{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T14:01:35Z","timestamp":1780063295953,"version":"3.54.0"},"publisher-location":"New York, NY, USA","reference-count":70,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T00:00:00Z","timestamp":1781913600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,21]]},"DOI":"10.1145\/3745756.3809215","type":"proceedings-article","created":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T12:52:21Z","timestamp":1780059141000},"page":"448-463","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Diversified Neural Networks: Defeating Adversarial Attacks via Numerous Orthogonal Variants"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8443-5148","authenticated-orcid":false,"given":"Ying","family":"Meng","sequence":"first","affiliation":[{"name":"Department of Computer Science, George Mason University, Fairfax, Virginia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9432-6017","authenticated-orcid":false,"given":"Qiang","family":"Zeng","sequence":"additional","affiliation":[{"name":"Department of Computer Science, George Mason University, Fairfax, Virginia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,20]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23362"},{"key":"e_1_3_2_1_2_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Abdullah Hadi","year":"2022","unstructured":"Hadi Abdullah, Aditya Karlekar, Vincent Bindschaedler, and Patrick Traynor. 2022. Demystifying limited adversarial transferability in automatic speech recognition systems. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_3_1","volume-title":"IEEE Symposium on Security and Privacy (S&P).","author":"Abdullah Hadi","year":"2021","unstructured":"Hadi Abdullah, Muhammad Sajidur Rahman, Washington Garcia, Logan Blue, Kevin Warren, Anurag Swarnim Yadav, Tom Shrimpton, and Patrick Traynor. 2021. Hear \"No Evil\", See \"Kenansville\"*: Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification Systems. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_4_1","volume-title":"IEEE Symposium on Security and Privacy (S&P).","author":"Abdullah Hadi","year":"2021","unstructured":"Hadi Abdullah, Kevin Warren, Vincent Bindschaedler, Nicolas Papernot, and Patrick Traynor. 2021. Sok: The faults in our asrs: An overview of attacks against automatic speech recognition and speaker identification systems. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_5_1","volume-title":"SpeechT5: Unified-Modal Encoder-Decoder Pre-training for Spoken Language Processing. arXiv preprint arXiv:2110.07205","author":"Ao Junyi","year":"2021","unstructured":"Junyi Ao, Rui Wang, Long Zhou, Chengyi Wang, Shuo Ren, Yu Wu, Shujie Liu, Tom Ko, Qing Li, Yu Zhang, Zhihua Wei, Yao Qian, Jinyu Li, and Furu Wei. 2021. SpeechT5: Unified-Modal Encoder-Decoder Pre-training for Spoken Language Processing. arXiv preprint arXiv:2110.07205 (2021)."},{"key":"e_1_3_2_1_6_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_7_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_8_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Baevski Alexei","year":"2022","unstructured":"Alexei Baevski, Wei-Ning Hsu, Qiantong Xu, Arun Babu, Jiatao Gu, and Michael Auli. 2022. Data2vec: A general framework for self-supervised learning in speech, vision and language. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_9_1","unstructured":"Alexei Baevski Yuhao Zhou Abdelrahman Mohamed and Michael Auli. 2020. wav2vec 2.0: A framework for self-supervised learning of speech representations. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_10_1","unstructured":"Harry Baker. [n. d.]. How many atoms are in the observable universe? https:\/\/www.livescience.com\/how-many-atoms-in-universe.html."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1053283.1053286"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2023.3333214"},{"key":"e_1_3_2_1_13_1","volume-title":"Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. In 10th ACM Workshop on Artificial Intelligence and Security.","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner. 2017. Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. In 10th ACM Workshop on Artificial Intelligence and Security."},{"key":"e_1_3_2_1_14_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2016","unstructured":"Nicholas Carlini and David A. Wagner. 2016. Defensive Distillation is Not Robust to Adversarial Examples. arXiv preprint arXiv:1607.04311 (2016)."},{"key":"e_1_3_2_1_15_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2018","unstructured":"Nicholas Carlini and David A. Wagner. 2018. Audio Adversarial Examples: Targeted Attacks on Speech-to-Text. arXiv preprint arXiv:1801.01944 (2018)."},{"key":"e_1_3_2_1_16_1","volume-title":"IEEE Symposium on Security and Privacy (S&P).","author":"Chen Guangke","year":"2021","unstructured":"Guangke Chen, Sen Chen, Lingling Fan, Xiaoning Du, Zhe Zhao, Fu Song, and Yang Liu. 2021. Who is real bob? adversarial attacks on speaker recognition systems. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3220673"},{"key":"e_1_3_2_1_18_1","volume-title":"ACM International Conference on Mobile Systems, Applications and Services (MobiSys).","author":"Chen Tao","year":"2024","unstructured":"Tao Chen, Yongjie Yang, Chonghao Qiu, Xiaoran Fan, Xiuzhen Guo, and Longfei Shangguan. 2024. Enabling hands-free voice assistant activation on earphones. In ACM International Conference on Mobile Systems, Applications and Services (MobiSys)."},{"key":"e_1_3_2_1_19_1","volume-title":"USENIX Security Symposium (USENIX Security).","author":"Chen Yuxuan","year":"2020","unstructured":"Yuxuan Chen, Xuejing Yuan, Jiangshan Zhang, Yue Zhao, Shengzhi Zhang, Kai Chen, and XiaoFeng Wang. 2020. Devil's Whisper: A General Approach for Physical Adversarial Attacks against Commercial Black-box Speech Recognition Devices. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_20_1","volume-title":"ALIF: Low-cost Adversarial Audio Attacks on Black-box Speech Platforms Using Linguistic Features. In IEEE Symposium on Security and Privacy (S&P).","author":"Cheng Peng","year":"2024","unstructured":"Peng Cheng, Yuwei Wang, Peng Huang, Zhongjie Ba, Xiaodong Lin, Feng Lin, Li Lu, and Kui Ren. 2024. ALIF: Low-cost Adversarial Audio Attacks on Black-box Speech Platforms Using Linguistic Features. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3175603"},{"key":"e_1_3_2_1_22_1","volume-title":"Gardner","author":"Feinman Reuben","year":"2017","unstructured":"Reuben Feinman, Ryan R. Curtin, Saurabh Shintre, and Andrew B. Gardner. 2017. Detecting Adversarial Samples from Artifacts. arXiv preprint arXiv:1703.00410 (2017)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOTOS.1997.595185"},{"key":"e_1_3_2_1_24_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_25_1","volume-title":"On the (Statistical) Detection of Adversarial Examples. arXiv preprint arXiv:1702.06280","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel. 2017. On the (Statistical) Detection of Adversarial Examples. arXiv preprint arXiv:1702.06280 (2017)."},{"key":"e_1_3_2_1_26_1","volume-title":"ACM International Conference on Mobile Computing and Networking (MobiCom).","author":"Guo Hanqing","year":"2024","unstructured":"Hanqing Guo, Guangjing Wang, Bocheng Chen, Yuanda Wang, Xiao Zhang, Xun Chen, Qiben Yan, and Li Xiao. 2024. WavePurifier: Purifying Audio Adversarial Examples via Hierarchical Diffusion Models. In ACM International Conference on Mobile Computing and Networking (MobiCom)."},{"key":"e_1_3_2_1_27_1","unstructured":"Song Han Jeff Pool John Tran and William Dally. 2015. Learning both weights and connections for efficient neural network. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_28_1","volume-title":"Ng","author":"Hannun Awni Y.","year":"2014","unstructured":"Awni Y. Hannun, Carl Case, Jared Casper, Bryan Catanzaro, Greg Diamos, Erich Elsen, Ryan Prenger, Sanjeev Satheesh, Shubho Sengupta, Adam Coates, and Andrew Y. Ng. 2014. Deep Speech: Scaling up end-to-end speech recognition. arXiv preprint arXiv:1412.5567 (2014)."