Skip to main content
QUICK REVIEW

[Paper Review] DolphinAtack: Inaudible Voice Commands

Guoming Zhang, Chen Yan|arXiv (Cornell University)|Aug 31, 2017
Speech and Audio Processing29 references126 citations
TL;DR

DolphinAttack shows that inaudible ultrasonic voice commands can be demodulated by MEMS/ECM microphones via nonlinear hardware and interpreted by popular SR systems, enabling stealthy activations and commands across devices. It also proposes defenses.

ABSTRACT

Speech recognition (SR) systems such as Siri or Google Now have become an increasingly popular human-computer interaction method, and have turned various systems into voice controllable systems(VCS). Prior work on attacking VCS shows that the hidden voice commands that are incomprehensible to people can control the systems. Hidden voice commands, though hidden, are nonetheless audible. In this work, we design a completely inaudible attack, DolphinAttack, that modulates voice commands on ultrasonic carriers (e.g., f > 20 kHz) to achieve inaudibility. By leveraging the nonlinearity of the microphone circuits, the modulated low frequency audio commands can be successfully demodulated, recovered, and more importantly interpreted by the speech recognition systems. We validate DolphinAttack on popular speech recognition systems, including Siri, Google Now, Samsung S Voice, Huawei HiVoice, Cortana and Alexa. By injecting a sequence of inaudible voice commands, we show a few proof-of-concept attacks, which include activating Siri to initiate a FaceTime call on iPhone, activating Google Now to switch the phone to the airplane mode, and even manipulating the navigation system in an Audi automobile. We propose hardware and software defense solutions. We validate that it is feasible to detect DolphinAttack by classifying the audios using supported vector machine (SVM), and suggest to re-design voice controllable systems to be resilient to inaudible voice command attacks.

Motivation & Objective

  • Demonstrate feasibility of inaudible voice command injections targeting voice controllable systems (VCS).
  • Explain how ultrasonic modulation can be demodulated by microphone nonlinearity to reach SR systems.
  • Validate attacks across multiple SR systems and device platforms to assess security implications.
  • Propose hardware/software defenses to mitigate inaudible command attacks.

Proposed method

  • Modulate baseband voice commands onto ultrasonic carriers using amplitude modulation (AM).
  • Exploit microphone nonlinearity to demodulate and recover baseband commands prior to the LPF stage.
  • Characterize microphone nonlinearity and demonstrate demodulation with MEMS and ECM microphones.
  • Design practical transmitters (bench-top and portable smartphone-based) to inject inaudible commands.
  • Evaluate activation and general control commands on diverse SR systems (Siri, Google Now, Alexa, etc.).
  • Assess carrier frequency selection, modulation depth, and voice selection to optimize attacks.

Experimental results

Research questions

  • RQ1Can inaudible ultrasonic commands be demodulated by typical microphone hardware and decoded by SR systems?
  • RQ2What are the hardware and software factors that influence the success of DolphinAttack across devices?
  • RQ3What activation and control commands can be issued via inaudible injections on major SR platforms?
  • RQ4What defenses can effectively detect or mitigate such inaudible command attacks?

Key findings

  • DolphinAttack can inject inaudible commands on ultrasonic carriers and have them decoded by SR systems like Siri, Google Now, and Alexa.
  • Activation commands could be generated even without owner voice samples, achieving 39% success with 89 tested activation command types (35 successful).
  • The attack was validated across 7 SR systems and 16 devices/platforms.
  • Experiments show successful demodulation of baseband signals through microphone nonlinearity for both MEMS and ECM microphones.
  • The study includes practical transmitter designs (bench-top and portable) and demonstrates potential real-world attack scenarios (e.g., FaceTime, airplane mode, navigation).
  • The authors propose hardware/software defenses to mitigate DolphinAttack.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.