{"id":"https://openalex.org/W3168346546","doi":"https://doi.org/10.1145/3433210.3437523","title":"HVAC: Evading Classifier-based Defenses in Hidden Voice Attacks","display_name":"HVAC: Evading Classifier-based Defenses in Hidden Voice Attacks","publication_year":2021,"publication_date":"2021-05-24","ids":{"openalex":"https://openalex.org/W3168346546","doi":"https://doi.org/10.1145/3433210.3437523","mag":"3168346546"},"language":"en","primary_location":{"id":"doi:10.1145/3433210.3437523","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3433210.3437523","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5073986426","display_name":"Yi Wu","orcid":"https://orcid.org/0009-0006-3120-3769"},"institutions":[{"id":"https://openalex.org/I75027704","display_name":"University of Tennessee at Knoxville","ror":"https://ror.org/020f3ap87","country_code":"US","type":"education","lineage":["https://openalex.org/I75027704"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yi Wu","raw_affiliation_strings":["University of Tennessee, Knoxville, TN, USA"],"affiliations":[{"raw_affiliation_string":"University of Tennessee, Knoxville, TN, USA","institution_ids":["https://openalex.org/I75027704"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100729468","display_name":"Xiangyu Xu","orcid":"https://orcid.org/0000-0002-1628-906X"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiangyu Xu","raw_affiliation_strings":["Shanghai Jiao Tong University, Shang Hai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University, Shang Hai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000206951","display_name":"Payton Walker","orcid":"https://orcid.org/0000-0002-8296-6321"},"institutions":[{"id":"https://openalex.org/I32389192","display_name":"University of Alabama at Birmingham","ror":"https://ror.org/008s83205","country_code":"US","type":"education","lineage":["https://openalex.org/I32389192"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Payton R. Walker","raw_affiliation_strings":["University of Alabama at Birmingham, Birmingham, AL, USA"],"affiliations":[{"raw_affiliation_string":"University of Alabama at Birmingham, Birmingham, AL, USA","institution_ids":["https://openalex.org/I32389192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100414706","display_name":"Jian Liu","orcid":"https://orcid.org/0000-0002-8331-0834"},"institutions":[{"id":"https://openalex.org/I75027704","display_name":"University of Tennessee at Knoxville","ror":"https://ror.org/020f3ap87","country_code":"US","type":"education","lineage":["https://openalex.org/I75027704"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jian Liu","raw_affiliation_strings":["University of Tennessee, Knoxville, TN, USA"],"affiliations":[{"raw_affiliation_string":"University of Tennessee, Knoxville, TN, USA","institution_ids":["https://openalex.org/I75027704"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059730489","display_name":"Nitesh Saxena","orcid":"https://orcid.org/0000-0001-6083-104X"},"institutions":[{"id":"https://openalex.org/I32389192","display_name":"University of Alabama at Birmingham","ror":"https://ror.org/008s83205","country_code":"US","type":"education","lineage":["https://openalex.org/I32389192"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nitesh Saxena","raw_affiliation_strings":["University of Alabama at Birmingham, Birmingham, AL, USA"],"affiliations":[{"raw_affiliation_string":"University of Alabama at Birmingham, Birmingham, AL, USA","institution_ids":["https://openalex.org/I32389192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100394750","display_name":"Yingying Chen","orcid":"https://orcid.org/0000-0002-3994-766X"},"institutions":[{"id":"https://openalex.org/I102322142","display_name":"Rutgers, The State University of New Jersey","ror":"https://ror.org/05vt9qd57","country_code":"US","type":"education","lineage":["https://openalex.org/I102322142"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yingying Chen","raw_affiliation_strings":["Rutgers University, Piscataway, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Rutgers