealthy attacks.
Key Takeaways
- FlowMur is a novel, stealthy, and practical audio backdoor attack designed for speech recognition systems (SRS).
- It operates effectively with limited adversary knowledge, making it highly relevant for real-world threat scenarios.
- The attack achieves over 98% attack success rates on diverse datasets (CommonVoice, Photo Keyword) without compromising the benign accuracy of the target model.
- FlowMur's triggers exhibit superior imperceptibility to human listeners and possess dynamicity (position-independent effectiveness) and robustness against ambient noise.
- The attack demonstrably bypasses both traditional and advanced defense mechanisms, including filters, pruning, STRIP, and BACC.
- This research highlights critical, unaddressed security vulnerabilities in SRS and necessitates the development of new, more robust defense strategies against sophisticated audio backdoor attacks.
About the Speaker(s)
The research on FlowMur was a collaborative effort involving Jiahe Lan, Jie Wang, Baochen Yan, Zheng Yan, and Elisa Bertino. The work was conducted between researchers affiliated with CID University in China and KU University in the US. While specific titles were not provided in the talk metadata, their collective expertise contributed to this significant advancement in understanding and addressing security threats to speech recognition systems.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
FlowMur presents a critical advancement in audio backdoor attacks, achieving superior stealth and effectiveness under a highly realistic limited-knowledge adversary model. Its ability to bypass both traditional and advanced defenses demands immediate attention from anyone securing speech recognition systems. This is not theoretical; it's a blueprint for a potent real-world threat.
Heather Calloway (CISO) — STRONG ACCEPT
This research on FlowMur exposes a critical, practical vulnerability in speech recognition systems via highly stealthy audio backdoors. It necessitates an urgent re-evaluation of AI/ML supply chain security and the efficacy of current defense mechanisms, forcing leaders to confront significant institutional risks.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024