{"id":"https://openalex.org/W4388017405","doi":"https://doi.org/10.1109/jiot.2023.3328253","title":"Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial Ultrasound","display_name":"Enrollment-Stage Backdoor Attacks on Speaker Recognition Systems via Adversarial Ultrasound","publication_year":2023,"publication_date":"2023-10-30","ids":{"openalex":"https://openalex.org/W4388017405","doi":"https://doi.org/10.1109/jiot.2023.3328253"},"language":"en","primary_location":{"id":"doi:10.1109/jiot.2023.3328253","is_oa":false,"landing_page_url":"https://doi.org/10.1109/jiot.2023.3328253","pdf_url":null,"source":{"id":"https://openalex.org/S2480266640","display_name":"IEEE Internet of Things Journal","issn_l":"2327-4662","issn":["2327-4662","2372-2541"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Internet of Things Journal","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5044549752","display_name":"Xinfeng Li","orcid":"https://orcid.org/0000-0002-9686-4369"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xinfeng Li","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085455545","display_name":"Junning Ze","orcid":"https://orcid.org/0009-0005-4799-1555"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Junning Ze","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101820345","display_name":"Chen Yan","orcid":"https://orcid.org/0000-0003-4430-5263"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chen Yan","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063893376","display_name":"Yushi Cheng","orcid":"https://orcid.org/0000-0002-0888-2322"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yushi Cheng","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017116027","display_name":"Xiaoyu Ji","orcid":"https://orcid.org/0000-0002-1101-0007"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaoyu Ji","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100407971","display_name":"Wenyuan Xu","orcid":"https://orcid.org/0009-0005-9946-0908"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenyuan Xu","raw_affiliation_strings":["USSLAB, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"USSLAB, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5044549752"],"corresponding_institution_ids":["https://openalex.org/I76130692"],"apc_list":null,"apc_paid":null,"fwci":1.5734,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.86684722,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":"11","issue":"8","first_page":"13108","last_page":"13124"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10201","display_name":"Speech Recognition and Synthesis","score":0.9923999905586243,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11609","display_name":"Geophysical Methods and Applications","score":0.982200026512146,"subfield":{"id":"https://openalex.org/subfields/2212","display_name":"Ocean Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.941066324710846},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8379744291305542},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6199257373809814},{"id":"https://openalex.org/keywords/speech-recognition","display_name":"Speech recognition","score":0.5781304836273193},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4963131546974182},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4555330276489258},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3991854786872864},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.31992197036743164}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.941066324710846},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8379744291305542},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6199257373809814},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.5781304836273193},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4963131546974182},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4555330276489258},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3991854786872864},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.31992197036743164},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/jiot.2023.3328253","is_oa":false,"landing_page_url":"https://doi.org/10.1109/jiot.2023.3328253","pdf_url":null,"source":{"id":"https://openalex.org/S2480266640","display_name":"IEEE Internet of Things Journal","issn_l":"2327-4662","issn":["2327-4662","2372-2541"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Internet of Things Journal","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.47999998927116394,"id":"https://metadata.un.org/sdg/4","display_name":"Quality Education"}],"awards":[{"id":"https://openalex.org/G2346075336","display_name":null,"funder_award_id":"226-2022-00223","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G2461859056","display_name":null,"funder_award_id":"62071428","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2509534683","display_name":null,"funder_award_id":"62222114","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4914349744","display_name":null,"funder_award_id":"62271280","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5303717354","display_name":null,"funder_award_id":"62201503","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994516692","display_name":null,"funder_award_id":"61925109","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":76,"referenced_works":["https://openalex.org/W1494198834","https://openalex.org/W1522301498","https://openalex.org/W1589969974","https://openalex.org/W2009376772","https://openalex.org/W2053150333","https://openalex.org/W2090861223","https://openalex.org/W2113606819","https://openalex.org/