{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T12:37:10Z","timestamp":1774874230832,"version":"3.50.1"},"reference-count":26,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472047"],"award-info":[{"award-number":["62472047"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072051"],"award-info":[{"award-number":["62072051"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["High-Confidence Computing"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1016\/j.hcc.2025.100337","type":"journal-article","created":{"date-parts":[[2025,7,2]],"date-time":"2025-07-02T04:19:29Z","timestamp":1751429969000},"page":"100337","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"title":["A fast gray-box adversarial example generation algorithm based on FakeBob"],"prefix":"10.1016","volume":"6","author":[{"given":"Jia","family":"Zheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wanjin","family":"Hou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huiyu","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.hcc.2025.100337_b1","doi-asserted-by":"crossref","unstructured":"B. Zheng, P. Jiang, Q. Wang, et al., Black-box adversarial attacks on commercial speech platforms with minimal information, in: ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 86\u2013107.","DOI":"10.1145\/3460120.3485383"},{"key":"10.1016\/j.hcc.2025.100337_b2","first-page":"20","article-title":"Explaining and harnessing adversarial examples","volume":"1050","author":"Goodfellow","year":"2015","journal-title":"Stat"},{"key":"10.1016\/j.hcc.2025.100337_b3","unstructured":"X. Yuan, Y. Chen, Y. Zhao, et al., CommanderSong: A systematic Approach for Practical Adversarial Voice Recognition, in: USENIX Security Symposium, 2018, pp. 49\u201364."},{"key":"10.1016\/j.hcc.2025.100337_b4","series-title":"In Proceedings of the 32nd USENIX Conference on Security Symposium","first-page":"2437","article-title":"QFA2SR: query-free adversarial transfer attacks to speaker recognition systems","author":"Guangke","year":"2023"},{"key":"10.1016\/j.hcc.2025.100337_b5","doi-asserted-by":"crossref","DOI":"10.1016\/j.sysarc.2022.102526","article-title":"Adversarial attacks and defenses in speaker recognition systems: A survey","volume":"127","author":"Lan","year":"2022","journal-title":"J. Syst. Archit."},{"key":"10.1016\/j.hcc.2025.100337_b6","series-title":"Did you hear that? Adversarial examples against automatic speech recognition","author":"Alzantot","year":"2018"},{"issue":"05","key":"10.1016\/j.hcc.2025.100337_b7","first-page":"1569","article-title":"Adversarial example generation method for black box intelligent speech software","volume":"33","author":"Yuan","year":"2022","journal-title":"J. Softw."},{"key":"10.1016\/j.hcc.2025.100337_b8","first-page":"15","article-title":"Targeted adversarial examples for black box audio systems","volume":"vol. 6","author":"Taori","year":"2019"},{"issue":"5","key":"10.1016\/j.hcc.2025.100337_b9","first-page":"1019","article-title":"Black-box adversarial attack toward speech recognition system","volume":"41","author":"Chen","year":"2020","journal-title":"Chin. Comput. Syst."},{"issue":"2","key":"10.1016\/j.hcc.2025.100337_b10","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1504\/IJBIC.2010.032124","article-title":"Firefly algorithm, stochastic test functions and design optimisation","volume":"2","author":"Yang","year":"2010","journal-title":"Int. J. Bio- Inspired Comput."},{"key":"10.1016\/j.hcc.2025.100337_b11","doi-asserted-by":"crossref","unstructured":"L. Zhang, Y. Meng, J. Yu, et al., Voiceprint mimicry attack towards speaker verification system in smart home, in: IEEE Conference on Computer Communications, 2020, pp. 377\u2013386.","DOI":"10.1109\/INFOCOM41043.2020.9155483"},{"key":"10.1016\/j.hcc.2025.100337_b12","doi-asserted-by":"crossref","unstructured":"G. Chen, S. Chen, L. Fan, et al., Who is real bob? Adversarial attacks on speaker recognition systems, in: IEEE Symposium on Security and Privacy, 2021, pp. 694\u2013711.","DOI":"10.1109\/SP40001.2021.00004"},{"key":"10.1016\/j.hcc.2025.100337_b13","doi-asserted-by":"crossref","unstructured":"D. Wang, J. Lin, Y. Wang, et al., Query-Efficient