{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T03:18:01Z","timestamp":1778901481563,"version":"3.51.4"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572286"],"award-info":[{"award-number":["62572286"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62422208"],"award-info":[{"award-number":["62422208"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62232010"],"award-info":[{"award-number":["62232010"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62350410480"],"award-info":[{"award-number":["62350410480"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shandong Science Fund","award":["ZR2024MF108"],"award-info":[{"award-number":["ZR2024MF108"]}]},{"name":"Shandong Science Fund","award":["ZR2025LZH006"],"award-info":[{"award-number":["ZR2025LZH006"]}]},{"name":"Shandong Science Fund","award":["ZR2024MF149"],"award-info":[{"award-number":["ZR2024MF149"]}]},{"name":"Ministry of Industry and Information Technology of China","award":["TC240A9ED-70"],"award-info":[{"award-number":["TC240A9ED-70"]}]},{"name":"Research Project of Quancheng Laboratory, China","award":["QCL20250106"],"award-info":[{"award-number":["QCL20250106"]}]},{"name":"Key Laboratory of Computing Power Network and Information Security"},{"DOI":"10.13039\/100010449","name":"Ministry of Education","doi-asserted-by":"publisher","award":["2024ZD012"],"award-info":[{"award-number":["2024ZD012"]}],"id":[{"id":"10.13039\/100010449","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tdsc.2026.3660980","type":"journal-article","created":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T20:50:49Z","timestamp":1770238249000},"page":"6119-6136","source":"Crossref","is-referenced-by-count":0,"title":["Adversarial Attacks on Closed Box Speech Recognition Systems via Laser Injection"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-0164-1384","authenticated-orcid":false,"given":"Huiting","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8003-0669","authenticated-orcid":false,"given":"Guoming","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1919-1680","authenticated-orcid":false,"given":"Xiaohui","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0231-8448","authenticated-orcid":false,"given":"Zhijie","family":"Xiang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5723-0614","authenticated-orcid":false,"given":"Yanni","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1101-0007","authenticated-orcid":false,"given":"Xiaoyu","family":"Ji","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5912-4647","authenticated-orcid":false,"given":"Xiuzhen","family":"Cheng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7935-886X","authenticated-orcid":false,"given":"Pengfei","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00014"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3510582"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref4","first-page":"49","article-title":"CommanderSong: A systematic approach for practical adversarial voice recognition","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Yuan"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423348"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23288"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2022.100098"},{"key":"ref8","article-title":"Real world audio adversary against wake-word detection systems","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref9","first-page":"5231","article-title":"Imperceptible, robust, and targeted adversarial examples for automatic speech recognition","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Qin"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559357"},{"key":"ref11","first-page":"2631","article-title":"Light commands: Laser-Based audio injection attacks on voice-controllable systems","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Sugawara"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559350"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560531"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICDSP.2009.5201259"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/741"},{"key":"ref16","article-title":"Google text-to-speech","year":"2023"},{"key":"ref17","first-page":"2667","article-title":"Devil\u2019s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices","volume-title":"Proc. USENIX Secur. Symp.","author":"Chen"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485383"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00004"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-10997-4_50"},{"key":"ref21","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref22","article-title":"Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets","author":"Balaji","year":"2019"},{"key":"ref23","first-page":"1829","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref24","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref25","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020"},{"key":"ref26","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref27","article-title":"On the convergence and robustness of adversarial training","author":"Wang","year":"2021"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24551"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363264"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3242292"},{"key":"ref31","article-title":"FAAG: Fast adversarial audio generation through interactive attack optimisation","author":"Miao","year":"2022"},{"key":"ref32","article-title":"Audio injection adversarial example attack","volume-title":"Proc. ICML 2021 Workshop Adversarial Mach. Learn.","author":"Liu"},{"key":"ref33","article-title":"VoiceBlock: Privacy through real-time adversarial attacks with audio-to-audio models","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"O\u2019Reilly"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045597"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23362"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23055"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196506"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2185448.2185453"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40349-1_4"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21513"},{"issue":"8","key":"ref41","first-page":"109","article-title":"Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle","volume":"24","author":"Yan","year":"2016","journal-title":"DEF CON"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24616"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.20"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2023.100129"},{"key":"ref46","article-title":"UNI-T UT385","year":"2024"},{"key":"ref47","first-page":"1106","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Krizhevsky"},{"key":"ref48","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3355117"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23030"},{"key":"ref51","first-page":"247","article-title":"KENKU: Towards efficient and stealthy black-box adversarial attacks against ASR systems","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Wu"},{"key":"ref52","first-page":"547","article-title":"Inaudible voice commands: The long-range attack and defense","volume-title":"Proc. 15th USENIX Symp. Netw. Syst. Des. Implementation","author":"Roy"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11517592\/11371711.pdf?arnumber=11371711","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T03:03:49Z","timestamp":1778900629000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11371711\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":52,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3660980","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}