{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T06:53:38Z","timestamp":1774508018285,"version":"3.50.1"},"reference-count":69,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2016"],"award-info":[{"award-number":["U21B2016"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272145"],"award-info":[{"award-number":["62272145"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2336208"],"award-info":[{"award-number":["U2336208"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Shenzhen Science and Technology Program","doi-asserted-by":"publisher","award":["KQTD20221101093559018"],"award-info":[{"award-number":["KQTD20221101093559018"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3404885","type":"journal-article","created":{"date-parts":[[2024,5,23]],"date-time":"2024-05-23T17:42:16Z","timestamp":1716486136000},"page":"5852-5866","source":"Crossref","is-referenced-by-count":31,"title":["Toward Stealthy Backdoor Attacks Against Speech Recognition via Elements of Sound"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3701-6383","authenticated-orcid":false,"given":"Hanbo","family":"Cai","sequence":"first","affiliation":[{"name":"College of Computer Science and Software Engineering, Hohai University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3594-408X","authenticated-orcid":false,"given":"Pengcheng","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Software Engineering, Hohai University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7033-5688","authenticated-orcid":false,"given":"Hai","family":"Dong","sequence":"additional","affiliation":[{"name":"School of Computing Technologies, RMIT University, Melbourne, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2563-083X","authenticated-orcid":false,"given":"Yan","family":"Xiao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Sun Yat-sen University, Shenzhen Campus, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6543-4801","authenticated-orcid":false,"given":"Stefanos","family":"Koffas","sequence":"additional","affiliation":[{"name":"Cybersecurity Group, Delft University of Technology, Delft, The Netherlands"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2258-265X","authenticated-orcid":false,"given":"Yiming","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3222963"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3229583"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10097275"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3237969"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3162397"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref8","first-page":"1","article-title":"BadPre: Task-agnostic backdoor attacks to pre-trained NLP foundation models","volume-title":"Proc. ICLR","author":"Chen"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833579"},{"key":"ref10","first-page":"1","article-title":"A unified evaluation of textual backdoor learning: Frameworks and benchmarks","volume-title":"Proc. NIPS","author":"Cui"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109512"},{"key":"ref12","first-page":"1","article-title":"Revisiting the assumption of latent separability for backdoor defenses","volume-title":"Proc. ICLR","author":"Qi"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560531"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3522783.3529523"},{"key":"ref17","article-title":"Adversarial audio: A new information hiding method and backdoor for DNN-based speech recognition models","author":"Kong","year":"2019","journal-title":"arXiv:1904.03829"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548261"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20096-0_45"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-21280-2_26"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/T-AIEE.1928.5055024"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1976.10158"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1561\/9781601981219"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref25","article-title":"Timit acoustic phonetic continuous speech corpus","author":"Garofolo","year":"4930"},{"key":"ref26","article-title":"A neural attention model for speech command recognition","author":"de Andrade","year":"2018","journal-title":"arXiv:1808.08929"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87802-3_69"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2021-1286"},{"key":"ref30","article-title":"End-to-end audio strikes back: Boosting augmentations towards an efficient audio classification network","author":"Gazneli","year":"2022","journal-title":"arXiv:2204.11479"},{"key":"ref31","first-page":"13238","article-title":"Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection","volume-title":"Proc. NIPS","author":"Li"},{"key":"ref32","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019","journal-title":"arXiv:1912.02771"},{"key":"ref33","first-page":"19165","article-title":"Sleeper agent: Scalable hidden trigger backdoors for neural networks trained from scratch","volume-title":"Proc. NIPS","author":"Souri"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616617"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3028448"},{"key":"ref36","article-title":"M-to-N backdoor paradigm: A stealthy and fuzzy attack to deep learning models","author":"Hou","year":"2022","journal-title":"arXiv:2211.01875"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"ref38","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref40","first-page":"1","article-title":"Backdoor attack in the physical world","volume-title":"Proc. ICLR Workshop","author":"Li"},{"key":"ref41","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. ICML","author":"Athalye"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096034"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096332"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265535"},{"key":"ref45","first-page":"1","article-title":"Domain watermark: Effective and harmless dataset copyright protection is closed at hand","volume-title":"Proc. NIPS","author":"Guo"},{"key":"ref46","first-page":"1","article-title":"Towards faithful XAI evaluation via generalization-limited backdoor watermark","volume-title":"Proc. ICLR","author":"Ya"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.7208\/chicago\/9780226191010.001.0001"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1523\/jneurosci.3815-12.2012"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1121\/1.381428"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.heares.2006.05.004"},{"key":"ref52","volume-title":"Psychoacoustics: Facts and Models","author":"Zwicker","year":"2013"},{"key":"ref53","volume-title":"Introduction to Signal Processing","author":"Orfanidis","year":"1995"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/j.specom.2017.01.008"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461375"},{"key":"ref56","volume-title":"Speech Commands: A Public Dataset for Single-Word Speech Recognition","author":"Warden","year":"2017"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178964"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2019.101027"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref60","article-title":"The vctk corpus: A multi-lingual corpus of read speech in a variety of accents","volume-title":"Proc. LREC","author":"Veaux"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.21437\/interspeech.2021-319"},{"key":"ref62","first-page":"1","article-title":"Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency","volume-title":"Proc. ICLR","author":"Guo"},{"key":"ref63","first-page":"38013","article-title":"UMD: Unsupervised model detection for X2X backdoor attacks","volume-title":"Proc. ICML","author":"Xiang"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-33377-4_33"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"issue":"11","key":"ref69","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10538215.pdf?arnumber=10538215","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,3]],"date-time":"2024-06-03T17:30:52Z","timestamp":1717435852000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10538215\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":69,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3404885","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}