Adversarial Attack Based On Latin Hypercube Sampling, in: IEEE International Conference on Image Processing, 2022, pp. 546\u2013550.","DOI":"10.1109\/ICIP46576.2022.9897705"},{"key":"10.1016\/j.hcc.2025.100337_b14","article-title":"Diffusion models for imperceptible and transferable adversarial attack","author":"Chen","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.hcc.2025.100337_b15","series-title":"Artificial Intelligence Safety and Security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.hcc.2025.100337_b16","doi-asserted-by":"crossref","unstructured":"P.Y. Chen, H. Zhang, Y. Sharma, et al., Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models, in: ACM Workshop on Artificial Intelligence and Security, 2017, pp. 15\u201326.","DOI":"10.1145\/3128572.3140448"},{"key":"10.1016\/j.hcc.2025.100337_b17","doi-asserted-by":"crossref","unstructured":"N. Carlini, D. Wagner, Towards evaluating the robustness of neural networks, in: IEEE Symposium on Security and Privacy, 2017, pp. 39\u201357.","DOI":"10.1109\/SP.2017.49"},{"key":"10.1016\/j.hcc.2025.100337_b18","doi-asserted-by":"crossref","unstructured":"Y.K. Kan, K. Xu, H. Li, J. Shi, VoiceDefense: Protecting Automatic Speaker Verification Models Against Black-box Adversarial Attacks, in: Proc. Interspeech., 2024, pp. 517\u2013521.","DOI":"10.21437\/Interspeech.2024-372"},{"key":"10.1016\/j.hcc.2025.100337_b19","doi-asserted-by":"crossref","unstructured":"Xin Wang, Kai Chen, Xingjun Ma, et al., AdvQDet: Detecting Query-Based Adversarial Attacks with Adversarial Contrastive Prompt Tuning, in: Proceedings of the 32nd ACM International Conference on Multimedia, 2024, pp. 6212\u20136221.","DOI":"10.1145\/3664647.3681032"},{"key":"10.1016\/j.hcc.2025.100337_b20","series-title":"International Conference on Machine Learning","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"Athalye","year":"2018"},{"key":"10.1016\/j.hcc.2025.100337_b21","series-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2017"},{"key":"10.1016\/j.hcc.2025.100337_b22","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer","year":"2020","journal-title":"Neural Inf. Process. Syst."},{"key":"10.1016\/j.hcc.2025.100337_b23","unstructured":"S. Hussain, P. Neekhara, S. Dubnov, et al., WaveGuard: Understanding and mitigating audio adversarial examples, in: USENIX Security Symposium, 2021, pp. 2273\u20132290."},{"key":"10.1016\/j.hcc.2025.100337_b24","series-title":"Isolated and ensemble audio preprocessing methods for detecting adversarial examples against automatic speech recognition","author":"Rajaratnam","year":"2018"},{"issue":"2\u20133","key":"10.1016\/j.hcc.2025.100337_b25","article-title":"Fundamentals of speaker recognition","volume":"6","author":"Erta\u015f","year":"2011","journal-title":"Pamukkale \u00dcniv. M\u00fchendislik Bilim. Derg."},{"key":"10.1016\/j.hcc.2025.100337_b26","unstructured":"A. Ilyas, L. Engstrom, A. Athalye, et al., Black-box adversarial attacks with limited queries and information, in: International Conference on Machine Learning, 2018, pp. 2137\u20132146."}],"container-title":["High-Confidence Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000418?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000418?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T11:26:24Z","timestamp":1774869984000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2667295225000418"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":26,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["S2667295225000418"],"URL":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100337","relation":{},"ISSN":["2667-2952"],"issn-type":[{"value":"2667-2952","type":"print"}],"subject":[],"published":{"date-parts":[[2026,3]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A fast gray-box adversarial example generation algorithm based on FakeBob","name":"articletitle","label":"Article Title"},{"value":"High-Confidence Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100337","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Author(s). Published by Elsevier B.V. on behalf of Shandong University.","name":"copyright","label":"Copyright"}],"article-number":"100337"}}