Mitigating Voice Assistant Eavesdropping via Event Source Review on Mobile Devices

Wenbin Huang, Ju Ren, Hangcheng Cao, Hanyuan Chen, Hongbo Jiang, Zhangjie Fu · IEEE Transactions on Information Forensics and Security · 2025

Voice assistants have been widely adopted for their ability to provide non-touch human-computer interaction. However, while they offer convenience, their continuous listening for specific wake-up words raises privacy concerns, as it may lead to eavesdropping on user conversations. To investigate this issue, we devised covert eavesdropping attacks by perturbing and replaying events generated during the user’s normal activation of the voice assistant. The results demonstrate the feasibility and harmfulness of such eavesdropping attacks. To counter these covert voice eavesdropping attacks, we propose an effective defense scheme called CrossUnwind. This scheme leverages the groundtruth that voice assistant wake-up requires hardware to generate and send wake-up events. Specifically, we designed a novel tombstone file parsing process and an accurate event discrimination algorithm to obtain detailed call station information of the wake-up event without compromising the system. This allows us to determine whether the current wake-up event was generated by hardware. We deployed CrossUnwind on real devices and compared it to well-known machine learning and deep learning methods. The results demonstrate that CrossUnwind can achieve high accuracy in eavesdropping detection with faster speeds and lower resource utilization.

Read the paper · More papers on PaperTik