Romanian Journal of Information Science and Technology (ROMJIST)

An open – access publication

  |  HOME  |   GENERAL INFORMATION  |   ROMJIST ON-LINE  |  KEY INFORMATION FOR AUTHORS  |   COMMITTEES  |  

ROMJIST is a publication of Romanian Academy,
Section for Information Science and Technology

Editor – in – Chief:
Radu-Emil Precup

Honorary Co-Editors-in-Chief:
Horia-Nicolai Teodorescu
Gheorghe Stefan

Secretariate (office):
Adriana Apostol
Adress for correspondence: romjist@nano-link.net (after 1st of January, 2019)

Founding Editor-in-Chief
(until 10th of February, 2021):
Dan Dascalu

Editing of the printed version: Mihaela Marian (Publishing House of the Romanian Academy, Bucharest)

Technical editor
of the on-line version:
Lucian Milea (University POLITEHNICA of Bucharest)

Sponsor:
• National Institute for R & D
in Microtechnologies
(IMT Bucharest), www.imt.ro

ROMJIST Volume 29, No. 3, 2026, pp. 225-236, DOI: 10.59277/ROMJIST.2026.3.02
 

Sebastian-Alexandru DRAGUSIN, Denisa TOMA, Robert-Nicolae BOSTINARU, Nicu BIZON
A Multi-Stage Poisoning Detection Pipeline for Embedded Voice-Command Systems

ABSTRACT: Embedded voice-command systems are increasingly adopted in cyber-physical and industrial environments, yet their machine-learning pipelines remain vulnerable to data poisoning attacks that can silently degrade recognition performance or induce targeted misclassifications. This paper proposes a multi-stage poisoning detection pipeline tailored for embedded voice-command applications, combining fast integrity screening with progressively stronger detection models. First, an audio integrity layer analyzes waveform and spectrogram consistency to flag abnormal patterns indicative of injected perturbations or corrupted samples. Second, a lightweight machine-learning detector based on Random Forests operates on compact statistical descriptors extracted from spectrogram representations, enabling efficient on-device or edge-level screening. Third, a spectrogram-based Convolutional Neural Network provides high-sensitivity discrimination between clean and poisoned samples, acting as a robust validation stage in higher-assurance deployments. To increase resilience, the training procedure integrates regularization and controlled augmentation to mitigate overfitting to spurious artifacts and reduce poisoning sensitivity. The proposed approach is designed to be deployable under embedded constraints by separating low-cost screening from deeper analysis, and it offers a structured methodology for securing voice-command pipelines against poisoning threats.

KEYWORDS: Anomaly detection; convolutional neural networks; cyber-physical systems; data poisoning; embedded systems; spectrogram analysis; voice-command recognition

Read full text (pdf)






  |  HOME  |   GENERAL INFORMATION  |   ROMJIST ON-LINE  |  KEY INFORMATION FOR AUTHORS  |   COMMITTEES  |