.</p>\n","updatedAt":"2026-08-14T15:16:27.503Z","author":{"_id":"66350219843f549fdac86347","avatarUrl":"/avatars/1ad7aa4e8e6d80c5d50bf4de502f11a4.svg","fullname":"Matteo Negri","name":"MNegri","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":4,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"fr","probability":0.32275810837745667},"editors":["MNegri"],"editorAvatarUrls":["/avatars/1ad7aa4e8e6d80c5d50bf4de502f11a4.svg"],"reactions":[],"isReport":false}},{"id":"6a7fc2658df58acee67426c2","author":{"_id":"63d3e0e8ff1384ce6c5dd17d","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/1674830754237-63d3e0e8ff1384ce6c5dd17d.jpeg","fullname":"Librarian Bot (Bot)","name":"librarian-bot","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":378,"isUserFollowing":false},"createdAt":"2026-08-15T01:35:33.000Z","type":"comment","data":{"edited":false,"hidden":false,"latest":{"raw":"This is an automated message from the [Librarian Bot](https://huggingface.co/librarian-bots). I found the following papers similar to this paper. \n\nThe following papers were recommended by the Semantic Scholar API \n\n* [Never Stop Speaking: a Denial-of-Service Attack on End-to-End Speech Language Models](https://huggingface.co/papers/2608.10405) (2026)\n* [From Semantics to Readout: Mechanistic Understanding of Audio Tokens after Fine-Tuning for Temporal Audio Grounding](https://huggingface.co/papers/2607.25355) (2026)\n* [Prosody-driven Jailbreaks in Audio LLMs: A Controlled Study and Mechanistic Analysis](https://huggingface.co/papers/2607.26541) (2026)\n* [Detect, Unlearn, Restore: Defending Text Summarization Models Against Data Poisoning](https://huggingface.co/papers/2606.26036) (2026)\n* [Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure](https://huggingface.co/papers/2608.02657) (2026)\n* [ReACT-CLIP: Response-Aware Test-Time Defense for Vision--Language Models](https://huggingface.co/papers/2608.01067) (2026)\n* [Model Confidence Under Answer-Preserving Attacks: An Informativeness-Manipulability Frontier](https://huggingface.co/papers/2608.06571) (2026)\n\n\n Please give a thumbs up to this comment if you found it helpful!\n\n If you want recommendations for any Paper on Hugging Face checkout [this](https://huggingface.co/spaces/librarian-bots/recommend_similar_papers) Space\n\n You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: `@librarian-bot recommend`","html":"<p>This is an automated message from the <a href=\"https://huggingface.co/librarian-bots\">Librarian Bot</a>. I found the following papers similar to this paper. </p>\n<p>The following papers were recommended by the Semantic Scholar API </p>\n<ul>\n<li><a href=\"https://huggingface.co/papers/2608.10405\">Never Stop Speaking: a Denial-of-Service Attack on End-to-End Speech Language Models</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2607.25355\">From Semantics to Readout: Mechanistic Understanding of Audio Tokens after Fine-Tuning for Temporal Audio Grounding</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2607.26541\">Prosody-driven Jailbreaks in Audio LLMs: A Controlled Study and Mechanistic Analysis</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2606.26036\">Detect, Unlearn, Restore: Defending Text Summarization Models Against Data Poisoning</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2608.02657\">Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2608.01067\">ReACT-CLIP: Response-Aware Test-Time Defense for Vision--Language Models</a> (2026)</li>\n<li><a href=\"https://huggingface.co/papers/2608.06571\">Model Confidence Under Answer-Preserving Attacks: An Informativeness-Manipulability Frontier</a> (2026)</li>\n</ul>\n<p> Please give a thumbs up to this comment if you found it helpful!</p>\n<p> If you want recommendations for any Paper on Hugging Face checkout <a href=\"https://huggingface.co/spaces/librarian-bots/recommend_similar_papers\">this</a> Space</p>\n<p> You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: <code>@librarian-bot recommend</code></p>\n","updatedAt":"2026-08-15T01:35:33.071Z","author":{"_id":"63d3e0e8ff1384ce6c5dd17d","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/1674830754237-63d3e0e8ff1384ce6c5dd17d.jpeg","fullname":"Librarian Bot (Bot)","name":"librarian-bot","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":378,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.7014416456222534},"editors":["librarian-bot"],"editorAvatarUrls":["https://cdn-avatars.huggingface.co/v1/production/uploads/1674830754237-63d3e0e8ff1384ce6c5dd17d.jpeg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2608.09158","authors":[{"_id":"6a7f3135f747ea94019af553","name":"Yuanhe Zhang","hidden":false},{"_id":"6a7f3135f747ea94019af554","name":"Weiliu Wang","hidden":false},{"_id":"6a7f3135f747ea94019af555","name":"Jie Ren","hidden":false},{"_id":"6a7f3135f747ea94019af556","name":"Liang Lin","hidden":false},{"_id":"6a7f3135f747ea94019af557","name":"Zhenhong Zhou","hidden":false},{"_id":"6a7f3135f747ea94019af558","name":"Haoran Gao","hidden":false},{"_id":"6a7f3135f747ea94019af559","name":"Kun Wang","hidden":false},{"_id":"6a7f3135f747ea94019af55a","name":"Chen