{"id":"https://openalex.org/W7117559352","doi":"https://doi.org/10.1145/3733799.3762974","title":"Black-Box Universal Adversarial Attack on Automatic Speech Recognition Systems for Maritime Radio Communication Using Evolutionary Strategies","display_name":"Black-Box Universal Adversarial Attack on Automatic Speech Recognition Systems for Maritime Radio Communication Using Evolutionary Strategies","publication_year":2025,"publication_date":"2025-10-13","ids":{"openalex":"https://openalex.org/W7117559352","doi":"https://doi.org/10.1145/3733799.3762974"},"language":"en","primary_location":{"id":"doi:10.1145/3733799.3762974","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3733799.3762974","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3733799.3762974","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5121541995","display_name":"Aliza Katharina Reif","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156774","display_name":"Institut f\u00fcr Arbeitsschutz der Deutschen Gesetzlichen Unfallversicherung","ror":"https://ror.org/0454e9996","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210156774"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Aliza Katharina Reif","raw_affiliation_strings":["German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany"],"raw_orcid":"https://orcid.org/0009-0005-7375-1109","affiliations":[{"raw_affiliation_string":"German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany","institution_ids":["https://openalex.org/I4210156774"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5121527058","display_name":"Lorenzo Bonasera","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156774","display_name":"Institut f\u00fcr Arbeitsschutz der Deutschen Gesetzlichen Unfallversicherung","ror":"https://ror.org/0454e9996","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210156774"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Lorenzo Bonasera","raw_affiliation_strings":["German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany"],"raw_orcid":"https://orcid.org/0000-0002-7931-5755","affiliations":[{"raw_affiliation_string":"German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany","institution_ids":["https://openalex.org/I4210156774"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024072796","display_name":"Stjepan Picek","orcid":"https://orcid.org/0000-0001-7509-4337"},"institutions":[{"id":"https://openalex.org/I145872427","display_name":"Radboud University Nijmegen","ror":"https://ror.org/016xsfp80","country_code":"NL","type":"education","lineage":["https://openalex.org/I145872427"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Stjepan Picek","raw_affiliation_strings":["Radboud University, Nijmegen, Netherlands"],"raw_orcid":"https://orcid.org/0000-0001-7509-4337","affiliations":[{"raw_affiliation_string":"Radboud University, Nijmegen, Netherlands","institution_ids":["https://openalex.org/I145872427"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072845141","display_name":"O. H. Ram\u00edrez-Agudelo","orcid":"https://orcid.org/0000-0002-9379-5409"},"institutions":[{"id":"https://openalex.org/I4210156774","display_name":"Institut f\u00fcr Arbeitsschutz der Deutschen Gesetzlichen Unfallversicherung","ror":"https://ror.org/0454e9996","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210156774"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Oscar Hern\u00e1n Ram\u00edrez-Agudelo","raw_affiliation_strings":["German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany"],"raw_orcid":"https://orcid.org/0000-0002-9379-5409","affiliations":[{"raw_affiliation_string":"German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany","institution_ids":["https://openalex.org/I4210156774"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5121570515","display_name":"Michael Karl","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156774","display_name":"Institut f\u00fcr Arbeitsschutz der Deutschen Gesetzlichen Unfallversicherung","ror":"https://ror.org/0454e9996","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210156774"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Karl","raw_affiliation_strings":["German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany"],"raw_orcid":"https://orcid.org/0009-0001-0535-0515","affiliations":[{"raw_affiliation_string":"German Aerospace Center (DLR), Institute for AI Safety and Security, Sankt Augustin, Germany","institution_ids":["https://openalex.org/I4210156774"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.7823777,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"146","last_page":"157"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8641999959945679,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8641999959945679,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12131","display_name":"Wireless Signal Modulation Classification","score":0.09239999949932098,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.00559999980032444,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5526000261306763},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.5361999869346619},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.4212999939918518},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.37950000166893005},{"id":"https://openalex.org/keywords/homogeneous","display_name":"Homogeneous","score":0.3465000092983246},{"id":"https://openalex.org/keywords/background-noise","display_name":"Background noise","score":0.32089999318122864},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.30979999899864197}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.786899983882904},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.6373000144958496},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5526000261306763},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.5361999869346619},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.4212999939918518},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39649999141693115},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.37950000166893005},{"id":"https://openalex.org/C66882249","wikidata":"https://www.wikidata.org/wiki/Q169336","display_name":"Homogeneous","level":2,"score":0.3465000092983246},{"id":"https://openalex.org/C100675267","wikidata":"https://www.wikidata.org/wiki/Q1371624","display_name":"Background