{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:26:17Z","timestamp":1783787177946,"version":"3.55.0"},"reference-count":80,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["HR001119S0026-GARD-FP-052"],"award-info":[{"award-number":["HR001119S0026-GARD-FP-052"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tifs.2021.3116438","type":"journal-article","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T20:52:24Z","timestamp":1632948744000},"page":"4811-4826","source":"Crossref","is-referenced-by-count":44,"title":["Study of Pre-Processing Defenses Against Adversarial Attacks on State-of-the-Art Speaker Recognition Systems"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8020-7551","authenticated-orcid":false,"given":"Sonal","family":"Joshi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9459-8426","authenticated-orcid":false,"given":"Jesus","family":"Villalba","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8245-0413","authenticated-orcid":false,"given":"Piotr","family":"Zelasko","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3033-7005","authenticated-orcid":false,"given":"Laureano","family":"Moro-Velazquez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4489-5753","authenticated-orcid":false,"given":"Najim","family":"Dehak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053795"},{"key":"ref72","first-page":"2059","article-title":"Denoising criterion for variational auto-encoding framework","volume":"31","author":"im","year":"2017","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref71","article-title":"Deep variational information bottleneck","author":"alemi","year":"2017","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref70","article-title":"Auto-encoding variational Bayes","author":"kingma","year":"2014","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref76","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume":"32","author":"paszke","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2019.101027"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2834"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-6393(99)00080-1"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-1955"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.207"},{"key":"ref79","first-page":"223","article-title":"The CMU Arctic speech databases","author":"kominek","year":"2004","journal-title":"Proc ISCA Speech Synth Workshop"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461375"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/741"},{"key":"ref31","first-page":"471","article-title":"Imperio: Robust over-the-air adversarial examples for automatic speech recognition systems","author":"sch\u00f6nherr","year":"2020","journal-title":"Proc Comput Secur Appl Conf"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23288"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICME46284.2020.9102886"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053747"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053076"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2010.2064307"},{"key":"ref60","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"tramer","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref61","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/SLT.2018.8639585"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3026543"},{"key":"ref64","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","author":"cohen","year":"2019","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1353"},{"key":"ref65","article-title":"MUSAN: A music, speech, and noise corpus","author":"snyder","year":"2015","journal-title":"arXiv 1510 08484 [cs]"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2017.7953152"},{"key":"ref29","first-page":"2667","article-title":"Devil&#x2019;s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices","author":"chen","year":"2020","journal-title":"Proc Usenix Secur Symp"},{"key":"ref67","first-page":"214","article-title":"Wasserstein generative adversarial networks","author":"arjovsky","year":"2017","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref68","article-title":"Adversarial audio synthesis","author":"donahue","year":"2019","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref69","first-page":"5767","article-title":"Improved training of Wasserstein GANs","author":"gulrajani","year":"2017","journal-title":"Proc Int Conf Neural Inf Process Syst (NIPS)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.specom.2014.10.005"},{"key":"ref1","first-page":"4213","article-title":"The Attacker&#x2019;s perspective on automatic speaker verification: An overview","author":"das","year":"2020","journal-title":"Proc INTERSPEECH"},{"key":"ref20","first-page":"730","article-title":"SoK: The faults in our ASRs: An overview of attacks against automatic speech recognition and speaker identification systems","author":"abdullah","year":"2021","journal-title":"Proc IEEE Symp Secur Privacy (SP)"},{"key":"ref22","first-page":"173","article-title":"DeepSpeech 2: End-to-end speech recognition in English and Mandarin","author":"amodei","year":"2016","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref21","first-page":"513","article-title":"Hidden voice commands","author":"carlini","year":"2016","journal-title":"Proc Usenix Secur Symp"},{"key":"ref24","first-page":"2672","article-title":"Generative adversarial nets","volume":"27","author":"goodfellow","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref23","first-page":"125","article-title":"WaveNet: A generative model for raw audio","author":"van den oord","year":"2016","journal-title":"Proc ISCA Speech Synth Workshop"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683713"},{"key":"ref25","first-page":"49","article-title":"Commandersong: A systematic approach for practical adversarial voice recognition","author":"yuan","year":"2018","journal-title":"Proc Usenix Secur Symp"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2441"},{"key":"ref51","article-title":"Characterizing audio adversarial examples using temporal dependency","author":"yang","year":"2019","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref59","first-page":"5998","article-title":"Attention is all you need","author":"vaswani","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref58","first-page":"6105","article-title":"EfficientNet: Rethinking model scaling for convolutional neural networks","author":"tan","year":"2019","journal-title":"Proc Int Conf Mach Learn (ICML)"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2019.101026"},{"key":"ref56","article-title":"BUT system description to VoxCeleb speaker recognition challenge 2019","author":"zeinali","year":"2019","journal-title":"Proc VoxCeleb Challange Workshop"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2017-620"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60276-5_3"},{"key":"ref52","first-page":"2565","article-title":"Class-conditional defense GAN against end-to-end speech attacks","author":"esmaeilpour","year":"2021","journal-title":"Proc IEEE Int Conf Acoust Speech Signal Process (ICASSP)"},{"key":"ref10","article-title":"Adversarial examples in physical world","author":"wang","year":"2021","journal-title":"Proc Workshop Track Int Conf Learn Represent (ICLR)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"ref40","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref13","article-title":"Cocaine noodles: Exploiting the gap between human and machine speech recognition","author":"vaidya","year":"2015","journal-title":"Proc USENIX Workshop Offensive Technol (WOOT)"},{"key":"ref14","article-title":"Generating adversarial examples for speech recognition","author":"iter","year":"2017"},{"key":"ref15","first-page":"6980","article-title":"Houdini: Fooling deep structured prediction models","author":"cisse","year":"2017","journal-title":"Proc Int Conf Neural Inf Process Syst (NIPS)"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8462693"},{"key":"ref18","article-title":"Crafting adversarial examples for deep learning based prognostics","author":"mode","year":"2020","journal-title":"Proc 19th IEEE Int Conf Mach Learn Appl (ICMLA)"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-9129-7_31"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2018-1929"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1017\/ATSIP.2019.21"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-2249"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2458"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1794"},{"key":"ref8","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ISSPIT.2018.8642623"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref46","first-page":"6164","article-title":"Adversarial defense for deep speaker recognition using hybrid adversarial training","author":"pal","year":"2021","journal-title":"Proc IEEE Int Conf Acoust Speech Signal Process (ICASSP)"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2021.101199"},{"key":"ref48","article-title":"Perceptual adversarial robustness: Defense against unseen threat models","author":"laidlaw","year":"2021","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref47","article-title":"The limitations of adversarial training and the blind-spot attack","author":"zhang","year":"2019","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref42","article-title":"Defense-GAN: Protecting classifiers against adversarial attacks using generative models","author":"samangouei","year":"2018","journal-title":"Proc Int Conf Learn Represent (ICLR)"},{"key":"ref41","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2018","journal-title":"Int Conf Learn Represent (ICLR)"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-2983"},{"key":"ref43","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent (ICLR)"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9151439\/09551961.pdf?arnumber=9551961","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:52:34Z","timestamp":1652194354000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9551961\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":80,"URL":"https:\/\/doi.org\/10.1109\/tifs.2021.3116438","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}