Reject early what is not useful speech and bound the load.
The threat
the attacker degrades the audio channel (abusive silence, noise, music injection, jamming) to bypass speech detection or exhaust processing.
Blind spotWhy classic frameworks miss it
dirty media is not a malformed packet; frameworks miss that abusing quality triggers costs, false negatives or VAD bypass.
MitigationProposed approach
quality thresholds (SNR, minimum speech duration), robust VAD detection, rejection of unusable streams, quotas.
The proposed control
a stream below the quality threshold is refused.
Expected evidence
a polluted stream triggers no action and no abnormal cost.
SourcesReferences and public research
MITRE ATLAS 2026.07AML.T0029 Denial of AI Service
Public researchPublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (model abuse categories), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic card, no rating, no verdict.