SkillFence: A Systems Approach to Practically Mitigating Voice-Based Confusion Attacks

12/16/2022
by   Ashish Hooda, et al.
0

Voice assistants are deployed widely and provide useful functionality. However, recent work has shown that commercial systems like Amazon Alexa and Google Home are vulnerable to voice-based confusion attacks that exploit design issues. We propose a systems-oriented defense against this class of attacks and demonstrate its functionality for Amazon Alexa. We ensure that only the skills a user intends execute in response to voice commands. Our key insight is that we can interpret a user's intentions by analyzing their activity on counterpart systems of the web and smartphones. For example, the Lyft ride-sharing Alexa skill has an Android app and a website. Our work shows how information from counterpart apps can help reduce dis-ambiguities in the skill invocation process. We build SkilIFence, a browser extension that existing voice assistant users can install to ensure that only legitimate skills run in response to their commands. Using real user data from MTurk (N = 116) and experimental trials involving synthetic and organic speech, we show that SkillFence provides a balance between usability and security by securing 90.83 user will need with a False acceptance rate of 19.83

READ FULL TEXT
research
05/03/2018

Understanding and Mitigating the Security Risks of Voice-Controlled Third-Party Skills on Amazon Alexa and Google Home

Virtual personal assistants (VPA) (e.g., Amazon Alexa and Google Assista...
research
06/03/2019

Evaluating Voice Skills by Design Guidelines Using an Automatic Voice Crawler

Currently, adaptive voice applications supported by voice assistants (VA...
research
10/19/2021

Two-stage Voice Application Recommender System for Unhandled Utterances in Intelligent Personal Assistant

Intelligent personal assistants (IPA) enable voice applications that fac...
research
10/21/2020

"Are you home alone?" "Yes" Disclosing Security and Privacy Vulnerabilities in Alexa Skills

The home voice assistants such as Amazon Alexa have become increasingly ...
research
06/22/2022

When It's Not Worth the Paper It's Written On: A Provocation on the Certification of Skills in the Alexa and Google Assistant Ecosystems

The increasing reach and functionality of voice assistants has allowed t...
research
01/22/2020

VoiceCoach: Interactive Evidence-based Training for Voice Modulation Skills in Public Speaking

The modulation of voice properties, such as pitch, volume, and speed, is...
research
01/19/2023

Legal Obligation and Ethical Best Practice: Towards Meaningful Verbal Consent for Voice Assistants

To improve user experience, Alexa now allows users to consent to data sh...

Please sign up or login with your details

Forgot password? Click here to reset