University, Piscataway, NJ, USA","institution_ids":["https://openalex.org/I102322142"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012589427","display_name":"Jiadi Yu","orcid":"https://orcid.org/0000-0002-0207-9643"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiadi Yu","raw_affiliation_strings":["Shanghai Jiao Tong University, Shang Hai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University, Shang Hai, China","institution_ids":["https://openalex.org/I183067930"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5073986426"],"corresponding_institution_ids":["https://openalex.org/I75027704"],"apc_list":null,"apc_paid":null,"fwci":0.9518,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.79815378,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"82","last_page":"94"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10201","display_name":"Speech Recognition and Synthesis","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10201","display_name":"Speech Recognition and Synthesis","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hvac","display_name":"HVAC","score":0.5936283469200134},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5931004881858826},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5913658142089844},{"id":"https://openalex.org/keywords/speech-recognition","display_name":"Speech recognition","score":0.38540899753570557},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.35599854588508606},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2668432593345642},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.22435107827186584},{"id":"https://openalex.org/keywords/air-conditioning","display_name":"Air conditioning","score":0.054032713174819946}],"concepts":[{"id":"https://openalex.org/C122346748","wikidata":"https://www.wikidata.org/wiki/Q1798773","display_name":"HVAC","level":3,"score":0.5936283469200134},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5931004881858826},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5913658142089844},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.38540899753570557},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35599854588508606},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2668432593345642},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.22435107827186584},{"id":"https://openalex.org/C103742991","wikidata":"https://www.wikidata.org/wiki/Q173725","display_name":"Air conditioning","level":2,"score":0.054032713174819946},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3433210.3437523","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3433210.3437523","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.5899999737739563}],"awards":[{"id":"https://openalex.org/G1164577867","display_name":null,"funder_award_id":"W911NF-18-1-0221","funder_id":"https://openalex.org/F4320338281","funder_display_name":"Army Research Office"},{"id":"https://openalex.org/G8057625547","display_name":null,"funder_award_id":"CCF2028876, CCF1909963, CNS1801630, CNS1714807, CNS1526524, CNS1547350","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":32,"referenced_works":["https://openalex.org/W12796654","https://openalex.org/W655565512","https://openalex.org/W1434018057","https://openalex.org/W2022217943","https://openalex.org/W2069883713","https://openalex.org/W2085521593","https://openalex.org/W2101234009","https://openalex.org/W2102146461","https://openalex.org/W2122979854","https://openalex.org/W2192412620","https://openalex.org/W2250319793","https://openalex.org/W2295176885","https://openalex.org/W2295413924","https://openalex.org/W2517672638","https://openalex.org/W2624801495","https://openalex.org/W2737697117","https://openalex.org/W2751902866","https://openalex.org/W2767951891","https://openalex.org/W2770312844","https://openalex.org/W2782403400","https://openalex.org/W2898523704","https://openalex.org/W2941750187","https://openalex.org/W2952730822","https://openalex.org/W2962717526","https://openalex.org/W2964301649","https://openalex.org/W2974139573","https://openalex.org/W2991076039","https://openalex.org/W3006816054","https://openalex.org/W3105332166","https://openalex.org/W4210694145","https://openalex.org/W4289038676