{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T09:02:18Z","timestamp":1753520538751,"version":"3.33.0"},"reference-count":38,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1109\/slt61566.2024.10832144","type":"proceedings-article","created":{"date-parts":[[2025,1,16]],"date-time":"2025-01-16T18:31:27Z","timestamp":1737052287000},"page":"1107-1114","source":"Crossref","is-referenced-by-count":1,"title":["Clean Label Attacks Against SLU Systems"],"prefix":"10.1109","author":[{"given":"Henry Li","family":"Xinyuan","sequence":"first","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]},{"given":"Sonal","family":"Joshi","sequence":"additional","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]},{"given":"Thomas","family":"Thebaud","sequence":"additional","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]},{"given":"Jesus","family":"Villalba","sequence":"additional","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]},{"given":"Najim","family":"Dehak","sequence":"additional","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]},{"given":"Sanjeev","family":"Khudanpur","sequence":"additional","affiliation":[{"name":"Johns Hopkins University,Center for Language and Speech Processing,USA"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1467","article-title":"Poisoning attacks against support vector machines","volume-title":"Proceedings of the 29th International Coference on International Conference on Machine Learning","volume":"2012","author":"Biggio"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i13.26921"},{"article-title":"Badtrack: A poison-only backdoor attack on visual object tracking","volume-title":"Thirty-seventh Conference on Neural Information Processing Systems","author":"Huang","key":"ref5"},{"article-title":"Forcing generative models to degenerate ones: The power of data poisoning attacks","volume-title":"NeurIPS 2023 Workshop on Backdoors in Deep Learning-The Good, the Bad, and the Ugly","author":"Jiang","key":"ref6"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.012.2200596"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ASRU57964.2023.10389676"},{"article-title":"Language models are few-shot learners","year":"2020","author":"Brown","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450034"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-acl.127"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179331"},{"article-title":"Label-consistent backdoor attacks","year":"2019","author":"Turner","key":"ref14"},{"key":"ref15","article-title":"Venomave: Clean-label poisoning against speech recognition","author":"Aghakhani","year":"2020","journal-title":"Computing Research Repository (CoRR), abs\/2010.10682"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SPW59333.2023.00010"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2022-10340"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66415-2_4"},{"article-title":"Simple, attack-agnostic defense against targeted training set attacks using cosine similarity","year":"2021","author":"Hammoudeh","key":"ref19"},{"key":"ref20","first-page":"25 154","article-title":"Not all poisons are created equal: Robust training against data poisoning","volume-title":"Proceedings of the 39th International Conference on Machine Learning, ser. Proceedings of Machine Learning Research","volume":"162","author":"Yang"},{"key":"ref21","article-title":"What doesn\u2019t kill you makes you robust (er): How to adversarially train against data poisoning","author":"Geiping","year":"2021","journal-title":"arXiv preprint arXiv:2102.13624"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-2396"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24797-2"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-3015"},{"key":"ref25","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint arXiv:1712.05526"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ASRU57964.2023.10389650"},{"key":"ref27","article-title":"Multitrigger backdoor attacks: More triggers, more threats","author":"Li","year":"2024","journal-title":"arXiv preprint arXiv:2401.15295"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/wacv56688.2023.00141"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/DSC53577.2021.00037"},{"key":"ref30","article-title":"Adversarial music: Real world audio adversary against wake-word detection system","volume":"32","author":"Li","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2019","author":"Madry","key":"ref31"},{"key":"ref32","article-title":"Convex Optimization","author":"Boyd","year":"2004","journal-title":"Cambridge University Press"},{"author":"He","key":"ref33","article-title":"Confidence-driven sampling for backdoor attacks"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.21437\/odyssey.2024-24"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.21437\/interspeech.2022-10977"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2018-1929"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"article-title":"Mitigating adversarial effects through randomization","year":"2018","author":"Xie","key":"ref38"}],"event":{"name":"2024 IEEE Spoken Language Technology Workshop (SLT)","start":{"date-parts":[[2024,12,2]]},"location":"Macao","end":{"date-parts":[[2024,12,5]]}},"container-title":["2024 IEEE Spoken Language Technology Workshop (SLT)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10830790\/10830793\/10832144.pdf?arnumber=10832144","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,17]],"date-time":"2025-01-17T07:49:49Z","timestamp":1737100189000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10832144\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/slt61566.2024.10832144","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]}}}