NUIT 1 End to End no response Attack

The attack takes advantage of the fact that digital assistants use microphones that can pick up sounds that are inaudible to the human ear. NUIT plays sounds in the near-ultrasound frequency range (16kHz-20kHz) to give voice commands to smart devices, some commands take less than a second to play.

Advertisement
Advertisement

The study shows you can deploy NUIT through several different means. For example, an attacker could trick you into clicking a link to a website or a YouTube video on your phone, which would then play the inaudible voice commands after a delay to control your phone. Researchers demonstrated that NUITs also work when playing from one phone which controls another, over Zoom calls, playing on a phone to control a smart speaker or other IOT device, or even embedded into files that have additional background music.

In tests, NUIT attacks successfully controlled gadgets including iPhones, Samsung Galaxy phones, and Google Home and Amazon Echo Devices.

Advertisement

This sort of novel attack tends to see limited action in the real world. But with the rise of AI-assisted computing, voice commands will likely become more essential to our daily lives and audio exploits will be more in demand than ever. 

The researchers will present more details about the study at the USENIX Security Symposium in August.