Personal Voice Assistant security - Denial of Service
| dc.contributor.advisor | Roedig, Utz | |
| dc.contributor.author | Sagi, Prathyusha | en |
| dc.contributor.funder | Science Foundation Ireland | en |
| dc.date.accessioned | 2026-09-16T13:28:33Z | |
| dc.date.available | 2026-09-16T13:28:33Z | |
| dc.date.issued | 2025-04-23 | en |
| dc.date.submitted | 2025-04-23 | en |
| dc.description.abstract | Personal Voice Assistants (PVA) have gained significant popularity across domains ranging from smartphones and smart speakers to critical setups like Intensive Care Units (ICUs) in hospitals, educational environments, and military operations. These PVAs offer hands-free convenience, allowing users to perform tasks such as setting reminders, controlling smart home devices, and managing complex processes. Despite their utility, they present notable security risks. One key vulnerability lies in the wake word detection process. PVAs continuously listen for a specific trigger word or phrase called a Wake Word, such as ’Alexa’, ’Hey Siri’, or ’Ok Google’. This wake word detection system can be vulnerable to attacks where an attacker masks the wake word using noise, preventing the device from waking up and processing user requests, effectively causing a Denial of Service (DoS) attack. Our study demonstrates how an attacker can strategically time a carefully designed noise burst, known as a jamming signal, to interfere with wake word detection in a PVA. By superimposing the jamming signal over specific sensitive regions of the wake word, the PVA can be rendered unresponsive. This is particularly concerning in highstakes environments such as Intensive Care Units (ICUs) or military operations, where voice commands are crucial. To address this vulnerability, we explore adversarial training, where the wake word detection model is retrained on wake word samples with jamming signals superimposed on sensitive regions, making the model resilient to targeted interference. We further show that using a wider range of noise types during adversarial training improves robustness to previously unseen jamming signals, while focusing on sensitive regions reduces training time and effort. Signal processing factors such as signal energies and phonetic characteristics, along with the model’s structure, play a key role in identifying these sensitive regions. Beyond robustness, alerting users to ongoing attacks is equally essential. We extend our wake word detection model from a binary classifier to a three-class classifier, labeling audio as non-wake word, wake word, or wake word + jamming signal. To reduce false alarms, we incorporate Direction of Arrival (DOA) and Short Time Energy (STE). DOA isolates jamming signals by identifying their direction relative to the wake word, while STE detects sudden energy spikes during sensitive regions, indicating deliberate interference. Combining either with the three-class classifier reduces unnecessary alarms, making the system robust to jamming and capable of detecting actual attacks. | en |
| dc.description.status | Not peer reviewed | en |
| dc.description.version | Accepted Version | en |
| dc.format.mimetype | application/pdf | en |
| dc.identifier.citation | Sagi, P. 2025. Personal Voice Assistant security - Denial of Service. PhD Thesis, University College Cork. | en |
| dc.identifier.endpage | 152 | en |
| dc.identifier.uri | https://hdl.handle.net/10468/19262 | |
| dc.language.iso | en | en |
| dc.publisher | University College Cork | en |
| dc.relation.project | info:eu-repo/grantAgreement/SFI/Frontiers for the Future::Awards/19/FFP/6775/IE/Personal Voice Assistant Security and Privacy/ | en |
| dc.relation.project | info:eu-repo/grantAgreement/SFI/Research Centres Programme::Phase 2/13/RC/2077_P2/IE/CONNECT_Phase 2/ | en |
| dc.rights | © 2025, Prathyusha Sagi. | en |
| dc.rights.uri | https://creativecommons.org/licenses/by/4.0/ | en |
| dc.subject | Denial of Service | en |
| dc.subject | Wake words | en |
| dc.subject | Jamming | en |
| dc.subject | Adversarial training | en |
| dc.subject | Wake word jamming detection | en |
| dc.title | Personal Voice Assistant security - Denial of Service | en |
| dc.type | Doctoral thesis | en |
| dc.type.qualificationlevel | Doctoral | en |
| dc.type.qualificationname | PhD - Doctor of Philosophy | en |
