{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T18:44:26Z","timestamp":1772822666699,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,6]],"date-time":"2024-11-06T00:00:00Z","timestamp":1730851200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,6]]},"DOI":"10.1145\/3689932.3694773","type":"proceedings-article","created":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T06:24:01Z","timestamp":1732256641000},"page":"137-148","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["EmoBack: Backdoor Attacks Against Speaker Identification Using Emotional Prosody"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-7045-0620","authenticated-orcid":false,"given":"Coen","family":"Schoof","sequence":"first","affiliation":[{"name":"Radboud University, Nijmegen, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6543-4801","authenticated-orcid":false,"given":"Stefanos","family":"Koffas","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Delft, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3612-1934","authenticated-orcid":false,"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"University of Padua, Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7509-4337","authenticated-orcid":false,"given":"Stjepan","family":"Picek","sequence":"additional","affiliation":[{"name":"Radboud University &amp; Delft University of Technology, Nijmegen, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Emotional voice conversion: Theory, databases and ESD. Speech Communi- cation 137","year":"2022","unstructured":"2022. Emotional voice conversion: Theory, databases and ESD. Speech Communi- cation 137 (2022), 1--18."},{"key":"e_1_3_2_1_2_1","volume-title":"Common voice: A massively-multilingual speech corpus. arXiv preprint arXiv:1912.06670","author":"Ardila Rosana","year":"2019","unstructured":"Rosana Ardila, Megan Branson, Kelly Davis, Michael Henretty, Michael Kohler, Josh Meyer, Reuben Morais, Lindsay Saunders, Francis M Tyers, and Gregor Weber. 2019. Common voice: A massively-multilingual speech corpus. arXiv preprint arXiv:1912.06670 (2019)."},{"key":"e_1_3_2_1_3_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan Eugene","year":"2021","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov. 2021. Blind backdoors in deep learning models. In 30th USENIX Security Symposium (USENIX Security 21). 1505--1521."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2021.03.004"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-77592-0"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.931100"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559357"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2020-2650"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0272-7358(02)00130-7"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3055844"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3570361.3613261"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/OJSP.2022.3190213"},{"key":"e_1_3_2_1_15_1","first-page":"8068","article-title":"Handcrafted backdoors in deep neural networks","volume":"35","author":"Hong Sanghyun","year":"2022","unstructured":"Sanghyun Hong, Nicholas Carlini, and Alexey Kurakin. 2022. Handcrafted backdoors in deep neural networks. Advances in Neural Information Processing Systems 35 (2022), 8068--8080.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_16_1","unstructured":"INTERPOL. 2024. Speaker Identification Integrated Project (SIIP). https:\/\/www.interpol.int\/Who-we-are\/Legal-framework\/Information-communications-and-technology-ICT-law-projects\/Speaker-Identification-Integrated-Project-SIIP. Accessed: 2024-06-08."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3084299"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096332"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3522783.3529523"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3328253"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Kang Liu Brendan Dolan-Gavitt and Siddharth Garg. 2018. Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. arXiv:1805.12185 [cs.CR]","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548261"},{"key":"e_1_3_2_1_23_1","volume-title":"Russo","author":"Livingstone Steven R.","year":"2018","unstructured":"Steven R. Livingstone and Frank A. Russo. 2018. The Ryerson Audio-Visual Database of Emotional Speech and Song (RAVDESS): A dynamic, multimodal set of facial and vocal expressions in North American English. PLOS ONE 13, 5 (05 2018), 1--35. https:\/\/doi.org\/10.1371 journal.pone.0196391"},{"key":"e_1_3_2_1_24_1","volume-title":"Information Security Practice and Experience","author":"Luo Yuxiao","unstructured":"Yuxiao Luo, Jianwei Tai, Xiaoqi Jia, and Shengzhi Zhang. 2022. Practical backdoor attack against speaker recognition system. In Information Security Practice and Experience. Springer, Taipei, Taiwan, 468--484."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10094675"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.forsciint.2016"},{"key":"e_1_3_2_1_27_1","volume-title":"Renato De Mori, and Yoshua Bengio","author":"Ravanelli Mirco","year":"2021","unstructured":"Mirco Ravanelli, Titouan Parcollet, Peter Plantinga, Aku Rouhe, Samuele Cornell, Loren Lugosch, Cem Subakan, Nauman Dawalatabad, Abdelwahab Heba, Jianyuan Zhong, Ju-Chieh Chou, Sung-Lin Yeh, Szu-Wei Fu, Chien-Feng Liao, Elena Rastorgueva, Fran\u00e7ois Grondin, William Aris, Hwidong Na, Yan Gao, Renato De Mori, and Yoshua Bengio. 2021. SpeechBrain: A General-Purpose Speech Toolkit. arXiv:2106.04624 [eess.AS] arXiv:2106.04624."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_3_2_1_29_1","volume-title":"Studying Squeeze-and- Excitation Used in CNN for Speaker Verification. In 2021 IEEE Automatic Speech Recognition and Understanding Workshop (ASRU). 1110--1115","author":"Rouvier Mickael","year":"2021","unstructured":"Mickael Rouvier and Pierre-Michel Bousquet. 2021. Studying Squeeze-and- Excitation Used in CNN for Speaker Verification. In 2021 IEEE Automatic Speech Recognition and Understanding Workshop (ASRU). 1110--1115. https:\/\/doi.org\/10. 1109\/ASRU51503.2021.9687936"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560531"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.3311\/PPee.20971"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.proeng.2012.06.363"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461375"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2023.12"},{"key":"e_1_3_2_1_35_1","unstructured":"Alexander Turner Dimitris Tsipras and Aleksander Madry. 2018. Clean-label backdoor attacks. (2018)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2014.6854363"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.3390\/app12125786"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS56603.2022.00033"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Tongqing Zhai Yiming Li Ziqi Zhang Baoyuan Wu Yong Jiang and Shu-Tao Xia. 2021. Backdoor Attack against Speaker Verification. arXiv:2010.11607 [cs.CR]","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3636534.3649345"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Haodong Zhao Wei Du Junjie Guo and Gongshen Liu. 2023. A Universal Identity Backdoor Attack against Speaker Verification based on Siamese Network. arXiv:2303.16031 [cs.CR]","DOI":"10.21437\/Interspeech.2022-446"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413391"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694773","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689932.3694773","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T02:08:55Z","timestamp":1755914935000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694773"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,6]]},"references-count":42,"alternative-id":["10.1145\/3689932.3694773","10.1145\/3689932"],"URL":"https:\/\/doi.org\/10.1145\/3689932.3694773","relation":{},"subject":[],"published":{"date-parts":[[2024,11,6]]},"assertion":[{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}