论文标题

认识Alexa的恶意双胞胎Malexa:通过智能的语音助手造成恶意软件引起的误解

Meet Malexa, Alexa's Malicious Twin: Malware-Induced Misperception Through Intelligent Voice Assistants

论文作者

Sharevski, Filipo, Treebridge, Paige, Jachim, Peter, Li, Audrey, Babin, Adam, Westbrook, Jessica

论文摘要

本文报告了一项研究的发现,其中用户(n = 220)与Alexa的恶意双胞胎Malexa相互作用。 Malexa是一位聪明的语音助手,具有简单且看似无害的第三方技能,向用户提供新闻简报。然而,这种转折在于,Malexa秘密地将这些简报有意介绍了有关报告的事件的误解。此秘密翻译称为恶意软件引起的误解(MIM)攻击。它与蹲或调用劫持攻击不同,因为它的重点是操纵通过第三方技能传递的“内容”,而不是技能的“调用逻辑”。在研究中,Malexa对法规简报进行了改写,使政府的反应听起来比Alexa发表的原始消息更偶然或宽大。结果表明,与Malexa互动的用户认为,政府对工人不太友好,更多地支持大型企业。结果还表明,Malexa能够引起误解,无论用户的性别,政治意识形态或与智能语音助手的互动频率如何。我们讨论了在人们的生活或工作环境中使用Malexa作为秘密的“影响者”的含义。

This paper reports the findings of a study where users (N=220) interacted with Malexa, Alexa's malicious twin. Malexa is an intelligent voice assistant with a simple and seemingly harmless third-party skill that delivers news briefings to users. The twist, however, is that Malexa covertly rewords these briefings to intentionally introduce misperception about the reported events. This covert rewording is referred to as a Malware-Induced Misperception (MIM) attack. It differs from squatting or invocation hijacking attacks in that it is focused on manipulating the "content" delivered through a third-party skill instead of the skill's "invocation logic." Malexa, in the study, reworded regulatory briefings to make a government response sound more accidental or lenient than the original news delivered by Alexa. The results show that users who interacted with Malexa perceived that the government was less friendly to working people and more in favor of big businesses. The results also show that Malexa is capable of inducing misperceptions regardless of the user's gender, political ideology or frequency of interaction with intelligent voice assistants. We discuss the implications in the context of using Malexa as a covert "influencer" in people's living or working environments.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源