{"id":"https://openalex.org/W4387321684","doi":"https://doi.org/10.1145/3607199.3607240","title":"PhantomSound: Black-Box, Query-Efficient Audio Adversarial Attack via Split-Second Phoneme Injection","display_name":"PhantomSound: Black-Box, Query-Efficient Audio Adversarial Attack via Split-Second Phoneme Injection","publication_year":2023,"publication_date":"2023-10-03","ids":{"openalex":"https://openalex.org/W4387321684","doi":"https://doi.org/10.1145/3607199.3607240"},"language":"en","primary_location":{"id":"doi:10.1145/3607199.3607240","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3607199.3607240","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5035545617","display_name":"Hanqing Guo","orcid":"https://orcid.org/0000-0003-3779-4679"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Hanqing Guo","raw_affiliation_strings":["Michigan State University, United States of America"],"raw_orcid":"https://orcid.org/0000-0003-3779-4679","affiliations":[{"raw_affiliation_string":"Michigan State University, United States of America","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083819169","display_name":"Guangjing Wang","orcid":"https://orcid.org/0000-0002-9353-9042"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guangjing Wang","raw_affiliation_strings":["Michigan State University, United States of America"],"raw_orcid":"https://orcid.org/0000-0002-9353-9042","affiliations":[{"raw_affiliation_string":"Michigan State University, United States of America","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039317227","display_name":"Y. Wang","orcid":"https://orcid.org/0009-0008-2062-9013"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yuanda Wang","raw_affiliation_strings":["Michigan State University, United States of America"],"raw_orcid":"https://orcid.org/0009-0008-2062-9013","affiliations":[{"raw_affiliation_string":"Michigan State University, United States of America","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076545839","display_name":"Bocheng Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bocheng Chen","raw_affiliation_strings":["Michigan State University, USA"],"raw_orcid":"https://orcid.org/0009-0001-0471-7063","affiliations":[{"raw_affiliation_string":"Michigan State University, USA","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042277127","display_name":"Qiben Yan","orcid":"https://orcid.org/0000-0001-6272-7668"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qiben Yan","raw_affiliation_strings":["Michigan State University, United States of America"],"raw_orcid":"https://orcid.org/0000-0001-6272-7668","affiliations":[{"raw_affiliation_string":"Michigan State University, United States of America","institution_ids":["https://openalex.org/I87216513"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100375264","display_name":"Xiao Li","orcid":"https://orcid.org/0000-0001-9660-9053"},"institutions":[{"id":"https://openalex.org/I87216513","display_name":"Michigan State University","ror":"https://ror.org/05hs6h993","country_code":"US","type":"education","lineage":["https://openalex.org/I87216513"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Li Xiao","raw_affiliation_strings":["Michigan State University, USA"],"raw_orcid":"https://orcid.org/0000-0001-9660-9053","affiliations":[{"raw_affiliation_string":"Michigan State University, USA","institution_ids":["https://openalex.org/I87216513"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5035545617"],"corresponding_institution_ids":["https://openalex.org/I87216513"],"apc_list":null,"apc_paid":null,"fwci":1.3633,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.84961519,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"366","last_page":"380"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9941999912261963,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9585999846458435,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/liveness","display_name":"Liveness","score":0.8187780976295471},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8132922649383545},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8027483224868774},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.738764226436615},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5599091053009033},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5132291316986084},{"id":"https://openalex.org/keywords/speech-recognition","display_name":"Speech