{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T01:22:21Z","timestamp":1755998541836,"version":"3.37.3"},"reference-count":77,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"China NSFC","doi-asserted-by":"publisher","award":["62201503","61925109","62222114","62071428","62271280"],"award-info":[{"award-number":["62201503","61925109","62222114","62071428","62271280"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["226-2022-00223"],"award-info":[{"award-number":["226-2022-00223"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2024,4,15]]},"DOI":"10.1109\/jiot.2023.3328253","type":"journal-article","created":{"date-parts":[[2023,10,30]],"date-time":"2023-10-30T19:25:53Z","timestamp":1698693953000},"page":"13108-13124","source":"Crossref","is-referenced-by-count":5,"title":["Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial Ultrasound"],"prefix":"10.1109","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9686-4369","authenticated-orcid":false,"given":"Xinfeng","family":"Li","sequence":"first","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]},{"given":"Junning","family":"Ze","sequence":"additional","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4430-5263","authenticated-orcid":false,"given":"Chen","family":"Yan","sequence":"additional","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]},{"given":"Yushi","family":"Cheng","sequence":"additional","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1101-0007","authenticated-orcid":false,"given":"Xiaoyu","family":"Ji","sequence":"additional","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]},{"given":"Wenyuan","family":"Xu","sequence":"additional","affiliation":[{"name":"USSLAB, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"volume-title":"How banking virtual assistants can improve your banking experience","year":"2022","author":"Ben Gran","key":"ref1"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417254"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3212480.3212505"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"ref5","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560531"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-21280-2_26"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00004"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423348"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3376897.3377856"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/7503.003.0105"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"issue":"1","key":"ref14","first-page":"949","article-title":"Natural evolution strategies","volume":"15","author":"Wierstra","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2650"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/icassp40776.2020.9052974"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683120"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2022.3188113"},{"key":"ref19","article-title":"SpeakerNet: 1D depth-wise separable convolutional network for text-independent speaker recognition and verification","author":"Koluguri","year":"2020","journal-title":"arXiv:2010.12653"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8462665"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.21437\/interspeech.2020-1064"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2017-950"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66218-9_27"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-25948-0_86"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1121\/1.399423"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2010.2064307"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461375"},{"key":"ref30","first-page":"1131","article-title":"\u2018OK, Siri\u2019 or \u2018Hey, Google\u2019: Evaluating voiceprint distinctiveness via content-based PROLE score","volume-title":"Proc. 31th USENIX Security Symp.","author":"He"},{"key":"ref31","doi-asserted-by":"crossref","DOI":"10.4249\/scholarpedia.3715","volume-title":"Speaker recognition","author":"Furui","year":"2008"},{"key":"ref32","first-page":"547","article-title":"Inaudible voice commands: The long-range attack and defense","volume-title":"Proc. 15th USENIX Symp. Netw. Syst. Design Implement. (NSDI)","author":"Roy"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485389"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24068"},{"key":"ref35","first-page":"2631","article-title":"Light commands: Laser-based audio injection attacks on voice-controllable systems","volume-title":"Proc. 29th USENIX Security Symp. (USENIX Security)","author":"Sugawara"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24254"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37337-5_29"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2022-463"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1121\/1.415166"},{"key":"ref40","first-page":"3457","article-title":"Infected phonemes: How a cold impairs speech on a phonetic level","volume-title":"Proc. 18th Annu. Conf. Int. Speech Commun. Assoc.","author":"Wagner"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3023818"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.specom.2022.03.010"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-1191"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1111\/j.2517-6161.1996.tb02080.x"},{"volume-title":"Sound physics","year":"2019","author":"Berg","key":"ref45"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24551"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICDSP.2009.5201259"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559357"},{"key":"ref49","first-page":"2455","article-title":"Learning normality is enough: A software-based mitigation against the inaudible voice attacks","volume-title":"Proc. 32nd USENIX Security Symp.","author":"Li"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24457"},{"key":"ref51","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"volume-title":"EXG X-series signal generator","year":"2019","key":"ref52"},{"volume-title":"NF HSA4015","year":"2013","key":"ref53"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICSDA.2017.8384449"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2826"},{"key":"ref56","article-title":"Short-duration speaker verification (SdSV) challenge 2021: The challenge evaluation plan","author":"Zeinali","year":"2019","journal-title":"arXiv:1912.06311"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2662"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2007.902876"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.21437\/Odyssey.2020-26"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278497"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2012.6288857"},{"volume-title":"Freesound","year":"2022","key":"ref62"},{"key":"ref63","first-page":"49","article-title":"CommanderSong: A systematic approach for practical adversarial voice recognition","volume-title":"Proc. 27th USENIX Security Symp.","author":"Yuan"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23030"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3300061.3345429"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2018.8486283"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354248"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/jiot.2023.3290001"},{"key":"ref69","article-title":"Can you hear it? Backdoor attacks via ultrasonic triggers","author":"Koffas","year":"2021","journal-title":"arXiv:2107.14569"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2023.3293429"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23362"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413467"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i16.17663"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3182979"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2906165"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23030"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/10495736\/10301792.pdf?arnumber=10301792","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,10]],"date-time":"2024-04-10T18:25:38Z","timestamp":1712773538000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10301792\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,15]]},"references-count":77,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2023.3328253","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"type":"electronic","value":"2327-4662"},{"type":"electronic","value":"2372-2541"}],"subject":[],"published":{"date-parts":[[2024,4,15]]}}}