","https://openalex.org/W4300824008"],"related_works":["https://openalex.org/W2474469336","https://openalex.org/W1541307921","https://openalex.org/W2893763841","https://openalex.org/W2368779261","https://openalex.org/W2794438528","https://openalex.org/W2778699561","https://openalex.org/W2995996972","https://openalex.org/W2312116756","https://openalex.org/W3128571556","https://openalex.org/W3007967230"],"abstract_inverted_index":{"Recent":[0],"years":[1],"have":[2,35],"witnessed":[3],"the":[4,24,49,56,82,151,159,195,215,231,247,253,261,266,275,292],"rapid":[5],"development":[6],"of":[7,27,48,84,139,162,184,198,211,265,296,318],"automatic":[8],"speech":[9,205],"recognition":[10],"(ASR)":[11],"systems,":[12],"providing":[13],"a":[14,94,113,128,135,226,239],"practical":[15],"voice-user":[16],"interface":[17],"for":[18,220],"widely":[19],"deployed":[20],"smart":[21],"devices.":[22],"With":[23],"ever-growing":[25],"deployment":[26],"such":[28,127],"an":[29,313],"interface,":[30],"several":[31],"voice-based":[32],"attack":[33,54,142,147,299,303],"schemes":[34],"been":[36],"proposed":[37,145],"towards":[38],"current":[39],"ASR":[40],"systems":[41],"to":[42,60,68,81,168,172,229,251,257],"exploit":[43],"certain":[44],"vulnerabilities.":[45],"Posing":[46],"one":[47],"more":[50,136,255,272],"serious":[51],"threats,hidden":[52],"voice":[53,63,86,141,164,209],"uses":[55],"human-machine":[57],"perception":[58],"gap":[59],"generate":[61],"obfuscated/hidden":[62],"commands":[64,76,87,310],"that":[65,104,126,177,187,307],"are":[66,188],"unintelligible":[67,167,256],"human":[69,208],"listeners":[70],"but":[71],"can":[72,106,131,148,244,281,311],"be":[73,107,132,283],"interpreted":[74],"as":[75,238],"by":[77,112,285],"machines.":[78,286],"However,":[79,203],"due":[80],"nature":[83],"hidden":[85,140,163],"(i.e.,":[88,166,207],"normal":[89,199,232],"and":[90,110,170,200,234,263,268,294],"obfuscated":[91,201,236],"samples":[92,213],"exhibit":[93],"significant":[95],"difference":[96],"in":[97,274],"their":[98],"acoustic":[99,191],"features),":[100],"recent":[101],"studies":[102],"show":[103,306],"they":[105],"easily":[108,149],"detected":[109],"defended":[111],"pre-trained":[114],"classifier,":[115],"thereby":[116],"making":[117],"it":[118,270,280],"less":[119],"threatening.":[120],"In":[121],"this":[122],"paper,":[123],"we":[124,175,259],"validate":[125],"defense":[129,154,248,321],"strategy":[130],"circumvented":[133],"with":[134,190],"advanced":[137],"type":[138],"calledHVAC.":[143],"Our":[144],"HVAC":[146,241,298,309],"bypass":[150],"existing":[152],"learning-based":[153],"classifiers":[155],"while":[156,278],"preserving":[157],"all":[158,178],"essential":[160],"characteristics":[161],"attacks":[165],"humans":[169],"recognizable":[171],"machines).":[173],"Specifically,":[174],"find":[176],"classifier-based":[179],"defenses":[180],"build":[181],"on":[182],"top":[183],"classification":[185],"models":[186],"trained":[189],"features":[192],"extracted":[193],"from":[194],"entire":[196],"audio":[197],"samples.":[202],"only":[204],"parts":[206],"parts)":[210],"these":[212],"contain":[214],"useful":[216],"linguistic":[217],"information":[218],"needed":[219],"machine":[221],"transcription.":[222],"We":[223],"thus":[224],"propose":[225],"fusion-based":[227],"method":[228],"combine":[230],"sample":[233,237,267],"corresponding":[235],"hybrid":[240],"command,":[242],"which":[243],"effectively":[245],"cheat":[246],"classifiers.":[249],"Moreover,":[250],"make":[252,269],"command":[254],"humans,":[258],"tune":[260],"speed":[262],"pitch":[264],"even":[271],"distorted":[273],"time":[276],"domain":[277],"ensuring":[279],"still":[282],"recognized":[284],"Extensive":[287],"physical":[288],"over-the-air":[289],"experiments":[290],"demonstrate":[291],"robustness":[293],"generalizability":[295],"our":[297,308],"under":[300,323],"different":[301],"realistic":[302,325],"scenarios.":[304],"Results":[305],"achieve":[312],"average":[314],"94.1%":[315],"success":[316],"rate":[317],"bypassing":[319],"machine-learning-based":[320],"approaches":[322],"various":[324],"settings.":[326]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
