vix.ing · top · new · best · stats

FakeWake: Understanding and Mitigating Fake Wake-up Words of Voice Assistants

2021/09/21 by Yanjiao Chen, Yijie Bai, Chen, Yanjiao +10 · 1 citation
Computer Science · #Adversarial Robustness in Machine Learning #Artificial intelligence #Computer science #Construct (python library) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Fuzzy logic #Fuzzy set #Generator (circuit theory) #Interface (matter) #Linguistics #Machine Learning (cs.LG) #Power (physics) #Set (abstract data type) #Speech Recognition and Synthesis #Speech recognition #Topic Modeling #Voice command device #Word (group theory) #cs.CR #cs.LG

paper · pdf · doi:10.48550/arxiv.2109.09958

published in arXiv (Cornell University) (Cornell University)

arxiv created 2021/09/21 · openalex publication_date 2021/09/21 · arxiv updated 2021/09/22 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/08

Abstract

In the area of Internet of Things (IoT) voice assistants have become an important interface to operate smart speakers, smartphones, and even automobiles. To save power and protect user privacy, voice assistants send commands to the cloud only if a small set of pre-registered wake-up words are detected. However, voice assistants are shown to be vulnerable to the FakeWake phenomena, whereby they are inadvertently triggered by innocent-sounding fuzzy words. In this paper, we present a systematic investigation of the FakeWake phenomena from three aspects. To start with, we design the first fuzzy word generator to automatically and efficiently produce fuzzy words instead of searching through a swarm of audio materials. We manage to generate 965 fuzzy words covering 8 most popular English and Chinese smart speakers. To explain the causes underlying the FakeWake phenomena, we construct an interpretable tree-based decision model, which reveals phonetic features that contribute to false acceptance of fuzzy words by wake-up word detectors. Finally, we propose remedies to mitigate the effect of FakeWake. The results show that the strengthened models are not only resilient to fuzzy words but also achieve better overall performance on original training datasets.

Citations

Related