W2135046866","https://openalex.org/W2136682440","https://openalex.org/W2150769028","https://openalex.org/W2168959749","https://openalex.org/W2170334586","https://openalex.org/W2726515241","https://openalex.org/W2748789698","https://openalex.org/W2791862028","https://openalex.org/W2811004397","https://openalex.org/W2890964092","https://openalex.org/W2901887177","https://openalex.org/W2916104401","https://openalex.org/W2923400712","https://openalex.org/W2962788625","https://openalex.org/W2963077926","https://openalex.org/W2963242190","https://openalex.org/W2964301649","https://openalex.org/W2979717817","https://openalex.org/W2984998244","https://openalex.org/W2998603316","https://openalex.org/W3007384386","https://openalex.org/W3007679772","https://openalex.org/W3007913795","https://openalex.org/W3013020904","https://openalex.org/W3015783745","https://openalex.org/W3017720918","https://openalex.org/W3024869864","https://openalex.org/W3025515949","https://openalex.org/W3042368254","https://openalex.org/W3042801391","https://openalex.org/W3081618117","https://openalex.org/W3092178912","https://openalex.org/W3093573519","https://openalex.org/W3095410713","https://openalex.org/W3097934054","https://openalex.org/W3105920175","https://openalex.org/W3109668151","https://openalex.org/W3138076532","https://openalex.org/W3153453329","https://openalex.org/W3162258435","https://openalex.org/W3163083600","https://openalex.org/W3184620678","https://openalex.org/W3209984917","https://openalex.org/W3212666643","https://openalex.org/W4214537185","https://openalex.org/W4221114270","https://openalex.org/W4225476734","https://openalex.org/W4233548736","https://openalex.org/W4287062987","https://openalex.org/W4296068784","https://openalex.org/W4300685083","https://openalex.org/W4300824008","https://openalex.org/W4306179629","https://openalex.org/W4308642956","https://openalex.org/W4312934276","https://openalex.org/W4324007093","https://openalex.org/W4382203157","https://openalex.org/W4383503656","https://openalex.org/W4391725296","https://openalex.org/W6631190155","https://openalex.org/W6682262322","https://openalex.org/W6742782308","https://openalex.org/W6743581629","https://openalex.org/W6748288002","https://openalex.org/W6750412548","https://openalex.org/W6771529784","https://openalex.org/W6779684038","https://openalex.org/W6784200033","https://openalex.org/W6799444384"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4320018150","https://openalex.org/W4328053081","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719"],"abstract_inverted_index":{"Automatic":[0],"Speaker":[1],"Recognition":[2],"Systems":[3],"(SRSs)":[4],"have":[5],"been":[6],"widely":[7],"used":[8],"in":[9],"voice":[10],"applications":[11],"for":[12],"personal":[13],"identification":[14],"and":[15,28,82,106,119,159,182,194,243],"access":[16,113],"control.":[17],"A":[18],"typical":[19],"SRS":[20,72,95,110,197],"consists":[21],"of":[22,64,71,131,161,207,246],"three":[23],"stages,":[24],"i.e.,":[25],"training,":[26],"enrollment,":[27,105],"recognition.":[29],"Previous":[30],"work":[31],"has":[32],"revealed":[33],"that":[34,211],"SRSs":[35],"can":[36,214],"be":[37],"bypassed":[38],"by":[39,47,148],"backdoor":[40,65,92,147],"attacks":[41,50],"at":[42,51,135],"the":[43,52,68,91,94,104,108,116,120,136,145,150,162,171],"training":[44],"stage":[45,70],"or":[46],"adversarial":[48,74],"example":[49],"recognition":[53,218],"stage.":[54,138],"In":[55],"this":[56,141,231,247],"paper,":[57],"we":[58,143,169,235],"propose":[59],"TUNER,":[60],"a":[61,100,128],"new":[62,248],"type":[63],"attack":[66,126,213],"against":[67,204],"enrollment":[69,137],"via":[73],"ultrasound":[75,98],"modulation,":[76],"which":[77],"is":[78,87],"inaudible,":[79],"synchronization-free,":[80],"content-independent,":[81],"black-box.":[83],"Our":[84,125],"key":[85],"idea":[86],"to":[88,114,165,223],"first":[89],"inject":[90],"into":[93],"with":[96,122,153],"modulated":[97],"when":[99],"legitimate":[101,117],"user":[102,118,133],"initiates":[103],"afterward,":[107],"polluted":[109],"will":[111],"grant":[112],"both":[115],"adversary":[121],"high":[123],"confidence.":[124],"faces":[127],"major":[129],"challenge":[130],"unpredictable":[132],"articulation":[134],"To":[139,229],"overcome":[140],"challenge,":[142],"generate":[144],"ultrasonic":[146,172],"augmenting":[149],"optimization":[151],"process":[152],"random":[154],"speech":[155,226],"content,":[156,227],"vocalizing":[157],"time,":[158],"volume":[160],"user.":[163],"Furthermore,":[164],"achieve":[166],"real-world":[167],"robustness,":[168],"improve":[170],"signal":[173],"over":[174],"traditional":[175],"methods":[176],"using":[177],"sparse":[178],"frequency":[179],"points,":[180],"pre-compensation,":[181],"single-sideband":[183],"(SSB)":[184],"modulation.":[185],"We":[186],"extensively":[187],"evaluate":[188],"TUNER":[189],"on":[190,239],"two":[191],"common":[192],"datasets":[193],"seven":[195,205],"representative":[196],"models,":[198],"as":[199,201],"well":[200],"its":[202],"robustness":[203],"kinds":[206],"defenses.":[208],"Results":[209],"show":[210],"our":[212],"successfully":[215],"bypass":[216],"speaker":[217],"systems":[219],"while":[220],"remaining":[221],"effective":[222],"various":[224],"speakers,":[225],"etc.":[228],"mitigate":[230],"newly":[232],"discovered":[233],"threat,":[234],"also":[236],"provide":[237],"discussions":[238],"potential":[240],"countermeasures,":[241],"limitations,":[242],"future":[244],"works":[245],"threat.":[249]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":6}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
