AI Briefing
KO

Voice AI systems are vulnerable to hidden audio attacks

·2026.05.18 20:51

Key point

An attack that manipulates Voice AI using audio inaudible to humans has been identified.

Details

As LALMs that handle voice and audio become everyday tools, it has been revealed that they can be manipulated even by audio mixed with faint signals imperceptible to humans. Research to be presented at the IEEE Symposium on Security and Privacy calls this attack AudioHijack, and it presents a method of altering waveforms to a degree nearly indistinguishable by humans in order to hijack the model's behavior.

The researchers optimized the attack on models with open weights, and showed that the same technique could transfer to commercial voice services. The attack was reusable regardless of the user's instructions, and malicious signals could be crafted with only about 30 minutes of training.

  • Models tested: 13 open models
  • Average success rate: 79-96%
  • Possible outcomes: sensitive web searches, downloading files from attacker-controlled sources, sending emails containing user data

Six attack outcomes were also confirmed: declaring inability to process the audio, refusing the request, outputting false information, inserting malicious links, changing persona, and inducing unauthorized tool use.

Defenses were weak. Providing examples of malicious instructions lowered the success rate by only 7%, and having the model self-check whether its response matched the user's intent caught only 28%. Monitoring internal attention was the most effective method, but attackers could evade it by being aware of this and lowering the intensity of the manipulation. The core risk is that audio mixed into real workflows—such as online videos, music, voice notes, and Zoom recordings—can serve as an attack vector.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.