},{"key":"e_1_3_2_1_29_1","volume-title":"Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong. arXiv preprint arXiv:1706.04701","author":"He Warren","year":"2017","unstructured":"Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong. arXiv preprint arXiv:1706.04701 (2017)."},{"key":"e_1_3_2_1_30_1","volume-title":"ACM International Conference on Mobile Computing and Networking (MobiCom).","author":"He Yitao","year":"2019","unstructured":"Yitao He, Junyu Bian, Xinyu Tong, Zihui Qian, Wei Zhu, Xiaohua Tian, and Xinbing Wang. 2019. Canceling inaudible voice commands against voice control systems. In ACM International Conference on Mobile Computing and Networking (MobiCom)."},{"key":"e_1_3_2_1_31_1","volume-title":"Kushal Lakhotia","author":"Hsu Wei-Ning","year":"2021","unstructured":"Wei-Ning Hsu, Benjamin Bolte, Yao-Hung Hubert Tsai, Kushal Lakhotia, Ruslan Salakhutdinov, and Abdelrahman Mohamed. 2021. Hubert: Self-supervised speech representation learning by masked prediction of hidden units. IEEE\/ACM transactions on audio, speech, and language processing 29 (2021), 3451\u20133460."},{"key":"e_1_3_2_1_32_1","volume-title":"WaveGuard: Understanding and Mitigating Audio Adversarial Examples. In USENIX Security Symposium (USENIX Security).","author":"Hussain Shehzeen","year":"2021","unstructured":"Shehzeen Hussain, Paarth Neekhara, Shlomo Dubnov, Julian McAuley, and Farinaz Koushanfar. 2021. WaveGuard: Understanding and Mitigating Audio Adversarial Examples. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.3390\/s23135784"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/582415.582418"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_3_2_1_36_1","volume-title":"DiffWave: A Versatile Diffusion Model for Audio Synthesis. In International Conference on Learning Representations (ICLR).","author":"Kong Zhifeng","year":"2021","unstructured":"Zhifeng Kong, Wei Ping, Jiaji Huang, Kexin Zhao, and Bryan Catanzaro. 2021. DiffWave: A Versatile Diffusion Model for Audio Synthesis. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.25"},{"key":"e_1_3_2_1_38_1","volume-title":"IEEE International Conference on Computer Vision (ICCV).","author":"Lu Jiajun","year":"2017","unstructured":"Jiajun Lu, Theerasit Issaranon, and David Forsyth. 2017. Safetynet: Detecting and rejecting adversarial examples robustly. In IEEE International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_2_1_39_1","volume-title":"Randomness in ml defenses helps persistent attackers and hinders evaluators. arXiv preprint arXiv:2302.13464","author":"Lucas Keane","year":"2023","unstructured":"Keane Lucas, Matthew Jagielski, Florian Tram\u00e8r, Lujo Bauer, and Nicholas Carlini. 2023. Randomness in ml defenses helps persistent attackers and hinders evaluators. arXiv preprint arXiv:2302.13464 (2023)."},{"key":"e_1_3_2_1_40_1","volume-title":"Nic: Detecting adversarial samples with neural network invariant checking. In 26th network and distributed system security symposium (NDSS).","author":"Ma Shiqing","year":"2019","unstructured":"Shiqing Ma and Yingqi Liu. 2019. Nic: Detecting adversarial samples with neural network invariant checking. In 26th network and distributed system security symposium (NDSS)."},{"key":"e_1_3_2_1_41_1","volume-title":"Sloane","author":"MacWilliams Jessie","year":"1977","unstructured":"Jessie MacWilliams and Neil J. A. Sloane. 1977. The Theory of Error-Correcting Codes. North-Holland."},{"key":"e_1_3_2_1_42_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_43_1","unstructured":"Market.us. 2024. Voice AI in Smart Homes Market Size Share & Trends Analysis Report. https:\/\/market.us\/report\/voice-ai-in-smart-homes-market\/. Accessed: 2024-11-27."},{"key":"e_1_3_2_1_44_1","unstructured":"Mozilla. 2019. DeepSpeech v0.4.1. https:\/\/github.com\/mozilla\/DeepSpeech\/releases\/tag\/v0.4.1. Accessed: 2023-01-01."