Li","hidden":false},{"_id":"6a7f3135f747ea94019af55b","name":"Li Sun","hidden":false},{"_id":"6a7f3135f747ea94019af55c","name":"Sen Su","hidden":false}],"publishedAt":"2026-08-10T00:00:00.000Z","submittedOnDailyAt":"2026-08-14T00:00:00.000Z","title":"From Inaudible Inputs to Model Failures: Low-Frequency Safety Risks in LALMs","submittedOnDailyBy":{"_id":"66350219843f549fdac86347","avatarUrl":"/avatars/1ad7aa4e8e6d80c5d50bf4de502f11a4.svg","isPro":false,"fullname":"Matteo Negri","user":"MNegri","type":"user","name":"MNegri"},"summary":"Large audio-language models (LALMs) have demonstrated strong capabilities in understanding diverse audio inputs. This diversity includes low-frequency signals that are inaudible to humans but can still enter the model and influence its generation. However, the practical impact of such low-frequency inputs on LALMs remains largely unexplored. In this paper, we propose Intermittent Low-Frequency Lockout (ILL), an inaudible red teaming method that evaluates this risk using a universal waveform template in a black box setting. ILL uses Sentence Attention Scale Estimation to determine active intervals and Frequency Confusion Transfer to construct a low-frequency waveform with continuous phase from corpus spectral variation. To mitigate this risk, we propose Distributional Requery Guard (DRG) to detect low-frequency distribution shifts and conditionally request a second recording for semantic recovery. Across six LALMs and multiple audio understanding tasks, ILL reduces accuracy by up to 67 percentage points while receiving a mean human audibility rating of 1.33, close to 1.17 for clean audio; DRG raises mean attacked accuracy from 28.5\\% to 46.1\\% after clean reacquisition. These findings identify a previously overlooked safety risk for LALMs and provide a foundation for future research on robust audio understanding.","upvotes":2,"discussionId":"6a7f3136f747ea94019af55d","ai_summary":"Researchers propose a black-box red-teaming method using inaudible low-frequency waveforms to expose vulnerabilities in audio-language models, alongside a defense that detects distribution shifts and requests a second recording to recover accuracy.","ai_keywords":["Large audio-language models","Intermittent Low-Frequency Lockout","Sentence Attention Scale Estimation","Frequency Confusion Transfer","Distributional Requery Guard","low-frequency red teaming","black-box attack"],"ai_summary_model":"thinkingmachines/Inkling-Small"},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"63ac5701c21e60a3e9b58aa7","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63ac5701c21e60a3e9b58aa7/g6EX7diOpuA94R2ab-rZC.png","isPro":true,"fullname":"Dipankar Sarkar","user":"dipankarsarkar","type":"user"},{"_id":"631e14ac473a6825f285e89d","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/631e14ac473a6825f285e89d/K-6QnoeGLg8XFvbTMMdqA.jpeg","isPro":false,"fullname":"Yury Panikov","user":"panikov","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2608/2608.09158.md","query":{}}">
From Inaudible Inputs to Model Failures: Low-Frequency Safety Risks in LALMs
Abstract
Researchers propose a black-box red-teaming method using inaudible low-frequency waveforms to expose vulnerabilities in audio-language models, alongside a defense that detects distribution shifts and requests a second recording to recover accuracy.
Large audio-language models (LALMs) have demonstrated strong capabilities in understanding diverse audio inputs. This diversity includes low-frequency signals that are inaudible to humans but can still enter the model and influence its generation. However, the practical impact of such low-frequency inputs on LALMs remains largely unexplored. In this paper, we propose Intermittent Low-Frequency Lockout (ILL), an inaudible red teaming method that evaluates this risk using a universal waveform template in a black box setting. ILL uses Sentence Attention Scale Estimation to determine active intervals and Frequency Confusion Transfer to construct a low-frequency waveform with continuous phase from corpus spectral variation. To mitigate this risk, we propose Distributional Requery Guard (DRG) to detect low-frequency distribution shifts and conditionally request a second recording for semantic recovery. Across six LALMs and multiple audio understanding tasks, ILL reduces accuracy by up to 67 percentage points while receiving a mean human audibility rating of 1.33, close to 1.17 for clean audio; DRG raises mean attacked accuracy from 28.5\% to 46.1\% after clean reacquisition. These findings identify a previously overlooked safety risk for LALMs and provide a foundation for future research on robust audio understanding.
Community
This is an automated message from the Librarian Bot. I found the following papers similar to this paper.
The following papers were recommended by the Semantic Scholar API
Please give a thumbs up to this comment if you found it helpful!
If you want recommendations for any Paper on Hugging Face checkout this Space
You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: @librarian-bot recommend
Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.