Can speech and ASR models be backdoored?
Yes. Speech recognition and spoken-language-understanding models can be backdoored at training time, with triggers as ordinary as a room's echo or a background alarm. What the demonstrated attacks show, and where their limits are.