{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:04:52Z","timestamp":1775837092637,"version":"3.50.1"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["2020AAA0107700"],"award-info":[{"award-number":["2020AAA0107700"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172359"],"award-info":[{"award-number":["62172359"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62032021"],"award-info":[{"award-number":["62032021"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972348"],"award-info":[{"award-number":["61972348"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102354"],"award-info":[{"award-number":["62102354"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772236"],"award-info":[{"award-number":["61772236"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Funding for Postdoctoral Scientific Research Projects in Zhejiang Province","award":["ZJ2021139"],"award-info":[{"award-number":["ZJ2021139"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2021FZZX001-27"],"award-info":[{"award-number":["2021FZZX001-27"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004835","name":"Zhejiang University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004835","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2046335"],"award-info":[{"award-number":["CNS-2046335"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2034870"],"award-info":[{"award-number":["CNS-2034870"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2308730"],"award-info":[{"award-number":["CNS-2308730"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2302689"],"award-info":[{"award-number":["CNS-2302689"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,1]]},"DOI":"10.1109\/tdsc.2023.3242292","type":"journal-article","created":{"date-parts":[[2023,2,6]],"date-time":"2023-02-06T18:59:01Z","timestamp":1675709941000},"page":"31-46","source":"Crossref","is-referenced-by-count":12,"title":["UniAP: Protecting Speech Privacy With Non-Targeted Universal Adversarial Perturbations"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4453-2274","authenticated-orcid":false,"given":"Peng","family":"Cheng","sequence":"first","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]},{"given":"Yuexin","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4095-4506","authenticated-orcid":false,"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut, Stamford, CT, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0921-8869","authenticated-orcid":false,"given":"Zhongjie","family":"Ba","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5240-5200","authenticated-orcid":false,"given":"Feng","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5230-3749","authenticated-orcid":false,"given":"Li","family":"Lu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Amazon hands over echo \u2018murder\u2019 data","year":"2017"},{"key":"ref2","article-title":"Amazon transcribe","year":"2018"},{"key":"ref3","article-title":"Dont buy anyone an echo","author":"Estes","year":"2017"},{"key":"ref4","article-title":"Nest secures control hub has a microphone \u2013 users only found out when it became google assistant enabled this week","year":"2019"},{"key":"ref5","article-title":"Is anyone listening to you on Alexa? a global team reviews audio","year":"2019"},{"key":"ref6","article-title":"Yep, human workers are listening to recordings from google assistant, too","author":"Verge","year":"2019"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3384419.3430727"},{"key":"ref8","article-title":"2018 reform of EU data protection rules","year":"2018"},{"key":"ref9","article-title":"California consumer privacy act (CCPA)","year":"2018"},{"key":"ref10","article-title":"Whats new in android privacy","author":"Blog","year":"2021"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376304"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0077"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081366"},{"key":"ref14","first-page":"547","article-title":"Inaudible voice commands: The long-range attack and defense","volume-title":"Proc. 15th USENIX Symp. Netw. Syst. Des. Implementation","author":"Roy","year":"2018"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24551"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00009"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref18","first-page":"49","article-title":"CommanderSong: A systematic approach for practical adversarial voice recognition","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Yuan","year":"2018"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23288"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23055"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423348"},{"key":"ref22","article-title":"Deep speech: Scaling up end-to-end speech recognition","author":"Hannun","year":"2014"},{"key":"ref23","article-title":"Real-time neural voice camouflage","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chiquier","year":"2022"},{"key":"ref24","article-title":"Did you hear that? adversarial examples against automatic speech recognition","author":"Alzantot","year":"2018"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427276"},{"key":"ref26","first-page":"2667","article-title":"Devils whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Chen","year":"2020"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485383"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1353"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref30","article-title":"Universal adversarial examples in speech command classification","author":"Vadillo","year":"2019"},{"key":"ref31","article-title":"Understanding LSTM Networks","author":"Olah","year":"2015"},{"key":"ref32","article-title":"Mycroft","year":"2016"},{"key":"ref33","article-title":"Swiftscribe","year":"2017"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3274371"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243777"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1201\/9781420015836"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00016"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/741"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA52953.2021.00135"},{"key":"ref40","article-title":"Project DeepSpeech","year":"2017"},{"key":"ref41","first-page":"965","article-title":"Acoustical sound database in real environments for sound scene understanding and hands-free speech recognition","volume-title":"Proc. 2nd Int. Conf. Lang. Resour. Eval.","author":"Nakamura","year":"2000"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/d18-2029"},{"key":"ref43","volume-title":"The Scientist and Engineers Guide to Digital Signal Processing","author":"Smith","year":"1997"},{"key":"ref44","article-title":"Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition","author":"Qin","year":"2019"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICDSP.2009.5201259"},{"issue":"3","key":"ref46","first-page":"130","article-title":"Calculation of the absorption of sound by the atmosphere ISO 9613-1","volume":"21","author":"Yoshihisa","year":"1997","journal-title":"J. INCE Jpn."},{"key":"ref47","first-page":"2309","article-title":"Dompteur: Taming audio adversarial examples","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Eisenhofer","year":"2021"},{"key":"ref48","article-title":"SpeechBrain: A general-purpose speech toolkit","author":"Ravanelli","year":"2021"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2021-1965"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2018-1456"},{"key":"ref51","article-title":"Speech commands: A dataset for limited-vocabulary speech recognition","author":"Warden","year":"2018"},{"key":"ref52","first-page":"1","article-title":"Universal adversarial head: Practical protection against video data leakage","volume-title":"Proc. Workshop Adv. Mach. Learn.","author":"Bai","year":"2021"},{"key":"ref53","first-page":"2705","article-title":"Defeating DNN-based traffic analysis systems in real-time with blind adversarial perturbations","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Nasr","year":"2021"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/MLSP.2019.8918913"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2018-2032"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2019.06.001"},{"key":"ref57","first-page":"4490","article-title":"TAPAS: Tricks to accelerate (encrypted) prediction as a service","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sanyal","year":"2018"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICME46284.2020.9102886"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053747"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2021-1668"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-91356-4_19"},{"key":"ref62","article-title":"Amazon transcribe","year":"2022"},{"key":"ref63","article-title":"Speech-to-text conversion powered by machine learning","year":"2021"},{"key":"ref64","article-title":"iflytek speech transcribe","year":"2022"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/8858\/10400751\/10037237-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10400751\/10037237.pdf?arnumber=10037237","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T17:33:53Z","timestamp":1727804033000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10037237\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1]]},"references-count":65,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2023.3242292","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1]]}}}