Back to Search
Start Over
FakeWake: Understanding and Mitigating Fake Wake-up Words of Voice Assistants
- Source :
- CCS
- Publication Year :
- 2021
- Publisher :
- ACM, 2021.
-
Abstract
- In the area of Internet of Things (IoT) voice assistants have become an important interface to operate smart speakers, smartphones, and even automobiles. To save power and protect user privacy, voice assistants send commands to the cloud only if a small set of pre-registered wake-up words are detected. However, voice assistants are shown to be vulnerable to the FakeWake phenomena, whereby they are inadvertently triggered by innocent-sounding fuzzy words. In this paper, we present a systematic investigation of the FakeWake phenomena from three aspects. To start with, we design the first fuzzy word generator to automatically and efficiently produce fuzzy words instead of searching through a swarm of audio materials. We manage to generate 965 fuzzy words covering 8 most popular English and Chinese smart speakers. To explain the causes underlying the FakeWake phenomena, we construct an interpretable tree-based decision model, which reveals phonetic features that contribute to false acceptance of fuzzy words by wake-up word detectors. Finally, we propose remedies to mitigate the effect of FakeWake. The results show that the strengthened models are not only resilient to fuzzy words but also achieve better overall performance on original training datasets.
- Subjects :
- FOS: Computer and information sciences
Computer Science - Machine Learning
Computer Science - Cryptography and Security
Computer science
business.industry
Interface (computing)
Cloud computing
Fuzzy logic
Machine Learning (cs.LG)
Tree (data structure)
If and only if
Human–computer interaction
business
Cryptography and Security (cs.CR)
Decision model
Word (computer architecture)
Generator (mathematics)
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
- Accession number :
- edsair.doi.dedup.....ad54be85fd13e140eee3857e6519f6c0
- Full Text :
- https://doi.org/10.1145/3460120.3485365