noise","level":2,"score":0.32089999318122864},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.30979999899864197},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3003999888896942},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2962000072002411},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.28859999775886536},{"id":"https://openalex.org/C133892786","wikidata":"https://www.wikidata.org/wiki/Q1145189","display_name":"Speaker recognition","level":2,"score":0.2874000072479248},{"id":"https://openalex.org/C40969351","wikidata":"https://www.wikidata.org/wiki/Q3516228","display_name":"Word error rate","level":2,"score":0.2809999883174896},{"id":"https://openalex.org/C143271835","wikidata":"https://www.wikidata.org/wiki/Q254515","display_name":"Similitude","level":2,"score":0.27970001101493835},{"id":"https://openalex.org/C11560541","wikidata":"https://www.wikidata.org/wiki/Q1756025","display_name":"Replay attack","level":3,"score":0.27549999952316284},{"id":"https://openalex.org/C114289077","wikidata":"https://www.wikidata.org/wiki/Q3284399","display_name":"Statistical model","level":2,"score":0.265500009059906},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.2612999975681305}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3733799.3762974","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3733799.3762974","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},{"id":"pmh:oai:elib.dlr.de:222579","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3733799.3762974>.","pdf_url":null,"source":{"id":"https://openalex.org/S4377196266","display_name":"elib (German Aerospace Center)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2898391981","host_organization_name":"Deutsches Zentrum f\u00fcr Luft- und Raumfahrt e. V. (DLR)","host_organization_lineage":["https://openalex.org/I2898391981"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"},{"id":"pmh:oai:repository.ubn.ru.nl:2066/329590","is_oa":true,"landing_page_url":"https://hdl.handle.net/2066/329590","pdf_url":"https://repository.ubn.ru.nl//bitstream/handle/2066/329590/329590.pdf","source":{"id":"https://openalex.org/S4306401067","display_name":"Radboud Repository (Radboud University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I145872427","host_organization_name":"Radboud University Nijmegen","host_organization_lineage":["https://openalex.org/I145872427"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Article in monograph or in proceedings"}],"best_oa_location":{"id":"doi:10.1145/3733799.3762974","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3733799.3762974","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Life below water","score":0.42020291090011597,"id":"https://metadata.un.org/sdg/14"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W2024425422","https://openalex.org/W2898435086","https://openalex.org/W2963058500","https://openalex.org/W2964301649","https://openalex.org/W2972706975","https://openalex.org/W2973057252","https://openalex.org/W2973252307","https://openalex.org/W3063913079","https://openalex.org/W3091896612","https://openalex.org/W3190041646","https://openalex.org/W3207651366","https://openalex.org/W4230799888","https://openalex.org/W4285094241","https://openalex.org/W4321061922","https://openalex.org/W4379622969","https://openalex.org/W4384936706","https://openalex.org/W4387321684","https://openalex.org/W4388097452","https://openalex.org/W4392100823","https://openalex.org/W4392487628","https://openalex.org/W4399354256","https://openalex.org/W4399515265","https://openalex.org/W4399849612","https://openalex.org/W4401514864","https://openalex.org/W4408351845"],"related_works":[],"abstract_inverted_index":{"This":[0],"paper":[1],"studies":[2],"the":[3,53,61,70,85,90,115,169,184,192],"design,":[4],"implementation,":[5],"and":[6,44,65,88,114,135],"evaluation":[7],"of":[8,30,81,117],"a":[9,20,98,141,179],"new":[10],"universal":[11,27,158,194],"adversarial":[12],"attack":[13,131,138,196],"targeting":[14],"automatic":[15],"speech":[16],"recognition":[17],"systems":[18,113],"in":[19,84,110],"black-box":[21,195],"setting.":[22],"A":[23,172],"genetic":[24],"algorithm":[25],"optimizes":[26],"perturbations":[28,159],"consisting":[29],"short":[31],"noise":[32,54,78],"bursts":[33],"that":[34,102,129,157,177],"cause":[35],"mistranscriptions":[36],"by":[37],"balancing":[38],"text":[39],"similarity":[40,47],"(character":[41],"error":[42],"rate)":[43],"perceptual":[45],"audio":[46,82],"(Mel":[48],"energy":[49],"distance)":[50],"to":[51,68,148,168,182],"keep":[52],"minimally":[55],"intrusive.":[56],"Experiments":[57],"are":[58],"conducted":[59],"on":[60,119,140,164],"models":[62],"Wav2Vec":[63],"2.0":[64],"OpenAI\u2019s":[66],"Whisper":[67,146],"investigate":[69],"attack\u2019s":[71],"performance":[72],"under":[73],"varying":[74],"parameters":[75],"such":[76,122],"as":[77,95,97,123],"volumes,":[79],"number":[80],"files":[83],"training":[86],"set,":[87],"for":[89],"standard":[91],"English":[92],"Librispeech":[93],"dataset,":[94],"well":[96],"synthetic":[99],"maritime":[100,124],"dataset":[101],"contains":[103],"more":[104,150,166],"homogeneous":[105],"data.":[106],"We":[107,127,155],"expose":[108],"vulnerabilities":[109],"state-of-the-art":[111],"ASR":[112,198],"risks":[116],"attacks":[118],"safety-critical":[120],"applications,":[121],"radio":[125],"communication.":[126],"demonstrate":[128],"our":[130,187,189],"is":[132,175],"highly":[133],"successful,":[134],"even":[136],"an":[137],"trained":[139,163],"single":[142],"input":[143],"works":[144],"universally.":[145],"proves":[147],"be":[149],"robust":[151],"against":[152,197],"these":[153],"attacks.":[154],"find":[156],"generalize":[160],"better":[161],"when":[162],"data":[165],"similar":[167],"test":[170],"set.":[171],"semantic":[173],"defense":[174],"developed":[176],"presents":[178],"novel":[180],"way":[181],"detect":[183],"attack.":[185],"To":[186],"knowledge,":[188],"work":[190],"represents":[191],"first":[193],"models.":[199]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-12-30T00:00:00"}