},{"key":"e_1_3_2_1_45_1","volume-title":"Mozilla Open Source Speech. Retrieved","year":"2024","unstructured":"Mozilla. n.d.. How long does model training take. Mozilla Open Source Speech. Retrieved July 15, 2024 from https:\/\/discourse.mozilla.org\/t\/how-long-does-model-training-take\/59048 GitHub repository with documentation on training costs and requirements."},{"key":"e_1_3_2_1_46_1","unstructured":"Mozilla. n.d.. Mozilla Common Voice Dataset. https:\/\/commonvoice.mozilla.org\/en\/datasets."},{"key":"e_1_3_2_1_47_1","volume-title":"Diffusion Models for Adversarial Purification. In International Conference on Machine Learning (ICML).","author":"Nie Weili","year":"2022","unstructured":"Weili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao, Arash Vahdat, and Animashree Anandkumar. 2022. Diffusion Models for Adversarial Purification. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_48_1","unstructured":"OpenSLR. n.d.. LibriSpeech ASR corpus. https:\/\/www.openslr.org\/12\/."},{"key":"e_1_3_2_1_49_1","volume-title":"On the effectiveness of defensive distillation. arXiv preprint arXiv:1607.05113","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot and Patrick McDaniel. 2016. On the effectiveness of defensive distillation. arXiv preprint arXiv:1607.05113 (2016)."},{"key":"e_1_3_2_1_50_1","volume-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)."},{"key":"e_1_3_2_1_51_1","volume-title":"IEEE Symposium on Security and Privacy (S&P).","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick Mcdaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016. Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_52_1","volume-title":"Florian Stimberg, Olivia Wiles, and Timothy A Mann.","author":"Rebuffi Sylvestre-Alvise","year":"2021","unstructured":"Sylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg, Olivia Wiles, and Timothy A Mann. 2021. Data augmentation can improve robustness. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_53_1","volume-title":"n.d.. Building a speech recognition system vs. buying or using an API. https:\/\/www.rev.com\/resources\/building-a-speech-recognition-system-vs-buying-or-using-an-api Accessed","year":"2025","unstructured":"Rev. n.d.. Building a speech recognition system vs. buying or using an API. https:\/\/www.rev.com\/resources\/building-a-speech-recognition-system-vs-buying-or-using-an-api Accessed: April 1, 2025."},{"key":"e_1_3_2_1_54_1","volume-title":"International Conference on Pattern Recognition (ICPR).","author":"Sallo Raymel Alfonso","year":"2021","unstructured":"Raymel Alfonso Sallo, Mohammad Esmaeilpour, and Patrick Cardinal. 2021. Adversarially training for audio classifiers. In International Conference on Pattern Recognition (ICPR)."},{"key":"e_1_3_2_1_55_1","volume-title":"Towards compact and robust deep neural networks. arXiv preprint arXiv:1906.06110","author":"Sehwag Vikash","year":"2019","unstructured":"Vikash Sehwag, Shiqi Wang, Prateek Mittal, and Suman Jana. 2019. Towards compact and robust deep neural networks. arXiv preprint arXiv:1906.06110 (2019)."},{"key":"e_1_3_2_1_56_1","unstructured":"The PaX Team. 2001. PaX: Address Space Layout Randomization (ASLR). https:\/\/pax.grsecurity.net\/. Accessed: 2024-11-14."},{"key":"e_1_3_2_1_57_1","unstructured":"Florian Tram\u00e8r Nicholas Carlini Wieland Brendel and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_58_1","volume-title":"Turbocharge Speech Understanding with Pilot Inference. In ACM International Conference on Mobile Computing and Networking (MobiCom).","author":"Wang Rongxiang","year":"2024","unstructured":"Rongxiang Wang and Felix Xiaozhu Lin. 2024. Turbocharge Speech Understanding with Pilot Inference. In ACM International Conference on Mobile Computing and Networking (MobiCom)."},{"key":"e_1_3_2_1_59_1","volume-title":"World Population. https:\/\/www.worldometers.info\/world-population\/ Accessed","year":"2026","unstructured":"Worldometers. 2026. World Population. https:\/\/www.worldometers.info\/world-population\/ Accessed: March 10, 2026."},{"key":"e_1_3_2_1_60_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Wu Shutong","year":"2023","unstructured":"Shutong Wu, Jiongxiao Wang, Wei Ping, Weili Nie, and Chaowei Xiao. 2023. Defending against Adversarial Audio via Diffusion Model. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_61_1","volume-title":"USENIX Security Symposium (USENIX Security).","author":"Wu Xinghui","year":"2023","unstructured":"Xinghui Wu, Shiqing Ma, Chao Shen, Chenhao Lin, Qian Wang, Qi Li, and Yuan Rao. 2023. KENKU: Towards Efficient and Stealthy Black-box Adversarial Attacks against ASR Systems. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_62_1","volume-title":"Diversity priors for learning early visual features. Frontiers in computational neuroscience 9","author":"Xiong Hanchen","year":"2015","unstructured":"Hanchen Xiong, Antonio J Rodr\u00edguez-S\u00e1nchez, Sandor Szedmak, and Justus Piater. 2015. Diversity priors for learning early visual features. Frontiers in computational neuroscience 9 (2015), 104."},{"key":"e_1_3_2_1_63_1","volume-title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In Network and Distributed System Security Symposium (NDSS).","author":"Xu Weilin","year":"2018","unstructured":"Weilin Xu, David Evans, and Yanjun Qi. 2018. Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"crossref","first-page":"8254478","DOI":"10.1155\/2021\/8254478","article-title":"Design of Smart Home Control System Based on Wireless Voice Sensor","volume":"2021","author":"Yang Changchun","year":"2021","unstructured":"Changchun Yang. 2021. Design of Smart Home Control System Based on Wireless Voice Sensor. Journal of Sensors 2021 (2021), 8254478.","journal-title":"Journal of Sensors"},{"key":"e_1_3_2_1_65_1","volume-title":"Characterizing Audio Adversarial Examples Using Temporal Dependency. In International Conference on Learning Representations (ICLR).","author":"Yang Zhuolin","year":"2019","unstructured":"Zhuolin Yang, Bo Li, Pin-Yu Chen, and Dawn Song. 2019. Characterizing Audio Adversarial Examples Using Temporal Dependency. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_66_1","volume-title":"IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN).","author":"Zeng Qiang","year":"2019","unstructured":"Qiang Zeng, Jianhai Su, Chenglong Fu, Golam Kayas, Lannan Luo, Xiaojiang Du, Chiu C. Tan, and Jie Wu. 2019. A Multiversion Programming Inspired Approach to Detecting Audio Adversarial Examples. In IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)."},{"key":"e_1_3_2_1_67_1","unstructured":"Qiang Zeng Zhi Xin Dinghao Wu Peng Liu and Bing Mao. 2014. Tailored application-specific system call tables. The Pennsylvania State University Tech. Rep (2014)."},{"key":"e_1_3_2_1_68_1","unstructured":"Shaofeng Zhang Meng Liu and Junchi Yan. 2020. The diversified ensemble neural network. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_69_1","volume-title":"Practical Adversarial Attack Against Object Detector. arXiv preprint arXiv:1812.10217","author":"Zhao Yue","year":"2018","unstructured":"Yue Zhao, Hong Zhu, Qintao Shen, Ruigang Liang, Kai Chen, and Shengzhi Zhang. 2018. Practical Adversarial Attack Against Object Detector. arXiv preprint arXiv:1812.10217 (2018)."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2017.2675902"}],"event":{"name":"MobiSys '26: 24th Annual International Conference on Mobile Systems, Applications and Services","location":"University of Cambridge Cambridge United Kingdom","acronym":"MobiSys '26","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 24th Annual International Conference on Mobile Systems, Applications and Services"],"original-title":[],"deposited":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T13:02:12Z","timestamp":1780059732000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3745756.3809215"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,20]]},"references-count":70,"alternative-id":["10.1145\/3745756.3809215","10.1145\/3745756"],"URL":"https:\/\/doi.org\/10.1145\/3745756.3809215","relation":{},"subject":[],"published":{"date-parts":[[2026,6,20]]},"assertion":[{"value":"2026-06-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}