arXiv · 2106.14191
Open, Sesame! Introducing Access Control to Voice Services
Abstract
Personal voice assistants (VAs) are shown to be vulnerable against record-and-replay, and other acoustic attacks which allow an adversary to gain unauthorized control of connected devices within a smart home. Existing defenses either lack detection and management capabilities or are too coarse-grained to enable flexible policies on par with other computing interfaces. In this work, we present Sesame, a lightweight framework for edge devices which is the first to enable fine-grained access control of smart-home voice commands. Sesame combines three components: Automatic Speech Recognition, Natural Language Understanding (NLU) and a Policy module. We implemented Sesame on Android devices and demonstrate that our system can enforce security policies for both Alexa and Google Home in real-time (362ms end-to-end inference time), with a lightweight (<25MB) NLU model which exhibits minimal accuracy loss compared to its non-compact equivalent.
Explore related subjects
Keep this discovery
Dominika Woszczyk, Alvin Lee, Soteris Demetriou. 2021-06-27. Open, Sesame! Introducing Access Control to Voice Services. https://doi.org/10.1145/3469261.3469405
Cite the original work for its findings. Save a collection to share your selection of sources.