We enforce internal consistency in trigger generation to lower FP from other unseen real-world variants (details will be added in revision) while preserving ASR. E.g., the attacked model achieves high clean acc. (Tab 1) and 8.2% FP on the original Tusimple dataset with benign triggers.