recognition","score":0.3810945153236389},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3446792960166931},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30016952753067017},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.15519732236862183}],"concepts":[{"id":"https://openalex.org/C15569618","wikidata":"https://www.wikidata.org/wiki/Q3561421","display_name":"Liveness","level":2,"score":0.8187780976295471},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8132922649383545},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8027483224868774},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.738764226436615},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5599091053009033},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5132291316986084},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.3810945153236389},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3446792960166931},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30016952753067017},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.15519732236862183},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3607199.3607240","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3607199.3607240","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.8100000023841858}],"awards":[{"id":"https://openalex.org/G2704182886","display_name":null,"funder_award_id":"76421595","funder_id":"https://openalex.org/F4320307791","funder_display_name":"Cisco Systems"}],"funders":[{"id":"https://openalex.org/F4320307791","display_name":"Cisco Systems","ror":"https://ror.org/03yt1ez60"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W95608104","https://openalex.org/W2141504799","https://openalex.org/W2193413348","https://openalex.org/W2603766943","https://openalex.org/W2745896134","https://openalex.org/W2746600820","https://openalex.org/W2747024632","https://openalex.org/W2753783305","https://openalex.org/W2933426098","https://openalex.org/W2942091739","https://openalex.org/W2963977978","https://openalex.org/W2964187693","https://openalex.org/W2964301649","https://openalex.org/W2979717817","https://openalex.org/W3007913795","https://openalex.org/W3015625436","https://openalex.org/W3106412272","https://openalex.org/W3109668151","https://openalex.org/W3110715780","https://openalex.org/W3138076532","https://openalex.org/W3153453329","https://openalex.org/W3156272176","https://openalex.org/W3163083600","https://openalex.org/W3201506562","https://openalex.org/W3207651366","https://openalex.org/W4281392593","https://openalex.org/W4300824008","https://openalex.org/W4306179629","https://openalex.org/W4308642081","https://openalex.org/W4380926246"],"related_works":["https://openalex.org/W2081199208","https://openalex.org/W1565271071","https://openalex.org/W3349016","https://openalex.org/W3160870209","https://openalex.org/W2139648957","https://openalex.org/W1481041875","https://openalex.org/W2391970076","https://openalex.org/W4385437088","https://openalex.org/W4379538695","https://openalex.org/W3009622996"],"abstract_inverted_index":{"In":[0,75],"this":[1],"paper,":[2],"we":[3,78],"propose":[4],"PhantomSound,":[5],"a":[6,44,50,144,158],"query-efficient":[7],"black-box":[8,14,173],"attack":[9,41,58,81,95,142,164],"toward":[10],"voice":[11,18,111],"assistants.":[12],"Existing":[13],"adversarial":[15,36,62,137,163],"attacks":[16],"on":[17],"assistants":[19],"either":[20],"apply":[21],"substitution":[22],"models":[23],"or":[24],"leverage":[25],"the":[26,32,56,66,72,76,93,115,141,150,155,171],"intermediate":[27],"model":[28],"output":[29],"to":[30,59,91,120],"estimate":[31],"gradients":[33],"for":[34],"crafting":[35],"audio":[37],"samples.":[38],"However,":[39],"these":[40],"approaches":[42],"require":[43],"significant":[45],"amount":[46],"of":[47,68,157],"queries":[48,69,179,186],"with":[49,126,170],"lengthy":[51],"training":[52],"stage.":[53],"PhantomSound":[54,101,134],"leverages":[55],"decision-based":[57],"produce":[60],"effective":[61],"audios,":[63],"and":[64,104,117,139,153,161,167,183],"reduces":[65],"number":[67],"by":[70,165],"optimizing":[71],"gradient":[73],"estimation.":[74],"experiments,":[77],"perform":[79],"our":[80],"against":[82],"4":[83],"different":[84],"speech-to-text":[85],"APIs":[86],"under":[87],"3":[88,122],"real-world":[89],"scenarios":[90],"demonstrate":[92],"real-time":[94],"impact.":[96],"The":[97,129],"results":[98],"show":[99],"that":[100,133],"is":[102,118],"practical":[103],"robust":[105],"in":[106,143],"attacking":[107],"5":[108,181],"popular":[109],"commercial":[110],"controllable":[112],"devices":[113],"over":[114],"air,":[116],"able":[119],"bypass":[121],"liveness":[123],"detection":[124],"mechanisms":[125],"success":[127],"rate.":[128],"benchmark":[130],"result":[131],"shows":[132],"can":[135],"generate":[136],"examples":[138],"launch":[140],"few":[145],"minutes.":[146],"We":[147],"significantly":[148],"enhance":[149],"query":[151],"efficiency":[152],"reduce":[154],"cost":[156],"successful":[159],"untargeted":[160],"targeted":[162],"93.1%":[166],"65.5%":[168],"compared":[169],"state-of-the-art":[172],"attacks,":[174],"using":[175],"merely":[176],"\u223c":[177,184],"300":[178],"(\u223c":[180,187],"minutes)":[182],"1,500":[185],"25":[188],"minutes),":[189],"respectively.":[190]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":6}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
