HandLock: Enabling 2-FA for Smart Home Voice Assistants using Inaudible Acoustic Signal

HandLock: Enabling 2-FA for Smart Home Voice Assistants using Inaudible Acoustic Signal
复制标题

DOI:
10.1145/3471621.3471866
复制
发表时间:
2021-10
期刊:
Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子:
--
通讯作者:
Shaohu Zhang;Anupam Das
Shaohu Zhang;Anupam Das
中科院分区:
其他
文献类型:
--
作者:
Shaohu Zhang;Anupam Das

文献摘要

相似文献

语音控制技术的使用已成为主流,并在全球范围内不断增长。虽然语音助理通过自动化和控制家用电器提供便利,但语音通道的开放性使语音助理难以安全。因此,语音助理已被证明容易受到重放攻击,模仿攻击和听不见的语音命令。现有的防御不提供实际的解决方案,因为它们要么依赖于外部硬件(例如,运动传感器)或在非常受限的设置下工作(例如,将设备保持靠近用户的嘴)。我们介绍了将基于手势的认证系统用于智能家居语音助理的概念,该系统称为HandLock,其使用内置麦克风和扬声器来生成和感测听不见的声学信号,以检测已知(即,授权)手势。我们提出的方法可以作为第二因素身份验证(2-FA),用于执行特定的敏感操作,例如通过语音助手确认在线购买。通过对45名被试的大量实验,我们发现HandLock可以以0.82%的错误接受率(FAR)为代价,达到平均96.51%的真阳性率(TPR)。我们在各种设置下对HandLock进行了全面的分析,以展示其准确性,稳定性,攻击弹性和可用性。我们的分析表明,HandLock不仅可以成功地阻止模仿攻击,而且可以在产生非常低的开销的同时做到这一点,并且与现代语音助手兼容。
The use of voice-control technology has become mainstream and is growing worldwide. While voice assistants provide convenience through automation and control of home appliances, the open nature of the voice channel makes voice assistants difficult to secure. As a result voice assistants have been shown to be vulnerable to replay attacks, impersonation attacks and inaudible voice commands. Existing defenses do not provide a practical solution as they either rely on external hardware (e.g., motion sensors) or work under very constrained settings (e.g., holding the device close to a user’s mouth). We introduce the concept of using a gesture-based authentication system for smart home voice assistants called HandLock, which uses built-in microphones and speakers to generate and sense inaudible acoustic signals to detect the presence of a known (i.e., authorized) hand gesture. Our proposed approach can act as a second-factor authentication (2-FA) for performing specific sensitive operations like confirming online purchases through voice assistants. Through extensive experiments involving 45 participants, we show that HandLock can achieve on average 96.51% true-positive-rate (TPR) at the expense of 0.82% false-acceptance-rate (FAR). We perform a comprehensive analysis of HandLock under various settings to showcase its accuracy, stability, resilience to attacks, and usability. Our analysis shows that HandLock can not only successfully thwart impersonation attacks, but can do so while incurring very low overheads and is compatible with modern voice assistants.