论文标题

LeakyPick:IoT音频间谍检测器

LeakyPick: IoT Audio Spy Detector

论文作者

Mitev, Richard, Pazii, Anna, Miettinen, Markus, Enck, William, Sadeghi, Ahmad-Reza

论文摘要

智能家居互联网(IoT)设备的制造商越来越多地为包括智能扬声器,电视,恒温器,安全系统和门铃的各种设备添加语音助手和音频监控功能。因此,这些设备中的许多设备都配备了麦克风,这引起了重大隐私问题:用户可能并不总是意识到何时将录音发送到云中,或者谁可以访问录音。在本文中,我们介绍了LeakyPick体系结构,该体系结构可以检测未经用户同意的智能家居设备将音频录制到Internet。我们的概念验证是一种泄漏的设备,该设备放置在用户的智能家居中,并在其环境中定期“探测”其他设备,并监视随后的网络流量,以了解指示音频传输的统计模式。我们的原型建立在Raspberry Pi上的价格少于40美元,在检测音频传输的测量精度为94%,以收集8个具有语音助手功能的设备。此外,我们使用LeakyPick识别了89个单词,Amazon Echo Dot误解了其尾流,从而导致了意外的音频传输。 LeakyPick为普通消费者提供了一种经济有效的方法,以监视其房屋,以使其对云的意外音频传输。

Manufacturers of smart home Internet of Things (IoT) devices are increasingly adding voice assistant and audio monitoring features to a wide range of devices including smart speakers, televisions, thermostats, security systems, and doorbells. Consequently, many of these devices are equipped with microphones, raising significant privacy concerns: users may not always be aware of when audio recordings are sent to the cloud, or who may gain access to the recordings. In this paper, we present the LeakyPick architecture that enables the detection of the smart home devices that stream recorded audio to the Internet without the user's consent. Our proof-of-concept is a LeakyPick device that is placed in a user's smart home and periodically "probes" other devices in its environment and monitors the subsequent network traffic for statistical patterns that indicate audio transmission. Our prototype is built on a Raspberry Pi for less than USD40 and has a measurement accuracy of 94% in detecting audio transmissions for a collection of 8 devices with voice assistant capabilities. Furthermore, we used LeakyPick to identify 89 words that an Amazon Echo Dot misinterprets as its wake-word, resulting in unexpected audio transmission. LeakyPick provides a cost effective approach for regular consumers to monitor their homes for unexpected audio transmissions to the cloud.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源