Live data from Hacker News

Hackers send silent commands to speech recognition systems with ultrasound

techcrunch.com

21–30 of 88 posts

Re: Hackers send silent commands to speech recognition systems with ultrasound

#22
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

"...no hardware solution..."

There is for new hardware. It's relatively simple to include a couple components on the mic input to filter out ultrasound.

There is indeed no hardware fix for anything already manufactured.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#23
post #8

Earlier quoted context omitted.

This will be fixed with a simple software update that ignores all sounds at inaudible frequencies.

Except the inaudible sounds are used for marketing purposes. Most companies aren't going to want to just close that door.

I'm genuinely curious - can you share a link how it works please? I've never heard of it.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#24
These speech recognition tools need to have some sort of authentication:

- How about having a secret "wake word" instead of "Alexa" or "Hey Siri"? - Only treating signals using human voice range - Voice identification

If this isn't patched soon (excluding ultrasounds), it could mean that these tools are already using inaudible signals for other purposes. For example, commercials could add ultrasounds to know who's watching them.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#25
post #22
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

"...no hardware solution..." There is for new hardware. It's relatively simple to include a couple components on the mic input to filter out ultrasound. There is indeed no hardware fix for anything already manufactured.

[deleted]

Re: Hackers send silent commands to speech recognition systems with ultrasound

#26
post #20

Earlier quoted context omitted.

This will be fixed with a simple software update that ignores all sounds at inaudible frequencies.

It's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the micropho…

> The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the microphone means the two tones mix together to produce a number of other frequencies, including the frequency "B-A"-"B" = "A".

Does this work for ears, too?

If so, are the non-linearities of different people's ears similar enough that two people hearing the same A and B would get the same results, or would person to person variations in non-linearity mean they might hear different results?

Re: Hackers send silent commands to speech recognition systems with ultrasound

#27
post #14

Earlier quoted context omitted.

Yeah, those parts are easily available on Aliexpress in droves. Imagine this in the crowded subway. "hey siri" "show me pictures of CENSORED " "send the first picture to mom" "yes, send it" :S

I’m pretty sure that Hey Siri is keyed to the users voice to some extent, so Siri should be safe. Not sure about Google, Cortana, Alexa etc.

Emphasis on "to some extent". Relying on it is a bad idea even though it'll keep out most randos.

Speech fingerprinting, much like actual fingerprints, is not a reliable way to establish identity, especially if you want to avoid false negatives as you probably would in mass consumer facing technology.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#29
post #20

Earlier quoted context omitted.

This will be fixed with a simple software update that ignores all sounds at inaudible frequencies.

It's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the micropho…

> the author refers to "harmonics" they are really talking about intermodulation.

No, he's talking about harmonics. It's a different effect from intermodulation. It's true that intermodulation involves the sum and difference two or more frequencies. Harmonics, however, involves integer multiples of a single frequency.

But the impact is the same as intermodulation in that it's really a hardware issue and cannot be countered using a simple frequency filter.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#30
post #22
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

"...no hardware solution..." There is for new hardware. It's relatively simple to include a couple components on the mic input to filter out ultrasound. There is indeed no hardware fix for anything already manufactured.

They are taking advantage of nonlinear properties in the microphone system, as described clearly in the article. There is no software filtering to protect against this using classical signal processing.

That said, it may be possible to detect the difference between human speech and the ultrasonic trick with a machine learning solution.

Post reply on HN