English

Trade-offs Between Capacity and Robustness in Neural Audio Codecs for Adversarially Robust Speech Recognition

Audio and Speech Processing 2026-03-11 v1 Sound

Abstract

Adversarial perturbations exploit vulnerabilities in automatic speech recognition (ASR) systems while preserving human perceived linguistic content. Neural audio codecs impose a discrete bottleneck that can suppress fine-grained signal variations associated with adversarial noise. We examine how the granularity of this bottleneck, controlled by residual vector quantization (RVQ) depth, shapes adversarial robustness. We observe a non-monotonic trade-off under gradient-based attacks: shallow quantization suppresses adversarial perturbations but degrades speech content, while deeper quantization preserves both content and perturbations. Intermediate depths balance these effects and minimize transcription error. We further show that adversarially induced changes in discrete codebook tokens strongly correlate with transcription error. These gains persist under adaptive attacks, where neural codec configurations outperform traditional compression defenses.

Keywords

Cite

@article{arxiv.2603.09034,
  title  = {Trade-offs Between Capacity and Robustness in Neural Audio Codecs for Adversarially Robust Speech Recognition},
  author = {Jordan Prescott and Thanathai Lertpetchpun and Shrikanth Narayanan},
  journal= {arXiv preprint arXiv:2603.09034},
  year   = {2026}
}

Comments

Submitted to Interspeech 2026

R2 v1 2026-07-01T11:11:25.415Z