Evaluating Synthetic Command Attacks on Smart Voice Assistants

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: He, Zhengxian, Kundu, Ashish, Ahamad, Mustaque
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912120262623232
author He, Zhengxian
Kundu, Ashish
Ahamad, Mustaque
author_facet He, Zhengxian
Kundu, Ashish
Ahamad, Mustaque
contents Recent advances in voice synthesis, coupled with the ease with which speech can be harvested for millions of people, introduce new threats to applications that are enabled by devices such as voice assistants (e.g., Amazon Alexa, Google Home etc.). We explore if unrelated and limited amount of speech from a target can be used to synthesize commands for a voice assistant like Amazon Alexa. More specifically, we investigate attacks on voice assistants with synthetic commands when they match command sources to authorized users, and applications (e.g., Alexa Skills) process commands only when their source is an authorized user with a chosen confidence level. We demonstrate that even simple concatenative speech synthesis can be used by an attacker to command voice assistants to perform sensitive operations. We also show that such attacks, when launched by exploiting compromised devices in the vicinity of voice assistants, can have relatively small host and network footprint. Our results demonstrate the need for better defenses against synthetic malicious commands that could target voice assistants.
format Preprint
id arxiv_https___arxiv_org_abs_2411_08316
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Evaluating Synthetic Command Attacks on Smart Voice Assistants
He, Zhengxian
Kundu, Ashish
Ahamad, Mustaque
Cryptography and Security
Sound
Audio and Speech Processing
Recent advances in voice synthesis, coupled with the ease with which speech can be harvested for millions of people, introduce new threats to applications that are enabled by devices such as voice assistants (e.g., Amazon Alexa, Google Home etc.). We explore if unrelated and limited amount of speech from a target can be used to synthesize commands for a voice assistant like Amazon Alexa. More specifically, we investigate attacks on voice assistants with synthetic commands when they match command sources to authorized users, and applications (e.g., Alexa Skills) process commands only when their source is an authorized user with a chosen confidence level. We demonstrate that even simple concatenative speech synthesis can be used by an attacker to command voice assistants to perform sensitive operations. We also show that such attacks, when launched by exploiting compromised devices in the vicinity of voice assistants, can have relatively small host and network footprint. Our results demonstrate the need for better defenses against synthetic malicious commands that could target voice assistants.
title Evaluating Synthetic Command Attacks on Smart Voice Assistants
topic Cryptography and Security
Sound
Audio and Speech Processing
url https://arxiv.org/abs/2411.08316