论文标题
嘿,Alexa,我刚打字了什么?用语音助手解码智能手机声音
Hey Alexa what did I just type? Decoding smartphone sounds with a voice assistant
论文作者
论文摘要
语音助手现在无处不在,聆听我们的日常生活。自从它们成为商业上可用的情况以来,隐私拥护者担心他们收集的数据可能会被滥用:第三方是否会提取私人对话?在本文中,我们表明隐私威胁超出了口头对话,并包括附近智能手机上键入的敏感数据。使用两台不同的智能手机和一台平板电脑,我们证明了攻击者可以从高达半米范围内收集的语音助手收集的录音中提取PIN代码和短信。这表明远程键盘 - 推断攻击不仅限于物理键盘,而且还扩展到虚拟键盘。随着我们的房屋充满始终在麦克风中,我们需要努力处理这些含义。
Voice assistants are now ubiquitous and listen in on our everyday lives. Ever since they became commercially available, privacy advocates worried that the data they collect can be abused: might private conversations be extracted by third parties? In this paper we show that privacy threats go beyond spoken conversations and include sensitive data typed on nearby smartphones. Using two different smartphones and a tablet we demonstrate that the attacker can extract PIN codes and text messages from recordings collected by a voice assistant located up to half a meter away. This shows that remote keyboard-inference attacks are not limited to physical keyboards but extend to virtual keyboards too. As our homes become full of always-on microphones, we need to work through the implications.