ICLR 2026poster0 citations

Are Deep Speech Denoising Models Robust to Adversarial Noise?

Will Schwarzer, Andrea Fanelli, Philip S. Thomas, Xiaoyu Liu

Abstract

Deep noise suppression (DNS) models enjoy widespread use throughout a variety of high-stakes speech applications. However, we show that four recent DNS models can each be reduced to outputting unintelligible gibberish through the addition of psychoacoustically hidden adversarial noise, even in low-background-noise and simulated over-the-air settings. For three of the models, a small transcription study with audio and multimedia experts confirms unintelligibility of the attacked audio; simultaneously, an ABX study shows that the adversarial noise is generally imperceptible, with some variance between participants and samples. While we also establish several negative results around targeted attacks and model transfer, our results nevertheless highlight the need for practical countermeasures before open-source DNS systems can be used in safety-critical applications.

Adversarial RobustnessAdversarial PerturbationsSecuritySafetySpeech EnhancementSpeech DenoisingNoise SuppressionDeep Noise SuppressionPsychoacoustic Masking
BibTeX
@inproceedings{
schwarzer2026are,
title={Are Deep Speech Denoising Models Robust to Adversarial Noise?},
author={Will Schwarzer and Andrea Fanelli and Philip S. Thomas and Xiaoyu Liu},
booktitle={The Fourteenth International Conference on Learning Representations},
year={2026},
url={https://openreview.net/forum?id=WtH2JxKJKf}
}
Are Deep Speech Denoising Models Robust to Adversarial Noise? · ICLR 2026