{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T14:15:47Z","timestamp":1775225747329,"version":"3.50.1"},"reference-count":60,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["2022ZD0160103"],"award-info":[{"award-number":["2022ZD0160103"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62276067"],"award-info":[{"award-number":["62276067"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"ARC Project","award":["DP210102447"],"award-info":[{"award-number":["DP210102447"]}]},{"name":"ARC Linkage Project","award":["LP190100676"],"award-info":[{"award-number":["LP190100676"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE\/ACM Trans. Audio Speech Lang. Process."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/taslp.2023.3304476","type":"journal-article","created":{"date-parts":[[2023,9,1]],"date-time":"2023-09-01T17:31:46Z","timestamp":1693589506000},"page":"3981-3992","source":"Crossref","is-referenced-by-count":10,"title":["Query-Efficient Black-Box Adversarial Attacks on Automatic Speech Recognition"],"prefix":"10.1109","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1800-1290","authenticated-orcid":false,"given":"Chuxuan","family":"Tong","sequence":"first","affiliation":[{"name":"School of Information Technology, Deakin University, Geelong, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2572-2355","authenticated-orcid":false,"given":"Xi","family":"Zheng","sequence":"additional","affiliation":[{"name":"Department of Computing, Macquarie University, Sydney, NSW, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5878-6032","authenticated-orcid":false,"given":"Jianhua","family":"Li","sequence":"additional","affiliation":[{"name":"School of Information Technology, Deakin University, Geelong, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2099-4973","authenticated-orcid":false,"given":"Xingjun","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University and Shanghai Artificial Intelligence Laboratory, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3026-7537","authenticated-orcid":false,"given":"Longxiang","family":"Gao","sequence":"additional","affiliation":[{"name":"Shandong Computer Science Center (National Supercomputer Center in Jinan), Qilu University of Technology (Shandong Academy of Sciences), Jinan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3545-7863","authenticated-orcid":false,"given":"Yong","family":"Xiang","sequence":"additional","affiliation":[{"name":"School of Information Technology, Deakin University, Geelong, VIC, Australia"}]}],"member":"263","reference":[{"key":"ref13","first-page":"49","article-title":"Commandersong: A systematic approach for practical adversarial voice recognition","author":"yuan","year":"0","journal-title":"Proc 27th USENIX Conf Secur Symp"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref12","first-page":"854","article-title":"High intrinsic dimensionality facilitates adversarial attack: Theoretical evidence","volume":"60","author":"amsaleg","year":"2020","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"ref56","first-page":"3935","article-title":"Enhancing the TED-LIUM corpus with selected data for language modeling and more ted talks","author":"rousseau","year":"0","journal-title":"Proc 9th Int Conf Lang Resour Eval"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI47803.2020.9308597"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/741"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2001.941023"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485383"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3026543"},{"key":"ref11","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2020\/438"},{"key":"ref17","first-page":"2667","article-title":"Devil's whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices","author":"chen","year":"0","journal-title":"Proc 29th USENIX Conf Secur Symp"},{"key":"ref16","first-page":"2631","article-title":"Light commands: Laser-based audio injection attacks on voice-controllable systems","author":"sugawara","year":"0","journal-title":"Proc 29th USENIX Secur Symp"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00016"},{"key":"ref18","first-page":"712","article-title":"Hear &#x201C;no evil,&#x201D; see &#x201C;kenansville&#x201D;: Efficient and transferable black-box attacks on automatic speech recognition systems","author":"abdullah","year":"0","journal-title":"Proc IEEE Symp Secur Privacy"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23362"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24068"},{"key":"ref46","first-page":"1","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"cheng","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref45","first-page":"1","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"ilyas","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref48","first-page":"5231","article-title":"Imperceptible, robust, and targeted adversarial examples for automatic speech recognition","author":"qin","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref42","first-page":"1","article-title":"Skip connections matter: On the transferability of adversarial examples generated with resnets","author":"wu","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_10"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00014"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref9","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"ref3","article-title":"Case-aware adversarial training","author":"fan","year":"2022"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143891"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30194-3_13"},{"key":"ref37","first-page":"707","article-title":"Binary codes capable of correcting deletions, insertions, and reversals","volume":"10","author":"levenshtein","year":"1966","journal-title":"Sov Phys Doklady"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00008"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1561\/116.00000050"},{"key":"ref30","first-page":"11","article-title":"Mel frequency cepstral coefficients for music modeling","author":"logan","year":"0","journal-title":"Proc Int Symp Music Inf Retrieval"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.21437\/Eurospeech.2003-382"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ASRU46091.2019.9003750"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref1","first-page":"1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref39","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016"},{"key":"ref38","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"ref23","first-page":"1327","article-title":"Hybrid batch attacks: Finding black-box adversarial examples with limited queries","author":"suya","year":"0","journal-title":"Proc 29th USENIX Conf Secur Symp"},{"key":"ref26","first-page":"33","article-title":"Fairseq S2T: Fast speech-to-text modeling with fairseq","author":"wang","year":"0","journal-title":"Proc 1st Conf Asia-Pacific Chapter Assoc Comput Linguistics 10th Int Joint Conf Natural Lang Process Syst Demonstrations"},{"key":"ref25","first-page":"173","article-title":"Deep speech 2: End-to-end speech recognition in english and mandarin","author":"amodei","year":"0","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384733"},{"key":"ref22","first-page":"10934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","author":"cheng","year":"0","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1819"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1561\/9781601980717"},{"key":"ref29","article-title":"Wav2Letter: An end-to-end convnet-based speech recognition system","author":"collobert","year":"2016"},{"key":"ref60","first-page":"1","article-title":"Characterizing audio adversarial examples using temporal dependency","author":"yang","year":"0","journal-title":"Proc Int Conf Learn Representations"}],"container-title":["IEEE\/ACM Transactions on Audio, Speech, and Language Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6570655\/9970249\/10237306.pdf?arnumber=10237306","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,13]],"date-time":"2023-11-13T19:34:30Z","timestamp":1699904070000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10237306\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":60,"URL":"https:\/\/doi.org\/10.1109\/taslp.2023.3304476","relation":{},"ISSN":["2329-9290","2329-9304"],"issn-type":[{"value":"2329-9290","type":"print"},{"value":"2329-9304","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}