A Survey on Amazon Alexa Attack Surfaces
Yanyan Li, Sara Kim, Eric Sy

TL;DR
This survey reviews the various attack surfaces of Amazon Alexa, highlighting security vulnerabilities across its voice data lifecycle and discussing potential mitigation strategies to enhance privacy and safety.
Contribution
It provides a comprehensive overview of attack surfaces in the Alexa ecosystem, covering stages from voice capture to cloud processing, and suggests mitigation solutions.
Findings
Identified six attack surfaces in Alexa's voice interaction lifecycle
Discussed vulnerabilities in voice data collection, transmission, and processing
Proposed mitigation strategies for each attack surface
Abstract
Since being launched in 2014, Alexa, Amazon's versatile cloud-based voice service, is now active in over 100 million households worldwide. Alexa's user-friendly, personalized vocal experience offers customers a more natural way of interacting with cutting-edge technology by allowing the ability to directly dictate commands to the assistant. Now in the present year, the Alexa service is more accessible than ever, available on hundreds of millions of devices from not only Amazon but third-party device manufacturers. Unfortunately, that success has also been the source of concern and controversy. The success of Alexa is based on its effortless usability, but in turn, that has led to a lack of sufficient security. This paper surveys various attacks against Amazon Alexa ecosystem including attacks against the frontend voice capturing and the cloud backend voice command recognition and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAI in Service Interactions · User Authentication and Security Systems · Context-Aware Activity Recognition Systems
