1.Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
2.School of Cyber Science and Engineering,Huazhong University of Science and Technology,Wuhan 430074,Hubei,China
The open microphone permission required by smart voice assistants brings the risk of user private conversation content leakage. The use of the selective ultrasonic microphone jamming system has been proposed as a means to protect user voice privacy and security. However, the current system is not fully effective in preserving speech privacy, and there are limitations with the active interference cancellation mechanism. Hence, this paper presents a selective ultrasonic microphone jamming system that addresses these challenges by incorporating enhanced safety considerations and improved applicability. This paper employs mixed speech type interference to effectively obfuscate unauthorized devices, enhancing security. Moreover, for improved applicability, an iterative adaptive filtering approach is designed, utilizing a reference high-frequency projection interference copy to enable authorized devices to capture cleaner speech amidst various types of interference signals. Furthermore, this paper extends the selective interference mechanism to preserve the touchless interaction capability between users and voice assistants.Experimental results demonstrate that the proposed system effectively blocks unauthorized microphones, and the quality of the denoised speech is higher than those recovered from existing selective ultrasonic jmicrophone amming systems in terms of subjective and objective speech evaluation.
利用麦克风非线性效应,攻击者可以在用户无察觉的情况向其注入危险的语音命令,如打开门。用户也可以在知情的情况下主动注入干扰来混淆麦克风,防止麦克风非法窃听,保护自己的隐私。BackDoor[4]利用麦克风硬件上的自动增益控制(automatic gain control, AGC)电路,发出高功率超声波抑制语音信号,并利用麦克风非线性原理注入额外的低频频率畸变来降低录制音频的质量。BackDoor未考虑授权机制,只考虑了如何进行干扰。Wearable Jammer[5]重点关注超声波干扰器的可用性和用户体验,设计了一款低功耗的可穿戴式手环干扰器,利用跳频余弦波干扰佩戴者周围的麦克风。Patronus[6]首次引入选择性干扰机制,设计了一种设备级别的选择性超声波干扰系统,能防止未经授权的窃听麦克风,同时降低干扰对授权设备的影响。Patronus利用无线通信向授权设备传输干扰的先验知识,利用原始的干扰作为参考信号进行自适应滤波,消除干扰噪声对授权设备的影响。然而,相比于可听声噪声消除,利用非线性频率泄露原理注入的干扰信号受到复杂非线性时变信道的影响,拥有更大程度的扭曲和失真,实际注入干扰和原始信号之间存在较大差异,Patronus通过原始干扰和其倍频信号模拟复杂非线性信道响应的方法只适用于余弦波干扰,而这种干扰方式被证明是不安全的[8],容易遭受到频率分析攻击。对于其他类型的干扰信号,如白噪声和语音,Patronus选择性干扰机制无法正常工作,无法有效去除干扰。MicShield[7]采用了一种语音级别的选择性超声波干扰系统,其中选择性干扰机制不包含主动去干扰技术,而是需要一个不受干扰的麦克风来监听唤醒词的前几个音素,以保证用户说出唤醒词后及时关闭干扰。MicShield在实际场景的适用性受到限制,因为无干扰麦克风的条件难以满足,虽然这可以通过麦克风特殊布局避免自干扰来实现,如将麦克风放置在干扰死角内,但这提升了用户部署系统的难度,又或者可以配置一个超声波麦克风来满足条件,然而这极大地提高了硬件成本。BigBrother[13]提出了超声波麦克风干扰系统的评估框架,使用多个评价指标量化分析了多种干扰系统在不同威胁模型下的干扰效果。
DEDVUKAJT. Apple’s Siri is eavesdropping on your conversations, putting users at risk: Report[EB/OL]. [2019-09-19].
[2]
KUNED F, BACKESJ, CLARKS S, et al. Ghost talk: Mitigating EMI signal injection attacks against analog sensors[C]//2013 IEEE Symposium on Security and Privacy. New York: IEEE Press, 2013: 145-159. DOI: 10.1109/SP.2013.20 .
ROYN, HASSANIEHH, CHOUDHURYR R. BackDoor: Making microphones hear inaudible sounds[C]//Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services. New York: ACM, 2017: 2-14. DOI: 10.1145/3081333.3081366 .
[6]
CHENY X, LIH Y, TENGS Y, et al. Wearable microphone jamming[C]//Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems. New York: ACM, 2020: 1-12. DOI: 10.1145/3313831.3376304 .
