{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T23:40:07Z","timestamp":1751931607471,"version":"3.41.2"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T00:00:00Z","timestamp":1754006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T00:00:00Z","timestamp":1754006400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T00:00:00Z","timestamp":1754006400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202274","62350410480"],"award-info":[{"award-number":["62202274","62350410480"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","award":["ZR2024MF149","ZR2024MF108"],"award-info":[{"award-number":["ZR2024MF149","ZR2024MF108"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Mobile Comput."],"published-print":{"date-parts":[[2025,8]]},"DOI":"10.1109\/tmc.2025.3555680","type":"journal-article","created":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T23:52:23Z","timestamp":1743465143000},"page":"7648-7662","source":"Crossref","is-referenced-by-count":0,"title":["UltraAdv: An Ultrasonic Adversarial Attack on Closed-Box Speech Recognition Systems"],"prefix":"10.1109","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8003-0669","authenticated-orcid":false,"given":"Guoming","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1919-1680","authenticated-orcid":false,"given":"Xiaohui","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0164-1384","authenticated-orcid":false,"given":"Huiting","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3878-7940","authenticated-orcid":false,"given":"Riccardo","family":"Spolaor","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5723-0614","authenticated-orcid":false,"given":"Yanni","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1101-0007","authenticated-orcid":false,"given":"Xiaoyu","family":"Ji","sequence":"additional","affiliation":[{"name":"Electrical Engineering, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5912-4647","authenticated-orcid":false,"given":"Xiuzhen","family":"Cheng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7935-886X","authenticated-orcid":false,"given":"Pengfei","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2022.100087"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref3","first-page":"49","article-title":"CommanderSong: A systematic approach for practical adversarial voice recognition","volume-title":"Proc. 27th {USENIX} Secur. Symp.","author":"Yuan"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423348"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3581791.3596837"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2019.2953041"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS56603.2022.00033"},{"key":"ref8","first-page":"547","article-title":"Inaudible voice commands: The long-range attack and defense","volume-title":"Proc. 15th USENIX Symp. Netw. Syst. Des. Implementation","author":"Roy"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23030"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559350"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23288"},{"key":"ref12","first-page":"11931","article-title":"Adversarial music: Real world audio adversary against wake-word detection systems","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref13","first-page":"5231","article-title":"Imperceptible, robust, and targeted adversarial examples for automatic speech recognition","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Qin"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559357"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"ref16","first-page":"2631","article-title":"Lightcommands: Laser-based audio injection attacks on voice-controllable systems","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Sugawara"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560531"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2906165"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081366"},{"year":"2024","key":"ref20","article-title":"Ultrasonic transducer"},{"year":"2024","key":"ref21","article-title":"RIGOL DG5072"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/741"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053747"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICDSP.2009.5201259"},{"year":"2024","key":"ref25","article-title":"Bluetooth speaker"},{"key":"ref26","first-page":"2667","article-title":"Devil\u2019s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices","volume-title":"Proc. USENIX Secur. Symp.","author":"Chen"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485383"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00004"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-10997-4_50"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref30"},{"article-title":"Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets","year":"2019","author":"Balaji","key":"ref31"},{"key":"ref32","first-page":"1829","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"Madry","key":"ref33"},{"article-title":"Fast is better than free: Revisiting adversarial training","year":"2020","author":"Wong","key":"ref34"},{"key":"ref35","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Shafahi"},{"article-title":"On the convergence and robustness of adversarial training","year":"2021","author":"Wang","key":"ref36"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24551"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5928"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363264"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3242292"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045597"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23362"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23055"},{"key":"ref44","first-page":"11908","article-title":"Adversarial music: Real world audio adversary against wake-word detection system","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Li"},{"article-title":"FAAG: Fast adversarial audio generation through interactive attack optimisation","year":"2022","author":"Miao","key":"ref48"},{"key":"ref49","first-page":"1","article-title":"Audio injection adversarial example attack","volume-title":"Proc. ICML Workshop Adversarial Mach. Learn.","author":"Liu"},{"key":"ref50","first-page":"30058","article-title":"VoiceBlock: Privacy through real-time adversarial attacks with audio-to-audio models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"O\u2019Reilly"},{"key":"ref51","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Tramer"},{"article-title":"Characterizing audio adversarial examples using temporal dependency","year":"2018","author":"Yang","key":"ref52"},{"key":"ref53","first-page":"2273","article-title":"{WaveGuard}: Understanding and mitigating audio adversarial examples","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Hussain"},{"key":"ref54","first-page":"247","article-title":"{KENKU}: Towards efficient and stealthy black-box adversarial attacks against {ASR} systems","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Wu"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2022.100098"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/s41965-024-00142-3"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2023.100153"}],"container-title":["IEEE Transactions on Mobile Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/7755\/11068893\/10946237.pdf?arnumber=10946237","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T22:59:20Z","timestamp":1751929160000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10946237\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8]]},"references-count":54,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tmc.2025.3555680","relation":{},"ISSN":["1536-1233","1558-0660","2161-9875"],"issn-type":[{"type":"print","value":"1536-1233"},{"type":"electronic","value":"1558-0660"},{"type":"electronic","value":"2161-9875"}],"subject":[],"published":{"date-parts":[[2025,8]]}}}