ASRJam: Human-Friendly AI Speech Jamming to Prevent Automated Phone Scams

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Grabovski, Freddie, Gressel, Gilad, Mirsky, Yisroel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911003057324032
author Grabovski, Freddie
Gressel, Gilad
Mirsky, Yisroel
author_facet Grabovski, Freddie
Gressel, Gilad
Mirsky, Yisroel
contents Large Language Models (LLMs), combined with Text-to-Speech (TTS) and Automatic Speech Recognition (ASR), are increasingly used to automate voice phishing (vishing) scams. These systems are scalable and convincing, posing a significant security threat. We identify the ASR transcription step as the most vulnerable link in the scam pipeline and introduce ASRJam, a proactive defence framework that injects adversarial perturbations into the victim's audio to disrupt the attacker's ASR. This breaks the scam's feedback loop without affecting human callers, who can still understand the conversation. While prior adversarial audio techniques are often unpleasant and impractical for real-time use, we also propose EchoGuard, a novel jammer that leverages natural distortions, such as reverberation and echo, that are disruptive to ASR but tolerable to humans. To evaluate EchoGuard's effectiveness and usability, we conducted a 39-person user study comparing it with three state-of-the-art attacks. Results show that EchoGuard achieved the highest overall utility, offering the best combination of ASR disruption and human listening experience.
format Preprint
id arxiv_https___arxiv_org_abs_2506_11125
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ASRJam: Human-Friendly AI Speech Jamming to Prevent Automated Phone Scams
Grabovski, Freddie
Gressel, Gilad
Mirsky, Yisroel
Computation and Language
Artificial Intelligence
Large Language Models (LLMs), combined with Text-to-Speech (TTS) and Automatic Speech Recognition (ASR), are increasingly used to automate voice phishing (vishing) scams. These systems are scalable and convincing, posing a significant security threat. We identify the ASR transcription step as the most vulnerable link in the scam pipeline and introduce ASRJam, a proactive defence framework that injects adversarial perturbations into the victim's audio to disrupt the attacker's ASR. This breaks the scam's feedback loop without affecting human callers, who can still understand the conversation. While prior adversarial audio techniques are often unpleasant and impractical for real-time use, we also propose EchoGuard, a novel jammer that leverages natural distortions, such as reverberation and echo, that are disruptive to ASR but tolerable to humans. To evaluate EchoGuard's effectiveness and usability, we conducted a 39-person user study comparing it with three state-of-the-art attacks. Results show that EchoGuard achieved the highest overall utility, offering the best combination of ASR disruption and human listening experience.
title ASRJam: Human-Friendly AI Speech Jamming to Prevent Automated Phone Scams
topic Computation and Language
Artificial Intelligence
url https://arxiv.org/abs/2506.11125