← Latest papers
🤖 AI

From Inaudible Inputs to Model Failures: Low-Frequency Safety Risks in LALMs

This paper introduces an inaudible red teaming method called Intermittent Low-Frequency Lockout (ILL) that exploits low-frequency signals to significantly degrade the performance of Large Audio-Language Models (LALMs), while also proposing a Distributional Requery Guard (DRG) mechanism to detect such attacks and recover semantic accuracy.

Original authors: Yuanhe Zhang, Weiliu Wang, Jie Ren, Liang Lin, Zhenhong Zhou, Haoran Gao, Kun Wang, Chen Li, Li Sun, Sen Su

Published 2026-08-11
📖 4 min read☕ Coffee break read

Original authors: Yuanhe Zhang, Weiliu Wang, Jie Ren, Liang Lin, Zhenhong Zhou, Haoran Gao, Kun Wang, Chen Li, Li Sun, Sen Su

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you are talking to a super-smart robot that can hear everything: your voice, the rustling of leaves, the hum of a refrigerator, and even the music playing in the background. Scientists call these "Large Audio-Language Models" (LALMs). They are like digital ears and brains combined, designed to understand the world through sound. But here's the catch: these robots hear things that human ears simply cannot. Just as a dog can hear a high-pitched whistle that is silent to us, these AI models can process sound waves that are far too low or too high for us to notice. This creates a strange gap: you might think you are having a normal conversation, but the robot is actually hearing a secret, invisible layer of noise underneath your words. This paper explores what happens when someone intentionally uses that invisible layer to trick the robot.

The researchers behind this study, led by Yuanhe Zhang and his team, decided to play a game of "red teaming," which is basically a fancy way of saying they tried to break the system to see where it was weak. They discovered a sneaky way to confuse these audio robots using Intermittent Low-Frequency Lockout (ILL). Think of it like this: imagine you are trying to listen to a friend tell a story, but someone is playing a very quiet, rhythmic thumping sound under the table. You can't hear the thumping at all, but it's vibrating the table just enough to make your friend's voice sound garbled to the person sitting across from you. That is essentially what ILL does. It uses a "universal waveform"—a specific pattern of low-frequency sound (between 5 and 20 Hz, which is below the range of human hearing)—that is injected into the audio the robot receives.

The team found that this invisible noise is incredibly effective at messing up the robot's brain. When they tested this on six different audio-language models, the robots' ability to understand speech, translate languages, or identify emotions dropped dramatically. In some cases, their accuracy fell by as much as 67 percentage points. The scariest part? The humans listening to the audio couldn't tell the difference. The researchers asked people to rate how noisy the audio sounded on a scale of 1 to 7. The clean audio got a rating of 1.17, and the audio with the secret attack got a rating of 1.33. That is barely a blip above "completely imperceptible," yet it was enough to make the AI stumble and give wrong answers.

The paper also argues against the idea that you need loud, obvious noise to break these systems. They showed that you don't need to blast the robot with static or loud music; a tiny, hidden, low-frequency pulse is enough to cause chaos. They tested this against other types of noise attacks and found that while their method wasn't always the absolute worst in every single scenario, it was consistently very strong and, crucially, much harder for humans to detect.

But the researchers didn't just want to break things; they wanted to fix them too. They proposed a defense called Distributional Requery Guard (DRG). Imagine if, every time you spoke to a robot and it seemed confused, the robot would politely say, "Hey, that sounded a bit weird. Could you say that again?" The DRG system acts like a bouncer at a club. It listens to the audio and checks if the "spectral fingerprint" (the pattern of frequencies) looks suspicious. If it detects that low-frequency interference is hiding in the mix, it asks the user to record the sentence a second time. By comparing the first recording (which might be jammed) with the second one (which is hopefully clean), the system can figure out what the user actually meant. This defense worked well, boosting the robots' accuracy from a low of 28.5% back up to 46.1% when a clean second recording was available.

In the end, this paper suggests a new kind of safety risk for the future of AI. It shows that because these models hear a wider range of sound than we do, they are vulnerable to attacks that are invisible to us. The authors suggest that we need to build better "ears" for our AI that can spot these hidden frequencies and ask for clarification, ensuring that what the robot hears matches what we actually intended to say. While the experiments were done in a controlled simulation rather than in the wild, the results highlight a real gap between human perception and machine hearing that we need to address before these audio assistants become a part of our daily lives.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →