Fingerprinting Voice Applications on Smart Speakers over Encrypted Traffic

Shriti Naraparaju · 2020

The popularity of smart speakers with virtual personal assistants such as Amazon Alexa and Google Assistant has been growing. However, the security and privacy of users using these devices have not been thoroughly examined which can lead to severe security and privacy concerns. In this poster, we present a fingerprinting attack of skills on Amazon Echo by analyzing the encrypted network traffic and show the potential privacy leakage of users using skills on smart speakers. Skills are voice applications that can be accessed through Amazon Alexa. Skills increase the diversity of using Amazon smart speakers by providing a variety of applications that can be used from a single platform with the use of voice commands without accessing a phone or a computer. In this fingerprinting attack, an adversary can eavesdrop on the network traffic of the smart speaker and predict the skill that is used by the user without decrypting the encrypted network traffic. For this attack, we collect the dataset consisting of 10,000 traces of encrypted network traffic related to 100 popular skills. We perform feature selection to investigate the top features that contribute to privacy leakage. We implement the attack by leveraging multiple machine learning algorithms. Among the different machine learning algorithms we implement, Random Forest Classifier performs the best by achieving an accuracy of 68.32% (compared to a random guess of 1%). The experimental results show that there is a need for developers to focus on the privacy leakages of users.

Read the paper · More papers on PaperTik