Alexa versus Alexa: Controlling Smart Speakers by Self-Issuing Voice Commands
Sergio Esposito, Daniele Sgandurra, Giampaolo Bella

TL;DR
This paper introduces AvA, a novel attack exploiting voice command interpretation vulnerabilities in Amazon Echo devices, enabling prolonged control without proximity, and discusses additional vulnerabilities and user survey insights.
Contribution
The paper presents a new self-issue voice command attack on Echo devices and uncovers two additional vulnerabilities, enhancing understanding of smart speaker security risks.
Findings
AvA achieves 99% command execution success rate.
Discovered vulnerabilities increase attack duration and success.
Most limitations against AvA are rarely exploited in practice.
Abstract
We present Alexa versus Alexa (AvA), a novel attack that leverages audio files containing voice commands and audio reproduction methods in an offensive fashion, to gain control of Amazon Echo devices for a prolonged amount of time. AvA leverages the fact that Alexa running on an Echo device correctly interprets voice commands originated from audio files even when they are played by the device itself -- i.e., it leverages a command self-issue vulnerability. Hence, AvA removes the necessity of having a rogue speaker in proximity of the victim's Echo, a constraint that many attacks share. With AvA, an attacker can self-issue any permissible command to Echo, controlling it on behalf of the legitimate user. We have verified that, via AvA, attackers can control smart appliances within the household, buy unwanted items, tamper linked calendars and eavesdrop on the user. We also discovered two…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdversarial Robustness in Machine Learning · Advanced Malware Detection Techniques · Ethics and Social Impacts of AI
