{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:57:46Z","timestamp":1773511066151,"version":"3.50.1"},"reference-count":42,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179331","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"1667-1683","source":"Crossref","is-referenced-by-count":11,"title":["TrojanModel: A Practical Trojan Attack against Automatic Speech Recognition Systems"],"prefix":"10.1109","author":[{"given":"Wei","family":"Zong","sequence":"first","affiliation":[{"name":"University of Wollongong,Institute of Cybersecurity and Cryptology (iC&#x00B2;),Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang-Wai","family":"Chow","sequence":"additional","affiliation":[{"name":"University of Wollongong,Institute of Cybersecurity and Cryptology (iC&#x00B2;),Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Willy","family":"Susilo","sequence":"additional","affiliation":[{"name":"University of Wollongong,Institute of Cybersecurity and Cryptology (iC&#x00B2;),Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kien","family":"Do","sequence":"additional","affiliation":[{"name":"Deakin University,Applied Artificial Intelligence Institute (A&#x00B2;I&#x00B2;),Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Svetha","family":"Venkatesh","sequence":"additional","affiliation":[{"name":"Deakin University,Applied Artificial Intelligence Institute (A&#x00B2;I&#x00B2;),Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00014"},{"key":"ref2","first-page":"173","article-title":"Deep speech 2: End-to-end speech recognition in english and mandarin","volume-title":"International conference on machine learning","author":"Amodei"},{"key":"ref3","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"International conference on machine learning","author":"Athalye"},{"key":"ref4","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2016.7472621"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23055"},{"key":"ref8","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.21437\/odyssey.2020-62"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2021.3073596"},{"key":"ref11","article-title":"Design and evaluation of a multi-domain trojandetection method on deep neural networks","author":"Gao","year":"2021","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143891"},{"key":"ref13","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref14","article-title":"Deep speech: Scaling up end-to-end speech recognition","author":"Hannun","year":"2014"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref16","first-page":"2273","article-title":"WaveGuard: Understanding and mitigating audio adversarial examples","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Hussain"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1406.3269"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD49262.2021.9437669"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423348"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5928"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ISQED48828.2020.9137011"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SIBGRAPI.2018.00067"},{"key":"ref27","article-title":"The natural language decathlon: Multitask learning as question answering","author":"McCann","year":"2018","journal-title":"CoRR"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref29","article-title":"Wanet - imperceptible warping-based backdoor attack","volume-title":"9th International Conference on Learning Representations, ICLR 2021, Virtual Event","author":"Nguyen"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref31","first-page":"5231","article-title":"Imperceptible, robust, and targeted adversarial examples for automatic speech recognition","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019","author":"Qin"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2001.941023"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461310"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427276"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-1955"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1176"},{"key":"ref39","article-title":"Characterizing audio adversarial examples using temporal dependency","volume-title":"7th International Conference on Learning Representations, ICLR 2019","author":"Yang"},{"key":"ref40","article-title":"Gradient surgery for multi-task learning","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual","author":"Yu"},{"key":"ref41","first-page":"49","article-title":"Commandersong: A systematic approach for practical adversarial voice recognition","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Yuan"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01453"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179331.pdf?arnumber=10179331","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:18:16Z","timestamp":1721452696000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179331\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179331","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}