- Research Article
- 10.1016/j.csl.2025.101869
Comparative study on noise-augmented training and its effect on adversarial robustness in ASR systems
- Aug 26, 2025
- Computer Speech & Language
- Karla Pizzi + 2 more +2
In this study, we investigate whether noise-augmented training can concurrently improve adversarial robustness in automatic speech recognition (ASR) systems. We conduct a comparative analysis of the adversarial robustness of four different ASR architectures, each trained under three different augmentation conditions: (1) background noise, speed variations, and reverberations; (2) speed variations only; (3) no data augmentation. We then evaluate the robustness of all resulting models against attacks with white-box or black-box adversarial examples. Our results demonstrate that noise augmentation not only enhances model performance on noisy speech but also improves the model’s robustness to adversarial attacks. • Comparative analysis: We examine for state-of-the-art automatic speech recognition (ASR) architectures under three different training conditions and evaluate their robustness with respect to white- and black-box adversarial attacks. • Practical implications: Our work has direct practical applications, as it shows that noise-augmented training, which is much cheeper than adversarial training, already helps in reducing the risks for adversarial attacks. This has not been explored in the context of automatic speech recognition yet and, thus, is a relevant contribution. • Contribution to security and privacy: Our paper provides necessary and useful insights to improve robustness against adversarial attacks.
Read more