How the Dolphin Attack Opens Doors and Windows in the Smart Home

Around 2,000 spectators from 16 countries followed the first InnovationFestival @karlsruhe.digital in a live stream on October 16, 2020. Speakers from the technology region presented the best innovations around topics such as Smart City, mobility, and artificial intelligence on the stage of the ZKM. In a 10-minute live hacking presentation "When Dolphins Trick the Smart Home," security consultant Maximilian Stauß from aramido demonstrated the Dolphin Attack with an attack on an Amazon Echo Dot. He showed the audience how smartphones and smart home devices can be attacked using voice commands in the ultrasonic range, without humans hearing it.

Attacks on Voice Assistants like Siri, Google Assistant, or Alexa Remain Unheard

While the integration of voice assistants in so-called smart homes leads to a variety of new application possibilities, it also creates a whole range of new security risks. A security risk is the Dolphin Attack, first scientifically published in 2017. It attacks voice recognition systems in frequency ranges that are imperceptible to humans. To do this, voice messages are transformed into frequencies that are not perceptible to humans and played back with powerful speakers. Due to the physical properties of the installed microphones, the received audio signal is demodulated and the original voice message is recovered, so that it can be processed and executed. This security vulnerability affects all common voice assistant systems from Amazon Alexa to Google Assistant, Apple Siri, Microsoft Cortana, and Samsung Bixby.

Vulnerability of Smart Home Devices Can Be Limited

Due to the hardware currently installed in smart home devices, an inaudible attack using the Dolphin Attack cannot be prevented. However, everyone has the opportunity to generally limit the vulnerability of their own voice assistants. The safest and easiest way is to deactivate the continuous listening of smart home devices and smartphones. Google Assistant, for example, can be activated with a button, which significantly reduces the danger of an inaudible attack. It is generally recommended to only use functions via the voice assistant that are truly needed. Access to services related to online shopping or online banking should be deactivated in favor of information security.

The Speaker

Maximilian Stauss
As a consultant for information security, Maximilian Stauß develops security concepts according to Security-by-Design principles with the goal of enabling companies to have a better understanding of threats and protective measures in the digital world. He was already able to implement the Dolphin Attack during his studies at the Karlsruhe Institute of Technology (KIT).