[7]
LIL K, LIUM N, YAOY G, et al. Patronus: Preventing unauthorized speech recordings with support for selective unscrambling[C]//Proceedings of the 18th Conference on Embedded Networked Sensor Systems. New York: ACM, 2020: 245-257. DOI: 10.1145/3384419.3430713 .
[8]
SUNK, CHENC, ZHANGX Y. “Alexa, stop spying on me!”: Speech privacy protection against voice assistants[C]//Proceedings of the 18th Conference on Embedded Networked Sensor Systems. New York: ACM, 2020: 298-311. DOI: 10.1145/3384419.3430727 .
[9]
CHENY K, GAOM, LIUY J, et al. Implement of a secure selective ultrasonic microphone jammer[J]. CCF Transactions on Pervasive Computing and Interaction, 2021, 3(4): 367-377. DOI: 10.1007/s42486-021-00074-2 .
[10]
CHENG K C, WHALENJ J. Comparative RFI performance of bipolar operational amplifiers[C]//IEEE International Symposium on Electromagnetic Compatibility. New York: IEEE Press, 2016: 1-5. DOI: 10.1109/ISEMC.1981.7569908 .
[11]
ABUELMA'ATTIM T. Analysis of the effect of radio frequency interference on the DC performance of bipolar operational amplifiers[J]. IEEE Transactions on Electromagnetic Compatibility, 2003, 45(2): 453-458. DOI: 10.1109/TEMC.2003.811312 .
[12]
ZHANGG M, YANC, JIX Y, et al. DolphinAttack: Inaudible voice commands[C]//Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2017: 103-117. DOI: 10.1145/3133956.3134052 .
[13]
ROYN, SHENS, HASSANIEHH, et al. Inaudible voice commands: The long-range attack and defense[C]//Proceedings of the 15th USENIX Conference on Networked Systems Design and Implementation. New York: ACM, 2018: 547-560. DOI: 10.5555/3307441.3307488 .
[14]
CHENY K, GAOM, LIY M, et al. Big brother is listening: An evaluation framework on ultrasonic microphone jammers[C]//IEEE INFOCOM 2022 ― IEEE Conference on Computer Communications. New York: IEEE Press, 2022: 1119-1128. DOI: 10.1109/INFOCOM48880.2022.9796834 .
[15]
SCHROEDERM R, ATALB S, HALLJ L. Optimizing digital speech coders by exploiting masking properties of the human ear[J]. The Journal of the Acoustical Society of America, 1979, 66(6): 1647-1652. DOI: 10.1121/1.383662 .
[16]
HEY T, BIANJ Y, TONGX Y, et al. Canceling inaudible voice commands against voice control systems[C]//MobiCom '19: The 25th Annual International Conference on Mobile Computing and Networking. New York: ACM, 2019: 1-15. DOI: 10.1145/3300061.3345429 .
COOKC E. Linear FM signal formats for beacon and communication systems[J]. IEEE Transactions on Aerospace and Electronic Systems, 1974, AES-10(4): 471-478. DOI: 10.1109/TAES.1974.307800 .
[19]
LEEH, KIMT H, CHOIJ W, et al. Chirp signal-based aerial acoustic communication for smart devices[C]//2015 IEEE Conference on Computer Communications (INFOCOM). New York: IEEE Press, 2015: 2407-2415. DOI: 10.1109/INFOCOM.2015.7218629 .
[20]
PÁEZ BORRALLOJ, GARCIA OTEROM. On the implementation of a partitioned block frequency domain adaptive filter (PBFDAF) for long acoustic echo cancellation[J]. Signal Processing, 1992, 27(3): 301-315. DOI: 10.1016/0165-1684(92)90077-A .
[21]
YANGF R, ENZNERG, YANGJ. On the convergence behavior of partitioned-block frequency-domain adaptive filters[J]. IEEE Transactions on Signal Processing, 2021, 69: 4906-4920. DOI: 10.1109/TSP.2021.3102175 .
[22]
GAROFOLOJ S, LAMELL F, FISHERW M, et al.Darpa Timit Acoustic-Phonetic Continuous Speech Corpus CD-ROM{TIMIT}[EB/OL]. [2023-01-02]. DOI: 10.6028/nist.ir.4930 .