Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
80 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

SPIRIT: Patching Speech Language Models against Jailbreak Attacks (2505.13541v1)

Published 18 May 2025 in eess.AS and cs.LG

Abstract: Speech LLMs (SLMs) enable natural interactions via spoken instructions, which more effectively capture user intent by detecting nuances in speech. The richer speech signal introduces new security risks compared to text-based models, as adversaries can better bypass safety mechanisms by injecting imperceptible noise to speech. We analyze adversarial attacks and find that SLMs are substantially more vulnerable to jailbreak attacks, which can achieve a perfect 100% attack success rate in some instances. To improve security, we propose post-hoc patching defenses used to intervene during inference by modifying the SLM's activations that improve robustness up to 99% with (i) negligible impact on utility and (ii) without any re-training. We conduct ablation studies to maximize the efficacy of our defenses and improve the utility/security trade-off, validated with large-scale benchmarks unique to SLMs.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Amirbek Djanibekov (7 papers)
  2. Nurdaulet Mukhituly (4 papers)
  3. Kentaro Inui (119 papers)
  4. Hanan Aldarmaki (29 papers)
  5. Nils Lukas (13 papers)